Privacy Policy

Last updated: 19 September 2026

This Privacy Policy governs your use of adaging.io (the "Website") and describes what data we collect, how it is stored, how it may be used, with whom it may be shared, and the choices you have about those uses and disclosures. Please read it carefully.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

"EEA" means the Member States of the European Union together with the other states of the European Economic Area.

"Process", in relation to personal data, includes to collect, store, use, and disclose to others.

For the meaning of capitalised terms not defined here, see our Terms of Use.

1. Personal data controller

The controller of your personal data is:

Xora Technologies S.L. Betera, Valencia, 46117, Spain. NIF: B22975635. Contact for all privacy matters: support@adaging.io

We are established in Spain, and our lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), www.aepd.es.

2. What categories of personal data do we collect?

We collect data you make available to us voluntarily, and data collected automatically when you use the Website.

2.1 Data you give us

Account data. Your email address and, where you set one, your password (stored in hashed form). Optionally your name or the name you choose to be called.

Questionnaire and profile answers. Your age or age range, sex where you provide it, your self-reported activity level, goals, and other answers you give in the intake questionnaire and in later check-ins.

Health-related answers. Parts of the questionnaire and the check-ins ask about matters that qualify as data concerning health under Article 9 GDPR: for example whether you have experienced falls, dizziness, chest pain on exertion, joint or back pain, balance difficulties, recent surgery, or conditions that affect movement, and how you rate your energy, sleep, and physical capability. See Section 5.

Your submissions. Notes, journal entries, feedback, support messages, and messages you send to our AI assistants. This includes the entries you save in the mood journal: the level you pick, the word and the reason you choose, and any free text you add to them.

Communications. The content of emails and support requests you send us.

2.2 Data we collect automatically

Data about how you found us. Referring URL, campaign and ad identifiers, and landing page.

Cookies and similar technologies. As described in our Cookie Policy, we use cookies and similar technologies to distinguish you from other users, keep you signed in, understand how the Website is used, and measure our advertising. The tools behind this are the Meta Pixel, Contentsquare and Mixpanel; the Cookie Policy names what each of them stores. You can control cookies through your browser settings, as described there.

Browser and device data. Data from or about the device you use to access the Website: IP address, approximate location derived from IP address, language settings, time zone, device type and model, screen size, operating system, browser, and internet service provider.

Transaction data. When you pay, you provide financial account details directly to our third-party payment processor. We do not collect or store full payment card numbers. We receive and store data about the transaction: date, time, amount, currency, payment method type, the last digits and brand of the card, subscription status, and refund and chargeback status.

Usage data. How you interact with the Website: pages and features you open, sessions started and completed, practices marked complete, check-ins submitted, time spent, and similar events.

2.3 What we do not collect

We do not collect data from wearables, fitness trackers, or medical devices. We do not collect video or audio of you. We do not request or store government identifiers. We do not use mobile advertising identifiers such as IDFA or AAID, because the Website is a web product.

Nothing in your profile, your answers, or your submissions is made public. There is no public profile and no social feed on the Website.

3. For what purposes do we process your personal data?

3.1 To provide the service. To create and maintain your account, authenticate you, give you access to the program, generate and configure your plan from your questionnaire answers, record your progress, calculate your progress indicator, and prevent or resolve errors and technical issues.

3.2 To keep you safe. To apply our health screening rules, to decide whether we can offer you the program at all, and to select a version of the program appropriate to your answers. See Sections 5 and 6.

3.3 To process your payments. To take payment, manage renewals and cancellations, issue refunds, handle chargebacks, and meet accounting and tax obligations.

3.4 To provide customer support. To answer your questions and send you service messages about security, payment transactions, subscription status, legal notices, and other Website-related matters.

3.5 To research and analyse use of the Website. To understand how the product is used, run surveys and tests, audit and troubleshoot, and maintain, improve, and develop the Website and new features. For this we use product analytics (Mixpanel) and session analytics (Contentsquare). Text on the page is masked before session analytics leaves your browser, so what you type or choose is not readable there.

