Ponce Core Tech · Bimini

Privacy Policy

Effective 4 August 2026 · Bimini is currently in limited, invitation-only beta.

This policy explains what Bimini collects, what we do with it, and who else sees it. Bimini is operated by Ponce Core Tech, LLC ("we", "us"). It covers the Bimini web application, the Bimini mobile app, and poncecore.tech.

Bimini handles health information, so we have tried to write this plainly rather than defensively. Where something is a limitation, we say so.

The three things most worth knowing. Your data is sent to a third-party AI provider (Anthropic) in order to generate the explanations Bimini exists to give you. We reduce identifying details before it is sent, but cannot guarantee removal of every one. And Bimini is an early beta — do not rely on it as your only copy of anything.

1. Who you are to us

Your account is a number. We do not ask for your name, your email address, your date of birth, or any other identifying detail in order to create an account. We do not require or use third-party login.

If you contact us for support, we will have whatever you put in that message, including your email address.

2. What we collect

Only what you give us, or what you explicitly connect. Specifically:

Health data you sync

Documents you upload

Information you enter

Genetic data, if you provide it

Data from services you connect

What we do not collect

3. What we do with it

We use your data to build your organized health picture, to show it back to you, to let Ponce answer your questions about it, and to generate summaries you can take to your physician. That is the entire purpose.

Plainly

We do not sell your data. We do not share it with advertisers, data brokers, insurers, or employers. Bimini is deliberately commerce-blind: Ponce recommends categories of intervention and evidence grades, never a specific brand or a commercial partner, and no one pays for placement.

4. The AI provider — the most important disclosure here

Bimini's explanations are generated by a large language model operated by Anthropic. To answer your question, relevant parts of your health data — metrics, and passages from your documents selected as relevant — are transmitted to Anthropic's API for processing. This is not optional; it is how the product works.

Before that text is sent, we automatically remove direct identifiers. It works in three layers: pattern matching that removes email addresses, phone numbers, Social Security numbers, labeled record and account numbers, and labeled dates of birth; a locally-run language model that flags names and addresses appearing without a label; and exact removal of any names you have configured in your privacy settings.

Honest limitation. Removing identifiers reduces identifying information. It does not guarantee removal, and the information may remain re-identifiable — it should be treated as sensitive health information. An unusual document layout, an unlabeled identifier, or a name we have not seen may pass through. Clinical values themselves — your lab results, your metrics — are deliberately not removed, because they are what the model needs in order to be useful. You should assume that meaningful health information about you is processed by Anthropic, and decide what to upload on that basis.

You can strengthen this yourself: the Documents area lets you list names to be removed from anything sent to the model.

5. Connected services (Ōura and similar)

If you choose to connect a third-party service, you will be sent to that provider to log in. Bimini never sees your password for that service. The provider gives us an access token instead.

Two consequences worth understanding:

We request the narrowest set of permissions the feature needs. What the provider does with your data is governed by that provider's own privacy policy, not this one.

6. How it is stored and protected

One exception you should know about. To find the passages relevant to your question, Bimini keeps a search index of your document text. That index has the identifier removal described in section 4 applied to it, but it is stored unencrypted on the server, separate from the encrypted originals. It is deleted when you delete the underlying documents. We are telling you this because it is the weakest point in the storage design and you deserve to know it rather than discover it.

During the beta, Bimini runs on infrastructure operated directly by Ponce Core Tech. Production hosting is planned to move to a major cloud provider.

7. Your choices

Depending on where you live you may have additional rights — to access, correct, delete, or restrict processing of your data, and to withdraw consent. Write to us and we will honor them.

8. Legal status of your data

Bimini is not a HIPAA-covered entity. HIPAA governs healthcare providers, health plans and their business associates. It generally does not apply to a consumer app you voluntarily give your own data to. Health information you put into Bimini therefore does not carry HIPAA protection. Other consumer health-privacy laws may apply to us, and where they do, we intend to comply.

Bimini is not a medical device. It does not diagnose, treat, or prescribe, and it is not medical advice. Bimini advises; your physician treats.

9. Children

Bimini is for adults. You must be 18 or older. We do not knowingly collect information from anyone under 18; if we learn we have, we will delete it.

10. Data retention

We keep your data for as long as your account exists. When you delete something, we delete it. Encrypted backups may persist for a short period before rotating out.

Text already transmitted to Anthropic is subject to Anthropic's own retention practices and cannot be recalled by us.

11. Breach notification

If we discover a breach affecting your health information, we will notify you — and any regulator we are required to notify — without undue delay, and tell you what was affected.

12. Changes

If we change this policy in a way that materially affects how your data is used, we will notify you in the app before the change takes effect. The effective date at the top always reflects the current version.

13. Contact

Questions, requests, or complaints: chip@poncecore.tech

Ponce Core Tech, LLC