My BioSignal
Privacy policy
Last updated: 12 August 2026
My BioSignal is a small, private build. This policy describes exactly what the service does with data today. It does not describe plans, and it does not promise controls that have not been built.
Who runs this service
My BioSignal, at mybiosignal.com, is operated by its owner, Oliver, an individual based in the European Union. For the purposes of the EU General Data Protection Regulation, the owner-operator is the data controller. You can reach him at oliver@overporten.com.
What My BioSignal is right now
My BioSignal is currently a single-owner personal health record. Exactly one account exists: the owner's, tied to one allowlisted email address and secured with a passkey. No one else can create an account or sign in, so the only person whose health data the service holds is the owner himself.
Everyone else interacts with the public pages: the landing page, the demo, and this policy. The demo uses generated sample data and touches no real health information.
What we collect from visitors
If you join the waitlist, we store your email address, normalized and kept once, and nothing else about you. We use it solely to contact you about the waitlist, and we remove it whenever you ask by emailing oliver@overporten.com.
Beyond that, the public pages collect nothing. There are no analytics, no advertising, no tracking pixels, no fingerprinting, and no third-party scripts. Public pages set no cookies at all.
WHOOP data
With the owner's explicit consent through WHOOP's OAuth flow, the server imports the owner's own WHOOP data through WHOOP's official API: profile, physiological cycles, recovery, sleep, and workouts. This data is used for one purpose only: showing the owner his own health record inside the app.
The connection can be ended at any time. The owner can disconnect WHOOP inside the app, which removes the stored access, or revoke My BioSignal's access directly in WHOOP's own settings. WHOOP's handling of data on its side is governed by WHOOP's own privacy policy.
Apple Health data
With the owner's explicit consent, given through Apple's own Health permission sheet on the owner's iPhone, the My BioSignal iPhone app reads exactly nine classes of record: step count, heart rate, resting heart rate, heart-rate variability measured as SDNN, body mass, height, active energy burned, sleep analysis, and workouts. The app imports a private server copy so the owner can see those records in My BioSignal. This access is read-only: My BioSignal never writes anything back to Apple Health.
On the You page, the owner can disconnect the server source, which stops future imports while keeping records already imported, or permanently delete My BioSignal's imported server copy and import position. Neither control deletes records from Apple Health or changes iPhone permissions. Apple Health access remains controlled in iOS Settings, and reconnecting the server source requires a new explicit action and consent in the iPhone app. Revoking access in iOS Settings or deleting the iPhone app stops the app from reading new records, but does not by itself erase a server copy already held by My BioSignal. Apple does not process data on our behalf: records travel directly from the owner's iPhone to this server, while device records remain governed by Apple's own terms.
How data is stored and protected
All data lives server-side in a Postgres database hosted by Neon. WHOOP OAuth tokens are encrypted at the application level with AES-256-GCM before they are stored. WHOOP credentials and tokens are only ever handled on the server and are never sent to a browser.
Cookies
After the owner signs in, the service uses an HttpOnly session cookie only to keep that owner signed in. Beginning a WHOOP connection also uses a separate, short-lived HttpOnly state cookie to protect the OAuth return, and that cookie is cleared when the return is handled. Neither cookie is used for tracking. Visitors who do not sign in receive no cookies, and no one other than the owner can sign in.
Service providers
We do not sell data and we do not share it with third parties for their own purposes. A small set of service providers process data on our behalf, strictly to run the service:
- Vercel, which hosts the application.
- Neon, which hosts the database.
- WHOOP, one of the two sources of the owner's health data, accessed through its official API under its own terms. The other source, Apple Health, involves no service provider: those records come straight from the owner's own iPhone.
- Anthropic, only when the owner uses the private in-app coaching chat. In that case the server sends relevant parts of the owner's own health record to Anthropic's API to generate the coaching reply. Nothing is sent unless the owner initiates a conversation, and no visitor data is ever involved.
- OpenAI, only when the owner explicitly records voice for the private coaching chat. The authenticated server sends the raw audio to OpenAI's transcription API once and returns the text as a draft. My BioSignal does not store the raw audio; it is held only long enough to transmit it and return the transcript. If the owner then sends that draft, its text can be stored as part of the coaching conversation. No visitor data is involved.
That list is complete. There is no email marketing provider, no analytics provider, and no advertising partner.
Your rights and deletion
Data is processed on the basis of consent: the owner's consent for the WHOOP connection, the Apple Health import and the coaching chat, and yours when you choose to join the waitlist. Consent can be withdrawn at any time.
The signed-in owner can download a full account export, view and revoke active sessions, disconnect WHOOP, disconnect Apple Health imports, and delete My BioSignal's imported Apple Health server copy from the You page. The owner can also request full account deletion after an exact typed confirmation and a fresh passkey check. A deletion request immediately disables sign-in access. Final erasure is not immediate: if WHOOP is connected, its provider access must be revoked first. Until that provider action is resolved, the account and its data remain inaccessible in a pending-deletion state, and the interface does not claim that final erasure has completed.
These self-service controls do not replace anyone's legal rights. You can ask to access, correct, or delete any data we hold about you by emailing oliver@overporten.com. Requests are honored promptly. If you are in the EU, you also have the right to lodge a complaint with your local data protection authority.
Changes to this policy
If the service changes in a way that affects data handling, this policy will be updated first and the date above will change. The policy describes what is live, not what is planned.
Contact
Questions about this policy or about your data: oliver@overporten.com.