Privacy policy
Effective Date: April 29, 2026
Introduction
Tally Health’s mission is to empower people to live longer, healthier lives.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Policy describes policies and practices regarding Tally Health collection and use of your personal information, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Policy as we undertake new personal information practices or adopt new privacy policies.
This Privacy Policy explains our practices with respect to personal information we collect and process about you through, or in association with, our website with a homepage located at TallyHealth.com and our products and services that we may offer from time to time or otherwise through your interactions with us (collectively, the “Services”).
Effective March 19, 2026, the Tally Health brand and business assets were acquired by IE Tally Holdings, LLC, an affiliate of TruDiagnostic, Inc., a Kentucky-based life sciences company specializing in epigenetic and methylation testing. IE Tally Holdings now owns and operates the Tally Health products and services.
Data Protection Officer
IE Tally Holdings, LLC has designated a Privacy Officer responsible for overseeing compliance with applicable privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Kentucky Consumer Data Protection Act (KCDPA), and other applicable state and federal privacy requirements. For privacy-related inquiries, please contact: Tally Health Privacy Officer at privacy@trudiagnostic.com.
Personal Information We Collect
Tally Health collects information about its website visitors and customers that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual or household (“personal information”).
In the past twelve (12) months, we collected the below categories of personal information from our users:
- Identifiers such as your name, email address, date of birth, phone number, or other similar identifiers.
- Personal information categories listed in the California Customer Records statute (Cal. Civ. Code 1798.80(e)) such as your personal details, demographic information.
- Characteristics of protected classifications under California or federal law such as sex at birth and age.
- Genetic and Health Information. When you purchase, access, and use our TallyAge™ test and use all related platforms, information, and services, you agree to provide and consent that we may collect the following Personal Information:
- Buccal tissue sample. Your tissue sample will be analyzed by Tally Health, our affiliated laboratory partners, and/or our contractors and vendors.
- Genetic Information. “Genetic Information” refers to the genetic and/or epigenetic data including those generated through processing of buccal tissue sample by us or by the Laboratory, our contractors, vendors, successors, assignees, or affiliated laboratory partners, or otherwise processed by and/or contributed to us and includes the results reported to you.
- Health Data. Health Data refers to the following information you provide when using a Tally Health membership, about your diet, mental health, sleep, fitness.
- Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement.
- Inferences drawn from any of the information above and lifestyle surveys that we provide to users.
Tally Health collects and processes the following specific types of Personal Information:
- Registration Information: name, email address, mailing address, date of birth, user ID, password, and payment information provided during account creation or purchases.
- Health and Wellness Information: biological age test results, health questionnaire responses, wellness goals, supplement usage data, and other health-related information you provide through the Services.
- Genetic and Biometric Information: to the extent the Services involve biological sample collection or genetic/epigenetic analysis performed through affiliated laboratory services, methylation biomarkers and related biological data derived from your samples.
- Device and Usage Information: IP address, browser type, operating system, device identifiers, pages viewed, links clicked, and the date and time of your visit.
- Commercial Information: records of products purchased, obtained, or considered, and other purchasing or consuming histories.
- Inferences: information derived from any of the above categories to create a profile reflecting your preferences, characteristics, predispositions, behavior, or attitudes.
How We Collect and Use (Process) Your Personal Information
We collect your personal information from the following categories of sources:
Directly from you. When you provide it to us directly by using the Services;
From third parties. From time to time, Tally Health receives personal information about individuals from third parties. We may also collect your personal information from a third party website (e.g. LinkedIn);
Automatically or indirectly from you. As is true of most other websites, Tally Health’s website collects certain information automatically and stores it in log files.
Tally Health has a legitimate interest in understanding how members, customers, and potential customers use the Services.
In addition, we collect and process your personal information for the following business and commercial purposes:
- Providing, predicting, or performing, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, and processing payments (however, payments are processed through Shopify so that we do not receive your full payment card details. Please refer to Shopify’s privacy policy).
