1. Introduction
Skye Collective LLC ("we," "us," or "our") operates the Bio-Tuning web application at mybiotuning.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the Service.
We are committed to protecting your privacy in compliance with applicable data protection laws, including:
- The General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA) and United Kingdom
- The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) for California residents
- The CAN-SPAM Act for commercial email communications
- The Canadian Anti-Spam Legislation (CASL) for users in Canada
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.
2. Personal Data We Collect
We collect the following categories of personal data:
Information You Provide Directly
- Account information: name, email address, phone number, city, and state
- Profile data: profile picture, practitioner credentials, and business information
- Payment information: processed securely by our payment processor (we do not store card numbers)
- Communications: messages sent to us via email or in-app support
- Assessment responses: results from in-app assessments such as the Brain Dominance Thinking Style test
Information Generated Through the Service
- Frequency and health data: your Fundamental Frequency and Heart Rate Variability (HRV) measurements as determined by your Bio-Tuning practitioner
- Listening data: session timestamps, durations, track completion status, listening streaks, and playback activity
- Progress data: program completion, level advancement, and experience points
- Practitioner-client relationship data: session notes, track orders, and credit transactions
Information Collected Automatically
- Device and browser information: browser type, operating system, device type
- Usage data: pages visited, features used, and interaction patterns
- IP address and approximate geographic location
- Cookies and similar tracking technologies (see Section 8)
- Log data: access times, error logs, and referring URLs
3. How We Use Your Data
We use the personal data we collect for the following purposes:
Service Delivery
- To create and manage your account
- To deliver personalized brainwave entrainment audio tracks based on your frequency data
- To track and display your listening progress and program completion
- To facilitate the practitioner-client relationship and shared data access
- To process payments and manage credit balances
Analytics and Improvement
- To provide analytics and insights to practitioners about client engagement
- To improve and maintain the Service through aggregated usage analytics
- To detect, prevent, and address technical issues and security threats
Communications
- To send transactional notifications about track orders and account activity
- To send service updates and important announcements
- To respond to customer support requests
- To send marketing communications (only with your explicit consent; see Section 9)
GDPR Legal Basis for Processing (EEA/UK Users)
Under the GDPR, we process your personal data based on the following legal grounds:
- Contract performance: Processing necessary to provide the Service you have requested (account management, audio delivery, progress tracking)
- Legitimate interests: Analytics, service improvement, fraud prevention, and security, where these interests are not overridden by your rights
- Consent: Marketing communications, non-essential cookies, and optional data sharing
- Legal obligation: Where required to comply with applicable laws, such as tax and financial reporting
4. Third-Party Service Providers
We share personal data with the following third-party service providers who process data on our behalf. Each provider is contractually bound to process data only for the purposes we specify and in accordance with applicable data protection laws.
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Name, email, payment method details |
| Brevo | Transactional and marketing email delivery | Name, email address |
| Cloudflare R2 | Secure storage of audio files and uploaded images | Uploaded files and associated metadata |
| Google Maps | Practitioner finder and map features | Search location data entered by users |
| Neon | Database hosting | All application data (encrypted at rest) |
| Render.com | Application hosting and deployment | Server logs, request data |
| Atlas Analytics | Usage analytics and engagement insights (optional) | Page views, feature interactions, anonymous session data |
| Cookie Consent | Cookie consent management (self-hosted) | Cookie preferences stored locally on your device |
We do not sell your personal information to third parties. We do not share your data with third parties for their own marketing purposes.
5. International Data Transfers
Our Service is hosted in the United States. If you are accessing the Service from outside the United States, please be aware that your personal data will be transferred to, stored, and processed in the United States.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:
- Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses in our agreements with service providers that process EEA/UK personal data
- EU-US Data Privacy Framework: Where applicable, we work with service providers who have certified under the EU-US Data Privacy Framework
You may request a copy of the applicable transfer safeguards by contacting us at the address listed in Section 14.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law. Below are our standard retention periods:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion request |
| Listening and progress data | Duration of account + 30 days after deletion request |
| Frequency and health data | Duration of account + 30 days after deletion request |
| Purchased audio tracks | Remain available to download for as long as you have an account |
| Practitioner high-resolution WAV masters | 90 days after creation |
| Payment and transaction records | 7 years (legal/tax requirements) |
| In-app notifications | 90 days, then automatically deleted |
| Server and access logs | 12 months |
| Cookie consent records | 12 months |
| Aggregated analytics (anonymized) | Indefinite (cannot identify individuals) |
7. Your Rights
GDPR Rights (EEA/UK Residents)
If you are located in the European Economic Area or United Kingdom, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent
- Right to lodge a complaint: File a complaint with your local data protection supervisory authority
CCPA/CPRA Rights (California Residents)
If you are a California resident, you have the following rights under the CCPA/CPRA:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to delete: Request deletion of your personal information
- Right to correct: Request correction of inaccurate personal information
- Right to opt out: Opt out of the sale or sharing of your personal information (see our Do Not Sell page)
- Right to non-discrimination: We will not discriminate against you for exercising your rights
- Right to limit use of sensitive personal information: Direct us to limit the use and disclosure of sensitive personal information
CASL Rights (Canadian Residents)
Under the Canadian Anti-Spam Legislation, we obtain your express consent before sending you commercial electronic messages. You may withdraw consent at any time by using the unsubscribe link in our emails or by contacting us directly.
