Skip to content
BodyDex
HomeGuidesComparePressData SourcesSupport
Download onApp StoreGet it onGoogle Play
  1. Home/
  2. Privacy Policy

Privacy Policy

Last Updated: September 13, 2026

Effective April 1, 2026

1.Introduction

BodyDex ("the App") is operated by Daniel Bobunov ("we," "us," or "our"), an individual developer. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App.

We are committed to protecting your privacy. BodyDex is built on a local-first architecture — the vast majority of your personal data is stored exclusively on your device and is never transmitted to our servers. We only process data remotely when you explicitly use features that require it (such as AI food scanning or the Bodydex Assistant).

This policy describes how the App handles your information. Where we rely on your consent — for the Bodydex Assistant, for Apple Health / Health Connect access, and for the consumer health data described in Section 13 — we ask for it separately in the App, before the feature is used, and you can withdraw it as described in Section 11.7. Using the App is not itself consent to any of those features.

2.Local-First Architecture

Your data belongs to you. BodyDex stores all core data in a local database on your device, protected by your device's built-in encryption at rest (iOS Data Protection / Android File-Based Encryption). We do not maintain a centralized user database, and we cannot access your personal data unless you explicitly initiate a feature that requires cloud processing.

The following data is stored exclusively on your device. Except for the limited, consented AI-feature payloads described in Section 6, it is never transmitted to our servers:

  • User profile information (name, email, physical attributes, goals)
  • All food logs, meal entries, and daily nutritional summaries
  • Weight logs, body measurements, and progress photos
  • Medication, supplement, and peptide schedules and adherence history
  • Recipes and custom food items
  • Exercise and workout logs
  • Dashboard layout preferences and app settings
  • Bodydex Assistant conversation history and memory
  • Notification preferences and schedules
  • Behavioral analytics data (food input patterns, feature usage frequency)

Note: As BodyDex evolves, we may introduce optional cloud backup and social features in the future. If and when such features are introduced, this Privacy Policy will be updated accordingly, and any cloud data storage will require your explicit opt-in consent.

3.Data We Collect

3.1 Data You Provide

When you use the App, you may voluntarily provide the following information, which is stored locally on your device:

  • Account Information: Name, email address (via Apple or Google Sign-In)
  • Physical Profile: Height, weight, age/date of birth, biological sex, activity level
  • Health Goals: Target weight, dietary goals, goal speed, diet type, motivations, obstacles, cooking frequency
  • Food Data: Food log entries, meal photos (for AI scanning only), recipes, custom food items
  • Health Tracking: Weight logs, body measurements, progress photos
  • Protocol Data: Medications (including optional prescribing doctor name), supplements, peptides, dosage schedules, adherence logs
  • User Content: Notes, recipe descriptions, coach conversation messages
  • Preferences: App theme, notification settings, dashboard layout, preferred units
  • Feedback: Feature requests, bug reports, and app satisfaction surveys (when voluntarily submitted)

Third-Party PII: The App allows you to optionally enter a prescribing doctor's name for medication records. This information is entered voluntarily, stored only on your device, and never transmitted to any server. We are not responsible for the accuracy of third-party information entered by users.

3.2 Data Collected Automatically

  • Device Identifier: A stable, app-scoped device identifier (iOS Vendor ID or a generated UUID) used exclusively for server-side rate limiting and abuse prevention. It is pseudonymous — not intended to directly identify you — and is not used to track you across other companies' apps or websites.
  • Subscription Status: Your subscription tier (Free or Premium, including trial status) is verified through RevenueCat to determine feature access. We store a cached status locally; the server verifies it periodically.
  • IP Address: Cloudflare and our server infrastructure process your IP address and ordinary request metadata for delivery, security, abuse prevention, and operational logging, under their retention controls. We do not attach your IP address to your tracking data.
  • Pseudonymized Service Usage: When you use AI-powered features (food scanning, voice logging, the Bodydex Assistant, food search, recipe import), we record a pseudonymized event noting which feature was used and whether the request succeeded, errored, or hit a rate limit. For recipe imports that fail, the event additionally notes the source platform (e.g. TikTok, Instagram, YouTube) and a technical failure reason so we can detect and fix import breakages; the shared link itself is not stored in these events. The event is indexed by a one-way SHA-256 hash of your account identifier so we can compute aggregate metrics (daily active users, error rates, cost forecasts) without storing your raw identifier. These events do not contain food data, photos, message contents, or voice transcripts, and use a hashed account identifier instead of the raw identifier. The identifier is pseudonymous: it can link events from the same account and may remain personal data.

3.3 Feedback & Support Submissions

When you submit a bug report, feature request, comment, or support request in the app (including replies in a support conversation), we collect:

  • The text you typed (title and description)
  • Any screenshots you chose to attach (optional)
  • Your email address, only if you typed one (optional, used for follow-up)
  • App version, platform, operating system, and OS version (auto-attached for diagnostics)
  • Your subscription status and the store it was purchased through (auto-attached, so we can prioritize and troubleshoot billing issues)
  • A pseudonymized device hash (one-way SHA-256, used only for anti-spam)
  • Your account identifier, only if you are signed in (so we can match feedback to your account if you ask us to)
  • A push notification token, only if you have granted notification permission (used solely to notify you when we reply to your submission)

Submissions are stored on our backend (Supabase, US region); that copy is scheduled for automatic deletion after 180 days. So that reports actually get seen and fixed, submissions (including any screenshots you attach) are also delivered to the developer through an operator notification service (Telegram Bot API, encrypted in transit) and retained in our internal support tooling for as long as reasonably necessary for support, security, or legal purposes. If you granted notification permission, we use your push token to notify you when we reply. Feedback is used solely to improve BodyDex — it is never sold, never used for marketing, and never shared beyond the delivery services named here.

