Privacy Policy
Please read this Policy carefully
This Privacy Policy is developed in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Its Protection" No. 94-V dated May 21, 2013 (as amended). Registration in or use of the Service constitutes your full and unconditional consent to this Policy. If you do not accept the Policy — immediately cease using the Service and delete your account.
Contents
- 1. General Provisions
- 2. Categories of Data Collected
- 3. Purposes and Legal Bases
- 4. Artificial Intelligence and Data
- 5. Transfer of Data to Third Parties
- 6. Data Storage and Protection
- 7. Data Retention
- 8. Data Localization and Cross-Border Transfer
- 9. User Responsibility for Data
- 10. User Rights
- 11. Cookies and Tracking
- 12. Security and Incidents
- 13. Links to Third-Party Sites
- 14. Minors
- 15. Changes to the Policy
- 16. Contact Information
1. General Provisions
This Privacy Policy ("Policy") defines the procedure for collecting, storing, processing, using, and protecting personal data of users ("User", "You") of the Lonevi platform, available at lonevi.com ("Service", "Platform").
The personal data operator is DreamLight LLP, BIN 120340007735 ("Company", "We", "Operator").
Operator Contact Details:
Platform: lonevi.com
Privacy: privacy@lonevi.com
Security: security@lonevi.com
Support: support@lonevi.com
This Policy is an integral part of the Terms of Use. Use of the Service constitutes full acceptance of this Policy. The Policy applies to all personal data that the User provides upon registration, use of the Service, or any other interaction with the Platform.
2. Categories of Data Collected
2.1. Data provided by the User
- Name, email address, password (stored encrypted)
- Date of birth and gender (for personalization)
- Profile photo (if uploaded by the User)
2.2. Health data — special category
- Health indicators entered manually (weight, blood pressure, pulse, biomarkers)
- Symptoms and queries in AI chat
- Medical documents, test results, and other files
- Medical card data, AI query history
- Personal health goals and preferences
Important: The User independently determines which medical data to enter into the Service. The Company is not responsible for the completeness or accuracy of data provided by the User.
2.3. Technical data (automatic)
- IP address, country, browser type and version, operating system, device
- Pages visited, actions on the Platform, session duration
- Cookie data (see section 11)
2.4. Payment data
Card data is processed exclusively by the payment provider and is not stored on Lonevi servers. The Company stores only: fact and date of payment, amount, last 4 digits of card.
2.5. Data we do NOT collect
- Identity documents (passport, national ID)
- Biometric data (fingerprints, facial recognition)
- Data not voluntarily provided by the User
3. Purposes and Legal Bases
| Purpose | Legal Basis | Data Category |
|---|---|---|
| Account creation and authentication | Contract performance | Account |
| AI analysis of queries and documents | Explicit consent | Medical |
| Personalized recommendations | Explicit consent | Medical + Account |
| Technical operation and security | Legitimate interest | Technical |
| Service improvement (anonymized) | Legitimate interest | Technical (anonymized) |
| Service notifications | Contract performance | |
| Marketing communications | Separate consent | |
| Payment processing | Contract performance | Payment |
| Compliance with legislation | Legal obligation | As required |
| Fraud prevention | Legitimate interest | Technical |
The Company processes only data necessary to achieve a specific purpose (data minimization principle).
4. Artificial Intelligence and Data
Data Transfer to OpenAI
Text content of your queries and uploaded documents is transmitted to OpenAI (USA) for AI assistant operation. The Company takes reasonable measures to minimize transmitted data and does not include direct user identifiers in AI queries. The Company is not responsible for OpenAI's privacy policy and data processing practices.
AI Model Training
The Company does not use your personal medical data to train its own AI models. Anonymized aggregated data may be used to improve the Service provided individual identification is impossible. You may opt out of improvement programs via Settings → Privacy.
5. Transfer of Data to Third Parties
The Company does not sell personal data. Transfer to third parties occurs only in the following strictly defined cases:
OpenAI (USA)
AI query processing · Data: Message and document text
Railway (USA)
Cloud server and DB hosting · Data: All data encrypted
Vercel (USA)
Web app hosting · Data: Technical request data
Google Analytics (USA)
Usage analytics · Data: Anonymized technical data
Payment provider
Payment processing · Data: Payment data
RK State authorities
Legal compliance · Data: Upon lawful request
Limitation of liability for third parties. The Company takes reasonable measures when selecting providers but is not responsible for the privacy policies and actions of third parties to whom data has been lawfully transferred, including security breaches on the part of such third parties.
6. Data Storage and Protection
The Company applies technical and organizational protection measures in accordance with RK Law No. 94-V and industry standards:
Encryption in transit
HTTPS/TLS 1.3 for all connections
Encryption at rest
Medical data and passwords stored encrypted
Access control
Principle of least privilege for all personnel
Security audits
Regular checks and access log analysis
Backups
Automated encrypted backups
Cryptographic protection
Certified means for medical data (KZ)
7. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Account duration + 30 days | Contract |
| Medical data and documents | Account duration or until consent withdrawal | Consent |
| AI chat history | Account duration + 30 days | Contract |
| Technical logs | 90 days | Security |
| Payment data | 5 years from payment date | RK tax law |
| Backups | 30 days | Data protection |
| Incident investigation data | Until completion + 1 year | Legitimate interest / law |
Upon expiry, data is permanently deleted or anonymized. Anonymized data may be retained indefinitely for analytical purposes.
