PRIVACY POLICY
Verendo Health LLC
Last updated: September 13, 2026
Effective date: October 1, 2026
1. WHO WE ARE AND WHAT THIS COVERS
Verendo Health LLC (“Verendo,” “we,” “us,” or “our”) is a Florida limited liability company formed on May 11, 2026. Kevin McCall, MS, RDN, CSSD is the sole member.
This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and what control you have over it. It covers our website, the Verendo client app once it launches, and our lab panel analysis service.
A note on HIPAA. Verendo is a cash-pay service. We do not bill insurance and we do not submit electronic health insurance claims, so we are not a HIPAA covered entity and we do not claim to be “HIPAA compliant.” We say this plainly because some companies imply otherwise. What we do instead is apply HIPAA-informed safeguards: we protect your health information with the security controls described in Section 6, because it is the right way to handle this data, not because a federal rule forces us to. Your rights under this policy come from state consumer privacy laws and from our own commitments here.
There is a second, separate policy for health data. Because your lab results and intake answers are especially sensitive, we maintain a standalone Consumer Health Data Privacy Policy. It explains, in more detail, what health data we collect, who can see it, and how to withdraw your consent or have it deleted. If you only read one page, read that one. The two policies work together, and where this policy and the Consumer Health Data Privacy Policy disagree about health data, the Consumer Health Data Privacy Policy controls.
Who can use the service. Our services are for adults 18 and older who are located in the United States. We do not target or offer our services to people in the European Union, the United Kingdom, or elsewhere outside the US, so this policy does not include GDPR terms. Our lab panel analysis is available in most of the United States. Our lab partner cannot currently serve people located in New York, New Jersey, Rhode Island, Hawaii or Puerto Rico.
2. WHAT WE COLLECT
2.1 Information you give us
- Account and contact information: your name, email address and date of birth, and your phone number or mailing address if you give them to us.
- Email list signup: your email address, if you join our email list. See Section 4.3.
- Payment information: when you buy a panel, your payment is handled by Stripe. See Section 4.3 for an important point about how we keep payment data and health data apart.
- Intake answers: health history, current medications and supplements, diagnosed conditions, allergies, diet, training, sleep, stress, symptoms, and your goals. You choose how much to share.
- Messages you send us: emails you send us, and coaching notes if you buy coaching.
2.2 Information created by using the service
- Lab results: biomarker values from the blood panel we order for you through Fullscript. Your blood is drawn at a Quest Diagnostics Patient Service Center, or at home by Getlabs if you choose the at-home draw, and Quest Diagnostics runs the tests. You never upload your labs. Your results come back to us through Fullscript.
- Your report: the analysis, biomarker assessments, and ranked recommendations our engine produces from your labs and your intake.
- Coaching records, if you buy coaching: session notes, progress, and follow-up comparisons.
2.3 Information collected automatically
- Usage data: when you visit our website, Cloudflare processes your IP address to deliver the page and protect the site, and Cloudflare Web Analytics records the page you viewed, the page that referred you, your browser type and your approximate country. See Section 8.
- Cookies and analytics: see Section 8.
2.4 Where the information comes from
We get information only from these places: (1) directly from you, (2) from Fullscript, which returns your lab results, (3) from Stripe, which confirms your payment when you buy a panel, and (4) automatically from your device when you use our website, or our app once it launches. We do not buy personal information from data brokers and we do not build profiles from outside sources.
3. WHY WE USE IT
- To deliver what you bought: order your panel, receive your results, run the analysis, produce your report, and send it to you.
- To communicate with you: confirmations, prep instructions before your blood draw, report delivery, and answers to your questions. If you join our email list, we use your email address to confirm your signup and to send you updates about Verendo.
- To reach you about a serious result: if a lab value is critically abnormal, we will try to reach you promptly using the email address you gave us. This is not emergency care. See our Medical Disclaimer.
- To take payment: when you buy a panel, through Stripe.
- To improve the service: we improve our analysis engine and reference ranges using de-identified and aggregated data only. Work like this never uses data that identifies you.
- To meet legal and tax obligations and to enforce our Terms.
- To send marketing, only if you opt in. You can unsubscribe at any time using the link in any marketing email, and unsubscribing never affects the service you purchased.
4. WHO WE SHARE IT WITH
We do not sell your personal information, and we do not sell your health data. Not to anyone, not ever. We also do not share your information for cross-context behavioral advertising. We do not use your health data to target ads.
We share information only with the service providers listed below, only for the purpose listed, and only to the extent needed to run the service.
