Privacy Policy
Last Updated: August 7, 2026
Effective April 1, 20261.Introduction
BodyDex ("the App") is operated by Daniel Bobunov ("we," "us," or "our"), an individual developer. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App.
We are committed to protecting your privacy. BodyDex is built on a local-first architecture — the vast majority of your personal data is stored exclusively on your device and is never transmitted to our servers. We only process data remotely when you explicitly use features that require it (such as AI food scanning or the AI Coach).
By using the App, you consent to the data practices described in this policy.
2.Local-First Architecture
The following data is stored exclusively on your device. Except for the limited, consented AI-feature payloads described in Section 6, it is never transmitted to our servers:
- User profile information (name, email, physical attributes, goals)
- All food logs, meal entries, and daily nutritional summaries
- Weight logs, body measurements, and progress photos
- Medication, supplement, and peptide schedules and adherence history
- Recipes and custom food items
- Exercise and workout logs
- Dashboard layout preferences and app settings
- AI Coach conversation history and memory
- Notification preferences and schedules
- Behavioral analytics data (food input patterns, feature usage frequency)
Note: As BodyDex evolves, we may introduce optional cloud backup and social features in the future. If and when such features are introduced, this Privacy Policy will be updated accordingly, and any cloud data storage will require your explicit opt-in consent.
3.Data We Collect
3.1 Data You Provide
When you use the App, you may voluntarily provide the following information, which is stored locally on your device:
- Account Information: Name, email address (via Apple or Google Sign-In)
- Physical Profile: Height, weight, age/date of birth, biological sex, activity level
- Health Goals: Target weight, dietary goals, goal speed, diet type, motivations, obstacles, cooking frequency
- Food Data: Food log entries, meal photos (for AI scanning only), recipes, custom food items
- Health Tracking: Weight logs, body measurements, progress photos
- Protocol Data: Medications (including optional prescribing doctor name), supplements, peptides, dosage schedules, adherence logs
- User Content: Notes, recipe descriptions, coach conversation messages
- Preferences: App theme, notification settings, dashboard layout, preferred units
- Feedback: Feature requests, bug reports, and app satisfaction surveys (when voluntarily submitted)
Third-Party PII: The App allows you to optionally enter a prescribing doctor's name for medication records. This information is entered voluntarily, stored only on your device, and never transmitted to any server. We are not responsible for the accuracy of third-party information entered by users.
3.2 Data Collected Automatically
- Device Identifier: A stable, app-scoped device identifier (iOS Vendor ID or a generated UUID) used exclusively for server-side rate limiting and abuse prevention. It is pseudonymous — not intended to directly identify you — and is not used to track you across other companies' apps or websites.
- Subscription Status: Your subscription tier (Free or Premium, including trial status) is verified through RevenueCat to determine feature access. We store a cached status locally; the server verifies it periodically.
- IP Address: Cloudflare and our server infrastructure process your IP address and ordinary request metadata for delivery, security, abuse prevention, and operational logging, under their retention controls. We do not attach your IP address to your tracking data.
- Pseudonymized Service Usage: When you use AI-powered features (food scanning, voice logging, AI Coach, food search, recipe import), we record a pseudonymized event noting which feature was used and whether the request succeeded, errored, or hit a rate limit. For recipe imports that fail, the event additionally notes the source platform (e.g. TikTok, Instagram, YouTube) and a technical failure reason so we can detect and fix import breakages; the shared link itself is not stored in these events. The event is indexed by a one-way SHA-256 hash of your account identifier so we can compute aggregate metrics (daily active users, error rates, cost forecasts) without storing your raw identifier. These events do not contain food data, photos, message contents, voice transcripts, or any personally identifiable information, and the hash cannot be reversed to identify you.
3.3 Feedback & Support Submissions
When you submit a bug report, feature request, comment, or support request in the app (including replies in a support conversation), we collect:
- The text you typed (title and description)
- Any screenshots you chose to attach (optional)
- Your email address, only if you typed one (optional, used for follow-up)
- App version, platform, operating system, and OS version (auto-attached for diagnostics)
- Your subscription status and the store it was purchased through (auto-attached, so we can prioritize and troubleshoot billing issues)
- A pseudonymized device hash (one-way SHA-256, used only for anti-spam)
- Your account identifier, only if you are signed in (so we can match feedback to your account if you ask us to)
- A push notification token, only if you have granted notification permission (used solely to notify you when we reply to your submission)
Submissions are stored on our backend (Supabase, US region); that copy is scheduled for automatic deletion after 180 days. So that reports actually get seen and fixed, submissions (including any screenshots you attach) are also delivered to the developer through an operator notification service (Telegram Bot API, encrypted in transit) and retained in our internal support tooling for as long as reasonably necessary for support, security, or legal purposes. If you granted notification permission, we use your push token to notify you when we reply. Feedback is used solely to improve BodyDex — it is never sold, never used for marketing, and never shared beyond the delivery services named here.
