Back to BioStack

Effective May 25, 2026

Privacy Policy

This Privacy Policy explains how BioStack by Ascend, operated by Ascend, collects, uses, shares, and protects information when you use the BioStack protocol engine, optional bloodwork extraction, newsletter, and Shopify-powered storefront.

BioStack is a dietary supplement recommendation and commerce experience. It is not a medical device, doctor, clinic, pharmacy, laboratory, insurer, or emergency service. Do not use BioStack to diagnose, treat, cure, or prevent disease, and do not delay medical care because of anything shown in the app.

Health, AI, and Liability

BioStack recommendations are based on self-reported information, optional lab values, catalog rules, and AI-generated or server-scored explanations. AI output and supplement matching can be incomplete, inaccurate, or unsuitable for your specific circumstances. You are responsible for reviewing labels, ingredients, allergens, contraindications, dosing instructions, and interactions before purchasing or using any product.

Consult a licensed healthcare professional before starting, stopping, or changing any supplement, especially if you are pregnant, nursing, under medical care, have a health condition, have abnormal labs, or take prescription or over-the-counter medication. If you experience a medical emergency, call emergency services.

Dietary supplement statements on BioStack have not been evaluated by the U.S. Food and Drug Administration. Products shown through the service are not intended to diagnose, treat, cure, or prevent any disease. Product descriptions, Shopify content, and AI summaries are informational only and do not guarantee any health outcome.

To the fullest extent allowed by law, BioStack and Ascend provide the service, protocols, AI summaries, product information, and store links "as is" and without warranties. We are not liable for indirect, incidental, consequential, special, exemplary, or punitive damages, lost profits, loss of data, health outcomes, product misuse, decisions made from AI output, or third-party services such as Shopify, Typeform, payment processors, shipping carriers, or AI providers. Some jurisdictions do not allow certain limitations, so these limits apply only where permitted.

Information We Collect

Protocol profile information

Name, age, biological sex, height, weight, body-fat estimate, goals, health ratings, conditions, family history, training, injuries, sunlight, sleep, stress, alcohol use, cosmetic concerns, medications, allergies, and extra context you choose to enter.

Bloodwork and biomarker information

Optional lab PDFs or images, file names, manually entered markers, extracted markers, units, reference ranges, collection dates, confidence scores, and source snippets. The app currently focuses on markers such as testosterone, estradiol, cortisol, TSH, fasting glucose, and sodium.

Site, analytics, and advertising information

Pages viewed, referral URLs, UTM parameters, approximate device and browser details, ad click identifiers, and limited event data such as product views, cart actions, checkout starts, newsletter clicks, and protocol funnel progress.

The protocol experience validates adults ages 18 to 100. Do not submit information about children or other people unless you have authority to do so.

Consumer Health Data

Some information you provide may be consumer health data or sensitive personal information, including goals, symptoms, conditions, family history, medications, allergies, biological sex, health ratings, lab files, extracted markers, manual lab entries, and health inferences generated by the protocol engine.

We collect this information from you, your device, uploaded files, manual entries, and inferences generated from those inputs. We use it to provide the protocol service you request, extract lab markers, personalize recommendations, show cautions, protect the service, and comply with law. We do not sell consumer health data and do not use it for targeted advertising.

We share consumer health data only as needed with the service providers described below, including the configured AI provider, hosting and security vendors, and commerce providers when necessary to provide a requested product or service. We do not intentionally collect health information from wearable devices or medical portals.

How We Use Information

  • Build, score, and display a personalized supplement protocol.
  • Extract structured biomarker values from optional lab uploads when you consent to AI processing.
  • Create Shopify carts, support checkout, fulfill orders, and provide customer support.
  • Send newsletters or marketing messages when you sign up or otherwise consent.
  • Measure site usage, ad performance, checkout intent, and funnel drop-off without sending protocol answers, lab values, or uploaded files to advertising tools.
  • Protect the service, prevent abuse, rate-limit high-cost AI routes, debug errors, and enforce our policies.
  • Comply with legal obligations, tax and accounting rules, security requirements, and lawful requests.

AI Processing

When configured, BioStack sends selected questionnaire summaries, normalized lab observations, and product-catalog context to an AI provider to draft protocol narratives and caution language. When you upload optional bloodwork and check the AI consent box, uploaded files are sent to the configured AI provider to extract structured markers. Uploaded lab files are not intentionally stored by this app after extraction, though AI providers, hosting providers, and security systems may process or retain data according to their own policies, contracts, and technical settings.

If you do not want lab files processed by an AI provider, do not upload them. If you do not want questionnaire or health profile information processed to generate a personalized protocol, do not submit the protocol quiz.

When We Share Information

AI providers

OpenAI, Anthropic, or Google may process questionnaire summaries, lab observations, or uploaded lab files depending on the configured provider. We use them to generate protocol narratives and extract markers, not to sell health data.

Shopify and commerce providers

Shopify receives cart, checkout, order, customer, and marketing-consent information needed to operate the store. Payment details are handled by Shopify and its payment processors, not by BioStack's protocol UI.

Analytics and advertising providers

Vercel Web Analytics and Meta Business Tools may receive page views, referrers, UTM parameters, device/browser details, ad click identifiers, and limited commerce or funnel events. We do not send protocol answers, lab values, conditions, medications, allergies, uploaded files, or extracted biomarkers to advertising tools.

Legal, safety, and business transfers

We may disclose information to comply with law, respond to lawful requests, protect rights and safety, investigate misuse, or as part of a merger, financing, acquisition, or sale of assets.

Retention

We keep personal information only as long as reasonably needed for the purposes described in this policy, unless a longer period is required or permitted by law. Protocol inputs and lab uploads are not stored in a user account by the current BioStack app. Bloodwork file bytes are processed for extraction and are not intentionally retained by this app after the request completes. Shopify, Typeform, AI providers, hosting providers, and payment providers may retain records under their own schedules.

Order, tax, accounting, legal, fraud-prevention, support, and security records may be retained for longer periods where needed to operate the business, resolve disputes, comply with law, or protect the service.

Your Choices and Rights

You can choose not to provide optional information, skip bloodwork, remove uploaded file names or extracted markers before continuing, unsubscribe from marketing emails, decline cookies in your browser, or stop using the protocol quiz before submission.

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, withdrawal of consent, or information about our collection, use, disclosure, or sharing of your personal information or consumer health data. You may also have the right not to be discriminated against for exercising privacy rights.

To make a privacy request, contact privacy@ascendbiostack.com. We may need to verify your request before acting on it. If your request relates to Shopify checkout, payments, order history, or Typeform newsletter submissions, we may direct or relay your request to the relevant provider.

Security

We use administrative, technical, and organizational safeguards designed for the sensitivity of the information, including request size limits, file-type checks for lab uploads, schema validation, rate limiting, signed protocol tokens, limited checkout data transfer, and HTTPS in production. No system is perfectly secure, and we cannot guarantee absolute security.

If we discover a breach involving personal information or consumer health data, we will evaluate and provide notices required by applicable law.

Children

BioStack is intended for adults. The protocol flow requires an age between 18 and 100. We do not knowingly collect personal information from children.

International Transfers

We and our providers may process information in the United States, Canada, and other countries where our vendors operate. These countries may have privacy laws that differ from those where you live.

Changes to This Policy

We may update this Privacy Policy as the service, vendors, laws, or business practices change. The effective date above shows when this version took effect. Material changes will be posted in the app or otherwise communicated as required by law.

Contact

For privacy questions, requests, or complaints, contact privacy@ascendbiostack.com.