
BITTING Privacy & Data Use Notice
Your health information. Your authorization.
BITTING is designed to help individuals organize personal health information. You decide whether to connect a participating healthcare organization and authorize access to selected information. BITTING does not receive your MyChart username or password, does not sell health information, and does not use health information for advertising.
Privacy Questions and Requests
To ask a privacy question, request access, correction or deletion, or report a concern, use the contact form available at cerixcorp.com.
Detailed Privacy Notice
Effective Date: August 19, 2026
This Privacy & Data Use Notice explains how Cerix Corp collects, uses, stores, and protects information through BITTING.
1. Information BITTING Collects
BITTING may collect information entered directly by the user, including identification and profile information, vital signs, weight, blood pressure, oxygen saturation, heart rate, symptoms, sleep information, nutrition, calories, vitamin K, INR, warfarin dosage, medications, medication inventory, notes, and related health-management information.
When a patient authorizes a healthcare connection, BITTING may retrieve selected information such as demographics, laboratory observations, diagnostic reports, test dates, LOINC codes, values, units, reference ranges, interpretations, FHIR identifiers, and synchronization dates. The information actually available depends on the healthcare organization and the permissions authorized by the patient.
BITTING may also maintain authorized-user information such as names, email addresses, roles, invitation records, access status, connection status, and system timestamps.
2. How Information Is Collected
Information is collected when a user enters it into BITTING, when an administrator authorizes access for a family member or healthcare professional, or when a patient expressly authorizes a participating healthcare organization to provide selected information through SMART on FHIR and OAuth 2.0.
Food searches may be sent to USDA FoodData Central. These requests are intended to contain food-search terms and not patient-identifying health information.
3. How Information Is Used
Cerix Corp uses information to operate BITTING; organize personal health records; calculate nutrition, vitamin K, calorie, INR, medication, and related summaries; display trends and synchronization status; prepare personal reports; manage authorized access; maintain security; troubleshoot errors; and improve the reliability of the application.
BITTING does not use health information for targeted advertising, data brokerage, or unrelated marketing, and Cerix Corp does not sell health information.
4. Healthcare Authorization and Credentials
Authentication with a healthcare organization occurs on that organization’s official authorization page. BITTING does not receive or store the patient’s MyChart username or password.
OAuth access and refresh tokens are stored in private server-side application properties and are not written into the health-data spreadsheet. Tokens are used only to perform the access authorized by the patient. Authorization may expire, be revoked through the healthcare organization, or be disconnected from BITTING.
Disconnecting removes the stored connection tokens and prevents future synchronization through that connection. It does not automatically delete laboratory information that was previously imported.
5. Storage, Access and Service Providers
User-entered information and imported laboratory data are stored in the Google Sheets database associated with the BITTING application. Private application configuration, authorization tokens, and invitation records are stored through Google Apps Script services.
Information may be processed by service providers required to operate BITTING, including Google services, Epic or participating healthcare organizations, USDA FoodData Central for food searches, and GoDaddy for the public website and contact form. These organizations operate under their own terms and privacy practices.
Access to BITTING is limited through Google-account authorization, assigned roles, or private invitation links. Private access links should be protected like passwords and should not be forwarded to unauthorized persons. Authorized family members or healthcare professionals may view information according to the access granted by the administrator.
6. Retention, Correction and Deletion
User-entered records and imported health information are retained until they are corrected, deleted, or a deletion request is completed. Revoking a user’s invitation prevents future access but does not automatically remove existing health records.
A user may request access to, correction of, or deletion of information associated with BITTING through the contact form at cerixcorp.com. Requests may require reasonable identity verification before action is taken. Some limited information may be retained when required for security, legal compliance, or documenting a completed request.
7. Security and Breach Notification
Cerix Corp uses reasonable administrative and technical measures appropriate to the current BITTING architecture, including role-based access, private server-side token storage, restricted administrator functions, and patient-authorized OAuth connections. No internet-based system can guarantee absolute security.
If Cerix Corp determines that a security incident requires notification under applicable law, affected individuals and appropriate authorities will be notified as required.
8. User Choices and Important Privacy Information
Users decide whether to enter information, authorize a healthcare connection, invite another person, synchronize information, or disconnect a connection. Users should connect only records they are legally authorized to access.
BITTING is an independent consumer application offered by Cerix Corp and is not operated by Epic Systems Corporation, MyChart, AdventHealth, or any healthcare provider. Depending on the circumstances, information transferred to an independent consumer application may not be protected by HIPAA in the same manner as information maintained by a healthcare provider.
9. Children
BITTING is not directed to children under 18 for independent use. A parent, legal guardian, or otherwise authorized representative must manage any information involving a minor.
10. Changes and Contact
Cerix Corp may update this notice to reflect changes to BITTING, its data practices, legal requirements, or security measures. The effective date will be updated when material changes are made.
Privacy questions, access requests, correction requests, deletion requests, or security concerns may be submitted through the contact form available at cerixcorp.com.
