Privacy Policy

Effective 27 September 2026

The short version

  • We collect what we need to run your training, the coach and the community features you use.
  • No ads, no selling data, no third-party trackers, and no training AI models on your data.
  • Health data is never used for advertising, never sold, never shared without your consent and never used to train AI.
  • Your account is private until you choose otherwise.
  • You can download or delete everything from the You tab at any time.

1. Who we are

Bodaptive is operated by its founder, an individual based in the United States (“Bodaptive”, “we”, “us”). We decide how and why your personal data is used for the Bodaptive website at bodaptive.com and the Bodaptive apps for iPhone and Android (the “Service”), which makes us the “controller” of that data under European and UK law.

This policy explains what we collect, why, who helps us process it, how long we keep it and what you can do about it. The Service is only for people aged 18 and over. You can reach us about anything in it at support@bodaptive.com.

Back to contents

2. What we collect

What you give us

  • Account: your name, email address and a salted hash of your password (never the password itself). If you sign in with Google, Google tells us your name, email address and account identifier; we never see your Google password.
  • Fitness profile: your goal, experience, schedule, equipment and units and, if you choose to give them, your height, weight, year of birth, sex and the body areas you want to work around. That last item can be information about your health.
  • Training: your plans, the workouts and routines you start and finish, every set you log, the feedback and ratings you give and any notes about discomfort.
  • Coach conversations: what you write to the coach, including during set-up, and its replies.
  • Community: your handle, bio and profile picture; your posts, photos, comments, likes and chat messages; workouts you build and share; groups, events and challenges you create or join; who you follow, befriend and block; and the reports you file. We remove hidden metadata, such as location, from photos you upload.

What the Service works out

Badges, challenge results and rankings, personal records, estimated recovery and the notifications we show you, all computed from the data above.

From connected health sources

Only if you connect one. See Health data.

Collected automatically

  • Server logs: the time, address requested, outcome and network (IP) address of each request, used to keep the Service secure and working. We do not store the network address with your account.
  • Usage and error events: which screens are opened, a few milestones (such as “workout finished”), error reports, the app version, a rough device class (phone, tablet or desktop) and a random identifier for your browser or app. They never include what you type, health details or IP addresses.
  • On your device: your time zone, so days and streaks are counted in your local time, and a random identifier for each phone you connect a health store from.

What we do not collect

Precise location, contacts, advertising identifiers, or payment details (the Service has no payments today).

Back to contents

3. How we use it

We use your data only to:

  • build your training plan and adapt it as you log workouts;
  • show you your history, progress, recovery estimates and badges;
  • run the coach and let it answer questions about your training;
  • run the community features you use, with the audience you choose;
  • compute challenges, leaderboards and group goals you take part in;
  • send the emails you need (confirming your address, resetting your password, a welcome, and notice before a trial ends) and, unless you turn them off, a weekly recap, a nudge when a workout is waiting or it has been a while, and updates on challenges you joined. Each of those has a one-click unsubscribe, and you choose them in You › Email settings;
  • keep the Service and its members safe: prevent spam, abuse and fraud, and moderate content;
  • find and fix problems and understand which features are used, so we can improve them;
  • meet legal obligations and enforce our Terms.

We do not sell your data, show advertising, or use your data to train artificial-intelligence models.

Back to contents

4. The AI coach and our AI provider

The coach runs on an AI model from Anthropic, which processes data for us as our service provider. When you message the coach we send Anthropic:

  • your message and the conversation so far;
  • a compact summary of the context it needs: your goal, experience, equipment, schedule and areas to work around, your current plan and recent workouts, and your recovery state;
  • if you have connected a health source, short summaries worked out by our own software (for example, “sleep below your usual three nights running”), never the raw data from Apple Health, Health Connect or a device maker.

We do not send your email address or password. The coach looks things up only through tools we control, and only for your own account.

Anthropic may not use this data to train its models and keeps it only for a limited time for safety and abuse monitoring, under its commercial terms. Anthropic also checks photos you upload (see Moderation and safety).

