← Back to Home

Privacy Policy

Version 3.0·Last updated: August 1, 2026

Please read this Policy carefully

This Privacy Policy is developed in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Its Protection" No. 94-V dated May 21, 2013 (as amended). Registration in or use of the Service constitutes your full and unconditional consent to this Policy. If you do not accept the Policy — immediately cease using the Service and delete your account.

1. General Provisions

This Privacy Policy ("Policy") defines the procedure for collecting, storing, processing, using, and protecting personal data of users ("User", "You") of the Lonevi platform, available at lonevi.com ("Service", "Platform").

The personal data operator is DreamLight LLP, BIN 120340007735 ("Company", "We", "Operator").

Operator Contact Details:

Platform: lonevi.com

Privacy: privacy@lonevi.com

Security: security@lonevi.com

Support: support@lonevi.com

This Policy is an integral part of the Terms of Use. Use of the Service constitutes full acceptance of this Policy. The Policy applies to all personal data that the User provides upon registration, use of the Service, or any other interaction with the Platform.

2. Categories of Data Collected

2.1. Data provided by the User

  • Name, email address, password (stored encrypted)
  • Date of birth and gender (for personalization)
  • Profile photo (if uploaded by the User)

2.2. Health data — special category

⚠️ Health data is a special category under RK Law No. 94-V and is processed solely on the basis of your explicit, voluntary, specific, and informed consent.
  • Health indicators entered manually (weight, blood pressure, pulse, biomarkers)
  • Symptoms and queries in AI chat
  • Medical documents, test results, and other files
  • Medical card data, AI query history
  • Personal health goals and preferences

Important: The User independently determines which medical data to enter into the Service. The Company is not responsible for the completeness or accuracy of data provided by the User.

2.3. Technical data (automatic)

  • IP address, country, browser type and version, operating system, device
  • Pages visited, actions on the Platform, session duration
  • Cookie data (see section 11)

2.4. Payment data

Card data is processed exclusively by the payment provider and is not stored on Lonevi servers. The Company stores only: fact and date of payment, amount, last 4 digits of card.

2.5. Data we do NOT collect

  • Identity documents (passport, national ID)
  • Biometric data (fingerprints, facial recognition)
  • Data not voluntarily provided by the User

3. Purposes and Legal Bases

PurposeLegal BasisData Category
Account creation and authenticationContract performanceAccount
AI analysis of queries and documentsExplicit consentMedical
Personalized recommendationsExplicit consentMedical + Account
Technical operation and securityLegitimate interestTechnical
Service improvement (anonymized)Legitimate interestTechnical (anonymized)
Service notificationsContract performanceEmail
Marketing communicationsSeparate consentEmail
Payment processingContract performancePayment
Compliance with legislationLegal obligationAs required
Fraud preventionLegitimate interestTechnical

The Company processes only data necessary to achieve a specific purpose (data minimization principle).

4. Artificial Intelligence and Data

Data Transfer to OpenAI

Text content of your queries and uploaded documents is transmitted to OpenAI (USA) for AI assistant operation. The Company takes reasonable measures to minimize transmitted data and does not include direct user identifiers in AI queries. The Company is not responsible for OpenAI's privacy policy and data processing practices.

AI Model Training

The Company does not use your personal medical data to train its own AI models. Anonymized aggregated data may be used to improve the Service provided individual identification is impossible. You may opt out of improvement programs via Settings → Privacy.

AI accuracy is not guaranteed. AI processing results may contain errors, inaccuracies, or bias from training data. The Company does not guarantee the accuracy, completeness, or timeliness of AI assistant responses and is not liable for consequences of their use.

5. Transfer of Data to Third Parties

The Company does not sell personal data. Transfer to third parties occurs only in the following strictly defined cases:

OpenAI (USA)

AI query processing · Data: Message and document text

Consent / Contract

Railway (USA)

Cloud server and DB hosting · Data: All data encrypted

Legitimate interest

Vercel (USA)

Web app hosting · Data: Technical request data

Legitimate interest

Google Analytics (USA)

Usage analytics · Data: Anonymized technical data

Consent (cookie)

Payment provider

Payment processing · Data: Payment data

Contract performance

RK State authorities

Legal compliance · Data: Upon lawful request

Legal obligation

Limitation of liability for third parties. The Company takes reasonable measures when selecting providers but is not responsible for the privacy policies and actions of third parties to whom data has been lawfully transferred, including security breaches on the part of such third parties.

6. Data Storage and Protection

The Company applies technical and organizational protection measures in accordance with RK Law No. 94-V and industry standards:

Encryption in transit

HTTPS/TLS 1.3 for all connections

Encryption at rest

Medical data and passwords stored encrypted

Access control

Principle of least privilege for all personnel

Security audits

Regular checks and access log analysis

Backups

Automated encrypted backups

Cryptographic protection

Certified means for medical data (KZ)

Security guarantee limitation. No data protection system can ensure absolute security. The Company is not liable for damages caused by security breaches that are not the result of the Company's intentional misconduct or gross negligence.

7. Data Retention

Data CategoryRetention PeriodBasis
Account dataAccount duration + 30 daysContract
Medical data and documentsAccount duration or until consent withdrawalConsent
AI chat historyAccount duration + 30 daysContract
Technical logs90 daysSecurity
Payment data5 years from payment dateRK tax law
Backups30 daysData protection
Incident investigation dataUntil completion + 1 yearLegitimate interest / law

Upon expiry, data is permanently deleted or anonymized. Anonymized data may be retained indefinitely for analytical purposes.

