Privacy Policy
Last updated: May 31, 2026
This policy explains what data Aion collects, how it is used and stored, when (and with whom) it is shared, and the choices and rights you have. It applies to the Aion mobile app (the “App”) and the Aion website. Aion is operated by Bionic Light Industries, Inc. (“Aion,” “we,” “us”).
1. Our privacy principles
- On-device first. Your raw health records are stored on your device and encrypted at rest. They do not leave your device unless you explicitly export them or enable an optional cloud feature.
- No advertising, ever. We do not use your health, fitness, or any other personal data for advertising, marketing, or use-based data mining — including by third parties.
- No model training on your data. Health data sent to an AI provider (only in optional cloud modes, only with your consent) is processed to answer your request and is not used to train that provider’s models.
- No third-party tracking. The App contains no advertising SDKs, no third-party analytics trackers, and no cross-app tracking. We do not ask for permission to track you because we don’t.
- You can leave. You can delete your account and associated data from within the App at any time.
2. The two tiers, and what leaves your device
Aion has two experiences with different data behavior. Knowing which you use tells you exactly what happens to your data.
Aion Core (source-available, on-device)
Core aggregates your health data into one secure place on your device and lets you share it with your own computer, over your own local network, using the Aion Bridge. In Core, your health data is not sent to Aion’s servers, to any AI provider, or to any third party. The bridge connection is local to your network and protected by a one-time pairing code.
Aion Standard (full features)
Standard adds optional cloud-powered features — most notably the conversational and voice health assistant. When you use a cloud assistant mode, relevant health context and your messages are sent to the AI provider that powers that mode so it can respond. Before any such sharing happens, the App tells you who the data goes to and asks for your explicit permission. You can use an on-device assistant mode instead, which keeps everything local.
Connected services (wearables, devices, and health records)
You may choose to connect third-party services — such as fitness wearables and rings (e.g. Fitbit, Oura, Polar, WHOOP, Withings, Garmin), continuous glucose monitors and diabetes platforms (e.g. Dexcom, Tidepool), activity services (e.g. Strava), and your healthcare provider’s patient records via SMART-on-FHIR (e.g. Epic, Cerner) — so the App can import your own data from them. When you connect a service:
- You authorize the connection yourself through that provider’s own secure sign-in. Aion requests read-only access to your data.
- The data we retrieve is written into your on-device health record. We do not store your connected-service health data on Aion’s servers, and we do not sell or share it.
- Authorization tokens (and, where a service requires it, credentials you enter) are stored only on your device in the operating system’s secure storage (Keychain on iOS, Keystore on Android, encrypted storage on the web). They are not transmitted to Aion’s servers.
- You can disconnect any service at any time from within the App, which removes its stored authorization from your device.
- Use of data obtained from these services complies with each provider’s API terms and user-data policies.
3. Data we collect
| Category | Examples | Why |
|---|---|---|
| Health & clinical data | Vitals, lab results, conditions, medications, allergies, immunizations, activity, symptom logs, mental-health screening responses (e.g. PHQ-9/GAD-7), and data you import from Apple Health (including Clinical Health Records), connected devices, or files. | To provide the App’s core functionality — organizing and presenting your health information to you. |
| Account data | Name and email address (when you create an account). | To create and secure your account, and to sync settings. |
| Audio & speech | Microphone audio and transcripts when you use the voice assistant. | To understand and respond to voice requests. On-device modes keep this local; cloud voice sends audio/transcripts to the provider powering that mode. |
| Location | Device location, only when you use a feature that needs it (e.g. emergency assistance, nearby-care). | Only used for the specific feature you invoke; you control access in system settings and in the App. |
| Device & app data | App settings, preferences, and basic diagnostic information you choose to share. | To run the App and, if you opt in, to fix bugs. |
We collect health data directly from you and from sources you connect (Apple Health, connected devices, or files you import). We do not compile your personal information from public databases or other sources without your consent.
4. How your data is stored and protected
- Encryption at rest. Health data stored on your device is encrypted (AES). On supported devices, encryption keys are held in the secure device keystore (e.g. iOS Keychain).
- No personal health information in iCloud. We do not store your personal health information in iCloud.
- De-identification before cloud processing. When an optional cloud feature is used, direct identifiers (such as name, email, and record identifiers) are stripped before transmission. Note that clinical values themselves (for example, a lab result) are part of what you’re asking the assistant about and may be included in the request you authorize.
- Local bridge security. The Aion Bridge serves your data only over your local network and only to a device you pair using a one-time code; the pairing is rate-limited and cleared when you stop the bridge.
5. When data is shared — and with whom
We do not sell your personal data. We share it only in these cases:
Service providers that power features you use
| Provider | Purpose | When |
|---|---|---|
| Anthropic (Claude) | Conversational/voice health assistant | Standard, cloud assistant mode, with your consent |
| OpenAI | Real-time voice assistant, voice transcription (speech-to-text), and text-to-speech | Standard, cloud voice modes, with your consent |
| Google (Sign-in) | Optional account sign-in | Only if you choose Google sign-in |
| Aion backend (hosted on Railway) | Account, sync, and routing for cloud features | When you use account-based or cloud features |
| Health data sources you connect | Importing your own records (e.g. Apple Health, Dexcom, Oura, Whoop, Withings, Strava, CMS Blue Button) | Only the sources you explicitly connect, via their official authorization |
These providers act as data processors: they process your data to deliver the requested feature and are not permitted to use your health data for their own advertising or to train their models on it. If you supply your own AI provider API key in Standard, your requests go directly to whatever endpoint you configure — which may be a third party we have no agreement with (for example OpenAI, Groq, Together, or a self-hosted server) — under your own account and that provider's terms. Choose such endpoints with care.
Other limited cases
- At your direction — e.g. when you export your data or share it with your own computer via the bridge.
- Legal requirements — if required by law, with notice where permitted.
- Business transfers — if Aion is involved in a merger or acquisition, with continued protection of your data and notice to you.
6. Your choices and rights
- Permissions. You control access to your camera, microphone, location, Bluetooth, calendar, Apple Health, and local network in your device settings, and you can change them at any time. Features degrade gracefully if you decline.
- Consent for cloud AI. Cloud assistant features ask for explicit permission before sending any data, and you can revoke it.
- Access & export. You can view and export your health data from within the App.
- Account & data deletion. You can delete your account and associated data from within the App (Settings → Account). Deletion removes your account and the health data we hold for it.
- Withdraw consent. You can turn off optional data uses (such as diagnostics or cloud modes) in Settings → Privacy.
Depending on where you live, you may have additional rights (access, correction, deletion, portability, objection). Contact us to exercise them.
7. Data retention
Health data stays on your device until you delete it or uninstall the App. Account data and any data synced for cloud features are retained while your account is active and deleted when you delete your account, except where we must retain limited records to comply with law. Cloud AI requests are processed to answer you and are not retained by us to build a profile of you.
8. Children
Aion is not directed to children under 13 (or the equivalent minimum age in your region) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
9. Not medical advice
10. Changes to this policy
We will update this policy as the App evolves and post the new “Last updated” date here. Material changes will be communicated in-app where appropriate.