Skip to content
Legal

Privacy Notice.

This Notice explains how N1 Research, LLC handles personal information across n1.care websites, applications, reports, support, and related services.

Last updated September 24, 2026N1 Research, LLC
ContentsScope and rolesWhat we collectHow we use itHealth informationAI and trainingHow we disclose itInternational transfersSecurityRetentionYour rightsCookiesChildrenRegional noticesAI assistant connectorsChanges and contact
Who controls clinical data?

When a clinic, clinician, employer, or other organization provides your information, that organization generally decides why it is processed and n1 acts on its instructions. Requests about a clinical record should usually go first to that organization.

1. Scope and roles

This Privacy Notice applies when n1 determines how and why personal information is processed, including website visits, direct consumer accounts, sales, support, and business contacts. It also explains at a high level how our Service processes patient information for customers.

For Customer Patient Data processed for a healthcare organization, n1 generally acts as a service provider or processor and the customer acts as controller or regulated entity. The customer’s privacy notice and our agreement with that customer govern that processing. If n1 acts as a HIPAA business associate, a signed BAA governs protected health information (“PHI”). Not every health app or use of health information is subject to HIPAA.

“Personal information” includes information that identifies, relates to, or can reasonably be linked with a person. Health and genetic information may receive additional legal protection.

2. Information we collect

Information you provide

  • account and identity information, such as name, email, organization, role, and credentials;
  • Customer Patient Data, including records, test results, diagnoses, medications, genetics, notes, images, prompts, corrections, and reports;
  • communications, support requests, questionnaire responses, and feedback;
  • billing and transaction information, generally processed with a payment provider; and
  • permissions, sharing choices, consent records, and administrative settings.

Information collected automatically

  • device, browser, IP address, approximate location, operating system, and language;
  • log, authentication, audit, security, feature-use, and diagnostic events;
  • referring pages, session interactions, and cookie or similar-technology identifiers; and
  • information required to prevent abuse, investigate incidents, and maintain reliability.

Information from others

We may receive information from healthcare organizations, clinicians, patients, authorized representatives, laboratories, connected services, identity providers, business partners, and publicly available sources. The person providing information is responsible for having authority to do so.

3. How we use information

Depending on the context and our role, we use personal information to:

  • provide, authenticate, operate, personalize, and support the Service;
  • ingest records, extract and organize data, generate Outputs, link evidence, and enable review, sharing, export, or deletion;
  • secure accounts, log access, detect misuse, investigate incidents, and protect patients and users;
  • communicate about accounts, transactions, support, security, product changes, and requested marketing;
  • process payments and administer trials, subscriptions, and enterprise relationships;
  • debug, measure, research, and improve performance and usability using information permitted by contract and law;
  • comply with law, enforce agreements, establish or defend legal claims, and respond to lawful requests; and
  • create aggregated or deidentified statistics that are not reasonably linkable to an individual.

Where laws such as the GDPR or UK GDPR apply, our legal basis may be performance of a contract, legitimate interests, compliance with law, protection of vital interests, consent, or another basis available for the specific processing. Processing health or other special-category information also requires an applicable additional condition. A customer acting as controller determines the basis for its Customer Patient Data.

4. Health and patient information

Health information is sensitive. We process Customer Patient Data only to provide and secure the Service, follow the customer’s documented instructions and applicable agreements, comply with law, and perform other uses that are expressly authorized.

Healthcare customers remain responsible for notices, authorizations, consents, access rules, recordkeeping, and the legality of uploads and disclosures. Patients should contact the relevant healthcare organization to exercise rights in records controlled by that organization. When required and permitted, n1 will assist the organization in responding.

We do not sell Customer Patient Data or use it for targeted advertising. We do not disclose it to data brokers. We may disclose it to authorized users, instructed recipients, and service providers that need it to deliver or secure the Service, subject to appropriate contractual restrictions.

5. AI systems and model training

The Service may send the minimum information needed for a task to AI model providers acting as service providers or subprocessors. The providers, location, retention, and configuration used may depend on the product, customer plan, region, and written agreement.

n1 does not use Customer Patient Data to train general-purpose AI models and does not permit an AI provider to use that data to train its general-purpose models. We may use deidentified, aggregated, or synthetic information to evaluate and improve systems, subject to law and contract.

