Privacy Policy
Last updated: April 7, 2026
BioSynCare exists to help people improve their well-being through scientifically informed sound and music. Our mission shapes how We handle Your data: We collect only what is needed to deliver and improve the Service, We are transparent about every category of data We process, and We give You meaningful control over Your information.
This Privacy Policy describes what data We collect, why We collect it, who We share it with, and what rights You have. It applies whenever You use the BioSynCare application on any platform (web, iOS, or Android).
Because BioSynCare is a wellness application, You may choose to share health-related information with Us. We treat such data with the highest level of care, in full accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Application refers to BioSynCare, the software program provided by the Company, available on web, iOS, and Android.
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to BioSynCare.
Country refers to: Italy.
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
Health-Related Data means any Personal Data relating to Your physical or mental health, wellness goals, or health conditions that You voluntarily provide to the Service.
Personal Data is any information that relates to an identified or identifiable individual.
Service refers to the Application.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. This may include:
• Email address
• Display name
• Gender and date of birth
• Usage Data
Health-Related Data
Because BioSynCare is a wellness application, You may voluntarily provide health-related information, including:
• Health conditions or wellness goals (free-text)
• Expectations for using the Service
• Breathing preferences (breath rate, progressive slowdown)
This data is classified as a special category of Personal Data under GDPR Article 9. We process it only on the basis of Your explicit consent, which You provide when submitting this information through the app. You may withdraw consent and request deletion of this data at any time.
Session and Interaction Data
When You use the Service, We collect data about Your sessions:
• Session names, start times, and duration settings
• Whether a session was completed or stopped early
• Custom session presets You create or save
• Room participation and chat messages in collaborative sessions
AI-Generated Content Data
BioSynCare includes an AI assistant (Seraphony) that generates personalized audio session presets. When You use this feature, the following data is sent to third-party AI providers for processing:
• Your free-text prompts and conversation history within the chat session
• Your language/locale preference
• Your breathing preferences and, if provided, health and expectation information from Your profile
This data is processed in real time and is not stored by the third-party AI providers beyond what is needed to generate the response. See the "Third-Party Service Providers" section below for details.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
Crash and Diagnostic Data
We collect crash reports and diagnostic data to improve the Service. On mobile devices this is handled by Firebase Crashlytics. On the web, crash reports may include the error message, stack trace, page URL, browser user agent, and Your user ID if You are signed in.
Payment Data
If You subscribe to a paid plan, payment processing is handled by third-party providers:
• Stripe for web subscriptions (checkout and billing portal)
• RevenueCat for mobile subscriptions (iOS and Android)
We do not store Your full payment card details. These providers may share subscription status, transaction identifiers, and billing state with Us to manage Your account tier.
Use of Your Personal Data
We use Your data for the purposes listed below — and only for these purposes:
To deliver the Service — generating personalized audio sessions, maintaining Your account, storing Your preferences, and enabling collaborative rooms.
To manage Your Account — handling registration, authentication, and subscription status so You can access the features available to Your plan.
To process payments — fulfilling subscription purchases and managing billing through our payment providers.
To communicate with You — sending essential service emails (e.g. security notices, account changes) and, only with Your consent, updates about new features. We do not send unsolicited marketing. We do not call or text You.
To improve the Service — analyzing anonymous usage patterns and crash reports to fix bugs, improve stability, and guide development priorities.
To respond to Your requests — handling support inquiries, data export requests, and account deletion requests, including any optional feedback You choose to provide during account deletion.
Who We Share Data With
We do not sell Your Personal Data. We share it only in the following limited situations:
• With Service Providers: the third-party providers listed in the "Third-Party Service Providers" section below, strictly for the purposes described there.
• In collaborative features: when You join a room or send chat messages, Your display name and messages are visible to other participants in that room.
• For legal reasons: if required by law, court order, or to protect the safety of our users (see "Disclosure" section below).
