← Back to dashboard

Privacy Policy

Last updated: August 6, 2026

The short version

bodop reads health data from portals and lab results you already have access to (with the Chrome extension) and shows it back to you on this dashboard (by reading the Google Sheet you point us to). bodop never stores your biomarker values. They live only in your own Google Sheet. To read and analyze them, data passes transiently through our API to an inference provider that retains nothing — it’s never written to any database we control. That Sheet lives in your own Google Drive, which you own and control. Our servers only ever see your readings in transit, briefly, while processing a scan or answering a question you ask our AI advisor.

We do store some things about you directly: your account (email, name), a password hash, and profile details you choose to enter (date of birth, sex, wellness goal, health conditions, diabetes status) so the AI advisor can personalize its guidance. This is health-adjacent information you typed in yourself — it is not the same thing as your lab data, but we treat it with the same level of care and disclose it plainly below.

1. Who we are

bodop ("we," "us," "our") provides a Chrome extension and web dashboard that help you collect and visualize your own health data. This policy explains what we collect, why, and what your rights are. It applies to the bodop Chrome extension and the bodop web application (this site).

2. Information we collect

a. Account information (stored on our servers, via Supabase)

  • Email address and a securely hashed password (we never see or store your plaintext password)
  • First and last name
  • Session tokens that keep you logged in

b. Profile information you choose to provide (stored on our servers)

On your Account page, you can optionally enter: date of birth, sex, a wellness goal, health conditions you're managing, and whether you have diabetes or prediabetes. This is used only to personalize the AI advisor's responses and dashboard calculations (e.g., age-based pheno-age math, diabetes-aware liver-score calculations). We treat this as sensitive information — see Section 7 for your rights over it.

c. Your health data — biomarkers, lab values, scan results (NOT stored on our servers)

When you use the Chrome extension to scan a health portal, lab result page, or PDF, the extension reads the visible content of that page locally in your browser, sends the extracted text to an AI model to structure it into biomarker values, and writes the result directly to a Google Sheet in your own Google Drive — not to any database we control. When you view your dashboard, this web app reads that same Sheet directly from Google, on the fly, using your Google authorization. We do not copy, cache, or persist the contents of that Sheet on our servers at any point.

d. Google account access

To show your dashboard, we ask you to connect a Google account and select the one Google Sheet the extension created for you, using Google's file picker. We request the narrowest permission Google offers for this (drive.file scope) — this grants us access only to the specific file you select, not to search, list, or read anything else in your Google Drive. We do not request access to your Gmail, Calendar, Photos, or any other Google product.

e. Questions you ask our AI advisor

If you ask the AI advisor a question about a biomarker, your question, the relevant recent readings, and limited profile context (sex, goal, conditions) are sent to our backend, forwarded to our AI processing provider to generate a response, and the response is returned to you. We do not log or store the content of these questions or answers.

f. How we use data from Google APIs (Chrome Web Store Limited Use)

bodop’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Concretely, that means: the extension collects and transmits data only to the extent strictly necessary for its single disclosed purpose — reading the health results you point it at and writing them into your own Google Sheet. bodop ships no analytics, telemetry, advertising, crash reporting, or usage tracking of any kind — not in the extension, and not in this dashboard. We do not collect data for any unreleased future feature, we do not sell or transfer your data to third parties for advertising or creditworthiness purposes, and no human at bodop reads your health data.

3. Third parties we share data with

We use a small number of service providers to operate bodop. None of them receive your data for any purpose beyond providing the specific service listed:

ProviderWhat they receivePurpose
GoogleOAuth identity, access to the one Sheet you selectSign-in and reading your health data Sheet
SupabaseAccount email, name, password hash, profile fields you enterAccount infrastructure and authentication
CerebrasYour advisor question + recent readings (webapp) or extracted page text (extension), transientlyAI processing to answer your question or structure your biomarkers
GroqExtracted page text (extension only), transientlyAlternate AI processing provider for the extension's scanning feature
VercelStandard web traffic/hosting logsHosting this web application

Both Groq and Cerebras state in their terms of service that data submitted through their commercial APIs is not used to train or fine-tune their models, and neither retains your inputs/outputs beyond what's operationally necessary to return a response.

For the extension's scanning feature, bodop provides API access to these AI providers by default — you do not need to create your own account with either one, and this traffic runs under bodop's account with that provider. If you'd prefer to use your own personal Groq or Cerebras API key instead, you can enter one in extension Settings; in that case, that traffic runs under your own account, not ours.

We do not sell your data. We do not share it with advertisers. We do not use it for marketing to third parties.

4. Data retention

  • Account and profile information: retained until you delete your account.
  • Health data (biomarker readings): never stored by us — retained only in your own Google Sheet, for as long as you choose to keep it there.
  • AI advisor questions/answers: not retained; each request is processed and discarded.
  • Extension scan content: read locally, processed transiently, discarded after writing to your Sheet.

5. Security

We use industry-standard practices to protect account information: encrypted connections (TLS) for all traffic, hashed passwords, database-level access controls that restrict each account to its own data, and the minimum OAuth permissions needed for each feature. No system is perfectly secure, and we can't guarantee absolute security, but protecting your information — especially the invariant that your biomarker values are never stored in any database we control — is a core design constraint of this product.

6. Your choices

  • Edit or remove profile information — anytime, from your Account page.
  • Disconnect Google access — anytime, from your Google Account's third-party access settings. This immediately revokes our access to your Sheet.
  • Delete your account — from your Account page, or by emailing us (Section 9). This permanently removes your account, profile, and any Google connection record from our systems. It does not delete your Google Sheet itself — that lives in your Drive and is yours to keep or delete.
  • Your Google Sheet — you can share, export, or delete it at any time directly in Google Drive; it is entirely under your control.

7. Additional rights for specific states

Washington residents — My Health My Data Act

If you're a Washington resident, the categories of consumer health data we process are: the profile information described in Section 2(b) that you choose to provide, and — transiently, never stored — the biomarker data described in Section 2(c). We collect this to provide the personalization and AI advisor features you request. We do not sell consumer health data, and we do not share it for advertising. You have the right to confirm whether we process your consumer health data, access it, and request deletion — contact us using Section 9 to exercise these rights.

California residents — CCPA/CPRA

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information (we do not sell personal information). To exercise these rights, contact us using Section 9.

8. Children's privacy

bodop is not directed to, and we do not knowingly collect information from, anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

9. Contact us

Questions about this policy, or want to exercise any right described above? Email bodop.app@gmail.com.

10. Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above and, for significant changes, notify you directly.