3.6 To communicate with you about your use of the Website. For example reminders and progress messages within the Website and by email, which you can turn off.

3.7 To send you marketing communications. Where you have consented or where permitted by law, to tell you about our products, features, offers, and content. You can withdraw consent or unsubscribe at any time using the link in any marketing email or by writing to support@adaging.io.

3.8 To measure and improve our advertising. To learn which of our ads bring people who start the quiz and subscribe, to report those outcomes back to the advertising platform, and to reach people who are likely to be interested in the program. For this we use the Meta Pixel and its server-side Conversions API. The legitimate interest we rely on here is our interest in promoting the Website in a measured and targeted way. How to limit this is in Section 8.2 and in our Cookie Policy.

3.9 To enforce our Terms and prevent fraud and abuse. To detect, prevent, investigate, and resolve fraud, payment abuse, unauthorised access, and other misuse, and to establish, exercise, or defend legal claims.

3.10 To comply with legal obligations. Including accounting, tax, and consumer law obligations, and responding to lawful requests from authorities.

4. Legal basis for processing (EEA and UK)

This section applies to users in the EEA and the United Kingdom.

Performance of a contract with you (Art. 6(1)(b)): providing the service, managing your account, generating and delivering your plan, processing payments, and providing customer support.

Your consent (Art. 6(1)(a)): marketing emails (Section 3.7). You can withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

Your explicit consent (Art. 9(2)(a)): all processing of health-related answers. See Section 5.

Our legitimate interests (Art. 6(1)(f)):

We balance these interests against your rights and freedoms, and you may object to processing based on legitimate interests as described in Section 12.

Compliance with a legal obligation (Art. 6(1)(c)): accounting and tax records, responses to lawful requests from authorities, and retention required by law.

5. Health-related data

This section is important because our product asks about your body.

5.1 What we treat as health data. Any answer that reveals something about your physical or mental health, including screening answers about falls, dizziness, chest pain, balance, pain, recent surgery, and conditions affecting movement, your self-assessments of energy, sleep, and capability, and the entries you save in the mood journal, including any free text you write in them.

5.2 Legal basis. We process this data on the basis of your explicit consent under Article 9(2)(a) GDPR. The first screen of the quiz tells you, with a link to this Policy, that by going further you agree to it, and every health question that follows is one you choose to answer: you can stop at any question, and nothing you have not answered is collected. Answering the health questions is how you give this consent. We rely on it for these answers only, and Section 5.3 says what we do with them.

The mood journal asks for its own consent, in the journal itself, before any entry leaves your device. Until you give it, your entries stay in the browser or app you wrote them in and nothing about them is sent to us. You can withdraw from the same place at any time, which stops anything further being sent; entries already stored stay until you ask us to remove them.

5.3 What we use it for. Only for three things: deciding whether we can safely offer you the program, configuring which version of the program and which practices you receive, and showing your own record back to you. Your progress and your mood journal are stored on our servers so that they follow your account: what you write in one browser or on one phone is there when you sign in somewhere else. We do not use health-related answers to target advertising, and we do not use them to build marketing segments.

5.4 Sharing. We do not sell health-related data and we do not share it with advertising partners, data brokers, insurers, or employers. It is accessible to our hosting and database providers acting as processors under contract, and to a small number of our own personnel who need it to operate and support the product. Our analytics providers do not receive it either: the events we send to Mixpanel carry no health answers, and text is masked before session analytics leaves your browser (Section 8.2).

5.5 Withdrawing consent. You can withdraw consent at any time, in the same place you gave it: in the app, open Profile and delete your account. Deletion completes after a 30-day period in which you can change your mind; your answers are removed with the account. You can also withdraw by writing to support@adaging.io, and before you have an account that is the way to do it. Because the program cannot be configured or delivered safely without these answers, withdrawal means we can no longer provide the service, and it will be treated as a cancellation. Withdrawal does not affect processing carried out before you withdrew.