- Marketing our products and services to you and others, including sending you messages about our products, services, and events.
- Communicating with you by email, SMS, postal mail, and other methods of communication, about products, subscriptions, services, order status, and information tailored to your requests or inquiries.
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
- Debugging to identify and repair errors that impair existing intended functionality.
- Undertaking internal research for technological development and demonstration.
- Undertaking activities to verify or maintain the quality or safety of the services or devices owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the services or devices owned, manufactured, manufactured for, or controlled by us.
- Complying with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, or for other purposes, as permitted or required by law.
- As necessary or appropriate to protect the rights, property, and safety of our users, us, and other third parties.
- Integrating Tally Health services with affiliated epigenetic testing platforms, laboratory infrastructure, and research programs, consistent with your consent, applicable intercompany agreements, and applicable law.
Cookies and Tracking Technologies
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. “Cookies” are pieces of information that may be placed on your computer by a website for the purpose of collecting data to facilitate and enhance your communication and interaction with that website.
We and our third-party service providers use the following types of cookies and tracking technologies: (a) Strictly Necessary Cookies, which are essential for the Services to function properly; (b) Functional Cookies, which remember your preferences and settings; (c) Analytics Cookies, including Google Analytics, which help us understand how visitors interact with the Services by collecting and reporting information anonymously; and (d) Advertising Cookies, which are used to deliver advertisements relevant to you and to measure the effectiveness of advertising campaigns. You may control cookies through your browser settings. For more information about Google Analytics and how to opt out, visit https://tools.google.com/dlpage/gaoptout.
Sharing Information with Third Parties
The personal information Tally Health collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval.
We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our Services, such as the labs who process and analyze user samples, courier companies, and hosting providers.
Tally Health does not sell your Personal Information and does not share your Personal Information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act.
A list of our primary third party service providers can be found here:
- Shopify: Our e-commerce platform provider and payment processor.
- Strategic Lab Partners: Our shipping and logistics partner.
Affiliated Companies: IE Tally Holdings may share personal information with its corporate affiliates as necessary to provide the Services, subject to the terms of this Privacy Policy and applicable intercompany data sharing agreements. Any affiliate receiving personal information is bound by obligations at least as protective as those set forth in this Privacy Policy.
In addition, we may, in the future, sell or otherwise transfer some or all of our business, operations or assets to a third party, whether by merger, acquisition or otherwise. Personal information we obtain from or about you via our website may be disclosed to any potential or actual third-party acquirers and may be among those assets transferred.
International Use
Information we collect about you will be processed in the United States. By using Tally Health’s services, you acknowledge that your personal information will be processed in the United States.
Your Privacy Rights
U.S. State Law Privacy Rights
The California Consumer Privacy Act of 2018 and its successor legislation (as amended by the California Privacy Rights Act, or CPRA), and similar laws in other U.S. states including the Kentucky Consumer Data Protection Act (KCDPA), (collectively, “Applicable State Laws”) provide certain residents with specific rights regarding their personal information, which are as follows:
- Right to Know: You have the right to request that we disclose certain information to you about the personal information we collected, used, disclosed, and sold about you in the past 12 months.
- Data Portability: You have the right to request a copy of personal information we have collected and maintained about you in the past 12 months.
- Right to Deletion: You have the right to request that we delete the personal information we collected from you and maintained, subject to certain exceptions. Exceptions include data required for historical logging and audit trails, data required for HIPAA compliance, and data subject to research exemptions under applicable law.
- Right to Correction: You have the right to correct inaccurate personal information that we have collected and maintain about you.
- Right to Opt-Out of Sales: You have the right to opt-out of the sale of your personal information; however, we do not “sell” personal information, as that term is defined under Applicable State Laws.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights under Applicable State Laws.
