Not medical advice. This is personal health intelligence and wellness insights from your own data, not a medical device, diagnosis, or treatment.

Privacy PolicyTerms of ServiceContact© 2026 Biomize
← Biomize

Privacy Policy

Last updated: June 17, 2026

This Privacy Policy explains how Biomize, the operator of the Biomize service (the “Service”), collects, uses, and shares information about you. Biomize is an independent, personal health-and-productivity insights tool, currently offered as a private, invite-only beta. Because the Service processes health-related information, please read this policy carefully. By using the Service you agree to this policy and to our Terms of Service.

1. Who we are

The Service is operated by Biomize, based in New York, USA. For any privacy question or request, email privacy@biomize.ai.

2. Information we collect

a. Account & authentication. We use Clerk, Inc. for sign-in. We collect your email address, your name (if provided), and authentication identifiers. We do not store your password. Clerk handles credentials.

b. Wearable, health & activity data from devices and apps you connect. If you connect them, we collect:

  • Oura Ring: sleep stages and duration, sleep and readiness scores, heart-rate variability (HRV), resting and overnight heart rate, respiratory rate, body-temperature deviation, and related daily summaries.
  • WHOOP: recovery, strain, sleep, HRV, and heart-rate metrics.
  • Garmin: activity, sleep, stress, heart rate, and related daily summaries.
  • Strava: workouts and activities (type, duration, distance, heart rate, and related metrics).
  • Apple Health (via an iOS Shortcut you set up): the health and activity metrics you choose to export, such as sleep, heart rate, steps, and workouts.
  • Apple Screen Time: approximate screen-time and phone-usage figures you export.
  • Dexcom (continuous glucose monitor): glucose readings and trends.

c. Calendar data. If you connect Google Calendar, Microsoft Outlook / Microsoft 365, or Apple Calendar (iCloud CalDAV), we collect event times, titles, durations, and attendee counts to relate your schedule to your biometrics.

d. Nutrition data. If you connect a nutrition source, FatSecret, or Terra (which bridges MyFitnessPal and Cronometer), we collect logged foods, meals, and macro/calorie data.

e. Financial transaction data. If you import a CSV of your transactions, we collect spending data (amounts, dates, merchants, categories) and use it to look for correlations between spending and stress.

f. Medical documents, lab results & medication data. Documents and images you upload, including lab results and other medical PDFs/images, which we analyze with AI to extract and summarize results, as well as medications and dose logs, GLP-1 doses, and symptom logs you record.

g. Skin photos. Photos you upload of your skin, which we analyze with AI.

h. Location data. If you upload Google Timeline data, we collect the location history it contains.

i. Body weight and other manual entries. Body weight and other notes, tags, and logs you create, which may include sensitive details such as alcohol or cannabis use, caffeine, late meals, workouts, and mood.

j. Derived & environmental data. Weather for your area (via Open-Meteo) and the analytics, models, and insights we compute from your data.

k. Technical data. Basic information needed to run the Service (timestamps, request and error logs). We do not use third-party advertising trackers.

3. Where your data comes from

We collect data (i) directly from you, including documents, photos, CSV transaction files, Google Timeline location exports, and manual logs you upload or enter, and (ii) from the third-party services you choose to connect, using credentials you authorize. Connectable sources include: Oura, WHOOP, Garmin, Strava, Dexcom, Apple Health (via an iOS Shortcut), and Apple Screen Time (wearables / health & activity); Google Calendar, Microsoft Outlook / Microsoft 365, and Apple Calendar via iCloud CalDAV (calendars); and FatSecret and Terra, which bridges MyFitnessPal and Cronometer (nutrition). You can disconnect any source at any time.

4. How we use your information

  • To provide and operate the Service and display your data.
  • To generate personalized insights, forecasts, and your AI morning briefing.
  • To compute statistical and machine-learning models from your own data (an “n-of-1” personal model).
  • To maintain security, debug, and improve the Service.
  • To communicate with you about the Service.

We do not sell your personal information, and we do not use it for advertising.

