Effective August 21, 2026
This policy explains what Noey Enterprises Inc. does with your data as a member of BioField Live, and — just as importantly — what it does not do.
Every claim here describes how the software actually behaves. Where something leaves your device, it is named, in the same plain words the feature itself uses.
The rest of this document is the detail behind those five lines.
Noey Enterprises Inc. is the controller of the personal data described here. We decide what is collected and why, and we are who you complain to.
Contact for anything about your data, including requests to see, correct, export or delete it: privacy@biofieldlive.com. We answer within one month; where a request is complex we may take a further two months and will tell you within the first.
When you take a reading, your device’s camera produces frames. Those frames are analysed in your browser — average colour over small patches of skin, from which a pulse estimate is derived — and then discarded. The video is never written to our servers and never leaves your device. The same is true of the microphone: what is derived from it are qualities of the sound, not a recording.
Two things do leave your device, both only when you choose them:
(a) Showing something to your companion. If you press to show your Neeber what you are looking at, one still image, reduced to 512 pixels, is sent to an automated captioner, which returns a short description such as “a cup of coffee on a windowsill”. The image is discarded in the same request and is never stored. Only the phrase reaches your companion. A caption that describes a person is dropped entirely rather than used. This happens once per press, never continuously, and never without the press.
(b) Dictation. Speaking to type uses your browser’s own speech recognition, and most browsers send that audio to the browser vendor for transcription. That is their processing, under their policy, not ours. It is a separate switch from spoken replies — which are produced on your device — precisely so that turning on a voice you can hear never quietly turns on a microphone that leaves.
Unless you turn on sync, these live only in your browser’s storage on the device you made them on: your moments and readings, your day and lifestyle summaries, your journal, and your profile and preferences. Clearing your browser’s data for this site erases them, and we cannot restore them.
On-device readings only. Settings contains a switch that stops every network call a reading would otherwise make. With it on, readings are generated by your device alone, and nothing about them — not even derived numbers — reaches us or any provider.
To run the Club we hold:
If you turn on sync so your records reach your other devices, each record is encrypted on your device before it is uploaded. What we store is a sealed packet: an initialisation vector and ciphertext. The key is derived on your devices and never sent to us.
Our servers validate the shape of the envelope — that it is a packet at all — and never the contents. There is no code path on our side that decrypts one, because we do not have the key.
The consequence, stated plainly: if you lose every device and the means of deriving your key, we cannot recover your sealed records. That is the cost of us not being able to read them, and we would rather tell you now than at the moment you need them.
We do see, and cannot avoid seeing, the metadata around a sealed record: which account it belongs to, roughly when it changed, and how large it is.
When a reading is written in words, what leaves your device is a small set of derived numbers — scores describing calm, energy and steadiness — together, if you have chosen to supply them, with a name to be called, an intention you are holding, an age range, and a tone you prefer.
No image, no video, no audio, and no raw signal is ever sent to an AI provider.
These requests are pass-through: we do not store the request or the text that comes back. Providers are engaged as processors, are contractually barred from using your data to train their models, and retain data only as long as their abuse-prevention obligations require. Turning on “on-device readings only” stops these requests entirely.
Membership payments are handled by a payment processor. Your card number and security code go to them, not to us — we never see or store them.
What we keep is the record of the transaction: that dues were paid, when, how much, the last four digits and card type, and the billing country needed for tax. We keep those records for 7 years, because tax and accounting law requires it, and that period is not shortened by a deletion request.
A pulse estimate derived from your face is treated as sensitive wherever the law treats it so — as biometric information in Illinois, Texas and Washington, as consumer health data under Washington’s My Health My Data Act and Nevada’s equivalent, and as special-category data under the GDPR and UK GDPR.
We hold ourselves to these rules everywhere, not only where they bind us:
You can withdraw biometric consent at any time in Settings. Doing so stops collection immediately and deletes what was derived.
Our lawful bases under the GDPR and UK GDPR:
We give every member the same core rights, regardless of whether their country compels us: to know what we hold, to get a copy in a portable form, to correct it, to delete it, to restrict or object to processing, and to withdraw consent.
EU, EEA, UK, Switzerland. You additionally have the right to lodge a complaint with your supervisory authority — in the UK the Information Commissioner’s Office, in Switzerland the FDPIC, and in the EU your national data protection authority. We would rather you told us first, but you are not required to.
California. You have the rights to know, delete, correct, and to opt out of sale or sharing — we do no sale or sharing, so there is nothing to opt out of — and to limit the use of sensitive personal information. We do not use sensitive personal information for anything beyond providing the Club, which is the exempt purpose, so that limit is already the state we operate in. You will never be discriminated against for exercising a right; membership terms do not change because you asked.
Other US states. Members in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy laws have equivalent rights, including appeal of a refused request. To appeal, reply to our decision and say so; if we refuse again we will tell you how to contact your Attorney General.
Canada, Brazil, Australia, and elsewhere. Members under PIPEDA, the LGPD, the Australian Privacy Act and comparable laws have the rights those laws give, and the same core rights above.
To exercise anything: privacy@biofieldlive.com, or use the export and delete controls in your account. We verify a request by the account it comes from; where a request is made on your behalf, we will ask for proof of authority.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in California and the other US state privacy laws. We have not done so in the preceding twelve months. There are no advertising trackers in the Club.
The only third parties who touch your data are processors doing a job for us — hosting, email and SMS delivery, payment processing, automated text generation, bot protection, and speech synthesis where you use a minted voice. Each is bound by contract to use it only for that job.
The Club runs on distributed infrastructure and your data may be processed in the United States and other countries.
For transfers out of the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss amendments where applicable, together with technical measures — chiefly the sealing described in section 6, which means much of what crosses a border is unreadable to anyone holding it, including us.
You can ask us for details of the safeguards used for a particular transfer at privacy@biofieldlive.com.
Transport is encrypted. Sign-in is by passkey or one-time code rather than a password, so there is no password of yours for anyone to steal from us. Session tokens are stored as hashes, so a copy of our database does not yield a way in. Synced records are sealed before they arrive.
No system is perfect. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant authorities within the deadlines the law sets — 72 hours to a supervisory authority under the GDPR — and tell you plainly what happened and what to do.
The Club is for adults and is not directed to children. We do not knowingly collect data from anyone under the minimum joining age. If you believe a child has given us data, write to privacy@biofieldlive.com and we will delete it and close the account.
We use a single sign-in cookie, which is strictly necessary to keep you signed in. It is HttpOnly, Secure, and scoped to the site that set it. There are no advertising cookies and no third-party analytics profiling in the Club.
We also use your browser’s local storage and database for your own records and preferences. That is storage on your device, not transmission to us, and clearing it removes them.
We may update this policy. If a change materially affects how we handle your data, we will tell you before it takes effect and, where the change requires it, ask for your consent again. The effective date at the top tells you which version you are reading.
Noey Enterprises Inc. — privacy@biofieldlive.com for data questions, hello@biofieldlive.com for everything else.