Privacy Policy

Privacy Policy

Last updated: September 26, 2026

Your privacy matters to us. This policy explains how Testra collects, uses, protects, and manages your information.

Your privacy matters to us. This policy explains how Testra collects, uses, protects, and manages your information.

Testra Privacy Policy

Effective date: SEPTEMBER 26, 2026

1. Who we are and what this Policy covers

Testra is operated by Chase Company Inc. ("Testra," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, protect, retain, and delete personal information through our website, application, and related support services (the "Service").

Testra helps adults organize and understand bloodwork through report uploads, biomarker extraction, historical records, the Testra Score, educational explanations, hormone-protocol logging, symptom check-ins, and AI chat. Information about these features applies when you use them. Testra provides education and personal recordkeeping, not medical diagnosis, prescribing, or treatment.

Our consumer Service is offered in English to eligible adults in Canada, excluding Quebec, and the United States. We do not currently offer accounts to residents of Quebec, the European Economic Area, or the United Kingdom. These availability restrictions do not remove any privacy rights that legally apply to information we receive, including information submitted through the public website.

Chase Company Inc. is responsible for personal information under its control. Our Privacy Officer can be contacted at:

Email: testra.support@chasecompanyinc.com
Mail: Privacy Officer, Chase Company Inc., 2157 Phelan Road West

This Policy describes our information practices. It is not a request for blanket consent. Accepting our Terms or viewing this Policy does not replace a separate consent or authorization required by law.

2. The information we collect and why

Personal information includes information that identifies you or can reasonably be linked to you. Health information includes both information you provide and information we derive, such as a score, trend, or inference.

Account information

We collect your name, email address, age, authentication information, account preferences, and consent records when you register or interact with account settings. Country and province/state information may be requested to determine eligibility and applicable requirements. We use this information to create and protect your account, communicate with you, apply appropriate educational context, and record your choices.

Uploaded bloodwork

When you upload a PDF or photograph, we receive the file and its included information and metadata. Reports may contain names, birth dates, addresses, patient or health-card numbers, laboratory and clinician details, collection dates, biomarker values, units, reference intervals, flags, and clinical notes.

We use uploaded reports to maintain your personal vault, extract and organize results, display trends, and generate the educational outputs you request. We do not need government identity numbers, health-card numbers, or unrelated third-party information for scoring. Please remove unnecessary identifiers before uploading where practicable. Upload only your own records.

Reports from LifeLabs, Dynacare, or another laboratory are received from you. Your upload does not automatically connect us to the laboratory or give us access to its other records.

Extracted results, scores, and inferences

We derive structured biomarker values, units, dates, reference intervals, calculations, classifications, priority indicators, trends, Testra Scores, and educational explanations. These are used to organize and explain the information available in your account. We protect these outputs as health information even when they are generated automatically or may be inaccurate.

Protocols and symptoms

We collect the hormone or TRT details you choose to enter, including compounds, testosterone ester, dose, injection frequency or timing, ancillary medications, and symptom responses. These entries may reveal prescription or nonprescribed substance use, reproductive or sexual health, mood, and other sensitive information.

We use them to maintain your records and provide context for requested educational features. We do not use protocol entries to determine employment, credit, insurance eligibility, or eligibility for healthcare.

AI conversations

We collect questions, messages, relevant conversation history, AI responses, and feedback you submit. We use them to answer your questions, provide relevant context, retain conversations for your review, and investigate specific support or safety concerns. Please do not include another person's health records, passwords, or payment-card details in chat.

Payments

Stripe processes payment information for purchases made through our Stripe checkout. We receive information needed to manage the purchase, such as customer and subscription identifiers, payment status, amount, currency, invoice details, and limited payment-method information. We use this to provide paid access, manage subscriptions, issue refunds, prevent fraud, and maintain accounting records.

Complete payment-card numbers and card security codes are handled by the payment processor rather than stored in Testra's application database. We do not send bloodwork values, medication entries, symptoms, or chat contents to Stripe for payment processing. If a purchase is made through an app store, that store handles payment under its own notice; Testra receives transaction and entitlement information needed to provide access.

Device, usage, and security information

When you use the Service, our systems receive technical information such as IP address, browser or device type, operating system, app version, session identifiers, request times, login events, and error information. We use necessary technical information to deliver the Service, authenticate access, prevent abuse, and investigate failures.

Usage analytics may record feature interactions, such as whether an upload completed, to assess reliability and usability. We exclude report contents, biomarker values, medication doses, symptoms, and chat text from routine analytics and error logs. Account-linked usage can itself reveal a health interest and is protected accordingly.

We do not request precise GPS location, collect address books, or perform biometric identification. A photograph of a report is used to process that report, not for facial recognition. IP addresses may indicate approximate location.

Support and compliance information

We collect information you provide in support correspondence, complaints, privacy requests, consent selections, and billing disputes. We use it to respond, verify authority where necessary, resolve issues, and document compliance. We ask for only the information reasonably necessary for the request.

3. How collection occurs and how consent works

We collect information directly through registration, forms, uploads, protocol entries, symptom responses, chats, purchases, and support communications; automatically through necessary technical operations and permitted analytics; and by deriving outputs from your information. Payment providers supply transaction records. We do not buy health profiles from data brokers or retrieve records from a clinician or laboratory merely because you name them.

Before processing sensitive health information on the basis of consent, we explain the relevant categories, purposes, and recipients and obtain the affirmative consent required by law. Where separate consent is required for sharing, that consent is distinct from collection consent. Optional tracking and marketing choices are not preselected or bundled into consent needed for the core Service.

You can decline optional fields and features. Without a report, we cannot analyze that report; without permission for AI processing needed for a requested feature, we cannot provide that feature. We do not require unrelated sensitive information as a condition of basic account administration.

Withdraw consent by emailing testra.support@chasecompanyinc.com. We explain the effects and stop the affected consent-based processing. Withdrawal does not make earlier lawful processing unlawful, and it does not prevent a separately authorized legal retention obligation. You can also request deletion. We do not use withdrawal as a reason to impose a penalty or deny unrelated rights.

4. AI processing and automated outputs

Testra uses commercial AI APIs from Anthropic, the provider of Claude, and/or OpenAI for extraction and educational responses. Depending on the feature, data sent to an API may include the uploaded report or relevant portions, extracted results, age-related context, protocol and symptom entries, your question, relevant conversation history, and technical identifiers needed to return the answer. A report may identify you even when your account name is not separately included.

We limit the information sent to what is reasonably necessary for the requested task. We do not use consumer chatbot accounts as the processing channel for your records. AI processing is disclosed before you submit health information for the relevant feature, with consent obtained where required.

We do not sell health information to AI providers or authorize its use to train their general-purpose models. We do not use your identifiable health records or conversations to train our own models or conduct unrelated research without separate, specific permission. Reporting a bad answer does not itself give that permission.

