Privacy Policy
Last updated: 2 September 2026
Data Controller & Contact Information
Data Controller: bionico GmbH, Zug, Switzerland
Email: info@bionico.swiss
bionico is committed to protecting your health data with the highest level of privacy and security. This Privacy Policy explains how we collect, use, and protect your personal health information.
What Health Data We Collect
bionico collects the following types of health information when you upload data to your profile:
- Blood biomarker data: Lab results including glucose, lipids, liver enzymes, kidney function, thyroid markers, and complete blood counts parsed from lab PDFs
- Genomic variants: Genetic variants from 23andMe exports, whole-genome sequencing files (
.vcfand gzipped.vcf.gz), and manual star-allele entries (e.g. CYP2D6 *1/*4). Coverage includes APOE, SLCO1B1, MTHFR, FOXO3, CYP1A2, ALDH2, HLA-B, F5 Leiden, VKORC1, and 40+ other clinically relevant polymorphisms across pharmacogenomics, nutrition, cardiometabolic, and fitness domains. Whole-genome sequencing files are parsed entirely on-device; only the interpreted rsID and genotype pairs are transmitted to our backend — raw sequence data never leaves your device. - Wearable metrics: Integration with Apple Health, WHOOP, Oura, and Garmin data including heart rate, sleep, recovery, activity, and HRV
- Medical records: Any additional medical records or DICOM files you upload
Where Your Health Data Is Stored
Web app (demo.bionico.ch): Your health data is stored locally in your browser's localStorage. You can clear all stored information at any time by clearing your browser's localStorage.
iOS app: When you use the bionico iOS app, your health data is stored in a Supabase-hosted PostgreSQL database in Zurich, Switzerland (AWS region eu-central-2), and the server-side functions that assemble requests for you execute in Zurich as well. Your account is protected by authentication, and Row Level Security ensures only you can access your data. You can delete your account and all data at any time in the app, or request deletion by contacting us.
Apple HealthKit: The bionico iOS app reads health data from Apple HealthKit with your explicit permission, including heart rate, heart rate variability (HRV), sleep analysis, and blood oxygen (SpO2). This data is used solely to generate your personalised health profile and is synced to your secure Supabase account. bionico does not sell, share, or use HealthKit data for advertising or marketing purposes, in compliance with Apple's HealthKit guidelines.
Wearable connections (WHOOP, Oura): You may optionally connect a WHOOP or Oura account. Nothing is read until you authorise it, and the connection is made through the provider’s own sign-in — bionico never sees your WHOOP or Oura password. From WHOOP we read sleep (stage durations and efficiency), recovery (heart rate variability, resting heart rate, blood oxygen), daily cycles and workouts. From Oura we read the daily sleep, activity and readiness summaries and overnight blood oxygen. We do not request profile or body-measurement data from either provider. The access tokens are held encrypted in Supabase Vault in Zurich and never leave it; the readings themselves are stored in your Zurich database alongside the rest of your data. You can disconnect at any time in the app, which deletes the stored credential.
Data sovereignty: You maintain complete control and ownership of your health data across both web and iOS platforms.
Backup: If you use browser sync features (iCloud, Google, etc.), your web localStorage may be synced to those services according to their privacy policies.
What Is Sent to Our Servers & Third Parties
Third-party AI processor — Anthropic PBC. bionico uses Anthropic's Claude API (operated by Anthropic PBC, San Francisco, USA) as its sole AI provider. The bionico iOS app presents an in-app disclosure and obtains your explicit permission before any data is sent to Anthropic. You can withdraw consent at any time in the app under Profile → "AI & your data" (withdrawing stops every AI feature, including the weekly letter, until you allow it again), by deleting your account from the Profile tab, or by emailing info@bionico.swiss.
What is sent to Anthropic, by feature:
- Ask (chat with your twin): The messages you type into the Ask tab, together with your recent readings (heart-rate variability, resting heart rate, oxygen, sleep), environmental and calendar context, and recent messages from the same thread so the answer has continuity. Genetic information appears only as an interpretation (for example "slower caffeine metabolism"); rsIDs and genotypes are removed before the request leaves our servers. No identifiers, email, or auth tokens are sent.
