Skip to content
Legal · Privacy

Privacy Policy

Privacy-firstLast updated: September 8, 2026

Bymax Bio is a personal health-tracking app maintained by the Bymax team. This policy explains how we handle your personal data and is aligned with Brazil's General Data Protection Law (LGPD, Law 13,709/2018) and the European Union's General Data Protection Regulation (GDPR).

Who we are

Bymax Bio is maintained by the Bymax team. We act as the controller of the personal data processed by the app.

To reach our privacy team, write to support@bymax.one.

Data we collect

Data you enter directly: weight, body measurements, medications, doses, symptoms, nutrition logs (hydration, calories, protein), daily wellbeing, configured reminders, notes and app preferences.

Technical data collected automatically: a pseudonymous local identifier, device model, operating system, language and crash diagnostics. The identifier is generated on your own device and is never linked to your name or email. For telemetry and crash reports, we send only a one-way hash of this identifier. For subscription management, the identifier is shared in its original form with the provider (RevenueCat) only to associate your purchases.

We do not require you to register a name, email, phone, government ID or address to use the app.

How we use your data

To provide and operate the app, personalize your experience, calculate charts and indicators and meet legal obligations.

When telemetry is enabled, we process aggregated, anonymous events to understand feature usage and improve the product.

We do not use your health data for advertising, nor do we sell it to third parties.

Legal basis

We process your personal data on the basis of our legitimate interest in operating and improving the product (Art. 7, IX of the LGPD), our legal obligations and, where applicable, your consent.

Usage telemetry and crash reports are processed on the basis of legitimate interest, are enabled by default and can be disabled by you at any time in Settings › Privacy.

Sensitive health data (including menstrual cycle records) is stored exclusively on your device, is not sent to telemetry or any third party, and can be erased by you at any time.

Sharing with third parties

Providers acting on our behalf under contractual agreements:

  • Anonymous telemetry (PostHog) — aggregated usage events, without sensitive health information;
  • Crash reports (Sentry) — sanitized technical diagnostics, without personal or health data;
  • Subscription management (RevenueCat) — receives only the app's local identifier to associate your purchases made via the Apple App Store or Google Play.

Subscription payments, when applicable, are processed directly by the Apple App Store or Google Play; we do not collect or store card data.

We do not sell your personal data.

Scope: these integrations (PostHog, Sentry and RevenueCat) apply exclusively to the Bymax Bio mobile app. This marketing site does not run product analytics — at most, aggregated traffic metrics from the hosting provider (Cloudflare).

Telemetry and crash reports

By default, usage telemetry and crash reports are enabled to help us understand issues and improve the product. You can disable them at any time in Settings › Privacy — from that moment, no new event or report will be sent.

The events we send are limited to a predefined list and never include dose, medication name, personal notes, menstrual cycle data or other sensitive health information.

Reproductive health data

Menstrual cycle tracking records (period dates, symptoms, predicted phase) are sensitive personal data under Article 11 of the LGPD.

This data is stored exclusively on your device and is not sent to our servers, telemetry or any third party.

The feature is opt-in, requires explicit acceptance of its disclaimer and can be deleted in Settings › Female health › Clear cycle data.

International transfers

Our service providers may process data in countries outside Brazil.

We adopt appropriate safeguards, such as standard contractual clauses, to ensure a level of protection compatible with the LGPD and the GDPR.

Your rights

Access, correction, deletion, anonymization, portability and withdrawal of consent regarding your personal data.

To exercise these rights, write to support@bymax.one.

You may also erase all app data in Settings › Erase all data.

Data retention

We retain your data for as long as needed to provide the service and meet legal obligations.

When you request deletion or uninstall the app, the associated data is removed within applicable legal timeframes.

Security

We adopt reasonable technical and organizational measures: encryption in transit, access controls and periodic review.

No system is completely secure; in the event of a relevant incident, we will notify you and the ANPD as required by law.

Children

The app is intended for users aged 17 and older. We do not knowingly collect data from minors under 17.

If you are a legal guardian and identify improper collection, contact us so we can remove it.

Changes to this policy

We may update this policy to reflect changes in the product, the law or security practices.

Material changes will be communicated within the app before they take effect.

Contact

Questions, rights requests or any privacy matter: support@bymax.one.