3.4 Data from Third Parties

  • Apple / Google Sign-In: Your name and email address as provided during authentication, delivered to us as identity tokens and profile claims — we never receive or store your Apple or Google password. A stable app account identifier is created from this sign-in and linked to your subscription status. Apple's "Hide My Email" feature is supported.
  • Apple HealthKit / Google Health Connect: If you grant permission, we may read and/or write health data as described in Section 5.

4.How We Use Your Data

We use the data described above to:

  • Calculate personalized calorie and macronutrient targets
  • Track food intake, nutrition, and dietary adherence
  • Manage medication, supplement, and protocol schedules with reminders
  • Provide AI-powered food photo analysis and nutritional estimation
  • Deliver AI nutrition coaching responses (when initiated by you)
  • Sync nutrition and fitness data with Apple HealthKit or Google Health Connect (with your permission)
  • Deliver push notification reminders (meal logging, medications, etc.)
  • Verify subscription status and enforce tier-based feature limits
  • Prevent abuse of free-tier rate limits via anonymous device identifiers
  • Monitor service quality and forecast infrastructure costs via pseudonymized, aggregate usage metrics (see Section 3.2)

We do NOT sell, rent, or share your personal data with advertisers, data brokers, or any third parties for marketing purposes. Our sole revenue model is subscription fees.

5.Apple HealthKit & Google Health Connect

HealthKit and Health Connect data is handled with the highest level of privacy protection. The App does not copy your health records to a server of ours to hold them: there is no account database. What the App reads from a health platform goes one of two ways, and Section 5.1 says which for each record type: some of it is written into the App's own database on your device (a weigh-in into your weight log, a drink into your water log, daily steps and active energy into your day; and a workout recorded by another app as a summary that feeds the muscle-recovery view, not as an entry in your workout history), and the rest is read on demand and not stored at all — the vitals readings, fetched for the dates a chart or a question covers, shown to you and held only in memory while the screen is open. Three things can then leave the device, all described in Section 6.2 and none of them without your consent to the Bodydex Assistant: values that were imported into your ordinary logs (the Assistant reads those as the log rows they became); a recovery percentage per muscle group, if the Assistant is asked about training and you allowed the fitness category — a single derived number that the workout summaries above feed into, never the external session itself; and, only if you tick the separate Health vitals option, vitals readings read on demand for the dates your question is about. Nothing is sent to a health platform except what Section 5.2 lists.

5.1 What We Read (with your permission)

Read into your logs. These become ordinary rows in the App's own database — a weigh-in in your weight log, a drink in your water log — and from that point the App treats them like anything you typed in yourself:

  • Step count
  • Active energy burned (calories)
  • Body weight and height
  • Heart rate
  • Water intake
  • Biological sex and date of birth (iOS only, for profile auto-fill during onboarding)

Read as a summary for muscle recovery. Workout and exercise sessions recorded by your other apps — a watch, a running app, another gym app — are read so the App can tell how recently each muscle group was worked. What is stored is a summary of each session: when it started and ended, how long it lasted, the activity type, the muscle groups it maps to, a workload estimate, the name of the app that recorded it, and an energy figure where the platform supplies one. These summaries are not entries in your workout history — your workout history holds the workouts you logged in Bodydex. They appear in the muscle-recovery view and as a count on the fitness dashboard, and you can turn the whole thing off at Profile › Apple Health / Health Connect › Workouts.

Read on demand to chart a vital against your doses. Each of these is requested on its own, at the moment you add that chart, and is read only for the dates being charted or asked about. They are not written into your logs:

  • Resting heart rate
  • Heart rate
  • Heart rate variability
  • Blood pressure (systolic and diastolic)
  • Blood glucose
  • Blood oxygen saturation
  • Respiratory rate
  • Sleep sessions (nightly total)
  • Body fat percentage
  • Lean body mass

The full list of the vitals charts you have enabled is in the App at Profile › Apple Health / Health Connect › Vitals for protocols. Sending any of these readings to the Bodydex Assistant additionally requires the separate Health vitals tick described in Section 5.3.

