Privacy Policy
Version 1.0.0-draft · Effective August 10, 2026
Prelaunch draft. BTech LLC will have this document reviewed before public distribution.
BTech LLC, a New Mexico limited liability company (“BTech,” “we,” or “us”), operates BiaVis. This policy explains what BiaVis collects, why it is used, how long it is kept, and the choices available to you. Contact privacy@biavis.app with privacy questions.
Information we process
- Account and identity: an anonymous account UUID; Sign in with Apple identifiers, email or private-relay email, and name when Apple supplies it; handle; profile appearance; country; and timezone.
- Fitness and competition: workout results, BiaVis Points, ratings, splits, challenges, Club participation, posts, RSVPs, reports, blocks, and moderation records.
- Verification evidence: precise GPS coordinates, timestamps, speed and accuracy values, motion classifications, device pseudonyms, app/device details, and verification diagnostics. Camera video is processed on-device and is not uploaded; body-joint coordinates derived from the camera may be uploaded to verify a result.
- Apple Health: raw HealthKit samples are read only with permission and remain on the device. Optional summaries can be shared with a Club only after an explicit choice.
- Support and safety: messages you send and the operational records needed to investigate, respond, prevent abuse, and meet legal obligations.
How we use information
We use information to provide workouts and competition; verify results and detect cheating or vehicle travel; calculate standings and BiaVis Points; operate social and safety features; export or delete your data; secure, diagnose, and improve the service; and meet legal obligations. We do not sell personal data, use cross-app tracking, run targeted advertising, or use health data for marketing.
Location and route privacy
Personal routes are private by default and are not placed on a public map or social feed. Verification evidence containing GPS coordinates temporarily leaves the phone so the server can independently validate a run or ride. Accepted evidence is scheduled for deletion after 30 days; evidence requiring review or considered suspicious is scheduled for deletion after 90 days. Device-only practice traces are kept for up to seven days.
Sharing and processors
We disclose information only as needed to operate the service, follow your sharing choices, protect people and the service, complete a business transaction subject to appropriate safeguards, or comply with law. Current categories of processors include Apple for platform identity, notifications, HealthKit, and distribution; Supabase for authentication, database, functions, and private evidence storage; Sites/Cloudflare infrastructure for the static website; and Porkbun for domain email. A current subprocessor record will be maintained before launch.
Retention
- Accepted verification evidence: 30 days.
- Review or suspicious evidence: 90 days.
- Device-only practice traces: 7 days.
- Completed export packages: links expire after 48 hours and packages are purged within 72 hours.
- Delivered notification payloads: 30 days; failed operational records: 90 days.
- Closed safety reports: 24 months, unless safety or litigation obligations require longer.
- Legal-acceptance proofs: six years after account closure, pseudonymously.
- Account, profile, and social information: for the account lifetime, then deleted or pseudonymized as described below.
Competitive result facts may remain pseudonymous after account deletion to preserve standings and anti-cheat integrity. Vendor logs and backups follow the actual retention configured with each processor; the final public policy will state those audited periods.
Your choices and rights
You can review permissions, request an export, delete local workout history, sign out, block accounts, or delete your account in Account & Safety. Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, or receive portable data. See the Data Rights page or email privacy@biavis.app. We will verify requests before disclosing or changing account data.
International use
BTech is based in the United States. Use from another country may involve transfers to the United States and other processor locations. Before worldwide launch, BTech will document the transfer mechanism and appoint EU or UK representatives if required.
Security and children
We use access controls, private storage, encryption in transit, row-level database security, and limited-retention evidence. No system is perfectly secure. BiaVis is restricted to people age 18 or older and is not directed to children.
Changes
Material Terms changes require renewed acceptance. Material privacy changes will be highlighted in the app; clarifications may be shown as a nonblocking notice. The version and effective date above identify this policy.