Effective 2026-04-24

Privacy Policy

What we collect, why, and how long we keep it.

This Privacy Policy explains how Filip Bochenek, a natural person established in Poland and operating the Service under the brand "BioStack" ("BioStack", "we", "our", "us") collects, uses, discloses, and protects information when you use the BioStack Intelligence application, website, APIs, and related services (collectively, the "Service"). Health data is sensitive; we treat it accordingly.

0. Data controller (RODO / GDPR)

For the purposes of Regulation (EU) 2016/679 ("RODO" in Poland; "GDPR" in English), the data controller (administrator danych osobowych) is:

  • Filip Bochenek, Poland.
  • Email for privacy / data-subject requests: biostack.legal@gmail.com.

We have not appointed a Data Protection Officer (Inspektor Ochrony Danych) because our processing does not meet the thresholds in Article 37 GDPR. You can reach the controller directly using the email above.

1. Information we collect

  • Account data. Email, authentication identifiers (via Supabase Auth / OAuth providers you select), and minimal profile attributes (display name, date of birth, biological sex, height, weight, training style, primary goal, PED status).
  • Health data you submit. Stack entries, cycles, bloodwork panels, markers, conversations with the AI Architect, saved protocols, and other notes you record. Some of this data falls into the "special category" of health data under Article 9 GDPR.
  • Payment data. Handled by our payment processor (Stripe). We receive only a customer identifier, subscription status, and last-four digits — never your full card number.
  • Device & usage data. IP address, user-agent, pages viewed, approximate locale/timezone, and basic crash diagnostics. Used for security, fraud prevention, and debugging.
  • Legal acceptance log. We store each legal-agreement acceptance with the version, timestamp, IP address, and user-agent to defend against future claims. See Section 5.

2. Legal bases for processing (Art. 6 & 9 GDPR)

  • Performance of a contract (Art. 6(1)(b) GDPR) — to provide the Service you signed up for: account creation, authentication, stack and bloodwork features, AI Architect responses, billing.
  • Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for processing of health data and other special-category data. You give this consent when you accept the agreements at /onboarding/agreement and tick the required checkboxes. You can withdraw consent at any time from Settings or by emailing us; withdrawal does not affect processing that occurred before withdrawal.
  • Legitimate interest (Art. 6(1)(f) GDPR) — security, fraud prevention, abuse detection, defending and establishing legal claims, and improving the Service. We balance these interests against your rights and only rely on this basis where your rights do not override.
  • Legal obligation (Art. 6(1)(c) GDPR) — retaining invoices and tax records as required by Polish and EU law; responding to lawful orders.

3. How we use data

  • To operate, secure, and improve the Service.
  • To generate personalized interpretations, interaction checks, and AI output — this processing happens on our infrastructure and on third-party inference APIs bound by data-processing agreements.
  • To comply with law, enforce our Terms, and protect the rights, property, and safety of users and the public.
  • We do not sell your personal data. We do not use your identifiable health data for advertising. We do not carry out automated decision-making with legal effect on you within the meaning of Article 22 GDPR — AI output is informational only and not a decision about you.

4. Sharing & processors

We share data only with service providers (processors) under contract who act on our documented instructions and offer appropriate safeguards. Current processors include:

  • Vercel Inc. (United States) — application hosting and edge functions.
  • Supabase, Inc. — managed Postgres database, authentication, and row-level security.
  • Stripe, Inc. — payment processing.
  • Anthropic, PBC and/or OpenAI, OpCo, LLC — large-language-model inference for the AI Architect feature.
  • PostHog (EU region) — privacy-focused product analytics (page views and feature usage). It is loaded only after you accept analytics cookies in the consent banner; session recording and autocapture are disabled, so we never record keystrokes, form inputs, or the health values you enter.
  • Email delivery and error monitoring providers.

We do not share your data with advertisers, data brokers, or unaffiliated third parties for marketing.

5. AI processing

When you use AI features, the minimum content necessary to answer your request is sent to our inference providers. We instruct providers not to train on your data where the provider supports such opt-outs. If you prefer not to have content processed by third-party models, do not use the AI Architect.

6. Retention

  • Active account data is retained for as long as your account is active.
  • If you delete your account, we delete or anonymize your profile, stack, bloodwork, and conversation data within 30 days, subject to backup cycles.
  • Legal acceptance records and a minimal compliance record (hashed user id, acceptance timestamps, document versions, IP and user-agent at acceptance) are retained for up to 6 years after account closure — the standard limitation period for civil claims under Article 118 of the Polish Civil Code — to preserve our ability to defend against claims. These records are not used for any other purpose.
  • Invoice and tax records are retained for at least 5 years from the end of the calendar year in which the tax obligation arose, as required by Article 86 of the Polish Tax Ordinance (Ordynacja podatkowa).

7. International transfers

Several of our processors are located outside the European Economic Area (notably the United States). Where we transfer personal data outside the EEA we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, supplementary technical and organizational measures. By using the Service you understand that your data may be transferred to and processed in such countries.

8. Security

We encrypt data in transit (TLS) and at rest. Database access is restricted via row-level security so that a user's data can only be read by that user (or by the controller under break-glass procedures). We log privileged access. No system is perfectly secure; you use the Service at your own risk.

9. Your rights under RODO / GDPR

Subject to the conditions in the GDPR, you have the right to:

  • Access your personal data and obtain a copy (Art. 15 GDPR).
  • Rectify inaccurate or incomplete data (Art. 16 GDPR).
  • Erase your data — "the right to be forgotten" (Art. 17 GDPR).
  • Restrict processing in certain circumstances (Art. 18 GDPR).
  • Receive your data in a portable, machine- readable format and transmit it to another controller (Art. 20 GDPR).
  • Object to processing based on legitimate interest (Art. 21 GDPR).
  • Withdraw consent at any time, without affecting the lawfulness of prior processing (Art. 7(3) GDPR).
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22 GDPR). We do not make such decisions about you.

You can exercise most of these rights directly from Settings. For anything else, email biostack.legal@gmail.com. We will respond within one month, extendable by two further months for complex requests, per Article 12(3) GDPR.

10. Right to lodge a complaint with a supervisory authority

If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland the competent authority is:

  • Prezes Urzędu Ochrony Danych Osobowych (UODO)
  • ul. Stawki 2, 00-193 Warszawa, Poland
  • Website: uodo.gov.pl

If you live in another EU/EEA country, you may instead lodge a complaint with the supervisory authority of your country of residence.

11. Children

The Service is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it.

12. Cookies and similar technologies

We use only the cookies and local-storage entries strictly necessary to authenticate you and remember preferences (theme, legal-acceptance state). We do not use advertising cookies, cross-site trackers, or analytics that profile you. Accordingly we do not show a consent banner — strictly necessary cookies do not require one under the Polish Telecommunications Act and Article 5(3) of the ePrivacy Directive.

13. Changes

We may update this Privacy Policy. Material changes are signaled by a version bump that routes you back through the acceptance screen on your next sign-in.

14. Contact

Privacy questions or data-subject requests: biostack.legal@gmail.com.

Privacy Policy · BioStack