8. Data Localization and Cross-Border Transfer
Under RK Law No. 94-V, personal data of Kazakhstan citizens must be initially collected and processed within Kazakhstan. Due to the use of international cloud services, some data is processed on servers in the USA.
Cross-border transfer is carried out with appropriate data protection guarantees based on contractual obligations of third parties. By using the Service, you consent to cross-border data transfer in accordance with this Policy.
Limitation of liability for cross-border transfer. The Company takes reasonable measures to ensure data protection during transfer but is not liable for the level of data protection in the recipient's jurisdiction beyond what is provided for by contractual obligations.
9. User Responsibility for Data Provided
The User independently determines which data to provide to the Service and is responsible for:
- Data accuracy. The User warrants that data provided is accurate, complete, and up-to-date. The Company does not verify the accuracy of medical data entered by the User and is not responsible for consequences of using inaccurate data.
- Third-party data. By uploading documents containing third-party personal data, the User warrants their explicit consent for processing such data. All responsibility for violations of third-party rights lies with the User.
- Account confidentiality. The User bears full responsibility for all actions performed under their account, including unauthorized actions by third parties — until notifying the Company of unauthorized access.
- Lawful use. The User is responsible for ensuring their use of the Service complies with applicable legislation.
10. User Rights
Under RK Law No. 94-V, the User has the right to:
Right of access
Obtain confirmation of processing and a copy of data
→ Settings → My Data or email
Right to rectification
Request correction of inaccurate data
→ Profile Settings or email
Right to erasure
Request deletion of all data
→ Settings → Delete Account or email
Right to restriction
Restrict processing in provided cases
→ privacy@lonevi.com
Right to withdraw consent
Withdraw consent at any time
→ Settings → Privacy
Right to complain
File a complaint with RK Ministry of Digital Development
→ RK Authorized Authority
What the data export contains (GET /users/me/export)
When you click "Download my data" you receive one JSON document covering every piece of personal data we retain:
- Profile — email, name, phone, language, timezone, registration and update timestamps
- Consents — accepted policy version, acceptance timestamp, marketing opt-in flag
- Family members — every relative profile you created or have shared access to, with link metadata (relation, access level)
- Event journal — full medical journal (entries, notes, extracted data, linked documents)
- Documents — metadata for every uploaded file (file name, mime type, status, title) plus a signed download URL for the file itself
- Consultations — monthly AI-chat usage counters
- AI request log — the prompts sent to the AI models on your behalf and the models’ replies, with processing time and token counts. Kept for 90 days, then deleted; removed immediately when you delete your account
- Subscriptions — plan history, statuses, billing periods, payment-provider identifiers
- Recommendations — Stage A output: title, reasoning, dosage note, status, pillar (lifestyle/genetics/environment), outcome
What we do NOT retain and therefore cannot include in the export:
- Full banking card details — handled exclusively by the payment provider; we store only payment confirmation, amount, and the last 4 digits of the card
- Biometric identifiers (fingerprints, face recognition)
- Government identity documents (passport, national ID)
- File contents of medical documents inside the JSON itself — fetched on demand via the per-document download link
How to submit a request:
Send an email to privacy@lonevi.com with subject "Exercise of Data Subject Rights", indicating your registered email and desired action. Response within 30 calendar days.
To protect against fraud, the Company may request identity verification before fulfilling a request. The Company reserves the right to decline a request if its execution contradicts legal requirements or the Company's legitimate interests.
11. Cookies and Tracking
We use the following categories of cookies:
Login and basic Service operation. Cannot be disabled.
Google Analytics — anonymized usage data.
Interface settings and user preferences.
12. Security and Incidents
In case of a security incident, the Company will:
- Notify the RK authorized authority within 1 business day of discovery
- Notify affected users within 72 hours if there is a high risk of rights violation
- Take immediate measures to contain the incident
Report suspected security breaches to security@lonevi.com. The Company is not liable for security breaches resulting from the User's own actions (sharing passwords with third parties, using insecure devices, etc.).
13. Links to Third-Party Sites
The Service may contain links to third-party websites and applications. This Policy applies exclusively to the Lonevi Platform and does not apply to third-party sites. The Company is not responsible for the privacy policies, content, or data processing practices of third-party sites. We recommend Users independently review the privacy policies of third-party resources.
14. Minors
The Lonevi Service is intended exclusively for persons who have reached 18 years of age.
The Company does not intentionally collect personal data of minors. Upon discovering such data, the account is immediately deleted. If you are a parent and learn that your child has provided us with data — contact privacy@lonevi.com. Data will be deleted within 48 hours.
15. Changes to the Policy
The Company may unilaterally amend this Policy. For material changes, the Company will notify Users by email 30 days in advance. For non-material changes — update the document date without separate notification.
Continued use of the Service after changes take effect constitutes full and unconditional consent to the updated Policy. If the User does not agree with changes — they must delete their account before the changes take effect.
16. Contact Information
Response time for personal data inquiries: no more than 30 days.