Legal & Privacy

    Privacy Policy

    How Beyond23 collects, uses, shares and protects personal data across the website, BioAge, the app, labs, wearables, AI features, coaching and Sprints.

    Version 1.1Last updated 25 July 2026Terms of Service

    1Who we are and what this Policy covers

    Beyond23 is a healthspan and wellness platform operated by TECHVITA LABS PRIVATE LIMITED (CIN: U72100GJ2024PTC150525), a company incorporated in India and based in Ahmedabad, Gujarat (“Beyond23”, “B23”, “we”, “us” or “our”).

    This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:

    • visit beyond23.life, its subdomains or any other website that links to this Policy;
    • complete the Beyond23 BioAge screening or view a BioAge result;
    • join a waitlist, reserve a place, purchase a membership, assessment or Sprint, or communicate with us;
    • create or use a Beyond23 account, mobile application, web application or other digital product;
    • connect a wearable, health platform, laboratory, diagnostic service or other third-party service;
    • interact with an AI-supported feature, coach, clinician, support representative or partner through Beyond23; or
    • otherwise use a Beyond23 product or service that links to this Policy.

    Together, these are the “Services”.

    This Policy should be read with our Terms of Service and any feature-specific notice shown when we ask for particular information or device permissions. If a feature-specific notice conflicts with this Policy, the more specific notice will apply to that feature.

    2Our privacy commitments

    Health information deserves a higher standard of care. Subject to the qualifications in this Policy, Beyond23 commits to the following principles:

    • Purpose before collection. We will explain why information is requested and use it for that purpose or another compatible purpose permitted by law.
    • Meaningful choice. Optional data sources, including wearables, photographs, voice samples and research participation, will be identified as optional unless genuinely required for a selected Service.
    • Data minimisation. We seek to collect and share only what is reasonably necessary for the relevant feature or Service.
    • No sale of personal health data. We do not sell or rent identifiable personal or health data to data brokers, advertisers or insurers.
    • No health-based advertising profiles. We do not use identifiable laboratory results, medical history, BioAge answers or health inferences to target third-party advertising.
    • Commercial use only after de-identification. We may share or license aggregated or de-identified insights for research, analytics or life-sciences purposes, including to organisations in India or other countries, only where the information is not reasonably capable of identifying you and subject to safeguards against re-identification.
    • Responsible AI. AI-supported outputs are used to assist education, personalisation and coaching. They are not a substitute for professional medical judgment.
    • User control. You can request access, correction or deletion, withdraw consent, disconnect integrations and raise a grievance, subject to legal and operational limitations explained below.

    3Personal data we may collect

    The information we collect depends on how you interact with Beyond23 and which Services you choose.

    3.1 Website, waitlist and reservation information

    • name, email address, mobile number and WhatsApp number;
    • city, country, preferred language and time zone;
    • OTP verification status and related authentication logs;
    • waitlist, referral, campaign or founding-member information;
    • messages, enquiries, survey responses and communication preferences; and
    • information you provide through contact, partner, affiliate or application forms.

    3.2 BioAge screening information

    If you complete BioAge, we may collect the answers you submit, which may include age range, biological sex, height, weight, waist or body-composition information, family history, lifestyle, sleep, activity, nutrition, stress, recovery, social connection, health history and other healthspan-related indicators.

    We may generate or infer:

    • a screening range or estimated BioAge-related result;
    • dimension-level scores, patterns or flags;
    • an archetype, such as Eagle, Wolf, Tiger, Bear or Owl;
    • educational insights and suggested areas to explore; and
    • information about completion, response changes and interactions with the screening.

    BioAge is a screening and engagement experience. Unless expressly stated otherwise for a separately validated feature, it does not measure or diagnose your biological age, disease, fitness for treatment or life expectancy.

    We use BioAge answers to provide the screening result and may also use them for internal research, validation, product improvement and analysis. Marketing contact and identifiable sharing with an external research, marketing or commercial partner require a separate, specific choice. We may share aggregated or de-identified BioAge information with selected research, analytics, marketing or life-sciences partners as described in Sections 6 and 8.

    3.3 Account and profile information

    When an account is available, we may collect:

    • name, date of birth, gender or sex-related information where relevant;
    • mobile number, email address, profile photograph and authentication details;
    • address, city, country, language and time zone;
    • goals, preferences, accessibility requirements and notification settings;
    • emergency contact information if you choose to provide it; and
    • account activity, consent history and privacy choices.

