Privacy Policy
Effective date: March 1, 2026 · Last updated: August 13, 2026
Contents
- Introduction and scope
- Information we collect
- How we handle health data
- Apple HealthKit — our specific commitments
- How we use information
- How we use AI
- How we share information
- De-identified and aggregated data
- Cookies, SDKs, and analytics
- Data retention
- Security
- Your choices and rights
- Consumer health data (Washington, Nevada, Connecticut, and similar laws)
- Biometric data
- Children's privacy
- International data transfers
- HIPAA and medical notice
- Changes to this policy
- How to contact us
1. Introduction and scope
This Privacy Policy explains how ZiroLabs LLC, a Texas limited liability company doing business as ZiroLabs AI ("ZiroLabs," "we," "us," or "our"), collects, uses, shares, and protects information in connection with Cen10 (the "app" or the "Services"), our consumer iOS application available at cen10.ai. Cen10 is a product of ZiroLabs LLC; it is not a separate legal entity, and ZiroLabs LLC is the entity responsible for Cen10 and for this policy.
Cen10 reads the health information you choose to connect and computes scores across 14 body systems along with longevity indicators, and it offers an AI "concierge" that explains your results and suggests actions. Importantly, Cen10 works with data you already have:
- We do not draw blood, order or perform lab tests, or operate a laboratory.
- We do not employ clinicians or provide telehealth or any clinical service.
- We analyze the data you connect or enter — we do not generate diagnostic testing of our own.
This Policy applies to the Cen10 app and to the ZiroLabs websites, communications, and support channels that link to it. It does not apply to third-party products or services you may connect to Cen10 (such as Apple Health, Apple Watch, or a lab portal), each of which is governed by its own privacy terms.
By using Cen10, you agree to this Policy together with the Cen10 Terms of Use. If you do not agree, please do not use the Services.
Who can use Cen10. Cen10 is intended only for individuals who are 18 years of age or older. See Section 15.
2. Information we collect
We collect only what we need to provide the Services. The categories below describe what we may collect, depending on the features you use.
2.1 Account information
When you create an account or contact us, we may collect information such as your name, email address, authentication credentials (including sign-in through Apple), and your communications with our support team. Depending on how the Services are offered, we may also collect limited billing or subscription status information from our payment or app-store processor (we do not receive your full payment card number).
2.2 Health data you connect
This is the core of what Cen10 does. With your permission, Cen10 may access and process:
- Apple Health / HealthKit data — for example, activity, heart rate, heart rate variability, sleep, respiratory metrics, and other categories you authorize.
- Wearable and device data — for example, data from Apple Watch or other wearables and connected sources you link.
- Lab results and biomarkers — values you enter or import (for example, cholesterol panels, metabolic markers, and other clinical measurements).
- Family history — health information about relatives that you choose to record.
- Notes and free-text entries — observations, symptoms, goals, or context you type in, including anything you share with the AI concierge.
From this data, Cen10 computes derived outputs such as body-system scores, biological age, and Life's Essential 8 indicators. These derived outputs are themselves health-related information and are treated with the same care.
You choose what to connect and enter, and you can disconnect a source or delete entries at any time (see Section 12).
2.3 Product-usage and interaction data
To understand how Cen10 is used and to keep improving it, we collect first-party product-usage and interaction data by default. This includes events such as when you open the app, which screens and features you view, your plan or subscription tier, paywall views, and when you run a brief or ask Cen10 AI, together with basic technical data such as device model, operating-system version, app version, and crash and diagnostic logs. This information is tied to a random, pseudonymous identifier, not to your name or email, and it never includes your health data, which stays on your device. This is our own product analytics, not cross-app tracking; we do not use it for advertising and we never sell it. You can turn it off at any time in Settings.
2.4 Information from third-party sources you connect
When you link a third-party source (such as Apple Health, a wearable account, or a lab portal), we receive the data and metadata you authorize that source to share. What we receive depends on the source and the permissions you grant, and is subject to that source's own privacy terms.
3. How we handle health data
Cen10 is built to be on-device-first and data-minimizing.
