Privacy Policy
Effective Date: April 1, 2026 | Last Updated: April 1, 2026
1. Introduction
BioEquilibria LLC ("Company," "we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and safeguard your personal information and health-related data when you access or use the BioEquilibria mobile application, website at bioeq.ai, web application, and any related services, features, or platforms we operate (collectively, the "Application").
BioEquilibria LLC operates as a Business Associate under HIPAA with respect to healthcare providers ("Covered Entities") who use or integrate with the Application. We do not directly provide medical services. Our HIPAA obligations arise through Business Associate Agreements ("BAAs") executed with Covered Entities whose patients' PHI we create, receive, maintain, or transmit on their behalf.
This Policy should be read in conjunction with our Terms of Service, which govern your use of the Application. By using the Application, you consent to the practices described in this Policy. If you do not agree with this Policy, please do not access or use the Application.
2. Information We Collect
2.1 Information You Provide Directly
Account Information: Name, email address, date of birth, password, and other registration details you submit when creating an account.
Health and Wellness Data: Health metrics, biometric data, dietary information, exercise logs, symptoms, goals, medications, supplement usage, and any other health-related information you voluntarily enter or upload into the Application.
User-Generated Content: Notes, journal entries, preferences, feedback, and communications you provide through the Application or to our support team.
Payment Information: If applicable, billing details processed through our third-party payment processor(s). We do not directly store full credit card numbers on our servers.
2.2 Information Collected Automatically
Device and Usage Data: Device type, operating system, unique device identifiers, IP address, browser type, app version, time zone, language settings, and usage patterns (e.g., features accessed, session duration, interaction timestamps).
Cookies and Tracking Technologies: We may use cookies, pixel tags, SDKs, and similar technologies to collect usage data and improve the Application experience. You can manage cookie preferences through your device or browser settings.
Log Data: Server logs that may include your IP address, access times, pages or screens viewed, app crashes, and referring URLs.
2.3 Information from Third Parties
We may receive information from integrated third-party services or platforms (e.g., wearable devices, fitness trackers, health platforms) that you choose to connect to the Application, subject to the permissions you grant.
2.4 Telehealth Data
If you use the Application's telehealth or telemedicine features, we may collect additional information in connection with remote healthcare consultations, including but not limited to: consultation records, clinical notes, diagnoses, treatment plans, prescriptions, audio or video recordings of sessions (where permitted by law and with your consent), and communications between you and healthcare providers. Telehealth data may constitute Protected Health Information (PHI) and is subject to the HIPAA protections described in this Policy.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and Operating the Application: To deliver Health Content, generate AI-powered insights and recommendations, personalize your experience, and maintain core functionality.
- Account Management: To create, maintain, and secure your account.
- Improvement and Development: To analyze usage trends, conduct research, develop new features, debug issues, and improve the accuracy and relevance of AI-generated outputs.
- Communications: To send service-related notifications, respond to your inquiries, and (with your consent where required) send promotional or educational content.
- Safety and Security: To detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Telehealth Services: To facilitate remote healthcare consultations, maintain telehealth session records, coordinate care between you and licensed healthcare providers, and comply with applicable state telehealth requirements.
- Aggregated and De-identified Data: We may create aggregated, anonymized, or de-identified datasets from your information for research, analytics, or business purposes. Such data cannot reasonably be used to identify you.
4. AI and Algorithmic Processing
The Application uses artificial intelligence and machine learning models to generate personalized Health Content. In connection with this processing:
- Your health data may be processed by automated systems to generate recommendations, insights, calculations, and tracking outputs.
- The Application is not a medical device, has not been evaluated or approved by the FDA, and is not intended to diagnose, treat, cure, or prevent any disease. All AI-generated outputs are for informational and educational purposes only and should be reviewed with a qualified healthcare provider.
- AI models are trained on broad, de-identified datasets. Your personal data, including any PHI, is not used to train or fine-tune third-party AI models without your explicit written authorization. All AI/ML providers that process PHI operate under Business Associate Agreements.
- Automated outputs are not reviewed by a licensed healthcare professional before delivery and may contain inaccuracies or biases inherent to algorithmic systems.
- You may request information about the logic involved in automated decision-making that affects you by contacting us at the address provided in Section 16.
