Privacy Policy

Effective date: July 25, 2026

This Privacy Policy explains how Bio-Conscious Technologies Inc. ("Bio-Conscious," "we," "us," or "our"), the maker of the Endobits platform, collects, uses, protects, and shares information when you visit our websites, contact us, or use our services. By using our site or services, you agree to the practices described here.

1. Who we are

Bio-Conscious Technologies Inc. builds predictive metabolic AI. Endobits is our clinical decision-support platform that reads continuous glucose monitoring (CGM) data to help clinicians predict, prioritize, and prevent metabolic disease. You can reach us at contact@bioconscious.tech.

2. Information we collect

  • Information you provide. When you fill out a form or contact us, we collect details such as your name, email address, organization or clinic/practice name, role, National Provider Identifier (NPI) if you choose to share it, and location.
  • Health and CGM data. Where you or your clinic choose to share it, we process glucose readings and related continuous glucose monitoring data, and information needed to generate reports.
  • Automatically collected data. Like most websites, we collect limited technical data such as IP address, device and browser type, and pages visited, through cookies and similar technologies.
  • Site assistant. If you use the question box on this website, we collect the question you type, along with limited technical data, so we can answer it, improve the site, and guard against misuse. Questions are processed by a third-party AI provider and kept for a limited period. The assistant answers only from the content of this website. Please do not include personal or health information in your question.

3. Protected Health Information (PHI)

When Endobits processes health information on behalf of a covered entity (such as a clinic or provider), we act as a business associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and handle that information in accordance with our Business Associate Agreements and applicable law. We use appropriate administrative, technical, and physical safeguards to protect PHI.

4. The Endobits™ Companion app — what stays on your phone

This section applies to the Endobits Companion iOS app.

What we collect on our servers:

  • Account email — used to create and sign in to your account. It is your account identifier.
  • Optional clinic information — if you choose to add your clinic or care contact in the app, we store it to prepare your doctor-ready report and, with your consent, to contact your clinic. This is optional; the app works fully without it.
  • App telemetry — a small, fixed list of first-party usage events (for example, "demo entered," "report generated") so we can see which features are used and fix problems. No third-party analytics SDKs. No advertising identifiers.
  • Sensor connection tokens — when you connect Dexcom, Eversense, or Nightscout, we store the access tokens needed to keep that connection alive, encrypted at rest. We do not store your sensor account password on our servers (credentials you choose to remember are stored in your device's secure keychain).

What stays on your device: your glucose readings and Apple Health data — glucose, meals (carbohydrates and energy), steps, heart rate, resting heart rate, sleep, workouts, active energy, and insulin delivery — are read and analyzed on your device. Forecasts, trends, and AGP analysis run locally. We do not upload this health data to our servers.

Apple Health (HealthKit) commitments: we request read-only access and never write to Apple Health. We will never use Apple Health data for advertising, marketing, or similar purposes; we will never sell it; and we will never share it with data brokers, advertising platforms, or analytics companies. Apple Health data is used solely to provide the app's features to you.

Research program (opt-in only): if you explicitly opt in inside the app, de-identified glucose pattern data may be used to improve our forecasting models. This is off by default, requires your explicit consent on a dedicated consent screen, and you can revoke it at any time in the app; revoking stops future use immediately. Data used under this program is de-identified before model training and is never sold or used for advertising.

Deletion: in the app, Settings → Delete account permanently deletes your server-side account and its data, removes stored connection tokens, and wipes the app's local keychain data. This is irreversible. Health data never left your device, so deleting the app removes it.

No ads: the Companion app shows no advertising and contains no third-party ad or tracking SDKs.

5. How we use information

  • To provide, operate, and improve the Endobits platform and generate reports.
  • To respond to your inquiries, provide support, and communicate about the service.
  • To secure our services, prevent fraud or misuse, and meet legal and regulatory obligations.
  • To develop and improve our models and features, using de-identified data as described below.

6. De-identified data

Where permitted and, where required, with your consent (for example, when you choose a "donate your data" option), we may use de-identified information, from which direct identifiers have been removed, to research, develop, and improve our algorithms and the metabolic-health field. De-identified data is not used to re-identify you.

7. How we share information

  • Service providers. With vendors who host, process, or support our services under confidentiality obligations.
  • Integrations you authorize. With CGM manufacturers, electronic health record (EHR/EMR) systems, and similar services you or your clinic connect.
  • Legal and safety. Where required by law, regulation, legal process, or to protect rights, safety, and security.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets.

We do not sell your personal information.

8. Data retention

We retain personal information for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it.

9. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal information, and to withdraw consent. Residents of certain jurisdictions (including under the EU/UK GDPR and the California Consumer Privacy Act) may have additional rights. To make a request, contact contact@bioconscious.tech. If your data is held by your clinic or provider, please also contact them directly.

11. Cookies

We use cookies and similar technologies to operate the site, remember preferences, and understand usage. You can control cookies through your browser settings.

12. Children's privacy

Our services are intended for healthcare professionals and adults. We do not knowingly collect personal information from children except where processed on behalf of a provider as part of clinical care and permitted by law.

13. International users

We are based in Canada and may process information in Canada, the United States, and other countries. Where required, we use appropriate safeguards for cross-border transfers.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted here with an updated effective date.

15. Contact us

Questions about this policy or your information? Email contact@bioconscious.tech.

This policy is provided for general information and does not constitute legal advice. It should be reviewed and adapted by qualified legal counsel for your specific jurisdiction and operations before publication.

Terms of Service →