Skip to content

Privacy Policy

Effective date: August 20, 2026.

1. Controller

Biocompile, Inc. is the controller responsible for the personal data processed through this website.

Biocompile, Inc.
Frontier Tower
995 Market Street
San Francisco, CA 94103
United States
Email: contact@biocompile.com

We apply GDPR-level protections to all visitors as our baseline and provide additional, region-specific rights where local law requires. To exercise your data-protection rights, contact us at the address above. See the imprint for full company details.

2. Data we collect

2.1 Contact form and pilot form

Two forms on this site send us a message. The contact form collects your name, your email address, and your message. The pilot form collects your name, your email address, the company, institution or team you belong to, and your answers to four open questions: your research focus, the roadblocks you run into, what you would most want taken off your plate, and the area of science that excites you. The four answers are free text, so what they contain is what you choose to write in them; please leave out anything confidential that your enquiry does not need.

By checking the consent checkbox on either form, you consent to this processing solely to respond to your enquiry (Art. 6(1)(a) GDPR). Your submission is composed into one message, forwarded to our team inbox, and not stored in a database. We retain correspondence for the duration of the enquiry thread plus six months after the last exchange. You may withdraw consent at any time by contacting us, though this does not affect the lawfulness of processing carried out before withdrawal.

2.2 Analytics (PostHog EU)

We use PostHog, hosted exclusively in the EU (Frankfurt, Germany), for privacy-preserving aggregate usage measurement. Analytics requests are sent to a path on our own domain and relayed by our servers to PostHog rather than being sent from your browser directly. This changes only the network route: the request, and the IP address it originates from, pass through our infrastructure before PostHog receives it, while the data described below and your consent choice stay the same. PostHog operates in one of three modes depending on your consent choice:

  • Before you make a choice (anonymous mode). We record aggregate measurement of how our pages are used, each event carrying the path you are on: a page-view and a page-exit event (between them giving how long the page was open, how far down it you scrolled, and the referring site's domain if there is one), which part of the page was in front of you and for how long, clicks on page elements, clicks that hit nothing and rapid repeated clicks in one spot, the position of clicks and scrolling on the page as coordinates, page-speed measurements, which of our calls to action came into view and which you selected, whether the consent banner was shown and what you chose on it, and a redirect event when you leave for our application. If you start a signup, the steps you take on the step described in section 2.5 are recorded in the same way: that it opened, that you selected the field, whether you submitted, closed or left it, how long it was open, and, on submit, the domain part of the address you entered. The address itself is never sent to our analytics, in this mode or any other, and neither is anything else you type: click measurement records which element was selected and the text printed on it, which on this site is our own published wording, and never the contents of a field. No cookies or localStorage entries are set, no device identifier is created or persisted, session recording and surveys are disabled, element attributes are masked, and we instruct PostHog to discard your IP address. Events also carry the technical characteristics your browser transmits with the request anyway (browser and operating system name and version, device type, and screen size); we do not read the high-entropy device-model identifier that browsers can expose. Because nothing is stored on or read from your device, and no identifier links one page you open to the next, this mode falls outside TDDDG Section 25 (formerly TTDSG Section 25) consent requirements. It is limited to first-party measurement of how our own pages perform and are used, which is the audience-measurement purpose recognised by the CNIL, and is based on our legitimate interest in measuring aggregate use of our public marketing site (Art. 6(1)(f) GDPR). The processing is strictly limited to what is necessary to produce aggregate statistics and cannot identify you.
  • After you accept (full mode). We record everything the anonymous mode records, and consent changes one thing about it: a visit identifier is stored in localStorage and a cookie, so the pages you open can be read as one visit rather than as unrelated arrivals. Nothing further is collected that was not collected before. Because you consented, links from this site to our application also carry that visit identifier and the session identifier as web address parameters (ph_did and ph_sid), so that the pages you saw here and what you go on to do in the application are measured as one journey rather than two unrelated ones. Neither value contains your name or your email address. In anonymous mode no such identifier exists and nothing is carried across. This is based on your consent (Art. 6(1)(a) GDPR). PostHog analytics data is retained for up to 7 years, the retention period of our analytics platform's current plan.
  • After you decline (no analytics). No PostHog requests are made and any in-memory analytics from anonymous mode are opted out.

