Pre-launch draft pending lawyer review. Final binding text will replace this page before any paid customer is onboarded.

Privacy Policy

Effective date: August 7, 2026 Owner: Bolthouse Labs, Inc.

This Privacy Policy explains what personal information Bolthouse Labs, Inc. (“Bolthouse Labs,” “we,” “us”) collects when you visit https://mybodyprism.com, purchase a license, or use the MyBodyPrism Desktop Viewer (the “Service”), and what we do with that information.

1. Summary

2. Information we collect

2.1 Information you would give us if you purchase a paid feature (future)

The Service is free in this version. If we introduce paid features in the future and you purchase one, our payment processor (Stripe, Inc.) would collect:

We would receive from Stripe a customer ID and the metadata needed to maintain your purchase (email, plan, purchase date, status). Card information remains in Stripe’s PCI-DSS-compliant environment.

2.2 Information you give us when you download the free Software

To download the free Desktop Viewer from our website, we ask for your email address. We use it to:

We do not sell this list, share it with third parties for their marketing, or send unrelated marketing. You may ask us to delete your email at any time by writing to support@mybodyprism.com, and any email we send includes a way to opt out of further messages.

Separately, if you provide an email address inside the Viewer when requesting a free license, it is used for occasional service emails as described in §4.1.

2.3 Information generated by your use of the Desktop Viewer

The Desktop Viewer is software you install on your own computer. It generates the following data on your device, which is never transmitted to us:

DataWhere it’s stored on your device
Your imaging volumes (your scans)The folder you opened
DICOM metadata tagsSame folder
ROI mask sidecars<case folder>/.somaviz_roi_masks.json
Per-series view defaults<case folder>/mybodyprism_overrides.json
Recent folders listWindows registry: HKCU\Software\MyBodyPrism\
Comparison FavoritesSame registry key
Application logs%APPDATA%\MyBodyPrism\logs\
Crash archive (PHI-scrubbed)%APPDATA%\MyBodyPrism\crashes\

Application logs intentionally do not include patient names or identifiers; only basenames and module names. The crash archive is PHI-scrubbed before it is written.

You can wipe all local Service state by deleting the following. Your source imaging files in their case folders are not touched by any of this.

LocationWhat it holds
%APPDATA%\MyBodyPrism\Application logs and PHI-scrubbed crash archives
%APPDATA%\SomaViz\Your licence file
HKCU\Software\MyBodyPrism\ (registry)Your preferences, and the record that you accepted the End User Licence Agreement

The second folder is named SomaViz for historical reasons — it is part of this application.

After erasing these, the next launch behaves like a first launch: the application will ask you to accept the End User Licence Agreement again, and will request a replacement licence for this computer. Because licences are issued per computer, the licence server returns the one already associated with your machine rather than refusing — so erasing your local data does not cost you access, provided the computer can reach the internet on that next launch.

2.4 Information you provide if you contact support

If you email support@mybodyprism.com, we retain your message and our response in our email system to provide continuing support and to improve the Service.

2.5 Information from our marketing site

The marketing site collects:

The site uses no analytics cookies, no advertising cookies, no session replay, no third-party tracking pixels.

3. How we use your information

PurposeInformation used
Provide and operate the ServiceCustomer ID, email, license type, machine-ID hash (Desktop activation)
Send service emails (download links, service updates, and — for any future paid features — purchase receipts)Email
Follow up on free downloads and announce future paid availabilityEmail (free-download leads, §2.2)
Process payments and license purchasesStripe customer ID (Stripe handles card data)
Provide customer supportEmail, support tickets
Detect and prevent abuseServer logs, session metadata, rate-limit counters
Comply with legal obligationsWhatever is required by valid legal process
Investigate security incidentsAll of the above, scoped to the incident

We do not:

4. Network transmissions from the Desktop Viewer

The Desktop Viewer’s only outbound network calls are to activate and verify your license. Those calls never include your imaging.

