Last updated: 2026-01-07
Welcome to Noyu. This Privacy Policy explains how PROJECT 120 LTD ("Noyu", "we", "us") collects, uses, and protects your personal information when you use our Platform and Services.
We are committed to protecting your privacy and handling your data transparently. This policy is written in plain English so you can understand exactly what happens to your information.
PROJECT 120 LTD - 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, United Kingdom.
Company number: 16584137
For privacy questions, email hello@noyu.health.
We collect information in several categories:
Name, email address, date of birth, biological sex, ethnicity, address, and phone number. We collect this directly from you when you register.
Blood test results, biomarkers, height, weight, and vital signs. This is collected from laboratory partners who process your samples.
Health and fitness data from connected devices and apps. This is only collected if you choose to connect a wearable device or health app (such as Apple Health, Garmin, or Oura) via our integration partner Terra. We may collect:
Your responses to lifestyle and health questionnaires, including information about your habits, goals, and health history. You provide this directly through the Platform.
Page views, feature usage, and interactions with the Platform. This is collected automatically through our analytics tools.
Payment status and transaction records. Card details are processed and stored by our payment provider Stripe - we do not store your full card number.
We do not knowingly collect data from anyone under 18. The Platform requires you to confirm you are at least 18 years old when registering.
Under UK GDPR, we need a lawful basis to process your personal data. Here is how we use your information and the legal grounds:
Creating your account, displaying your health data, generating insights, and managing your membership.
Lawful basis: Contract (Article 6(1)(b))
Analysing your blood test results, wearable metrics, and questionnaire responses to provide personalised insights.
Lawful basis: Explicit consent (Article 9(2)(a))
Handling subscription payments and maintaining billing records.
Lawful basis: Contract; Legal obligation
Analysing usage patterns to fix bugs, improve features, and develop new functionality. Health Data used for this purpose is anonymised or aggregated.
Lawful basis: Legitimate interests (Article 6(1)(f))
Service notifications, health insights, and occasional marketing communications (you can unsubscribe at any time).
Lawful basis: Legitimate interests; Consent for marketing
Responding to legal requests and maintaining required records.
Lawful basis: Legal obligation (Article 6(1)(c))
We take the protection of your Health Data seriously. We do not:
We share your data with the following categories of recipients, all of whom are bound by appropriate data protection agreements:
To process your blood samples and provide results. They receive only the information needed to perform the tests.
Processes card payments securely. Card data is stored in their EU data centres.
Hosts our database infrastructure in EU/UK data centres.
Hosts our website and application infrastructure.
Provides product analytics to help us understand how the Platform is used and improve it.
Connects wearable device data from Apple Health, Garmin, Oura, and other providers if you choose to link them.
We use third-party AI services to generate health insights. Data sent for AI processing is de-identified - your name and contact details are not included in AI requests.
Only where required by law or to protect safety.
We primarily host and process data in the United Kingdom and European Union. Where we need to transfer data outside of the UK (for example, to service providers in the US), we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the UK Government or rely on adequacy decisions where applicable.
We use cookies and similar technologies on our Platform:
You can manage your cookie preferences through your browser settings or our cookie banner.
We retain your data for as long as necessary to provide the Services and fulfil the purposes described in this policy, or as required by law. Specifically:
When you delete your account, we will delete or anonymise your personal data within a reasonable timeframe, except where we are required to retain it by law.
Under UK GDPR, you have the following rights:
To exercise any of these rights, email hello@noyu.health. We will respond within one month.
We take the security of your data seriously and implement appropriate technical and organisational measures:
No system is 100% secure, but we work hard to protect your data and will notify you promptly if a breach occurs that affects your rights.
We aim to make our Platform accessible to everyone, including those with disabilities, in accordance with WCAG 2.1 AA standards. If you have difficulty accessing any part of the Platform or this Privacy Policy, please contact us at hello@noyu.health so we can help.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 30 days before they take effect. Continued use of the Platform after that date means you accept the updated policy.
If you have concerns about how we handle your data, please contact us first at hello@noyu.health. We will do our best to resolve your concerns.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
If you have any questions about this Privacy Policy, please contact us at:
Email: hello@noyu.health
PROJECT 120 LTD
3rd Floor, 86-90 Paul Street
London, EC2A 4NE
United Kingdom