Bivryn
Features Support Terms
English
Get Bivryn

Privacy Policy

Last updated: June 30, 2026 · Effective immediately

The short version: Your biological data lives on your iPhone. We do not sell it, share it with advertisers, or store raw HealthKit data on our servers. You can export everything, or delete everything, from inside the app.

1. Who we are

Bivryn ("we," "us," "our") is a personal biological intelligence app for iPhone and Apple Watch. This policy explains what data Bivryn collects, how it is used, and the choices you have. By using Bivryn, you agree to the practices described here.

2. Data we collect

2.1 Health data (on-device)

With your permission, Bivryn reads health data from Apple Health, including:

  • Sleep duration and stages
  • Heart rate variability (HRV), resting heart rate, and walking heart rate
  • Heart-rate recovery after exercise
  • Active energy, steps, and respiratory rate
  • VO₂max, blood pressure, glucose, irregular heart rhythm notifications
  • Wrist temperature, menstrual cycle data, state of mind
  • Biological characteristics (sex, date of birth, height, weight, waist)

Computed on your device: Bivryn derives readings — Bio Age, body state, recovery curve, illness signal, trigger library — directly on your iPhone from the data above. These derivations stay local. They never leave your device unless you explicitly share a Doctor Snapshot export.

This data is read on your device. Raw HealthKit samples never leave your iPhone or your iCloud account.

2.2 Data you create inside Bivryn

Anything you log inside Bivryn — supplements, medications, meals, mood, notes, symptoms, blood-work panels, family history, conditions, experiments — is stored locally on your device using SwiftData, with optional sync to your private iCloud database.

2.3 Photos and PDFs

When you photograph a supplement label, medication, meal, or upload a blood-work PDF, the image or PDF is sent securely to our AI provider (Anthropic) for parsing. The parsed text result is returned to your device and stored locally. We do not retain the source image or PDF, and we do not store the parsed result on our servers.

2.4 Location (optional)

If you grant location access, Bivryn uses Significant Location Changes (cell-tower-level accuracy, no GPS) to detect travel and interpret your biology accordingly (jet lag, circadian shift). Your coordinates stay on your device. Only an integer kilometer-from-home value is ever computed, and that value never leaves your device.

2.5 My Circle sharing (optional, opt-in)

Bivryn's "My Circle" feature lets you optionally share a calm biology summary with up to 5 people you care about. When you invite someone and they accept, sharing works through Apple's CloudKit Shared Database, which is end-to-end encrypted between your iCloud account and theirs. Bivryn's servers never see the shared summary; Apple stores it encrypted on their infrastructure per their standard iCloud privacy terms.

What crosses the share depends on the permission tier you pick when you invite: "Summary Only" (default) sends a short interpretive read — e.g. "steady today" — with no numeric metrics. "Summary + Trends" adds directional arrows. "Everything" is an explicit opt-in that includes selected numeric fields (HRV, sleep, resting heart rate, etc.). At every tier, the sharer's raw HealthKit samples stay on the sharer's device — the share carries pre-computed interpretation values only.

We use Sign in with Apple to identify sharers to each other. Bivryn never sees your email address or phone number; the identity anchor is Apple's opaque user identifier. You can pause or remove any connection at any time, which stops all future shares to that person immediately. Existing shared summaries on Apple's servers age out per Apple's iCloud retention policy.

My Circle is off by default. You must explicitly create an invite for any sharing to occur. No contact-book access is requested by Bivryn; when you share an invite link, you pick the recipient yourself via iOS's standard share sheet or a QR code.

2.6 Weather (optional)

When you grant location, Bivryn also uses your coordinates to look up local weather (temperature, humidity, dew point) via Apple's WeatherKit, so it can contextualize sleep and HRV (hot nights, humid days). Coordinates are sent directly from your device to Apple's WeatherKit endpoint and never reach our servers. You can opt out anytime from Profile → Permissions, or by revoking Location in iOS Settings.

Weather data provided by Apple Weather. See Apple Weather legal attribution.

2.7 Analytics (opt-out available)

Bivryn uses PostHog to collect non-personal usage events (e.g., "user completed a breathing session," "user viewed Discoveries") so we can improve the product. We do not send personal information, health data, or your name to PostHog. Analytics are on by default and disclosed during onboarding. You can opt out anytime in Profile → Privacy.