- Meals (photo analysis): The meal photos you choose to analyze, plus a generic non-personal "balanced eating" instruction string. No identifiers are sent.
- Lab / wearable / document upload: The contents of lab reports, wearable exports and other health documents you upload from the Profile tab, plus the file name and the category you selected, read once to extract their values. Genetic files are never sent to Anthropic: genome files and genetic test exports are read on your phone (Profile → Import genetics) and our servers refuse them as upload types.
- Health profile scoring: Your age in years, sex and goal, the biomarkers, wearable readings, Apple Health summary metrics, medications and conditions stored in your bionico account, and for genetics only the gene, domain, interpretation and evidence tier of each marker. No name, e-mail, date of birth, rsID, genotype or zygosity is included; our servers remove these fields before the request is sent. Sent only when you tap "Generate profile".
- Weekly synthesis letter: Once a week, your recent readiness scores, wearable trends, training sessions, meals, active medications, conditions, and notable biomarkers are processed to write your personal weekly letter. This runs only for accounts that have accepted the in-app AI disclosure.
What is NOT sent to Anthropic: your name, email address, date of birth, Apple ID, Apple Sign-in tokens, Supabase auth tokens, your genome file, the rsIDs and genotypes of your genetic markers, your calendar titles or precise location, or any data you have not actively submitted via an AI feature (the weekly letter being the one scheduled exception described above).
Anthropic's data handling. Per Anthropic's Commercial Terms of Service, Anthropic does not use API inputs or outputs to train models. Under Anthropic's default API data-retention policy, requests and responses are retained for up to 30 days for trust-and-safety monitoring and then deleted. Anthropic processes data in the United States. Anthropic is not certified under the Swiss–US Data Privacy Framework; the transfer relies on the EU Standard Contractual Clauses (Modules 2 and 3) with the Swiss addendum, as permitted by Art. 16(2)(d) of the Swiss Federal Act on Data Protection, supported by our transfer impact assessment. We are aiming to move AI processing to European data centres with version 1.3.
Other infrastructure (no AI processing):
- Supabase (Zurich, Switzerland — eu-central-2) — hosts your account database with row-level security, so only you can read your data.
- Netlify, Inc. (USA; content served from its global edge network) — hosts this website and stores the name, contact, country and goal fields of the access questionnaire until we have processed them. Your answers about genetic testing and blood work are not sent to Netlify; they are stored in our database in Zurich, Switzerland. Netlify does not process health data from the app.
- Apple HealthKit — read-only on your device with your explicit per-category permission. HealthKit data is never sold, shared, or used for advertising.
- WHOOP, Inc. (USA) — only if you choose to connect a WHOOP account. bionico requests your sleep, recovery, cycle and workout data from WHOOP’s servers using an access token you authorise. Your bionico health record is never sent to WHOOP; the flow is inbound only.
- Oura Health Oy (Finland, EU; some infrastructure in the USA) — only if you choose to connect an Oura account. bionico requests your daily sleep, activity and readiness summaries and overnight blood oxygen. As with WHOOP, your bionico health record is never sent to Oura; the flow is inbound only.
- NCBI PubMed (public research database, USA) — to select current research for your weekly letter, we query PubMed using short, non-identifying search terms derived from your flagged markers or condition names (for example, a biomarker name). No identifiers, personal values, or account data are ever included in these queries.
No third-party analytics or tracking: bionico does not use Google Analytics, Mixpanel, Segment, or any third-party analytics services. We do not track your behaviour or install tracking cookies.
No advertising or data sales: We never sell, share, or license your health data to advertisers, insurers, pharmaceutical companies, or any third party. Ever. The only sharing that exists is sharing you start yourself — see "Sharing You Initiate" below.
Sharing You Initiate
Clinician report links. You can create an expiring, private link that shares a snapshot of your health profile — lab values, medications, wearable trends, and a genetics summary (genotypes and raw genetic identifiers are never included) — with a clinician of your choice. The link's token is stored only as a cryptographic hash. The link expires automatically (7 or 30 days, your choice), you can revoke it at any time with immediate effect, and every time the report is opened, a counter visible to you is updated. Report generation is deterministic and involves no AI processing.