If you would rather not share anything with the AI provider, do not use the coach. Your plan, workouts and progress work without it.

Back to contents

5. Health data

This section covers health and fitness data from Apple Health (HealthKit), Android Health Connect and connected devices, and the health information you tell us yourself. Connecting a source is always your choice, made in You → Connections, where we list what will be read and why before your phone asks for permission.

What we read, and from where

  • Apple Health (iPhone app) and Health Connect (Android app): today, your daily steps and active energy. As features arrive we may ask for distance, exercise minutes, resting heart rate, heart-rate variability, sleep and workouts; each needs your permission on the phone, and we read only the types you allow. On first connection we read up to 90 days of history. We never read clinical or medical records, and we do not write to your health store today.
  • Oura, WHOOP, Polar and Withings, as each becomes available: the same kinds of daily activity, sleep, recovery and workout data, through a connection you authorise on their site.
  • Strava: Bodaptive does not integrate with Strava.
  • What you tell us: body areas to work around and notes about discomfort.

Why we use it

To show you your activity, sleep and recovery next to your training, to inform your recovery estimates and badges, to count your steps in challenges and group goals if you choose, and to give the coach short summaries so it can answer questions about your recovery.

Our promises

  • Never used for advertising or marketing, and never used to decide eligibility for credit, insurance or employment.
  • Never sold, and never given to data brokers.
  • Never shared with third parties without your consent. The only exceptions are the service providers that host and process it for us under contract (listed in Who we share data with) and a valid legal demand.
  • Never used to train artificial-intelligence models, ours or anyone else’s.
  • Shown to other people only if you opt in. “Count in challenges” is a separate switch, off by default. When it is on, your step totals appear on the challenges and group goals you join. Data from WHOOP is never shown to anyone else without that explicit opt-in. Turn it off and your steps leave the boards straight away.

Bodaptive’s use and transfer of information received from Health Connect follows the Health Connect Permissions Policy, including its Limited Use requirements. Data from Apple Health is used only for the health and fitness features described here.

How long we keep it

As long as the source stays connected. When you disconnect a source, the days and workouts imported from it are deleted immediately, and so are its access tokens. Deleting your account deletes all of it. Backups roll off within 35 days.

How to revoke access

  • In Bodaptive: You → Connections → choose the source → Disconnect.
  • On iPhone: open the Health app → Sharing → Apps → Bodaptive, and turn off what you no longer want to share.
  • On Android: open Health Connect → App permissions → Bodaptive, and remove permissions.
  • For Oura, WHOOP, Polar or Withings: disconnect in Bodaptive, or remove Bodaptive from the connected apps in their app or website.

How we protect it

Health data travels encrypted. Tokens for cloud connections are encrypted with AES-256 before they are stored and never reach your browser or our logs.

Consumer health data notice (Washington, Nevada and other US states)

Laws such as Washington’s My Health My Data Act treat some of what we hold as “consumer health data”: the body areas and discomfort notes you give us, data from connected health sources, and recovery estimates we derive from them.

  • We collect it from you, from your phone’s health store, and from device makers you connect.
  • We use it only for the purposes in “Why we use it” above, which you consent to when you enter it or connect a source.
  • We share it only with our service providers (hosting, database, and the AI provider for coach summaries), and with other members only through the challenge opt-in above.
  • We never sell it.
  • You can see it (Download my data), delete it (disconnect, or delete your account) and withdraw consent (disconnect, or remove the information from your profile) at any time, or email us. If we decline a request, you can appeal as described in US state privacy rights below.
Back to contents

6. What other people can see

Your account is private until you make it public. Until you choose a handle, nobody can find you. Each post, workout, group, event and challenge has its own audience (only you, friends, followers or everyone signed in), capped by your account setting. Some public things, such as your profile card and public workouts, can be opened by anyone with the link.

Group content is visible to the group’s members, and a public group’s posts to anyone signed in. Your comments and likes are seen by whoever can see the post. Challenge leaderboards show participants their rankings and results. A block hides you and the other person from each other everywhere.

