English

Privacy Policy and GDPR Compliance

This Privacy Policy sets forth the types of personal data collected during the use of the Application “BioScore” and the website www.bioscore-app.com (including its subdomains), how such data is processed and used, and the circumstances under which it may be shared.

This Privacy Policy is incorporated within and made available to the User directly through the “BioScore” Application.

Last Updated: August 24, 2026.

1. PREAMBLE AND LEGAL DISCLAIMER

1.1 Nature of the Service:

BIOSCORE (hereinafter referred to as the “Application”) is a digital wellness and biological optimization tool published and operated by SHM GLOBAL LLC, having its principal office located at 2105 Vista Oeste NW - Suite E #3912, Albuquerque, NM 87120, USA, registered under EIN: 98-1899183 (hereinafter referred to as the “Publisher” or “Company”).

1.2 Avertissement médical fondamental

The Application IS NOT a medical device under Regulation (EU) 2017/745 on medical devices, nor under any applicable U.S. Food and Drug Administration (FDA) regulations or guidance.

Under no circumstances does the Application constitute or provide:

  • a medical teleconsultation or clinical service;

  • a tool for medical diagnosis, prognosis, treatment, or prescription;

  • a substitute for professional medical advice, evaluation, diagnosis, or treatment;

  • an in vitro diagnostic medical device (IVD).

The Application provides wellness optimization suggestions based on published scientific literature. These suggestions are offered strictly for general informational and educational purposes only. They do not substitute for a consultation with a qualified healthcare professional. The Publisher expressly disclaims any and all liability for any decisions made or actions taken by the User based on the information provided within the Application.

The User expressly acknowledges and agrees to use the service with a full understanding of this fundamental distinction. In the event of any medical concerns or questions regarding their health status, the User is strongly advised to consult a licensed physician or qualified healthcare provider without delay.

1.3 Purpose of this Privacy Policy:

The purpose of this Privacy Policy is to inform users of the Application (hereinafter referred to as the “User” or “Users”) of the policies and procedures governing the collection, processing, storage, and protection of their personal data, in accordance with Regulation (EU) 2016/679 of April 27, 2016 (General Data Protection Regulation or “GDPR”), French Law No. 78-17 of January 6, 1978, as amended (the “Data Protection Act”), applicable provisions of the French Public Health Code, and applicable U.S. federal and state privacy statutes.

The Publisher is committed to processing Users’ personal data with the utmost transparency, fairness, and diligence.

2. DATA CONTROLLER AND CONTACT INFORMATION:

2.1 Identity of the Data Controller:

The data controller responsible for the processing of personal data collected through the Application is:

SHM GLOBAL LLC

A New Mexico Limited Liability Company

Business Registration Number: 0008050985

Principal Office Address: 2105 Vista Oeste NW - Suite E #3912, Albuquerque, NM 87120, USA

Email: contact@bioscore-app.com

Managing Member / Officer: Simon Moniot

2.2 EU Representative:

Because the Publisher is established outside the European Union and offers services to individuals residing within the EU, it has designated a representative in the European Union pursuant to Article 27 of the GDPR:

Simon MONIOT

Address: 110 Avenue du Pont Juvénal, 34000 Montpellier, France

Email: contact@bioscore-app.com

This EU representative serves as the primary contact point for European supervisory authorities and data subjects regarding all matters pertaining to the processing of personal data.

2.3 Data Protection Point of Contact:

For any inquiries regarding the protection of your personal data or to exercise your privacy rights, you may contact:

Simon MONIOT

Email: contact@bioscore-app.com

Mailing Address: 110 Avenue du Pont Juvénal, 34000 Montpellier, France

The Publisher undertakes to respond to any such request within a maximum period of thirty (30) calendar days from receipt of the request, in accordance with Article 12.3 of the GDPR and applicable state privacy laws.

3. CATEGORIES OF DATA COLLECTED AND PURPOSES OF PROCESSING:

3.1 Categories of Data Collected:

The Application collects and processes the following categories of personal data:

a) Identification and Account Data

  • Email address

  • First name (optional)

  • Profile photo (optional)

  • Password (stored in encrypted/hashed form)

  • Internal Unique Identifier (UUID)

b) Profile and Preference Data

  • Biological sex (used solely for calibrating biomarker reference ranges)

  • Date of birth or age group

  • Primary wellness goal (optimization / overall health)

  • User-reported symptoms

  • User-reported dietary profile

c) Health Data (Special Category under Article 9 of the GDPR)

  • Blood and urine test results imported by the User (including numerical biomarker values, units of measurement, and laboratory reference ranges)

  • Date of specimen collection

  • Laboratory name

  • Historical lab data and biomarker tracking trends over time

  • Wellness and health score generated by the Application (“BioScore”)

d) Technical and Usage Data

  • IP address

  • Device type, model, and operating system

  • Session identifier

  • Access and usage logs

e) Billing and Subscription Data

  • Subscription history (plan type, start date, status)

  • Payment credentials (credit card details, etc.) are never collected, processed, or stored by the Publisher (see Section 8).