3.4 Data from Third Parties
- Apple / Google Sign-In: Your name and email address as provided during authentication, delivered to us as identity tokens and profile claims — we never receive or store your Apple or Google password. A stable app account identifier is created from this sign-in and linked to your subscription status. Apple's "Hide My Email" feature is supported.
- Apple HealthKit / Google Health Connect: If you grant permission, we may read and/or write health data as described in Section 5.
4.How We Use Your Data
We use the data described above to:
- Calculate personalized calorie and macronutrient targets
- Track food intake, nutrition, and dietary adherence
- Manage medication, supplement, and protocol schedules with reminders
- Provide AI-powered food photo analysis and nutritional estimation
- Deliver AI nutrition coaching responses (when initiated by you)
- Sync nutrition and fitness data with Apple HealthKit or Google Health Connect (with your permission)
- Deliver push notification reminders (meal logging, medications, etc.)
- Verify subscription status and enforce tier-based feature limits
- Prevent abuse of free-tier rate limits via anonymous device identifiers
- Monitor service quality and forecast infrastructure costs via pseudonymized, aggregate usage metrics (see Section 3.2)
We do NOT sell, rent, or share your personal data with advertisers, data brokers, or any third parties for marketing purposes. Our sole revenue model is subscription fees.
5.Apple HealthKit & Google Health Connect
5.1 What We Read (with your permission)
- Step count
- Active energy burned (calories)
- Body weight and height
- Heart rate
- Water intake
- Biological sex and date of birth (iOS only, for profile auto-fill during onboarding)
- Workout and exercise session data
5.2 What We Write (with your permission)
- Dietary energy consumed (calories)
- Dietary macronutrients (protein, carbohydrates, fat, fiber — and, where the platform supports them, sugar, sodium, and cholesterol)
- Body weight measurements
- Water intake
- Workout sessions with estimated active calories (Google Health Connect)
5.3 Health Data Commitments
We make the following commitments regarding your Apple HealthKit and Google Health Connect data:
- Raw health records are stored exclusively on your device and are never transmitted to our servers; when you use AI features, only consented, derived summaries are processed transiently (see Section 6)
- Health data is NOT used for advertising or marketing of any kind
- Health data is NOT sold or disclosed to data brokers or any third party
- Health data is NOT shared with third parties for purposes unrelated to providing core health functionality within the App
- Health data is NOT used for any purpose other than providing health and fitness functionality directly to you within the App
- You can revoke health data permissions at any time through your device's Settings
6.AI Feature Data Processing
Certain features use AI services that require transmitting limited data to our secure server infrastructure (Cloudflare Workers) for processing. Beyond auto-expiring rate-limiting counters (most within 48 hours; see Section 9 for the exact retention tiers), our servers keep only short-lived operational records: the status record for a video import you started (kept up to 7 days so the result can be delivered to your device — see Section 6.4), the opt-in scan-accuracy report photos described in Section 6.1, an anonymized shared recipe cache (Section 6.4), the install-measurement records described in Section 8.1, and the pseudonymized usage events described in Section 3.2. These records are not linked to your name or email address. AI requests are keyed to a pseudonymous account identifier (used for authentication and rate limiting); your name and email address are never included.
6.1 AI Food Photo Scanner
- Data sent: Food photo (image data), scan mode type, and your pseudonymous account identifier
- Data NOT sent: Your name, email address, or profile details
- Storage: Photos are processed in real-time and immediately discarded — we do not keep food photos on our servers, with one exception: if you rate a scan result as inaccurate and explicitly choose "Send with photo," that single photo is stored (with no account identifier attached) so we can reproduce and fix the failure, and is automatically deleted within 90 days.
6.2 AI Nutrition Coach
- Data sent: Your message text (limited to 300 characters), last 5 messages for context, and a compact personalization summary (today's macro totals, age, sex, goal type, weight trend, and — with your in-app consent — the names and doses of your active supplements, medications, and peptides)
- Data NOT sent: Full conversation history, email address, full name, or complete profile data
- Storage: Messages are processed in real-time and not stored server-side. Full conversation history is stored only on your device.
6.3 Voice-Assisted Food Logging & Voice Corrections
- Data sent: A short audio clip of your voice command (up to approximately 25 seconds), which our servers transcribe to text using a speech-to-text AI service (currently Cloudflare Workers AI, with Groq as a fallback); optional vocabulary hints derived from your tracked item names, to improve recognition; and/or a text transcript produced on your device (limited to 2,000 characters)
- Data NOT sent: Your name, email address, or profile details
- Storage: We do not retain audio clips or transcripts after processing; our speech-to-text providers may retain limited data under their own terms.
