Legal

Privacy Policy

Effective date: 31 July 2026
Last updated: 31 July 2026
Entity: BioForge LLC (Florida)

BioForge handles two very different kinds of information about you, under two different sets of rules. This policy explains both in plain language, and tells you exactly what we will and will not do with your data.

The short version

We do not sell your personal information. Not to data brokers, not to advertisers, not to anyone.

We do not send your health information to advertising platforms. No Meta pixel, no advertising trackers, and no analytics on any page where you enter health information. This is a deliberate design decision — see Section 7.

Your medical records are governed by HIPAA, not by this policy. HIPAA is stricter. See Section 1.

You can ask us what we have about you, correct it, or ask us to delete it — regardless of what state you live in. See Section 9.

1Scope and Two Kinds of Data

This Privacy Policy explains how BioForge LLC ("BioForge," "we," "us"), a Florida limited liability company, handles information collected through our website at bioforge.health, our forms, our client portal, and our marketing and support communications (together, the "Site").

Important distinction. Information you give us as a patient in the course of clinical care — your medical history, lab results, prescriptions, clinical notes, and communications with your provider — is Protected Health Information (PHI). PHI is governed by HIPAA, our Notice of Privacy Practices, and the authorizations you sign. It is not governed by this Privacy Policy, and HIPAA gives you more protection than this policy does. Where the two could ever conflict as to PHI, the Notice of Privacy Practices controls.

This policy covers everything else: the information you give us before you become a patient, information collected automatically when you browse, and information used to run the business side of the relationship.

This policy does not apply to the independent providers, compounding pharmacies, or laboratories you may interact with. They maintain their own privacy practices.

2Information We Collect

CategoryExamplesDo we collect it?
IdentifiersName, email, phone, mailing address, account IDYes
Account dataUsername, hashed password, security settings, preferencesYes
Payment dataCard brand, last four digits, billing ZIP, transaction historyYes — full card numbers are handled by our payment processor and never stored on our systems
Health information you volunteer pre-intakeGoals, symptoms, or history you type into an application formYes — treated with PHI-level care from the moment we receive it
Clinical PHIMedical history, labs, prescriptions, provider notesYes — governed by HIPAA, not this policy
CommunicationsEmails, support tickets, SMS, form submissionsYes
Device and usage dataIP address, browser type, pages viewed, referring URL, timestampsYes — see Section 7 for the limits we place on this
Precise geolocationGPS-level locationNo
Biometric identifiersFingerprints, faceprints, voiceprintsNo
Government ID numbersSSN, driver's license, passportNo, except where a specific regulatory or identity-verification requirement applies and we tell you at the time
Data purchased from brokersAppended demographic or health-interest dataNo

You are never required to give us health information to browse the Site. You only provide it when you choose to apply or to receive care.

3How We Collect It

  • Directly from you — when you fill out a form, create an account, message us, call us, or enroll.
  • Automatically — limited technical data logged when you visit, as described in Sections 7 and 8.
  • From service providers acting for us — for example our payment processor confirming a transaction, or our email provider reporting a bounce.
  • From your providers, pharmacies, or labs — only with your authorization, and only as PHI under HIPAA.

We do not buy personal information about you from data brokers or list vendors.

4How We Use It

PurposeWhat that means
Provide the ServicesCreate and maintain your account, coordinate scheduling and labs, deliver the Services you purchase
Process paymentsCharge your payment method, issue receipts, handle billing questions and refunds
Communicate with youRespond to inquiries, send service and appointment notices, provide support
Safety and qualityInvestigate adverse events, respond to complaints, improve clinical operations
Security and fraud preventionAuthenticate logins, detect abuse, protect accounts and systems
Legal complianceMeet recordkeeping, tax, licensure, and regulatory obligations; respond to lawful requests
Improve the SiteUnderstand which pages are useful, fix errors — using aggregate and de-identified data wherever possible
Marketing you asked forSend you our newsletter or offers only if you opted in, and only using non-health contact data

What we will never do: use your health information to target advertising to you; sell or rent your information; disclose that you are a BioForge patient to an advertising platform; or use your data to train a third party's machine-learning model.

5How We Share It

We share personal information only in these situations:

  • Service providers under contract — payment processing, email delivery, hosting, scheduling, CRM/EHR, SMS delivery, and customer support. They may use your information only to perform services for us, are bound by written confidentiality obligations, and where they touch PHI, by a HIPAA Business Associate Agreement.
  • Your treating providers, pharmacies, and laboratories — to coordinate your care, as authorized by you and as governed by HIPAA.
  • Legal and safety — when required by law, subpoena, or court order; to establish, exercise, or defend legal claims; or where we believe in good faith it is necessary to prevent serious harm to you or another person. Where we may lawfully notify you of a legal demand for your data, we will.
  • Business transfer — in a merger, acquisition, financing, or sale of assets. If a transfer would materially change who handles your health information, we will notify you in advance and you may cancel without penalty. PHI transfers remain subject to HIPAA.
  • With your direction — anytime you ask us to share information with someone, such as a spouse, trainer, or outside physician.