• With Your consent: for any other purpose, only after obtaining Your explicit agreement.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
If You voluntarily send feedback during account deletion, We may keep that feedback in a separate internal record after the account itself is deleted so We can understand churn reasons and improve the Service.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Transfer of Your Personal Data
BioSynCare is based in Italy. However, some of our Service Providers (notably Google Firebase, OpenAI, Stripe, and RevenueCat) process data in the United States. This means Your Personal Data may be transferred to and maintained on servers outside the European Economic Area.
When such transfers occur, We rely on appropriate safeguards — including Standard Contractual Clauses approved by the European Commission and the providers' own data protection commitments — to ensure Your data receives a level of protection consistent with the GDPR.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
Our Service may give You the ability to delete certain information about You from within the Service.
You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Beyond the sharing described above, We may disclose Your Personal Data only when We believe in good faith that it is necessary to:
• Comply with a legal obligation or valid request by a public authority (e.g. a court or government agency)
• Protect the safety of our users or the public
• Protect the rights or property of the Company
• Prevent or investigate possible wrongdoing in connection with the Service
In the event of a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will notify You before Your data becomes subject to a different privacy policy.
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation, We rely on the following legal bases to process Your Personal Data:
Consent — for processing Health-Related Data and for sending You marketing communications. You may withdraw consent at any time.
Performance of a contract — to provide You with the Service, manage Your Account, and process subscription payments.
Legitimate interests — for analytics, crash reporting, fraud prevention, and improving the Service, where these interests are not overridden by Your rights.
Legal obligation — where We are required to retain or disclose data to comply with applicable law.
Third-Party Service Providers
We use the following third-party services to operate and improve the Service. Each provider may process Personal Data on Our behalf:
Google Firebase (Google LLC) — authentication, Firestore database, Cloud Functions, Crashlytics, and hosting. Data may be stored in the United States.
OpenAI (OpenAI, L.L.C.) — AI processing for the Seraphony feature. Prompts and profile context are sent to OpenAI's API to generate session presets.
Google Gemini (Google LLC) — alternative AI processing for the Seraphony feature when configured.
Stripe (Stripe, Inc.) — web payment processing and subscription management.
RevenueCat (RevenueCat, Inc.) — mobile in-app purchase and subscription management for iOS and Android.
These providers are contractually obligated to protect Your data and may only process it for the purposes described in this policy. For details, please refer to each provider's own privacy policy.
Your Rights Under GDPR
If You are located in the European Economic Area, You have the following rights regarding Your Personal Data:
Right of access — You may request a copy of the Personal Data We hold about You.
Right to rectification — You may request that We correct inaccurate or incomplete data.
Right to erasure — You may request deletion of Your Personal Data. You can do this directly from the account settings in the app, or by contacting Us.
Right to restrict processing — You may request that We limit how We use Your data.
Right to data portability — You may request an export of Your data in a structured, machine-readable format. The app provides a data export feature in account settings.
Right to object — You may object to processing based on legitimate interests or for direct marketing purposes.
Right to withdraw consent — Where processing is based on consent, You may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact Us at the email address provided below. We will respond within 30 days.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or Your local supervisory authority.
Children's Privacy
BioSynCare is not directed at children. We do not knowingly collect Personal Data from anyone under the age of 14 (the age of digital consent under Italian law implementing the GDPR). If You are a parent or guardian and believe Your child has provided Us with Personal Data, please contact Us and We will promptly delete it.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the Service or in applicable law. When We do, We will update the "Last updated" date at the top and, for material changes, notify You via email or a prominent in-app notice before the changes take effect.
Data Controller
Riccardo Berti (sole proprietorship / partita IVA)
Via Silvio Pellico 380
21042 Caronno Pertusella (VA), Italia
Email: riccardo@aeterni.org
Phone: +39 340 669 6735
Contact Us
We welcome questions about this Privacy Policy, Your data, or any of Your rights. Please reach out — we are committed to responding promptly and transparently.
• By email: riccardo@aeterni.org