5.2 What We Write (with your permission)

  • Dietary energy consumed (calories)
  • Dietary macronutrients (protein, carbohydrates, fat, fiber — and, where the platform supports them, sugar, sodium, and cholesterol)
  • Body weight measurements
  • Water intake
  • Workout sessions with estimated active calories (Google Health Connect)

5.3 Health Data Commitments

We make the following commitments regarding your Apple HealthKit and Google Health Connect data:

  • We run no health-record database of our own. We operate no account database, and we hold no health record of yours on our servers for us to look at — with one transient exception: if you use the Bodydex Assistant, a reply that pauses mid-answer leaves a working copy on our proxy on the criteria described in Section 6.2, and that copy can contain records you consented to send. What the App reads from a health platform either goes into its own database on your device or is not stored at all — Section 5.1 says which, per record type. When you use the Bodydex Assistant with your explicit consent, the records and summaries listed in Section 6.2 are sent to OpenAI through our proxy, and what our own server keeps while doing that is described there. Some of those values were imported from a health platform (see the callout above and Section 5.1) and are sent as the ordinary log rows they became, under the ordinary data-access categories you grant in Profile › Bodydex Assistant › What the assistant can see.
  • Dedicated vitals reads are a separate opt-in. Reading the vitals listed in Section 5.1 as readings — resting heart rate, heart rate, heart rate variability, blood pressure, blood glucose, blood oxygen, respiratory rate, sleep, body fat, lean body mass, and the daily steps and active energy read from your health app — and sending them to OpenAI requires the "Health vitals" category, which is off unless you tick it yourself and which no preset ever turns on. While it is off, the Assistant performs no dedicated read of your health app and no such reading is sent.
  • Imported values are not covered by that tick, and we do not claim they are. A weight or water entry that came from Apple Health or Health Connect is a row in your own log from the moment it is imported, and the Assistant reads it under the matching ordinary category — body or nutrition — which the App's default data-access answer turns on. So with "Health vitals" off, the Assistant can still be sent a weigh-in that originated in your health app, because it reads it as your weight log and not as a health-platform reading. A workout recorded by another app is not a log row and is never sent as one; what it can reach the Assistant as is the per-muscle recovery percentage described in the callout, under the fitness category. If you do not want any of that, switch the relevant category off in Profile › Bodydex Assistant › What the assistant can see.
  • Readings and imported values alike are never sold, never used for advertising, and never shared with anyone beyond the recipients named for the feature you are using.
  • Health data is NOT used for advertising or marketing of any kind
  • We do not sell health data or disclose it to data brokers. The online features described in this policy disclose specified health data to the recipients identified for those features
  • Health data is NOT shared with third parties for purposes unrelated to providing core health functionality within the App
  • Health data is NOT used for any purpose other than providing health and fitness functionality directly to you within the App
  • You can revoke health data permissions at any time through your device's Settings

6.AI Feature Data Processing

Certain features use AI services that require transmitting limited data to our secure server infrastructure (Cloudflare Workers) for processing. Beyond auto-expiring rate-limiting counters (most within 48 hours; see Section 9 for the exact retention tiers), our servers keep only short-lived operational records: the status record for a video import you started (kept up to 7 days so the result can be delivered to your device — see Section 6.4), the opt-in scan-accuracy report photos described in Section 6.1, an anonymized shared recipe cache (Section 6.4), the install-measurement records described in Section 8.1, the pseudonymized usage events described in Section 3.2, and the two Assistant records described in Section 6.2 (a working copy of a reply that paused mid-answer, whose content we attempt to replace with a contentless record as soon as the reply finishes and which — then, or if that attempt does not succeed — we attempt to remove on the criteria set out in that section, where a failed attempt can leave it in place longer, and a cache of answers to standard Research Library questions that contains no personal context). AI requests are keyed to a pseudonymous account identifier (used for authentication and rate limiting); your profile name and email address are not attached automatically, but content you submit may itself identify you.

6.1 AI Food Photo Scanner

  • Data sent: Food photo (image data), scan mode type, and your pseudonymous account identifier
  • Data NOT sent: Your name, email address, or profile details
  • Storage: Photos are processed in real-time and immediately discarded — we do not keep food photos on our servers, with one exception: if you rate a scan result as inaccurate and explicitly choose "Send with photo," that single photo is stored (with no account identifier attached) so we can reproduce and fix the failure, and is automatically deleted within 90 days.

6.2 Bodydex Assistant

The Bodydex Assistant is an automated AI system. It is off until you turn it on, and it only runs after you give explicit consent in the App to the processing described here, including health data. The provider is OpenAI (OpenAI OpCo, LLC, United States), reached through our server proxy.

