Privacy policy
BIOS is made by Helion AI Infrastructure ("Helion", "we", "us"). This policy explains what data BIOS collects, why, where it goes, and how you delete it. It applies to the BIOS apps for iPhone, iPad, and Mac, the BIOS server at api.usebios.com, and this website.
The short version: BIOS reads data from the business tools you connect so that your agents can do work you approve. We do not sell it, we never mix one customer's data with another's, and disconnecting a tool removes our access.
1. What we collect
Account and company data
- Your name, email address, and a hashed password, or your Apple ID token if you sign in with Apple.
- Your company name, the teammates you invite, and the projects and agents you set up inside BIOS.
- A device push token so we can notify you when an action needs your approval.
Data from platforms you connect
When you connect a platform through its sign-in (OAuth), that platform gives BIOS a token and the data below. We request the minimum scopes each capability needs.
| Platform | What BIOS reads | What BIOS can write |
|---|---|---|
| Shopify | Orders and products | Nothing |
| Klaviyo | Account, profiles, lists, campaigns, metrics | Campaign drafts, only when you approve the action |
| Meta | Ad account insights (ads_read) | Nothing |
| Google Ads | Campaign and performance data | Nothing |
| Google Calendar, Microsoft 365 | Calendar events (read-only) | Nothing |
| Slack | Messages in channels where BIOS is mentioned or messaged directly | Replies in those threads |
Your AI subscriptions
If you sign in to Claude, ChatGPT, or Grok inside BIOS, we store the resulting token encrypted so your agents can run on your subscription. The token is never placed in a prompt, a log, or an agent's memory. You can instead provide your own API key.
BIOS in ChatGPT, Codex and Claude
You can connect BIOS to ChatGPT, Codex or Claude to use it from those apps. Before any AI app can connect, an owner of your company must have agreed to AI data sharing in BIOS, and you sign in to BIOS and choose Allow. We then keep a record of the connection (which app, which person allowed it, what it may do, and when it was allowed or ended) and its access tokens, stored only as one-way hashes. When the app uses BIOS, BIOS sends it what you asked for: your company's numbers, what is waiting for your approval, and answers to your questions. A request you send to your team through the app is stored as a message in your company's BIOS thread, like a message you type in BIOS.
Usage data
Server logs (request path, timing, status, and a redacted error message), the actions your agents proposed and what you decided, and crash reports from the apps. We do not use advertising trackers, and this website sets no cookies.
2. Why we use it
- To run the service: sign you in, keep your devices in sync, and let agents do the work you asked for.
- To keep agents inside guardrails: every action is checked against a trust tier before it runs, and irreversible actions always wait for your tap.
- To improve BIOS from measured outcomes, only where you have given permission for your store's outcomes to be used, and never by blending one customer's data with another's.
- To reach you about your account, invites, and approvals.
3. Google API Services user data
BIOS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is read only to show your schedule to you and your agents inside BIOS; Google Ads data is read only to report and plan for your own ad accounts. We do not transfer Google user data to third parties except as needed to provide the feature, do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.
4. Who we share it with
We never sell your data and never share it across customers. We use these providers to run BIOS, each bound to process data only on our instructions:
- A hosting provider in the United States for the BIOS server and database.
- Apple, for push notifications and Sign in with Apple.
- An email provider, for verification and invitation emails.
- The AI provider you chose (Anthropic, OpenAI, or xAI). When an agent runs, the prompt it needs, which can include data from your connected platforms, is sent to that provider under your own subscription and their terms.
- The platforms you connect, to read and, where you approve, write on your behalf.
- The AI app you connect BIOS to (OpenAI for ChatGPT and Codex, Anthropic for Claude). It receives what BIOS returns in your conversations, under that company's terms and your account with them.
We may also disclose data if the law requires it, or to protect the rights and safety of Helion, our customers, or others.
5. How long we keep it
- Account and company data: while your company's account is active, then deleted within 30 days of the company's deletion. A member who deletes their own account is disabled and every sign-in they hold ends. Their name and email stay on the company's records, such as decisions and messages they wrote, until the company's account is deleted.
- Platform tokens: deleted the moment you disconnect the platform, and the platform's authorization is revoked.
- Data read from a platform: deleted within 30 days of disconnecting that platform or deleting your account.
- AI app connections: a connection stops working when you disconnect it in an app that tells BIOS (otherwise once it has gone unused for 30 days), when you are removed from the company, reset your password, sign out everywhere or delete your account, or when no owner is sharing AI data any more. Access tokens expire within an hour, and expired tokens and sign-in codes are deleted within about a day of expiring while BIOS is in use. The record of the connection is kept while your company's account is active, then deleted with it.
- Registered AI app details (the app's name and return addresses, no personal data) are kept so the app can reconnect.
- Requests sent through an AI app: kept with your company's other messages while your company's account is active.
- Server logs: 30 days.
6. Deleting your data
You can disconnect any platform or delete your account from inside the app at any time, or email us. Full instructions are on the data deletion page.
7. Security
Credentials are encrypted at rest with a key that never leaves the server. Every customer's data is isolated in the database with row-level security enforced on every table. All traffic uses TLS. Agents never hold a credential: a broker makes each call on their behalf. Read more on the security page.
8. Your rights
You can access, correct, export, or delete your data by emailing us. If you are in a jurisdiction that grants additional rights (for example the EU, UK, or California), we honor them on request. We do not discriminate against you for exercising them.
9. Children
BIOS is a business tool for adults. We do not knowingly collect data from anyone under 18.
10. Changes
If we change this policy in a way that matters, we will email account holders before it takes effect and update the date above.
11. Contact
Helion AI Infrastructure
Texas, United States
sutton@helionhq.com