Privacy Policy

Effective August 21, 2026

This policy explains what Noey Enterprises Inc. does with your data as a member of BioField Live, and — just as importantly — what it does not do.

Every claim here describes how the software actually behaves. Where something leaves your device, it is named, in the same plain words the feature itself uses.

1. The short version

  • Your camera and microphone are read on your device. Video and audio are processed frame by frame in your browser and are never stored by us and never sent to us. Section 3 names the two exceptions precisely, because a policy with an unnamed exception is not a policy.
  • Most of what you create is sealed before it reaches us. Your synced records are encrypted on your device with a key we never receive. We hold the ciphertext and cannot read it.
  • We do not sell your data, share it for advertising, or use it to train machine-learning models.
  • Readings can be kept entirely on your device. One switch in Settings stops every network call a reading would make.
  • You can take your data out and have it deleted, wherever you live — not only where the law compels it.

The rest of this document is the detail behind those five lines.

2. Who is responsible for your data

Noey Enterprises Inc. is the controller of the personal data described here. We decide what is collected and why, and we are who you complain to.

Contact for anything about your data, including requests to see, correct, export or delete it: privacy@biofieldlive.com. We answer within one month; where a request is complex we may take a further two months and will tell you within the first.

3. Camera, microphone, and the two exceptions

When you take a reading, your device’s camera produces frames. Those frames are analysed in your browser — average colour over small patches of skin, from which a pulse estimate is derived — and then discarded. The video is never written to our servers and never leaves your device. The same is true of the microphone: what is derived from it are qualities of the sound, not a recording.

Two things do leave your device, both only when you choose them:

(a) Showing something to your companion. If you press to show your Neeber what you are looking at, one still image, reduced to 512 pixels, is sent to an automated captioner, which returns a short description such as “a cup of coffee on a windowsill”. The image is discarded in the same request and is never stored. Only the phrase reaches your companion. A caption that describes a person is dropped entirely rather than used. This happens once per press, never continuously, and never without the press.

(b) Dictation. Speaking to type uses your browser’s own speech recognition, and most browsers send that audio to the browser vendor for transcription. That is their processing, under their policy, not ours. It is a separate switch from spoken replies — which are produced on your device — precisely so that turning on a voice you can hear never quietly turns on a microphone that leaves.

4. What stays on your device

Unless you turn on sync, these live only in your browser’s storage on the device you made them on: your moments and readings, your day and lifestyle summaries, your journal, and your profile and preferences. Clearing your browser’s data for this site erases them, and we cannot restore them.

On-device readings only. Settings contains a switch that stops every network call a reading would otherwise make. With it on, readings are generated by your device alone, and nothing about them — not even derived numbers — reaches us or any provider.

5. What we hold on our servers

To run the Club we hold:

  • Your account: the email address or phone number you joined with, when you joined, your membership status, and — if you gave it — a display name and date of birth used for the age check.
  • Sign-in material: public keys for your passkeys (never a private key, which cannot leave your device), and short-lived one-time codes. We do not store passwords.
  • Your sessions and devices: a coarse label such as “iPhone · Safari” and when it was last used, so you can recognise your own devices and end a session you do not.
  • Consents: what you agreed to, which version, and when — the record that proves we asked.
  • Membership administration: your application and invitation records, and correspondence you send to support.
  • Sealed records: if you turn on sync, your moments and other records as ciphertext (section 6).
  • Your companion: a seed — a short string from which your Neeber’s name, appearance and life are derived — and what you have chosen to name them. Not the readings that shaped the seed; those were digested on your device and discarded.
  • Technical logs: minimal, short-lived records of requests, used to keep the service up and to stop abuse.

6. Sealed sync: we hold it, we cannot read it

If you turn on sync so your records reach your other devices, each record is encrypted on your device before it is uploaded. What we store is a sealed packet: an initialisation vector and ciphertext. The key is derived on your devices and never sent to us.

Our servers validate the shape of the envelope — that it is a packet at all — and never the contents. There is no code path on our side that decrypts one, because we do not have the key.

The consequence, stated plainly: if you lose every device and the means of deriving your key, we cannot recover your sealed records. That is the cost of us not being able to read them, and we would rather tell you now than at the moment you need them.

We do see, and cannot avoid seeing, the metadata around a sealed record: which account it belongs to, roughly when it changed, and how large it is.

7. What is sent to AI providers, and what is not

When a reading is written in words, what leaves your device is a small set of derived numbers — scores describing calm, energy and steadiness — together, if you have chosen to supply them, with a name to be called, an intention you are holding, an age range, and a tone you prefer.

No image, no video, no audio, and no raw signal is ever sent to an AI provider.

These requests are pass-through: we do not store the request or the text that comes back. Providers are engaged as processors, are contractually barred from using your data to train their models, and retain data only as long as their abuse-prevention obligations require. Turning on “on-device readings only” stops these requests entirely.

8. Payments

Membership payments are handled by a payment processor. Your card number and security code go to them, not to us — we never see or store them.

What we keep is the record of the transaction: that dues were paid, when, how much, the last four digits and card type, and the billing country needed for tax. We keep those records for 7 years, because tax and accounting law requires it, and that period is not shortened by a deletion request.

9. Biometric and health-adjacent information

A pulse estimate derived from your face is treated as sensitive wherever the law treats it so — as biometric information in Illinois, Texas and Washington, as consumer health data under Washington’s My Health My Data Act and Nevada’s equivalent, and as special-category data under the GDPR and UK GDPR.