  • Data sent with every message: your message text (limited to 300 characters); your earlier messages in the current conversation, which the App sends to our proxy up to the 50 most recent and of which our proxy forwards only the 5 most recent to OpenAI as context; your profile and setup details (age, sex, height, weight, goal and goal pace, activity level, diet type, cooking frequency, focus areas, obstacles, motivations, whether you work with a human coach, any coach or motivation note you entered, and your preferred day window if you set one); a nutrition summary (today's totals, targets, per-meal calories and water, and 7-day averages); your recent weight readings (the last few you logged) and goal estimate; the names of your active supplements, medications, and peptides with the doses you recorded; and your saved Assistant notes and the details it remembered from earlier chats.
  • Data sent for some questions: at the Assistant's request during a chat, the App may read from your device and send: dated nutrition, water, and per-meal totals for up to the last 30 days; dated weight measurements for any period you ask about, up to your whole recorded history, with your goal estimate; your body measurements, and the recipes you have saved with their ingredients, macros, and how often you cook them; a protocol overview (each active medication, supplement, and peptide with the dose you recorded, its schedule summary, 7- and 30-day adherence, supply level, and the next dose and time slot recorded in your schedule); dose history for up to 30 days (counts of taken, skipped, and missed doses, injection sites used, and the last taken date, for one protocol or all); workouts (sessions with dates, names, duration, volume, calories, and streak); reminder settings (notification preferences, permission status, and how many protocols have reminders); your logging streak and badges (names, earned status and dates, progress); and the full record of one protocol, workout, or routine you ask about. Opening the Assistant from a Research Library entry or a protocol page also sends that entry's topic and a short summary of the selected protocol (name, recorded dose, schedule, 7-day adherence, supply level). With the separate "Health vitals" opt-in turned on, the App may also read and send readings from Apple Health or Health Connect — resting heart rate, heart rate, heart rate variability, blood pressure, blood glucose, blood oxygen, respiratory rate, sleep duration, body fat, lean body mass, and daily steps and active energy — for the dates your question is about, and only the readings that question needs. Some of the other values above may also be derived from Apple Health or Health Connect if you connected them.
  • Data NOT added automatically: your profile name and email address are not attached to Assistant requests; a pseudonymous account identifier is used instead. Messages and notes you write may themselves contain identifying information — do not include details you wish to keep private.
  • Abuse-monitoring identifier sent to OpenAI: each Assistant request to OpenAI carries a keyed pseudonymous identifier derived from your account identifier, sent only so that OpenAI can detect abuse of its service under its usage policies. It is not your name or email address, and it is not joinable to our own analytics.
  • What the Assistant may read: six categories — nutrition and calories, protocols and dose logs, workouts and fitness, body weight and measurements, health vitals, and memory — each of which you turn on or off in Profile › Bodydex Assistant › What the assistant can see. "Health vitals" is off unless you tick it, and no preset turns it on. Your setup answers (age, sex, height, activity level, units and the goal you chose) ride with every message while at least one category is on; allow nothing there and the Assistant answers from your messages only.
  • Storage on our servers: your conversation history and Assistant memory are stored on your device, not on our servers. Two server-side records exist. First, when a reply pauses mid-answer to look something up in the App, our Cloudflare proxy holds a working copy of that reply — which can include AI text, the pending requests for your data, the data returned, and personal information. We attempt to replace the content of that working copy with a record that carries no message text as soon as the reply finishes — an opaque turn reference kept only so a repeated request can be told it has already been handled. We do that on every completed reply, normally within seconds of the reply landing; we cannot promise every attempt succeeds, and where one does not the content is not removed at completion but stays subject to the criteria below. If a paused reply is never finished and never resumed — you close the App, your phone locks, the network drops — we cannot give you a measured maximum, so here are the criteria instead, as data-protection law allows where a period cannot be given: the pause stops being resumable after 3 minutes, the record becomes eligible for deletion 10 minutes after that, and a deletion scheduled at the moment of the pause then attempts to remove it once it is eligible, rather than waiting for a later request to trigger a sweep. Those two figures describe when the record becomes eligible for deletion, not when deletion succeeds: the delivery of a scheduled deletion is retried by the platform, an attempt can still fail, and where one does the copy stays in place until a later attempt succeeds. So we cannot bound how long an abandoned working copy persists. Second, answers to standard Research Library questions, which are sent without any of your personal context, are cached for up to 7 days so they need not be regenerated.
  • Retention by OpenAI: OpenAI states that content sent through its API is not used to train its models unless the customer opts in, and that it keeps abuse-monitoring logs for up to 30 days unless a longer period is required by law or reasonably necessary to protect its services or any third party from harm. We use OpenAI's standard API terms and have not arranged zero-data-retention, so you should assume OpenAI may hold Assistant content for up to 30 days under its own terms, and longer where those exceptions apply.
  • Narrowing what the Assistant may read: if you switch a category off — including unticking "Health vitals" — the Assistant starts a fresh conversation. The earlier conversation is never sent again, including anything the Assistant had remembered from it, so data covered by a permission you withdrew cannot be replayed to OpenAI by a later message. The turns the App removed from the live thread are kept on your device as a read-only transcript you can open and delete, and it cannot be sent: nothing in the App reads it back into a request. It is kept for that single reason — so that tightening a permission does not silently destroy your own history — and Delete transcript removes it, including while your consent is withdrawn. Only the 200 most recent messages are kept in a conversation; older ones are dropped.
  • Withdrawing consent: see Section 11.7. Withdrawing consent stops the sending: new Assistant requests stop at once, including further requests from a reply already in progress, and nothing from your conversations, memory or notes is sent to OpenAI afterwards. It does not erase them. They stay in the App's database on your device — your live thread, any archived or read-only transcript, your notes, and the facts the Assistant saved — and so, in one narrow case, does a conversation the App was unable to read back: rather than overwrite or destroy your history, the App sets those bytes aside untouched, and nothing parses, sends or replays them. We are not relying on the consent you withdrew to keep any of this, and we keep none of it for a purpose of our own. It is on your device, we have no access to it, and it is yours to delete: Delete transcript for an archived or read-only conversation, New Chat or Clear everything for the current one, per-note delete and Reset Assistant Memory for notes and remembered facts, Redo Assistant Setup to clear every one of them at once, or Delete All Data for the whole App. Withdrawal cannot recall information already received by our providers, which remains subject to OpenAI's retention described above.