6.4 Video Recipe Import
- Data sent: The video link you share, and the video's audio track and captions retrieved from that link (via a content-retrieval service) for transcription and recipe extraction
- Data NOT sent: Your name, email address, or profile details
- Storage: A status record for your import (including the shared link and the resulting recipe) is kept for up to 7 days so the result can be delivered to your device, then automatically deleted. An anonymized result cache keyed to the video link (not to you) is retained for up to 30 days to avoid re-processing the same public video.
For ordinary web recipe pages (non-video links), your device fetches the page directly: the destination website receives the URL request and ordinary network metadata (including your IP address) under its own policies, and the parsed recipe is stored only on your device.
6.5 AI Transparency
When you use the features described in this section, you are interacting with an automated artificial-intelligence system, not a human. The outputs these features produce — nutritional estimates, coaching responses, and analysis results — are AI-generated content, and the App identifies these features as AI-powered at the point of use. This disclosure is provided in line with applicable AI transparency laws, including Article 50 of the EU Artificial Intelligence Act.
6.6 AI Training Data Usage
7.Progress Photos, Camera & Microphone
7.1 Progress Photos
The App allows you to take and store body progress photos for personal tracking. These photos are:
- Stored exclusively on your device in the App's local database
- Never uploaded to our servers or any cloud service
- Never shared with any third party
- Permanently deleted when you use the "Delete All Data" feature
7.2 Camera Access
The App requests camera access to enable AI food scanning, barcode scanning, nutrition label scanning, and progress photos. The camera is only activated when you explicitly open a scanning or photo feature. Food photos captured for AI analysis are transmitted for processing and then discarded from our servers (except the optional scan-accuracy reports described in Section 6.1). On your device, a copy of each scan photo is kept temporarily for your scan history and is automatically cleaned up on a schedule of roughly 30 to 90 days depending on subscription tier and scan status.
7.3 Photo Library Access
The App may request access to your photo library to allow you to select existing food photos for AI analysis. Selected photos are processed identically to camera captures.
7.4 Microphone Access
The App may request microphone access for voice-assisted food logging and voice corrections. When you use these features, a short audio clip of your speech (up to approximately 25 seconds) is transmitted to our server infrastructure and transcribed to text by a speech-to-text AI service (see Section 6.3); your device may also produce a local transcript used as a fallback. Audio is recorded only while you are actively using a voice feature, is processed transiently, and is not retained after transcription.
8.Third-Party Services
The App integrates with the following third-party services. Each service has its own privacy policy governing their handling of data:
| Service | Purpose | Data Shared |
|---|---|---|
| FatSecret Platform API | Food search & nutrition data | Search queries, barcode numbers |
| AI Service Providers (currently Google, OpenAI, Groq, and Cloudflare Workers AI) | Food analysis, coaching, voice transcription, recipe extraction | Food photos, voice audio clips, short text messages, and personalization context, keyed to a pseudonymous account identifier (see Section 6) |
| Apify | Video content retrieval for recipe import | The video link you share (see Section 6.4) |
| RevenueCat | Subscription management | App-scoped user ID, purchase transaction data |
| Cloudflare | Secure API proxy & infrastructure | All AI requests are routed through Cloudflare Workers; rate-limiting counters stored in Cloudflare KV (auto-expiring, 48 hours to 365 days by tier — see Section 9) |
| Apple / Google | Authentication, push notifications, health data sync | Sign-in credentials (managed by Apple/Google), push notification tokens |
| USDA FoodData Central | Nutrition reference data | Search queries and barcode numbers, sent directly from your device — the service also receives ordinary request metadata (including your IP address) under its own policies |
| Open Food Facts | Barcode product data | Search queries and barcode numbers, sent directly from your device (plus ordinary request metadata, including your IP address); public data used under ODbL license |
We encourage you to review the privacy policies of these third-party services. We are not responsible for the privacy practices of third-party service providers.
8.1 Ad Install Measurement (No Tracking)
When BodyDex is first installed, our own server sends a single "the app was installed" event to our advertising platform (e.g., Meta) so we can tell whether our ads work; only installs that followed one of our own ads are counted toward a campaign. The event carries a random, app-scoped install identifier (retained by us for up to 90 days for de-duplication), your platform and app version, and on Android the store referrer when present. It is sent by our own server — BodyDex contains no advertising or tracking SDKs— and contains no name, no email, no health data, and no advertising identifier. It is not linked to any data you enter in the app, and nothing further is ever reported after installation. On iOS, install counting additionally uses Apple's privacy-preserving SKAdNetwork / AdAttributionKit framework, which reports only aggregated campaign-level counts. We do not respond to these events with any form of profiling, retargeting, or data sharing.
