One L1fe is operated by One L1fe, Nørrebro Vænge 2, 2200 Copenhagen, Denmark. We are the data controller for the personal data described in this policy.
Questions or requests: privacy@one-l1fe.com
You give us:
| Category | Examples |
|---|---|
| Account | Name, email address, password (stored hashed), settings |
| Profile | Age or date of birth, sex, height, weight, time zone |
| Goals and context | Training goals, sport, target events, sleep and lifestyle context |
| Coach conversations | Messages you send the AI coach and its replies |
| Support | Emails you send us and our replies |
| Optional | Phone number, if you choose to give it |
You connect, nothing is imported unless you authorise it, and you can disconnect at any time:
| Source | Data imported |
|---|---|
| Wearables and fitness platforms | Heart rate, HRV, resting heart rate, sleep, activity and workouts, training load, VO2 max estimates, respiratory rate, blood oxygen, steps |
| Laboratory and biomarker testing | Blood panel results, reference ranges, sample dates |
| Other health testing you choose to add | Results and derived metrics from the provider |
We collect automatically: IP address, device type, operating system, app version, features used, timestamps, errors and crash reports. Website cookies are covered in section 8.
Most of what makes One L1fe useful is data about your body. Under Article 9 GDPR, health data is a special category and gets stronger protection.
Our legal basis is your explicit consent, under Article 9(2)(a) GDPR. In practice:
Your health data is stored and processed on servers we operate through our cloud provider. It is not kept only on your device. Server side processing is what lets the coach combine sources, track change over time, and generate personalised insight. Some processing happens outside the EU/EEA, as described in section 7.
| Purpose | Legal basis |
|---|---|
| Create and run your account | Contract, Art. 6(1)(b) |
| Import, store and display your health data; generate insights and coaching | Explicit consent, Art. 6(1)(a) and 9(2)(a) |
| Provide support | Contract, Art. 6(1)(b) |
| Security, fraud prevention, fault diagnosis, aggregated product analytics | Legitimate interests, Art. 6(1)(f) |
| Marketing emails and product updates | Consent, Art. 6(1)(a), and section 10 of the Danish Marketing Practices Act |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object (section 9).
We do not use your health data to train general purpose AI models, and our AI providers are contractually barred from doing so.
Any provider listed here processes data on our behalf under an Article 28 data processing agreement. We do not sell your data and do not share it with advertisers.
We may also disclose data to public authorities where legally required, or in a merger or acquisition, in which case we notify you in advance so you can delete your account first if you prefer.
The AI coach. When you use it, you are interacting with an AI system, not a person. To answer, we send your question and the metrics needed for it to our model provider, the minimum for that request, not your full record. Our contract will require that your data is used only to respond to you, is not used for training, and is retained by the provider only briefly or not at all. We keep your conversation history so the coach has context and you can look back; you can delete it at any time. We do not make solely automated decisions with legal or similarly significant effects under Article 22, the coach suggests, you decide.
Some providers may process data outside the EU/EEA, including in the United States. Where they do, we rely on an adequacy decision (including the EU/US Data Privacy Framework where applicable) or on the European Commission's Standard Contractual Clauses with appropriate safeguards. Email us for a copy of the safeguards for any specific transfer.
One L1fe uses only cookies and similar technology strictly necessary for it to work, such as keeping you signed in. We use no advertising cookies, tracking pixels or third party analytics, so there is no consent banner.
You have the right to access your data, have it corrected or deleted, restrict or object to processing, receive it in a portable format, and withdraw consent at any time. You can object to direct marketing at any time with no reason given, and we will stop.
Email privacy@one-l1fe.com. We respond within one month, and will tell you within that month if a complex request needs longer. It is free. We may need to verify your identity first, particularly for health data. A full export will be available from your account settings.
We use encryption in transit and at rest, access controls limiting staff access to what a task requires, multi factor authentication on administrative systems, access logging, and tested backups.
No system is perfectly secure. If a breach occurs we will notify Datatilsynet within 72 hours where Article 33 requires it, and notify you directly without undue delay where the breach is likely to be a high risk to you.
| Data | Retention |
|---|---|
| Account, profile and health data | While your account is open; deleted within 30 days of account deletion or withdrawal of consent |
| Coach conversation history | Until you delete it, or 30 days after account deletion |
| Waiting list emails | Until you unsubscribe, or 18 months from signup if we have not launched |
| Security and access logs | 12 months |
| Support correspondence | 24 months after the case closes |
Genuinely anonymised aggregate statistics, which cannot be linked back to you, may be kept indefinitely.
We may update this policy as the product develops; the date at the top shows the current version. For material changes, a new category of data, a new purpose, a new provider handling health data, or a change of controller, we notify you by email or in the app before it takes effect. Where a change needs your consent, we ask for it separately rather than treating continued use as agreement.