We hold ourselves to these rules everywhere, not only where they bind us:

  • Nothing is collected without your consent, given before collection, separately from these documents, and withdrawable at any time.
  • We never sell, lease, trade or profit from biometric or health-adjacent information. There is no circumstance in which we would.
  • Face frames are not retained at all. They are analysed on your device and discarded in the same moment. We hold no face template, no faceprint, and no biometric identifier from which you could be recognised.
  • Derived scores are deleted when you delete the moment they belong to, when you close your membership, or within three years of your last use of the Club — whichever comes first.
  • We do not disclose it to anyone except a processor acting for us under contract, or where a court order or law compels it — and we will tell you if that happens unless we are forbidden to.

You can withdraw biometric consent at any time in Settings. Doing so stops collection immediately and deletes what was derived.

10. Why we are allowed to process this (EU, EEA, UK)

Our lawful bases under the GDPR and UK GDPR:

  • Performance of a contract — running your membership, signing you in, taking payment, providing the features you joined for.
  • Your explicit consent — for anything derived from your camera or microphone, which is special-category data under Article 9(2)(a), and for optional extras such as dictation. You may withdraw consent at any time; withdrawal does not undo processing already carried out lawfully.
  • Legitimate interests — keeping the Club secure, preventing abuse and fraud, and understanding aggregate reliability. We have weighed these against your rights and use the least data that works.
  • Legal obligation — tax, accounting, and responding lawfully to authorities.

11. Your rights, wherever you live

We give every member the same core rights, regardless of whether their country compels us: to know what we hold, to get a copy in a portable form, to correct it, to delete it, to restrict or object to processing, and to withdraw consent.

EU, EEA, UK, Switzerland. You additionally have the right to lodge a complaint with your supervisory authority — in the UK the Information Commissioner’s Office, in Switzerland the FDPIC, and in the EU your national data protection authority. We would rather you told us first, but you are not required to.

California. You have the rights to know, delete, correct, and to opt out of sale or sharing — we do no sale or sharing, so there is nothing to opt out of — and to limit the use of sensitive personal information. We do not use sensitive personal information for anything beyond providing the Club, which is the exempt purpose, so that limit is already the state we operate in. You will never be discriminated against for exercising a right; membership terms do not change because you asked.

Other US states. Members in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy laws have equivalent rights, including appeal of a refused request. To appeal, reply to our decision and say so; if we refuse again we will tell you how to contact your Attorney General.

Canada, Brazil, Australia, and elsewhere. Members under PIPEDA, the LGPD, the Australian Privacy Act and comparable laws have the rights those laws give, and the same core rights above.

To exercise anything: privacy@biofieldlive.com, or use the export and delete controls in your account. We verify a request by the account it comes from; where a request is made on your behalf, we will ask for proof of authority.

12. We do not sell or share your data

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in California and the other US state privacy laws. We have not done so in the preceding twelve months. There are no advertising trackers in the Club.

The only third parties who touch your data are processors doing a job for us — hosting, email and SMS delivery, payment processing, automated text generation, bot protection, and speech synthesis where you use a minted voice. Each is bound by contract to use it only for that job.

13. Where your data goes

The Club runs on distributed infrastructure and your data may be processed in the United States and other countries.

For transfers out of the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss amendments where applicable, together with technical measures — chiefly the sealing described in section 6, which means much of what crosses a border is unreadable to anyone holding it, including us.

You can ask us for details of the safeguards used for a particular transfer at privacy@biofieldlive.com.

14. How long we keep things

  • Camera and microphone frames: not retained — discarded as they are processed.
  • Shown images: not retained — discarded in the same request that captioned them.
  • Reading requests and their text: not retained.
  • Your records and sealed data: until you delete them or close your membership.
  • Account and sign-in material: for as long as you are a member, then deleted within 30 days of closure.
  • Backups: deleted content ages out of backups within 90 days.
  • Support correspondence: 24 months.
  • Payment and tax records: 7 years, as the law requires.
  • Consent records: kept while you are a member and for as long afterwards as we may need to show we asked.

15. How we protect it

Transport is encrypted. Sign-in is by passkey or one-time code rather than a password, so there is no password of yours for anyone to steal from us. Session tokens are stored as hashes, so a copy of our database does not yield a way in. Synced records are sealed before they arrive.

No system is perfect. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant authorities within the deadlines the law sets — 72 hours to a supervisory authority under the GDPR — and tell you plainly what happened and what to do.

16. Children

The Club is for adults and is not directed to children. We do not knowingly collect data from anyone under the minimum joining age. If you believe a child has given us data, write to privacy@biofieldlive.com and we will delete it and close the account.

17. Storage on your device, and cookies

We use a single sign-in cookie, which is strictly necessary to keep you signed in. It is HttpOnly, Secure, and scoped to the site that set it. There are no advertising cookies and no third-party analytics profiling in the Club.

We also use your browser’s local storage and database for your own records and preferences. That is storage on your device, not transmission to us, and clearing it removes them.

18. Changes, and how to reach us

We may update this policy. If a change materially affects how we handle your data, we will tell you before it takes effect and, where the change requires it, ask for your consent again. The effective date at the top tells you which version you are reading.

Noey Enterprises Inc. — privacy@biofieldlive.com for data questions, hello@biofieldlive.com for everything else.