Last updated July 19, 2026
Privacy Policy
This policy explains how Eisen Labs LLC handles information when you use Protocol One in the United States.
Information we handle
Our separate Consumer Health Data Privacy Policy gives the required categories, sources, purposes, sharing details, and consumer-health-data rights.
- Account and contact information, including email address and authentication records. If you choose Google sign-in, Google provides Supabase the basic identity information you authorize, such as your verified email address and name, to create or access your Protocol One account.
- Health and wellness records you choose to enter or upload, including protocols, administrations, symptoms, measurements, laboratory results, and documents.
- Subscription and entitlement status. Payment-card details are handled by the applicable billing provider, not stored by Protocol One.
- Security, diagnostic, and consent-respecting product analytics that exclude health-record content and free text.
Why we use it
We use information to provide and secure your private record, synchronize devices, validate subscriptions, respond to support requests, improve reliability with your consent, and comply with legal obligations. AI features process only the records or lab PDF you select with per-request consent to extract reviewable rows, organize information, or draft clinician questions. Extracted rows are not saved as lab records until you confirm them. These features do not diagnose, prescribe, or change treatment records.
Sharing and processors
We do not sell health information or use it for advertising. Service providers may process limited information for hosting, authentication, storage, billing, app delivery, error tracking, notifications, and AI generation under contractual restrictions. Current provider categories include Supabase, Vercel and its AI Gateway, Stripe, Apple, Google, Expo, Sentry, APNs, and FCM, as applicable to the feature and platform you use.
Retention and deletion
You can permanently delete your account from account deletion. Product health and wellness records are deleted with the account; deletion processing is targeted within 30 days. Limited billing, fraud-prevention, security, and audit records may be retained when required by law or legitimate security obligations and are isolated from product use. Backups age out under the backup retention schedule.
Your choices
You may export your information, correct or delete it, withdraw optional analytics consent, and disconnect health-platform integrations. Contact us to exercise a privacy right or appeal a response. We may verify your identity before acting on a request.
Security and children
We use access controls, encryption in transit and at rest, row-level authorization, restricted privileged access, monitoring, and incident-response procedures. No system is risk-free. Protocol One is not intended for anyone under 18.
Contact
Eisen Labs LLC13864 Heron's Landing Way Unit 1, Jacksonville, FL 32224
privacy@eisenlabs.io