    3.4 Health and wellness information

    Depending on the Service you select, we may collect:

    • medical and family history, current symptoms, diagnoses, allergies, medications and supplements;
    • laboratory reports, biomarker values, reference ranges and testing metadata;
    • blood pressure, pulse, weight, waist measurements, body composition and other vitals;
    • sleep, activity, exercise, recovery, heart-rate, respiratory, glucose, temperature or other wearable-derived information;
    • nutrition, hydration, mood, stress, cognition, pain, energy and self-reported outcomes;
    • physical performance information, such as step tests, sit-to-stand, balance or grip-strength results;
    • health questionnaires and screening tools;
    • goals, routines, adherence, challenges and progress information;
    • coaching notes, chat messages and consultation-related records; and
    • any other health information you choose to upload or provide.

    3.5 Images, audio and digital biomarkers

    Certain optional features may allow you to submit or capture photographs, video or audio, including face photographs, body photographs, skin images, photographs of a mole, bruise or other area of concern, voice samples or recordings used during coaching.

    From these files, Beyond23 or an authorised provider may generate technical or health-related features, measurements, signals, embeddings, estimates or other derived information. Before collecting this type of information, we will provide a feature-specific notice explaining the purpose, whether the input is stored, whether analysis occurs on your device or on a server, and how long the source file and derived information are retained.

    Unless a feature-specific notice says otherwise, source photographs, video and voice files are used only to complete the requested analysis and generate the related report or feature. They are automatically deleted from active processing systems immediately after processing completes. We do not sell these source files, use them for advertising, or use them to train a general-purpose AI model. Any authorised processor handling a source file for us must apply equivalent use and deletion restrictions. Derived measurements or reports may be retained with the member record for the purposes described in this Policy.

    Do not upload intimate images, government identification, or information about another person unless the feature specifically requests it and you have lawful authority to provide it.

    3.6 Connected devices and third-party health services

    With your permission, we may receive information from services such as Apple Health, Google Health Connect, a wearable manufacturer, a continuous glucose monitor, a laboratory, a diagnostic provider, a health-record platform or another service you choose to connect.

    The information received depends on the permission you grant and may include activity, sleep, heart rate, recovery, glucose, body measurements, workouts, device identifiers, laboratory results and related timestamps. You can usually disconnect an integration through Beyond23 or the third party’s settings. Disconnecting stops future collection but does not automatically delete information already imported.

    3.7 Coaching, clinician and support interactions

    We may collect messages, appointment details, programme notes, goals, action plans, feedback and outcomes from your interactions with coaches, clinicians, support personnel or other authorised professionals. Calls or sessions will be recorded only where permitted by law and after appropriate notice or consent.

    If a clinician provides a regulated professional service, additional professional, consent and record-keeping terms may apply.

    3.8 Transaction information

    We may collect plan selection, order, invoice, billing address, tax, payment status, refund and transaction identifiers. Card, bank or UPI credentials are generally processed by an authorised payment provider and are not intended to be stored by Beyond23, except for limited tokens or transaction details needed to manage your purchase.

    Never disclose an OTP, card PIN, CVV or banking password to anyone claiming to represent Beyond23.

    3.9 Device, usage and technical information

    We may automatically collect:

    • IP address, browser, device type, operating system and application version;
    • device or advertising identifiers where permitted;
    • language, approximate location derived from IP, time zone and network information;
    • pages viewed, links selected, feature usage, session duration, crashes and diagnostics;
    • referral URL, campaign attribution and cookie or similar identifiers; and
    • security, authentication, fraud-prevention and audit logs.

    We do not intend to place sensitive health information in advertising pixels, campaign URLs or third-party advertising identifiers.

    3.10 Information from other sources

    We may receive information from a laboratory, wearable provider, coach, clinician, employer-sponsored programme, community partner, referral partner or another person only where you have authorised the sharing, directed the transfer, or the sharing is otherwise permitted by law.

    If someone purchases a Service for you, we may receive limited contact and order information, but we will seek your consent before collecting health information or activating a personal profile.

    4How we collect personal data

    We collect information:

    • directly from you;
    • automatically when you use the Services;
    • from a device, application or provider you connect;
    • from authorised coaches, clinicians, laboratories or programme partners;
    • from cookies and similar technologies; and
    • by generating insights or inferences from information described above.