4.1 Our service providers
| Provider | What they do for us | What they receive | Health data? |
|---|---|---|---|
| Fullscript | Orders your lab panel and routes it through the Authorization Network, where a licensed network clinician reviews and signs the order. Also fulfills supplement recommendations if you choose to buy them. | Name, date of birth, sex, contact details, the panel ordered, the clinical information the reviewing clinician needs to approve it, and the resulting lab data held in their system. | Yes |
| Quest Diagnostics | Performs the blood draw at a Quest Patient Service Center and runs the tests, contracted through Fullscript. | Name, date of birth, biological sex, and your specimen. | Yes |
| Getlabs | Performs your blood draw at home, only if you choose the at-home draw. | Name, date of birth, address, phone number, appointment details, and your specimen. | Yes, only if you choose the at-home draw |
| Stripe | Processes your payment when you buy a panel. | Name, email, billing details, payment card data (which Stripe collects and holds directly), and the fact that you bought a Verendo lab panel. | Only the fact that you bought a lab panel. Never your intake answers, lab results, anything we infer from them, or your report. See Section 4.3. |
| Google Cloud (GCP) | Hosts the server that stores your intake answers, lab results and reports. Google provides the infrastructure only. Verendo operates the software on it. The server is covered by Google’s Business Associate Agreement, which we took on as an extra contractual safeguard by choice. It is not a sign that HIPAA applies to us, because it does not. | The information stored on that server, including your intake answers, lab results and reports. | Yes, as infrastructure |
| Google Workspace | Hosts our email inboxes, including [email protected] and [email protected]. Covered by Google’s Business Associate Agreement. | Anything you email us, including health information you choose to include. | Yes, if your email includes it |
| Cloudflare | Serves our website, provides HTTPS and attack protection, runs Cloudflare Web Analytics, and keeps the proof-of-signup record for our email list. | Your IP address and standard web traffic data, and the page-view details described in Section 8. If you join our email list, your email address passes through Cloudflare, but only the proof-of-signup record described in Section 4.3 is kept there. Your readable email address is not stored in Cloudflare. | Only in transit, if you send health information through the website. Cloudflare does not store it. |
| Resend | Sends our email and stores the contacts on our email list. | Your email address and the content of the emails we send you. If you join our email list, Resend stores your email address as a contact on that list. | Only what appears in an email we send you |
4.2 Software we run ourselves
The following are not outside companies receiving your data. They are software we run ourselves. No third party gets a copy of your information through them.
| System | What it does |
|---|---|
| Supabase (self-hosted) | Our database and file storage, and the sign-in system for Verendo accounts once they launch. It runs as self-hosted Postgres, GoTrue authentication, and storage on the Google Cloud server described above. Row-level security limits each account to its own records, and the database itself enforces that limit. |
| n8n (self-hosted) | Workflow software that connects our own systems. It runs on the same Google Cloud server. |
| Matomo (self-hosted) | Analytics software that runs on our own server for internal use. It is not connected to this website. See Section 8. |
| Our report software | Our own software will produce your analysis and turn your report into a PDF once the service opens. Your report is never sent to an outside AI service or to an outside document service to be formatted. |
4.3 Three things worth calling out
Payment data and health data stay separate. When you buy a panel, Stripe processes your payment. Stripe receives your name, email, billing details and the fact that you bought a Verendo lab panel. It never receives your intake answers, your lab results, anything we infer from them, or your report. We deliberately keep the payment pipeline and the health data pipeline separate, so that the company processing your card learns nothing about your health beyond the fact that you bought a panel.
Your health data is never sent to an AI vendor. Our analysis engine is deterministic and follows rules we wrote. There is no large language model in the pipeline that produces your report, and no part of your labs, intake, or report is sent to an AI service from Anthropic, OpenAI, Google, or any other AI provider. We have no Business Associate Agreement with any AI vendor because your data never goes to one.
Our email list. If you join our email list, your email address is stored as a contact by Resend, which also sends you a confirmation email. Separately, Cloudflare keeps a proof-of-signup record that contains only a scrambled one-way code made from your email address, a scrambled code made from your IP address, a shortened description of your browser, your approximate country and the time you signed up. It is kept for 5 years so we can show that you asked to join. You can unsubscribe from the list at any time.
4.4 Other sharing
- When you tell us to. We will share your information with your doctor, a family member, or another professional if you ask us to in writing.
- When the law requires it. We may disclose information in response to a subpoena, court order, or lawful government request, or when necessary to protect the rights or safety of you, us, or someone else.