5. How we share your information (service providers)

We share data only with the providers that make the Service work, and only as needed:

ProviderPurposeData involved
Clerk, Inc.AuthenticationAccount identifiers, email
Neon, Inc.Database hostingAll stored Service data (encrypted in transit)
Fly.io, Inc.Backend/API hostingService data in processing
Vercel Inc.Frontend hostingApp delivery; no health data stored
Anthropic, PBCGenerating insights & briefings; analyzing uploaded medical documents & skin photos (Claude AI)The biometric/calendar/log context needed to write an insight; uploaded documents & photos
OpenAI, L.L.C.Text-to-speech for the spoken briefingThe text of your briefing
ElevenLabs, Inc.Text-to-speech for the spoken briefing (optional provider)The text of your briefing
Stripe, Inc.Payments & billingBilling identifiers; payment status (card data handled by Stripe)
Resend (Plus Five Five, Inc.)Transactional emailEmail address; message content
Functional Software, Inc. (Sentry)Error monitoringDiagnostic/error data; technical identifiers
Amazon Web Services / Tigris (S3)Audio cache storageGenerated briefing audio files
Google LLCCalendar source (if connected)OAuth tokens; calendar events
Microsoft CorporationOutlook / Microsoft 365 calendar source (if connected)OAuth tokens; calendar events
Apple Inc. (iCloud)Apple Calendar source via CalDAV (if connected)Credentials; calendar events
Dexcom, Inc.Glucose source (if connected)OAuth tokens; glucose data
WHOOP, Inc.Wearable source (if connected)OAuth tokens; recovery/sleep/HR data
Garmin International, Inc.Wearable source (if connected)OAuth tokens; activity/sleep/HR data
Strava, Inc.Activity source (if connected)OAuth tokens; workout/activity data
Oura Health OyWearable source (if connected)OAuth tokens; sleep/readiness/HR data
FatSecretNutrition source (if connected)OAuth tokens; food/nutrition logs
Terra (Tera API, Inc.)Nutrition bridge for MyFitnessPal/Cronometer (if connected)OAuth tokens; food/nutrition logs
Open-MeteoWeatherCoarse area only

About the AI providers.When we generate an insight or briefing, the relevant portion of your data is sent to Anthropic and/or OpenAI to produce the result. Per their API terms, Anthropic and OpenAI do not use data submitted through their APIs to train their models by default, and retain it only transiently for abuse monitoring. We send the minimum context needed. When you upload medical documents, lab results, or skin photos, those files are sent to Anthropic’s Claude to extract and summarize their contents so we can show them back to you.

We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer (e.g., if the Service is acquired), in which case we will notify you.

6. Google API data: Limited Use

Biomize’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data solely to provide user-facing features within the Service; we do not transfer or sell it, do not use it for advertising, and do not use it to train generalized AI models.

7. Consumer health data

Some information you provide or connect (sleep, HRV, glucose, substance-use logs, and similar) is “consumer health data” under laws such as Washington’s My Health My Data Act and similar state laws. We collect and process this data only to provide the Service to you, with your consent, and we do not sell it. You may withdraw consent and delete this data at any time (see Section 9). For health-data questions, email privacy@biomize.ai.

8. Data retention

We keep your data while your account is active. When you delete specific data or your account, we delete the associated personal data from our active systems, and from backups within a reasonable period. We may retain limited records where required by law.

9. Your rights and choices

Regardless of where you live, you can:

  • Access / export your data: email us.
  • Delete your data or your entire account: email privacy@biomize.ai and we will delete it.
  • Disconnect any data source at any time in Settings, which stops further collection from it.
  • Withdraw consent to processing of your consumer health data.

Depending on your state (e.g., California) or country (e.g., the EEA/UK under GDPR), you may have additional rights such as correction, portability, restriction, objection, and the right to complain to a regulator. We honor these requests: email privacy@biomize.ai and we will respond as required by law. We will not discriminate against you for exercising your rights.

10. Security

We protect your data with encryption in transit (HTTPS/TLS), authenticated access, hosting on reputable infrastructure, and least-necessary data sharing. No system is perfectly secure, but we work to protect your information and will notify you and authorities of a breach of unsecured health data as required, including under the FTC Health Breach Notification Rule.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a minor has used the Service, contact us and we will delete the data.

12. International users

The Service is operated from the United States. If you access it from outside the U.S., you understand your data will be processed in the U.S.

13. Changes to this policy

We may update this policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, notice in the app.

14. Contact

Biomize
Email: privacy@biomize.ai
New York, USA

← Back to Biomize