4.1 License activation (our License API)

To issue or activate your license, the Viewer contacts the MyBodyPrism License API (api.mybodyprism.com) over HTTPS and sends:

It does not send any imaging, imaging-derived data, DICOM tag values, file paths, your name, or date of birth. The API returns your signed license file, which is then verified offline on your device.

4.2 Crash reporting — local only

If the Viewer crashes, a PHI-scrubbed crash detail is written locally to %APPDATA%\MyBodyPrism\crashes\. Nothing is transmitted to us automatically. If you ask us for help with a crash, you may choose to email us that file.

4.3 No other outbound paths

There are no update checks, no telemetry, no analytics, and no feature-usage tracking.

5. Third-party service providers

We use the following third-party service providers in the operation of the Service:

ProviderPurposeData shared
Stripe, Inc.Payment processing and license-purchase managementName, email, billing address, card data (handled by Stripe)
Amazon Web Services, Inc.Cloud hosting (website, license API, installer downloads)Billing + license metadata only — no medical imaging flows to our cloud
Sectigo Limited / The SSL StoreCode-signing certificateBolthouse Labs corporate identity only (no customer data)
GoDaddy / Microsoft 365 / Route 53 / etc.DNS, email infrastructureEmail-routing only

We do not share your information with any third party other than as described above. We do not allow any of these providers to use your information for purposes outside the scope of providing the contracted service.

6. Data retention

CategoryRetention
Stripe customer + purchase record (only if you purchase a future paid feature)As long as the purchase is active, plus 7 years for tax / accounting records
Service-side license records (machine ID hash, activation codes)As long as your license is active, plus 90 days
Free license records (machine-ID hash)For the life of the free program, to enforce the one-free-license-per-machine limit
Free-download leads (email address, §2.2)Until you ask us to delete it, or 24 months after your last interaction with us, whichever comes first
Marketing site server logs30 days
Support email history3 years from last contact
Imaging data (Desktop)Not retained by us at any time
Crash reportsLocal only (PHI-scrubbed, on your device; not transmitted)

7. Security

We protect your information using industry-standard practices:

We engage in periodic security reviews and welcome responsible disclosure of security vulnerabilities at support@mybodyprism.com with “Security:” in the subject line.

8. Your rights

8.1 Universal rights

Regardless of where you live, you may:

To exercise any of these rights, email support@mybodyprism.com. We will respond within 30 days.

8.2 California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended:

To exercise CCPA rights, email support@mybodyprism.com with “CCPA request” in the subject line.

8.3 European Economic Area, UK, Switzerland (GDPR / UK-GDPR / DSG)

If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation:

Our lawful basis for processing your personal information is performance of a contract (providing the free Service, or a future paid feature you purchase) and legitimate interests (operating the Service, following up on free downloads, preventing abuse, securing data). We do not rely on consent for any current processing; any future opt-in feature would rely on your consent.

To exercise GDPR rights, email support@mybodyprism.com with “GDPR request” in the subject line.

8.4 International transfers

The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. We rely on Standard Contractual Clauses with our processors (Stripe, AWS) for any cross-border transfers of personal information from the EEA, UK, or Switzerland.

9. Children’s privacy

The Service is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 13 (under 16 in the EEA/UK). If you believe we have inadvertently collected such information, please contact support@mybodyprism.com and we will delete it.

Pediatric imaging may be opened in the Service by a parent or legal guardian; the personal information collected in connection with the parent’s license belongs to the parent, not the child whose imaging is being viewed.

10. Data Processing Agreement (DPA)

For EU/UK customers who require a Data Processing Agreement under GDPR Art. 28, contact support@mybodyprism.com with “DPA request” in the subject line.

11. Changes to this Policy

We may update this Policy from time to time. The effective date above will reflect the most recent revision. Material changes will be communicated by email to registered users (users who have provided an email address) and posted at https://mybodyprism.com/legal/privacy at least 30 days before they take effect.

12. Contact

Bolthouse Labs, Inc. c/o Legalinc Corporate Services Inc. 131 Continental Dr, Suite 305 Newark, DE 19713 United States

Email: support@mybodyprism.com

For privacy-specific inquiries: include “Privacy” in the subject line.