- If the business changes hands. If Verendo is merged, acquired, or sold, your information may transfer to the new owner under the same protections described here. We will tell you before that happens whenever we reasonably can.
5. HOW LONG WE KEEP IT
| Information | How long we keep it |
|---|---|
| Intake answers, health history, lab results, engine inferences, and your reports | While your account is active, so you can compare panels over time. If your account is inactive for 24 months, we email you first and then delete your health information. This is the health-data rule, and the Consumer Health Data Privacy Policy controls it. |
| Coaching notes | Kept for 5 years after your last coaching session, even if you ask us to delete your data sooner. If we keep a coaching record after a deletion request, we will tell you exactly what we kept. |
| Contact and account information | While your account is active, plus 1 year. If your account is inactive for 24 months, we email you first and then close it. |
| Email list contact: your email address, held by Resend | Until you ask us to delete it. You can unsubscribe from the list at any time. |
| Proof-of-signup record for the email list: scrambled codes made from your email address and IP address, a shortened description of your browser, your approximate country, and the time you signed up | 5 years from when you signed up |
| Emails and other messages you send us | While your account is active, plus 1 year. Messages that discuss your health are health data and follow the health-data rule in the first row. |
| Consent records: date and time, email address, IP address, browser type, document versions | 7 years after the later of account closure or your last consent event. These never contain your intake answers, lab results or reports. We keep them to prove that collection was authorized and that we honored your requests. |
| Billing and payment records | 7 years from the transaction, for tax and business records. They show that you bought a Verendo lab panel, but never contain your intake answers, lab results or reports. |
| Website analytics data | Held by Cloudflare under its own retention schedule. It does not identify you. |
| De-identified, aggregated data | Indefinitely. It cannot be traced back to you. |
The 7 year periods on payment and consent records reflect standard business record retention and evidence needs. They never contain your intake answers, lab results or reports. After any period ends, we securely delete or de-identify the data.
You can ask us to delete your data sooner. See Section 7.
6. HOW WE PROTECT IT, STATED HONESTLY
We are a single-member company, not a hospital system. Here is what we actually do, without dressing it up.
What is in place:
- Your information travels over encrypted HTTPS connections.
- Health information is stored in a database on a Google Cloud server in the United States that we control, covered by Google’s Business Associate Agreement. Verendo chose that agreement as an extra contractual safeguard. It is not a sign that HIPAA applies to us, because it does not.
- Row-level security limits each account to its own records. That limit is enforced by the database itself rather than by application code that could have a bug.
- Server credentials never leave the server. They are never placed in a browser or an app.
- Changes to the database structure are logged.
- Signing in to the server requires an SSH key. Access is limited to Kevin McCall. No other staff have access, because there are no other staff.
- A written plan for what happens if there is a breach.
- Data minimization. We do not collect information we do not need.
What we do not claim:
- We do not keep a log of each time someone reads the database.
- We are not HIPAA certified, and no such certification exists.
- We have not completed a SOC 2 audit.
- No system is perfectly secure. We use reasonable, current safeguards, but we cannot promise that no incident will ever happen.
If there is a breach. If your personal information is exposed in a security incident, we will investigate promptly and notify you without unreasonable delay, by email, and by mail if we cannot reach you by email. Our notice will tell you what happened, what information was involved, what you can do to protect yourself, and what we are doing about it. We will also notify state authorities where the law requires it. Because we are not a HIPAA covered entity, HIPAA’s federal breach reporting process does not apply to us. State breach notification laws do, and we follow them.
7. YOUR RIGHTS AND HOW TO USE THEM
California residents have these rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. We extend the same rights to every client, in every state. You do not have to prove where you live to ask.
- Know. Ask what personal information we have collected about you, where it came from, why we collected it, and who we shared it with.
- Access. Get a copy of your information, including your lab results and your report, in a portable format.
- Correct. Ask us to fix information that is wrong or incomplete.
- Delete. Ask us to delete your information, except records we must or are allowed to keep: billing records for tax purposes, consent records, the email list proof-of-signup record, and coaching records for 5 years after your last session.
- Opt out of sale or sharing. There is nothing to opt out of, because we do not sell your personal information and we do not share it for cross-context behavioral advertising. We are stating the right so you know it exists.
- Limit the use of sensitive personal information. Your lab results, health history, and biometric data are sensitive personal information. We use them only to deliver the service you purchased.
- Withdraw consent to health data processing. Email [email protected]. Covered in detail in the Consumer Health Data Privacy Policy.
- No retaliation. We will never charge you more, give you a worse service, or refuse to serve you because you exercised a privacy right.
