Privacy Policy — The Biological Reboot

Effective date: July 24, 2026 (last updated August 27, 2026)

Publisher: Andrew Caravello, DO (individual developer)

Contact: andrewcaravello@gmail.com


Summary

The Biological Reboot is a local-first wellness app. Your profile, biomarkers, supplement stack, condition map, daily practice logs, bookmarks, notes, and conversations are stored on your device. We do not operate a publisher server or account system, and we do not receive, sell, or analyze your data. Ask can use Apple Intelligence on the device, or it can send the question and disclosed context to a cloud provider you select (Anthropic, OpenAI, or Google) and, when needed, search terms to named research services. Encrypted backup sends a protected file only to the destination you choose in the iOS share sheet.

If you uninstall the app, your data is gone. If you back up your iPhone to iCloud (the default), Apple's device backup includes the app's data — restored automatically when you set up a new phone "from iCloud Backup." For full portability between devices or for protection against uninstall, the app provides an in-app encrypted backup feature (see "Backups," below).


What we collect

Nothing on our end. We do not operate any server, cloud service, analytics endpoint, advertising network, or third-party data partnership. The app contains no Google Analytics, no Facebook SDK, no Mixpanel, no Sentry, no Firebase, no Amplitude, no telemetry of any kind.

What you enter is stored on your device by default. Ask sends only the categories listed in its consent sheet when you choose to send a question. Specifically:

DataWhere it lives
Profile (year of birth, biological sex, menopausal status, medication list, supplement stack, life-stage flags)iPhone local storage. Ask can include the disclosed safe profile fields and stack entries after consent; the dedicated disease fields listed below are excluded from the automatic snapshot.
Biomarker entries (CRP, NLR, ferritin, vitamin D, etc.)iPhone local storage. The listed entered biomarker values are included when you consent and send an Ask question.
Condition Atlas entries and problem plans (diagnoses, symptoms, injuries, recovery states, safety answers, goals, and daily response check-ins you add)iPhone local storage. They are not attached to Ask automatically. “Ask about this map” and “Personalize this with Ask” create a visible, editable question draft; its contents are sent only if you press Send.
Daily practice logs (sleep hours, exercise minutes, prep checklist)iPhone local storage
Lesson bookmarks and notesiPhone local storage
Apple Health data read into the app (HRV, sleep stages, resting HR, workouts, etc.)Complete sample history, timestamps, and individual raw samples stay on the iPhone and are not sent. When you consent and press Send, Ask may include only the selected descriptive Health observations listed below. Inferred scores, lock states, selected moves, forecasts, personal stage, dose ranges, and profile-derived contraindications are not sent and stay on-device.
App settings (complexity mode, hormone therapy context, framework assistant key, etc.)iPhone local storage

The app uses your iPhone's built-in browser storage (WKWebView localStorage). There is no publisher cloud account or login. The app does not add an account identifier because none exists; text or images you choose to send through Ask may still contain identifying information.


Apple Health (HealthKit)

The app reads the following HealthKit data types (with your permission, granted in the iOS Health app):

The app reads these for its on-device displays and analysis. Your complete Apple Health sample history, timestamps, and individual raw samples stay on-device. If you separately enable Ask, consent, and press Send, Ask may include only these selected descriptive observations when available: last-night sleep duration, seven-day deep-sleep share, latest HRV, latest resting heart rate, steps today, latest Cardio Fitness estimate, overnight respiratory rate, and overnight blood-oxygen average. They are labeled as consumer estimates. Reboot Score, Immune Rest Score, personal Switch or Stage, lock states or coverage, selected moves, response classes, and forecasts are not sent.

The app writes nothing to Apple Health.

You can revoke HealthKit access at any time from iOS Settings → Privacy & Security → Health → Reboot.


Backups (the encrypted-file feature)

The app provides a "Back up · restore from file" feature in Settings (and a periodic Today-tab reminder). When you use it:

  1. The app collects your profile, practice logs, Reader state, Wiki pages, and Condition Atlas entries into a single bundle on-device. The bundle excludes every AI provider API key, AI consent record, current conversation, saved conversations, and chat folders.
  2. You set a passphrase. The app encrypts the bundle with AES-GCM 256 (a standard symmetric cipher) using a key derived from your passphrase via PBKDF2-SHA256 with 200,000 iterations and a unique random salt.
  3. iOS's native share sheet opens. You choose where to save the encrypted file — typically Files → iCloud Drive, AirDrop to another device, or email to yourself. The file extension is .reboot.
  4. The encryption happens before the file leaves the app. The file is unreadable without your passphrase.