Automated processing helps organize information and draft Outputs. n1 does not intend the Service to make solely automated decisions that produce legal or similarly significant effects. Qualified human review is required before an Output is used in care or another high-impact context.

6. When we disclose information

We may disclose personal information:

  • to the customer, Authorized Users, patients, and recipients selected through sharing or integration controls;
  • to vetted hosting, storage, security, communications, analytics, support, payment, and AI service providers that process it for us;
  • to professional advisers, auditors, insurers, and financing sources under confidentiality obligations;
  • to authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate fraud or security events, or establish and defend claims;
  • in connection with a merger, financing, reorganization, bankruptcy, acquisition, or sale, subject to appropriate protections; or
  • at your direction or with your consent.

We do not sell personal information for money. If a jurisdiction treats particular analytics or advertising disclosures as a “sale” or “sharing,” we provide the choices required by applicable law. We do not use Customer Patient Data for behavioral advertising.

7. Data location and international transfers

Patient records are currently stored on AWS infrastructure in the United States. n1 and its service providers may also process information in countries other than where it was collected. Laws in those countries may differ. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, the UK international data transfer addendum, contractual restrictions, or another lawful mechanism.

In-country hosting is not currently offered. Contact us if your organization has specific data-location requirements. Any future binding data-residency commitment must be stated in the applicable order form or DPA.

8. Security and incidents

We use administrative, technical, and organizational safeguards designed for the nature of the information, which may include encryption in transit and at rest, access controls, logging, environment separation, vendor review, backups, and incident-response procedures. No safeguard, transmission, or storage system can guarantee absolute security.

Users must protect credentials, devices, exports, and sharing links and promptly notify n1 of suspected unauthorized access. If we identify a reportable breach, we will notify affected customers, individuals, or authorities as required by applicable law and contract.

9. Retention and deletion

We retain information only as long as reasonably necessary for the purposes described here, including providing the Service, meeting customer instructions, securing systems, resolving disputes, enforcing agreements, and satisfying legal, accounting, or audit duties. Retention depends on the data type, account settings, product mode, customer agreement, legal requirements, and backup cycle.

When deletion is requested or an account ends, we delete or deidentify information according to the applicable workflow and agreement, unless retention is required or permitted by law. Copies may remain temporarily in encrypted backups or restricted legal and security records until ordinary deletion cycles complete. We may retain aggregated or deidentified information that cannot reasonably identify a person.

10. Your privacy rights

Depending on your location and our role, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, opt out of certain disclosures or marketing, and appeal a denied request. You may also complain to a privacy or data-protection authority.

We may verify your identity and authority, ask for information needed to locate records, and deny or limit a request where law permits. Authorized agents must provide proof of authority. We will not unlawfully discriminate against you for exercising a right.

For Customer Patient Data controlled by a clinic or other organization, send the request to that organization. For information controlled by n1, use our contact form or email longevity@n1.care. Do not include health records in an email.

11. Cookies and communications

We may use essential cookies or similar technologies for authentication, security, preferences, performance, and site functionality. Where consent is required for nonessential analytics, we will request it before use. Browser controls can block cookies, but parts of the Service may stop working.

You can opt out of promotional email using the unsubscribe link or by contacting us. We may still send transactional, safety, security, legal, and service messages.

12. Children

The Service is not directed to children and n1 does not knowingly create accounts for children without an authorized adult, healthcare organization, and any legally required permission. A healthcare customer may process pediatric records under its own authority and agreement with n1. If you believe a child provided information improperly, contact us.

13. Regional information

United States and HIPAA

HIPAA applies only in the circumstances defined by law. When HIPAA applies to a customer’s use of n1 and n1 handles protected health information (PHI) as a business associate, n1 enters into a Business Associate Agreement (BAA) with that customer. We also require appropriate agreements with subprocessors that create, receive, maintain, or transmit that PHI on our behalf.

The applicable BAA defines permitted uses and disclosures of PHI, required safeguards, incident and breach reporting, subcontractor obligations, and the return or deletion of PHI. Health information outside HIPAA may still be protected by other federal or state privacy and breach-notification laws.

European Economic Area and United Kingdom

Under the EU GDPR and UK GDPR, genetic data and data concerning health are special-category personal data. Processing requires an applicable lawful basis and a separate condition for processing special-category data, together with any additional requirements that apply. When n1 processes Customer Patient Data for a customer, the customer determines the purposes of that processing and n1 acts on its documented instructions under the applicable agreement or DPA.

