BodyM is designed for wellness tracking, education, AI-assisted organization, community support, and supplement commerce. It is not a medical provider, emergency service, pharmacy, or replacement for your clinician.
01

Scope

This Privacy Policy explains how BodyM collects, uses, discloses, and protects information when you use our websites, mobile applications, tracking tools, community features, AI features, supplement shop, subscriptions, and related services.

By using BodyM, you acknowledge this Privacy Policy. If you do not agree, do not use BodyM.

02

Information we collect

The information we collect depends on how you use BodyM. It may include information you provide directly, information created through your use of the service, and information from integrations you choose to connect.

  • Account information: name, username, email, authentication identifiers, profile settings, membership tier, support messages, and account preferences.
  • GLP-1 journey data: medication name, dose label, injection date and time, injection site, side effects, symptoms, severity, weight, height, BMI, goals, meals, supplements, body or face progress photos, notes, and progress history.
  • Community content: posts, comments, likes, replies, reports, display name, avatar, tags, and profile context you choose to show.
  • AI Copilot data: questions, conversation history, logs or context included in prompts, AI responses, and feedback about answers.
  • Shop and subscription data: products viewed or selected, checkout metadata, billing status, shipping information, discount use, and purchase support requests. Payment card details are processed by payment providers and are not stored by BodyM.
  • Device and usage data: IP address, app version, device type, browser, operating system, pages viewed, crashes, diagnostics, approximate location from IP, referring links, cookies, and similar technologies.
  • Health integration data: if you connect Apple Health or Health Connect, BodyM may read weight, steps, distance, active calories, total calories where available, sleep duration, resting heart rate, and heart-rate variability. Historical access supports the 7, 30, and 90-day trends you request. Background access is used only after you separately enable Automatic health sync.
03

Sensitive health and wellness data

BodyM may process information that could be considered sensitive health, wellness, biometric-adjacent, or consumer health data under some laws. We use this data to provide tracking, personalization, AI summaries, community context you request, reminders, and safety-oriented product experiences.

BodyM does not sell your identifiable health journey data. We do not use Apple Health or similar health integration data for advertising or sell it to data brokers.

BodyM asks for authorization before connecting a system health source. Automatic sync and AI Coach access to connected health data are separate, off-by-default controls. You can change system permissions, disable either control, request deletion, or contact us at any time.

04

Face progress photos

If you choose to add face progress photos, BodyM collects the image you select or upload, the date and time associated with the entry, the progress-photo category, and any notes or tags you add. BodyM does not collect Face ID data, face templates, facial geometry, facial landmarks, biometric identifiers, or identity-verification data from these photos.

We use face progress photos only to show your private progress timeline, help you compare your own GLP-1 journey over time, and provide optional AI context when you intentionally include a photo in an AI Coach request. BodyM does not use face progress photos to identify you, authenticate you, train face-recognition systems, or target advertising.

Face progress photos may be processed by service providers that operate BodyM storage, backup, security, support, and optional AI routing. We do not sell face progress photos or share them with advertisers. They are not visible to other users unless you choose to post or share them in a community or export flow.

Face progress photos are stored with your account or local app data, depending on the feature used. We retain them until you delete the photo or your account, subject to limited backup, security, legal, or dispute-resolution retention described in this policy.

05

How we use information

  • Provide and maintain accounts, authentication, tracking, community, AI, shop, subscriptions, reminders, and support.
  • Generate charts, summaries, goal progress, timeline views, AI Copilot answers, clinician-ready exports, and user-requested reports.
  • Personalize product experiences, including community filters, supplement pack recommendations, Pro prompts, and onboarding.
  • Process checkout, subscriptions, refunds, shipping, fraud prevention, and billing support.
  • Moderate community content, investigate abuse, enforce our Terms, and protect user safety.
  • Improve reliability, debug crashes, analyze usage, prevent spam, and secure the service.
  • Comply with legal obligations and respond to lawful requests.
06

AI processing

Before the mobile app sends a real AI Coach request, BodyM asks for your permission. If you allow it, BodyM sends your question, recent AI Coach conversation, relevant user-entered GLP-1 profile or wellness logs, and only photos you intentionally attach through our backend to OpenRouter, our third-party AI routing provider. Connected Apple Health or Health Connect observations are included only when you separately turn on Use health data in AI Coach. OpenRouter forwards the request to the configured model provider so it can generate the response you requested. If you decline, BodyM does not send the AI request.

Health summaries obtained through the direct Oura, WHOOP, Google Health, or Suunto API are excluded from AI Coach requests.

AI request data is used to provide the response and operate, secure, and troubleshoot the AI feature. It is not shared with advertisers or used by BodyM for targeted advertising. You can stop future sharing by not using AI Coach and can contact support@bodym.me to request deletion help.

Do not enter information you do not want processed by AI systems. AI output is educational support and should not be treated as medical advice. We may use safety filters, logging, or review workflows to detect abuse, improve reliability, and route serious risk language to appropriate disclaimers.

07

Community visibility

Community posts, comments, profile tags, avatars, and interaction counts may be visible to other users or the public depending on the product surface. Do not post information you want to keep private.

Even if you delete content, copies may remain in backups, moderation logs, user notifications, search indexes, or screenshots outside BodyM's control.

08

How we share information

We share information only as needed to operate BodyM, fulfill your requests, comply with law, or protect users and the service.

