Effective Date: August 3, 2026 | Last Updated: August 3, 2026
This Privacy Policy (“Policy”) describes how Elytix Corporation and its affiliates (“Elytix,” “we,” “us,” or “our”) collect, use, disclose, protect, and otherwise process personal information, including sensitive biometric and health-related data, in connection with our websites, mobile applications, platforms, research studies, and related services (collectively, the “Services” or “Platform”). It applies to all users of the Services, including Research Associates participating in Elytix-sponsored research studies, individuals exploring benefits or research opportunities, and visitors to our Sites.
By accessing or using the Services, registering for an account, submitting biometric data (including via face-scan), providing health or other information, enrolling in a research study, or otherwise interacting with Elytix, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree, do not use the Services or provide any personal information.
1. Information We Collect
1.1 Personal Identifiers and Account Information
We collect information you provide directly, such as name, date of birth, contact information (email, phone, mailing address), government-issued identification (for identity verification and W-2/employment eligibility), employment or gig-worker status/history, Social Security Number or equivalent (for tax reporting and benefits eligibility where required), and account credentials. We also collect information about your employer, plan sponsor, or referring entity where applicable.
1.2 Biometric Information (Face-Scan and Related Data)
Elytix does not use facial recognition technology. The face scan utilizes remote photoplethysmography (rPPG) technology to measure and derive vital-sign and wellness biomarkers (such as heart rate, heart rate variability, oxygen saturation, and stress indicators) from subtle color changes in facial video captured by the device camera. The scan does not identify you, does not create, match, or store any facial-geometry templates, facial-recognition data, or identity-matching vectors, and does not perform facial recognition or identity authentication. Liveness detection is used solely as a secondary anti-fraud measure to confirm that a live person is present during the scan and to help ensure data integrity for research purposes. The primary purpose of the face scan is as a research and health-data collection instrument to gather objective biomarker data in support of the Elytix research protocols, predictive analytics, and health plan innovation initiatives. We process this biomarker data only with your explicit consent and in accordance with applicable federal privacy and research regulations.
1.3 Health, Medical, and Research-Related Information
We collect all medical and health-related information accumulated by or through the Elytix application and Platform, including without limitation: medications (current and historical), doctors and healthcare providers seen, appointments made or scheduled, symptoms reported, diagnoses, treatment plans, lab results, claims and utilization data (if enrolled in associated Group Health Plans), biometric-derived health indicators or predictive analytics, responses to questionnaires and research surveys, family and medical history, lifestyle factors, and any other health or medical information you provide or that is generated in connection with your research participation or benefits. All such information will be de-identified in accordance with applicable standards (HIPAA Safe Harbor or Expert Determination) before being used for research, analytics, dataset creation, AI model development, or any commercial or licensing purposes as described in this Policy. This information may constitute Protected Health Information (PHI) under HIPAA while identifiable.
1.4 Employment, Benefits, and Participation Data
We collect information related to your research participation status, compensation history and amounts, W-2 employment records (during active participation), tax forms and withholdings, enrollment and eligibility status for group health plans and ancillary benefits (e.g., petcare, identity protection, travel), claims or utilization data (if applicable), and records of communications with research coordinators, providers, or plan administrators.
1.5 Device, Usage, and Technical Information
We automatically collect device information (type, operating system, browser, IP address, device identifiers, mobile carrier), app usage data (features accessed, time spent, actions taken, assessment completion), cookies and similar tracking technologies (for authentication, preferences, analytics, and security), and logs of interactions with the Platform (including failed login attempts or biometric capture quality metrics). Elytix does not collect precise or live geolocation data from Research Associates or other users.
1.6 Information from Third Parties and Affiliates
We may receive information about you from affiliated entities, research partners, plan sponsors or employers, healthcare providers, labs, background or identity verification services, public records, or other sources (including inbound referrals of prospective Research Associates) to verify eligibility, prevent fraud, administer benefits, or support research objectives.