API providers may retain content or technical records for service operation, security, abuse prevention, and legal obligations under the applicable API arrangements. Retention depends on the provider, endpoint, and enabled features. We do not promise that every API request has zero retention or that deleting a conversation from Testra instantly removes every provider-held copy. Our deletion process includes relevant provider-held content to the extent required by law and within the scope of our processing arrangements. Contact the Privacy Officer for information about the arrangements applicable to your data.

Scores, rankings, and educational classifications are produced using the available inputs and Testra's methodology; AI may generate associated explanations. These activities can constitute profiling of health information. We do not use them to make decisions about insurance, employment, lending, or access to treatment. You may request correction of inaccurate inputs and information about the principal factors behind a result. A review by support staff is not a clinical assessment.

5. Who receives information

We do not sell personal information or consumer health data, rent health records, or share personal information for cross-context behavioral advertising. We do not provide health records to advertisers, data brokers, employers, or insurers for their independent use.

We disclose information only for the following purposes and subject to applicable consent and legal requirements:



RecipientInformation and purposeSupabaseAccount information, uploads, extracted values, protocol and symptom entries, chats, and outputs for database operations, authentication, private file storage, and recovery services used by Testra.Anthropic and/or OpenAIThe content described in Section 4 to perform requested AI processing and associated limited security functions.VercelWebsite and application requests, relevant processing data, and necessary technical information to host and deliver the Service. Requests can contain health data when a feature requires server-side processing.Stripe or the app store through which you purchasePurchase, subscription, transaction, billing, and fraud-prevention information, as explained in Section 2.Authorized personnel and contracted technical supportInformation necessary to address a particular support request, maintain the Service, investigate an incident, or fulfill a privacy obligation. Access must be limited to the assigned task.Professional advisersInformation necessary for legal, accounting, or compliance work. Routine financial accounting does not require your laboratory reports.A recipient you direct us to contactOnly information within your valid, specific sharing instruction and any required authorization.Authorities or a qualifying business successorOnly under Sections 6 and 7.

Processors must act under appropriate contractual restrictions addressing confidentiality, security, permitted purposes, incident reporting, assistance with rights requests, and retention or deletion. Approved subprocessors are subject to corresponding obligations. A provider is not authorized to use health information for unrelated advertising or independent profiling merely because it helps operate Testra.

Some recipients, including payment providers, separately determine processing necessary for their own legal duties. Their independent activities are governed by their own privacy notices, including Stripe's Privacy Policy. Those notices do not expand Testra's permission to share health data.

We do not routinely share health information with corporate affiliates. We do not disclose records to a family member, clinician, coach, or laboratory merely because that person claims a relationship with you. Files you download and share yourself leave Testra's controls.

6. Legal requests and protection of rights

We review legal demands for validity, jurisdiction, and scope and require appropriate legal process where necessary. We disclose only information required or permitted by the applicable law. We seek clarification or narrowing of disproportionate or defective requests where appropriate.

We do not voluntarily provide lists of people using TRT or performance-enhancing compounds to law enforcement for general investigative purposes. A record of substance use is not, by itself, a reason for us to report you.

Where legally permitted and practicable, we notify an affected user of a demand before disclosure, unless notice would create a material safety risk or compromise a legally protected investigation. We may preserve information in response to a valid preservation obligation without disclosing it until disclosure is separately authorized.

We may disclose strictly necessary information to address fraud or an attack on the Service, establish or defend legal claims, or respond to a specific serious threat when legally permitted or required. We apply additional restrictions governing health information. This provision does not authorize routine monitoring of medical emergencies or unrestricted disclosure to authorities.

7. Business transactions

If Testra is involved in an acquisition, merger, financing, reorganization, or insolvency proceeding, we use aggregated or redacted information wherever practicable. Identifiable information may be disclosed only as legally permitted and necessary, under restrictions on use, access, protection, and return or destruction if the transaction does not proceed.

A successor receiving information must respect the applicable privacy commitments and legal obligations. We provide required notice and obtain required consent before a new or incompatible use. We do not offer health records as a standalone asset for unrelated exploitation. A business transaction does not override a statutory prohibition on selling or disclosing health data.

8. Storage and international processing

Testra operates from Canada and uses the service providers identified above. Information may be stored, transmitted, or processed outside your province, state, or country, including in the United States. Provider infrastructure, authorized subprocessors, and authorized support personnel may operate in additional countries. Remote access from another country is also a cross-border processing activity, even if the underlying database stays in one location.

We do not promise that all information remains in Canada or that every copy stays in a single country. We limit cross-border processing to authorized service purposes and apply appropriate contractual and security safeguards. We remain responsible for information under our control when a processor handles it on our behalf.

Foreign courts, regulators, law enforcement, or national-security authorities may lawfully access information under the laws of their jurisdiction. Those laws may differ from your local laws. Contractual protections cannot prevent every legally required disclosure.

Contact testra.support@chasecompanyinc.com for information about the processing locations and safeguards applicable to your records, or questions about our use of service providers outside Canada. If a change materially affects the disclosed processing or requires new consent, we provide the applicable notice and obtain that consent before the new processing begins.

9. Security

We apply administrative, technical, and organizational safeguards appropriate to sensitive health information. Our security requirements include:

  • Encryption of stored health data, uploaded reports, and retained backups using AES-256.

  • Encryption in transit using HTTPS/TLS 1.2 or later, including connections carrying health data to AI processors.

  • Private storage and user-specific database and file-access permissions.

  • Restricted administrative access, multifactor authentication for privileged accounts, and controlled handling of secret API keys.

  • Limiting access to authorized personnel with a service-related need and confidentiality obligations.

  • Excluding health content from routine analytics and error logs; any exceptional incident evidence containing such content receives restricted access and purpose-limited retention.

  • Reviewing access permissions and security configurations and testing that users cannot access other users' records.

Encryption is not end-to-end encryption: authorized systems must decrypt relevant information to perform extraction, scoring, storage retrieval, and AI processing. Authorized access may also be necessary for support, security, or legal compliance. Encryption does not make data anonymous.

No service can guarantee absolute security. That limitation does not reduce our obligation to use appropriate safeguards or meet applicable law. Please protect your credentials and devices and report suspected unauthorized access to testra.support@chasecompanyinc.com.

10. Retention and deletion

We retain personal information only for its disclosed purposes and permitted legal obligations. Retention depends on the record and purpose, as follows:



InformationRetention criteriaAccount profileWhile the account remains open and needed to provide it; removed following account deletion, except narrowly required compliance records.Reports, biomarkers, protocols, symptoms, scores, and conversationsWhile you maintain them in your account for the requested historical archive, unless you request earlier deletion or retention is no longer necessary for that purpose.AI-provider copiesOnly for processing purposes permitted under Section 4 and the relevant service arrangements, subject to applicable deletion obligations.Routine security and technical recordsOnly while needed to operate, troubleshoot, and protect the Service; incident-specific evidence is retained only while the investigation, remediation, or applicable legal need continues.Usage analyticsOnly while needed for the identified reliability or usability purpose, after which account-linked records are deleted or effectively de-identified.Support correspondenceWhile the request is being resolved and afterward only as necessary to address related follow-up or a documented dispute. Unnecessary medical attachments are removed earlier.Transaction and tax recordsFor the statutory accounting or tax-retention period applying to the record. Keeping an invoice does not require keeping bloodwork.Consent, rights-request, and incident recordsFor the period required to demonstrate compliance or meet a specific statutory recordkeeping obligation. PIPEDA breach records are retained for at least 24 months where that requirement applies.