6.3 Voice-Assisted Food Logging & Voice Corrections

  • Data sent: A short audio clip of your voice command (up to approximately 25 seconds), which our servers transcribe to text using a speech-to-text AI service (currently Cloudflare Workers AI, with Groq as a fallback); optional vocabulary hints derived from your tracked item names, to improve recognition; and/or a text transcript produced on your device (limited to 2,000 characters). The resulting transcript text is then sent to OpenAI to be parsed into food entries.
  • Data NOT sent: Your name, email address, or profile details
  • Storage: We do not retain audio clips or transcripts after processing; our speech-to-text providers may retain limited data under their own terms.

6.4 Video Recipe Import

  • Data sent: The video link you share, and the video's audio track and captions retrieved from that link (via a content-retrieval service) for transcription and recipe extraction
  • Data NOT sent: Your name, email address, or profile details
  • Storage: A status record for your import (including the shared link and the resulting recipe) is kept for up to 7 days so the result can be delivered to your device, then automatically deleted. An anonymized result cache keyed to the video link (not to you) is retained for up to 30 days to avoid re-processing the same public video.

For ordinary web recipe pages (non-video links), your device fetches the page directly: the destination website receives the URL request and ordinary network metadata (including your IP address) under its own policies, and the parsed recipe is stored only on your device.

6.5 AI Transparency

When you use the features described in this section, you are interacting with an automated artificial-intelligence system, not a human. The outputs these features produce — nutritional estimates, Assistant responses, and analysis results — are AI-generated content, and the App identifies these features as AI-powered at the point of use: the Assistant announces itself as an AI system when you set it up, and its chat screen carries a persistent notice that you are talking to an AI that can make mistakes. If you ask the Assistant whether it is a human or an AI, it should tell you that it is an AI. This disclosure is provided in line with applicable AI transparency laws, including Article 50 of the EU Artificial Intelligence Act. The Assistant is a tracking and general-information tool; it is not designed to provide companionship, therapy, counselling, or crisis support.

6.6 AI Training Data Usage

We do not collect, use, or sell your personal data for the purpose of training large language models, our own or anyone else's. We train no model. What follows is what the providers we send data to are permitted to do with it under their own terms, which differs between them.

Bodydex Assistant (OpenAI): OpenAI states that content sent through its API is not used to train its models unless the customer opts in; we have not opted in. OpenAI may still retain content for service operation, abuse monitoring, or legal requirements under its terms (see Section 6.2).

Other AI features: content submitted to food scanning, voice transcription, and recipe extraction — food images, audio clips, and nutritional text prompts — may be used by the respective provider for model improvement in accordance with that provider's terms. We do not attach your name or email address to these submissions; an app-specific pseudonymous identifier may accompany the request for rate limiting, and submitted content can itself contain identifying information if you choose to include it (for example, in a photo).

7.Progress Photos, Camera & Microphone

7.1 Progress Photos

The App allows you to take and store body progress photos for personal tracking. These photos are:

  • Stored exclusively on your device in the App's local database
  • Never uploaded to our servers or any cloud service
  • Never shared with any third party
  • Permanently deleted when you use the "Delete All Data" feature

7.2 Camera Access

The App requests camera access to enable AI food scanning, barcode scanning, nutrition label scanning, and progress photos. The camera is only activated when you explicitly open a scanning or photo feature. Food photos captured for AI analysis are transmitted for processing and then discarded from our servers (except the optional scan-accuracy reports described in Section 6.1). On your device, a copy of each scan photo is kept temporarily for your scan history and is automatically cleaned up on a schedule of roughly 30 to 90 days depending on subscription tier and scan status.

7.3 Photo Library Access

The App may request access to your photo library to allow you to select existing food photos for AI analysis. Selected photos are processed identically to camera captures.

7.4 Microphone Access

The App may request microphone access for voice-assisted food logging and voice corrections. When you use these features, a short audio clip of your speech (up to approximately 25 seconds) is transmitted to our server infrastructure and transcribed to text by a speech-to-text AI service (see Section 6.3); your device may also produce a local transcript used as a fallback. Audio is recorded only while you are actively using a voice feature, is processed transiently, and is not retained after transcription.

8.Third-Party Services

The App integrates with the following third-party services. Each service has its own privacy policy governing their handling of data:

ServicePurposeData Shared
FatSecret Platform APIFood search & nutrition dataSearch queries, barcode numbers
OpenAI (OpenAI OpCo, LLC, United States)Bodydex Assistant chat; parsing voice-log transcripts into food entriesAssistant messages and the personalization context listed in Section 6.2 (including health data, with your explicit consent); voice-log transcript text; keyed to a pseudonymous account identifier
Other AI Service Providers (currently Google, Groq, and Cloudflare Workers AI)Food photo, label and menu analysis; voice transcription; recipe extractionFood photos, voice audio clips, and short text prompts, keyed to a pseudonymous account identifier (see Section 6)
ApifyVideo content retrieval for recipe importThe video link you share (see Section 6.4)
RevenueCatSubscription managementApp-scoped user ID, purchase transaction data
CloudflareSecure API proxy & infrastructureAll AI requests are routed through Cloudflare Workers; rate-limiting counters stored in Cloudflare KV (auto-expiring, 48 hours to 365 days by tier — see Section 9)
Apple / GoogleAuthentication, push notifications, health data syncSign-in credentials (managed by Apple/Google), push notification tokens
USDA FoodData CentralNutrition reference dataSearch queries and barcode numbers, sent directly from your device — the service also receives ordinary request metadata (including your IP address) under its own policies
Open Food FactsBarcode product dataSearch queries and barcode numbers, sent directly from your device (plus ordinary request metadata, including your IP address); public data used under ODbL license

We encourage you to review the privacy policies of these third-party services. We are not responsible for the privacy practices of third-party service providers.

