Privacy Policy

Your Privacy Matters: Body Journey is committed to protecting your personal data. Your photos, weight data, workout information, and progress data are stored securely on your device with encrypted storage.

1. Information We Collect

1.1 Personal Data You Provide

When you use Body Journey, you may provide:

Location Data: Body Journey does NOT collect, access, or use your location data. The app does not request location permissions and does not track where you are.

1.2 Automatically Collected Information

Based on your consent level, we may collect:

2. How We Use Your Information

Your data is used to:

Heart Rate Monitoring: Body Journey uses your device's body sensors (heart rate monitor on compatible devices or wearables) during workout sessions if you choose to enable this feature. Heart rate data is stored locally on your device and only synced to Apple HealthKit or Health Connect if you enable health integration. This data is never sent to third-party servers.

3. Data Storage and Security

3.1 Local Storage

All your photos, weight data, and workout information are stored locally on your device using Hive encrypted database. We use Flutter Secure Storage and industry-standard encryption to protect your sensitive information. Your data remains on your device and is never uploaded to our servers.

3.2 Biometric Authentication

If you enable biometric authentication (Face ID, Touch ID, or fingerprint), this data is handled entirely by your device's operating system and secure enclave. Biometric data never leaves your device and is never transmitted to our servers or any third party.

3.3 Strava Integration (Optional)

If you choose to connect your Strava account and enable auto-sync:

3.4 Health Data Integration

If you enable Health app integration:

Improved Health Integration: We've refined our Health integration to prevent duplicate workouts. Body Journey now uses a smart, write-only model for workouts, nutrition, and heart rate. We only READ weight data from your Health app. This means:

  • ✅ Your Apple Watch/Android Wear workouts sync directly to Body Journey with complete details
  • ✅ These workouts export to your Health app once - no duplicates!
  • ✅ Weight data syncs both ways seamlessly
  • ✅ No more workouts showing "0/0 sets" from incomplete Health imports

Health data permissions are requested separately and you have granular control over each data type. You can enable or disable sync for weight, workouts, heart rate, and nutrition independently. This data is governed by Apple's HealthKit privacy policy or Google's Health Connect privacy policy.

4. Data Sharing and Disclosure

We do not sell, rent, or share your personal data with third parties, except:

5. Privacy Consent Levels

Body Journey implements granular privacy controls with four consent levels:

You can change your privacy consent level at any time in Settings > Privacy & Data. On first launch, you'll be prompted to choose your preferred level. GDPR and CCPA rights are fully supported.

6. Third-Party Services

Body Journey uses the following third-party services (based on your consent and feature enablement):

AI Photo Processing: Body Journey only processes food photos through AI when you explicitly tap "Analyze" on a food photo. Your progress photos (front, side, back) are NEVER sent to AI services and remain stored securely on your device only.

These services have their own privacy policies. We encourage you to review them:

7. Your Rights and Choices

You have complete control over your data with the following rights:

8. Children's Privacy

Body Journey is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us to have it removed.

9. International Data Transfers

Your data is primarily stored on your device. If you enable analytics, data may be processed by Firebase (Google) servers in accordance with Firebase's data processing locations. These transfers are protected by appropriate safeguards including encryption and compliance with GDPR, CCPA, and other data protection regulations.

10. Data Retention

We retain your data according to the following policies:

You can delete all your data at any time from Settings within the app. Deleting the app will remove all local data from your device.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of any material changes by:

Your continued use of the app after changes constitutes acceptance of the updated policy. If you do not agree with changes, you can revoke consent in Settings > Privacy & Data or delete the app.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Email: privacy@bodyjourney.app

Subject Line: Privacy Policy Inquiry

13. Additional Information for California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of Personal Information Collected:

Categories of Personal Information NOT Collected:

We do not sell or share your personal information for cross-context behavioral advertising.

14. Additional Information for European Users (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing:

To exercise these rights, please contact us using the information provided above or manage settings directly in the app.

15. Security Measures

We implement industry-standard security measures to protect your data:

While we implement strong security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using industry best practices.

Privacy by Design: Body Journey is built with privacy as a core principle. Your fitness journey data stays on your device. Health integration and analytics are optional features that you explicitly enable. You have complete control over your data at all times.