Feature-flag decision endpoints and third-party data sharing are disabled in every mode. Session recording is disabled in every mode on this website. We honour the Do-Not-Track (DNT) browser signal and the Global Privacy Control (GPC) signal. When either is detected, no analytics run in any mode. A browser sending Global Privacy Control is not shown the consent banner either, because the signal is already an answer, and the "Cookie settings" link has nothing to change for as long as that signal is sent. Otherwise you can withdraw or re-grant consent at any time via that link in the footer (Art. 7(3) GDPR).

2.3 Bot protection (Cloudflare Turnstile)

Our contact form and our pilot form use Cloudflare Turnstile to protect against automated abuse. Turnstile processes limited technical data (browser type, interaction patterns) to verify you are human. This is based on our legitimate interest in preventing spam (Art. 6(1)(f) GDPR).

2.4 Server logs

This website runs on our own infrastructure in the Amazon Web Services Frankfurt region (eu-central-1), within the European Union. Standard server access logs record truncated IP addresses, request paths, timestamps, and HTTP status codes. These are retained for up to 14 days and used exclusively for security monitoring and debugging.

2.5 Signup step

When you select a button that starts a signup, we show a short step that asks for your work email address before sending you to our application at app.biocompile.com. We store that address, its domain and a coarse classification of that domain (a work address, a free mailbox, a shared role address, or a disposable one), the time you entered it, the page and the button you came from, the domain of the site that referred you if there was one, your language preference, the wording of the notice you were shown on the step at that moment, and a keyed hash of your IP address used to limit abuse of the form. We cannot reverse that hash to your address. We do this so that we can prefill the signup form for you. This is based on our legitimate interest in completing a signup you started yourself (Art. 6(1)(f) GDPR). We do not add this address to a mailing list, we do not enrich it with data from other sources, and we do not share it with advertisers or data brokers.

The step also tells you, at the moment you enter the address, that a founder may write to you once to help you get started. That single message is the only thing we send as a result of this step. It is about the signup you began yourself, it is announced to you before you hand the address over, and it is not sent at all once an account exists, because there is then nothing to help you start. It is based on the same legitimate interest (Art. 6(1)(f) GDPR), and it is not a newsletter: there is no sequence behind it and no second message if you do not reply. Anything beyond that one message would need your consent, and the place we would ask for it is inside the product, not on this step.

If we cannot store the address at that moment, for example because the service that holds it is unavailable, we send it instead to our own support inbox so that your signup is not lost. That message goes through Twilio SendGrid, our email provider, and is held in our inbox at Google Workspace. We delete it there within 30 days. This is the only case in which the address reaches a mailbox rather than our database, and it carries nothing beyond the address, the page you came from and the button you selected.

You may object to this processing at any time under Art. 21(1) GDPR. Write to contact@biocompile.com and we will delete your address. If you do not complete signup, we delete the record 90 days after you entered it. If you do complete signup, we delete the record within 30 days of your account being created, after which your address is held only as part of your account.

Your address is passed to app.biocompile.com through a single-use token that expires after ten minutes, so that the address itself does not appear in a web address, in server logs, or in your browser history.

Closing the step, with the Escape key or by selecting outside it, returns you to the page you were on and stores nothing. The step is asked once per visit: after you have given an address, later signup buttons go straight through. The buttons themselves carry the ordinary signup link, so opening one in a new tab or going to app.biocompile.com/signup directly reaches signup without passing through the step.

