Privacy Policy
Last updated: October 3, 2026
BioasisHQ helps you bring your nutrition, training, sleep, supplements, compounds, protocols and body data into one place so you can see how they connect over time. It is a wellness and information tool. It is not a medical device, it does not diagnose disease, and it does not give medical advice.
This policy explains what data we collect, why, who processes it on our behalf, and how you can delete it. We do not sell your personal information.
1. Data we collect
| Category | What it is | When we collect it |
|---|---|---|
| Account data | Email address, password (stored by our authentication provider, never in plain text) and authentication identifiers | When you create an account or sign in |
| Profile | Details you enter during setup, such as goals, age, sex, height, weight and body-composition targets | When you enter or edit them |
| Wellness logs | Meals, foods, water, workouts, sets, soreness check-ins, sleep, weight and body measurements, supplements, compounds, protocols and stacks, doses you log, notes and preferences | When you enter them |
| Apple Health (HealthKit) data | Only the types you approve, such as steps, active energy, workouts, heart rate, resting heart rate, heart rate variability, sleep, respiratory rate, blood oxygen, weight, body fat, lean mass, BMI and nutrition totals | Only after you grant permission in the iOS Health prompt. BioasisHQ reads this data; it does not write data to Apple Health |
| Camera and photos | Product barcodes you scan; photos of meals, supplement labels and nutrition labels; Form Checker video frames; images you choose from your photo library | Only when you use a camera, scan or photo feature and grant camera or photo permission |
| Microphone / voice | Voice recordings you make for voice logging or to talk to Cura | Only when you use a voice feature and grant microphone permission |
| Bluetooth | Readings from a supported kitchen scale you connect | Only while the app is open and you use the scale feature. Bluetooth is not used to determine your location |
| Purchase and subscription status | Which plan you hold, trial status, renewal and expiry, and an anonymous purchase identifier | When you start a trial, buy, restore, or your subscription renews or ends |
| Diagnostics | App error reports and failed-lookup records (for example, a food search that returned no match) | Automatically when an error or failed lookup happens |
We do not collect your precise location or your contacts. The app contains no advertising SDKs and no third-party analytics or tracking SDKs, and we do not track you across other companies' apps or websites.
We do not use HealthKit data for advertising or marketing, we do not sell it, and we do not use it for data mining unrelated to providing the features you use. We do not store HealthKit data in iCloud.
2. How we use data
- Provide the features you use: logging, dashboards, trends, protocol and dose tracking, Form Checker, and connecting these records so you can see how they relate over time (the BioasisHQ intelligence engine, CIE, works only from your own records).
- Process subscriptions, trials and restored purchases.
- Answer support requests and enforce our Terms of Use.
- Keep the service secure and prevent abuse.
- Fix bugs and improve reliability, using diagnostics.
3. Cura AI: optional third-party processing, only with your consent
Cura features that use cloud AI are optional. Before any of your data is sent to a third-party AI provider, the app asks for your explicit consent ("Allow Cura AI?"). Nothing is sent unless you tap Allow. Our servers also refuse AI requests from accounts that have not given consent.
If you allow it, we may send the following to OpenAI (United States) so Cura can answer you:
- text or voice prompts you send to Cura (voice is transcribed by OpenAI);
- food descriptions, meal photos, supplement-label photos and nutrition-label photos you ask us to scan;
- summaries of your app activity that are needed to answer your question;
- limited wellness metrics (for example steps, sleep or heart rate) when they are relevant to your request.
If cloud voice playback is used, the text Cura is about to speak is sent to OpenAI or ElevenLabs (United States) to generate the audio.
All AI requests are made from our servers, not directly from your phone. The first-launch Cura tutorial is scripted and runs on your device; it does not send data to OpenAI. You can withdraw Cura AI consent at any time in Settings → Privacy & Data Use → Cura AI Processing. After you withdraw consent, no new data is sent to these providers. Under OpenAI's API terms, data sent through the API is not used to train OpenAI's models by default.