The vault is an ongoing personal archive, not an unconditional promise of permanent storage. Canceling a subscription does not automatically request deletion. You can request deletion of specific records or your whole account at testra.support@chasecompanyinc.com. We do not keep an entire health history indefinitely merely because a transaction record must be retained.

We act on valid deletion requests without undue delay and within the applicable legal requirements. Deletion covers relevant active records and associated derived information, and we instruct processors and other recipients to delete information where required. Tell us if you want related chats deleted as well as a report: deleting a report alone may not identify a separate conversation into which you copied its contents.

When immediate deletion from a disaster-recovery backup is not technically feasible and deferred deletion is lawful, the information is restricted from ordinary use and removed through the applicable backup-deletion cycle within the legal deadline. If a backup is restored, deletion instructions are reapplied. Where Washington's health-data law applies, a permitted backup-deletion delay never exceeds six months after authentication of the request.

We may retain specific information longer only for a legally permitted, documented reason, such as a binding preservation requirement or a necessary legal claim. Retained material is restricted to that purpose and deleted when the reason ends. We explain applicable exceptions unless prohibited by law. An exception available under one law is not used to defeat a stricter applicable health-data rule.

11. Cookies, analytics, and communications

Necessary cookies, local storage, and similar technologies support login, security, checkout, and privacy preferences. Blocking them may prevent those functions. Device permissions for selecting a photograph or file allow the requested upload; they do not authorize unrelated access to your photo collection.

Optional analytics technologies are used only with the consent or other permission required by law. Before optional tracking that requires consent begins, we explain its purpose and provide a choice. You may withdraw consent through an available privacy control or by contacting us. Necessary security processing continues where lawfully required to operate the Service.

We do not use health records or chat contents for targeted advertising. We do not permit advertising pixels, session replay, or keystroke recording within authenticated health-record screens. We do not use healthcare-facility geofences to identify or target people seeking care.

We honor applicable opt-out preference signals, including Global Privacy Control, for activities subject to those signals. We do not sell information or engage in cross-context behavioral advertising even without a signal. Browser Do Not Track settings do not disable necessary authentication or security operations.

Account, billing, privacy, and security notices are service communications. Promotional messages are sent only as permitted by law and include an unsubscribe method. Opting out of marketing does not stop necessary account notices. Routine email and notification previews do not need to include your biomarker values or medication details, and we minimize sensitive content in those channels.

12. Your choices and rights

You may request access to your personal information, correction of inaccurate information, deletion, an electronic copy or export, and withdrawal of consent. Depending on applicable law, you may also have rights to restrict or object to processing, obtain recipient information, limit certain sensitive-information uses, opt out of sale or targeted advertising, and appeal a refusal.

Send requests to testra.support@chasecompanyinc.com, using the subject "Privacy request," or write to the Privacy Officer at 2157 Phelan Road West. Include your account email and the action requested. Do not send laboratory reports or identity documents in an initial message unless necessary; we will arrange proportionate verification.

We use reasonable methods to verify identity before releasing, changing, or deleting sensitive records. Verification may use your existing account or registered email. We request additional evidence only when reasonably necessary and use it for verification, not another purpose. You do not need to create a new account. Authorized agents may submit requests with appropriate proof of authority, and we respect valid powers of attorney. We do not impose verification on an opt-out where the law prohibits it.

An access response explains relevant information held, purposes, and disclosures. Where applicable, exports include original reports and available structured information in a commonly used electronic format. Proprietary scoring code is not part of your personal-data export, but we do not withhold your underlying values simply because they contribute to a proprietary score.

A correction to an extracted value does not silently alter the original laboratory report. You may provide a corrected report or request an annotation. We cannot change the laboratory's own records; contact the laboratory for corrections to its source document.

Requests are ordinarily free. Any fee or refusal based on an excessive or unfounded request must be permitted by the applicable law, supported by reasons, and communicated in advance where required. We do not discriminate against you for exercising rights. A feature may become unavailable if it cannot operate without information you ask us to stop processing.

13. Response times, appeals, and complaints

We respond within the period required by the applicable law:

  • Canadian access requests: Generally within 30 days. We use an extension only when the applicable statute permits it and provide the required notice and reasons.

  • California requests to know, correct, or delete: Within 45 days, with a further 45 days only when legally permitted and explained within the initial period. We acknowledge receipt within 10 business days where required.

  • Washington consumer-health requests: Within 45 days, with one permitted 45-day extension explained within the initial period.

  • Other applicable laws: Their specific deadlines and extension conditions apply, including a shorter period where required.

We begin verification promptly; verification does not automatically restart a statutory deadline. An acknowledgment is not a substitute for completing the request.

If we cannot fully comply, we explain the lawful reason, any partial action, and your appeal or complaint route. To appeal, email testra.support@chasecompanyinc.com with the subject "Privacy appeal." We provide a written decision within 45 days or any shorter applicable period and explain how to contact the relevant regulator if the appeal is denied. You do not need to complete our appeal process before exercising a right to complain directly to a regulator.

Canadian users can contact the Office of the Privacy Commissioner of Canada or their competent provincial commissioner. U.S. users can contact their state attorney general, the Federal Trade Commission, or an applicable state privacy authority. The relevant authority depends on the matter and governing law.

14. Canadian privacy and health-information laws

We process information in accordance with PIPEDA where it applies and applicable provincial privacy legislation, including relevant Alberta and British Columbia requirements. Our Privacy Officer handles questions concerning outside-Canada service providers, safeguards, consent, access, and complaints.

Health information is treated as sensitive. Its presence in an educational app does not make it ordinary marketing data. We apply reasonable collection limits, appropriate consent, restricted disclosure, safeguards, and access and correction procedures.

Ontario's Personal Health Information Protection Act, 2004 (PHIPA) applies according to the legal role and activity involved. The direct-to-consumer Service does not create a healthcare-provider relationship, and a user upload does not by itself establish that Testra is a health information custodian. Where a particular activity brings Testra within PHIPA obligations, those obligations govern that activity. We do not represent this Policy as a PHIPA certification or as a healthcare custodian's notice on behalf of your clinician.

15. California and other U.S. privacy rights

For California residents, the categories of information addressed by this Policy include identifiers and account information; customer and transaction records; age and other characteristics contained in submitted records; internet or device activity and approximate IP-derived location; uploaded electronic records; health and other sensitive information, including account-access credentials; and inferences derived from these categories.