- On-device processing and storage. Your connected health data is processed and stored on your device and is not uploaded to our servers. Scores and indicators are computed locally. The only things we hold server-side are your account identity, your subscription, and — unless you opt out — a coarse, aggregate-only demographic slice (your sex and age range) for anonymous product analytics; never your health metrics, labs, or records.
- Data minimization. We collect and transmit the least data necessary to deliver the feature you requested. We avoid sending health data off the device unless a feature you use requires it.
- Encryption. When health data must leave your device for a requested feature (for example, to generate an AI explanation), it is encrypted in transit and processed in isolated environments by contracted processors that act only on our behalf. Data at rest in those environments is protected using appropriate technical safeguards (see Section 11).
- Purpose limitation. Health data is used to provide the health features you request — not for advertising, marketing, data-mining, or model training on identifiable data.
4. Apple HealthKit — our specific commitments
If you connect Apple Health, Cen10's use of HealthKit data is governed by Apple's requirements and by these commitments. We:
- Use HealthKit data only to provide the health and fitness features you request within Cen10;
- Never use HealthKit data for advertising, marketing, or data-mining, or for any use-based data mining;
- Never sell HealthKit data to anyone;
- Never disclose HealthKit data to third parties without your permission, and never provide it to third parties for advertising or similar services;
- Do not use HealthKit data to train AI or machine-learning models.
You control which HealthKit categories Cen10 may read through iOS permission settings, and you can change or revoke those permissions at any time in the Health app or iOS Settings.
5. How we use information
We use the information described above to:
- Provide, operate, and maintain the app and its core features, including computing body-system scores, biological age, Life's Essential 8, and related indicators;
- Generate AI explanations and suggested actions through the concierge when you request them (see Section 6);
- Personalize your experience and remember your preferences and connected sources;
- Provide customer support and respond to your requests;
- Maintain security, prevent fraud and abuse, and debug and improve reliability;
- Improve our own Services (for example, fixing errors and refining our scoring logic), using de-identified or aggregated data where feasible (see Section 8);
- Comply with legal obligations and enforce our terms.
Legal bases (EEA/UK). Where the GDPR or UK GDPR applies, we rely on: your consent (including your explicit consent for processing health data, which is a special category of personal data); performance of a contract with you; our legitimate interests in operating and improving the Services in a privacy-protective way (balanced against your rights); and compliance with legal obligations. You may withdraw consent at any time (see Section 12).
6. How we use AI
The Cen10 concierge uses artificial intelligence to explain your results and suggest possible actions. You should understand the following:
- Processors under contract. When a feature requires AI processing that cannot be performed on-device, relevant data is sent — encrypted in transit — to third-party AI providers that act only on ZiroLabs' behalf under contract, in isolated environments.
- No training on your identifiable data. ZiroLabs does not use your identifiable health data to train AI or machine-learning models, and our contracted AI providers are contractually prohibited from using your data to train or improve their own models. Your data is used only to produce the output you requested.
- Outputs are informational only. AI outputs may be inaccurate, incomplete, or out of date. They are provided for information and education only and are not medical advice, diagnosis, or treatment. Always consult a qualified professional before acting on anything the app tells you, and never disregard professional advice because of something you read in Cen10.
7. How we share information
We do not sell your personal information. We share information only in the limited ways described here.
7.1 Service providers and subprocessors
We share information with vendors that perform services for us — such as cloud hosting, isolated AI processing, analytics, crash reporting, and customer support — strictly on our behalf and under contracts that limit their use of the data to providing those services. Current categories of subprocessors include cloud hosting, isolated AI processing, analytics, and crash reporting; a current list is available on request.
7.2 Legal and safety
We may disclose information if we reasonably believe it is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of our users, ZiroLabs, or the public.
7.3 Business transfer
If ZiroLabs is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will require that any successor honor the commitments in this Policy, and we will notify you of any material change in how your information is handled.
7.4 With your direction
We share information at your request or with your direction — for example, when you choose to export your data or share a result.
7.5 What we do not do
- No sale of personal information. We do not sell your personal information for money or other valuable consideration.
