Trust Center

Trust is not a feature.
It is the foundation of BodySynk.

Your health data belongs to you. Not BodySynk. Not advertisers. Not insurers. Not AI companies. Every decision we make starts with that principle.

  • Your data stays private
  • You own your data
  • We do not sell your data
  • We do not train public AI models on your health data
  • No advertising profiles
  • Export or delete your data anytime
Data ownership

You own your health data

BodySynk is a place to keep, understand, and act on your own health information. It is not a place where your data quietly becomes someone else's asset.

You own it

Your health data is yours. BodySynk holds it on your behalf — we never claim ownership of what you put in.

You control it

You decide what to add, what to share, and what to remove. Nothing is shared with another person or organization without your action.

You can export it

Download your records, reports, and history at any time, in formats you can take with you.

You can delete it

Delete individual entries, full categories, or your entire account. When you delete, it is gone — not archived for analytics.

A platform you can trust should be easy to leave. Export your data, download your reports, or delete your account whenever you choose.

AI transparency

How AI works inside BodySynk

BodySynk does not simply hand your health data to an AI and ask it what it thinks. AI helps explain. It does not replace health reasoning.

  1. 01

    Your data is structured first

    BodySynk reads your data with structured health logic — not a generic AI prompt. The system identifies what is relevant before any AI is involved.

  2. 02

    Only the relevant context is selected

    Instead of handing an AI everything about you, BodySynk selects the narrow slice of context needed to answer the question in front of you.

  3. 03

    Identifiers are removed

    Names, IDs, dates of birth, addresses, and other identifiers are stripped through deterministic redaction before anything leaves the boundary.

  4. 04

    AI helps explain — not decide

    AI turns the structured findings into plain language. It does not replace health reasoning, and it does not see who you are.

Your health data is never used to train public AI models.

Your uploads, blood tests, reports, conversations, medications, supplements, imaging, and DNA information are not used to train ChatGPT, Claude, Gemini, or any other public AI system. Not by us. Not by our providers under our agreements.

Privacy by design

Built so that trust is not required

The strongest privacy controls are the ones the system enforces automatically, not the ones a policy document promises.

Protected in transit and at rest

Your health information is protected both while moving between your device and our systems, and while stored on our infrastructure.

We only process what is needed

BodySynk works from the smallest amount of data required to answer a question. Anything else is left alone.

Isolated, per-user workspaces

Your data lives in your own workspace, separated from other users by design. Row-level rules enforce that separation on every read and write.

Fail-safe defaults

If the system cannot guarantee privacy for a request, the request is blocked. We do not 'try anyway'.

Privacy Protection Pipeline

The process that runs before any AI sees your data.

Every upload and every AI request passes through six layers. There are no bypass paths.

  1. Step 01

    Secure upload

    Files travel over encrypted channels into your private workspace.

  2. Step 02

    Local text extraction

    Text is extracted inside our trusted environment, never through an external AI provider.

  3. Step 03

    Identifier detection

    Pattern-based redaction locates names, IDs, dates, and addresses. No external AI is used to detect personal data.

  4. Step 04

    Automatic redaction

    Identifiers are replaced with neutral tokens like [NAME] or [ID] before anything leaves the boundary.

  5. Step 05

    Double verification

    A second pass re-scans the sanitized text. If anything personal remains, the request is blocked.

  6. Step 06

    Final privacy checkpoint

    Every AI call flows through one gateway that requires a fresh proof of redaction. The build itself fails if any code tries to bypass it.

No ads. No data sales.

We do not monetize your health data

BodySynk earns money from people who choose to pay for BodySynk. That is the entire business model.

  • No advertising business model.
  • No sale of health data to anyone, ever.
  • No advertising profiles built from your records.
  • No third-party marketing use of your health information.
  • No data brokers, no insurer pipelines, no analytics resale.

If we ever changed this, you would be told plainly, before anything changed — and you would still be free to leave with all of your data.

Leaving BodySynk

You can leave anytime

A platform you cannot leave is not a platform you can trust. BodySynk is built so that walking away is straightforward.

Export your data

Take your records, reports, and history with you in standard formats.

Download your reports

Keep your generated health summaries and timelines, even if you stop using BodySynk.

Delete your account

Close your account whenever you want. No retention games, no hidden barriers, no win-back tricks.

Delete your personal health data

When you delete, your personal health data is removed from our active systems. We do not keep a shadow copy for analytics.

No lock-in. No hidden barriers. No dark patterns at the exit.

Compliance and roadmap

Where we are, and where we are going

We would rather be transparent about where we stand than claim certifications we do not hold.

Today

Encryption in transit and at rest, per-user data isolation, role-based access controls, audit logging, deterministic redaction before any AI call, and a final privacy checkpoint for every AI request.

In progress

Ongoing security reviews, expanded internal access controls, third-party penetration testing, and formalized incident response procedures.

Roadmap

Working toward recognized privacy and security frameworks appropriate to health data. We will publish updates here as each step is reached — not before.

This page is maintained by the BodySynk team. It describes practices that are in place today and is not a substitute for legal or regulatory certification.

Contact

Trust and security contact

One inbox for privacy, security, and data questions.

Security questions

Questions about how BodySynk is built, hosted, or protected.

Privacy questions

How your data is collected, used, retained, and deleted.

Data requests

Export, correct, or delete your personal data. You can also do this from inside the app.

Responsible disclosure

If you believe you have found a security issue, please contact us before publishing. We will respond and credit responsible reports.

Reach the trust and security team at [email protected].

Your data is yours. You can see it, take it, and remove it — at any time, for any reason.