8. Data Localization and Cross-Border Transfer

Under RK Law No. 94-V, personal data of Kazakhstan citizens must be initially collected and processed within Kazakhstan. Due to the use of international cloud services, some data is processed on servers in the USA.

Cross-border transfer is carried out with appropriate data protection guarantees based on contractual obligations of third parties. By using the Service, you consent to cross-border data transfer in accordance with this Policy.

Limitation of liability for cross-border transfer. The Company takes reasonable measures to ensure data protection during transfer but is not liable for the level of data protection in the recipient's jurisdiction beyond what is provided for by contractual obligations.

9. User Responsibility for Data Provided

The User independently determines which data to provide to the Service and is responsible for:

  • Data accuracy. The User warrants that data provided is accurate, complete, and up-to-date. The Company does not verify the accuracy of medical data entered by the User and is not responsible for consequences of using inaccurate data.
  • Third-party data. By uploading documents containing third-party personal data, the User warrants their explicit consent for processing such data. All responsibility for violations of third-party rights lies with the User.
  • Account confidentiality. The User bears full responsibility for all actions performed under their account, including unauthorized actions by third parties — until notifying the Company of unauthorized access.
  • Lawful use. The User is responsible for ensuring their use of the Service complies with applicable legislation.

10. User Rights

Under RK Law No. 94-V, the User has the right to:

Right of access

Obtain confirmation of processing and a copy of data

→ Settings → My Data or email

Right to rectification

Request correction of inaccurate data

→ Profile Settings or email

Right to erasure

Request deletion of all data

→ Settings → Delete Account or email

Right to restriction

Restrict processing in provided cases

→ privacy@lonevi.com

Right to withdraw consent

Withdraw consent at any time

→ Settings → Privacy

Right to complain

File a complaint with RK Ministry of Digital Development

→ RK Authorized Authority

What the data export contains (GET /users/me/export)

When you click "Download my data" you receive one JSON document covering every piece of personal data we retain:

  • Profile — email, name, phone, language, timezone, registration and update timestamps
  • Consents — accepted policy version, acceptance timestamp, marketing opt-in flag
  • Family members — every relative profile you created or have shared access to, with link metadata (relation, access level)
  • Event journal — full medical journal (entries, notes, extracted data, linked documents)
  • Documents — metadata for every uploaded file (file name, mime type, status, title) plus a signed download URL for the file itself
  • Consultations — monthly AI-chat usage counters
  • AI request log — the prompts sent to the AI models on your behalf and the models’ replies, with processing time and token counts. Kept for 90 days, then deleted; removed immediately when you delete your account
  • Subscriptions — plan history, statuses, billing periods, payment-provider identifiers
  • Recommendations — Stage A output: title, reasoning, dosage note, status, pillar (lifestyle/genetics/environment), outcome

What we do NOT retain and therefore cannot include in the export:

  • Full banking card details — handled exclusively by the payment provider; we store only payment confirmation, amount, and the last 4 digits of the card
  • Biometric identifiers (fingerprints, face recognition)
  • Government identity documents (passport, national ID)
  • File contents of medical documents inside the JSON itself — fetched on demand via the per-document download link

How to submit a request:

Send an email to privacy@lonevi.com with subject "Exercise of Data Subject Rights", indicating your registered email and desired action. Response within 30 calendar days.

To protect against fraud, the Company may request identity verification before fulfilling a request. The Company reserves the right to decline a request if its execution contradicts legal requirements or the Company's legitimate interests.

11. Cookies and Tracking

We use the following categories of cookies:

Strictly necessaryNo consent required

Login and basic Service operation. Cannot be disabled.

AnalyticsConsent required

Google Analytics — anonymized usage data.

FunctionalConsent required

Interface settings and user preferences.

12. Security and Incidents

In case of a security incident, the Company will:

  • Notify the RK authorized authority within 1 business day of discovery
  • Notify affected users within 72 hours if there is a high risk of rights violation
  • Take immediate measures to contain the incident

Report suspected security breaches to security@lonevi.com. The Company is not liable for security breaches resulting from the User's own actions (sharing passwords with third parties, using insecure devices, etc.).

13. Links to Third-Party Sites

The Service may contain links to third-party websites and applications. This Policy applies exclusively to the Lonevi Platform and does not apply to third-party sites. The Company is not responsible for the privacy policies, content, or data processing practices of third-party sites. We recommend Users independently review the privacy policies of third-party resources.

14. Minors

The Lonevi Service is intended exclusively for persons who have reached 18 years of age.

The Company does not intentionally collect personal data of minors. Upon discovering such data, the account is immediately deleted. If you are a parent and learn that your child has provided us with data — contact privacy@lonevi.com. Data will be deleted within 48 hours.

15. Changes to the Policy

The Company may unilaterally amend this Policy. For material changes, the Company will notify Users by email 30 days in advance. For non-material changes — update the document date without separate notification.

Continued use of the Service after changes take effect constitutes full and unconditional consent to the updated Policy. If the User does not agree with changes — they must delete their account before the changes take effect.

16. Contact Information

Operator

DreamLight LLP (Lonevi)

lonevi.com

Response time for personal data inquiries: no more than 30 days.

Privacy PolicyTerms of Use