- No sale or sharing of de-identified health data. We do not sell, license, or share de-identified or aggregated health data to third parties for their own purposes.
- No cross-context behavioral advertising with health data. We do not use your health data — including HealthKit data or derived scores — for targeted or cross-context behavioral advertising.
8. De-identified and aggregated data
We may create de-identified or aggregated data from information we hold. When we do, we take reasonable measures to ensure the data cannot reasonably be used to re-identify you, and we maintain and use it only in de-identified or aggregated form.
We use such data only to operate and improve our own Services — for example, to evaluate and refine our scoring models and app performance. We do not sell it and do not share it with third parties for their own purposes.
9. Cookies, SDKs, and analytics
Our app and any related web pages may use limited software development kits (SDKs), cookies, or similar technologies for essential functions, security, and product analytics (for example, understanding which features are used and diagnosing crashes). We do not use these technologies to build advertising profiles from your health data or to serve you targeted ads based on health data. Where required by law, we obtain consent before using non-essential technologies, and you can manage certain preferences through your device or app settings. Current analytics and diagnostic providers are limited to standard app-analytics and crash-reporting tools; a current list is available on request.
Usage-data control. Sharing product-usage data is on by default because it helps us make Cen10 better. You can turn it off at any time in Settings, which stops new product-analytics events from being collected.
Coarse demographics. For analytics only, we associate a coarse demographic slice with your account: your sex and an age range (for example, 30 to 39), not your date of birth. We use it to understand product usage across groups; it is never used for advertising and is never sold.
10. Data retention
Because Cen10 is on-device-first, much of your health data remains on your device and is under your control; deleting it there removes it. For information we hold on our systems, we retain it only for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Data sent to AI or other processors for a requested feature is retained only as long as necessary to deliver that feature and then deleted or de-identified in accordance with our contracts. Specific retention periods depend on the type of data and the purpose; contact us for more information.
11. Security
We use administrative, technical, and organizational safeguards designed to protect your information, including encryption in transit, encryption at rest in our processing environments, isolation of AI processing, access controls and least-privilege practices, and ongoing monitoring. On-device data also benefits from your device's own protections (such as your passcode, biometric lock, and iOS security features). No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident. Please help protect your account by keeping your device and credentials secure.
12. Your choices and rights
You have meaningful control over your information.
12.1 Controls available to everyone
- Disconnect sources. You can disconnect Apple Health, a wearable, or any other connected source at any time in the app or in iOS settings. New data from that source will stop flowing.
- Manage permissions. You can change what HealthKit categories Cen10 may read in the iOS Health app or Settings.
- Access, correct, export, delete. You can access and review your data, correct or edit entries, export your data, and delete data or your entire account.
To make a request, use the in-app controls or contact us at legal@cen10.ai. We will verify your request as required by law and respond within the timeframes the law provides. You may authorize an agent to act on your behalf where the law allows.
12.2 U.S. state privacy rights (California and other states)
Depending on where you live (for example, California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws), you may have the right to:
- Know / access the personal information we have collected about you and how we use and disclose it;
- Correct inaccurate personal information;
- Delete personal information;
- Portability — obtain a copy of your data in a portable format;
- Opt out of the sale of personal information, sharing for cross-context behavioral advertising, and certain profiling — note: we do not sell personal information, do not share it for cross-context behavioral advertising, and do not use your health data for such advertising, so there is nothing to opt out of in these respects;
- Limit the use of sensitive personal information — we already limit our use of sensitive information (including health data) to providing the Services you request and related permitted purposes;
- Non-discrimination — we will not discriminate against you for exercising your rights.
California residents may also request information about disclosures for direct-marketing purposes ("Shine the Light"); we do not disclose personal information to third parties for their own direct marketing. Because we do not sell or share personal information as those terms are defined under the CCPA/CPRA, we do not process Global Privacy Control signals as opt-out-of-sale signals, but we honor applicable rights described above.
To exercise these rights, contact us at legal@cen10.ai. If we deny a request, you may appeal by replying to our response or contacting us at the same address; where required, we will explain your right to contact your state attorney general.