5. How We Share Your Information
We do not sell your personal health data. We may share your information only in the following limited circumstances:
| Recipient | Purpose and Details |
|---|---|
| Service Providers | Third-party vendors who perform services on our behalf (e.g., cloud hosting, analytics, AI/ML providers, payment processing). These providers are bound by contractual data protection obligations and, where applicable, Business Associate Agreements. |
| Covered Entities | Healthcare providers with whom we have BAAs and who have authorized the exchange of PHI through the Application for treatment, payment, and healthcare operations. |
| Legal and Regulatory | When required by law, regulation, subpoena, court order, or governmental request; or to protect our rights, safety, or property, or that of our users or the public. |
| Business Transfers | In connection with a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets. We will notify you of any such change. |
| With Your Consent | We may share information with third parties when you have given us explicit consent to do so. |
| Aggregated/De-identified | We may share aggregated or de-identified data that cannot reasonably be used to identify you, for research, analytics, or business purposes. |
5.1 Information Shared by You
The Application may permit you to share your Health Information with healthcare providers, family members, caregivers, or other individuals you designate ("Authorized Recipients"). We are not responsible for any unauthorized access, use, or disclosure of your information caused by Authorized Recipients. Once shared, copies may be incorporated into the recipient's own records, and we cannot retrieve, modify, or delete information from third-party systems. Sharing is entirely voluntary and at your own risk.
6. Data Retention and Account Deletion
We retain your personal information for as long as your account is active or as needed to provide you with the Application's services. We may also retain and use your information as necessary to comply with legal obligations, resolve disputes, enforce our agreements, maintain security, and fulfill legitimate business purposes.
You may delete your account at any time through the in-app account settings, via your account settings at bioeq.ai, or by contacting our Privacy Officer at the address in Section 16 or by emailing privacy@bioeq.ai. Upon account deletion, we will permanently delete your personal information and account data within the timeframe required by applicable law, except where retention is required by law or contractual obligation.
Certain records may be retained as required under our Business Associate Agreements with Covered Entities, including HIPAA record retention requirements. Applicable state medical record retention laws may additionally require retention of health-related documentation for defined periods.
We will also retain a disclosure log recording how your Health Information was shared with third parties, providers, and Authorized Recipients during the life of your account. This log will be maintained only for as long as necessary to satisfy applicable legal and contractual obligations, after which it will be securely deleted.
All retained data will continue to be protected under HIPAA and this Policy. Once all applicable retention periods have expired, any remaining data will be securely deleted or de-identified. Account deletion is permanent and irreversible.
7. Data Security
We implement reasonable and appropriate administrative, technical, and physical safeguards in compliance with the HIPAA Security Rule designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication mechanisms
- Regular security assessments and monitoring
- Employee training on data protection practices
HOWEVER, NO METHOD OF ELECTRONIC TRANSMISSION OR STORAGE IS COMPLETELY SECURE. WE CANNOT AND DO NOT GUARANTEE THE ABSOLUTE SECURITY OF YOUR DATA. YOU ACKNOWLEDGE AND ACCEPT THE INHERENT RISKS OF PROVIDING INFORMATION ELECTRONICALLY.
In the event of a Breach of Unsecured PHI, we will notify the applicable Covered Entity in accordance with the HIPAA Breach Notification Rule (45 CFR § 164.410). The Covered Entity is responsible for notifying affected individuals as required by 45 CFR §§ 164.404–408. For non-PHI security breaches, we will notify affected users and applicable regulatory authorities in accordance with applicable state and federal law.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information and account data. You may delete your account through the in-app settings, via web, or by contacting our Privacy Officer. Certain data may be retained as required by law or contractual obligation (see Section 6).
- Data Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
- Restriction of Processing: Request that we limit the processing of your data under certain circumstances.
- Objection: Object to processing of your personal information based on legitimate interests.
- Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Opt-Out of Marketing: Unsubscribe from marketing communications at any time.
With respect to PHI, your HIPAA rights (including access, amendment, and accounting of disclosures) are provided to you by your healthcare provider (the Covered Entity), not by BioEquilibria LLC directly. We will cooperate with the Covered Entity to support the fulfillment of these rights as required by our BAA.
To exercise any of your rights under this Policy, please contact us using the information in Section 16. We will respond within the timeframe required by applicable law. We may verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.
9. Children's Privacy
The Application is not directed to children under the age of 13. In compliance with the Children's Online Privacy Protection Act ("COPPA", 15 U.S.C. §§ 6501–6506), we do not knowingly collect, use, or disclose personal information from children under 13 without verifiable parental consent. Users between the ages of 13 and 17 may use the Application only with the consent and supervision of a parent or legal guardian, as described in our Terms of Service.
If we learn that we have collected personal information from a child under 13 without proper parental consent, we will take prompt steps to delete that information. If you believe a child under 13 has provided us with personal information, please contact us at the address in Section 16.
10. State-Specific Privacy Rights
10.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to request deletion, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination. We do not sell your personal information as defined under the CCPA/CPRA.
You may designate an authorized agent to submit privacy requests on your behalf. If you use an authorized agent, we may require the agent to provide written proof of authorization (such as a signed power of attorney or written permission from you), and we may verify your identity directly before processing the request.
To submit a verifiable consumer request, please contact us using the information in Section 16.
