Privacy by design

Privacy Policy

Last updated: 3 May 2026 · Effective: 3 May 2026

Your health data belongs to you. This policy explains exactly what we collect, how we store and protect it, who can access it, and the rights you have at any time.

The short version

  • • Your data is not sold and is not used for advertising.
  • • DNA files are parsed in your browser: we store the derived markers report, never the raw genome file.
  • • Where AI works with text, direct identifiers are removed first. Document-image and photo features send the uploaded image itself to our AI processor so its contents can be read.
  • • You can export your account and health records as JSON, and delete your account, at any time from Settings.
  • • Data is encrypted in transit and at rest, with row-level isolation per user.

1. Who we are

BodySynk (“BodySynk”, “we”, “us”) is operated by Basse Consulting FZE, a company registered in the United Arab Emirates. Basse Consulting FZE is the legal entity responsible for operating the BodySynk platform at bodysynk.com, and is the data controller for personal data processed through the platform. For privacy questions, see the Contact section below.

2. What we collect

We only collect what you actively give us, plus the minimum needed to operate the service.

Account data

  • • Email address and authentication credentials.
  • • Display name and optional profile information.

Health data you upload

  • • Lab results (blood panels, biomarkers, etc.) you upload as PDFs or enter manually.
  • • Supplement and medication stacks, dosages and schedules.
  • • Fasting logs (start and end times, notes).
  • • Wearable summaries (sleep, HRV, steps, recovery) you choose to sync.
  • • Self-reported health conditions, family history and goals.
  • • DNA files: parsed locally in your browser. We only store the derived markers report, never the raw genome file or full sequence.
  • • Food scans and product lookups you perform.

Usage data

  • • Basic technical logs (timestamps, request paths, error codes) for security and reliability.
  • • Device and browser type, sufficient to render the app correctly.
  • • No advertising trackers, no third-party analytics that profile you across the web.

3. How we use your data

  • • Provide the core features: dashboards, summaries, fasting tracking, drug and food scans, and sharing with people you explicitly choose.
  • • Generate personalized insights from your own data — never cross-user profiling.
  • • Send transactional emails (sign-in, account changes, share invites). No marketing without consent.
  • • Detect abuse, fraud, and protect the integrity of the service.
  • • Comply with legal obligations.

4. AI processing & privacy filtering

Some BodySynk features (lab interpretation, the “Ask” assistant, drug interaction summaries, food insights) use large language models. How your data is handled depends on whether the feature works with text or with an image.

Text and structured data

  1. Where a document contains machine-readable text, that text is extracted within our trusted environment.
  2. Pattern-based, deterministic redaction removes names, dates of birth, IDs, addresses, phone numbers and other identifiers.
  3. A second verification pass re-scans the sanitized text. If identifiers remain, the request is blocked.
  4. Only the redacted text is sent to the AI provider, through our privacy gateway. The result is pseudonymized, not anonymous: it can still be linked back to your account within BodySynk.

Images, scanned documents and photos

Some workflows cannot be reduced to text before processing — scanned or photographed lab reports, imaging, supplement and medication labels, meal and skin photos, and images you attach in the assistant. For these features the uploaded image itself is transmitted to our AI processor over an encrypted connection so that its contents can be extracted or classified. Such an image may contain printed identifiers that we cannot remove in advance, so please avoid uploading documents containing information you do not wish to be processed this way.

We do not use your data to train AI models, and BodySynk does not retain prompt or response content in its own telemetry. We are still obtaining written confirmation from our AI provider regarding upstream retention, training use and processing regions, and we do not state those as settled facts until we have it.

Read the pipeline in plain language on our Trust Center.

6. Storage & security

  • • Encryption in transit (TLS) and at rest.
  • • Row-level security in our database — by default, only your own user can read your records.
  • • Strict separation between accounts; family or shared-access features require your explicit invitation.
  • • Principle of least privilege for internal access; engineering access to production data is logged and limited to incident response.
  • • Regular dependency and security scanning.

7. Sharing & disclosure

We share data only in these limited cases:

  • Sub-processors we use to run the service: cloud hosting, database and storage, email delivery, and AI inference. Text sent for AI processing is redacted first; document-image workflows send the image itself. We are in the process of documenting and executing each vendor’s data-processing terms and will not claim an agreement is in place before it is.
  • People you invite — family members or trusted contacts you explicitly grant access to.
  • Legal requirements — if compelled by a valid legal process. We push back on overbroad requests.
  • Business transfer — in the unlikely event of a merger or acquisition, your data and these protections move with the service. You will be notified in advance.

We do not sell your data. We do not share it with advertisers or data brokers. Ever.

8. Retention & deletion

  • • Account and health data are retained as long as your account is active.
  • • You can delete individual records (a lab, a fast, a supplement) at any time.
  • • Deleting your account removes your health records and uploaded files from our active systems and deletes your sign-in account. Copies can persist for a limited period in our hosting provider’s encrypted platform backups until those backups age out; we do not publish a fixed figure we have not verified with the provider.
  • • We retain a pseudonymous closure record (account age, record counts and any reason you type in) with no name, contact details or health content.
  • • Minimal operational logs may be retained for security and debugging up to 12 months.

9. Your rights

Wherever you live, you can:

  • Access — see the data we hold about you.
  • Export — download a structured JSON export of your account and health records from Settings, with time-limited links to your uploaded files. The export states what it covers and what it excludes (internal security logs, usage telemetry and regenerable caches). If you need something the export does not include, contact us.
  • Correct — edit any record at any time.
  • Delete — remove individual records or your entire account.
  • Restrict or object — to specific processing, by contacting us.
  • Withdraw consent — without affecting prior lawful processing.
  • Lodge a complaint — with your local data protection authority (EEA/UK).

10. International transfers

Core health data at rest is hosted in the European Union (Ireland). Other operational processing — application hosting at the network edge, email delivery and AI inference — may take place outside the EEA, and we do not currently claim that every byte of operational data stays in Europe. Where data leaves the EEA we rely on the transfer mechanisms in our providers’ terms, together with encryption in transit and identifier redaction on text sent for AI processing. We are completing our review of each provider’s transfer mechanism and processing region and will publish the outcome rather than assert it in advance.

11. Children

BodySynk is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

12. Not medical advice

BodySynk surfaces patterns in your data and provides educational context. Nothing on the platform is medical advice, diagnosis or treatment. Always consult a qualified clinician before making health decisions or changing medications.

13. Changes to this policy

When we make material changes, we will notify you by email and in-app at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the current version.

14. Contact us

Privacy questions, data requests, or anything else: [email protected]. You can also reach us via the contact page.