People who can see what you share may copy or screenshot it. If someone saves a copy of a workout you shared, their copy stays if you delete yours, without your name.

Back to contents

7. Moderation and safety

Reports. When you report something, we record what you reported, the reason, any note you add and when. Our team reviews it. We never tell the reported person who reported them.

Automated photo checks. Before anyone else can see a photo you upload, we remove hidden metadata such as location, and send the photo to Anthropic’s AI model to check it against our Community Guidelines, for example for nudity, graphic violence or someone’s private documents. A photo that clearly breaks the rules is rejected; one that might is held for our team to review, and until then only you can see it. The check also suggests a short description of the photo, which you can edit, for people who use screen readers. Only whether a photo is shown is decided this way, and you can ask for a person to review a decision by emailing us.

Records. We keep a record of reports, the decisions we make and the reasons, so we can handle appeals and repeat abuse.

Legal reporting. We report child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC), and may share information with the authorities when someone’s safety is at risk or the law requires it.

Back to contents

8. Who we share data with

We do not sell your personal data or share it for advertising. We share it only with these service providers, which process it for us under contract and only to run the Service, and in the other cases below.

Fly.io
Runs our web and API servers. United States (Chicago).
Neon
Hosts our database, on Amazon Web Services. United States (Ohio).
Tigris (through Fly.io)
Stores the photos you upload. United States; copies may be cached near the people viewing them.
Amazon Web Services (Amazon SES)
Delivers our emails. United States (Ohio).
Anthropic
Runs the AI coach and checks uploaded photos. United States.
Cloudflare
Runs our domain’s DNS and forwards email you send to our support address.
Google
Signs you in, if you choose “Continue with Google”.
Stripe
Processes payments for Pro on the web and stores your card. We never see or store your full card number. United States.
Apple and Google app stores
Distribute the apps. They collect data under their own policies and may give us aggregate statistics and crash reports.

We may also share data:

  • with other members, as you choose through your visibility settings;
  • when the law requires it, such as a valid court order, or when needed to protect someone’s safety, our rights or the Service;
  • with a company that takes over the Service in a merger, acquisition or sale, which must honour this policy, including every promise about health data;
  • with anyone else, only with your consent.
Back to contents

9. Cookies and similar technologies

We use one cookie to keep you signed in, and, only if you open a friend’s invite link, a second one that remembers the invite for 30 days so it still counts when you sign up. Both are needed for what you asked for, so there is no consent banner. Your browser or app also stores a few things on your device, such as your settings, workouts waiting to sync when you are offline, and the random identifiers described above. There are no advertising cookies, third-party analytics, tracking pixels or cross-site tracking.

Back to contents

10. How long we keep data

Your account, profile, training, coach conversations and community content
As long as you have an account. You can delete individual posts, photos, comments, messages and workouts at any time.
Content you delete
Hidden from everyone at once, and erased from our systems within 30 days.
After you delete your account
Removed from our live database straight away; photos and other stored files within 30 days; backups roll off within 35 days.
Health data
While the source is connected; deleted as soon as you disconnect it.
Server logs, usage and error events
Up to 90 days. When your account is deleted, your events stop being linked to you.
Record of the emails we sent you
90 days: which email, when, and whether it was delivered or skipped. Deleted with your account.
Reports and moderation decisions
Two years after the case is closed, then deleted. If you delete your account, reports you filed stay without your name.
Content removed for breaking the rules
Up to 90 days, so it can be reviewed on appeal, or longer where the law requires us to preserve it.
Billing records
Payment events, amounts and dates (never card details, which Stripe holds) are kept for 7 years, as tax and accounting law requires, even after you delete your account. Once your account is deleted they are no longer linked to you.
Unused accounts
We may delete an account unused for three years, after emailing a warning at least 30 days ahead.

We may keep data longer when the law requires it, or to resolve a dispute or legal claim. Counts and statistics that no longer identify anyone may be kept.

