Pre-launch draft pending lawyer review. Final binding text will replace this page before any paid customer is onboarded.
Privacy Policy
Effective date: August 7, 2026 Owner: Bolthouse Labs, Inc.
This Privacy Policy explains what personal information Bolthouse Labs, Inc. (“Bolthouse Labs,” “we,” “us”) collects when you visit https://mybodyprism.com, purchase a license, or use the MyBodyPrism Desktop Viewer (the “Service”), and what we do with that information.
1. Summary
- This version of the Desktop Viewer stores and processes your medical imaging on your device. It does not upload, sync, or back up your imaging, and no feature of this version transmits your scans off your device.
- Crash reporting is local only. PHI-scrubbed crash details are written to a folder on your own computer; nothing is sent to us automatically.
- The only network calls the Viewer makes are to activate your free license (see §4) — these send a hashed machine ID and your license details, never your imaging.
- We collect your email address when you download the free Software from our website, so we can follow up about your experience and tell you about updates and any future paid features. See §2.2.
- We don’t sell your data. Ever.
- No tracking pixels, no behavioral advertising. The marketing site uses essential cookies only.
2. Information we collect
2.1 Information you would give us if you purchase a paid feature (future)
The Service is free in this version. If we introduce paid features in the future and you purchase one, our payment processor (Stripe, Inc.) would collect:
- Name
- Email address
- Billing address
- Payment card information (handled directly by Stripe; we never see, store, or transmit your card number, CVV, or expiration)
- The paid feature you purchased
We would receive from Stripe a customer ID and the metadata needed to maintain your purchase (email, plan, purchase date, status). Card information remains in Stripe’s PCI-DSS-compliant environment.
2.2 Information you give us when you download the free Software
To download the free Desktop Viewer from our website, we ask for your email address. We use it to:
- Send you occasional service emails about the Software (for example, important updates).
- Follow up with you personally about your experience.
- Notify you when new features and any future paid options become available.
We do not sell this list, share it with third parties for their marketing, or send unrelated marketing. You may ask us to delete your email at any time by writing to support@mybodyprism.com, and any email we send includes a way to opt out of further messages.
Separately, if you provide an email address inside the Viewer when requesting a free license, it is used for occasional service emails as described in §4.1.
2.3 Information generated by your use of the Desktop Viewer
The Desktop Viewer is software you install on your own computer. It generates the following data on your device, which is never transmitted to us:
| Data | Where it’s stored on your device |
|---|---|
| Your imaging volumes (your scans) | The folder you opened |
| DICOM metadata tags | Same folder |
| ROI mask sidecars | <case folder>/.somaviz_roi_masks.json |
| Per-series view defaults | <case folder>/mybodyprism_overrides.json |
| Recent folders list | Windows registry: HKCU\Software\MyBodyPrism\ |
| Comparison Favorites | Same registry key |
| Application logs | %APPDATA%\MyBodyPrism\logs\ |
| Crash archive (PHI-scrubbed) | %APPDATA%\MyBodyPrism\crashes\ |
Application logs intentionally do not include patient names or identifiers; only basenames and module names. The crash archive is PHI-scrubbed before it is written.
You can wipe all local Service state by deleting the following. Your source imaging files in their case folders are not touched by any of this.
| Location | What it holds |
|---|---|
%APPDATA%\MyBodyPrism\ | Application logs and PHI-scrubbed crash archives |
%APPDATA%\SomaViz\ | Your licence file |
HKCU\Software\MyBodyPrism\ (registry) | Your preferences, and the record that you accepted the End User Licence Agreement |
The second folder is named SomaViz for historical reasons — it is
part of this application.
After erasing these, the next launch behaves like a first launch: the application will ask you to accept the End User Licence Agreement again, and will request a replacement licence for this computer. Because licences are issued per computer, the licence server returns the one already associated with your machine rather than refusing — so erasing your local data does not cost you access, provided the computer can reach the internet on that next launch.
2.4 Information you provide if you contact support
If you email support@mybodyprism.com, we retain your message and our response in our email system to provide continuing support and to improve the Service.
2.5 Information from our marketing site
The marketing site collects:
- Server access logs (IP address, user agent, requested URL, timestamp) — retained 30 days for security and abuse-prevention.
- Your email address when you request the free download (see §2.2).
- Essential cookies needed to maintain a checkout session (Stripe-managed) and to remember acceptance of legal documents.
The site uses no analytics cookies, no advertising cookies, no session replay, no third-party tracking pixels.
3. How we use your information
| Purpose | Information used |
|---|---|
| Provide and operate the Service | Customer ID, email, license type, machine-ID hash (Desktop activation) |
| Send service emails (download links, service updates, and — for any future paid features — purchase receipts) | |
| Follow up on free downloads and announce future paid availability | Email (free-download leads, §2.2) |
| Process payments and license purchases | Stripe customer ID (Stripe handles card data) |
| Provide customer support | Email, support tickets |
| Detect and prevent abuse | Server logs, session metadata, rate-limit counters |
| Comply with legal obligations | Whatever is required by valid legal process |
| Investigate security incidents | All of the above, scoped to the incident |
We do not:
- Sell or rent your personal information.
- Use your information for behavioral advertising.
- Use your imaging for training AI models.
- Share your information with third parties for marketing purposes.
4. Network transmissions from the Desktop Viewer
The Desktop Viewer’s only outbound network calls are to activate and verify your license. Those calls never include your imaging.
4.1 License activation (our License API)
To issue or activate your license, the Viewer contacts the MyBodyPrism
License API (api.mybodyprism.com) over HTTPS and sends:
- a one-way hash of a stable hardware identifier of your machine (used only to bind the license to your computer);
- a free-license request (or, in the future, a paid activation code);
- the app version; and
- optionally, your email address — only if you provide it, to send occasional service emails.