We never see or store your passphrase. It exists only in your memory and in the password manager you choose to use. If you lose the passphrase, the backup cannot be restored — by you or by anyone, including us.

Restore: in Settings → Back up · restore from file → tap Restore from file. iOS's document picker opens; you select your .reboot file. The app asks for the passphrase, decrypts the file in memory, confirms the contents with you, then overwrites your current on-device data with the backup.


Optional features that may send data off the device

The app has one optional assistant feature. You may use Apple Intelligence on the device, or choose a cloud provider. Cloud-provider data leaves the device only when you explicitly enable the feature, complete the in-app consent dialog, and send a question:

Ask the framework about your data — your choice of AI provider (off by default)

Where it lives. The app's home screen — "Ask The Biological Reboot." Configuration, consent, and conversation history live on the home screen; the revoke control lives in Settings (opened from the menu).

What triggers transmission. Tapping Send on a question, after consent has been granted. No data is sent on app launch, on profile changes, on biomarker entry, on Stack edits, on Condition Atlas or problem-plan edits, on daily response check-ins, or on any background interval. “Ask about this map” and “Personalize this with Ask” only prepare a visible draft in the Ask composer; the draft does not leave the device unless you press Send. The app has no scheduled outbound traffic of any kind.

The selected AI service. Apple operates Apple Intelligence through Foundation Models on supported devices; this route is keyless, can receive photos you explicitly attach when the iOS 27 system model supports vision, and does not use Reboot's live research tools. Anthropic, PBC operates Claude at https://api.anthropic.com/v1/messages (privacy, terms). OpenAI, L.L.C. operates GPT at https://api.openai.com/v1/responses (privacy, terms). Google LLC operates Gemini at https://generativelanguage.googleapis.com (privacy, terms). Claude, GPT, and Gemini requests use your own provider API key; that provider bills your account, not this app. None is affiliated with this app or its author.

Account linkage for cloud providers. Your API key authenticates the request to the selected provider account. That provider can therefore associate the question, attachment, and included context with that account. For Apple's App Privacy disclosure, these transmitted categories are declared as data linked to you, used for App Functionality, and not used for tracking or advertising.

Web search. When a question reaches past what the book and its mechanism map contain, the selected assistant may run a provider-supported web search. Your question text, or a search query derived from it, can then travel through that provider to the open web. The book controls how Reboot describes the framework; each external source controls what that source actually found. Support, extensions, and conflicts are surfaced explicitly rather than rewritten to fit the book. This is named in the in-app consent sheet, and consent is required before any question is sent.

PubMed literature search. When the assistant needs a specific study, trial, dose, or citation, it runs a live search against the U.S. National Library of Medicine's PubMed (NCBI E-utilities). The search terms, built from your question, are sent directly from your device to PubMed — a second outbound destination separate from the selected AI provider; no other profile data is sent there. This is what lets the assistant cite a real paper by its PMID rather than relying on model memory. It is named in the in-app consent sheet, and consent is required before any question is sent.

Clinical-trial, drug-label, and additional-literature searches. For a specific trial, a drug label, or a paper PubMed did not surface, the assistant may also query — directly from your device — ClinicalTrials.gov (the U.S. NIH clinical-trials registry), openFDA (the U.S. Food and Drug Administration drug-label API), and Europe PMC (the EMBL-EBI biomedical-literature service). As with PubMed, only the search terms built from your question travel to these services; no other profile data is sent. Each is named in the in-app consent sheet, and consent is required before any question is sent.

Apple Guideline 5.1.2(i) consent. Per Apple's App Review guidelines (updated Nov 13, 2025), apps must disclose third-party AI data sharing and obtain explicit user permission before transmission. We satisfy this with an in-app consent sheet that names the selected provider, lists exactly what is sent, and requires affirmative-action acceptance. Changing providers invalidates the prior consent and requires a fresh review. No data can be transmitted before the user taps "I understand and consent."

What is sent on each question.

Dedicated profile fields not added automatically.

The app does not automatically add the following dedicated profile fields to an AI context snapshot. They remain available to the app's on-device safety banners, Stack-add checks, and framework map:

User-entered text can contain the same information. Your question, symptom notes, stack entries, and any attached image are sent as entered. If you type or attach a diagnosis, medication, pregnancy status, or other sensitive fact in one of those places, the selected provider receives that content. The in-app preview lets you inspect the assembled request before sending.

