Privacy Policy

Effective date: July 14, 2026.

BodyBench is developed and operated by Kai Luo, an individual developer. This policy describes what BodyBench collects, how it's used, and where it goes.

1. What we collect

Test and health data. Results from the fitness tests you run — VO₂max, heart rate, HRV, body fat, strength and power scores, posture angles, and similar. If you connect Apple Health, we read (never write) VO₂max, resting heart rate, body fat, height/weight, and HRV to help fill in your results.

Photos and videos. Jump-test captures, posture scan photos, and meal photos you choose to take within the App.

Free-text notes. Training feedback and injury descriptions you choose to type.

Your name. The first name you enter during setup, used only to personalize greetings in the App.

Anonymous device identifier. A random identifier generated on your device and stored in the Keychain, used only to apply fair-use rate limits on our backend and not linked to any personal information.

Subscription verification data. When you request an AI reading, the App sends the signed subscription receipt issued by Apple's StoreKit to our backend so it can confirm you're entitled to the paid feature. This is a one-time, transient check — we don't store the receipt.

We do not collect your precise location, contacts, browsing history, or any financial information — subscription payments are handled entirely by Apple, and we never see your card details.

2. How we use it

All of the above is used solely to run the App's core functionality: scoring your tests, showing your history and trends, and — only when you tap to request it — generating an AI Coach reading, posture insight, or meal analysis. We do not use your data for advertising, and we do not build behavioral profiles or track you across other apps or websites.

3. Where it lives

Your test results, photos, and notes are stored locally on your device. BodyBench has no account system and no server that stores your data by default.

When you tap to request an AI reading, the relevant data for that specific request is sent to our backend (api.getbodybench.com), which forwards it to a third-party AI provider (Claude, DeepSeek, Gemini, GLM, or Qwen) and returns the response. Which provider handles a given request is decided by BodyBench as an internal routing detail — it isn't something you choose or see. Our backend is a thin relay: it applies the fair-use rate limit and subscription check described above, forwards your request, and does not log or retain the content of your test data, photos, or notes.

4. Third-party AI providers

Each AI provider processes the data you send it under its own privacy policy and data-handling practices, which we don't control. BodyBench decides which provider to use for each request; no data is sent to a provider unless you actively request a reading.

5. No tracking, no ad SDKs

BodyBench does not include any advertising or analytics SDK, does not use your device's advertising identifier, and does not track you across apps or websites. This is also declared in the app's PrivacyInfo.xcprivacy manifest (NSPrivacyTracking = false).

6. Your choices

You can delete your local test data anytime from Settings › Data & privacy › Reset test data. Disconnecting Apple Health in iOS Settings stops future reads immediately. Uninstalling the App removes all locally stored data.

7. Children's privacy

BodyBench is not directed at children under 16. We do not knowingly collect data from children under that age.

8. Security

Data in transit to AI providers is sent over standard HTTPS/TLS. Data at rest on your device is protected by iOS's standard app sandboxing and device encryption.

9. Our backend proxy

BodyBench runs a small backend proxy so AI-provider API keys don't have to live on individual devices. It sits between the App and whichever AI provider is handling your request, and its only jobs are: apply fair-use rate limiting (using the anonymous device identifier described above), verify your subscription entitlement, and forward your request to the provider. It does not persist your test data, photos, or notes beyond the time needed to complete that single request.

10. Changes to this policy

We'll update the effective date above whenever this policy changes, and — for material changes — try to surface that in the App itself.

11. Contact

Questions about this policy: contact@getbodybench.com.