10.2 Washington Residents (My Health My Data Act)
If you are a Washington State resident, you have additional rights under the Washington My Health My Data Act (MHMDA, RCW 19.373), which provides specific protections for consumer health data collected by health-related applications, wellness platforms, and similar services.
Under the MHMDA, you have the right to:
- Know whether we are collecting, sharing, or selling your consumer health data.
- Withdraw consent for future collection and sharing of your consumer health data.
- Request deletion of your consumer health data, which we will fulfill within thirty (30) days of receiving a verified request.
We will obtain your consent before collecting or sharing consumer health data as defined under the MHMDA. We do not sell consumer health data. We do not use geofencing technology around healthcare facilities for the purpose of collecting consumer health data or delivering advertising.
The MHMDA provides a private right of action, meaning Washington residents may bring legal claims for violations of this law. To exercise your rights under the MHMDA, please contact us using the information in Section 16.
10.3 Other U.S. State Laws
Residents of states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, and Texas) may have additional rights such as the right to appeal a decision regarding a privacy rights request. To exercise these rights, please contact us at the address in Section 16.
11. HIPAA Compliance
BioEquilibria LLC operates as a Business Associate under HIPAA with respect to healthcare providers (Covered Entities) who use or integrate with the Application. Our HIPAA obligations are defined by the Business Associate Agreements we execute with these Covered Entities.
11.1 Our Obligations as a Business Associate
In our role as a Business Associate, we:
- Use and disclose PHI only as permitted by our BAAs and as required by law.
- Implement administrative, physical, and technical safeguards in compliance with the HIPAA Security Rule to protect the confidentiality, integrity, and availability of electronic PHI.
- Report any Breach of Unsecured PHI to the applicable Covered Entity in accordance with 45 CFR § 164.410.
- Ensure that any subcontractors that handle PHI on our behalf agree to substantially the same restrictions and conditions.
- Support Covered Entities in fulfilling their obligations to patients, including facilitating access, amendment, and accounting of disclosures of PHI.
- Make our internal practices and records available to the Secretary of HHS for compliance determination purposes.
11.2 Your HIPAA Rights
Your rights under HIPAA with respect to your Protected Health Information — including the right to access your PHI, request amendments, receive an accounting of disclosures, request restrictions, and request confidential communications — are provided to you by your healthcare provider (the Covered Entity), not by BioEquilibria LLC directly. If you wish to exercise your HIPAA rights, please contact your healthcare provider. We will cooperate with the Covered Entity to support the fulfillment of these rights as required by our BAA.
11.3 Breach Notification
In the event of a Breach of Unsecured PHI, we will notify the applicable Covered Entity without unreasonable delay and no later than sixty (60) calendar days from discovery. The Covered Entity is responsible for notifying affected individuals and the U.S. Department of Health and Human Services as required by the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414).
11.4 Complaints
If you believe your privacy rights have been violated, you may file a complaint with your healthcare provider (the Covered Entity) or directly with the U.S. Department of Health and Human Services, Office for Civil Rights. Information about filing a complaint with HHS is available at https://www.hhs.gov/ocr/complaints . You may also contact our Privacy Officer at the address in Section 16.
12. Do Not Track Disclosure
Some web browsers include a "Do Not Track" (DNT) feature that sends a signal to websites and online services indicating that you do not wish to be tracked. There is currently no uniform standard for how companies should respond to DNT signals. Accordingly, the Application does not currently respond to or process DNT signals. You can manage your tracking preferences through your browser or device settings.
13. International Visitors
The Application and all Services are intended for use in the United States only. We do not target, direct, or offer the Application to users outside of the United States, including users in the European Union or European Economic Area. If you access the Application from outside the United States, you do so at your own risk and are solely responsible for compliance with your local laws. By using the Application, you consent to the transfer, processing, and storage of your information in the United States.
14. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will provide notice through the Application or via the email address associated with your account at least thirty (30) days before the changes take effect.
Your continued use of the Application after the effective date of any modifications constitutes your acceptance of the updated Policy.
15. Information Shared by You
The Application may permit you to share your Health Information with healthcare providers, family members, caregivers, or other individuals you designate ("Authorized Recipients"). We are not responsible for any unauthorized access, use, or disclosure of your information caused by Authorized Recipients or other third parties.
Once your information has been shared, copies may be incorporated into the recipient's own records. We cannot retrieve, modify, or delete information from third-party systems. Sharing is entirely voluntary and at your own risk.
If you use social media integrations or post information in any public or semi-public setting through the Application, that information may be broadly visible and is not controlled by BioEquilibria LLC.
16. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
BioEquilibria LLCPrivacy Officer: Geo Marquez
Email: privacy@bioeq.ai
Address: 175 N Main St, Unit #1022, Alpharetta, GA 30009
Website: bioeq.ai
© 2026 BioEquilibria LLC. All rights reserved.