2. How We Use Your Information
We use the information we collect for the following primary purposes (and other purposes disclosed at the time of collection or with your consent):
- To provide, operate, maintain, and improve the Platform and Services, including eligibility verification, research study administration, compensation processing (W-2), and benefits enrollment/coordination;
- To conduct identity verification using conventional methods (such as account credentials or government-issued identification), and to perform liveness detection during a scan, in each case to protect against fraud, unauthorized access, or ineligible participation;
- To assess your suitability for specific research studies, determine or maintain eligibility for compensation and benefits, and monitor ongoing compliance with study protocols;
- To develop, train, validate, and improve AI models, predictive analytics, and face-scan-based health risk or outcomes tools (using both identifiable and de-identified data as permitted);
- To create de-identified and/or aggregated datasets from Submitted Data (including health, biometric, and participation information) for internal research, quality improvement, health plan innovation, scientific advancement, and external licensing or monetization to third parties such as researchers, pharmaceutical companies, insurers, government agencies, or analytics firms;
- To facilitate communications with you regarding your participation, compensation, benefits, assessments, important notices, and (with opt-in consent) marketing or research opportunities;
- To comply with legal, regulatory, tax, employment, and research ethics obligations (including HIPAA, ERISA, Common Rule/IRB requirements where and if applicable, tax reporting, and data retention for study integrity);
- To protect the security and integrity of the Platform, prevent abuse, and enforce these Terms and our legal rights;
- To analyze usage patterns, improve user experience, and develop new features or studies; and
- For other purposes with your consent or as otherwise permitted or required by law.
“Submitted Data” means all information, biometric data, biomarker readings, health and medical information, responses, images, videos, and other materials you provide, upload, or that are generated through your use of the Platform, face scans, assessments, questionnaires, or research participation (as more fully described in the Terms of Use).
Data-Set Cohorts and Aggregated Research Datasets. As part of our research and data monetization activities, Elytix creates, maintains, and licenses aggregated, de-identified data-set cohorts ("Cohorts") derived from Research Associate Submitted Data. These Cohorts may be organized by demographics, health conditions, biometric profiles, participation patterns, geographic factors, or other research-relevant attributes. Cohorts are used internally for AI model training, predictive analytics, health outcomes research, and platform improvement, and may be licensed or sold to third parties (researchers, pharmaceutical companies, insurers, government agencies, or analytics firms) under strict data use agreements that prohibit re-identification attempts and require compliance with applicable laws. Once data is incorporated into a Cohort and de-identified, it becomes part of Elytix’s sole and exclusive property as set forth in this Policy and the Research Participation Agreement and Informed Consent. Your individual data contributes to these Cohorts but you have no ownership, control, or rights with respect to any Cohort or the de-identified data contained therein.
3. Research Data, De-identification, Data Monetization, and Authorization for Use of De-Identified Information
A fundamental aspect of the Elytix model is the collection and responsible use of healthcare and biomarker information from Research Associates to advance scientific understanding, develop innovative predictive tools (including AI face-scan analytics), design better health plan products, and generate revenue through data licensing that helps sustain participant compensation, benefits, and platform operations.
We employ industry-standard and regulatory-compliant methods to de-identify and anonymize healthcare information, including the HIPAA Safe Harbor method (removing 18 specific identifiers) and/or Expert Determination (statistical or scientific principles ensuring very low risk of re-identification). Once data is properly de-identified in accordance with applicable standards, it is no longer considered Protected Health Information (PHI) under HIPAA or equivalent state laws.
This Section 3 applies only to Research Associates. It describes the data authorizations granted through the Research Participation Agreement and Informed Consent and the Biometric / rPPG Consent, each of which is separately presented and accepted at enrollment. Those documents, and not this Privacy Policy, are the instruments by which those authorizations are given. This Section does not apply to visitors to the Sites who are not Research Associates. Under those enrollment documents, as a Research Associate:
- You consent to the collection, use, processing, disclosure, de-identification, aggregation, analysis, retention, and commercialization of your healthcare information, biometric data (as limited to biomarker readings and non-identifying data), and related Submitted Data as described in this Policy and the Research Participation Agreement and Informed Consent.
