Privacy Policy
How we collect, use, store, and protect your personal data.
Last updated July 21, 2026
Introduction
Beneat is committed to protecting your privacy. This policy explains how we collect, use, disclose, retain, and safeguard your information when you use the Beneat platform, website, APIs, MCP server, and related services.
By using the Service, you consent to these practices. If you do not agree, please do not use the Service.
Information We Collect
Information you provide:
- Account registration (email, username, profile)
- Wallet addresses you connect
- Agent configurations and trading parameters
- Communications with us (support, feedback)
Collected automatically:
- Device information (browser, OS, identifiers)
- Log data (IP, access times, pages viewed)
- Usage analytics (feature usage, session duration)
- Cookies and similar technologies
On-chain data: We index publicly available blockchain data. This is not considered private information.
Third-Party Integration Data
When you connect a third-party service, Beneat receives only the information needed for the features you enable:
- Wearable platforms — WHOOP, Suunto, and Fitbit through the Google Health API: health and fitness data for BioSync
- Exchange APIs — trade history, portfolio, balances
- Blockchain services — transaction data and account states
Google Health API / Fitbit data we read:
- Health measurements — daily heart-rate variability (RMSSD), daily resting heart rate, daily oxygen saturation, nightly skin temperature, and daily respiratory rate
- Sleep — sleep-session timing, minutes asleep, minutes in the sleep period, derived sleep efficiency, and deep, light, and REM stage duration
- Activity — daily total calories burned
- Profile — the Google Health API user identifier, age, membership start date, and configured or automatically calculated walking and running stride lengths, where available
Access is opt-in and read-only. Beneat does not request permission to add, change, or delete data in Google Health. We collect data only after you connect Fitbit and authorize the requested Google Health permissions.
How We Use Information
- Service delivery — operating and improving the platform
- Analytics — performance metrics, risk scores, rankings
- Personalization — tailoring features and recommendations
- BioSync — displaying your wearable measurements, creating daily readiness check-ins, and helping you compare your own readiness with your trading performance
- Communication — support and service notifications
- Security — detecting fraud and threats
- Legal compliance — fulfilling obligations
How readiness is calculated: Beneat normalizes wearable measurements to a 0–100 scale. Because Google Health does not provide a native recovery score, Beneat derives a recovery proxy from normalized HRV and sleep duration: 60% HRV and 40% sleep when both are available, or the available measurement when only one is present.
The provider-normalized readiness score is a weighted average of recovery (35%), HRV (20%), sleep duration (20%), sleep quality (10%), a recovery-based stress proxy (10%), and activity when available (5%). Missing inputs are omitted and the remaining weights are proportionally rebalanced; activity alone cannot produce a readiness score.
A daily terminal readiness check-in combines sleep duration (20%), sleep quality (15%), HRV (15%), stress (10%), recovery (5%), circadian alignment (5%), and an optional cognitive primer (30%). Missing wearable dimensions may use a neutral default. If you skip the cognitive primer, its weight is redistributed across the other dimensions. The result is rounded and limited to 0–100. Readiness is a wellness and decision-support estimate, not a medical diagnosis or medical advice.
Data Sharing and Google Health Limited Use
We do not sell your personal data. We may share personal data only in limited circumstances:
- Service providers — trusted processors bound by confidentiality and used only to operate the features you request
- Legal requirements — when required by applicable law or regulation
- Security — when necessary to investigate abuse or protect users and the Service
- Business transfers — Google Health data is transferred as part of a merger, acquisition, or asset sale only with your explicit prior consent
- Internal operations — aggregated and anonymized information may be used internally to operate and improve BioSync
Google Health API data, including raw, derived, aggregated, and anonymized data, is not sold or rented; transferred to advertising platforms, data brokers, or information resellers; used to serve contextual, personalized, or interest-based advertising; or used to determine creditworthiness or eligibility for lending. It is not displayed publicly or shared with other Beneat users.
Beneat uses Google Health data only to provide or improve the user-facing BioSync features described above. The use of information received from the Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements.
Leaderboard data and on-chain activity are displayed publicly by design; Google Health API data is not part of those public surfaces.
Data Storage and Retention
- Account data — retained while active and deleted within 30 days after account deletion
- Usage logs — retained for up to 12 months
- Google authorization tokens — encrypted with authenticated AES-256-GCM and stored server-side in access-restricted persistent storage, retained only while Fitbit is connected, and deleted when you disconnect
- Google Health measurements — processed server-side and may be temporarily cached to provide live BioSync views
- Readiness records — normalized measurements and derived daily readiness scores may be stored with your Beneat account
- Biometric and derived data — deleted from active production systems within 30 days after disconnection, account deletion, or a verified deletion request, unless retention is required by law
- Aggregated analytics — anonymized information may be retained for internal service operations but is never sold or used for advertising
- On-chain data — retained as long as it remains publicly available on-chain
Your Rights and Google Health Controls
Depending on jurisdiction, you may have rights to:
- Access — request a copy of your data
- Correction — correct inaccurate data
- Deletion — request deletion, subject to legal requirements
- Portability — receive data in a machine-readable format
- Objection — object to specific processing
- Withdrawal — withdraw consent at any time
To stop Google Health collection, open Beneat Terminal, go to Settings → Wearables → Fitbit, and select Disconnect. This deletes Beneat's stored Google authorization token and stops future collection. You can also revoke Beneat directly from your Google Account connections.
Disconnecting stops future access but does not by itself immediately erase readiness records already stored with your Beneat account. To delete those records or all Google Health-derived data, email info@beneat.ai. We verify the request and complete deletion from active production systems within 30 days. You may use the same address to exercise any privacy right; we respond within 30 days.
Data Security
- Encryption — TLS 1.3 in transit, AES-256 at rest
- Access controls — authentication for internal systems
- Monitoring — regular security assessments
- Secure development — code review and auditing
- Incident response — procedures for breaches
No method is 100% secure. We encourage strong passwords and key protection.
Cookies
We use cookies for:
- Essential — authentication and preferences
- Analytics — understanding usage patterns
We do not use advertising or tracking cookies. Control via browser preferences.
International Transfers
Data may be processed in countries other than your residence. We ensure appropriate safeguards for international transfers.
Children's Privacy
The Service is not for individuals under 18. We do not knowingly collect data from children. If discovered, we delete it promptly.
Changes to Policy
We may update this policy. Material changes will be posted here with a revised date. Review periodically.
Contact
Privacy questions or data requests: info@beneat.ai