3.2 Purposes of Processing and Legal Bases:

The personal data collected by the Application is processed for the specific purposes, legal bases under the GDPR, and data categories set forth in the table below:

Purpose of Processing

User account creation and management

Personalization of biomarker reference ranges

Automated extraction of lab results (via AI processing)

Calculation of wellness score and optimization recommendations

Tracking biomarker trends over time

Subscription and billing management

Service maintenance, security, and enhancement

Handling and responding to privacy rights requests

Legal Basis

Performance of a contract (GDPR Art. 6.1.b)

Explicit consent (GDPR Art. 9.2.a)

Explicit consent (GDPR Art. 9.2.a)

Explicit consent (GDPR Art. 9.2.a)

Explicit consent (GDPR Art. 9.2.a)

Performance of a contract (GDPR Art. 6.1.b)

Legitimate interest (GDPR Art. 6.1.f)

Legal obligation (GDPR Art. 6.1.c)

Categories of Data Concerned

Identification data

Sex, age, health data

Health data (PDF lab report files)

Health data, user profile

Historical health data

Identification data, subscription history

Technical data

Identification data

3.3 Use of Third-Party Artificial Intelligence

The Application uses an artificial intelligence service provided by Anthropic PBC (United States) to automatically extract results from blood test report files uploaded by the User (PDF or photo).

Data transmitted: the report file as uploaded by the User, which may contain their first and last name, date of birth and laboratory name. The User's profile details required to interpret the results are also transmitted: sex, age, weight, height, reported symptoms, lifestyle and current medications.

Recipient: Anthropic PBC, via its Claude API, whose servers are located in the United States.

Purpose: structured extraction of test results only. Data transmitted is never used by Anthropic to train or improve its artificial intelligence models. It is stored temporarily by Anthropic for security and abuse detection purposes, then deleted.

Consent: before the first file submission, the Application displays a consent screen detailing what data is sent, to whom, and for what purpose. The User must expressly agree before any transmission takes place. This consent may be revoked at any time from the Application's Settings, under Privacy (see Section 4.2).

Protection: Anthropic PBC is bound by a Data Processing Agreement and by the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914). Anthropic provides a level of data protection at least equivalent to that required by the GDPR.

4. LEGAL BASIS FOR PROCESSING HEALTH DATA — EXPLICIT CONSENT:

4.1 Special Category of Data:

Blood and urine analysis results constitute data concerning health within the meaning of Article 4(15) of the GDPR and fall under the special categories of personal data governed by Article 9(1) of the GDPR, the processing of which is in principle prohibited unless specific conditions or exceptions apply.

4.2 Obtaining Explicit and Informed Consent:

Pursuant to Article 9(2)(a) of the GDPR, the processing of User health data relies strictly on the User’s explicit, freely given, specific, informed, and unambiguous consent, obtained prior to any processing activities.

Such consent is collected through a clear affirmative action by the User at the time of:

  • account creation and acceptance of these terms;

  • the initial upload or import of a blood analysis or lab report into the Application;

  • the activation of any feature involving a new processing activity of health data.

The User is expressly informed that:

  • their health data will be processed for the purposes of analysis, scoring, and generating wellness optimization suggestions;

  • their lab report files (PDF or image formats) will be transmitted to a third-party Artificial Intelligence service provider for automated data extraction (see Section 5);

  • these processing operations involve data transfers outside the European Union (see Section 5);

  • their consent may be revoked at any time—without affecting the lawfulness of processing based on consent before its withdrawal—from the Application's Settings, under Privacy, or by submitting a request to contact@bioscore-app.com.

4.3 Consequences of Withdrawal of Consent:

The withdrawal of consent shall result in the immediate cessation of all processing of health data and, upon the User’s request, the permanent deletion of all such health data in accordance with the conditions set forth in Section 7.3.

The User is hereby informed that revoking consent will render any features of the Application relying on the processing of health data entirely unusable.