We do not share your information with advertisers, data brokers, or social media platforms.

6We Do Not Sell Your Data

BioForge does not sell your personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under state privacy laws — including the California Consumer Privacy Act.

We have not sold or shared personal information for these purposes in the preceding twelve months, and we do not currently intend to. If that ever changes, we will update this policy, notify you in advance, and provide a working opt-out before any such use begins.

7Advertising and Tracking — Our Commitment

This section describes a deliberate design choice, and we want to be specific about it because the health industry's track record here is poor.

Federal regulators have repeatedly taken enforcement action against health companies whose websites leaked user health data to advertising platforms through embedded tracking pixels. The FTC has penalized companies millions of dollars for exactly this, and the FTC and HHS Office for Civil Rights jointly warned well over a hundred health organizations about the practice.

Our commitments:

  • No advertising pixels or trackers on health-related pages. We do not deploy Meta/Facebook Pixel, TikTok Pixel, Google Ads remarketing tags, LinkedIn Insight Tag, Snapchat Pixel, or equivalent advertising trackers on any page where you enter, view, or discuss health information — including the application form, intake, portal, and account pages.
  • No health data in analytics. Where we use analytics on general marketing pages, it is configured to exclude URLs, form fields, and page titles that could reveal a health condition, therapy, or treatment interest, and IP addresses are truncated or anonymized where the tool supports it.
  • No custom audiences built from patient lists. We do not upload client or patient lists to advertising platforms to build custom or lookalike audiences.
  • No third-party session recording or heat-mapping tools on pages that collect health information.
  • Vendor review. Before adding any tag or script to the Site, we assess whether it could transmit health-related data to a third party, and we do not add it if it could.

If you ever observe behavior inconsistent with this section, please tell us at privacy@bioforge.health — we will investigate and correct it.

8Cookies and Your Choices

We use a small number of cookies and similar technologies:

TypePurposeCan you turn it off?
Strictly necessaryKeep you logged in, maintain your session, security and fraud prevention, load balancingNo — the Site will not function without these
PreferenceRemember settings such as your display choicesYes
AnalyticsAggregate, privacy-limited understanding of which pages are usedYes
AdvertisingWe don't use these. See Section 7.

Your controls:

  • Cookie settings — use the cookie preference control on the Site to accept or decline non-essential cookies. Declining will not reduce your access to any Service.
  • Browser settings — most browsers let you block or delete cookies.
  • Global Privacy Control — we honor the GPC browser signal as a valid opt-out request where applicable law recognizes it.
  • Do Not Track — browser DNT signals are not yet standardized. We honor GPC instead, which is.
  • Marketing email — unsubscribe from any marketing message, or email us.
  • SMS — reply STOP. See Section 15.

9Your Rights

Comprehensive state privacy statutes apply based on where you live and, in some cases, the size of the business. Rather than making you check whether a law happens to cover you, we extend the following rights to every BioForge user regardless of state:

  • Know and access — ask what personal information we hold about you, where we got it, and who we shared it with.
  • Copy / portability — receive a copy in a portable, machine-readable format.
  • Correct — fix information that is inaccurate.
  • Delete — ask us to delete your personal information, subject to the limits below.
  • Opt out — of marketing communications, of analytics, and of any sale or targeted advertising use (we don't do the latter — see Section 6).
  • Withdraw consent — where processing is based on your consent.
  • Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
  • Appeal — if we decline a request, you may appeal, and we will respond in writing with our reasoning.

Limits on deletion. We may be legally required to retain certain records even if you ask us to delete them. Medical records in particular are subject to mandatory retention periods under Florida law and HIPAA, and we cannot delete them on request. We may also retain what we need to complete a transaction, comply with tax and regulatory obligations, detect fraud, or establish or defend legal claims. Where we cannot delete, we will tell you why and delete what we can. Your rights in your medical records are exercised under HIPAA — see our Notice of Privacy Practices.

10How to Exercise Your Rights

Email privacy@bioforge.health or write to the address in Section 20. Tell us what you want and give us enough detail to find your records.

  • Verification. To protect you, we verify your identity before acting — usually by confirming control of the email address on your account. For sensitive requests we may ask for more. We use verification information only for that purpose and then delete it.
  • Timing. We acknowledge within 10 business days and respond substantively within 45 days. If we need more time, we will tell you why and may extend once by 45 days.
  • Cost. Free, unless a request is manifestly unfounded or repetitive, in which case we will tell you before charging anything.
  • Authorized agents. You may use an agent, with written authorization we can verify.
  • Appeals. Reply to our decision with the word "appeal." A different person will review it and respond in writing within 45 days. If we deny your appeal, we will tell you how to contact the Florida Attorney General or your state's regulator.