12.3 EEA/UK (GDPR) rights
If you are in the EEA, UK, or Switzerland, you have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent at any time (without affecting processing already carried out). Our legal bases are described in Section 5. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). If you wish to contact us about these rights, you can reach us at legal@cen10.ai.
13. Consumer health data (Washington, Nevada, Connecticut, and similar laws)
This section provides additional protections for "consumer health data" under laws such as the Washington My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut Data Privacy Act, and applies to residents those laws protect. Where this section conflicts with another part of this Policy, the more protective terms govern for covered consumers. This section serves as our Consumer Health Data Privacy Policy.
What we collect and why. We collect consumer health data — such as the health information you connect or enter and the scores and indicators Cen10 derives from it — only to provide the Services you request (computing your body-system, longevity, and related insights and offering AI explanations), and for the closely related purposes described in Section 5.
Sources and recipients. We collect consumer health data from you and from the sources you connect (Section 2). We share it only with service providers and subprocessors (processors) that act on our behalf under contract (Section 7.1), and never sell it.
No sale. We do not sell consumer health data, and we do not collect, use, or share it beyond what is necessary to provide the Services or as you direct. We will not sell consumer health data without your valid authorization.
Affirmative consent before sharing. We obtain your affirmative, opt-in consent before collecting or sharing consumer health data beyond what is necessary to provide a product or service you requested, and separate authorization before any sale.
Your rights. If you are a covered consumer, you have the right to:
- Confirm and access whether we are collecting, sharing, or selling your consumer health data, and access that data;
- Withdraw consent to our collection and sharing of your consumer health data;
- Delete your consumer health data (we will also direct our processors to delete it);
- Appeal a decision on your request.
How to submit a request or authorization. Use the in-app controls or contact us at legal@cen10.ai. We will verify your request as required by law, respond within the legal timeframe, and provide an appeal path if we decline. An authorized agent may submit a request with your written permission.
Restricted geofencing. We do not use geofencing to track, collect data from, or send notifications to consumers based on proximity to any health-care facility, consistent with MHMDA.
14. Biometric data
Cen10 works with health metrics (such as heart rate, HRV, sleep, and lab values) to compute wellness and longevity scores. Cen10 does not use biometric identifiers — such as facial-recognition templates, fingerprints, or voiceprints — to identify you.
If we ever introduce a feature that collects or uses biometric identifiers subject to laws like the Illinois Biometric Information Privacy Act (BIPA) or similar state laws, we will provide the required notice, obtain your written consent, and publish our retention and deletion practices before doing so.
15. Children's privacy
Cen10 is intended only for adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, please contact us at legal@cen10.ai and we will delete it.
16. International data transfers
ZiroLabs is based in the United States, and our processors may be located in the United States or other countries. If you access Cen10 from outside the United States, your information may be transferred to, stored in, and processed in the United States and other jurisdictions whose data-protection laws may differ from your own. Where required, we use appropriate safeguards for international transfers — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — and take additional measures as needed. Contact us for more information about these safeguards.
17. HIPAA and medical notice
Not a HIPAA covered entity. ZiroLabs offers Cen10 directly to consumers and is generally not a HIPAA "covered entity" or "business associate." The data you connect to Cen10 is generally not "protected health information" under HIPAA, and this Policy — not HIPAA — governs how we handle it.
Not medical advice; not a medical device. Cen10 provides information and education only. It is not medical advice, diagnosis, or treatment; it is not a medical device; and it does not create a doctor-patient or other professional relationship. Scores, biological age, Life's Essential 8, AI explanations, and suggested actions are informational and may be inaccurate or incomplete. Always seek the advice of a qualified health professional with any questions about your health, and never delay or disregard professional advice because of Cen10. If you think you may have a medical emergency, call 911 or your local emergency number.
18. Changes to this policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and provide notice through the app or by other appropriate means before the changes take effect, where required. Your continued use of Cen10 after an update means you accept the revised Policy.
19. How to contact us
Questions, requests, or concerns about privacy? Reach us at:
- Legal entity: ZiroLabs LLC (doing business as ZiroLabs AI)
- Email: legal@cen10.ai