- You expressly authorize Elytix to de-identify and/or anonymize your healthcare information and biomarker data using appropriate methods (including HIPAA Safe Harbor or Expert Determination) and to use, license, sell, disclose, or otherwise exploit such de-identified/anonymized data (alone or in aggregate form, including in data-set Cohorts) for any lawful purpose, including without limitation: internal or external research; development and training of AI, machine learning, or predictive models; product development; health economics and outcomes research; marketing or business development by Elytix or third parties; sale or licensing to pharmaceutical, biotechnology, insurance, analytics, government, academic, or other commercial or non-commercial entities; and any other purpose not prohibited by law.
- YOU ACKNOWLEDGE AND AGREE THAT, ONCE PROPERLY DE-IDENTIFIED IN ACCORDANCE WITH APPLICABLE STANDARDS, SUCH INFORMATION IS NO LONGER PROTECTED HEALTH INFORMATION (PHI) UNDER HIPAA OR EQUIVALENT STATE LAWS, AND THE RESTRICTIONS OF HIPAA NO LONGER APPLY TO IT. YOU FURTHER ACKNOWLEDGE AND AGREE THAT ALL DE-IDENTIFIED DATA AND ALL RIGHT, TITLE, AND INTEREST THEREIN (INCLUDING ALL INTELLECTUAL PROPERTY RIGHTS) SHALL BELONG SOLELY AND EXCLUSIVELY TO ELYTIX CORPORATION. ELYTIX SHALL HAVE THE UNFETTERED, PERPETUAL, IRREVOCABLE RIGHT TO USE, LICENSE, SELL, ASSIGN, DISCLOSE, COMMERCIALIZE, OR OTHERWISE EXPLOIT SUCH DE-IDENTIFIED DATA IN ANY MANNER AND FOR ANY LAWFUL PURPOSE WITHOUT ANY FURTHER OBLIGATION, NOTICE, CONSENT, OR COMPENSATION TO YOU. YOU HEREBY ASSIGN AND TRANSFER TO ELYTIX ANY AND ALL RIGHTS YOU MAY HAVE IN SUCH DE-IDENTIFIED DATA. YOU WILL NOT ASSERT ANY OWNERSHIP, CONTROL, PRIVACY, OR OTHER RIGHTS OVER SUCH DE-IDENTIFIED DATA OR ATTEMPT TO RESTRICT ITS USE, SALE, OR DISCLOSURE BY ELYTIX OR ITS AUTHORIZED LICENSEES. THIS OWNERSHIP AND ASSIGNMENT SURVIVE ANY WITHDRAWAL, TERMINATION, OR EXPIRATION OF YOUR PARTICIPATION. ONLY DE-IDENTIFIED DATA (NEVER IDENTIFIABLE BIOMETRIC OR HEALTH INFORMATION) IS EVER LICENSED, SOLD, OR DISCLOSED TO THIRD PARTIES.
- You understand that de-identification methods, while designed to minimize re-identification risk to very low levels in accordance with regulatory standards, are not infallible, and that no method can guarantee 100% anonymity in all circumstances (particularly as technology and data linkage capabilities evolve). You accept this residual risk as part of your voluntary participation.
- This consent and authorization are perpetual, irrevocable (to the extent permitted by law), and survive the termination or withdrawal of your research participation, account closure, or cessation of use of the Services. De-identified data and derivative datasets may be retained and used indefinitely.
- You will not receive additional compensation, royalties, or other consideration for the use, licensing, or monetization of de-identified data derived from your participation, beyond the research participation compensation and benefits eligibility expressly offered. You acknowledge that the broader societal, scientific, and platform-sustainability benefits of data contribution are part of the value exchange for participation.
- If you have concerns about these data practices or do not wish to consent to de-identification and the associated authorization, you should not participate in Elytix research studies or provide healthcare information beyond what is strictly necessary for basic Platform functionality (if any such limited functionality exists without full participation).