5.6 Aggregated analysis. We may analyse health-related answers in aggregated or de-identified form to improve the program. Aggregated and de-identified data does not identify you and is not personal data.

6. Automated processing and profiling

We use automated logic in two places:

Screening. Your answers to screening questions are checked automatically against fixed rules. If they indicate a risk we are not equipped to handle, we do not offer you the program and we tell you to speak to a healthcare professional instead.

Plan configuration. Your answers determine which program version, starting level, and progression you receive, and how your progress indicator is calculated.

This processing has no legal effect on you and does not significantly affect you in the sense of Article 22 GDPR: the only outcome is which version of an optional wellness product you are offered. It is not a medical assessment and it is not a diagnosis. If you disagree with the outcome, you can contact us at support@adaging.io to have it reviewed by a person.

7. AI assistants

The Website includes text-based AI assistants.

Messages you send to an assistant, together with the context needed to answer (such as your current program stage and recent check-ins), are sent to third-party AI model providers acting as our processors under contract. Those providers process the data only to return a response to us and on our instructions.

We do not permit our AI providers to use your conversations to train their models.

We store conversations so the assistant can keep context, and so we can debug, secure, and improve the product. Our personnel may review conversations for those purposes.

Do not enter payment card details, government identifiers, or personal data about other people into the assistants.

8. With whom do we share your personal data?

We share personal data with third parties that help us operate, provide, improve, integrate, support, and market the Website. We do not sell your personal data.

8.1 Service providers (processors). Acting on our instructions and under written contracts:

A current list of the specific providers we use is available on request at support@adaging.io.

8.2 Advertising and analytics partners. Meta receives online identifiers (the _fbp cookie and the identifier of the ad you clicked), the pages you open, and the steps you reach: quiz started, email entered, checkout opened, subscription bought, with the amount. Once you have entered your email, a hashed form of it is included so that a purchase can be matched to the ad you clicked. Mixpanel receives usage events and a short, fixed list of quiz answers that are not about your health: your sex, age band and the time you have available per day, and, in the quiz for men, your event date and how you heard about us. Contentsquare receives session analytics: pages, clicks, scrolling and the layout of the page, with all text masked before it leaves your browser. None of them receives your health-related answers. You can limit Meta's use of this data in your Meta ad settings and block all three in your browser, as described in our Cookie Policy.

8.3 Professional advisers and authorities. Our accountants, auditors, and lawyers, and courts, law enforcement, regulators, and other public authorities where we are legally required to respond or where disclosure is necessary to protect our rights, your safety, or the safety of others.

8.4 Corporate transactions. If we buy or sell assets or business lines, customer data may be one of the transferred assets. We may also share data with an affiliated entity, or transfer it in the course of a merger, consolidation, divestiture, asset sale, or insolvency. We will tell you before your data becomes subject to a different privacy policy.

9. International data transfers

We may transfer personal data to countries other than the one in which it was collected in order to provide the Website. Where those countries do not offer an equivalent level of protection, we apply safeguards.

For transfers of personal data from the EEA or the UK to countries without an adequacy decision, we rely on the Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum where relevant, and we carry out transfer risk assessments and apply supplementary measures where needed. Where a recipient in the United States is certified under the EU-US Data Privacy Framework, we may rely on the European Commission's adequacy decision of 10 July 2023.

We no longer rely on the EU-US Privacy Shield, which was invalidated in 2020.

You can request a copy of the safeguards we use at support@adaging.io.

10. Data retention

We keep personal data for as long as needed for the purposes set out in this Privacy Policy, and then delete or anonymise it, unless a longer period is required or permitted by law.