Section 2 identifies the categories and sources, Sections 2–5 explain purposes and recipients, and Section 10 explains retention criteria. These descriptions cover our current practices and the applicable categories handled during the preceding 12 months, or since the relevant feature began if shorter. We do not sell or share any category for cross-context behavioral advertising, including information about minors, and do not offer payment or discounts in exchange for health-data rights.

Where the California Consumer Privacy Act, as amended by the CPRA, applies, you have rights to know, access, correct, delete, obtain portable information, opt out of sale or sharing, limit qualifying sensitive-information uses, and receive nondiscriminatory treatment. Our sensitive-information uses are confined to requested services and other legally permitted purposes; a new use requiring an additional choice will not begin without that choice. Use Section 12's request process and Section 13's timelines. You may complain to the California Privacy Protection Agency or California Attorney General.

Other applicable state privacy, medical-confidentiality, and consumer-health laws remain effective, including relevant Nevada and Connecticut protections and California medical-information law. We honor applicable access, correction, deletion, consent, appeal, and opt-out rights through the same contact routes. Information generated within Testra does not lose health-data protection simply because it is an inference. Nothing in this Policy waives statutory rights or relies on a blanket exemption for all health information.

HIPAA applies to specified entities and activities, not every health app. We do not represent that ordinary consumer records in Testra automatically receive HIPAA coverage. A separate covered-entity or business-associate arrangement would require its own assessment and applicable agreements. Other privacy protections continue to apply whether or not HIPAA applies.

16. Consumer Health Data Privacy Notice

This notice describes our consumer-health practices, including those relevant to Washington's My Health My Data Act and Nevada's consumer-health provisions. It must be read as a specific health-data notice, not as permission for additional uses.

Information and sources. We collect your uploaded reports and associated identifiers, biomarkers, protocol and medication entries, symptoms, chat content, generated scores and explanations, and linked account or usage information that reveals health status or seeking health services. Sources are you, the records you upload, your interactions, and the results or inferences we generate.

Uses. We use these categories to provide your requested archive, extraction, trends, scoring, education and chat, and necessary support, security, and rights handling. We obtain the consent required for collection and use. Where a law permits processing necessary to provide a requested service without separate consent, we apply that exception only within its legal scope.

Disclosures. Reports and health records are processed by Supabase for storage and database services, by Vercel when needed for application delivery, and by Anthropic and/or OpenAI for the AI functions described in Section 4. Authorized technical support, security providers, and professional advisers receive only task-necessary categories. Other disclosures are limited to your valid directions, lawful demands, and qualifying transactions described above. We obtain separate sharing consent where required. There is no routine affiliate sharing and no sale of consumer health data.

Rights. Request confirmation of collection or sharing, access, deletion, or consent withdrawal at testra.support@chasecompanyinc.com, or write to the Privacy Officer, Chase Company Inc., 2157 Phelan Road West. Washington consumers may obtain a list of third parties and affiliates with whom their consumer health data was shared or sold and a contact mechanism for those recipients. No new account is required. Requests and appeals follow Section 13.

Deletion. We notify the processors and other recipients required to honor a deletion request. Applicable deletion duties include backups, subject only to permitted delays and exceptions. Washington's permitted archival or backup delay cannot exceed six months after authentication.

Appeals and changes. Appeal by emailing testra.support@chasecompanyinc.com with "Privacy appeal." Washington appeals receive a decision within 45 days and a route to the Washington Attorney General's complaint process if denied. Nevada consumers can also request review of a refusal using this contact. Material changes are communicated under Section 20; new health-data categories or purposes receive the advance disclosure and consent required by law.

17. Security incidents

We assess suspected unauthorized access, loss, use, or disclosure; take reasonable containment and corrective measures; coordinate with relevant processors; and document the response. Unauthorized disclosures to a vendor or tracking service can be an incident even without a malicious intrusion.

Under PIPEDA, where a breach creates a real risk of significant harm, we report to the federal Privacy Commissioner and notify affected individuals as soon as feasible after determining that threshold is met. We also notify other organizations or government institutions when required to reduce harm and keep the required breach records.

Where the FTC Health Breach Notification Rule applies, individual notice is given without unreasonable delay and no later than 60 calendar days after discovery. FTC notice for breaches involving 500 or more individuals accompanies individual notice; reportable smaller breaches are reported within 60 calendar days after the calendar year ends. Required media and substitute notices are provided when their conditions apply.

We comply with other applicable state and provincial notification rules, including shorter deadlines and additional regulator notices. A lawful delay is used only when its requirements are satisfied. Notices explain the incident, affected information, response, protective steps, and a contact route, with any additional information required by law. The existence of a maximum deadline does not justify unnecessary delay.

18. Children and ineligible users

The Service is intended for adults who are at least 18 and have reached the age of majority where they reside. We do not knowingly collect children's health records, allow accounts for minors, or invite parents to upload a child's records. Do not submit a minor's report through your account.

If we discover information collected from an ineligible child, we restrict processing and delete it unless narrowly required to meet a binding legal duty or document the response. A parent or guardian can notify testra.support@chasecompanyinc.com without including unnecessary medical details. We do not treat an age statement alone as permission to ignore evidence that a user is a child.

19. De-identified information and external services

We may use technical statistics that have been aggregated or de-identified to understand reliability and performance only where the applicable standard prevents reasonable association with an individual. Removing a name or replacing it with a code does not by itself make health information anonymous. We do not attempt to re-identify genuinely de-identified data except where expressly permitted to assess the effectiveness of de-identification, and require corresponding restrictions on authorized recipients.

This provision does not authorize conversion of your health records into an unrelated research or commercial dataset or circumvention of a pending deletion request.

External laboratories, clinicians, payment services, and websites maintain their own records and policies. We are responsible for our own handling and our processors' activities as required by law; we cannot change a laboratory's independent records merely because you delete an uploaded copy from Testra.

20. Changes to this Policy

We update this Policy when practices or applicable requirements change and identify the new effective date. Material changes are communicated through a prominent website or app notice and, when appropriate or legally required, direct email before they take effect. We review the accuracy of our disclosures at least annually.

Before collecting a new health-data category or using or sharing health information for a new purpose, we provide the required disclosure and obtain fresh consent when required. Continued use is not a substitute for that consent. Updates do not retroactively authorize a use or disclosure that was previously prohibited.

21. Contact

For privacy questions, access, correction, deletion, consent withdrawal, appeals, or suspected security incidents, contact:

Privacy Officer
Chase Company Inc., operating as Testra
Email: testra.support@chasecompanyinc.com
Mail: 2157 Phelan Road West

Please identify the request and your account email, but avoid including unnecessary health records or identity documents in an initial message. We will arrange any verification or secure information exchange needed to address it.

Testra Privacy Policy

Effective date: SEPTEMBER 26, 2026

1. Who we are and what this Policy covers

Testra is operated by Chase Company Inc. ("Testra," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, protect, retain, and delete personal information through our website, application, and related support services (the "Service").