- Right to Limit Use of Sensitive Personal Information (CPRA): California residents have the right to direct us to limit our use and disclosure of Sensitive Personal Information (“SPI”) — which includes genetic data, health data, and biometric information — to uses necessary to perform the services you have requested, or as otherwise permitted under CPRA regulations. To exercise this right, please visit our Privacy Choices page or contact us at privacy@trudiagnostic.com.
- Right to Opt-Out of Sharing for Cross-Context Behavioral Advertising (CPRA): California residents have the right to opt-out of the sharing of personal information for cross-context behavioral advertising.
- Kentucky Consumer Data Protection Act (KCDPA) Rights: Kentucky residents have the right to: (1) confirm whether we are processing your personal data; (2) access your personal data; (3) correct inaccuracies in your personal data; (4) delete personal data you have provided or that we have obtained about you; (5) obtain a portable copy of your personal data; and (6) opt out of processing of your personal data for purposes of targeted advertising, sale of personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. To exercise these rights, please contact us at privacy@trudiagnostic.com.
HIPAA Notice and Integration with TruDiagnostic Health Programs
To the extent that any health information collected through Tally Health’s services meets the definition of Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its implementing regulations, such information will be handled in accordance with applicable HIPAA Privacy and Security policies and procedures. Tally Health products are designed as consumer wellness tools and are not intended to create a covered entity relationship.
For questions about how your health information may be governed under HIPAA, please contact the Tally Health Privacy Officer at privacy@trudiagnostic.com.
Security of Your Information
We use reasonable and appropriate physical, technical, and organizational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of personal information. Those safeguards include: (i) the pseudonymization and encryption of personal information where we deem appropriate; (ii) taking steps to ensure personal information is backed up and remains available in the event of a security incident; and (iii) periodic testing, assessment, and evaluation of the effectiveness of our safeguards.
As part of IE Tally Holdings’ enterprise security program, Tally Health operations are subject to information security policies and procedures consistent with those maintained by its corporate affiliates, including those required under the HIPAA Security Rule (45 CFR Part 164, Subpart C) to the extent applicable.
Data Storage and Retention
Your personal information is stored on servers and cloud-based infrastructure located in the United States, operated by Tally Health and/or its authorized service providers. We retain service data for the duration of your business relationship with us and for a period of time thereafter, consistent with applicable legal requirements (including HIPAA retention requirements where applicable), to analyze the data for our own operations, and for historical and archiving purposes. Genetic and health data may be subject to longer retention periods as required by law or as necessary for ongoing research programs to which you have consented.
Tally Health retains Personal Information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Specific retention periods include: (a) account and registration information is retained for the duration of your account and for a reasonable period thereafter; (b) health and wellness data is retained for the duration of your account and for a period of three (3) years following account deletion to comply with applicable health data retention requirements; (c) genetic or biometric data, if applicable, is retained as required by CLIA regulations and applicable state law; (d) transaction records are retained for seven (7) years for tax and accounting purposes; and (e) aggregated or de-identified data may be retained indefinitely.
Children’s Data
We do not knowingly attempt to solicit or receive information from children under the age of 18. By using the Services, you represent that you are 18 years of age or older.
Communications Opt-Out
You may opt out of receiving marketing or other communications from us at any time through a given communications channel (such as email) by following the opt-out link or other unsubscribe instructions provided in any email message received, or by contacting us as provided at the end of this Privacy Policy.
Modification and Updates
This Privacy Policy replaces all previous disclosures we may have provided to you about our information practices with respect to the Services and the Tally Health website. We reserve the right, at any time, to modify, alter, and/or update this Privacy Policy, and any such modifications, alterations, or updates will be effective upon our posting of the revised Privacy Policy.
Questions, Concerns, or Complaints
If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:
Tally Health (owned and operated by IE Tally Holdings, LLC)
228 Park Avenue South
PMB 28994
New York, NY 10003
hello@tallyhealth.com
tallyhealth.com