5. DATA TRANSFERS OUTSIDE THE EUROPEAN UNION:

5.1 Transparent Information Regarding International Data Transfers:

Pursuant to Articles 13(1)(f) and 44 through 49 of the GDPR, the Publisher hereby informs the User that the processing of their personal data involves transfers of personal data to third countries located outside the European Union, specifically including the United States of America.

5.2 Data Processors Involved and Locations:

5.3 TRANSFER SAFEGUARDS AND PROTECTION MECHANISMS:

Data transfers to the United States rely on the following regulatory protection mechanisms:

a) EU-U.S. Data Privacy Framework (DPF):

As of July 10, 2023, the United States benefits from a partial adequacy decision issued by the European Commission (Adequacy Decision C(2023) 4745). This decision covers U.S. entities that are self-certified with the U.S. Department of Commerce under the Data Privacy Framework. The Publisher regularly verifies the certification status of its U.S. data processors under the DPF.

b) Standard Contractual Clauses (SCCs):

In addition to the DPF, or for processors not certified under the DPF, the Publisher relies on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (UE) 2021/914 of June 4, 2021) as a valid transfer mechanism pursuant to Article 46(2)(c) of the GDPR.

The Publisher confirms that every sub-processor with which personal data is shared is bound by a Data Processing Agreement imposing data protection obligations at least equivalent to those required by the GDPR. These agreements specifically prohibit any use of personal data for the sub-processor's own purposes, including the training of artificial intelligence models.

5.4 Information Regarding Residual Risks:

The Publisher informs the User, in full transparency, of the following residual risks:

  • Access by U.S. Authorities:

    Data transferred to the United States may potentially be subject to U.S. surveillance laws, including Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333, which may authorize U.S. intelligence agencies to access data without prior notification to the data subject.

  • Absence of HDS Certification:

    Neither Supabase Inc. nor Anthropic PBC holds a Health Data Hosting certification (“Hébergeur de Données de Santé” or HDS) within the meaning of Article L.1111-8 of the French Public Health Code. The Publisher is fully aware of this limitation and is actively working on migrating its infrastructure to an HDS-certified hosting provider located within the European Union (see Section 5.5).

  • Transmission of Lab Files to the AI API: lab report files (PDF or photo) submitted to the Anthropic API for automated data extraction are sent in their entirety and may contain direct identifiers (such as first and last name, or date of birth appearing on the original document). User profile data (sex, age, weight, height, symptoms, lifestyle, medications) is also transmitted to support the interpretation of results. Instructions are passed to the AI model not to extract identifying information from the document, but these instructions do not prevent the source file and profile data from being transmitted to the sub-processor's servers.

5.5 COMPLIANCE ROADMAP AND ACKNOWLEDGMENT OF INTERNATIONAL TRANSFERS:

The Publisher actively commits to pursuing the following actions to continuously enhance the protection of User data:

  • Migrating the health data hosting infrastructure to an HDS-certified provider located within the European Union;

  • Implementing an anonymization or pseudonymization process for lab report files prior to their transmission to the Artificial Intelligence API;

  • Continuously evaluating international transfer mechanisms in light of evolving European jurisprudence and guidance from the European Data Protection Board (EDPB).

Acknowledgment and Express Consent for International Data Transfers:

By using the Application and providing their explicit consent, the User acknowledges having been clearly informed of these international data transfers, the associated residual risks, and the protective safeguards implemented, and expressly consents to such transfers under the conditions set forth above.

6. DATA SECURITY:

6.1 Technical and Organizational Security Measures:

The Publisher implements the following technical and organizational security measures to safeguard User personal data:

Technical Measures:

  • Data in Transit Encryption: Encryption of data in transit using TLS 1.2 protocol at a minimum (HTTPS) for all communications between the Application, hosting servers, and third-party APIs;

  • Data at Rest Encryption: Encryption of data at rest on database servers using industry-standard AES-256 encryption;

  • Password Hashing: Password storage utilizing an irreversible cryptographic hashing algorithm (bcrypt);

  • Secure Authentication: Secure user authentication implemented via OAuth 2.0 / PKCE protocol and/or email/password credentials;

  • User Data Isolation: Database-level data segregation between Users enforced via Row Level Security (RLS) policies;

  • API Key Security: API keys and sensitive credentials strictly managed server-side (Edge Functions) and never exposed client-side.

Organizational Measures:

  • Restricted Access Control: Production environment access strictly restricted to the Data Controller;

  • Access & Permission Audits: Periodic review and auditing of access controls and system permissions;

  • Security Awareness: Ongoing adherence to cybersecurity best practices and data governance standards.