9.Data Retention
- Local data: Stored on your device indefinitely until you choose to delete it (via "Delete All Data" or by uninstalling the App). Because this data exists only on your device, we cannot recover it if the App is uninstalled or your device is lost, reset, or damaged. Profile → Export Data produces a portable copy of your records (JSON/CSV — a data copy, not a restorable in-app backup; image files and certain settings are not included).
- Rate-limiting counters: Anonymous counters stored in our server infrastructure automatically expire and are deleted on a tiered schedule: daily usage counters within 48 hours, monthly usage counters within approximately 35 days, and lifetime free-tier anti-abuse counters (video recipe imports) within 365 days.
- Anti-abuse device identifier: A minimal, app-scoped device identifier is retained for fraud and abuse prevention and intentionally survives "Delete All Data" (see Section 11.2). It is pseudonymous and not intended to directly identify you.
- AI-processed data: Food photos, text messages, voice audio, and transcripts submitted for AI processing are NOT stored on our servers — they are processed transiently and discarded — with two scoped exceptions: opt-in scan-accuracy report photos (deleted within 90 days; see Section 6.1) and video-import status records (deleted within 7 days; see Section 6.4).
- Feedback submissions: The backend copy is automatically deleted after 180 days; copies delivered to our internal support tooling are retained as long as needed to investigate and resolve the issue (see Section 3.3).
- Subscription data: Managed by RevenueCat per their data retention policy. Cached subscription status on our server expires within 5 minutes.
10.Data Security
We take reasonable measures to protect your information:
- Local encryption: Data on your device is stored in a local database protected by your operating system's built-in encryption at rest (iOS Data Protection / Android File-Based Encryption)
- Transport encryption: All data transmitted between the App and our servers uses HTTPS/TLS encryption in transit
- Secure proxy: AI service requests are routed through our secure server infrastructure — API keys are never exposed on your device
- Server-side verification: Subscription status and rate limits are verified server-side to prevent tampering
- Credential separation: The App includes only the public client credentials needed to access certain services; credentials capable of privileged access are kept server-side
While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
11.Your Rights
Because your data is stored locally on your device, you have direct, immediate control over your information at all times:
11.1 Right to Access
All your data is visible and accessible to you directly within the App at any time.
11.2 Right to Delete
You can permanently delete all data stored on your device through the App (Profile → Delete All Data). This action is irreversible and removes all personal data from the local database and signs you out. Feedback reports you may have submitted are retained as described in Section 3.3 (the backend copy auto-deletes within 180 days); subscription and billing records are managed by Apple, Google, and RevenueCat under their own policies. The anonymous device identifier used for rate limiting is preserved to prevent abuse but contains no personal information.
11.3 Right to Export (Data Portability)
You can export your data at any time through the App (Profile → Export Data). Data is exported in portable formats (JSON and CSV) that you can save, transfer, or use as you see fit.
11.4 Right to Revoke Permissions
You can revoke health data, camera, microphone, notification, and photo library permissions at any time through your device's Settings. Revoking permissions may disable certain features but will not affect your existing data.
11.5 California Residents (CCPA)
If you are a California resident, you have the right to: know what personal information is collected, request deletion of your personal information, and opt out of the sale of your personal information. We do not sell your personal information. You can exercise your rights using the Delete All Data and Export Data features within the App, or by contacting us at .
11.6 European Users (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the rights of access, rectification, erasure, restriction, data portability, and objection. Since your data is stored locally on your device, you can exercise most of these rights directly. For any requests you cannot fulfill through the App — including requests concerning the limited server-side records described in this policy — contact us at and we will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local supervisory authority.
Data processed by our AI features is transmitted to infrastructure operated by our service providers primarily in the United States and, where our edge network operates, in other countries. By using AI features, you consent to this transfer.
12.Children's Privacy
BodyDex is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at and we will take steps to delete such information.
Users between the ages of 13 and 18 may use the App only with the consent and supervision of a parent or legal guardian.
13.Website Privacy
The BodyDex marketing website (bodydex.app) uses Cloudflare Web Analytics to measure page traffic and understand which pages visitors reach. It is privacy-first by design: it uses no cookies, no tracking pixels, and no fingerprinting, and it does not track you across other websites. It records only aggregate, non-identifying information such as page views, referrer, country, and device type.
We do not collect personal information through the website, and we do not sell any data. The website is a static informational site hosted on Cloudflare Pages.
14.Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this page. It is your responsibility to review this Privacy Policy periodically for changes.
Your continued use of the App after any modifications to this Privacy Policy constitutes your acceptance of the updated policy.
If we make material changes to the way we handle your data, we will make reasonable efforts to provide notice through the App or our website.
15.Contact Information
For questions, concerns, or requests regarding your privacy or this policy:
Privacy inquiries:
General legal inquiries:
Developer: Daniel Bobunov