Privacy Policy — BioApex
Version: 1.3.0 · Last updated: 2026-09-01
1. Data controller
The data controller for BioApex is:
LogicLoom Kamil Zwarycz Sole proprietorship (JDG), Poland, registered 2024-12-01, trading as KZ Labs NIP: 5871749235 · REGON: 540001576 ul. Kalinowa 6L lok. 3, 81-198 Kosakowo, Poland
Privacy contact: contact@kzlab.dev
Given the scale of processing (sole proprietorship, no large-scale processing of special-category data, no systematic large-scale monitoring), formally appointing a Data Protection Officer is not required under GDPR Article 37. The contact above serves as the data-protection point of contact.
2. Local-first — your habit data never reaches us
BioApex has no user accounts, no sign-in, and no server we operate. The app contains no code that transmits your habit data anywhere: there is no API call, upload, or sync in the app that sends your logs to us. Your data is written to storage inside your device’s app sandbox and stays there.
Concretely, two on-device stores hold your data:
- an MMKV key–value store (active-day state, readiness score, settings, reminder preferences, streak bookkeeping, cached entitlement state);
- a SQLite database (
protocol.db) holding the history: daily score, readiness score, Apple Health sleep minutes, free-text breach reasons, custom habits, caffeine logs (dose in mg and drink type), fasting sessions, and thermal (cold/heat) exposure sessions.
On iOS there is a third location: a shared App Group container (group.com.kzlab.bioapex.widget) holding a small snapshot that the home-screen widget process reads. That container is a second process on your device. It is still local, and it is still removed on uninstall.
This data is not encrypted at rest. See §11.
The only data that leaves your device is described in §3.
3. What actually leaves your device
Two things, both narrow:
| Category | What is sent | Why | Legal basis (GDPR) |
|---|---|---|---|
| Subscription/purchase data | The store transaction receipt for your purchase, the product identifier (yearly or monthly), and an anonymous app-user identifier generated on your device by RevenueCat | Granting and verifying Pro access | Art. 6(1)(b) — performance of a contract |
| Crash reports — only if you turn “Crash Reports” on in Settings; it is off by default | Stack trace, device and OS version, app version. Never your habits, scores, notes, or health data | Diagnosing and fixing bugs | Art. 6(1)(a) — consent, given by switching the toggle on |
Note on the crash-reporting toggle: it is read at app launch, so a change takes effect the next time you open the app. Crash reporting also stays inert until a Sentry project is provisioned; as shipped today no crash data is transmitted to anyone (§5).
Everything else — your checklist, scores, readiness ratings, breach notes, caffeine logs, fasting and thermal sessions, and Apple Health sleep minutes — is stored only on your device and is never transmitted to us or to any third party.
4. Health data, in detail
On iOS only, with your permission, the app reads your sleep duration from Apple Health:
- It requests read-only access to the single data type
SleepAnalysis. It never writes to Apple Health. - It reads no other health or biometric data — no heart rate, no HRV, no steps, no activity. It sums your sleep samples for the day, excluding time in bed and awake, and stores the total in minutes on your device.
- The permission prompt is presented by iOS; the app asks for it at each cold launch until you answer it.
- The value is used to draw the “recovery” line on your local chart and is included in the CSV/JSON export you can trigger yourself.
There is no Google Health Connect integration, so none of this applies on Android.
Because this data is stored locally and never transmitted, no special-category data under GDPR Article 9 leaves your device.
5. Recipients of data (subprocessors)
| Party | Purpose | Location |
|---|---|---|
| RevenueCat | Subscription and entitlement management — receives the store transaction receipt from Apple/Google and confirms your purchase back to the app. Configured with no user identity, so it assigns an anonymous identifier | US (EU-US Data Privacy Framework certified) |
| Apple App Store / Google Play | Payment processing for subscriptions | Processed directly by Apple/Google — we never see or store card details |
| Sentry — only if you enable “Crash Reports” | Receives crash and error diagnostics so we can fix bugs | US/EU (configurable data region) |
Sentry configuration. In our configuration, personal information, default-PII transmission, automatic session tracking, performance tracing, and screenshot attachment are all disabled. Native crash handling — which covers native crashes, ANRs, app hangs, and native/stall tracking — is left at the SDK default and therefore active whenever crash reporting is enabled. That data is diagnostic only.