Sharing a report is entirely your action, addressed to a recipient you choose. bionico never shares your health data with anyone on its own initiative.
Account Deletion
You can permanently delete your bionico account and all associated data at any time:
- iOS app: Open the Profile tab, scroll to the "Delete account" section at the bottom, tap Delete account, and confirm. This permanently removes your account and every record we hold about you (health profile, biomarkers, genomics, wearable data, meals, chat history, uploads, daily state).
- Web app: Clear your browser localStorage for
demo.bionico.ch, or email info@bionico.swiss with "Delete my account" in the subject line.
Account deletion is irreversible. Once executed, your data cannot be recovered.
Your Health Data Rights Under Swiss Data Protection Law (nDSG)
Applicable regulation: Your health data is protected under the Federal Act on Data Protection (Bundesgesetz über den Datenschutz — nDSG), which came into force on January 1, 2023.
Classification as Sensitive Personal Data
Under Article 5 of the nDSG, health data — including genetic information, biomarkers, lab results, and wearable metrics — is classified as sensitive personal data. Processing sensitive personal data is only permitted when:
- Explicit consent has been obtained from the data subject (you), or
- Processing is required by law for specific purposes
Our Legal Basis
bionico processes your health data on the basis of explicit consent (Article 5(1) nDSG). When you upload health data to bionico, you provide explicit consent for us to:
- Store your data — on the iOS app, in a Supabase-hosted PostgreSQL database in Zurich, Switzerland (AWS eu-central-2) protected by authentication and Row Level Security; on the web app, in your browser's localStorage
- Transmit data to Claude AI for analysis and personalised health insights, only after you have accepted the in-app AI disclosure
- Generate your Digital Health Twin and domain scores
Your Data Subject Rights
Under Article 15 of the nDSG, you have the following rights:
- Right of access: You can request confirmation of what health data bionico holds about you and receive a copy of it
- Right of correction: You can request correction of inaccurate health data
- Right to deletion: You can delete your data yourself — on the iOS app, via Profile → Delete account; on the web app, by clearing your browser localStorage — or request deletion by contacting us
- Right to data portability: You can request your data in a structured, machine-readable format
- Right to withdraw consent: You can withdraw your consent at any time, preventing further processing
Exercising Your Rights
To exercise any of these rights, contact us at info@bionico.swiss with "Data Subject Request" in the subject line. We will respond to your request within 30 days.
Your Health Data Rights Under GDPR (Article 9)
Applicable regulation: If you are located in the European Union or United Kingdom, your health data is also protected under the General Data Protection Regulation (GDPR).
Special Category Data
Under Article 9(1) of the GDPR, health data (including genetic information and biometric data) is classified as special category personal data. Processing special category data is prohibited unless specific conditions apply.
Our Legal Basis
bionico processes your health data under Article 9(2)(a) GDPR — explicit consent. You provide this consent when you upload health data to bionico and use the platform.
Your Data Subject Rights
Under Chapter III of the GDPR, you have the following rights:
- Right of access (Article 15): You can request and receive a copy of your personal data
- Right to rectification (Article 16): You can correct inaccurate data
- Right to erasure (Article 17): You can request deletion of your data
- Right to restrict processing (Article 18): You can restrict how we use your data
- Right to data portability (Article 20): You can receive your data in a portable format
- Right to object (Article 21): You can object to processing of your data
- Right to withdraw consent (Article 7): You can withdraw consent at any time
Exercising Your Rights
To exercise any of these rights, contact us at info@bionico.swiss with "Data Subject Request" in the subject line. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Data Retention & Deletion
- iOS app: Data is stored in a Supabase-hosted PostgreSQL database in Zurich, Switzerland (AWS eu-central-2). You can permanently delete your account and all associated data at any time from Profile → Delete account in the app, which executes an immediate cascading delete across every table that holds your rows. Any operational backup snapshots are purged within 30 days. You can also request deletion by email.
- Web app: Data persists in browser localStorage until you explicitly clear it. You can delete all data by clearing your browser cache and localStorage, or by emailing us.
- AI requests: Data sent to Anthropic's Claude API is retained by Anthropic for up to 30 days for trust-and-safety monitoring under its default API policy, then deleted. Anthropic does not use it to train models.
