Privacy Policy

Last updated: May 31, 2026

The short version. Aion is built to keep your health data on your device, under your control. We do not sell your data, we do not use it for advertising, and we never use your health data to train AI models. Cloud features that send data off your device are optional and ask for your explicit permission first, naming exactly who receives it.

This policy explains what data Aion collects, how it is used and stored, when (and with whom) it is shared, and the choices and rights you have. It applies to the Aion mobile app (the “App”) and the Aion website. Aion is operated by Bionic Light Industries, Inc. (“Aion,” “we,” “us”).

1. Our privacy principles

2. The two tiers, and what leaves your device

Aion has two experiences with different data behavior. Knowing which you use tells you exactly what happens to your data.

Aion Core (source-available, on-device)

Core aggregates your health data into one secure place on your device and lets you share it with your own computer, over your own local network, using the Aion Bridge. In Core, your health data is not sent to Aion’s servers, to any AI provider, or to any third party. The bridge connection is local to your network and protected by a one-time pairing code.

Aion Standard (full features)

Standard adds optional cloud-powered features — most notably the conversational and voice health assistant. When you use a cloud assistant mode, relevant health context and your messages are sent to the AI provider that powers that mode so it can respond. Before any such sharing happens, the App tells you who the data goes to and asks for your explicit permission. You can use an on-device assistant mode instead, which keeps everything local.

Connected services (wearables, devices, and health records)

You may choose to connect third-party services — such as fitness wearables and rings (e.g. Fitbit, Oura, Polar, WHOOP, Withings, Garmin), continuous glucose monitors and diabetes platforms (e.g. Dexcom, Tidepool), activity services (e.g. Strava), and your healthcare provider’s patient records via SMART-on-FHIR (e.g. Epic, Cerner) — so the App can import your own data from them. When you connect a service:

3. Data we collect

CategoryExamplesWhy
Health & clinical dataVitals, lab results, conditions, medications, allergies, immunizations, activity, symptom logs, mental-health screening responses (e.g. PHQ-9/GAD-7), and data you import from Apple Health (including Clinical Health Records), connected devices, or files.To provide the App’s core functionality — organizing and presenting your health information to you.
Account dataName and email address (when you create an account).To create and secure your account, and to sync settings.
Audio & speechMicrophone audio and transcripts when you use the voice assistant.To understand and respond to voice requests. On-device modes keep this local; cloud voice sends audio/transcripts to the provider powering that mode.
LocationDevice location, only when you use a feature that needs it (e.g. emergency assistance, nearby-care).Only used for the specific feature you invoke; you control access in system settings and in the App.
Device & app dataApp settings, preferences, and basic diagnostic information you choose to share.To run the App and, if you opt in, to fix bugs.

We collect health data directly from you and from sources you connect (Apple Health, connected devices, or files you import). We do not compile your personal information from public databases or other sources without your consent.

4. How your data is stored and protected

5. When data is shared — and with whom

We do not sell your personal data. We share it only in these cases:

Service providers that power features you use

ProviderPurposeWhen
Anthropic (Claude)Conversational/voice health assistantStandard, cloud assistant mode, with your consent
OpenAIReal-time voice assistant, voice transcription (speech-to-text), and text-to-speechStandard, cloud voice modes, with your consent
Google (Sign-in)Optional account sign-inOnly if you choose Google sign-in
Aion backend (hosted on Railway)Account, sync, and routing for cloud featuresWhen you use account-based or cloud features
Health data sources you connectImporting your own records (e.g. Apple Health, Dexcom, Oura, Whoop, Withings, Strava, CMS Blue Button)Only the sources you explicitly connect, via their official authorization

These providers act as data processors: they process your data to deliver the requested feature and are not permitted to use your health data for their own advertising or to train their models on it. If you supply your own AI provider API key in Standard, your requests go directly to whatever endpoint you configure — which may be a third party we have no agreement with (for example OpenAI, Groq, Together, or a self-hosted server) — under your own account and that provider's terms. Choose such endpoints with care.

Other limited cases

Health data is never used for advertising, marketing, or use-based data mining, by us or by any third party. This includes any data obtained from Apple Health / HealthKit and the Clinical Health Records API.

6. Your choices and rights

Depending on where you live, you may have additional rights (access, correction, deletion, portability, objection). Contact us to exercise them.

7. Data retention

Health data stays on your device until you delete it or uninstall the App. Account data and any data synced for cloud features are retained while your account is active and deleted when you delete your account, except where we must retain limited records to comply with law. Cloud AI requests are processed to answer you and are not retained by us to build a profile of you.

8. Children

Aion is not directed to children under 13 (or the equivalent minimum age in your region) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

9. Not medical advice

Aion is a wellness and personal health-information tool — not a medical device and not a substitute for professional care. Aion does not provide diagnosis or treatment. Always consult a qualified healthcare provider before making medical decisions, and call your local emergency number for emergencies.

10. Changes to this policy

We will update this policy as the App evolves and post the new “Last updated” date here. Material changes will be communicated in-app where appropriate.

11. Contact us

Bionic Light Industries, Inc.
Privacy: privacy@blihealth.com
Support: aion-app.health/support