Privacy Policy

Last updated: December 7, 2025

1. Overview

BioQuery™ ("we", "our", or "the Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our service at www.bioquery.io.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address: Required for account creation and communication
  • Name: If provided via Google OAuth
  • Profile picture: If provided via Google OAuth

2.2 Usage Data

We automatically collect:

  • Query history: The natural language queries you submit
  • Query Cards viewed: Which cards you access
  • Feature usage: Downloads, exports, customizations
  • Technical data: IP address, browser type, device information

2.3 What We Do NOT Collect

Important: BioQuery™ queries publicly available, de-identified research datasets. We do not collect, store, or process any:

  • Personal health information (PHI)
  • Individually identifiable genetic data
  • Patient records or clinical data

The TCGA and GTEx datasets we query contain only de-identified, aggregated research data that has been approved for public access by the NIH.

3. How We Use Your Information

We use collected information to:

  • Provide and improve the Service
  • Authenticate your account
  • Enforce rate limits and prevent abuse
  • Send service-related communications (account verification, security alerts)
  • Analyze usage patterns to improve features
  • Generate aggregate statistics (e.g., most common query types)

4. Information Sharing

We do NOT sell your personal information. We may share data with:

4.1 Service Providers

  • Supabase: Database and authentication (stores account data)
  • Google Cloud: Hosting and BigQuery (processes queries)
  • Anthropic: AI processing (receives query text for parsing)

4.2 Legal Requirements

We may disclose information if required by law or to protect our rights.

4.3 Public Query Cards

Query Cards are public by default and accessible via permalink. Your queries may be visible to others who access the card URL. We do not display your name or email on public cards unless you choose to share them.

5. Data Retention

Data TypeRetention Period
Account informationUntil account deletion
Query historyUntil account deletion
Query CardsIndefinitely (public archive)
Server logs90 days

6. Your Rights

You have the right to:

  • Access: Request a copy of your data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion
  • Export: Download your query history
  • Opt-out: Unsubscribe from non-essential communications

To exercise these rights, contact us at privacy@bioquery.io.

7. Data Security

We implement industry-standard security measures including:

  • HTTPS encryption for all data transmission
  • Encrypted database storage
  • OAuth 2.0 for authentication
  • Regular security audits
  • Access controls and audit logging

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. Cookies and Tracking

We use:

  • Essential cookies: Required for authentication and session management
  • Analytics: Anonymous usage statistics to improve the Service

We do NOT use third-party advertising cookies or sell data to advertisers.

9. International Users

BioQuery™ is operated from the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US, which may have different data protection laws than your country.

9.1 GDPR (European Users)

If you are in the EU/EEA, you have additional rights under GDPR including:

  • Right to data portability
  • Right to restrict processing
  • Right to object to processing
  • Right to lodge a complaint with a supervisory authority

Our legal basis for processing is:

  • Contract: To provide the Service you requested
  • Legitimate interest: To improve and secure the Service
  • Consent: For optional communications

10. Children's Privacy

BioQuery™ is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify registered users of material changes via email. Continued use of the Service after changes constitutes acceptance.

12. Contact Us

For privacy-related questions or requests:


BioQuery™ is a trademark of BioQuery. All rights reserved.