6.2 PERSONAL DATA BREACH NOTIFICATION:

Pursuant to Articles 33 and 34 of the GDPR, in the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, the Publisher undertakes to:

  • Notify the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés — CNIL) without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach;

  • Inform affected Users without undue delay if the personal data breach is likely to result in a high risk to their rights and freedoms.

7. DATA RETENTION:

7.1 Data Retention Periods:

Data Category

Account Data (email, profile)

Health Data (lab reports, biomarker results, scores)

Uploaded PDF Lab Files

Technical Data (logs, IP addresses)

Billing Data

Data transmitted to the AI sub-processor (Anthropic PBC)

Retention Period

Duration of the contractual relationship + 3 years following account deletion

Duration of the contractual relationship — permanently deleted within 30 days of account deletion or withdrawal of consent

Deleted from servers immediately upon data extraction — not retained beyond processing

12 months maximum

Statutory retention period for accounting and tax records (10 years — French Commercial Code Art. L. 123-22)

Temporarily retained by Anthropic for security and abuse detection purposes, in accordance with its retention policy. The Publisher does not have direct control over this period.

Legal Justification

Civil statute of limitations and dispute management

Data minimization principle (GDPR Art. 5(1)(e))

Data minimization principle

Legal obligation (LCEN) and system security

Legal obligation

Contractual obligation (DPA) and legitimate interest in security

7.2 Account Deletion:

The User may request the deletion of their account at any time by sending a request to contact@bioscore-app.com or directly through the Application’s settings menu.

7.3 Right to Erasure of Health Data:

The deletion of health data may be requested independently of account deletion. The Publisher shall proceed with the erasure of all health data (imported lab reports, extracted results, history, and scores) within thirty (30) days following receipt of the request.

Data erasure will be executed within production systems. Any potential copies residing in automated backups will be purged in accordance with the backup retention cycle, within a maximum timeframe of ninety (90) days.

8. PAYMENT AND BILLING DATA:

8.1 Payment Processing:

Payment processing for Application subscriptions is fully delegated to third-party payment service providers certified under the Payment Card Industry Data Security Standard (PCI-DSS):

  • For iOS Payments: Apple (App Store — In-App Purchases);

  • For Android Payments: Google (Google Play — In-App Purchases);

  • For Web Payments (where applicable): Stripe Inc.

8.2 No Storage of Banking or Payment Data:

The Publisher does not collect, store, or process User payment card or banking details (such as credit card numbers, expiration dates, or security codes/CVV) at any time. All payment credentials are processed exclusively by the aforementioned payment service providers within their certified secure environments.

The Publisher retains only the technical and transaction data necessary for the commercial management of subscriptions, specifically: subscription plan type, start and end dates, and current subscription status (active, expired, canceled).

9. DATA PROCESSORS AND INTERNATIONAL TRANSFERS:

9.1 Granted rights

To provide the Service, the Publisher relies on specialized third-party sub-processors. International data transfers to the United States are secured through standard contractual and statutory safeguards, as detailed below:

9.2 Exercise of Rights:

Users may exercise their data protection rights through the following channels:

  • By Email: By submitting a request to contact@bioscore-app.com, accompanied by proof of identity in cases of reasonable doubt concerning the identity of the requester;

  • Directly Within the Application: Via account settings, for account deletion and data removal requests. Through the Application's Settings, under Privacy: to view the status of consent for processing by the third-party artificial intelligence service and to withdraw it.

The Publisher undertakes to acknowledge receipt of the request within seven (7) days and to provide a substantive response within a maximum of thirty (30) days. This period may be extended by two (2) additional months where necessary, taking into account the complexity and number of requests, in accordance with Article 12(3) of the GDPR. In the event of an extension, the User will be informed within the initial one-month timeframe.

9.3 Right to Lodge a Complaint with a Supervisory Authority:

If a User encounters difficulties in exercising their rights or in the event of an unresolved dispute with the Publisher, the User has the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés — CNIL):

CNIL — Commission Nationale de l’Informatique et des Libertés

3 Place de Fontenoy — TSA 80715

75334 Paris Cedex 07, France

www.cnil.fr

10. AUTOMATED PROCESSING AND PROFILING:

10.1 Nature of Automated Processing:

The Application utilizes automated data processing mechanisms for the following purposes:

  • Biomarker Data Extraction: Automated extraction of blood and urine test results from uploaded PDF files using artificial intelligence (large language models);

  • Wellness Scoring: Calculation of a general wellness score (“BioScore”) derived from comparing the User’s biomarkers against optimal reference ranges established in scientific literature;

  • Personalized Recommendations: Generation of personalized wellness optimization suggestions (including targeted nutrition protocols, dietary supplementation, exercise, and lifestyle interventions);

  • Supplementation Scheduling: Chrono-supplementation planning to optimize dietary supplement intake timing;

  • Action Prioritization: Daily prioritization of personalized wellness actions tailored to the User’s profile.