No Sentry project is currently provisioned, so in the build this policy covers, crash reporting transmits nothing at all. If that changes we will update this section.
We use no analytics vendor, no advertising or attribution SDK, no push-notification server, and no LLM or AI API in this app. On Android, Firebase Analytics and Firebase Cloud Messaging auto-init are explicitly switched off at the manifest level.
6. International data transfers
RevenueCat may process data outside the European Economic Area. Where this occurs, the transfer relies on the mechanisms provided for under GDPR — in particular the EU-US Data Privacy Framework (DPF) for certified US entities. Current certification status can be verified at https://www.dataprivacyframework.gov/.
Sentry’s data region is configurable; if you enable crash reporting, the configured region applies.
7. Data retention
| Category | Retention |
|---|---|
| Habit data on your device — checklist state and history, readiness scores, breach notes, custom habits, caffeine logs, fasting and thermal sessions, Apple Health sleep minutes, settings and reminder preferences | Lives only on your device, for as long as the app is installed. Removed when you uninstall. We hold no copy and cannot recover it |
| Exports you create (CSV / JSON) | Written to your device’s cache and handed to the operating system’s share sheet. What happens next is up to the app you share them with. We never receive them |
| Subscription/purchase data (held by RevenueCat) | Per RevenueCat’s own retention policy, for as long as needed to service your subscription and meet financial record-keeping obligations |
| Crash reports (held by Sentry, only if you opt in) | Per Sentry’s own retention policy |
8. Your rights
Under GDPR you have the right to:
- Access and erasure of your habit data. Because it never leaves your device, you can erase it yourself at any time:
- Settings → “Clear All Data” deletes every row of your history (daily scores, readiness ratings, breach notes, Apple Health sleep minutes, caffeine logs, fasting sessions, thermal sessions), any habits you created, and your settings — across both on-device stores and the widget snapshot. The app’s built-in habit catalog and tips are app content, not your data, so they are restored rather than deleted.
- Uninstalling the app remains the most complete option: it removes both on-device stores and the widget container outright.
- Access, correction, or erasure of subscription data held by RevenueCat — contact us at the address in §1, or RevenueCat directly. We will forward and assist with the request.
- Object to processing based on legitimate interest, and request restriction of processing — contact us at the address in §1. This currently applies to subscription data and any crash data (§3).
- Rectification — correct inaccurate subscription records through the store or by contacting us.
- Withdraw consent at any time, by turning Crash Reports off in Settings. This does not affect processing carried out before withdrawal.
- Lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl. EU users may also complain to their own national authority.
We respond to rights requests without undue delay, and no later than one month after receipt (GDPR Art. 12(3)).
9. Children’s data
BioApex does not knowingly collect personal data from children, and it has no account system and no age gate, so no age declaration is collected at all — see §2 for why there is very little personal data in the app to begin with. If you believe a child has provided personal information through the app’s purchase flow, contact us at contact@kzlab.dev.
10. Cookies
The app uses no cookies and contains no web view or embedded browser, so no cookie or local-storage handling applies to it. The companion website at studio.kzlab.dev sets no cookies either.
11. Data security
- Your habit data stays inside your device’s app sandbox, protected by the operating system’s standard app-data protections.
- It is not encrypted at rest. The MMKV store is opened without an encryption key and the SQLite database is a plain file. The protection you get is the OS sandbox and your device lock, nothing more. This is why §6 of the Terms asks you to keep your device secured.
- The optional Face ID / Touch ID app lock (Pro) gates the app UI against casual access. It is off by default, and it is a UI gate, not data-at-rest encryption.
- We do not store any password, because there is no account to log into.
- Subscription validation happens through Apple’s and Google’s own secure purchase APIs and RevenueCat’s SDK. We never see or handle raw payment details.
12. Changes to this policy
We will provide at least 30 days’ notice of material changes to this policy, via an in-app notice and/or the contact channel in §13. The “last updated” date at the top of this document reflects the most recent revision.
13. Contact
- Privacy: contact@kzlab.dev
- Support: contact@kzlab.dev
- Correspondence address: LogicLoom Kamil Zwarycz, ul. Kalinowa 6L lok. 3, 81-198 Kosakowo, Poland.