Effective 2026-08-18
Privacy Policy
This Privacy Policy explains how BioOps collects, uses, stores, and shares information when you use the BioOps website, dashboards, mobile app, Apple Health sync, and Model Context Protocol (MCP) server. It applies to sensitive health information, including laboratory records. Contact us at contact@bioops.app.
Information We Collect
- Account information, such as your email address and profile details from your sign-in provider.
- Mobile device registration data, such as install ID, platform, device name, app version, OS version, and last-seen time.
- Apple Health data you authorize the mobile app to read. The mobile app processes authorized records locally and uploads only finalized artifacts, such as hourly and daily metrics, sleep sessions, workouts, observations, scores, and source provenance.
- Source metadata needed to preserve provenance, such as HealthKit sample IDs, source bundle IDs, source names, timestamps, timezone offsets, and finalized mobile artifact details.
- Laboratory records that you or an MCP client acting with your authorization submit, including report dates and identifiers, test names and identifiers, values, units, comparators, reported flags, reference ranges, notes, and source provenance. BioOps stores the structured record used by the Labs dashboard; uploaded source documents are not retained by the laboratory workflow.
- Health context that you or an authorized MCP client deliberately records, such as a condition, injury, symptom, event, external measurement, or note, together with its dates, status, confidence, measurements, relationships, and provenance.
- MCP authorization records, such as connected client IDs, scopes, token metadata, and token use timestamps. Secret token values are stored as hashes where supported by the system.
- Operational logs and error information needed to secure, debug, and run the service.
How We Use Information
- To authenticate you and operate your BioOps account.
- To process Apple Health records locally in the mobile app, and to receive, store, deduplicate, and display the finalized artifacts you choose to sync. BioOps does not recalculate health values on the server.
- To store and display sleep sessions and summaries finalized on your device.
- To store and display laboratory records and health context you deliberately submit. BioOps preserves reported laboratory values, units, flags, and reference ranges; it does not provide clinical interpretation or invent missing results.
- To provide MCP access to clients you explicitly authorize, limited to the scopes you approve, and to audit record changes made through those clients.
- To maintain security, troubleshoot issues, prevent abuse, and improve reliability.
- To comply with legal obligations and enforce our Terms.
What BioOps Does Not Do
- BioOps does not provide medical advice, diagnosis, treatment, or emergency support.
- BioOps does not sell your personal information.
- BioOps does not use your health information for advertising or build advertising profiles from it.
- BioOps does not upload raw HealthKit samples for server-side processing. Authorized health records are summarized and finalized on your device before synchronization.
Sharing
We disclose information only as needed to operate the service, comply with law, protect rights and security, or at your direction. If you authorize an MCP client, that client can access or change only the data permitted by its approved read or write scopes until you revoke access or its token expires. An authorized client may send that data to an AI model or another provider under that provider's terms and privacy practices. BioOps does not control a third-party client or how it handles information after you authorize disclosure. Review its permissions and policies before connecting it.
Service Providers
BioOps relies on hosting, authentication, database, logging, email, repository, analytics, and infrastructure providers to operate the service. These providers may process data on our behalf and may do so outside New Zealand. We limit provider access to what is reasonably needed for the service and use provider and technical safeguards appropriate to the information and the service's MVP stage.
Security
BioOps uses measures such as access controls, scoped and revocable tokens, row-level security, audit records, and hashed secret storage where appropriate. These controls reduce risk but do not make an internet service completely secure. You are responsible for protecting your account, devices, email, one-time client secrets, and any MCP clients you authorize. Contact us promptly if you believe access has been compromised.
Access, Correction, Retention And Deletion
You may ask for access to, or correction of, personal information BioOps holds about you. You can also revoke MCP clients, delete supported records, or permanently delete your complete BioOps account through Account → Delete BioOps account on web or mobile. Whole-account deletion removes live account data, health records, notes, laboratory data, legal acceptances, mobile credentials, and MCP authorizations. It does not delete data held by Apple Health. For an access or correction request, email contact@bioops.app. We retain information only while reasonably needed for the purposes described here, to operate and secure the service, resolve disputes, or meet legal obligations. After whole-account deletion, live user-linked audit and tombstone rows are removed. Copies in restricted infrastructure backups age out under the provider backup-retention schedule and are not restored as an active account.
Laboratory reports appear on their supplied collection date. If you delete a report or an individual result through BioOps, it is immediately excluded from ordinary calendar, timeline, report, and trend views. BioOps uses a soft-deletion record so limited metadata—including identity, revision, actor, time, and action—may remain in tombstones and audit logs under these retention practices. Deleting the final active result also removes the empty parent report from ordinary views.
BioOps is an experimental MVP, not a records-retention or backup service. The service, an account, a feature, or stored data may be disabled, reset, or permanently deleted at any time, including during testing or migration and without advance notice where the law permits. Keep independent copies of laboratory reports and any health information you need. A deletion request does not require BioOps to retain data that has already been deleted.
Health Data Sensitivity
Health data can be sensitive. Only sync data you are comfortable storing in BioOps and sharing with MCP clients you authorize. Laboratory results and AI-generated discussion can reveal health conditions even when names are omitted. BioOps is not intended or supplied as software as a medical device and is not designed or validated for a therapeutic purpose or clinical decision-making. Do not use it for emergencies or as your only copy of important health information.
New Zealand Privacy Rights
BioOps handles personal information subject to applicable privacy law, including the New Zealand Privacy Act 2020 where it applies. You may contact us to exercise your access or correction rights or to raise a privacy concern. You may also contact the Office of the Privacy Commissioner.
Changes
We may update this Privacy Policy as the product changes. If changes are material, we may require you to accept the updated policy before continuing to use authenticated features.
See also the Terms and Conditions.