8.1 Ad Install Measurement (No Tracking)

When BodyDex is first installed, our own server sends a single "the app was installed" event to our advertising platform (e.g., Meta) so we can tell whether our ads work; only installs that followed one of our own ads are counted toward a campaign. The event carries a random, app-scoped install identifier (retained by us for up to 90 days for de-duplication), your platform and app version, and on Android the store referrer when present. It is sent by our own server — BodyDex contains no advertising or tracking SDKs— and contains no name, no email, no health data, and no advertising identifier. It is not linked to any data you enter in the app, and nothing further is ever reported after installation. On iOS, install counting additionally uses Apple's privacy-preserving SKAdNetwork / AdAttributionKit framework, which reports only aggregated campaign-level counts. We do not respond to these events with any form of profiling, retargeting, or data sharing.

9.Data Retention

  • Local data: Stored on your device indefinitely until you choose to delete it (via "Delete All Data" or by uninstalling the App). Because this data exists only on your device, we cannot recover it if the App is uninstalled or your device is lost, reset, or damaged. Profile → Export Data produces a portable copy of your records (JSON/CSV — a data copy, not a restorable in-app backup; image files and certain settings are not included).
  • Rate-limiting counters: Anonymous counters stored in our server infrastructure automatically expire and are deleted on a tiered schedule: daily usage counters within 48 hours, monthly usage counters within approximately 40 days, and lifetime free-tier anti-abuse counters (video recipe imports) within 365 days.
  • Anti-abuse device identifier: A minimal, app-scoped device identifier is retained for fraud and abuse prevention and intentionally survives "Delete All Data" (see Section 11.2). It is pseudonymous and not intended to directly identify you.
  • AI-processed data: Food photos, text messages, voice audio, and transcripts submitted for AI processing are NOT stored on our servers — they are processed transiently and discarded — with three scoped exceptions: opt-in scan-accuracy report photos (deleted within 90 days; see Section 6.1), video-import status records (deleted within 7 days; see Section 6.4), and the working copy of an Assistant reply that paused mid-answer, whose content we attempt to replace with a contentless record as soon as the reply finishes and which — then, or if that attempt does not succeed — we attempt to remove on the criteria stated in Section 6.2, where a failed attempt can leave it in place longer — read that section for the criteria and its limits.
  • Retention by AI providers: Our providers may retain submitted content under their own terms after we have discarded it. For the Bodydex Assistant, OpenAI states a default abuse-monitoring retention of up to 30 days (longer where required by law); we have not arranged zero-data-retention (see Section 6.2). Other providers' retention is governed by their published terms (see Section 8).
  • Feedback submissions: The backend copy is automatically deleted after 180 days; copies delivered to our internal support tooling are retained as long as needed to investigate and resolve the issue (see Section 3.3).
  • Subscription data: Managed by RevenueCat per their data retention policy. Cached subscription status on our server expires within 5 minutes.

10.Data Security

We take reasonable measures to protect your information:

  • Local encryption: Data on your device is stored in a local database protected by your operating system's built-in encryption at rest (iOS Data Protection / Android File-Based Encryption)
  • Transport encryption: All data transmitted between the App and our servers uses HTTPS/TLS encryption in transit
  • Secure proxy: AI service requests are routed through our secure server infrastructure — API keys are never exposed on your device
  • Server-side verification: Subscription status and rate limits are verified server-side to prevent tampering
  • Credential separation: The App includes only the public client credentials needed to access certain services; credentials capable of privileged access are kept server-side

While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

11.Your Rights

Because your data is stored locally on your device, you have direct, immediate control over your information at all times:

11.1 Right to Access

All your data is visible and accessible to you directly within the App at any time.

11.2 Right to Delete

You can permanently delete all data stored on your device through the App (Profile → Delete All Data). This action is irreversible and removes all personal data from the local database and signs you out. Feedback reports you may have submitted are retained as described in Section 3.3 (the backend copy auto-deletes within 180 days); subscription and billing records are managed by Apple, Google, and RevenueCat under their own policies. The anonymous device identifier used for rate limiting is preserved to prevent abuse but contains no personal information. Deleting local data does not delete exported files, device backups, records you wrote to Apple Health or Health Connect, or content already processed by our AI providers under their retention terms (Section 9). Uninstalling or reinstalling the App should not be relied on as a way to erase every copy.

11.3 Right to Export (Data Portability)

You can export your data at any time through the App (Profile → Export Data). Data is exported in portable formats (JSON and CSV) that you can save, transfer, or use as you see fit.

11.4 Right to Revoke Permissions

You can revoke health data, camera, microphone, notification, and photo library permissions at any time through your device's Settings. Revoking permissions may disable certain features but will not affect your existing data.

11.5 California Residents (CCPA)

If you are a California resident, you have the right to: know what personal information is collected, request deletion of your personal information, and opt out of the sale or sharing of your personal information. We do not sell or share your personal information. You can exercise your rights using the Delete All Data and Export Data features within the App, or by contacting us at .