Back to contents

11. Download, delete and other choices

  • Download your data: You → Your data → Download my data. You get a complete copy of everything we hold about you as a JSON file, without passwords or tokens.
  • Delete your account: You → Your data → Delete account, then type DELETE to confirm. It is immediate and permanent. It also disconnects your health sources; groups you own pass to their longest-serving admin or member.
  • Correct your data: edit your profile and settings in the You tab.
  • Choose who sees what: your account’s visibility and each item’s audience.
  • Disconnect health sources: You → Connections.

For anything else, email support@bodaptive.com from the address on your account, so we can confirm it is you. We answer within one month, and within the time your local law sets if it is shorter.

Back to contents

12. Users in the EU, UK and elsewhere

We offer the Service in many countries. If you are in the European Economic Area, the United Kingdom or Switzerland, data protection law requires a legal basis for each use of your data. Ours are:

Performing our contract with you
Your account, plan, workouts, coach, community features, challenges and badges.
Your explicit consent
Health data from connected sources and the health information you give us (GDPR Article 9(2)(a)), and counting your steps in challenges. You can withdraw consent at any time by disconnecting or removing it, without affecting what happened before.
Our legitimate interests
Keeping the Service secure, preventing spam and abuse, moderating content (including automated photo checks), and fixing and improving the Service. We have weighed these against your rights, and you can object.
Legal obligations
Answering lawful requests and keeping required records.

Your rights

You have the right to access your data, correct it, delete it, receive it in a portable format, restrict or object to how we use it, and withdraw consent. We do not make decisions about you with legal or similarly significant effects based solely on automated processing. You can complain to your local data protection authority, but we would like the chance to help first.

Transfers to the United States

We are based in the United States, and your data is stored and processed there. When you use the Service from another country, your data comes to us in the United States, where data protection law may differ from yours. Where our service providers receive personal data from Europe or the UK, they rely on the EU–US Data Privacy Framework (with its UK and Swiss extensions) or on the European Commission’s Standard Contractual Clauses and the UK addendum.

Everywhere else

Wherever you live, you can use the controls above and ask us to access, correct or delete your data.

Back to contents

13. US state privacy rights

Residents of California and other states with privacy laws (such as Colorado, Connecticut, Oregon, Texas, Virginia and Washington) have rights to know what personal information we hold, to get a copy, to correct and delete it, and not to be treated differently for using these rights. We give these rights to every member, wherever they live.

  • Categories we collect: identifiers (name, email, handle), account login details, characteristics you choose to give (age, sex), health and fitness information, the content you post, and in-app activity. The sources and purposes are described above.
  • We disclose these only to the service providers listed above, for business purposes.
  • We do not sell or “share” personal information for cross-context behavioural advertising, do not use it for targeted advertising or profiling with significant effects, and have not done so in the past 12 months. We treat a Global Privacy Control signal as an opt-out anyway.
  • We use sensitive information (login details and health data) only to provide the Service you ask for.

To make a request, use the controls above or email support@bodaptive.com. An authorised agent can make a request for you with your signed permission; we will confirm it with you. We respond within 45 days. If we decline, reply with “Appeal” and we will review the decision within 45 days; if you still disagree, you can contact your state’s attorney general.

Back to contents

14. Security

Data travels between your device and our servers over encrypted connections, and our database and backups are encrypted by our providers. Passwords are stored as salted hashes. Only the people who run the Service can reach production systems, and admin actions are logged. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires, without undue delay.

Back to contents

15. Children

The Service is only for people aged 18 and over, and we do not knowingly collect data from anyone younger. If you believe someone under 18 has an account, tell us at support@bodaptive.com and we will delete it.

Back to contents

16. Changes to this policy

We will update this policy as the Service changes and post the new version here with a new effective date. If a change matters to you, we will tell you in the app or by email before it takes effect. We will never use health data in a new way without asking you first.

Back to contents

Questions? Email support@bodaptive.com.

Get the app

Bodaptive for iPhone and Android is on its way. Until then it runs in your phone's browser — add it to your home screen and it opens like an app.

Start free on the web