How to make a request
Email [email protected] with your request in the subject line, for example “Data Deletion Request” or “Data Access Request,” or write to us at the postal address in Section 11. We do not have self-serve privacy settings, so every request comes to us this way.
- We confirm we received it within 5 business days.
- We verify your identity, so that nobody else can request your health data.
- We complete an access or correction request within 45 days. If we genuinely need more time, we will tell you why and take up to 45 more days.
- When we verify a deletion request, we delete your information within 30 days, including any copies we hold. That shorter deadline is the one in our Consumer Health Data Privacy Policy, and we apply it to everything, not just health data.
- For deletions, we confirm in writing what was deleted and what we had to keep, along with the legal reason we kept it.
You can name an authorized agent to make a request for you. We will still need to verify your identity.
If we say no, you can appeal. If we deny a request we will tell you why in writing and tell you how to appeal. Reply to that denial, or email [email protected] with “Appeal” in the subject line, and we will respond within 45 days. If we still deny it, we will give you a link to complain to your state attorney general.
A note on residents of Washington, Nevada and California. Washington’s My Health My Data Act, Nevada’s SB 370 and California’s Confidentiality of Medical Information Act give you specific rights over consumer health data. Those rights, and how to use them, are covered in the Consumer Health Data Privacy Policy.
8. COOKIES AND ANALYTICS
- What we store on your device. Our website sets no cookies other than the one that remembers your cookie banner choice, if you make one. Cloudflare may set a short-lived security cookie if it has to challenge traffic it thinks is automated; see the Cookie Policy. If we add a cookie that the site or your account needs to work, such as one that keeps you signed in once accounts launch, the Cookie Policy will list it.
- Our cookie banner asks first. Nothing is pre-ticked, and rejecting is exactly as easy as accepting. Today none of the banner’s optional switches turns anything on or off, because nothing we run depends on them.
- Analytics. We use Cloudflare Web Analytics on every page of this website. It sets no cookies and stores nothing on your device, so the cookie banner does not control it. It counts page views and records the page you viewed, the page that referred you, your browser type and your approximate country. It does not identify you and does not follow you to other websites. We do not run any other analytics or advertising trackers on this website. Our website code includes an error-monitoring tool, Sentry, that is switched off; if we ever turn it on, we will update this page first. Matomo runs on our own server for internal use and is not connected to this website. If we ever add an outside analytics vendor, we will name that vendor in the table in Section 4.1 and update this section before it runs. If that vendor would receive health data, we will ask for your consent again first.
- Email address protection. Cloudflare also runs a small script on our pages that hides email addresses from automated scrapers. It sets no cookies.
- Analytics never receive health data. No analytics tool of any kind runs on a page that contains your lab results or your report.
- We run no advertising or marketing trackers. No advertising pixels and no third-party ad networks.
You can also manage cookies in your browser settings, and the Cookie Policy lists every cookie we set.
About Global Privacy Control and Do Not Track. A Global Privacy Control signal tells a site not to sell or share your personal information. We do not sell or share personal information at all, so there is nothing for that signal to switch off. Our only website analytics tool sets no cookies and does not identify you. We have not yet built separate technical handling for a GPC or Do Not Track signal, and we are not going to claim we have. If you send us a GPC signal and want us to treat it as a withdrawal of any consent you gave, email [email protected] and we will do that in writing.
9. CHILDREN
Our service is for adults 18 and older. We do not knowingly collect information from anyone under 18. If we learn that we have, we delete it promptly. If you believe a minor has given us information, contact us at the address in Section 11.
10. CHANGES TO THIS POLICY
We may update this policy. If a change is material, we will email you and post a notice at least 30 days before it takes effect. The effective date at the top of this page always shows the current one. We keep prior versions available on request.
11. CONTACT US
Verendo Health LLC
Kevin McCall, MS, RDN, CSSD, Privacy Contact
7901 4th St N Ste 300, St. Petersburg, FL 33702
Email: [email protected]
Related documents:
- Consumer Health Data Privacy Policy, which covers your lab results and intake data in detail
- Terms of Service
- Medical Disclaimer
- Cookie Policy
Verendo’s lab panel analysis is informational and educational. It is not medical advice, not a diagnosis, and not treatment. 1:1 coaching is not yet available. When we offer it, it will be available only to clients located in Arizona, California, Colorado, Florida, Michigan, Texas and Wisconsin. Kevin is licensed in Florida (license ND15442); the other states on this list do not require a license for this kind of nutrition coaching.