4. How We Share and Disclose Your Information
We do not sell your identifiable personal information or PHI for marketing purposes in the traditional sense. However, we do share and disclose information as follows:
- With service providers, vendors, and contractors who perform services on our behalf (e.g., cloud hosting, identity verification, payroll/W-2 processing, lab services, data analytics, security, customer support) under appropriate confidentiality and data protection agreements;
- With affiliated entities and other plan administrators or benefits partners, for purposes of benefits enrollment, administration, claims processing, and coordination of group health and ancillary benefits;
- With research partners, study sponsors, IRBs (Institutional Review Boards where and if applicable), and academic or scientific collaborators under data use or research agreements that include appropriate protections;
- With healthcare providers, labs, and care coordinators involved in your assessment, treatment, or research participation, as necessary for care coordination or study requirements;
- With third-party licensees or purchasers of de-identified and aggregated datasets, as described in Section 3 above;
- To comply with legal obligations, respond to subpoenas, court orders, or government requests, or protect the rights, property, or safety of Elytix, our users, or the public;
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, where your information may be transferred as part of the transaction (de-identified data licenses and surviving ownership rights will typically transfer with the data assets);
- With your consent or at your direction (e.g., to share records with another provider or for a specific research collaboration you approve).
We require recipients of identifiable data to maintain appropriate confidentiality and security protections and to use the data only for authorized purposes. De-identified data shared with licensees is provided under terms that prohibit re-identification attempts and require compliance with applicable laws.
5. Data Security
We implement reasonable and appropriate administrative, technical, and physical safeguards designed to protect your personal information, biometric data, and PHI from unauthorized access, use, disclosure, alteration, or destruction. These include encryption of sensitive data in transit (TLS) and at rest (where feasible), access controls and authentication (including multi-factor), regular security assessments, employee training, and incident response procedures. Biometric data is stored and processed with heightened protections. Elytix stores only derived biomarker values and related metrics; no facial-geometry or facial-identity template is created or retained at any point.
Despite our efforts, no security measures are perfect or impenetrable, and we cannot guarantee absolute security. In the event of a data breach that compromises your personal information, we will notify you and applicable regulators as required by law (e.g., under HIPAA Breach Notification Rule where applicable, or state breach notification statutes).
6. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to provide the Services, to comply with legal, tax, employment, and regulatory obligations (including research record retention requirements under the Common Rule or FDA regulations where and if applicable), to resolve disputes, enforce agreements, and for legitimate business purposes such as maintaining de-identified research datasets. Identifiable data is typically retained for the duration of your active participation plus a reasonable period thereafter (e.g., 7 years or as required by specific study protocols, statutes of limitations, or regulatory holds). De-identified and aggregated data may be retained indefinitely, as it no longer identifies you and supports ongoing and future research and commercial uses as consented.
You may request deletion of certain identifiable personal information, subject to limitations: we may be unable to delete information that is necessary for active legal or research obligations, that has already been de-identified and aggregated into datasets, or that we are required to retain by law. Requests to delete biometric data will be honored where feasible and not overridden by legal or study integrity requirements; however, de-identified derivatives may persist.
7. Your Rights and Choices
Depending on your jurisdiction and the nature of the data, you may have certain rights regarding your personal information. These may include:
- Right to Access / Know: Request confirmation of whether we process your personal information and obtain a copy of certain data we hold about you (subject to verification and exceptions for research data or de-identified datasets).
- Right to Correction: Request correction of inaccurate personal information (we will take reasonable steps to verify and update).
- Right to Deletion: Request deletion of personal information, subject to legal, research integrity, and operational exceptions as noted above.
- Right to Opt-Out of Sale/Sharing: While we do not “sell” identifiable personal information for cross-context behavioral advertising in the CCPA/CPRA sense, you may have rights regarding sharing for targeted advertising or certain data uses; contact us to exercise opt-out rights where applicable.
- Right to Limit Use of Sensitive Personal Information: You may have rights to limit use of sensitive data (biometrics, health) to what is necessary for the Services; however, core research participation requires processing of such data.
- HIPAA Rights (if applicable): If Elytix or an affiliate is a Covered Entity or you have rights with respect to PHI held by a Covered Entity in connection with benefits or services, you may have rights to access, amend, request an accounting of disclosures, and receive a Notice of Privacy Practices. Contact the applicable entity or Elytix Privacy Officer for HIPAA-related requests.
