← Biomize

Privacy Policy

Last updated: June 4, 2026

This Privacy Policy explains how Eli Gelb (“we,” “us,” or “I”), the operator of Biomize (the “Service”), collects, uses, and shares information about you. Biomize is an independent, personal health-and-productivity insights tool, currently offered as a private, invite-only beta. Because the Service processes health-related information, please read this policy carefully. By using the Service you agree to this policy and to our Terms of Service.

1. Who we are

The Service is operated by Eli Gelb, an individual based in New York, USA. For any privacy question or request, email eligelb1@gmail.com.

2. Information we collect

a. Account & authentication. We use Clerk, Inc. for sign-in. We collect your email address, your name (if provided), and authentication identifiers. We do not store your password — Clerk handles credentials.

b. Biometric & health data from devices you connect. If you connect them, we collect:

  • Oura Ring: sleep stages and duration, sleep and readiness scores, heart-rate variability (HRV), resting and overnight heart rate, respiratory rate, body-temperature deviation, and related daily summaries.
  • Dexcom (continuous glucose monitor): glucose readings and trends.

c. Calendar data. If you connect Google Calendar, we collect event times, titles, durations, and attendee counts to relate your schedule to your biometrics.

d. Information you enter manually. Notes, tags, and logs you create — which may include sensitive details such as alcohol or cannabis use, caffeine, late meals, workouts, mood, and approximate phone/screen-time usage.

e. Derived & environmental data. Weather for your area (via Open-Meteo) and the analytics, models, and insights we compute from your data.

f. Technical data. Basic information needed to run the Service (timestamps, request and error logs). We do not use third-party advertising trackers.

3. Where your data comes from

We collect data (i) directly from you, and (ii) from the third-party services you choose to connect (Oura, Dexcom, Google), using credentials you authorize. You can disconnect any source at any time.

4. How we use your information

  • To provide and operate the Service and display your data.
  • To generate personalized insights, forecasts, and your AI morning briefing.
  • To compute statistical and machine-learning models from your own data (an “n-of-1” personal model).
  • To maintain security, debug, and improve the Service.
  • To communicate with you about the Service.

We do not sell your personal information, and we do not use it for advertising.

5. How we share your information (service providers)

We share data only with the providers that make the Service work, and only as needed:

ProviderPurposeData involved
Clerk, Inc.AuthenticationAccount identifiers, email
Neon, Inc.Database hostingAll stored Service data (encrypted in transit)
Fly.io, Inc.Backend/API hostingService data in processing
Vercel Inc.Frontend hostingApp delivery; no health data stored
Anthropic, PBCGenerating insights & briefings (Claude AI)The biometric/calendar/log context needed to write an insight
OpenAI, L.L.C.Text-to-speech for the spoken briefingThe text of your briefing
Google LLCCalendar source (if connected)OAuth tokens; calendar events
Dexcom, Inc.Glucose source (if connected)OAuth tokens; glucose data
Open-MeteoWeatherCoarse area only

About the AI providers. When we generate an insight or briefing, the relevant portion of your data is sent to Anthropic and/or OpenAI to produce the result. Per their API terms, Anthropic and OpenAI do not use data submitted through their APIs to train their models by default, and retain it only transiently for abuse monitoring. We send the minimum context needed.

We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer (e.g., if the Service is acquired) — in which case we will notify you.

6. Google API data — Limited Use

Biomize’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data solely to provide user-facing features within the Service; we do not transfer or sell it, do not use it for advertising, and do not use it to train generalized AI models.

7. Consumer health data

Some information you provide or connect (sleep, HRV, glucose, substance-use logs, and similar) is “consumer health data” under laws such as Washington’s My Health My Data Act and similar state laws. We collect and process this data only to provide the Service to you, with your consent, and we do not sell it. You may withdraw consent and delete this data at any time (see Section 9). For health-data questions, email eligelb1@gmail.com.

8. Data retention

We keep your data while your account is active. When you delete specific data or your account, we delete the associated personal data from our active systems, and from backups within a reasonable period. We may retain limited records where required by law.

9. Your rights and choices

Regardless of where you live, you can:

  • Access / export your data — email us.
  • Delete your data or your entire account — email eligelb1@gmail.com and we will delete it.
  • Disconnect any data source at any time in Settings, which stops further collection from it.
  • Withdraw consent to processing of your consumer health data.

Depending on your state (e.g., California) or country (e.g., the EEA/UK under GDPR), you may have additional rights such as correction, portability, restriction, objection, and the right to complain to a regulator. We honor these requests — email eligelb1@gmail.com and we will respond as required by law. We will not discriminate against you for exercising your rights.

10. Security

We protect your data with encryption in transit (HTTPS/TLS), authenticated access, hosting on reputable infrastructure, and least-necessary data sharing. No system is perfectly secure, but we work to protect your information and will notify you and authorities of a breach of unsecured health data as required, including under the FTC Health Breach Notification Rule.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a minor has used the Service, contact us and we will delete the data.

12. International users

The Service is operated from the United States. If you access it from outside the U.S., you understand your data will be processed in the U.S.

13. Changes to this policy

We may update this policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, notice in the app.

14. Contact

Eli Gelb — Biomize
Email: eligelb1@gmail.com
New York, USA