How to Exercise Your Rights
To exercise any of your rights, you may:
- Email us at support@skyecollective.com
- Write to us at: Skye Collective LLC, Attn: Privacy, 5671 Palmer Way, Suite G, Carlsbad, CA 92010
- Use the in-app Settings page to manage your account and preferences
We will respond to verifiable requests within 30 days (GDPR) or 45 days (CCPA/CPRA). We may ask you to verify your identity before processing your request.
8. Cookie Policy
We use cookies and similar technologies to operate the Service, remember your preferences, and analyze usage patterns. Our cookie consent manager allows you to control which types of cookies are active on your device.
We use the following categories of cookies:
- Strictly necessary cookies: Required for the Service to function (authentication, session security, consent preferences). These cannot be disabled.
- Analytics cookies: When enabled, help us understand how users interact with the Service. Data is aggregated and anonymous.
You can manage your cookie preferences at any time by clicking "Cookie Settings" in the footer of our website, or by visiting our Cookie Policy page for a full declaration of all cookies used.
We do not use third-party advertising cookies or cookies that track your activity across other websites.
9. Email Communications
We comply with the CAN-SPAM Act, CASL, and applicable email marketing regulations. Our email practices include:
- We will not send you commercial emails without your opt-in consent
- Every marketing email includes a clear, functional unsubscribe link
- We honor unsubscribe requests within 10 business days
- We include our physical mailing address in all commercial emails
- We do not use deceptive subject lines or misleading header information
Transactional emails (e.g., track order confirmations, account security notifications) are not considered marketing communications and may be sent without separate consent, as they are necessary for the operation of the Service.
You can manage your email notification preferences in the Settings page within the application.
10. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from:
- Children under 13: In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect, use, or disclose personal information from children under 13.
- Children under 16: In compliance with the GDPR, we do not process personal data of children under 16 without verifiable parental consent in jurisdictions where this applies.
If we become aware that we have collected personal data from a child without proper consent, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@skyecollective.com.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS/TLS encryption for all data in transit
- Encryption at rest for stored data
- Secure password hashing using industry-standard algorithms
- Role-based access controls limiting data access to authorized personnel
- Regular security reviews of our infrastructure and codebase
- Automatic session management and authentication safeguards
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but will promptly notify affected users and relevant authorities of any data breach in accordance with applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify registered users via in-app notification and/or email
- Where required by law, obtain your consent to material changes
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes are posted constitutes your acknowledgment of the updated terms.
13. SMS and Mobile Information
When you provide your mobile phone number, Skye Collective LLC (Bio-Tuning) may use it to communicate with you regarding your inquiries, requested information, appointments, products or services, customer support, or other communications that you have requested or consented to receive.
We obtain consent for SMS communications separately where required, through a distinct, optional checkbox presented alongside our forms. Providing a telephone number does not by itself constitute consent to receive text messages. Your SMS consent status is recorded separately from your other form information, together with the date, the form on which consent was given, and the version of the disclosure shown to you.
We do not sell, rent, or share mobile contact information with third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with third parties for marketing or promotional purposes. This applies notwithstanding any other provision of this policy: the disclosures to service providers described in Section 4 are limited, for mobile and SMS opt-in information, to providers that assist us in operating our communications and customer-service systems, solely as necessary to provide those services on our behalf.
You may opt out of SMS messages at any time by replying STOP to any message. You may reply HELP for assistance. Message and data rates may apply, and message frequency varies. See also the SMS Terms & Conditions in our Terms of Service.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For GDPR-related inquiries, you may also contact your local data protection supervisory authority.