3. Hosting and processors

This website is hosted by:

  • Amazon Web Services (Frankfurt, Germany, eu-central-1) — server infrastructure
  • Cloudflare (EU data centers) — CDN, DDoS protection, Turnstile
  • PostHog (Frankfurt, Germany) — analytics (consent-gated)
  • Twilio SendGrid — delivery of the messages this site sends, which are the contact and pilot enquiries in section 2.1 and the fallback described in section 2.5
  • Google Workspace — the inbox those messages arrive in

Every processor is covered by a data processing agreement, and the processing itself takes place within the European Union. Five of these processors are established in the United States, so their flows are named individually rather than covered by one general statement. For Amazon Web Services, the data is stored in the EU region and the remaining exposure is potential access by the US parent; we rely on Amazon Web Services, Inc.'s certification under the EU-US Data Privacy Framework together with the EU Standard Contractual Clauses carried by the AWS Data Processing Addendum. For Cloudflare, Inc., any transfer or access outside the EEA is safeguarded by the EU Standard Contractual Clauses in Cloudflare's data processing agreement. PostHog, Inc. is likewise a United States company, and the position is the same as for Amazon Web Services: the analytics data is processed and stored exclusively in PostHog's European Union region, and the remaining exposure is potential access by the US parent, for which we rely on the EU Standard Contractual Clauses carried by the PostHog data processing agreement. For Twilio Inc. and Google LLC, any transfer or access outside the EEA is safeguarded by the EU Standard Contractual Clauses carried by their respective data processing agreements.

4. Your rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time (Art. 7(3))
  • Lodge a complaint with your local data protection supervisory authority

To exercise any of these rights, contact us at contact@biocompile.com. We will respond within one month.

4.1 California residents

If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the California Online Privacy Protection Act (CalOPPA):

  • Categories of personal information collected: Internet or other electronic network activity information (anonymized measurement events in anonymous mode; pageviews, clicks, and Web Vitals in full mode); identifiers (name and email address via the contact form, the pilot form, and the signup step); professional or employment-related information (the company, institution or team and the research answers you give on the pilot form).
  • Sale or sharing: We do not sell or share your personal information as defined under CCPA. PostHog operates as a service provider under contract and does not receive data for its own commercial purposes.
  • Your rights: You have the right to know what personal information we collect, to request deletion, and to request correction. To exercise these rights, email contact@biocompile.com. We will respond within 45 days.
  • Do Not Track / Global Privacy Control: This site honours both the DNT browser signal and the GPC signal. When either is detected, all analytics are disabled.

5. Cookies and storage

This website sets no cookies and writes nothing to your browser's storage before you make a choice on the consent banner. If you accept analytics, a consent preference (__biocompile_consent) is stored in localStorage and persists until you clear it or use the "Cookie settings" link in the footer. No third-party tracking cookies are used at any time.

One further entry is written only if you start a signup: once you have answered the signup step described in section 2.5, we note that answer (__biocompile_handoff) so that the step is not shown to you again on the way to the same page. It is stored in sessionStorage, which your browser discards when you close the tab, and it holds no personal data beyond the single-use token described above.

For details on what each consent mode does, see Cookie Notice.

6. Retention summary

  • Contact-form and pilot-form correspondence: duration of the enquiry thread + 6 months
  • Signup step, signup not completed: 90 days from the day you entered your address
  • Signup step, signup completed: deleted within 30 days of your account being created
  • PostHog analytics (full mode): up to 7 years (analytics platform plan retention)
  • Server logs: up to 14 days
  • Consent choice: persisted in your browser's localStorage until you clear it

7. Changes

We may update this privacy policy to reflect changes in our practices or legal requirements. The current version is always available at this URL.

We use privacy-friendly analytics hosted in the EU to improve this site. No cookies are set until you choose. Cookie Notice

Your first project starts here.

Free to start, with credits included.

We use this address to prefill your signup. A founder may email you once to help you get started. No newsletter. Privacy Policy

Already have an account? Sign in