Testra helps adults organize and understand bloodwork through report uploads, biomarker extraction, historical records, the Testra Score, educational explanations, hormone-protocol logging, symptom check-ins, and AI chat. Information about these features applies when you use them. Testra provides education and personal recordkeeping, not medical diagnosis, prescribing, or treatment.

Our consumer Service is offered in English to eligible adults in Canada, excluding Quebec, and the United States. We do not currently offer accounts to residents of Quebec, the European Economic Area, or the United Kingdom. These availability restrictions do not remove any privacy rights that legally apply to information we receive, including information submitted through the public website.

Chase Company Inc. is responsible for personal information under its control. Our Privacy Officer can be contacted at:

Email: testra.support@chasecompanyinc.com
Mail: Privacy Officer, Chase Company Inc., 2157 Phelan Road West

This Policy describes our information practices. It is not a request for blanket consent. Accepting our Terms or viewing this Policy does not replace a separate consent or authorization required by law.

2. The information we collect and why

Personal information includes information that identifies you or can reasonably be linked to you. Health information includes both information you provide and information we derive, such as a score, trend, or inference.

Account information

We collect your name, email address, age, authentication information, account preferences, and consent records when you register or interact with account settings. Country and province/state information may be requested to determine eligibility and applicable requirements. We use this information to create and protect your account, communicate with you, apply appropriate educational context, and record your choices.

Uploaded bloodwork

When you upload a PDF or photograph, we receive the file and its included information and metadata. Reports may contain names, birth dates, addresses, patient or health-card numbers, laboratory and clinician details, collection dates, biomarker values, units, reference intervals, flags, and clinical notes.

We use uploaded reports to maintain your personal vault, extract and organize results, display trends, and generate the educational outputs you request. We do not need government identity numbers, health-card numbers, or unrelated third-party information for scoring. Please remove unnecessary identifiers before uploading where practicable. Upload only your own records.

Reports from LifeLabs, Dynacare, or another laboratory are received from you. Your upload does not automatically connect us to the laboratory or give us access to its other records.

Extracted results, scores, and inferences

We derive structured biomarker values, units, dates, reference intervals, calculations, classifications, priority indicators, trends, Testra Scores, and educational explanations. These are used to organize and explain the information available in your account. We protect these outputs as health information even when they are generated automatically or may be inaccurate.

Protocols and symptoms

We collect the hormone or TRT details you choose to enter, including compounds, testosterone ester, dose, injection frequency or timing, ancillary medications, and symptom responses. These entries may reveal prescription or nonprescribed substance use, reproductive or sexual health, mood, and other sensitive information.

We use them to maintain your records and provide context for requested educational features. We do not use protocol entries to determine employment, credit, insurance eligibility, or eligibility for healthcare.

AI conversations

We collect questions, messages, relevant conversation history, AI responses, and feedback you submit. We use them to answer your questions, provide relevant context, retain conversations for your review, and investigate specific support or safety concerns. Please do not include another person's health records, passwords, or payment-card details in chat.

Payments

Stripe processes payment information for purchases made through our Stripe checkout. We receive information needed to manage the purchase, such as customer and subscription identifiers, payment status, amount, currency, invoice details, and limited payment-method information. We use this to provide paid access, manage subscriptions, issue refunds, prevent fraud, and maintain accounting records.

Complete payment-card numbers and card security codes are handled by the payment processor rather than stored in Testra's application database. We do not send bloodwork values, medication entries, symptoms, or chat contents to Stripe for payment processing. If a purchase is made through an app store, that store handles payment under its own notice; Testra receives transaction and entitlement information needed to provide access.

Device, usage, and security information

When you use the Service, our systems receive technical information such as IP address, browser or device type, operating system, app version, session identifiers, request times, login events, and error information. We use necessary technical information to deliver the Service, authenticate access, prevent abuse, and investigate failures.

Usage analytics may record feature interactions, such as whether an upload completed, to assess reliability and usability. We exclude report contents, biomarker values, medication doses, symptoms, and chat text from routine analytics and error logs. Account-linked usage can itself reveal a health interest and is protected accordingly.

We do not request precise GPS location, collect address books, or perform biometric identification. A photograph of a report is used to process that report, not for facial recognition. IP addresses may indicate approximate location.

Support and compliance information

We collect information you provide in support correspondence, complaints, privacy requests, consent selections, and billing disputes. We use it to respond, verify authority where necessary, resolve issues, and document compliance. We ask for only the information reasonably necessary for the request.

3. How collection occurs and how consent works

We collect information directly through registration, forms, uploads, protocol entries, symptom responses, chats, purchases, and support communications; automatically through necessary technical operations and permitted analytics; and by deriving outputs from your information. Payment providers supply transaction records. We do not buy health profiles from data brokers or retrieve records from a clinician or laboratory merely because you name them.

Before processing sensitive health information on the basis of consent, we explain the relevant categories, purposes, and recipients and obtain the affirmative consent required by law. Where separate consent is required for sharing, that consent is distinct from collection consent. Optional tracking and marketing choices are not preselected or bundled into consent needed for the core Service.

You can decline optional fields and features. Without a report, we cannot analyze that report; without permission for AI processing needed for a requested feature, we cannot provide that feature. We do not require unrelated sensitive information as a condition of basic account administration.

Withdraw consent by emailing testra.support@chasecompanyinc.com. We explain the effects and stop the affected consent-based processing. Withdrawal does not make earlier lawful processing unlawful, and it does not prevent a separately authorized legal retention obligation. You can also request deletion. We do not use withdrawal as a reason to impose a penalty or deny unrelated rights.

4. AI processing and automated outputs

Testra uses commercial AI APIs from Anthropic, the provider of Claude, and/or OpenAI for extraction and educational responses. Depending on the feature, data sent to an API may include the uploaded report or relevant portions, extracted results, age-related context, protocol and symptom entries, your question, relevant conversation history, and technical identifiers needed to return the answer. A report may identify you even when your account name is not separately included.

We limit the information sent to what is reasonably necessary for the requested task. We do not use consumer chatbot accounts as the processing channel for your records. AI processing is disclosed before you submit health information for the relevant feature, with consent obtained where required.

We do not sell health information to AI providers or authorize its use to train their general-purpose models. We do not use your identifiable health records or conversations to train our own models or conduct unrelated research without separate, specific permission. Reporting a bad answer does not itself give that permission.

API providers may retain content or technical records for service operation, security, abuse prevention, and legal obligations under the applicable API arrangements. Retention depends on the provider, endpoint, and enabled features. We do not promise that every API request has zero retention or that deleting a conversation from Testra instantly removes every provider-held copy. Our deletion process includes relevant provider-held content to the extent required by law and within the scope of our processing arrangements. Contact the Privacy Officer for information about the arrangements applicable to your data.

Scores, rankings, and educational classifications are produced using the available inputs and Testra's methodology; AI may generate associated explanations. These activities can constitute profiling of health information. We do not use them to make decisions about insurance, employment, lending, or access to treatment. You may request correction of inaccurate inputs and information about the principal factors behind a result. A review by support staff is not a clinical assessment.