    Please provide accurate and current information. Incomplete or inaccurate information may affect the relevance of a screening, insight or programme.

    5Why we use personal data

    We may use personal data to:

    • provide, personalise and administer the Services you request;
    • calculate and present a BioAge screening range, archetype or related educational insight;
    • create a baseline and connect information across time;
    • interpret laboratory, wearable and self-reported patterns;
    • generate educational content, coaching support, reminders and programme recommendations;
    • coordinate appointments, laboratory collections, follow-up tests, coaching or partner services;
    • authenticate users, send OTPs and protect accounts;
    • process payments, invoices, cancellations and refunds;
    • provide customer support and respond to requests or grievances;
    • send transactional and programme-related communications;
    • send marketing communications where you have consented or where otherwise permitted, with an option to opt out;
    • operate, troubleshoot, secure, audit and improve the Services;
    • test feature performance, quality and safety;
    • detect fraud, abuse, security incidents or violations of our Terms;
    • conduct de-identified or aggregated analytics and research;
    • develop, validate, share or commercially license aggregated or de-identified research and insights, including with selected life-sciences organisations;
    • comply with legal, tax, regulatory and professional obligations;
    • establish, exercise or defend legal claims; and
    • complete a merger, financing, reorganisation or sale, subject to appropriate protections.

    We process personal data with your consent, to provide a Service you request, to comply with law, for security and fraud prevention, and for other uses permitted under applicable law. Where a separate or additional consent is appropriate — for example, for optional device access, marketing, identifiable research participation or certain images and voice features — we will request it separately.

    For BioAge, other than processing needed to operate the screening and show the requested result, the principal intended uses are Beyond23 research, validation and product improvement. We may contact you for marketing only if you choose that option. We may share identifiable BioAge data with a selected external research, marketing or commercial partner only under a separately presented consent that describes the partner or partner category and purpose. Aggregated or de-identified BioAge insights may be used and shared as described in this Policy.

    For a Beyond23 member or app user, health and programme information is used primarily to deliver the selected assessment, membership or Sprint and for related educational purposes. It is maintained in an access-controlled environment and made available to authorised coaches or programme personnel only to the extent reasonably needed to support the member’s journey. It may also contribute to aggregated or de-identified research and commercial insights under the safeguards described in this Policy.

    6BioAge privacy choices

    BioAge may be offered before account creation. The screen on which BioAge begins will clearly state:

    • whether a name, email or mobile number is required;
    • whether answers are stored if you do not create an account;
    • how long an incomplete or unsaved screening is retained;
    • whether analytics are associated with an identifier; and
    • what information is required to save, share or personalise the result.

    Our operating model is to:

    • permit users to view a basic result without creating an account;
    • store an incomplete anonymous or pseudonymous session for no more than 30 days;
    • obtain express consent before linking BioAge answers to a mobile number, email address or member profile;
    • present separate, unticked choices for (a) receiving Beyond23 marketing and (b) identifiable participation in research or sharing with a named or clearly described external partner;
    • allow research, product improvement and commercial collaboration using aggregated or de-identified BioAge information, with contractual restrictions against re-identification;
    • not disclose an identifiable BioAge result to an employer, insurer, family member, referral partner or other third party without your direction or a legal requirement; and
    • clearly distinguish the public screening result from a later assessment informed by labs, wearables, history and professional input.

    7AI, automated processing and model improvement

    Beyond23 may use rules-based systems, statistical models and artificial intelligence to organise information, identify patterns, generate summaries, personalise content, support coaches and respond to questions.

    AI-supported outputs may be incomplete, inaccurate or inappropriate for your circumstances. Beyond23 does not use a BioAge result or AI output by itself to make decisions that produce legal or similarly significant effects concerning insurance, employment, credit or access to essential services.

    Where third-party AI providers process information for us, we seek to:

    • provide only the information reasonably needed for the requested function;
    • use contractual and technical safeguards appropriate to the information;
    • prohibit independent advertising or sale of the information; and
    • prohibit use of identifiable member health data to train a provider’s general-purpose model unless the member has separately and expressly opted in.

    We may use de-identified or aggregated information to evaluate and improve algorithms, content and Services. We will not publicly release research or analytics that reasonably identifies you. If we wish to use identifiable information for research, a testimonial, publication or model training beyond delivering the Services, we will seek a separate consent where required.

