Institute for Human Optimization

Website Privacy Policy

This policy explains how the Institute for Human Optimization collects, uses, discloses and protects personal information through its websites, digital services and online communications.

Effective: September 4, 2026Last updated: September 4, 2026Applies to Institute for Human Optimization and Longevity Gyms

1. Scope and who we are

This Website Privacy Policy applies to websites and digital services operated by the Institute for Human Optimization (“IFHO,” “we,” “us” or “our”), including the Longevity Gyms website and related landing pages, forms, scheduling experiences and electronic communications that link to this policy.

Longevity Gyms is operated by the Institute for Human Optimization. This policy does not replace our HIPAA Notice of Privacy Practices, which governs protected health information (“PHI”) when IFHO acts as a HIPAA covered health care provider.

Medical emergencies: Our websites, email, text messages and web forms are not monitored for emergencies. Call 911 or go to the nearest emergency department if you believe you are experiencing a medical emergency.

2. Information we collect

Information you provide

  • Contact and identity information, such as your name, email address, telephone number, mailing address and date of birth.
  • Appointment and service information, including preferred services, scheduling details, goals, questions and communications with us.
  • Account, intake and health-related information you submit through an authorized patient, booking or clinical workflow.
  • Transaction information, such as purchase details and limited payment-related information. Payment card data may be collected directly by our payment processor rather than stored by us.
  • Marketing preferences, survey responses, testimonials, event registrations and other information you choose to provide.

Information collected automatically

  • Device, browser and network information, including IP address, device identifiers, operating system, browser type and approximate location inferred from IP address.
  • Usage information, including pages viewed, links selected, referring pages, dates and times of visits, and interactions with emails or advertisements.
  • Cookie and similar-technology data as described below.

Information from other sources

We may receive information from scheduling, CRM, payment, communications, analytics, advertising, referral and clinical technology providers; from health care professionals involved in your care; or from another person acting with your authorization.

3. How we use information

We may use personal information to:

  • Provide, coordinate, personalize and improve services;
  • Schedule appointments, process transactions and respond to requests;
  • Communicate about appointments, programs, service updates and administrative matters;
  • Send marketing communications where permitted by law and honor opt-out requests;
  • Operate, secure, debug, analyze and improve our websites and digital services;
  • Prevent fraud, misuse, security incidents and other harmful activity;
  • Maintain records, enforce agreements and comply with legal, regulatory, licensing and professional obligations; and
  • Establish, exercise or defend legal claims.

Where information is PHI, we use and disclose it only as permitted by HIPAA and other applicable law, as described in our HIPAA Notice of Privacy Practices.

4. How we disclose information

We may disclose personal information to:

  • Service providers and business associates that support hosting, security, CRM, communications, scheduling, payments, analytics, professional services and clinical operations. These may include GoHighLevel/LeadConnector and Zenoti when used in our workflows.
  • Health care participants, including clinicians, laboratories, pharmacies and other providers, when permitted by law and appropriate for care or operations.
  • Professional advisers, such as attorneys, accountants, auditors and insurers.
  • Government, regulatory or legal recipients when disclosure is required or permitted by law, or reasonably necessary to protect rights, safety and security.
  • Transaction participants in connection with a merger, financing, reorganization, sale of assets or similar transaction, subject to applicable confidentiality and legal requirements.
  • Other recipients at your direction or with your consent.

We do not sell PHI. We do not sell personal information for monetary consideration. Some analytics or advertising technologies may constitute “sale,” “sharing” or targeted advertising under certain state privacy laws; where applicable, we provide the required notice and method to opt out.

5. Cookies, analytics and online tracking

We and authorized vendors may use cookies, pixels, tags, software development kits and similar technologies to keep the site working, remember preferences, understand site performance, measure communications and, where enabled, support advertising.

You may manage cookies through available website controls and your browser settings. Blocking some cookies may affect site functionality. Where required by law, we honor recognized opt-out preference signals, such as Global Privacy Control, for the browser or device sending the signal.

Health-data safeguard: We do not authorize advertising technologies to receive PHI from authenticated patient portals, clinical intake workflows or pages where a visitor enters sensitive health information. Sensitive forms should be completed only through the secure workflows we identify for that purpose.

6. Health information and HIPAA

Not all information collected through a public website is PHI. HIPAA generally applies when individually identifiable health information is created, received, maintained or transmitted by IFHO in its role as a covered health care provider or by a business associate acting on its behalf.

When you use an authorized patient intake, scheduling, clinical or payment workflow connected to your care, applicable health information may be governed by our HIPAA Notice of Privacy Practices. General browsing data, public-site cookie data and information collected for non-clinical purposes may instead be governed by this Website Privacy Policy and other applicable privacy laws.

A business associate agreement with a technology vendor defines HIPAA responsibilities between IFHO and that vendor. It does not make every form, integration, plug-in, tracking pixel or user account HIPAA-compliant. We configure designated systems and limit PHI to approved workflows.

7. Email, telephone and text communications

If you provide contact information, we may contact you about appointments, services, transactions and, where permitted, marketing. Message and data rates may apply. Marketing text-message consent is not a condition of purchasing services. You may opt out of marketing emails using the unsubscribe link and of marketing texts by replying STOP. We may still send non-marketing communications permitted by law.

Standard email and SMS may not be fully secure. Do not send sensitive health information through ordinary email or text unless we specifically instruct you that the channel is appropriate.

8. Your choices and privacy rights

Depending on your residence and applicable law, you may have rights to confirm whether we process your personal data; access, correct, delete or obtain a portable copy of it; opt out of targeted advertising, sale or certain profiling; withdraw consent; and appeal a decision on a privacy request.

Maryland residents may have rights under the Maryland Online Data Privacy Act for covered processing occurring on or after April 1, 2026. Certain entities and data—including data governed by HIPAA—may be exempt. We will evaluate each request under the law that applies to the information and our relationship with you.

To submit a request or appeal, email [email protected] with “Privacy Request” or “Privacy Appeal” in the subject line, or use the contact information below. Describe the request and the email or telephone number associated with you. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, subject to verification. We will not discriminate against you for exercising a privacy right.

If we deny a request, you may appeal by contacting us within a reasonable period using “Privacy Appeal” in the subject line. We will respond within the period required by applicable law and, when required, explain how to contact the appropriate state regulator or attorney general.

For rights concerning medical records or other PHI, follow the process in our HIPAA Notice of Privacy Practices.

9. Security and retention

We use administrative, technical and physical safeguards designed to protect personal information based on its sensitivity and the context in which it is processed. No internet transmission, system or storage method can be guaranteed to be completely secure.

We retain information for as long as reasonably necessary for the purposes described in this policy, including providing services, maintaining medical and business records, meeting legal and professional requirements, resolving disputes, enforcing agreements and protecting security. Retention periods vary by information type and applicable law. We then delete, de-identify or securely dispose of information when reasonably practicable.

10. Children’s privacy

Our public websites are not directed to children under 13, and we do not knowingly collect personal information online from a child under 13 without appropriate parental authorization. A parent or legal guardian who believes a child submitted information through a public website should contact us. This section does not restrict information collected as part of legally authorized health care.

12. Changes to this policy

We may update this policy to reflect changes in our practices, technology or legal obligations. We will post the revised policy with a new “Last updated” date and provide additional notice when required by law. Material changes apply prospectively unless otherwise permitted by law.

13. Contact us

Privacy Officer
Institute for Human Optimization

7030 Hi Tech Drive, Suite 102
Hanover, Maryland 21076

Telephone: 410-858-4086
Email: [email protected]