Privacy Policy

Last updated: April 28, 2026

This Privacy Policy applies to the Biostacks mobile application for iOS and Android. Biostacks is built on a single principle: your health data belongs to you. We designed the app to collect as little data as possible and to keep your supplement data on your device unless you choose to use an optional feature that sends data elsewhere.

What we do not collect

We do not operate a Biostacks backend server for app data. We have no database of user accounts, supplement stacks, intake logs, or any other personal or health information you enter into the app.

Data stored on your device

Your supplements, stacks, intake logs, settings, and local backup history are stored locally on your device using on-device storage. Biostacks does not receive this data. It leaves your device only when you choose to use optional features such as cloud backup, barcode lookup, manual export, or AI sharing.

Optional cloud backup

If you enable iCloud or Google Drive backup, your data is synced to your personal cloud account using your own credentials. Biostacks cannot access your iCloud or Google Drive data. Apple and Google’s respective privacy policies govern that storage.

Optional barcode lookup

Barcode scanning is an optional feature. When you scan a barcode, the barcode may be sent to the National Institutes of Health dietary supplement label database and/or Open Food Facts to look up product information. The barcode is sent without a Biostacks account, name, email, or health profile attached. However, your IP address and standard request metadata may be visible to NIH or Open Food Facts as part of the network request.

Optional AI sharing

The “Share with AI” feature copies a prompt to your clipboard that includes the Biostacks schema and your current app configuration. Biostacks does not send this prompt to any AI service automatically. If you paste it into an AI assistant, you are choosing to share that information with that third-party service, and that service’s privacy policy applies.

Subscriptions

Biostacks uses RevenueCat to manage in-app subscriptions. RevenueCat receives purchase receipts and related app, device, and store information needed to validate your subscription. Biostacks does not share your supplements, stacks, intake logs, or other health information with RevenueCat. Purchases are processed by Apple (App Store) or Google (Google Play) under their respective privacy policies.

App permissions

Biostacks may ask for camera access for barcode scanning, notification permission for reminders, and file or clipboard access for import, export, backup, and AI sharing features. These permissions are used only for the feature you choose to use.

Security

Biostacks stores app data locally on your device and relies on your device operating system, device passcode or biometrics, and any cloud account protections you choose to use. If you enable iCloud or Google Drive backup, your synced data is protected by your Apple or Google account and their cloud storage systems. Biostacks cannot view, recover, or reset that data for you.

Deleting your data

Because Biostacks does not receive your app data, most deletion happens on your device or in your cloud account. You can delete local app data by deleting data in the app where available, deleting local snapshots from version history, or removing the app from your device. If you enabled iCloud or Google Drive backup, you are responsible for deleting any synced backup files from your own cloud account. You should also delete any manual exports, shared files, or AI prompts from the places where you saved or shared them.

Analytics and tracking

The Biostacks mobile app does not use analytics SDKs, advertising frameworks, or tracking pixels. We do not track how you use the app.

Children

Biostacks is not directed at children under 16. We do not knowingly collect any information from children.

Changes to this policy

If we make material changes we will update the date at the top of this page.

Contact

Questions? Email us at support@biostacks.app.