The Biological Reboot is a local-first wellness app. Your profile, biomarkers, supplement stack, daily practice logs, bookmarks, notes, and conversations are stored on your device. We do not operate a publisher server or account system, and we do not receive, sell, or analyze your data. There are two user-directed exceptions: Ask sends the question and disclosed context to Anthropic and, when needed, search terms to named research services; encrypted backup sends a protected file only to the destination you choose in the iOS share sheet.
If you uninstall the app, your data is gone. If you back up your iPhone to iCloud (the default), Apple's device backup includes the app's data — restored automatically when you set up a new phone "from iCloud Backup." For full portability between devices or for protection against uninstall, the app provides an in-app encrypted backup feature (see "Backups," below).
Nothing on our end. We do not operate any server, cloud service, analytics endpoint, advertising network, or third-party data partnership. The app contains no Google Analytics, no Facebook SDK, no Mixpanel, no Sentry, no Firebase, no Amplitude, no telemetry of any kind.
What you enter is stored on your device by default. Ask sends only the categories listed in its consent sheet when you choose to send a question. Specifically:
| Data | Where it lives |
|---|---|
| Profile (year of birth, biological sex, menopausal status, medication list, supplement stack, life-stage flags) | iPhone local storage. Ask can include the disclosed safe profile fields and stack entries after consent; the dedicated disease fields listed below are excluded from the automatic snapshot. |
| Biomarker entries (CRP, NLR, ferritin, vitamin D, etc.) | iPhone local storage. The listed entered biomarker values are included when you consent and send an Ask question. |
| Daily practice logs (sleep hours, exercise minutes, prep checklist) | iPhone local storage |
| Lesson bookmarks and notes | iPhone local storage |
| Apple Health data read into the app (HRV, sleep stages, resting HR, workouts, etc.) | Raw samples cached on iPhone and not sent. Derived scores and trends may be included only when you enable Ask, consent, and send a question. |
| App settings (complexity mode, hormone therapy context, framework assistant key, etc.) | iPhone local storage |
The app uses your iPhone's built-in browser storage (WKWebView localStorage). There is no publisher cloud account or login. The app does not add an account identifier because none exists; text or images you choose to send through Ask may still contain identifying information.
The app reads the following HealthKit data types (with your permission, granted in the iOS Health app):
The app reads these to derive its framework readings (e.g., the Reboot Score, the Install Pulse Window, the 22-Lock Coverage map). Raw Apple Health samples stay on-device. If you separately enable Ask and send a question, the on-device scores and trends derived from those samples are included in the context snapshot described below; the raw samples are not.
The app writes nothing to Apple Health.
You can revoke HealthKit access at any time from iOS Settings → Privacy & Security → Health → Reboot.
The app provides a "Back up · restore from file" feature in Settings (and a periodic Today-tab reminder). When you use it:
.reboot.We never see or store your passphrase. It exists only in your memory and in the password manager you choose to use. If you lose the passphrase, the backup cannot be restored — by you or by anyone, including us.
Restore: in Settings → Back up · restore from file → tap Restore from file. iOS's document picker opens; you select your .reboot file. The app asks for the passphrase, decrypts the file in memory, confirms the contents with you, then overwrites your current on-device data with the backup.
The app has one optional feature that sends data outside your device, only when you explicitly enable it and complete a one-time in-app consent dialog:
Where it lives. The app's home screen — "Ask The Biological Reboot." Configuration, consent, and conversation history live on the home screen; the revoke control lives in Settings (opened from the menu).
What triggers transmission. Tapping Send on a question, after consent has been granted. No data is sent on app launch, on profile changes, on biomarker entry, on Stack edits, or on any background interval. The app has no scheduled outbound traffic of any kind.
The third-party AI service. Anthropic, PBC — operator of the Claude AI service. Each question is sent to https://api.anthropic.com/v1/messages using your own sk-ant-… API key. Anthropic bills the call to your Anthropic account, not to this app. Anthropic's handling of your data is governed by their privacy policy at anthropic.com/legal/privacy and commercial terms at anthropic.com/legal/commercial-terms. They are not affiliated with this app or its author. The separate public research services named below receive only search terms, never the profile context sent to Anthropic.
Account linkage. Your API key authenticates the request to your Anthropic account. Anthropic can therefore associate the question, attachment, and included context with that account. For Apple's App Privacy disclosure, these transmitted categories are declared as data linked to you, used for App Functionality, and not used for tracking or advertising.
Web search. When a question reaches past what the book and its mechanism map contain, Claude may run a web search through Anthropic to answer it. Your question text, or a search query derived from it, then travels to Anthropic and on to the open web. Results are read through the framework and never override the book. This is named in the in-app consent sheet, and consent is required before any question is sent.
PubMed literature search. When the assistant needs a specific study, trial, dose, or citation, it runs a live search against the U.S. National Library of Medicine's PubMed (NCBI E-utilities). The search terms, built from your question, are sent directly from your device to PubMed — a second outbound destination separate from Anthropic; no other profile data is sent there. This is what lets the assistant cite a real paper by its PMID rather than relying on model memory. It is named in the in-app consent sheet, and consent is required before any question is sent.
