BioHACK

Effective Date: 2026-08-07 · Last Modified: 2026-08-07


1. Summary

For easy reading, here is a summary first. See the sections below for details.

Stored only on your device Daily self-assessment records, card completion logs, completion rates, practice responses
Stored on our servers Account information, content posted to the social feed/chat, anonymous usage statistics
Sale / advertising use We do not. We do not use health-related information for advertising or marketing, and we do not sell it to third parties
Advertising / tracking SDKs Not used
Deletion You can delete your account and data within the app

2. Information Stored Only on Your Device and Never Transmitted

The following is stored only on your device and is never transmitted to the Company's servers.

Storage method: an encrypted local database (Android: Room / iOS: GRDB, with SQLCipher applied). Recommendation calculations are also performed on your device, and no data is sent externally during this process.

If you delete the app, this information is deleted from your device along with it, and the Company cannot recover it.


3. Information Stored on Our Servers

3.1 Account Information

3.2 Content You Post (Social Feed and Chat)

3.3 Usage Statistics

3.4 Pre-Registration Email (Pre-Launch)


4. Information We Do Not Collect

In the interest of transparency, the Company does not collect the following:

We do not use advertising SDKs or tracking SDKs. Accordingly, the Service does not display an iOS tracking-permission prompt.


5. Handling of Health-Related Information

Because BioHACK is a health and wellness service, much of the information you enter may constitute health information or sensitive information under applicable law.

The Company commits to the following:

The Company is not a Covered Entity under the U.S. HIPAA. BioHACK is not a medical institution and does not provide medical services.


6. Third-Party Disclosure and Processing Entrustment

The Company does not sell personal information. To the extent necessary to operate the Service, we entrust processing to the following:

Processor Processing Activity Location
Supabase Authentication, database, realtime communication Japan (Tokyo) — AWS ap-northeast-1
Google Account sign-in (OAuth) United States, among others
Cloudflare R2 Audio content delivery (download only) Global CDN
Apple / Google Payment processing (upon introduction of subscriptions) Each company's own policies

We may provide information to relevant authorities where required by law, or where necessary to prevent an imminent risk to life or bodily safety.


7. Cross-Border Transfer

Users' personal information is stored in Japan. In accordance with Article 28-8 of the Personal Information Protection Act of Korea (PIPA), we provide the following disclosure:

Item Details
Recipient of transfer Supabase, Inc. (contact channel published at supabase.com/privacy)
Country of transfer Japan — Amazon Web Services Tokyo region (ap-northeast-1)
Timing and method of transfer Continuously during use of the Service, via encrypted transmission over telecommunications networks
Items transferred All items collected as listed in Section 3 above (account identifier, email, profile, activity records, posts, chat)
Purpose of use Providing the Service, including authentication, data storage, and realtime communication
Retention period Until account withdrawal or termination of the processing agreement

In addition, Google account sign-in (OAuth) is processed in the United States, and audio content delivery is processed through Cloudflare's global CDN. The CDN only delivers content and does not store account information, but your connecting IP address is processed during transmission.

If you do not wish to consent, your use of the Service may be limited — because our storage infrastructure is located outside Korea, we cannot provide account functionality without this transfer.

When transferring personal information of EU residents, we rely on Standard Contractual Clauses (SCCs) or another lawful transfer mechanism.

Raw measurement data is not transferred outside Korea. Raw sensor data — such as heart rate and sleep data — as well as audio and video, are stored only on your device and are never sent to our servers (ADR-0004). The items listed above under "Items transferred" are account and activity records.


8. Retention Period


9. Your Rights

Regardless of where you reside, you may request the following:

How to delete your account 1. In the app: iOS — Me tab → Delete Account · Android — Profile → Delete Account 2. Without the app installed: https://biohack.iaiu.net/delete-account

Deleting your account also deletes your account information, posts, and chat messages. If you have a subscription, you must cancel it separately, through the App Store or Google Play, for billing to stop.

Submit requests to: support@iaiu.net


10. Children's Personal Information

The Service is intended for users 16 and older. We do not knowingly collect personal information from anyone under 16, and if we become aware that we have done so, we delete it immediately.


11. Security

However, no method of transmission or storage can guarantee complete security.


12. Region-Specific Additional Notices


13. Changes

If the Company changes this Policy, it will notify you via in-app notice. Material changes will be announced at least 30 days before they take effect.


14. Contact

Data Protection Officer: Kim Chang-myoung (Representative) Email: privacy@iaiu.net Address: 17 Bundang-ro 201beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea (Seohyeon-dong) [경기도 성남시 분당구 분당로201번길 17 (서현동)] Business Entity: IAIU · Business Registration Number 213-08-81338