11How Long We Keep Data

DataRetention
Medical records / PHIAs required by Florida law and HIPAA — generally at least 5 years after the last patient contact, longer for minors and in certain circumstances
Billing and tax records7 years
Account and contact dataWhile your account is active, plus 2 years after closure
Marketing contact dataUntil you unsubscribe, then suppression-list only
Support and communication logs3 years
Web server and security logs12 months
Applications that don't become clients12 months, then deleted

When a retention period ends, we delete or irreversibly de-identify the data.

12How We Protect Data

  • Encryption in transit (TLS) and at rest for systems holding health or payment data.
  • Access controls — role-based, least-privilege access; individual accounts; multi-factor authentication for staff.
  • Vendor diligence — security review before onboarding, Business Associate Agreements where PHI is involved.
  • Payment isolation — card data is processed by a PCI-DSS compliant processor; we never store full card numbers.
  • Email authentication — SPF, DKIM, and DMARC are configured on our domain to prevent spoofing of BioForge communications.
  • Monitoring, logging, and periodic risk assessment, including the Security Risk Analysis required by the HIPAA Security Rule.
  • Workforce training on privacy and security, with confidentiality agreements.

No system is perfectly secure, and we will not claim otherwise. What we commit to is industry-standard safeguards, prompt investigation of any incident, and honest notification if something goes wrong.

Please do not send health information through unsecured channels — ordinary email, SMS, social media messages, or the general contact form. Use the client portal or another secure channel we designate.

13Data Breach Notification

If a breach of security compromises your personal information, we will notify you as required by Section 501.171, Florida Statutes — generally within 30 days of determining a breach occurred — and will notify the Florida Department of Legal Affairs where the statute requires it.

If the breach involves protected health information, we will also comply with the HIPAA Breach Notification Rule, including notice to you, to the Secretary of Health and Human Services, and where applicable to the media.

Our notice will describe what happened, what data was involved, and what you can do.

14Children's Privacy

The Site and the Services are intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it promptly. If you believe a minor has given us information, contact privacy@bioforge.health.

15Text Messages and Email

If you provide a mobile number and opt in, we may send appointment, refill, billing, and service messages by SMS. Consent to marketing texts is never a condition of purchasing anything. Message and data rates may apply and frequency varies.

  • Reply STOP to any message to opt out; HELP for help.
  • We do not share your mobile number with third parties for their own marketing.
  • SMS and standard email are not encrypted. We keep health detail out of them and use the secure portal for anything clinical.

16Third-Party Links

The Site may link to third-party websites and services. We don't control them and aren't responsible for their privacy practices. Review their policies before providing information.

17Where Data Is Processed

We store and process personal information in the United States. We do not transfer personal information outside the United States for storage. If that ever changes, we will update this policy and implement appropriate safeguards. If you access the Site from outside the U.S., you understand your information will be processed here.

18State-Specific Disclosures

Florida

The Florida Digital Bill of Rights (Part III, Chapter 501, Fla. Stat.) imposes obligations principally on very large online platforms — companies with more than $1 billion in global annual revenue meeting additional criteria. BioForge does not meet that threshold, and we tell you that rather than implying a compliance status we don't have. We nonetheless extend FDBR-style rights to you voluntarily under Section 9. Florida's breach notification law, Section 501.171, does apply to us — see Section 13.

California

If you are a California resident, you have rights under the CCPA as amended, including rights to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information, plus a right against discrimination. We do not sell or share personal information (Section 6), and we use sensitive personal information only to provide the Services you requested and for the permitted purposes in the statute. California's "Shine the Light" law: we do not disclose personal information to third parties for their direct marketing.

Washington, Nevada, and other consumer health data laws

Washington's My Health My Data Act and Nevada's SB 370 regulate "consumer health data" outside HIPAA and create significant restrictions on sharing and selling it — Washington's law includes a private right of action. We do not sell consumer health data, and we do not share it with advertising platforms (Sections 6 and 7). If you are a Washington resident, you may request a list of third parties with whom we have shared your consumer health data by writing to privacy@bioforge.health.

Other states

Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others — have comparable rights. Section 9 extends these rights to everyone, so you do not need to determine whether your state's law technically covers us.

19Changes to This Policy

We may update this policy. When we do, we will change the "Last updated" date and post the new version here. We review this policy at least annually.

For material changes — meaningfully broadening how we use or share your information — we will give you at least 30 days' advance notice by email to the address on your account and by conspicuous notice on the Site, and where the law requires consent, we will ask for it before the change applies to data we already hold. Material changes apply prospectively only. Prior versions are available on request.

20Contact Us

Privacy questions and rights requests:
privacy@bioforge.health

HIPAA Privacy Officer (for medical records and PHI):
privacy@bioforge.health

By mail:
BioForge LLC
Attn: Privacy
3105 NW 107th Ave, STE 400-O6
Doral, Florida 33172

If you are not satisfied with our response, you may contact the Florida Attorney General's Consumer Protection Division, your own state's attorney general, or — for health privacy — the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints. We will not retaliate against you for filing a complaint.

If any part of this policy is unclear, email us and ask. We would rather explain it plainly than have you agree to something you don't understand.