Public legal draft
Privacy Policy
This draft explains the information BH.Loop handles, why it is handled, and the limits of the platform's current synthetic-data posture. It is prepared for legal review before public OAuth access is enabled.
Last updated: August 1, 2026
Current posture and scope
BH.Loop is a wellness and longevity venue platform operated by BH Labs, LLC. This policy covers the BH.Loop web application and its member, staff, owner, operator, upload, and clinician-review surfaces.
Today, all platform records are synthetic or demonstrative. BH.Loop does not collect or accept real member health, laboratory, biomarker, or wearable data at this time. Demonstration records are not real people or venue customers.
[LEGAL REVIEW: What effective date and jurisdiction-specific supplements should apply to this policy?]
Information we handle
- Identity and sign-in information. When live Google sign-in is enabled, BH.Loop requests only the scopes
openid,email, andprofile. These can provide a stable Google account identifier, email address, display name, profile image, and verification state. BH.Loop also represents the resulting actor and membership identifiers. - Access and session context. Organization, location, membership, role, authorized purpose, policy version, session digest, status, and validity times are used to decide which platform context a person may access.
- Organization and location records. The data model includes organization display names, location configuration and status, and location-scoped catalog entries and publication identifiers.
- Assistant interactions. Staff-entered goals, encrypted question content when retained, question digests and references, response and trace records, model identifiers, guardrail verdicts, latency, and event or correlation identifiers may be processed.
- Structured safety records. The current schema can represent synthetic encrypted safety-flag codes, state and validity intervals, subject references, and supersession history. Safety questionnaire answers are represented as structured flags, not free-text health descriptions.
- Security and audit records. Scoped access grants, actors, effective roles, organizations, locations, purposes, actions, policy versions, outcomes, timestamps, target references, and rejection codes support access decisions and review.
Sources and how we use information
Information can come from the person using BH.Loop, an authorized organization administrator, Google when a person chooses Google sign-in, and BH.Loop's own access, assistant, and audit processes.
BH.Loop uses the information described above to:
- authenticate a person and resolve their permitted organization, location, and role;
- serve the requested platform surface and location-scoped published content;
- process synthetic staff-assistant requests and return guarded responses;
- record access decisions, denials, model traces, and operational failures; and
- protect the service, investigate misuse, and test isolation and safety controls.
[LEGAL REVIEW: Does any use of non-health contact, purchase, identity, or interaction data constitute a sale, sharing, targeted advertising, profiling, or another regulated secondary use that requires an opt-out or separate notice?]
Health and biomarker features
No real member health data is collected today. Synthetic structured safety records exist only to exercise the platform's access, encryption, decision, and audit boundaries.
If laboratory, biomarker, or wearable features launch, BH Labs will revise this policy before accepting real data and will describe the categories actually collected, their sources, purposes, recipients, retention, deletion process, and any consent or authorization required for that launch.
For that future launch, biomarker values will be encrypted and visible only to the member and the authorized importing role. Biomarker values will not be shared with third parties or sold. Members may request deletion of their data. Safety answers will remain structured flags rather than free-text health descriptions.
BH.Loop does not currently claim HIPAA compliance, BAA coverage, or any privacy or security certification. BH Labs has not yet executed a Google Cloud BAA. Cloudflare has no BAA for the current plan, and the OpenRouter integration is code-limited to synthetic-only use because no BAA is configured for that path.
[LEGAL REVIEW: Before any health feature launches, which health-data laws, consents, authorizations, notices, and member-request rights apply to BH Labs and participating organizations?]
Service providers and data disclosures
The current wired service paths are:
- The current synthetic-data-only deployment is hosted on a VPS by a European data-center provider (Germany). Migration to Google Cloud in the
us-east1region is planned but has not yet been applied. - Cloudflare provides DNS. It is not intended to proxy application traffic when real health data is enabled.
- Google provides sign-in when a person chooses Google SSO, limited to
openid email profile. - OpenRouter receives synthetic staff-assistant requests and routes them to the configured model provider, currently OpenAI's
gpt-4.1-nano. The Vercel AI SDK is an application library, not a host. - Future shop and CRM paths may receive only contact and purchase information. They will not receive health data. Above an individual venue boundary, BH Labs will use only de-identified or aggregate data, not raw member health information.
[LEGAL REVIEW: What legally compelled disclosures, corporate-transaction disclosures, and notice commitments should this policy authorize?]
[LEGAL REVIEW: What international-transfer disclosures and transfer mechanisms are required for users outside the United States and for model routing through OpenRouter?]
Retention and security
The current schema includes tenant row-access policies, scoped actor and purpose context, encrypted fields for retained questions and safety-flag codes, short-lived access grants, and access-audit records. No technical control can guarantee absolute security.
[LEGAL REVIEW: What retention periods, legal holds, backup-expiry periods, and deletion or crypto-erasure commitments apply to each category of identity, assistant, safety, and audit information?]
Your choices and requests
A person can decline Google sign-in and should not provide real health information while the platform remains synthetic-only. Requests about personal information must be verified before BH Labs acts on them. Members may request deletion of their data.
[LEGAL REVIEW: Which access, correction, deletion, portability, restriction, objection, appeal, and consent-withdrawal rights apply, and what verification process and response deadlines should BH Labs use?]
[LEGAL REVIEW: What minimum age applies, and does BH.Loop need a children's privacy section or parental-consent workflow?]
[LEGAL REVIEW: What notice and consent process is required when this policy changes, especially before real health-data features launch?]
Contact
[LEGAL REVIEW: Confirm the legal controller/business entity, privacy contact email, mailing address, and any representative or data-protection-officer details that must appear here.]
Read the Terms of Service for the rules governing use of BH.Loop.