Clinical-trial, drug-label, and additional-literature searches. For a specific trial, a drug label, or a paper PubMed did not surface, the assistant may also query — directly from your device — ClinicalTrials.gov (the U.S. NIH clinical-trials registry), openFDA (the U.S. Food and Drug Administration drug-label API), and Europe PMC (the EMBL-EBI biomedical-literature service). As with PubMed, only the search terms built from your question travel to these services; no other profile data is sent. Each is named in the in-app consent sheet, and consent is required before any question is sent.
Apple Guideline 5.1.2(i) consent. Per Apple's App Review guidelines (updated Nov 13, 2025), apps must disclose third-party AI data sharing and obtain explicit user permission before transmission. We satisfy this with a one-time in-app consent sheet that names Anthropic, lists exactly what is sent, and requires affirmative-action acceptance. No data can be transmitted before the user taps "I understand and consent."
What is sent on each question.
Dedicated profile fields not added automatically.
The app does not automatically add the following dedicated profile fields to an Anthropic context snapshot. They remain available to the app's on-device safety banners, Stack-add checks, and framework map:
User-entered text can contain the same information. Your question, symptom notes, stack entries, and any attached image are sent as entered. If you type or attach a diagnosis, medication, pregnancy status, or other sensitive fact in one of those places, Anthropic receives that content. The in-app preview lets you inspect the assembled request before sending.
No individualized dose calculator. The assistant is instructed not to calculate a medication or supplement dose from your age, weight, kidney function, biomarkers, or other individualized parameters. Catalog literature ranges may be included as educational reference and should be checked with a clinician.
Other things that never leave the device:
Camera and photos (optional). If you attach a photo to a question in Ask, for example a lab report, a supplement label, or a food item, that image is sent to Anthropic together with your question, the same way your text is, and only after you have enabled Ask, consented, and explicitly attached the image. The app accesses your camera or photo library only at the moment you tap to attach, uses the image solely to answer that question, stores it nowhere off the device, and transmits it nowhere except Anthropic for that single request.
Design boundary. The automatic context is intentionally narrower than the on-device profile. This keeps disease-specific safety decisions in the app's authored rules and leaves diagnosis, treatment, and individualized prescribing to licensed clinicians.
Revocation. Tap "Revoke Anthropic connection" in Ask. This deletes the saved API key and conversation history, disables the shortcut, and records the grant and revocation timestamps locally so the app knows consent is no longer active. The next time you enable the feature, the full consent dialog appears again.
Storage on Anthropic's side. Anthropic states that standard API inputs and outputs are automatically deleted from its backend within 30 days, subject to stated exceptions such as legal or usage-policy enforcement, separately controlled services, or a different agreement. Anthropic also states that commercial API inputs and outputs are not used to train its models unless the customer explicitly opts in or reports material. See Anthropic's API retention explanation, commercial training explanation, and Commercial Terms. These policies are controlled by Anthropic and may change.
Cost. Pay-as-you-go to Anthropic. Anthropic bills your own Anthropic account directly under Anthropic's own pricing and terms, and we never see your payment details. The Biological Reboot does not sell, resell, mark up, or take any share of Claude access. The app does not collect any subscription, license, or transaction fee for using this feature.
Live research tools are enabled. The framework-plus-research capability described above (Anthropic web search, PubMed, ClinicalTrials.gov, openFDA, and Europe PMC) is active in the current build. Every one of these destinations is named in the in-app consent dialog, and your affirmative consent is required before any question — and therefore any outbound search — is sent.
The app does not include the following common third-party SDKs:
The app uses these Apple-provided frameworks:
The app is built on Capacitor (open-source web-to-native shell, MIT-licensed) which is statically compiled into the app binary. Capacitor itself does not transmit data.
The app is not designed for children under 13 and does not knowingly collect data from anyone. It carries no advertising and is rated 17+ on the App Store due to the discussion of adult health topics (including medications, supplements, biomarkers, menopause, cancer, autoimmunity).
The app is for educational and wellness purposes only. It does not provide medical advice, diagnosis, or treatment. It does not establish a doctor-patient relationship between you and the publisher. Always consult a licensed healthcare provider about any health condition. Never start, stop, or change medication based on what the app suggests; talk to your prescriber first.
The core proposed mechanism chain is described in a peer-reviewed Hypothesis and Theory article in Frontiers in Immunology (doi:10.3389/fimmu.2026.1861044). Publication does not establish that the hypothesis is correct. The broader 22-lock book/app extension and the app's personal interpretations have not been independently validated.
Because the app does not collect or store your data on any server, the standard "right to access / right to delete / right to portability" requests do not apply in the usual sense. Your data is already entirely in your possession — on your device. You can:
If you live in a jurisdiction (EU/UK GDPR, California CCPA, Quebec Law 25, Brazil LGPD) that grants you rights against a data controller, please note: we are not a controller of your data in the cloud sense, because there is no cloud. But you can still contact the publisher at the address below with any questions.
If the app changes in a way that meaningfully affects this policy (e.g., a new feature that transmits data, a new third-party SDK), we will update this policy and surface a notice in the app on next launch. The policy version and effective date appear at the top of this document.
Andrew Caravello, DO
Email: andrewcaravello@gmail.com
Subject line: "Reboot privacy" or "The Biological Reboot privacy" (mail sent with the older "The Biological Reboot privacy" subject still reaches the same inbox)
For scholarly correspondence on the framework itself, use subject line "Reboot Correspondence" — see the in-app Settings → "Author bio + correspondence" surface for the author bio and contact channels.
This policy is linked from the App Store listing and from within the app's Settings.