Effective 2026-06-18

Privacy Policy

This Privacy Policy explains how BioOps collects, uses, stores, and shares information when you use the BioOps website, mobile app, Apple Health sync, and MCP server. Contact us at contact@bioops.app.

Information We Collect

  • Account information, such as your email address and profile details from your sign-in provider.
  • Mobile device registration data, such as install ID, platform, device name, app version, OS version, and last-seen time.
  • Apple Health data you authorize the mobile app to read and upload, currently including sleep, nutrition, body measurements, blood pressure, time in daylight, VO2 max, and workout records.
  • Source metadata needed to preserve provenance, such as HealthKit sample IDs, source bundle IDs, source names, timestamps, timezone offsets, and raw payload details.
  • MCP authorization records, such as connected client IDs, scopes, token metadata, and token use timestamps. Secret token values are stored as hashes where supported by the system.
  • Operational logs and error information needed to secure, debug, and run the service.

How We Use Information

  • To authenticate you and operate your BioOps account.
  • To receive, store, deduplicate, process, and display Apple Health records you choose to sync.
  • To reconstruct sleep sessions and summaries from raw sleep samples.
  • To provide MCP access to clients you explicitly authorize.
  • To maintain security, troubleshoot issues, prevent abuse, and improve reliability.
  • To comply with legal obligations and enforce our Terms.

What BioOps Does Not Do

  • BioOps does not provide medical advice, diagnosis, treatment, or emergency support.
  • BioOps does not sell your personal information.
  • BioOps does not intentionally collect Apple Health data unless you grant HealthKit permission and initiate sync through the mobile app.

Sharing

We share information only as needed to operate the service, comply with law, protect rights and security, or at your direction. If you authorize an MCP client, that client can access the scoped data exposed by the MCP tools until you revoke its access or the token expires. Third-party clients are not controlled by BioOps.

Service Providers

BioOps relies on hosting, authentication, database, logging, repository, analytics, and infrastructure providers to operate the service. These providers process data on our behalf under their own security and privacy commitments.

Security

BioOps uses access controls, scoped tokens, row-level security, and hashed token storage where appropriate. No internet service can be guaranteed completely secure. You are responsible for protecting your account, devices, email, and any MCP clients you authorize.

Retention And Deletion

We keep information while your account is active or as needed to operate the service, resolve disputes, comply with law, and maintain backups. You can ask us to delete your account or data by emailing contact@bioops.app. Some records may remain temporarily in backups or logs.

Health Data Sensitivity

Health data can be sensitive. Only sync data you are comfortable storing in BioOps and sharing with MCP clients you authorize. Do not use BioOps for emergencies or as your only copy of important health information.

Changes

We may update this Privacy Policy as the product changes. If changes are material, we may require you to accept the updated policy before continuing to use authenticated features.

See also the Terms and Conditions.