In practice:

We also have obligations to retain data so that transactions can be processed, settled, refunded, or charged back, to help identify fraud, and to comply with anti-money-laundering and other rules that apply to us and to our payment providers. Because of this, some data is retained even after you delete your account.

11. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, hashed passwords, access controls limiting access to personnel who need it, logging, and contractual security commitments from our processors.

No system is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

12. Your privacy rights

You have the following rights in relation to your personal data:

Access. Obtain confirmation of whether we process your data and a copy of it.

Rectification. Correct inaccurate data and complete incomplete data. You can edit much of this yourself in your profile.

Erasure. Ask us to delete your personal data. You can request deletion from your profile or by writing to us. Where we are legally required to keep some data, we will complete your request once those obligations end.

Restriction and objection. Ask us to stop or limit certain processing, and object to processing based on our legitimate interests. You can object to direct marketing at any time and we will stop.

Withdrawal of consent. Withdraw any consent you gave, including explicit consent to processing health-related data, at any time.

Data portability. Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.

Complaint. Lodge a complaint with a supervisory authority, in particular in the EU Member State where you live, work, or where you believe an infringement occurred. In Spain this is the AEPD (www.aepd.es). We would prefer that you contact us first at support@adaging.io so we can try to resolve the matter.

To exercise any of these rights, write to support@adaging.io. We will respond within one month, which may be extended by two further months for complex requests, and we will tell you if we need the extension. We may need to verify your identity before acting. You may use an authorised agent, in which case we will verify the agent's identity, your identity, and their authority.

We will not discriminate against you for exercising these rights.

13. California privacy rights

This section applies to residents of California and describes rights under the California Consumer Privacy Act as amended by the CPRA ("CCPA").

Categories collected. In the past 12 months we have collected the categories of personal information described in Section 2, namely identifiers, customer records, commercial information, internet and network activity, approximate geolocation derived from IP address, and inferences drawn to configure your program. See Section 2 for the sources and Section 3 for the purposes.

Sensitive personal information. Health-related answers are sensitive personal information under the CCPA. We collect and use them only to provide the service you requested and for safety screening, which are purposes permitted without a right to limit under the CCPA. We do not use them to infer characteristics about you for any other purpose.

No sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising within the meaning of the CCPA. Where advertising cookies are used with your consent, we treat the relevant opt-out signals as described in Section 15.

Your rights. Subject to limits in the law, you have the right to know what personal information we collect, use, disclose, and retain; to access specific pieces and categories; to delete personal information; to correct inaccurate personal information; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

To make a request, contact support@adaging.io. We will verify your request and respond as required by law. You may use an authorised agent.

Shine the Light. California residents may ask once a year what personal information we share with third parties for those third parties' direct marketing purposes. Send an email to support@adaging.io with the subject line "Request for California Shine the Light Privacy Information", and include your state of residence and your email address in the message.

14. Age limitation

The Website is intended for adults. We do not knowingly process personal data of anyone under 18 years of age. If you believe someone under 18 has provided us with personal data, contact us at support@adaging.io and we will delete it.

15. Do Not Track and Global Privacy Control

The Website does not respond to browser "Do Not Track" signals, because no common standard for them has been adopted. We do recognise the Global Privacy Control (GPC) signal and treat it as a valid opt-out of sale and sharing where the law requires it. To find out whether the third-party services we use honour these signals, please review their own privacy policies.

16. Changes to this Privacy Policy

We may modify this Privacy Policy at any time. If we make material changes, we will notify you through the Website or by other available means and give you an opportunity to review the revised version before it takes effect. By continuing to access or use the Website after the changes take effect, you agree to the revised Privacy Policy. Where a change requires your consent under applicable law, we will ask for it.

17. Contact us

If you have any question or concern about this Privacy Policy or about how we collect, use, or store your data:

Xora Technologies S.L. Betera, Valencia, 46117, Spain. NIF: B22975635. support@adaging.io

Supervisory authority: Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es