Privacy Policy

Last updated: July 22, 2026

BioVantage AI is a medical education and clinical decision-support application. This Privacy Policy explains how information is collected, used, stored, and protected — including data from your Google account — when you use the application (the "Service"). By creating an account or signing in, you agree to the practices described here.

1. Google User Data We Access

When you sign in using your Google account, we request access to the following Google user data through OAuth scopes:

  • OpenID Connect identity: Your Google account email address and a public profile identifier (name) to create and identify your account.
  • Email address (openid / userinfo.email): Used as your unique account identifier and for account-related communications.

We do not request, and do not access, your Google Contacts, Google Drive files, Google Calendar, Gmail messages, YouTube data, or any other Google service data beyond the basic identity scopes listed above.

2. How We Use Your Data

We use the information we collect — including Google user data — solely to provide and improve the Service's functionality:

  • To authenticate you and maintain your secure session.
  • To create and manage your user profile, preferences, and progress.
  • To store your case study history, challenge scores, analysis history, and study paths so you can review them later.
  • To send transactional emails such as verification codes, recovery confirmations, and security notifications.
  • To generate aggregated, anonymous analytics to improve app performance and user experience.

We do not use your Google user data to serve personalized advertising, and we do not sell your data to any third party.

3. Data You Provide Directly

In addition to Google account data, you may voluntarily provide:

  • Display name, profile icon, gender (optional), and accessibility/preferences settings.
  • Symptoms, lab values, patient histories, and images you submit for AI analysis. You are responsible for removing any personally identifiable patient information before submission.
  • Recovery request notes if you request account restoration.

4. Sharing, Transfer, and Disclosure

We share, transfer, or disclose your data only in these limited circumstances:

  • Service providers: We use trusted infrastructure and AI processing providers that act as processors under our instructions (e.g., cloud hosting and large-language-model inference). These providers are bound by confidentiality and may not use your data for their own purposes.
  • App owners/administrators: If you are an app owner (admin), you may view limited account metadata (email, name, role, usage stats) for administrative purposes. Regular users cannot access other users' data.
  • Legal compliance: We may disclose data if required by law, court order, or to protect the rights, property, or safety of our users or the public.

We do not transfer Google user data to any third party for purposes other than providing or improving the Service's functionality.

5. Data Protection Mechanisms

We protect your data using industry-standard safeguards:

  • Authentication tokens and passwords are handled via secure, server-side session management; passwords are never stored in plain text.
  • Row-level security (RLS) policies enforce that users can only read and modify their own records unless they hold an authorized admin role.
  • Sensitive mutations (e.g., account recovery, display-name changes) are performed through authenticated backend functions that verify permissions server-side.
  • All communication with our servers is encrypted in transit over HTTPS/TLS.

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Data Retention and Deletion

We retain your data for as long as your account is active. You may request deletion at any time from Settings → Delete Your Account. When you delete your account:

  • Your account is deactivated and you can no longer sign in.
  • A secure, limited snapshot is retained in our deleted-users archive so an authorized owner can restore your account if needed.
  • Google user data obtained at sign-in (email, name) is retained only within this recovery snapshot until it is purged.

To request earlier deletion of your recovery snapshot, contact us through the in-app support options. We will process verified requests within 30 days.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. You can exercise several of these rights directly in the app (profile editing, data export via your records, account deletion). For other requests, contact us through the in-app support options.

8. Children's Privacy

The Service is intended for medical students, professionals, and educators. We do not knowingly collect data from children under 13 (or the applicable age in your jurisdiction). If you believe we have collected data from a minor, contact us and we will promptly remove it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date and notify you of material changes through the app or by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your data, reach us through the in-app Contact Support page or at the support email listed in the app.