No individualized dose calculator or dose-range transmission. The assistant is instructed not to calculate a medication or supplement dose from your age, weight, kidney function, biomarkers, or other individualized parameters. Neither individualized doses nor catalog literature dose ranges are included in the automatic Ask context.

Other local boundaries:

Camera and photos (optional). If you attach a photo to a question in Ask, for example a lab report, a supplement label, or a food item, that image is sent to the selected AI provider together with your question, the same way your text is, and only after you have enabled Ask, consented, and explicitly attached the image. The app accesses your camera or photo library only at the moment you tap to attach, uses the image solely to answer that question, stores it nowhere off the device, and transmits it nowhere except the selected provider for that request.

Design boundary. The automatic context is intentionally narrower than the on-device profile. This keeps disease-specific safety decisions in the app's authored rules and leaves diagnosis, treatment, and individualized prescribing to licensed clinicians.

Revocation. Tap "Revoke AI connection" in Ask. This deletes all saved provider API keys and conversation history, disables the shortcut, and records the grant and revocation timestamps locally so the app knows consent is no longer active. The next time you enable the feature, the full consent dialog appears again.

Provider-side storage. Retention and model-training controls differ by provider and can change. Review the selected provider's privacy policy and service terms linked above before consenting. Provider-side storage and account controls are outside this app's control.

Cost. Apple Intelligence requires no separate provider key or Reboot charge. Claude, GPT, and Gemini are pay-as-you-go to the selected provider: that provider bills your own API account directly under its pricing and terms, and we never see your payment details. The Biological Reboot does not sell, resell, mark up, or take any share of AI access. The app does not collect any subscription, license, or transaction fee for using this feature.

Live research tools are enabled for supported cloud routes. The framework-plus-research capability described above (provider-supported web search, PubMed, ClinicalTrials.gov, openFDA, and Europe PMC) is active for supported cloud providers in the current build. Apple Intelligence can use a bounded local source-search tool and, on supported iOS 27 devices, photos you explicitly attach; it does not run web or public-research tools. Every outbound destination category is named in the in-app consent dialog, and your affirmative consent is required before any cloud question — and therefore any outbound search — is sent.


Third parties

The app does not include the following common third-party SDKs:

The app uses these Apple-provided frameworks:

The app is built on Capacitor (open-source web-to-native shell, MIT-licensed) which is statically compiled into the app binary. Capacitor itself does not transmit data.


Children's privacy

The app is not designed for children under 13 and does not knowingly collect data from anyone. It carries no advertising. Apple's current age-rating system classifies its frequent medical and treatment information as 16+; Apple devices running operating systems earlier than version 26 display the corresponding 17+ rating.


Medical disclaimer (not a privacy clause — but stated here for completeness)

The app is for educational and wellness purposes only. It does not provide medical advice, diagnosis, or treatment. It does not establish a doctor-patient relationship between you and the publisher. Always consult a licensed healthcare provider about any health condition. Never start, stop, or change medication based on what the app suggests; talk to your prescriber first.

The core proposed mechanism chain is described in a peer-reviewed Hypothesis and Theory article in Frontiers in Immunology (doi:10.3389/fimmu.2026.1861044). Publication does not establish that the hypothesis is correct. The broader 22-lock book/app extension and the app's personal interpretations have not been independently validated.


Your rights

Because the app does not collect or store your data on any server, the standard "right to access / right to delete / right to portability" requests do not apply in the usual sense. Your data is already entirely in your possession — on your device. You can:

If you live in a jurisdiction (EU/UK GDPR, California CCPA, Quebec Law 25, Brazil LGPD) that grants you rights against a data controller, please note: we are not a controller of your data in the cloud sense, because there is no cloud. But you can still contact the publisher at the address below with any questions.


Changes to this policy

If the app changes in a way that meaningfully affects this policy (e.g., a new feature that transmits data, a new third-party SDK), we will update this policy and surface a notice in the app on next launch. The policy version and effective date appear at the top of this document.


Contact

Andrew Caravello, DO
Email: andrewcaravello@gmail.com
Subject line: "Reboot privacy" or "The Biological Reboot privacy" (mail sent with the older "The Biological Reboot privacy" subject still reaches the same inbox)

For scholarly correspondence on the framework itself, use subject line "Reboot Correspondence" — see the in-app Settings → "Author bio + correspondence" surface for the author bio and contact channels.

This policy is linked from the App Store listing and from within the app's Settings.