4. Who processes your data (service providers)
| Provider | What they do for us | Data involved |
|---|---|---|
| Supabase (United States) | Authentication, database, file storage and server functions. Most of your data is stored here, linked to your account | Account data, profile, wellness logs, photos and audio you upload, purchase status, diagnostics |
| OpenAI | Optional Cura AI processing, only after your consent | As described in Section 3 |
| ElevenLabs | Optional Cura cloud voice playback, only after your consent | Text to be spoken |
| RevenueCat | Subscription and receipt management (App Store purchase validation, entitlement status) | Anonymous app user ID, purchase and subscription status. RevenueCat does not receive your health data |
| Apple | HealthKit, in-app purchases and payments, under Apple's own policies | As governed by Apple |
| Nutrition data providers (FatSecret, USDA FoodData Central, Open Food Facts) | Food search and barcode lookup | The food names you search or the barcode number you scan, not linked to your health records or identity. Some barcode and food lookups are sent directly from your device to Open Food Facts or USDA, so those services can see your device's IP address |
| MuscleWiki | Exercise data and demonstration videos | Requested through BioasisHQ's servers; your personal information is not shared with MuscleWiki |
We share data with these providers only to run BioasisHQ. We do not sell personal information and we do not share it for advertising.
5. Subscriptions
Purchases are processed by Apple. We never see your payment card. RevenueCat tells the app which plan you hold. See the Terms of Use for plan details, trials, renewal and cancellation.
6. Retention and account deletion
We keep your data for as long as your account exists, so the app can show your history.
Delete your account in the app:
- Open BioasisHQ and go to Settings.
- Under Account, tap your email (Account & deletion). You can also get there from Settings → Privacy & Data Use.
- Tap Delete Account.
- Type DELETE to confirm, then tap Delete My Account.
Deletion happens immediately and cannot be undone. We delete your login, your profile and the personal app data linked to your account, including your nutrition, exercise, protocol and stack logs, saved preferences and Cura AI consent settings, and the app clears the data stored on your phone.
Some records are kept after deletion with the link to your account removed, so they are no longer associated with you: entries you contributed to shared catalogs (such as food or supplement submissions), food-lookup and app error logs. Files you uploaded (such as meal or label photos) may remain in our file storage after the account is deleted; email support@bioasishq.com from the address on your account and we will delete them. If you can't sign in, email us and we will delete your account for you.
Deleting the app from your phone does not delete your account. Deleting your account does not cancel an Apple subscription; cancel it in iOS Settings → [your name] → Subscriptions → BioasisHQ.
You can revoke HealthKit access at any time in iOS Settings → Health → Data Access & Devices → BioasisHQ, and camera, photo, microphone and Bluetooth access in iOS Settings → BioasisHQ.
7. Security
Data is sent over encrypted connections. Supabase, our storage provider, encrypts stored data. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.
8. Your choices and rights
You can access and correct most of your data in the app, withdraw Cura AI consent, revoke device permissions, and delete your account at any time. There is no self-serve export in the app today; to get a copy of your data, email support@bioasishq.com. Depending on where you live (for example the EU/UK or California), you may have additional rights to access, correct, delete or port your data, or to object to certain processing. To make a request, email support@bioasishq.com. We will not discriminate against you for exercising these rights.
9. Children
BioasisHQ is intended for adults and is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe a child has given us data, contact us and we will delete it.
10. International users
We are based in the United States and store data in the United States. By using BioasisHQ, your data will be processed in the United States.
11. Health information, FDA status and no medical advice
BioasisHQ is for education and personal organization only. It does not provide medical advice, diagnosis or treatment, and it does not provide dosing recommendations. Where the app shows an FDA status for a compound, that is a factual label with a link to the official FDA record (for example Drugs@FDA) or a statement that no official record is linked. It is not a claim that BioasisHQ, or any particular use of a compound, is approved by the FDA. Always consult a qualified healthcare professional before making medical decisions.
12. Changes
If we change this policy, we will update the date above and, for material changes, tell you in the app.
13. Contact
LWTC LLC — BioasisHQ
Email: support@bioasishq.com