    De-identified information may also be shared, licensed or otherwise made available on commercial terms to research institutions, analytics providers, healthcare or life-sciences organisations in India or internationally. Such information must not be reasonably capable of identifying you, and recipients must not attempt to re-identify an individual or combine the information with other data for that purpose. You will not ordinarily receive payment from these uses unless a separate agreement expressly provides otherwise.

    8When we share personal data

    We may share personal data with the following recipients for the purposes described in this Policy.

    8.1 Service providers

    Providers may support cloud hosting, data storage, analytics, authentication, OTP delivery, email, WhatsApp or SMS messaging, payments, customer support, security, AI processing, application development and other operations. They may process information only for authorised purposes and subject to appropriate contractual obligations.

    8.2 Laboratories, wearables and diagnostic partners

    When you book, connect or authorise a service, we may share the information required to identify you, perform the service, return a result, resolve an issue or coordinate follow-up. These providers may also act as independent data fiduciaries or controllers for parts of their service and may have their own privacy notices.

    8.3 Coaches, clinicians and programme personnel

    Member information is used primarily to deliver the selected assessment, membership or Sprint and provide educational support. We may provide authorised coaches, clinicians and programme personnel access to information reasonably needed to understand your baseline, personalise guidance, monitor progress or support your journey. Access is role-based, limited to the relevant member relationship and provided through approved systems.

    8.4 Partners selected or directed by you

    We may share information when you ask us to send a report, connect a service or coordinate with a provider. Before a new category of partner receives identifiable health data, we will provide notice or obtain consent where required.

    8.5 Research and analytics collaborators

    We may share, license or commercialise aggregated or de-identified information that is not reasonably capable of identifying an individual with selected research, analytics, healthcare or life-sciences collaborators in India or internationally. Recipients must be contractually prohibited from attempting to re-identify individuals or using the information outside the agreed purpose. Identifiable research or partner sharing will occur only with an appropriate legal basis, a separate consent where required, governance review and safeguards.

    8.6 Corporate transactions

    Information may be disclosed as part of due diligence, financing, restructuring, acquisition, merger or transfer of some or all of our business. Recipients will be required to protect the information and use it consistently with applicable law and this Policy until users are notified of any material change.

    8.7 Legal, safety and rights protection

    We may disclose information where reasonably necessary to comply with law or legal process, respond to a lawful request, prevent fraud or serious harm, investigate security incidents, enforce our agreements or protect the rights and safety of users, Beyond23 or others.

    Beyond23 does not sell or rent identifiable personal or health data. This restriction does not prevent the permitted commercial use of aggregated or de-identified information described above. If our business model changes in a way that would involve identifiable data or a materially different use, we will update this Policy and seek fresh consent where required.

    9Third-party services and links

    Third-party laboratories, wearables, app stores, payment providers, messaging platforms, health-record systems, websites and services have their own terms and privacy practices. Beyond23 is not responsible for a third party’s independent processing. Review the third party’s privacy notice and permissions before connecting or using it.

    If you disconnect a third-party integration, information already held by that third party remains subject to its policies.

    10Cookies and similar technologies

    We may use:

    • essential cookies needed for security, authentication and core functions;
    • preference cookies that remember choices;
    • analytics cookies that help us understand performance and usage; and
    • marketing cookies, only where enabled and permitted.

    Where required, non-essential cookies will not be activated until you make a choice. You can change cookie preferences through your browser settings or any cookie controls we make available. Blocking some cookies may affect functionality.

    We maintain a cookie inventory identifying each cookie, provider, purpose and duration. Health answers, laboratory values and identifiable health inferences are not sent to advertising pixels or embedded in URLs.

    11Communications

    We may send service messages needed to verify an account, deliver a result, manage a purchase, provide a programme, notify you of security or policy changes, or respond to you. These are not marketing messages.

    With your consent or as otherwise permitted, we may send updates, research, offers or invitations by email, SMS, WhatsApp or push notification. You can opt out of marketing through the message, account settings or by contacting us. Opting out of marketing does not stop essential service communications.

    WhatsApp and similar platforms process information under their own terms. Do not use an unsecured messaging channel for urgent or highly sensitive information unless the feature specifically supports it.

    12Children and family accounts

    The public BioAge screening, memberships and personal Beyond23 accounts are intended for individuals aged 18 or older unless a specific service clearly states otherwise.