5. Who receives information

We do not sell personal information or consumer health data, rent health records, or share personal information for cross-context behavioral advertising. We do not provide health records to advertisers, data brokers, employers, or insurers for their independent use.

We disclose information only for the following purposes and subject to applicable consent and legal requirements:



RecipientInformation and purposeSupabaseAccount information, uploads, extracted values, protocol and symptom entries, chats, and outputs for database operations, authentication, private file storage, and recovery services used by Testra.Anthropic and/or OpenAIThe content described in Section 4 to perform requested AI processing and associated limited security functions.VercelWebsite and application requests, relevant processing data, and necessary technical information to host and deliver the Service. Requests can contain health data when a feature requires server-side processing.Stripe or the app store through which you purchasePurchase, subscription, transaction, billing, and fraud-prevention information, as explained in Section 2.Authorized personnel and contracted technical supportInformation necessary to address a particular support request, maintain the Service, investigate an incident, or fulfill a privacy obligation. Access must be limited to the assigned task.Professional advisersInformation necessary for legal, accounting, or compliance work. Routine financial accounting does not require your laboratory reports.A recipient you direct us to contactOnly information within your valid, specific sharing instruction and any required authorization.Authorities or a qualifying business successorOnly under Sections 6 and 7.

Processors must act under appropriate contractual restrictions addressing confidentiality, security, permitted purposes, incident reporting, assistance with rights requests, and retention or deletion. Approved subprocessors are subject to corresponding obligations. A provider is not authorized to use health information for unrelated advertising or independent profiling merely because it helps operate Testra.

Some recipients, including payment providers, separately determine processing necessary for their own legal duties. Their independent activities are governed by their own privacy notices, including Stripe's Privacy Policy. Those notices do not expand Testra's permission to share health data.

We do not routinely share health information with corporate affiliates. We do not disclose records to a family member, clinician, coach, or laboratory merely because that person claims a relationship with you. Files you download and share yourself leave Testra's controls.

6. Legal requests and protection of rights

We review legal demands for validity, jurisdiction, and scope and require appropriate legal process where necessary. We disclose only information required or permitted by the applicable law. We seek clarification or narrowing of disproportionate or defective requests where appropriate.

We do not voluntarily provide lists of people using TRT or performance-enhancing compounds to law enforcement for general investigative purposes. A record of substance use is not, by itself, a reason for us to report you.

Where legally permitted and practicable, we notify an affected user of a demand before disclosure, unless notice would create a material safety risk or compromise a legally protected investigation. We may preserve information in response to a valid preservation obligation without disclosing it until disclosure is separately authorized.

We may disclose strictly necessary information to address fraud or an attack on the Service, establish or defend legal claims, or respond to a specific serious threat when legally permitted or required. We apply additional restrictions governing health information. This provision does not authorize routine monitoring of medical emergencies or unrestricted disclosure to authorities.

7. Business transactions

If Testra is involved in an acquisition, merger, financing, reorganization, or insolvency proceeding, we use aggregated or redacted information wherever practicable. Identifiable information may be disclosed only as legally permitted and necessary, under restrictions on use, access, protection, and return or destruction if the transaction does not proceed.

A successor receiving information must respect the applicable privacy commitments and legal obligations. We provide required notice and obtain required consent before a new or incompatible use. We do not offer health records as a standalone asset for unrelated exploitation. A business transaction does not override a statutory prohibition on selling or disclosing health data.

8. Storage and international processing

Testra operates from Canada and uses the service providers identified above. Information may be stored, transmitted, or processed outside your province, state, or country, including in the United States. Provider infrastructure, authorized subprocessors, and authorized support personnel may operate in additional countries. Remote access from another country is also a cross-border processing activity, even if the underlying database stays in one location.

We do not promise that all information remains in Canada or that every copy stays in a single country. We limit cross-border processing to authorized service purposes and apply appropriate contractual and security safeguards. We remain responsible for information under our control when a processor handles it on our behalf.

Foreign courts, regulators, law enforcement, or national-security authorities may lawfully access information under the laws of their jurisdiction. Those laws may differ from your local laws. Contractual protections cannot prevent every legally required disclosure.

Contact testra.support@chasecompanyinc.com for information about the processing locations and safeguards applicable to your records, or questions about our use of service providers outside Canada. If a change materially affects the disclosed processing or requires new consent, we provide the applicable notice and obtain that consent before the new processing begins.

9. Security

We apply administrative, technical, and organizational safeguards appropriate to sensitive health information. Our security requirements include:

  • Encryption of stored health data, uploaded reports, and retained backups using AES-256.

  • Encryption in transit using HTTPS/TLS 1.2 or later, including connections carrying health data to AI processors.

  • Private storage and user-specific database and file-access permissions.

  • Restricted administrative access, multifactor authentication for privileged accounts, and controlled handling of secret API keys.

  • Limiting access to authorized personnel with a service-related need and confidentiality obligations.

  • Excluding health content from routine analytics and error logs; any exceptional incident evidence containing such content receives restricted access and purpose-limited retention.

  • Reviewing access permissions and security configurations and testing that users cannot access other users' records.

Encryption is not end-to-end encryption: authorized systems must decrypt relevant information to perform extraction, scoring, storage retrieval, and AI processing. Authorized access may also be necessary for support, security, or legal compliance. Encryption does not make data anonymous.

No service can guarantee absolute security. That limitation does not reduce our obligation to use appropriate safeguards or meet applicable law. Please protect your credentials and devices and report suspected unauthorized access to testra.support@chasecompanyinc.com.

10. Retention and deletion

We retain personal information only for its disclosed purposes and permitted legal obligations. Retention depends on the record and purpose, as follows:



InformationRetention criteriaAccount profileWhile the account remains open and needed to provide it; removed following account deletion, except narrowly required compliance records.Reports, biomarkers, protocols, symptoms, scores, and conversationsWhile you maintain them in your account for the requested historical archive, unless you request earlier deletion or retention is no longer necessary for that purpose.AI-provider copiesOnly for processing purposes permitted under Section 4 and the relevant service arrangements, subject to applicable deletion obligations.Routine security and technical recordsOnly while needed to operate, troubleshoot, and protect the Service; incident-specific evidence is retained only while the investigation, remediation, or applicable legal need continues.Usage analyticsOnly while needed for the identified reliability or usability purpose, after which account-linked records are deleted or effectively de-identified.Support correspondenceWhile the request is being resolved and afterward only as necessary to address related follow-up or a documented dispute. Unnecessary medical attachments are removed earlier.Transaction and tax recordsFor the statutory accounting or tax-retention period applying to the record. Keeping an invoice does not require keeping bloodwork.Consent, rights-request, and incident recordsFor the period required to demonstrate compliance or meet a specific statutory recordkeeping obligation. PIPEDA breach records are retained for at least 24 months where that requirement applies.