It does not send any imaging, imaging-derived data, DICOM tag values, file paths, your name, or date of birth. The API returns your signed license file, which is then verified offline on your device.
4.2 Crash reporting — local only
If the Viewer crashes, a PHI-scrubbed crash detail is written
locally to %APPDATA%\MyBodyPrism\crashes\. Nothing is transmitted
to us automatically. If you ask us for help with a crash, you may
choose to email us that file.
4.3 No other outbound paths
There are no update checks, no telemetry, no analytics, and no feature-usage tracking.
5. Third-party service providers
We use the following third-party service providers in the operation of the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing and license-purchase management | Name, email, billing address, card data (handled by Stripe) |
| Amazon Web Services, Inc. | Cloud hosting (website, license API, installer downloads) | Billing + license metadata only — no medical imaging flows to our cloud |
| Sectigo Limited / The SSL Store | Code-signing certificate | Bolthouse Labs corporate identity only (no customer data) |
| GoDaddy / Microsoft 365 / Route 53 / etc. | DNS, email infrastructure | Email-routing only |
We do not share your information with any third party other than as described above. We do not allow any of these providers to use your information for purposes outside the scope of providing the contracted service.
6. Data retention
| Category | Retention |
|---|---|
| Stripe customer + purchase record (only if you purchase a future paid feature) | As long as the purchase is active, plus 7 years for tax / accounting records |
| Service-side license records (machine ID hash, activation codes) | As long as your license is active, plus 90 days |
| Free license records (machine-ID hash) | For the life of the free program, to enforce the one-free-license-per-machine limit |
| Free-download leads (email address, §2.2) | Until you ask us to delete it, or 24 months after your last interaction with us, whichever comes first |
| Marketing site server logs | 30 days |
| Support email history | 3 years from last contact |
| Imaging data (Desktop) | Not retained by us at any time |
| Crash reports | Local only (PHI-scrubbed, on your device; not transmitted) |
7. Security
We protect your information using industry-standard practices:
- Encryption at rest: All AWS-side data is encrypted with customer-managed AWS KMS keys. The license-signing key is HSM-backed (AWS KMS asymmetric RSA-2048).
- Encryption in transit: TLS 1.2 or higher for all network transmissions.
- Access controls: Least-privilege IAM roles, MFA required for all administrative access, no long-lived AWS access keys.
- No medical imaging in our cloud: in this version of the Service, your medical imaging does not flow through our cloud infrastructure. Any future feature that stores or streams imaging through our infrastructure will be opt-in, engineered to HIPAA-grade safeguards, and covered by an update to this policy before it ships.
- Audit logging: All access to Service-side data is logged with tamper-evident retention in an S3 bucket with Object Lock enabled.
- No public-read storage: No customer data is stored in any publicly accessible location.
We engage in periodic security reviews and welcome responsible disclosure of security vulnerabilities at support@mybodyprism.com with “Security:” in the subject line.
8. Your rights
8.1 Universal rights
Regardless of where you live, you may:
- Access the personal information we have about you.
- Correct inaccurate personal information.
- Delete your account and associated personal information (subject to retention obligations for tax, accounting, and legal compliance).
- Export your license and account metadata in a portable format.
To exercise any of these rights, email support@mybodyprism.com. We will respond within 30 days.
8.2 California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended:
- Right to know what personal information we collect, use, disclose, and (if applicable) sell about you. See §2 and §3 above for our practices.
- Right to delete your personal information.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share your personal information within the meaning of the CCPA.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes outside the scope of providing the Service.
- Right to non-discrimination for exercising any of these rights.
To exercise CCPA rights, email support@mybodyprism.com with “CCPA request” in the subject line.
8.3 European Economic Area, UK, Switzerland (GDPR / UK-GDPR / DSG)
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right not to be subject to solely automated decision-making (Art. 22) — we do not engage in solely automated decision-making about you
- Right to lodge a complaint with a supervisory authority
Our lawful basis for processing your personal information is performance of a contract (providing the free Service, or a future paid feature you purchase) and legitimate interests (operating the Service, following up on free downloads, preventing abuse, securing data). We do not rely on consent for any current processing; any future opt-in feature would rely on your consent.
To exercise GDPR rights, email support@mybodyprism.com with “GDPR request” in the subject line.
8.4 International transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. We rely on Standard Contractual Clauses with our processors (Stripe, AWS) for any cross-border transfers of personal information from the EEA, UK, or Switzerland.
9. Children’s privacy
The Service is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 13 (under 16 in the EEA/UK). If you believe we have inadvertently collected such information, please contact support@mybodyprism.com and we will delete it.
Pediatric imaging may be opened in the Service by a parent or legal guardian; the personal information collected in connection with the parent’s license belongs to the parent, not the child whose imaging is being viewed.
10. Data Processing Agreement (DPA)
For EU/UK customers who require a Data Processing Agreement under GDPR Art. 28, contact support@mybodyprism.com with “DPA request” in the subject line.
11. Changes to this Policy
We may update this Policy from time to time. The effective date above will reflect the most recent revision. Material changes will be communicated by email to registered users (users who have provided an email address) and posted at https://mybodyprism.com/legal/privacy at least 30 days before they take effect.
12. Contact
Bolthouse Labs, Inc. c/o Legalinc Corporate Services Inc. 131 Continental Dr, Suite 305 Newark, DE 19713 United States
Email: support@mybodyprism.com
For privacy-specific inquiries: include “Privacy” in the subject line.