Switzerland

Under the Swiss Federal Act on Data Protection, health and genetic data are sensitive personal data. Where Swiss law applies, n1 and its customers are responsible for the obligations that apply to their respective roles. Relevant international-transfer safeguards are described above.

United States state privacy laws

Residents of certain states may have additional rights regarding access, correction, deletion, portability, appeal, and opting out of sale, targeted advertising, or profiling. n1 does not sell Customer Patient Data or use it for targeted advertising. We honor applicable requests after verification.

Other countries

Other health, privacy, professional, localization, and international-transfer requirements may apply. We work with customers to identify any additional agreements or deployment requirements, while each customer remains responsible for confirming that its use of n1 is permitted in its jurisdiction.

14. AI assistant connectors

n1 offers a connector that lets an Authorized User work with their n1 records from an AI assistant such as Claude, using the Model Context Protocol (MCP). This section applies when you connect n1 to an assistant. The rest of this Notice continues to apply to information n1 handles, except as stated here.

Connecting and disconnecting

You connect by signing in to n1 and granting the assistant access through OAuth 2.0. The grant lists what the assistant may do: read records, biomarkers, genetics and reports and, if you allow it, make changes. To withdraw access, disconnect n1 in the assistant; this stops that assistant from using the connector. n1 cannot currently revoke an assistant’s access from its side. The connector does not store the assistant’s access tokens; it holds them in memory only for the duration of each request.

What the assistant receives

When the assistant requests information through the connector during your conversation, n1 sends it that information, within the access you granted: for example a patient’s biomarker values, diagnoses, medications, procedures, genetic markers or reports. n1 makes this disclosure at your direction, as described in section 6. The information is transmitted to the assistant’s provider (for Claude, Anthropic) and is then governed by that provider’s terms and privacy notice, not by this Notice. The provider is not n1’s service provider or subprocessor, and n1’s commitments in section 5, including those on model training, do not apply to it. Review the provider’s settings and terms, including whether it may use your conversations to train its models.

Healthcare organizations and HIPAA

Connecting an assistant discloses patient information to a third party. Where HIPAA applies, do not connect an assistant unless your organization has a Business Associate Agreement with the assistant provider that covers this use and your agreement with n1 permits the disclosure. For Customer Patient Data that n1 processes for a healthcare organization, that organization, as controller or regulated entity, remains responsible for deciding whether its users may connect an assistant.

Documents you share with the assistant

A lab report or other document you paste or upload into the conversation is processed by the assistant, not uploaded to n1. Information from it is saved to n1 only through a confirmed change, as described below.

Changes to records

Through the connector, the assistant can add, edit or delete readings, diagnoses, medications and procedures, and generate reports. For each change, the connector first returns a preview and completes the change only on a separate confirmation. The assistant is instructed to show you the preview and ask for your agreement before confirming, but n1 cannot verify what the assistant shows you, so review each proposed change before you agree to it. The connector cannot delete patients or change billing or payment settings. Changes are recorded in the audit events described in section 2 and retained under section 9.

What n1 keeps

Apart from the operational log described here and the audit events for confirmed changes, the connector does not store conversations, documents or record contents. For each request, the operational log records your n1 account identifier, the tool used, the identifiers of the records accessed and record counts. Because these identifiers can be linked to you and to patients, n1 treats the log as personal information and uses it only to operate, secure and troubleshoot the connector. Clinical values, document contents, tokens and credentials are not written to the log. The log is retained for seven days. The connector runs on Cloudflare infrastructure, a hosting service provider under section 6, which may process the log in countries other than where it was collected, as described in section 7.

15. Changes and contact

We may update this Notice to reflect changes in law, technology, or the Service. We will post the updated date and provide additional notice where required. Earlier versions may be requested.

N1 Research, LLC is the company responsible for this Notice. Privacy questions and requests may be sent through our contact form or to longevity@n1.care. Do not send patient information or health records by ordinary email.

Terms of UseContact n1

The whole health story. Every answer traced to its source.

ProductHow it worksReportsPricing
SolutionsFor cliniciansFor patients
CompanyAboutContact
Trust & legalSecurity & compliancePrivacyTermsPatents
© 2026 N1 Research, LLC