    Do not create an account for a child or submit a child’s health information without a Beyond23 service expressly designed for minors and the verifiable consent of a parent or lawful guardian. If we learn that we collected a child’s personal data contrary to this requirement, we will take reasonable steps to delete or restrict it.

    Family or caregiver access, if introduced, will require a separate authorised profile or sharing mechanism. Sharing credentials is not an acceptable substitute.

    13Data retention

    We retain personal data only as long as reasonably necessary for the purposes described, including providing the Services, maintaining continuity, meeting legal or professional obligations, resolving disputes, preventing fraud and enforcing agreements.

    Retention depends on the category and context. Our retention schedule covers at least:

    • incomplete and unsaved BioAge sessions: 30 days;
    • source photographs, video and voice used for digital-biomarker analysis: automatically deleted from active processing systems immediately after the requested analysis and report generation, with the same rule applied to any temporary processor copy;
    • identifiable waitlist and enquiry information: 24 months after the last meaningful interaction, or until withdrawal;
    • active account and programme information: while the account or programme is active;
    • health, laboratory and coaching records after account closure: for the period required by the relevant service, professional and legal obligations;
    • support and grievance records: 3 years after closure;
    • financial and transaction records: for the period required by tax, accounting and fraud-prevention laws;
    • security and authentication logs: for the period required for security monitoring and audit; and
    • encrypted backups: rotating deletion within 90 days, subject to legal holds.

    When retention is no longer necessary, we will delete, anonymise or securely isolate the information. Deletion from active systems may not immediately remove information from encrypted backups, legal archives or records that another independent provider must retain.

    14Security

    We use reasonable technical, organisational and physical safeguards appropriate to the nature of the information. Measures may include encryption in transit and at rest, access controls, multi-factor authentication, audit logging, environment separation, secure development practices, vulnerability management, vendor diligence, workforce confidentiality obligations and incident-response procedures.

    No system is completely secure. You are responsible for protecting your device, OTPs and account credentials and for notifying us promptly of suspected unauthorised access.

    If a personal data breach occurs, we will investigate, mitigate and provide notifications to affected individuals and authorities where required by applicable law.

    15International processing and transfers

    Beyond23 and its providers may process information in India and in other countries where our infrastructure or providers operate. Those countries may have different privacy laws.

    Where personal data is transferred outside India, we will take measures required by applicable law, which may include contractual safeguards, security reviews and compliance with restrictions or conditions notified by the Government of India.

    16Your rights and choices

    Subject to applicable law and appropriate identity verification, you may request:

    • a summary of personal data being processed and relevant processing information;
    • correction, completion or updating of inaccurate or incomplete information;
    • deletion or erasure of personal data that is no longer required or must be erased;
    • withdrawal of consent;
    • disconnection of an integration or revocation of device permissions;
    • a copy or export of certain information where available;
    • opt-out from marketing;
    • grievance redressal; and
    • nomination of another individual to exercise applicable rights in the event of death or incapacity, where provided by law and supported by the Service.

    To submit a request, contact privacy@beyond23.life. We may request information needed to verify your identity and protect your account.

    Withdrawal of consent does not affect processing already lawfully completed. It may prevent us from providing a feature that depends on the information. We may retain information where required by law, professional obligations, fraud prevention, security, dispute resolution or legal claims.

    If we deny or limit a request, we will explain the reason where required.

    17Grievances and complaints

    Please first contact our Grievance Officer at grievance@beyond23.life, TECHVITA LABS PRIVATE LIMITED, Ahmedabad, Gujarat, India.

    We will acknowledge and address grievances within the period required by applicable law and aim to provide a substantive response within 30 days. When available and applicable, you may also lodge a complaint with the Data Protection Board of India after using Beyond23’s grievance process. Nothing in this Policy limits rights available under applicable consumer, privacy or other law.

    18Changes to this Policy

    We may update this Policy to reflect changes in law, technology, providers or Services. We will update the “last updated” date and provide prominent or direct notice of a material change where appropriate. If a change requires fresh consent, we will request it before applying the new use to your personal data.

    19Contact us

    For privacy questions or requests:

    • TECHVITA LABS PRIVATE LIMITED (CIN: U72100GJ2024PTC150525)
    • Ahmedabad, Gujarat, India
    • Privacy: privacy@beyond23.life
    • Support: support@beyond23.life
    Questions about this document? Write to legal@beyond23.life. You can also read our Terms of Service.