Why that is not just about who pays whom. California defines a sale by reference to valuableconsideration, not only money, so the fact that we pay our AI providers rather than the reverse does not by itself settle the question. What settles it for us is the terms and the use. We disclose your data to a provider only in order to perform the feature you asked for, and we receive nothing of value in return — no money, no service credit, no data back. What each provider is then permitted to do with it is set by that provider's own terms and differs between them: Section 6.6 states which ones may use submitted content to improve their models, and we do not claim that every provider is contractually limited to our purpose. For the Bodydex Assistant, OpenAI's Data Processing Addendum records that OpenAI will not provide us with monetary or other valuable consideration in exchange for your data, that we have therefore not "sold" it, that OpenAI will not "sell" or "share" it, and that OpenAI will not process it outside our direct business relationship or combine it with data it holds about you from anywhere else. We run no advertising or tracking SDKs, and the install-measurement event in Section 8.1 carries no name, email, health data or advertising identifier.

11.6 European Users (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including the rights of access, rectification, erasure, restriction, data portability, and objection. Since your data is stored locally on your device, you can exercise most of these rights directly. For any requests you cannot fulfill through the App — including requests concerning the limited server-side records described in this policy — contact us at (or ) and we will respond within the timeframe required by applicable law — ordinarily within one month of receipt for GDPR and UK GDPR rights requests, extendable where the law allows. You also have the right to lodge a complaint with your local supervisory authority. UK users: we acknowledge data-protection complaints within 30 days, investigate them, and tell you the outcome.

Legal bases. Where the GDPR or UK GDPR applies, we process: Bodydex Assistant messages and context, including health data, on the basis of your explicit consent (Articles 6(1)(a) and 9(2)(a)); Apple Health / Health Connect data on the basis of the permission you grant on your device; subscription verification and delivery of the features you use on the basis of our contract with you (Article 6(1)(b)); rate limiting, abuse prevention, service monitoring, and install measurement on the basis of our legitimate interest in operating a secure, affordable service (Article 6(1)(f)); and feedback you choose to submit on the basis of your consent.

Your records that stay on your device. The App's purpose is to hold your records for you, and it holds them in a database on your device: we have no access to that database, it is not synced to us, and nothing in it is sent anywhere except as this policy describes. Where the GDPR or UK GDPR applies, our basis for providing that storage is the performance of our contract with you (Article 6(1)(b)) — it is the service you chose — and what goes into it is what you enter, import or ask the App to keep. When you withdraw a consent, that withdrawal ends the basis for the processing it covered: we stop sending. We do not treat a withdrawn consent as permission to keep anything, and we do not rely on it as a basis for the records that remain on your device. Those remain because deleting your own history without your asking would be a loss you did not choose — they are readable and deletable by you, and Section 11.2 and Section 6.2 name the controls. If you would rather they were gone, use them; Delete All Data removes everything the App holds.

International transfers. Data processed by our online features is transmitted to infrastructure operated by our service providers primarily in the United States and, where our edge network operates, in other countries. Bodydex is operated by Daniel Bobunov, a sole trader established in New Jersey, United States, who is the controller for the processing described in this policy and the customer under each of the provider agreements below. Where the GDPR or UK GDPR applies, these are the safeguards we rely on for transfers to the providers named in this list, and we do not rely on your consent as the transfer mechanism for any of them:

  • OpenAI (Bodydex Assistant; parsing voice-log transcripts). We use OpenAI's published, non-negotiated terms. Its Services Agreement provides at Section 5.3 that if the customer uses the services to process personal data, OpenAI and the customer will comply with OpenAI's Data Processing Addendum, "which is incorporated by this reference into the Agreement" — so the Addendum governs our account without a separate signature. Under that Addendum, EEA and Swiss data is processed by OpenAI Ireland Limited, and onward transfers out of the EEA or Switzerland are made on the basis of agreements containing the EU Standard Contractual Clauses or an adequacy decision under Article 45 GDPR; UK data is processed by OpenAI OpCo, LLC under the EU Standard Contractual Clauses as amended by the UK International Data Transfer Addendum, which the Addendum deems entered into between us as data exporter and OpenAI OpCo, LLC as data importer, with the Information Commissioner's Office as the competent supervisory authority. Read them at openai.com/policies/services-agreement and openai.com/policies/data-processing-addendum.
  • Cloudflare (the server proxy every AI request passes through, the rate-limiting counters, and the speech-to-text service used for voice features). Cloudflare's Self-Serve Subscription Agreement states that where customer content includes personal data of European data subjects, Cloudflare acts as processor or sub-processor and will handle it in compliance with Cloudflare's Data Processing Addendum, "which is hereby incorporated by reference into this Agreement." That Addendum applies the EU Standard Contractual Clauses to restricted transfers to Cloudflare, Inc. (United States) and deems the UK International Data Transfer Addendum executed between us and Cloudflare for UK transfers. Read them at cloudflare.com/terms and cloudflare.com/cloudflare-customer-dpa.
  • Apify (retrieving a video you share for recipe import). Apify's Data Processing Addendum is incorporated into its agreement so that "no separate signature is required," and incorporates the EU Standard Contractual Clauses and, for UK transfers, the UK Addendum. Read it at docs.apify.com/legal/data-processing-addendum.

