Privacy Policy
Last updated: September 18, 2026
BiOGuide is a free, non-commercial study resource. Almost everything on the site - every topic page, every practice question, every timed attempt - works with no account at all. This page explains what happens on the small part that does involve an account: login, your profile, and the leaderboard.
What we collect
If you never create an account, we don’t collect anything about you beyond standard, anonymous web hosting logs (handled by our host, Vercel).
If you create an account (optional, via Sign Up on the Account page), we collect:
- Email and password - used only to log you in. Passwords are never stored in readable form; authentication is handled by our backend provider, Supabase, using industry-standard hashing. We never see or store your raw password.
- Display name - chosen at signup, shown publicly on the leaderboard.
- Avatar - a picture you pick from a small curated set, shown publicly next to your name.
- Country, education level, and a short “about” bio - all optional, filled in on your profile. Country is shown publicly on the leaderboard as a flag; education level and “about” are shown only on your own profile.
- Timed Attempt / quiz activity - if you submit a practice test to the leaderboard, we store your score, timing, and per-question results, tied to your account, so we can rank you and show your history.
That’s the complete list. We don’t collect payment information (the site is free), and we don’t run advertising scripts or sell data to advertisers. We do use analytics tools to understand traffic and how the site is used, described in the Analytics section below.
Why we collect it
Only to run the features you’re actually using: logging you in, showing your chosen name/avatar/country on the leaderboard, and keeping a record of your practice-test results so the leaderboard and your own history stay accurate. We don’t sell data, and we don’t use it for advertising.
Where it’s stored
Account and profile data lives in Supabase, a hosted Postgres database and authentication provider. The site itself is hosted on Vercel. Both are reputable infrastructure providers used by many websites - naming them here is normal and doesn’t mean either can see or use your data beyond storing/serving it on our behalf.
Row-level security rules mean other logged-in users can never read your email or your private practice-test details directly from the database - only what’s meant to be public (display name, avatar, country, leaderboard results) is visible to others.
Accounts are optional
You can read every topic page and attempt every practice question without ever signing up. An account only unlocks saving leaderboard results, a profile, and full access to BiOBytes articles.
Cookies and local storage
Your login session is kept in your browser’s local storage, not a cookie, so you stay logged in between visits - this is standard behavior for any site with accounts, not a tracking mechanism. Google Analytics 4 sets first-party cookies to recognize return visits; PostHog is configured to use local storage only, not cookies. Neither is used for advertising, and we don’t run ad-targeting scripts of any kind.
Analytics
We use three tools to understand how the site is used. None of them sell data or run advertising:
- Umami (self-hosted, on our own infrastructure) - anonymous page views and Core Web Vitals. No cookies, no personal data. This is also what powers the visitor-country counts on the About page.
- PostHog (hosted in the EU) - tracks a small set of specific actions, like completing signup or submitting a practice attempt, not full page content or recordings of your session. If you’re logged in, these actions are linked to your account so we can understand how account holders actually use the site; if you’re not logged in, they’re anonymous.
- Google Analytics 4 - standard traffic and behavior analytics, using the first-party cookies described above. You can opt out at any time using Google’s browser add-on or by enabling Do Not Track in your browser.
BiOLab: protocols, results, and feedback
BiOLab is different from the rest of the site: it’s the one place where content you submit can be shown publicly to any visitor, not just other logged-in BiOGuide members. If you use BiOLab, here’s specifically what that means:
- Protocols you submit (title, category, description, the full protocol text, and any source attribution you provide) publish immediately and are shown to any visitor of the archive, logged in or not - there is no staff review queue before it goes live. Your display name, avatar, and country are shown as the author, the same way they appear on the leaderboard.
- Feedback/comments you leave on a protocol are public to any visitor, attributed to your display name the same way.
- Results you submit against a protocol (a numeric value, unit, and optional photo) are private by default - visible only to you. They only become visible to other visitors if you explicitly choose “Make public” on that result. Making a result public also makes any photo attached to it visible to others; keeping it private keeps the photo visible only to you.
- Photos you attach to a result are re-encoded before upload, which strips EXIF metadata (GPS location, device model, capture timestamp) automatically - we never store that metadata. This is separate from what’s in the frame: the submission form asks you not to include your face, other people, or identifying surroundings in the photo itself, since stripping EXIF data doesn’t change what the image visually shows.
- Reporting and removal: any protocol or result can be reported by another logged-in user. If BiOGuide staff act on a report, the content is hidden from public view (a removal flag, checked before anything is ever shown publicly) rather than deleted outright, so we retain an internal record of what was reported, why, and what was done about it. A removed protocol or result is no longer visible to anyone except (where applicable) the person who submitted it.
If you’d rather not have something you submitted to BiOLab shown publicly, the simplest option is not to submit it, or to keep a result private and never toggle it public. If you want a public protocol, feedback comment, or public result removed, email us at the address below and we’ll take it down.
Deleting your data
If you have an account, you can delete it yourself at any time: log in, go to the Account page, and use Delete my account at the bottom of your profile. This permanently and immediately removes your login, profile, avatar/country/education/about, and all leaderboard/attempt history - it cannot be undone. We keep a minimal internal record that a deletion occurred (just a date and an internal ID, nothing identifying) so we can confirm a deletion happened if you ever ask us to check.
If you’d rather we do it for you, or you have any other privacy question, email us at r6394175@gmail.com.
A note for younger users
BiOGuide’s audience includes a lot of school-age students. If you’re under the age required in your country to agree to this kind of policy on your own (for example, under 13 in the US), please ask a parent or guardian to help you sign up, or to reach out to us at the email above with any questions or a deletion request on your behalf.
Changes to this policy
If this policy changes in any meaningful way, we’ll update the “Last updated” date at the top of this page. Since BiOGuide is run by one person rather than a legal team, treat this as a clear, honest first pass rather than a final legal document - if you have concerns, please just email us.