2.8 Subscriptions

Subscription transactions are processed by Apple through StoreKit. We do not receive your payment information. We do receive a transaction identifier from Apple to verify your entitlement.

3. How we use data

Your data is used to:

  • Generate personalized interpretations of your biology (Body State, Discoveries, Bivryn Bio Age, Why Today, Weekly Recap, Ask Bivryn, Investigation).
  • Build your personal baselines and detect patterns over time — including the 1, 2, and 3-day lag patterns surfaced in Discoveries.
  • Contextualize your biology with local weather (temperature, humidity, dew point) when location is granted.
  • Render widgets, Live Activities, and Apple Watch complications.
  • Send optional notifications (morning briefing, post-meal walk reminder) when you've enabled them.

4. Third-party services

4.1 Anthropic (Claude API)

Bivryn uses Anthropic's Claude API to generate biological interpretations. When Bivryn calls the API, only the minimum context required is sent — typically a summary of recent metrics (e.g., "sleep 6h 20m, HRV 38 ms below baseline") and your free-form question or note. We do not send your name, email, address, or any identifier that ties the request to you. Your iPhone calls Anthropic directly; our backend never sees the request body. Bivryn's lightweight server (Kriva) exists only to vend the API key to your device — it does not proxy or log your prompts. Anthropic processes requests in accordance with their commercial terms and does not use API content to train their models.

4.2 PostHog (analytics)

Non-personal product-usage events only. No health data, no PII. Opt-out available in-app.

4.3 Apple (HealthKit, CloudKit, StoreKit, WeatherKit)

Apple processes HealthKit reads on-device, CloudKit sync to your private iCloud, StoreKit subscription transactions, and WeatherKit weather lookups (if you've granted location). For WeatherKit, your device sends a coordinate directly to Apple — our servers never see it. Apple's privacy practices apply to all four.

Weather data provided by Apple Weather. See Apple Weather legal attribution.

5. Data we do NOT collect

  • We do not have user accounts. We do not collect email addresses for account creation.
  • We do not collect your name, phone number, address, or government identifiers.
  • We do not collect or sell advertising identifiers.
  • We do not store your raw HealthKit data on our servers — ever.
  • We do not store images or PDFs you upload after they have been parsed.

6. Your choices

  • Export everything. Profile → Privacy → Export. You receive a JSON archive of everything Bivryn has stored locally.
  • Delete everything. Profile → Privacy → Delete all my data. One confirmation; full wipe.
  • Revoke permissions. Anytime, from iOS Settings → Privacy & Security → Health, Camera, Microphone, Speech Recognition, Location.
  • Opt out of analytics. Profile → Privacy → Analytics.
  • Cancel your subscription. iOS Settings → [Your Name] → Subscriptions.

7. Children

Bivryn is not intended for users under 13. If you are between 13 and 18, please use Bivryn only with the consent of a parent or guardian. We do not knowingly collect data from children.

8. Security

Data on your device is protected by iOS data protection. Data in transit (e.g., API calls to our backend) is encrypted via TLS. We follow industry best practices, but no system is perfectly secure; we encourage you to keep your device updated and protected.

9. International users

Bivryn is operated from the United States. If you use the app from outside the US, the data you generate locally remains on your device. Our backend services may be hosted in regions including the United States and the European Union. By using Bivryn, you consent to the transfer of any data we do collect (analytics, API requests) to these regions.

10. Your rights (GDPR, CCPA)

If you are a resident of the European Economic Area, the United Kingdom, or California, you have specific rights regarding your personal information: the right to access, correct, delete, restrict, or port your data, and the right to object to processing.

Because Bivryn stores most data on your device, you can exercise these rights directly through the in-app Export and Delete controls. For any data we do hold (analytics events, subscription receipts), contact us using the details in Section 12.

11. Changes to this policy

We may update this policy. When we do, we will update the "Last updated" date at the top and, for material changes, notify users in-app. Continued use of Bivryn after a change indicates acceptance.

12. Contact

For privacy questions, data requests, or any concerns, reach us at @SaySereze on X.

Ready when you are. 7-day free trial · iPhone + Apple Watch.

Get Bivryn
Bivryn

Biological intelligence for people who want their biology to make sense.

Product

Features Privacy

Company

Support X / Twitter

Legal

Privacy Policy Terms of Use
© 2026 Bivryn. All rights reserved. Bivryn is not a medical device. Informational only.