The other providers named in Section 8 receive the content described for each feature in Section 6, and Section 6.6 states how each of them may use it under its own terms. Section 8 is the full list of recipients. If you want a copy of the agreement or transfer clauses we rely on for a particular provider, ask us at and we will send you the version that applies to our account. Your consent is a lawful basis for the processing, not a transfer tool. The Bodydex Assistant sends health data only after your explicit consent, and that consent is given in the knowledge that the data will be processed in the United States; it does not replace the safeguards above, and withdrawing it stops further sending (Section 11.7).

11.7 Right to Withdraw Consent

You can withdraw any consent you gave in the App as easily as you gave it, from the same device: Bodydex Assistant — Profile → Bodydex Assistant → Withdraw consent stops new Assistant requests at once, including further requests from a reply already in progress, and the Assistant stays off until you consent again. Withdrawing does not delete anything: your setup, conversations, memory, and notes stay on your device. Redo Assistant Setup is a separate, destructive option that also clears those. Health platforms — revoke access in your device's Settings; Everything — Profile → Delete All Data. Withdrawal does not affect the lawfulness of processing before withdrawal and cannot recall information already received by a provider, which remains subject to that provider's retention (Section 9). You can also contact us at .

11.8 Connecticut Residents

Since July 1, 2026, the Connecticut Data Privacy Act applies to any person that controls or processes consumers' sensitive data, without a volume threshold (Conn. Gen. Stat. § 42-516(2), as amended by P.A. 25-113, § 6). We process exactly that, so the Act applies to us in full and we claim no exemption. Our Consumer Health Data Privacy Policy sets out the applicability reasoning, the categories, the recipients, the 45-day response deadline and the 60-day appeal deadline.

As a Connecticut resident you may confirm whether we process your personal data and access it, correct inaccuracies in it, delete it, obtain a portable copy of it, and opt out of targeted advertising, the sale of your personal data, and profiling in furtherance of automated decisions that produce a legal or similarly significant effect. Access, export and deletion are direct in the App (Sections 11.1–11.3), and you correct a record by editing it where you entered it. For anything else, or to appeal a refusal, email — put "health data appeal" in the subject for an appeal; we answer an appeal in writing, with reasons, within 60 days, and if we deny it we tell you how to complain to the Connecticut Attorney General.

The three opt-outs are empty for us, and we say so rather than offering a control that would do nothing: we do not sell personal data, so the list of third parties it has been sold to is empty; we display no advertising in the App and do no targeted advertising; and we do not profile you in furtherance of automated decisions that produce a legal or similarly significant effect. We do not collect, use or sell personal data for the purpose of training large language models (Section 6.6). If any of that changes, this section changes with it and we will tell you before it takes effect (Section 15).

12.Children's Privacy

BodyDex is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at and we will take steps to delete such information.

Users between the ages of 13 and 18 may use the App only with the consent and supervision of a parent or legal guardian.

13.Consumer Health Data Privacy Policy

Our Consumer Health Data Privacy Policy explains the consumer health data we process, its sources and purposes, the recipients it is shared with, and how to exercise your applicable rights, for the purposes of the Washington My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act. It is published at its own address and linked from every page of this site. In short: consumer health data is stored on your device for tracking; selected records and summaries are processed through the online features described in Section 6, with your explicit consent for the Bodydex Assistant; we do not sell it, do not share it with advertisers or data brokers, and do not use geofencing.

14.Website Privacy

The BodyDex marketing website (bodydex.app) uses Cloudflare Web Analytics to measure page traffic and understand which pages visitors reach. It is privacy-first by design: it uses no cookies, no tracking pixels, and no fingerprinting, and it does not track you across other websites. It records only aggregate, non-identifying information such as page views, referrer, country, and device type.

We do not collect personal information through the website, and we do not sell any data. The website is a static informational site hosted on Cloudflare Pages.

15.Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this page. It is your responsibility to review this Privacy Policy periodically for changes.

We will notify you of material changes and obtain fresh consent before changed processing where the law requires it. Continued use alone does not provide that consent.

If we make material changes to the way we handle your data, we will make reasonable efforts to provide notice through the App or our website.

16.Contact Information

For questions, concerns, or requests regarding your privacy or this policy:

Privacy inquiries:

General legal inquiries:

Developer: Daniel Bobunov

Terms of Service →Data Sources →
BodyDex

Your nutrition, decoded. AI food scanning, peptide tracking, fitness logging, and an AI coach — all in one app.

Guides

  • All guides
  • AI calorie counter
  • AI macro tracker
  • GLP-1 tracker
  • Peptide tracker
  • Supplement tracker

Compare

  • All comparisons
  • vs MyFitnessPal
  • vs Cal AI
  • vs MacroFactor
  • vs Lose It!
  • vs Yazio
  • vs Cronometer
  • MyFitnessPal alternatives
  • Cal AI alternatives
  • Download iOS
  • Download Android

Company

  • Get the app
  • Support
  • Accessibility
  • Press
  • Data sources
  • Privacy
  • Consumer Health Data Privacy Policy
  • Terms
© 2026 BodyDex. All rights reserved.Made with real data · Sourced openly

BodyDex is a nutrition tracking tool, not a medical device. Information provided is not medical advice. Always consult a healthcare professional before making dietary, supplement, or peptide changes.