- Biometric-Specific Rights: In jurisdictions with biometric privacy laws, you may have rights to notice, consent, and limitations on retention/disclosure of biometric data. We honor applicable rights and provide mechanisms to exercise them.
- California Residents (CCPA/CPRA): California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Elytix collects categories of personal information including identifiers, biometric information (limited to rPPG biomarker data as described in Section 1.2), health/medical information, employment/participation data, and device/usage data from the sources described in Section 1. We use this information for the business and research purposes described in Section 2 (research study administration, biomarker analysis, de-identified dataset creation and licensing, benefits coordination, etc.). We do not sell identifiable personal information for monetary consideration. Certain analytics technologies may constitute “sharing” under CPRA; California residents may opt out of the “sale” or “sharing” of personal information by emailing support@elytix.com. We do not sell or share the personal information of individuals we know to be under 16. Sensitive personal information (biometric data and health information) is used only as necessary to provide the Services and for the research purposes described herein; you may have the right to limit use of sensitive personal information to what is necessary. To exercise CCPA/CPRA rights, submit a verifiable request to support@elytix.com.
To exercise any of these rights, submit a verifiable request via email to support@elytix.com or through the Platform’s account settings or support portal. We will respond within the timeframes required by applicable law (typically 30-45 days). We may require identity verification before fulfilling certain requests. Note that exercising deletion or opt-out rights may impact your eligibility to continue or re-enroll in research studies, receive compensation, or maintain benefits, as data contribution is integral to participation.
You may also opt-out of marketing communications by following unsubscribe instructions in emails or texting STOP for SMS. You cannot opt-out of transactional, research, or benefits-related communications necessary for participation.
8. Cookies, Tracking Technologies, and Analytics
We use cookies, web beacons, pixels, local storage, and similar technologies to authenticate users, remember preferences, analyze usage, prevent fraud, and for security purposes. We may use third-party analytics providers (e.g., Google Analytics or similar) that collect information about your use of the Sites via cookies and other technologies. You can manage cookie preferences through your browser settings, but disabling certain cookies may impair Platform functionality or security features.
9. Third-Party Links and Services
The Services may contain links to third-party websites, apps, or services (including Linked Sites, research partner portals, or benefits administrator sites). We are not responsible for the privacy practices, content, or data handling of these third parties. Review their privacy policies before providing information or using their services.
10. Children’s Privacy
The Services are not directed to individuals under the age of 18 (or the applicable age of majority), and we do not knowingly collect personal information from children. Research Associates and participants must be adults legally capable of providing informed consent and entering into research participation agreements. If we become aware that we have inadvertently collected information from a child, we will take steps to delete it promptly.
11. International Users and Cross-Border Data Transfers
The Services are primarily intended for use by individuals in the United States. If you access the Services from outside the U.S., you acknowledge that your information may be transferred to, stored in, and processed in the United States or other jurisdictions where our servers, service providers, or research partners are located. These jurisdictions may have data protection laws that differ from those in your country. By using the Services, you consent to such transfers to the extent necessary to provide the Services.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services. We will post the updated Policy on the Sites with a new effective date. For material changes affecting your rights or data practices (particularly regarding biometric data, de-identification, or the authorization for use of de-identified information), we will provide prominent notice on the Platform or via email/SMS where feasible, and continued use or participation after the effective date constitutes acceptance of the updated Policy. We encourage you to review this Policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, your personal information, biometric data, research data practices, the authorization for use of de-identified information, or wish to exercise your rights, please contact us at:
Elytix Corporation Attn: Privacy Officer / Data Protection 6101 Enterprise Park Drive, Suite 800 Chattanooga, TN 37416 Email: support@elytix.com Phone: (646) 599-2068 (or the contact number listed on the Platform)
For HIPAA-related matters or to request a Notice of Privacy Practices from a Covered Entity affiliate, please specify in your request. We will respond to legitimate inquiries in accordance with applicable law.
— END OF PRIVACY POLICY —