The vault is an ongoing personal archive, not an unconditional promise of permanent storage. Canceling a subscription does not automatically request deletion. You can request deletion of specific records or your whole account at testra.support@chasecompanyinc.com. We do not keep an entire health history indefinitely merely because a transaction record must be retained.

We act on valid deletion requests without undue delay and within the applicable legal requirements. Deletion covers relevant active records and associated derived information, and we instruct processors and other recipients to delete information where required. Tell us if you want related chats deleted as well as a report: deleting a report alone may not identify a separate conversation into which you copied its contents.

When immediate deletion from a disaster-recovery backup is not technically feasible and deferred deletion is lawful, the information is restricted from ordinary use and removed through the applicable backup-deletion cycle within the legal deadline. If a backup is restored, deletion instructions are reapplied. Where Washington's health-data law applies, a permitted backup-deletion delay never exceeds six months after authentication of the request.

We may retain specific information longer only for a legally permitted, documented reason, such as a binding preservation requirement or a necessary legal claim. Retained material is restricted to that purpose and deleted when the reason ends. We explain applicable exceptions unless prohibited by law. An exception available under one law is not used to defeat a stricter applicable health-data rule.

11. Cookies, analytics, and communications

Necessary cookies, local storage, and similar technologies support login, security, checkout, and privacy preferences. Blocking them may prevent those functions. Device permissions for selecting a photograph or file allow the requested upload; they do not authorize unrelated access to your photo collection.

Optional analytics technologies are used only with the consent or other permission required by law. Before optional tracking that requires consent begins, we explain its purpose and provide a choice. You may withdraw consent through an available privacy control or by contacting us. Necessary security processing continues where lawfully required to operate the Service.

We do not use health records or chat contents for targeted advertising. We do not permit advertising pixels, session replay, or keystroke recording within authenticated health-record screens. We do not use healthcare-facility geofences to identify or target people seeking care.

We honor applicable opt-out preference signals, including Global Privacy Control, for activities subject to those signals. We do not sell information or engage in cross-context behavioral advertising even without a signal. Browser Do Not Track settings do not disable necessary authentication or security operations.

Account, billing, privacy, and security notices are service communications. Promotional messages are sent only as permitted by law and include an unsubscribe method. Opting out of marketing does not stop necessary account notices. Routine email and notification previews do not need to include your biomarker values or medication details, and we minimize sensitive content in those channels.

12. Your choices and rights

You may request access to your personal information, correction of inaccurate information, deletion, an electronic copy or export, and withdrawal of consent. Depending on applicable law, you may also have rights to restrict or object to processing, obtain recipient information, limit certain sensitive-information uses, opt out of sale or targeted advertising, and appeal a refusal.

Send requests to testra.support@chasecompanyinc.com, using the subject "Privacy request," or write to the Privacy Officer at 2157 Phelan Road West. Include your account email and the action requested. Do not send laboratory reports or identity documents in an initial message unless necessary; we will arrange proportionate verification.

We use reasonable methods to verify identity before releasing, changing, or deleting sensitive records. Verification may use your existing account or registered email. We request additional evidence only when reasonably necessary and use it for verification, not another purpose. You do not need to create a new account. Authorized agents may submit requests with appropriate proof of authority, and we respect valid powers of attorney. We do not impose verification on an opt-out where the law prohibits it.

An access response explains relevant information held, purposes, and disclosures. Where applicable, exports include original reports and available structured information in a commonly used electronic format. Proprietary scoring code is not part of your personal-data export, but we do not withhold your underlying values simply because they contribute to a proprietary score.

A correction to an extracted value does not silently alter the original laboratory report. You may provide a corrected report or request an annotation. We cannot change the laboratory's own records; contact the laboratory for corrections to its source document.

Requests are ordinarily free. Any fee or refusal based on an excessive or unfounded request must be permitted by the applicable law, supported by reasons, and communicated in advance where required. We do not discriminate against you for exercising rights. A feature may become unavailable if it cannot operate without information you ask us to stop processing.

13. Response times, appeals, and complaints

We respond within the period required by the applicable law:

  • Canadian access requests: Generally within 30 days. We use an extension only when the applicable statute permits it and provide the required notice and reasons.

  • California requests to know, correct, or delete: Within 45 days, with a further 45 days only when legally permitted and explained within the initial period. We acknowledge receipt within 10 business days where required.

  • Washington consumer-health requests: Within 45 days, with one permitted 45-day extension explained within the initial period.

  • Other applicable laws: Their specific deadlines and extension conditions apply, including a shorter period where required.

We begin verification promptly; verification does not automatically restart a statutory deadline. An acknowledgment is not a substitute for completing the request.

If we cannot fully comply, we explain the lawful reason, any partial action, and your appeal or complaint route. To appeal, email testra.support@chasecompanyinc.com with the subject "Privacy appeal." We provide a written decision within 45 days or any shorter applicable period and explain how to contact the relevant regulator if the appeal is denied. You do not need to complete our appeal process before exercising a right to complain directly to a regulator.

Canadian users can contact the Office of the Privacy Commissioner of Canada or their competent provincial commissioner. U.S. users can contact their state attorney general, the Federal Trade Commission, or an applicable state privacy authority. The relevant authority depends on the matter and governing law.

14. Canadian privacy and health-information laws

We process information in accordance with PIPEDA where it applies and applicable provincial privacy legislation, including relevant Alberta and British Columbia requirements. Our Privacy Officer handles questions concerning outside-Canada service providers, safeguards, consent, access, and complaints.

Health information is treated as sensitive. Its presence in an educational app does not make it ordinary marketing data. We apply reasonable collection limits, appropriate consent, restricted disclosure, safeguards, and access and correction procedures.

Ontario's Personal Health Information Protection Act, 2004 (PHIPA) applies according to the legal role and activity involved. The direct-to-consumer Service does not create a healthcare-provider relationship, and a user upload does not by itself establish that Testra is a health information custodian. Where a particular activity brings Testra within PHIPA obligations, those obligations govern that activity. We do not represent this Policy as a PHIPA certification or as a healthcare custodian's notice on behalf of your clinician.

15. California and other U.S. privacy rights

For California residents, the categories of information addressed by this Policy include identifiers and account information; customer and transaction records; age and other characteristics contained in submitted records; internet or device activity and approximate IP-derived location; uploaded electronic records; health and other sensitive information, including account-access credentials; and inferences derived from these categories.

Section 2 identifies the categories and sources, Sections 2–5 explain purposes and recipients, and Section 10 explains retention criteria. These descriptions cover our current practices and the applicable categories handled during the preceding 12 months, or since the relevant feature began if shorter. We do not sell or share any category for cross-context behavioral advertising, including information about minors, and do not offer payment or discounts in exchange for health-data rights.

Where the California Consumer Privacy Act, as amended by the CPRA, applies, you have rights to know, access, correct, delete, obtain portable information, opt out of sale or sharing, limit qualifying sensitive-information uses, and receive nondiscriminatory treatment. Our sensitive-information uses are confined to requested services and other legally permitted purposes; a new use requiring an additional choice will not begin without that choice. Use Section 12's request process and Section 13's timelines. You may complain to the California Privacy Protection Agency or California Attorney General.