- Retention limits inside bionico: Ask conversations and weekly letters are kept for 12 months, environmental context for 90 days, the raw AI response behind a meal analysis for 30 days, and expired or revoked clinician report links for 30 days; a nightly job removes older records.
- Account deletion is irreversible. Once executed, your data cannot be recovered.
Security Measures
- iOS app storage: Health data is stored in a Supabase-hosted PostgreSQL database in Zurich, Switzerland (AWS eu-central-2). Every table is protected by Row Level Security policies so that only the authenticated account owner can read or write their rows. Authentication credentials are held in the iOS Keychain; application state is held in the app's private sandbox.
- Web app storage: The web demo stores data in browser localStorage on your device. Data is not encrypted at rest in localStorage; for additional security, we recommend device-level encryption (e.g. FileVault).
- On-device genetics: Genome files (.vcf and .vcf.gz) and genetic test exports are parsed entirely on your device; only the matched rsID and genotype pairs, with their curated interpretation, are stored in your bionico account. They are never sent to any AI provider — the AI receives the interpretation only.
- Transport security: All data sent to Supabase and to Claude AI is transmitted over TLS 1.3, providing encryption in transit.
- Hosting infrastructure: This website is hosted by Netlify, Inc. (SOC 2 Type II). The iOS app's backend database is hosted by Supabase in Zurich, Switzerland (AWS eu-central-2) under a Data Processing Agreement, and its server-side functions execute in Zurich as well.
- Authentication: Access to your account is protected by Sign in with Apple or email-based authentication with session tokens managed by Supabase Auth.
- No third-party access: We do not share encryption keys, access tokens, or authentication credentials with any third party.
Children's Privacy
bionico is not intended for individuals under 18 years of age. We do not knowingly collect health data from children. If you are aware of a child using bionico, please contact us at info@bionico.swiss.
International Data Transfers
iOS app. Your health data is stored in the Supabase-hosted PostgreSQL database in Zurich, Switzerland, and our server-side functions run in Zurich as well. Data leaves Switzerland and the EU only when an AI feature you have consented to routes a request to Anthropic's Claude API in the United States, and, for the weekly letter's research selection, when short non-identifying search terms are sent to NCBI PubMed (USA). For Anthropic the safeguard is the EU Standard Contractual Clauses with the Swiss addendum (Anthropic is not on the Swiss–US Data Privacy Framework list); the name, contact and goal fields of the website access questionnaire are stored by Netlify, Inc. (USA) under its data processing terms, while the questionnaire's answers about genetic testing and blood work stay in our Swiss database.
Wearable connections. If you connect WHOOP (WHOOP, Inc., United States) or Oura (Oura Health Oy, Finland, with some infrastructure in the United States), bionico makes a request to that provider carrying only the access token you authorised, and receives your readings in return. This is an inbound flow: none of your bionico health record, laboratory results, genetics or clinical documents is ever sent to WHOOP or Oura. What each provider already holds about you is governed by your own agreement with them, and their own privacy policy applies to it. The readings we receive are stored in Zurich with everything else, and disconnecting removes the stored credential.
Web app. Data stored in browser localStorage remains on your local device and is not transferred internationally unless you explicitly use an AI feature.
Anthropic. Anthropic does not use API data for model training. See "What Is Sent to Our Servers & Third Parties" above for per-feature detail.
Policy Changes
bionico may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. We will notify you of material changes by updating the "Last updated" date on this page and, if required, by email. Your continued use of bionico following such changes constitutes acceptance of the updated Privacy Policy.
Contact & Data Subject Requests
Email: info@bionico.swiss
Mailing address: bionico GmbH, Zug, Switzerland
For privacy concerns, data subject requests, or to exercise your rights under nDSG or GDPR, please contact us with "Data Subject Request" or "Privacy Inquiry" in the subject line. We will respond within 30 days.
Legal Disclaimer
This Privacy Policy is an informational overview, not legal advice. While we have made efforts to ensure accuracy, data protection law is complex and jurisdiction-specific. If you require a formal legal interpretation of how nDSG, GDPR, or other data protection regulations apply to your use of bionico, we strongly recommend consulting with qualified legal counsel in your jurisdiction.