Legal

BaroShift Privacy Policy

Last Updated: April 15, 2026

1.

Our Commitment to Your Privacy

Welcome to BaroShift. Our mission is to help you improve your well-being. We are committed to protecting your privacy and handling your data with transparency and care. This policy explains what personal data we collect, how we use and share it, and your rights regarding your data.

2.

Information We Collect

We collect information necessary to provide and improve our services. This includes:

Information You Provide to Us:

  • Account Information: When you create an account, we collect your name, email address, and password.
  • Profile Information (Optional): You may choose to provide additional information like your date of birth and gender to help personalize features like demographic comparisons.
  • Payment Information: If you purchase a Starter Bundle or Resilience Pass, our third-party payment processor will collect your payment card information. We do not store this information on our servers.

Information from Your Use of the Service:

  • Health and Biometric Data: With your explicit consent, we collect health and biometric data essential for the app's function, such as heart rate, heart rate variability (HRV), and respiration patterns, either from your phone's camera or the BaroShift wearable.
  • Sensitive Personal Information (U.S. Residents): For residents of the United States, certain data we collect, specifically neural data (data generated by measuring the activity of your central or peripheral nervous system, such as nervous system balance) and respiration patterns, is classified as "Sensitive Personal Information" under applicable state laws.
  • User Content: We collect information you voluntarily add to the app, such as journal entries, mood logs, or contextual tags for your measurements.

Information Collected Automatically:

  • Usage and Technical Data: We collect data about how you interact with our app, such as features used and session times. We also collect device information (e.g., IP address, operating system, device type) to ensure compatibility and troubleshoot issues.
3.

How We Use Your Information

We use your information for the following purposes:

  • To Provide and Maintain the Service: To operate the app, manage your account, provide customer support, and ensure the core functionality of our services.
  • To Personalize Your Experience: To tailor content, provide personalized insights, and adapt our services to your goals.
  • To Improve Our Services: To analyze usage patterns, conduct research and development, and fix bugs.
AI-Driven Wellness Insights: We use AI algorithms to analyze your biometric data (heart rate, HRV, and respiration) to generate personalized insights. This automated processing is essential to the Service; therefore, no opt-out is available for core operational analysis. Use of the Service constitutes a request for this automated health profiling.
  • To Communicate With You: To send you service-related announcements and updates.
  • For Scientific Research (With Your Optional Consent): With your separate and optional consent, we may use your anonymized data for scientific research and publications. You can provide or withdraw this consent at any time in your settings without affecting your use of the service.
4.

How We Share Your Information

We do not sell your personal data. We only share your information in the following limited circumstances:

  • With Your Consent: We will share your data with third parties (e.g., a coach or healthcare provider) only when you have given us your explicit permission.
  • With Service Providers: We work with trusted third-party vendors for services like cloud hosting (in Canada and the U.S.), payment processing, and analytics. These partners are legally and contractually obligated to protect your data.
  • For Legal and Safety Reasons: We may disclose your information if required by law, court order, or to protect the rights, property, or safety of our company, our users, or the public.
5.

Your Rights and Choices

You are in control of your personal data. Depending on your jurisdiction, you have the right to:

  • Access and Portability: Request a copy of the personal data we hold about you in a structured, technological format.
  • Correction: Update or correct any inaccuracies in your information.
  • Deletion: Request the permanent deletion of your account and all associated data.
  • Limit Use of Sensitive Information (U.S. Residents): Request that we limit the use and disclosure of your Sensitive Personal Information (such as neural data) to only those uses necessary to provide the Service.
  • Opt-Out of Automated Profiling: Automated profiling is essential to our Service. You may opt-out of secondary data use (e.g., model training), but opting out of core analysis requires account termination as the Service cannot function without it.
  • Manage Cookies: Control tracking technologies through your device settings.
6.

Data Security and Retention

We use industry-standard security measures, including data encryption in transit and at rest, to protect your information. We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it.

Breach Notification:

In the event of a security breach, we will notify affected individuals in accordance with applicable law, including the U.S. FTC Health Breach Notification Rule (within 60 days of discovery) and Canadian federal and provincial requirements.

7.

International Data Transfers

Your personal data is stored and processed on our servers located in Canada and the United States, where data protection laws may differ from those in your country of residence. We use appropriate safeguards, such as standard contractual clauses, to protect your data when it is transferred internationally.

8.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information immediately.

9.

Changes to This Privacy Policy

We may update this policy from time to time. We will notify you of any significant changes by email or through an in-app notification. Significant changes will be provided with at least 30 days' notice before becoming effective.

10.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at: legal@baroshift.com