1. Your privacy and your choices
This policy explains how BioMIR handles information in the app, on this website and through optional data-sharing programs. You can use the app without sharing your health records with BioMIR. Participation in a data-sharing program is voluntary and requires a separate opt-in.
Apple Health permission lets the app read the records you authorize. It does not give BioMIR permission to receive those records or use them for research. Each program explains its purpose, eligible data, risks and withdrawal process before you decide.
2. Information used on your device
With your permission, BioMIR reads supported Apple Health measurements and clinical records. It also uses profile details, including age and sex where needed, and information you enter in the app. These records support your metrics, trends and explanations. Available results depend on your permissions and the information available.
App history is stored locally. Core health calculations do not require sending your records to BioMIR. Demo records are synthetic and are excluded from the optional program export. You can change Apple Health permissions in system settings; withdrawing program consent does not change your Apple Health records.
3. Optional sharing with BioMIR
In Settings → Authorization → Research Consent, review the available program and choose which eligible data to include. The current program evaluates daily habits, sleep and fitness to improve BioMIR’s Behavioral and Functional scores. It includes selected history already stored by the app, including previously synced days. It excludes cardiometabolic records, clinical records and clinical-model results.
The current consent permits only the stated software evaluation. It does not permit clinical-model development, estimates of years of aging or mortality risk, advertising, sale or unrelated research. Additional data categories or purposes require separate disclosure and consent.
Creating an export does not send it. You decide whether to save or share the file. Before sending records to BioMIR, contact research@biomir.co to confirm an approved transfer method and the applicable program terms. Do not attach health records to ordinary email. Exporting a file does not enroll you in a clinical trial.
4. Export privacy: what is removed and retained
The export includes only specifically permitted fields. Names, email addresses, other contact details, addresses, account and device identifiers, location, date of birth, original calendar dates and free-text notes are excluded. Software-build details and the date of consent are also excluded. Random codes identify the export and consent record; they are not generated from your identity or device.
The file retains selected measurements, sex, exact fractional age (age expressed in years, including a decimal part), and elapsed days between observations. This preserves the timing needed for analysis without including original calendar dates.
Removing direct identifiers reduces privacy risk but does not guarantee anonymity. Precise age and detailed health patterns may still allow someone to identify a person or link records. The export has not been qualified as meeting a formal HIPAA de-identification method. BioMIR’s program must not attempt to identify participants from exported health patterns or combine them with outside information to identify them.
A service you use to share the file may reveal your sender address or account details separately. An email alias hides an address; it does not anonymize the health records. Review both the file and the destination before sharing.
5. Recipients and safeguards
BioMIR is the intended recipient for its own program. Before accepting a file, the program must identify its responsible organization, authorized recipients and transfer arrangements. Any service provider handling the file must be bound to equivalent protections, limited purposes and appropriate deletion requirements. New recipients or uses require the disclosure and permission applicable to that program.
The temporary app export uses iOS file protection and is excluded from device backup. Closing the export screen removes that temporary copy. Files you save or send remain at the destinations you choose and are outside the app’s control.
Program requirements include access limited to authorized personnel, secure storage and transfer, separation of contact correspondence from analytical records, and documented withdrawal and deletion. These requirements must be verified before BioMIR accepts program files. This policy is not evidence that a receiving service has been qualified.
6. Retention, withdrawal and deletion
The current program limits retention of received source files to 12 months after receipt, or less when a verified deletion request is received. Its service targets are acknowledgment within 7 days and completion within 30 days. These are BioMIR policy commitments, not universal statutory deadlines. Any legally required exception must be explained.
Turning Research Consent off stops future program exports in the app. To withdraw from use of a file already received by BioMIR, contact research@biomir.co. Once the request is verified and the file located, the program must stop new use of the affected source records and associated participant-level analysis records. A deletion request covers those records and working copies. Completed analyses and combined results that cannot identify you may remain.
Keep the random dataset code supplied with your export: it helps locate your file without providing additional health information. BioMIR may need limited information to verify a request. If a file cannot be located, that limitation must be explained. Withdrawal cannot retrieve copies held independently by recipients you chose.
Before accepting files, BioMIR must document backup deletion periods and any legal retention obligations. Copies awaiting deletion or retained under a legal obligation must be excluded from further program use. You must be told the reason, scope and duration of any remaining retention.
For support correspondence and other information supplied directly to BioMIR, contact contact@biomir.co to request access, correction or deletion. Retention periods for correspondence and website logs must be established and disclosed before this revision becomes effective.
7. Website and other services
This website stores your light or dark theme choice in browser local storage. Wix provides the website hosting. Hosting services may process IP addresses and technical request logs to deliver and secure the website. This privacy page does not accept health-record submissions.
Apple processes App Store purchases under its own policies. External links, email services and services you choose for sharing have their own practices. BioMIR must maintain an accurate inventory of its service providers, processing locations, retention periods and any analytics or tracking before publication; additional collection must be disclosed.
8. Questions and privacy requests
Contact research@biomir.co for program participation, transfer arrangements, withdrawal or deletion of program records. Contact contact@biomir.co for general support and other privacy questions. Avoid including health records in an initial email. Correspondence itself reveals the sender’s address and message contents.
Privacy rights and complaint routes depend on your location and the laws that apply. BioMIR must confirm its responsible legal entity, applicable rights, service-provider arrangements and any cross-border processing before this policy becomes effective. Each program must also define eligibility, including how requests involving minors are handled. This policy does not authorize participation by a minor.
9. Policy versions and changes
The public policy address is https://www.biomir.co/privacy. Prior versions remain available in the policy history. The date and version identify the text; a preparation date does not establish that it has been approved or taken effect.
Changes to a program’s purpose, data categories or recipients require updated disclosure and consent where applicable. A general policy update does not expand permission you previously gave. Program-specific consent remains separate from this policy.