Other applicable state privacy, medical-confidentiality, and consumer-health laws remain effective, including relevant Nevada and Connecticut protections and California medical-information law. We honor applicable access, correction, deletion, consent, appeal, and opt-out rights through the same contact routes. Information generated within Testra does not lose health-data protection simply because it is an inference. Nothing in this Policy waives statutory rights or relies on a blanket exemption for all health information.

HIPAA applies to specified entities and activities, not every health app. We do not represent that ordinary consumer records in Testra automatically receive HIPAA coverage. A separate covered-entity or business-associate arrangement would require its own assessment and applicable agreements. Other privacy protections continue to apply whether or not HIPAA applies.

16. Consumer Health Data Privacy Notice

This notice describes our consumer-health practices, including those relevant to Washington's My Health My Data Act and Nevada's consumer-health provisions. It must be read as a specific health-data notice, not as permission for additional uses.

Information and sources. We collect your uploaded reports and associated identifiers, biomarkers, protocol and medication entries, symptoms, chat content, generated scores and explanations, and linked account or usage information that reveals health status or seeking health services. Sources are you, the records you upload, your interactions, and the results or inferences we generate.

Uses. We use these categories to provide your requested archive, extraction, trends, scoring, education and chat, and necessary support, security, and rights handling. We obtain the consent required for collection and use. Where a law permits processing necessary to provide a requested service without separate consent, we apply that exception only within its legal scope.

Disclosures. Reports and health records are processed by Supabase for storage and database services, by Vercel when needed for application delivery, and by Anthropic and/or OpenAI for the AI functions described in Section 4. Authorized technical support, security providers, and professional advisers receive only task-necessary categories. Other disclosures are limited to your valid directions, lawful demands, and qualifying transactions described above. We obtain separate sharing consent where required. There is no routine affiliate sharing and no sale of consumer health data.

Rights. Request confirmation of collection or sharing, access, deletion, or consent withdrawal at testra.support@chasecompanyinc.com, or write to the Privacy Officer, Chase Company Inc., 2157 Phelan Road West. Washington consumers may obtain a list of third parties and affiliates with whom their consumer health data was shared or sold and a contact mechanism for those recipients. No new account is required. Requests and appeals follow Section 13.

Deletion. We notify the processors and other recipients required to honor a deletion request. Applicable deletion duties include backups, subject only to permitted delays and exceptions. Washington's permitted archival or backup delay cannot exceed six months after authentication.

Appeals and changes. Appeal by emailing testra.support@chasecompanyinc.com with "Privacy appeal." Washington appeals receive a decision within 45 days and a route to the Washington Attorney General's complaint process if denied. Nevada consumers can also request review of a refusal using this contact. Material changes are communicated under Section 20; new health-data categories or purposes receive the advance disclosure and consent required by law.

17. Security incidents

We assess suspected unauthorized access, loss, use, or disclosure; take reasonable containment and corrective measures; coordinate with relevant processors; and document the response. Unauthorized disclosures to a vendor or tracking service can be an incident even without a malicious intrusion.

Under PIPEDA, where a breach creates a real risk of significant harm, we report to the federal Privacy Commissioner and notify affected individuals as soon as feasible after determining that threshold is met. We also notify other organizations or government institutions when required to reduce harm and keep the required breach records.

Where the FTC Health Breach Notification Rule applies, individual notice is given without unreasonable delay and no later than 60 calendar days after discovery. FTC notice for breaches involving 500 or more individuals accompanies individual notice; reportable smaller breaches are reported within 60 calendar days after the calendar year ends. Required media and substitute notices are provided when their conditions apply.

We comply with other applicable state and provincial notification rules, including shorter deadlines and additional regulator notices. A lawful delay is used only when its requirements are satisfied. Notices explain the incident, affected information, response, protective steps, and a contact route, with any additional information required by law. The existence of a maximum deadline does not justify unnecessary delay.

18. Children and ineligible users

The Service is intended for adults who are at least 18 and have reached the age of majority where they reside. We do not knowingly collect children's health records, allow accounts for minors, or invite parents to upload a child's records. Do not submit a minor's report through your account.

If we discover information collected from an ineligible child, we restrict processing and delete it unless narrowly required to meet a binding legal duty or document the response. A parent or guardian can notify testra.support@chasecompanyinc.com without including unnecessary medical details. We do not treat an age statement alone as permission to ignore evidence that a user is a child.

19. De-identified information and external services

We may use technical statistics that have been aggregated or de-identified to understand reliability and performance only where the applicable standard prevents reasonable association with an individual. Removing a name or replacing it with a code does not by itself make health information anonymous. We do not attempt to re-identify genuinely de-identified data except where expressly permitted to assess the effectiveness of de-identification, and require corresponding restrictions on authorized recipients.

This provision does not authorize conversion of your health records into an unrelated research or commercial dataset or circumvention of a pending deletion request.

External laboratories, clinicians, payment services, and websites maintain their own records and policies. We are responsible for our own handling and our processors' activities as required by law; we cannot change a laboratory's independent records merely because you delete an uploaded copy from Testra.

20. Changes to this Policy

We update this Policy when practices or applicable requirements change and identify the new effective date. Material changes are communicated through a prominent website or app notice and, when appropriate or legally required, direct email before they take effect. We review the accuracy of our disclosures at least annually.

Before collecting a new health-data category or using or sharing health information for a new purpose, we provide the required disclosure and obtain fresh consent when required. Continued use is not a substitute for that consent. Updates do not retroactively authorize a use or disclosure that was previously prohibited.

21. Contact

For privacy questions, access, correction, deletion, consent withdrawal, appeals, or suspected security incidents, contact:

Privacy Officer
Chase Company Inc., operating as Testra
Email: testra.support@chasecompanyinc.com
Mail: 2157 Phelan Road West

Please identify the request and your account email, but avoid including unnecessary health records or identity documents in an initial message. We will arrange any verification or secure information exchange needed to address it.

TESTRA

BLOODWORK INTELLIGENCE FOR MEN

Product

Company

Contact

Your data, your control.

We take your privacy seriously. Learn how we collect, use, and protect your data.

Testra is a product of Chase Company Inc.

© 2026 Chase Company Inc. All rights reserved.

TESTRA

BLOODWORK INTELLIGENCE FOR MEN

Product

Company

Contact

Your data, your control.

We take your privacy seriously. Learn how we collect, use, and protect your data.

Testra is a product of Chase Company Inc.

© 2026 Chase Company Inc. All rights reserved.

TESTRA

BLOODWORK INTELLIGENCE FOR MEN

Product

Company

Contact

Your data, your control.

We take your privacy seriously. Learn how we collect, use, and protect your data.

Testra is a product of Chase Company Inc.

© 2026 Chase Company Inc. All rights reserved.