The short version: Your biological data lives on your iPhone. We do not sell it, share it with advertisers, or store raw HealthKit data on our servers. You can export everything, or delete everything, from inside the app.
Bivryn ("we," "us," "our") is a personal biological intelligence app for iPhone and Apple Watch. This policy explains what data Bivryn collects, how it is used, and the choices you have. By using Bivryn, you agree to the practices described here.
With your permission, Bivryn reads health data from Apple Health, including:
This data is read on your device. Raw HealthKit samples never leave your iPhone or your iCloud account.
Anything you log inside Bivryn — supplements, medications, meals, mood, notes, symptoms, blood-work panels, family history, conditions, experiments — is stored locally on your device using SwiftData, with optional sync to your private iCloud database.
When you photograph a supplement label, medication, meal, or upload a blood-work PDF, the image or PDF is sent securely to our AI provider (Anthropic) for parsing. The parsed text result is returned to your device and stored locally. We do not retain the source image or PDF, and we do not store the parsed result on our servers.
If you grant location access, Bivryn uses Significant Location Changes (cell-tower-level accuracy, no GPS) to detect travel and interpret your biology accordingly (jet lag, circadian shift). Your coordinates stay on your device. Only an integer kilometer-from-home value is ever computed, and that value never leaves your device.
Bivryn uses PostHog to collect non-personal usage events (e.g., "user completed a breathing session," "user viewed Discoveries") so we can improve the product. We do not send personal information, health data, or your name to PostHog. Analytics are on by default and disclosed during onboarding. You can opt out anytime in Profile → Privacy.
Subscription transactions are processed by Apple through StoreKit. We do not receive your payment information. We do receive a transaction identifier from Apple to verify your entitlement.
Your data is used to:
Bivryn uses Anthropic's Claude API to generate biological interpretations. When Bivryn calls the API, only the minimum context required is sent — typically a summary of recent metrics (e.g., "sleep 6h 20m, HRV 38 ms below baseline") and your free-form question or note. We do not send your name, email, address, or any identifier that ties the request to you. Your iPhone calls Anthropic directly; our backend never sees the request body. Bivryn's lightweight server (Kriva) exists only to vend the API key to your device — it does not proxy or log your prompts. Anthropic processes requests in accordance with their commercial terms and does not use API content to train their models.
Non-personal product-usage events only. No health data, no PII. Opt-out available in-app.
Apple processes HealthKit reads on-device, CloudKit sync to your private iCloud, and StoreKit subscription transactions. Apple's privacy practices apply.
Bivryn is not intended for users under 13. If you are between 13 and 18, please use Bivryn only with the consent of a parent or guardian. We do not knowingly collect data from children.
Data on your device is protected by iOS data protection. Data in transit (e.g., API calls to our backend) is encrypted via TLS. We follow industry best practices, but no system is perfectly secure; we encourage you to keep your device updated and protected.
Bivryn is operated from the United States. If you use the app from outside the US, the data you generate locally remains on your device. Our backend services may be hosted in regions including the United States and the European Union. By using Bivryn, you consent to the transfer of any data we do collect (analytics, API requests) to these regions.
If you are a resident of the European Economic Area, the United Kingdom, or California, you have specific rights regarding your personal information: the right to access, correct, delete, restrict, or port your data, and the right to object to processing.
Because Bivryn stores most data on your device, you can exercise these rights directly through the in-app Export and Delete controls. For any data we do hold (analytics events, subscription receipts), contact us using the details in Section 12.
We may update this policy. When we do, we will update the "Last updated" date at the top and, for material changes, notify users in-app. Continued use of Bivryn after a change indicates acceptance.
For privacy questions, data requests, or any concerns, reach us at @SaySereze on X.