10.2 Absence of Decisions Producing Legal Effects:

In accordance with Article 22 of the GDPR, the User has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

The Publisher explicitly specifies that the automated processing implemented by the Application:

  • Produces no legal effects whatsoever regarding the User;

  • Does not, under any circumstances, constitute a medical diagnosis, medical prognosis, or therapeutic prescription;

  • Is provided solely as informative wellness suggestions that the User remains entirely free to adopt or disregard;

  • Does not condition the User’s access to any service, insurance policy, employment, or third-party benefit;

  • Is never communicated or disclosed to third parties (including employers, insurers, credit institutions, or other entities).

The User may at any time request human intervention to re-evaluate a score or recommendation, or contest the outcome of any automated processing, by contacting contact@bioscore-app.com.

10.3 Right to Establish Post-Mortem Directives:

Pursuant to Article 85 of French Law No. 78-17 of January 6, 1978, as amended, the User has the right to define directives regarding the retention, erasure, and communication of their personal data after their death. These directives may be general (registered with a certified digital trusted third party approved by the CNIL) or specific (addressed directly to the Publisher at contact@bioscore-app.com).

In the absence of such directives, the User’s heirs may exercise the rights provided by applicable law, specifically to settle the estate or to request the cessation of processing of the deceased user’s data.

11. COOKIES AND TRACKERS:

The Mobile Application does not use or store cookies within the meaning of the ePrivacy Directive (Directive 2002/58/EC). Technical identifiers necessary for authentication and user session functionality are stored locally on the User’s device (via AsyncStorage / SecureStore) and are not shared with any third parties for advertising purposes.

The Application contains no advertising trackers and does not share any data with advertising networks, ad-tech companies, or data brokers.

12. SOCIAL MEDIA AND ONLINE PRESENCE:

The Publisher may maintain an active presence on social media platforms and online channels (including Instagram, LinkedIn, YouTube, as well as on the website bioscore-app.com).

The Publisher does not collect any personal data through these third-party platforms and does not create any database using information that Users may publish or share on them. The Publisher shall not be held liable for any data processing activities carried out independently by the social media platforms themselves.

Users are encouraged to consult the respective privacy policies of each platform in order to configure their privacy and data-sharing settings.

13. MERGERS, ACQUISITIONS, AND ASSET TRANSFERS:

In the event that SHM Global LLC is involved in a merger, acquisition, asset sale, corporate restructuring, or bankruptcy proceeding, Users’ personal data may be transferred to the successor entity or acquiring party.

In such an event, the Publisher undertakes to:

  • Notify Users via in-app notification and/or email at least thirty (30) days prior to the effective transfer of their data;

  • Ensure that the acquiring or receiving entity agrees to adhere to this Privacy Policy or provides data protection guarantees that are at least equivalent;

  • Allow Users to delete their account and associated data prior to the effective transfer if they do not consent to such transfer.

14. AMENDMENTS TO THE PRIVACY POLICY:

The Publisher reserves the right to modify or update this Privacy Policy at any time to reflect changes in regulatory requirements, judicial precedents, or technical enhancements.

In the event of material modifications affecting Users’ rights or the conditions governing the processing of their health data, the Publisher will inform Users via in-app notification and/or email at least fifteen (15) days prior to the effective date of such changes.

Continued use of the Application following the effective date of the modifications constitutes full acceptance of the updated Privacy Policy. If the User does not agree to the modified terms, they may delete their account in accordance with the conditions outlined in Section 7.2.

15. GOVERNING LAW AND JURISDICTION:

This Privacy Policy shall be governed by and construed in accordance with the laws of France.

In the event of any dispute arising out of or in connection with the interpretation or execution of this Privacy Policy, the parties shall attempt in good faith to resolve their dispute amicably. Failing an amicable settlement, the dispute shall be submitted to the exclusive jurisdiction of the competent courts within the jurisdiction of MONTPELLIER, France, subject to any mandatory statutory provisions governing consumer jurisdictional rights.

16. CONTACT

For any questions regarding this Privacy Policy or the processing of your personal data, please contact us at: contact@bioscore-app.com

This Privacy Policy became effective on August 24, 2026.