  • Service providers: hosting, database, authentication, analytics, crash reporting, support, email, notifications, AI routing, payment processing, shipping, and fulfillment.
  • Payment and commerce partners: payment processors such as Stripe, app stores, tax providers, shipping carriers, and product fulfillment partners.
  • Community users and public viewers: content and profile information you choose to post or make visible.
  • Legal, safety, and compliance recipients: when required by law, legal process, fraud prevention, security, or to protect rights and safety.
  • Business transfers: if BodyM is involved in a merger, acquisition, financing, reorganization, or sale of assets.
09

Medical and HIPAA status

BodyM is a consumer tracking, coaching, community, and wellness-support service. BodyM is not a medical practice, pharmacy, telehealth provider, or HIPAA covered entity for general app use.

The mobile app does not select or sell GLP-1 medication, issue online prescriptions, make refill decisions, fulfill prescriptions, or arrange medication delivery. Medication and injection information in BodyM is entered by the user for personal tracking.

10

Apple Health, Health Connect, Oura, WHOOP, Google Health, Suunto, and device integrations

If you choose to connect health or device integrations, you control what categories are shared through your device settings. You can revoke access through the relevant platform settings.

For Apple Health and Health Connect, BodyM displays each authorized category in Health Intelligence: steps, distance, active calories, total calories where available, sleep, resting heart rate, heart-rate variability, and weight. Historical access supports real 7, 30, and 90-day trends. BodyM does not create placeholder observations for missing data.

Automatic health sync is optional and off by default. On Android, BodyM requests Health Connect background access only after you enable Automatic health sync. On iOS, BodyM enables Apple Health background delivery only after you enable Automatic health sync. Disabling it stops BodyM's background refresh task.

Use health data in AI Coach is a separate optional control and is off by default. When disabled, connected Apple Health and Health Connect observations are not included in AI Coach context.

BodyM stores authorized health summaries with your account so your trends can remain available across your devices. We use health integration data only to provide user-facing tracking, summaries, sync, and optional AI features you request. We do not sell this data, use it for third-party advertising, or share it with advertisers.

Oura data connected through the Oura API is used only for your BodyM tracker and progress displays. It is not sent to BodyM AI Coach or another AI model through the direct Oura API. Disconnecting Oura revokes access and deletes the Oura data stored in your BodyM account.

WHOOP data is collected only after you expressly authorize the requested categories. BodyM stores authorized WHOOP summaries for your tracker and progress displays until you disconnect WHOOP or delete your account. It is not sent to BodyM AI Coach, another AI model, or advertisers. Disconnecting WHOOP revokes access and deletes the WHOOP data stored in your BodyM account.

Google Health data is collected only after an in-app disclosure and your affirmative OAuth consent. BodyM requests read-only activity and fitness, health metrics and measurements, and sleep categories for your private Tracker. It is not used for advertising or sent to BodyM AI Coach in this release. Disconnecting Google Health revokes Google access and deletes the Google Health data stored in your BodyM account.

BodyM's use and transfer of information received from Google Health API will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.

Suunto data is collected only after you authorize BodyM through Suunto. BodyM stores read-only activity, sleep, recovery, and workout summaries for your private Tracker. It is not used for advertising or sent to BodyM AI Coach in this release. Disconnecting Suunto revokes Suunto access and deletes the Suunto data stored in your BodyM account.

11

Cookies, analytics, and similar technologies

We may use cookies, local storage, SDKs, pixels, or similar technologies to keep you signed in, remember preferences, understand performance, measure product usage, prevent abuse, and improve the service.

Your browser or device may let you limit cookies or tracking. Some features may not work correctly if these technologies are disabled.

12

Retention

We keep information for as long as needed to provide BodyM, maintain your account, comply with legal obligations, resolve disputes, prevent abuse, support safety, and improve the service.

You may request deletion, but we may retain limited information where required or permitted by law, such as security logs, transaction records, tax records, legal records, backups, and de-identified or aggregated data.

13

Your choices and rights

  • Access, update, or correct certain account and profile information in the app.
  • Delete community content where product controls allow it, or contact us for help.
  • Request access, correction, deletion, portability, or restriction of certain personal information where applicable law provides those rights.
  • Use in-app account deletion controls where available, including app-store-required deletion paths.
  • Withdraw consent for optional integrations through device settings or disconnect a wearable account in BodyM.
  • Opt out of non-essential marketing communications by using unsubscribe links or contacting us.
  • Delete your account from the app settings, or contact support@bodym.me if you need help.
14

US state privacy and consumer health data rights

Depending on where you live, you may have rights to know, access, correct, delete, obtain a copy of, or appeal decisions about your personal information. Some laws also provide rights related to sensitive or consumer health data.

BodyM does not sell identifiable consumer health data. If we introduce targeted advertising or data sharing that triggers opt-out rights, we will provide appropriate controls.

We may create aggregated or de-identified statistics to understand product quality, community trends, and content needs. We do not attempt to re-identify de-identified data except as permitted by law for security or validation.

15

Security

We use administrative, technical, and organizational safeguards designed to protect information. No internet or mobile service is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed.

16

Children

BodyM is not intended for children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided information to BodyM, contact us so we can review and delete it as appropriate.

17

International users

BodyM is operated for users in the United States unless otherwise stated. If you access BodyM from outside the United States, your information may be processed in the United States or other countries where our providers operate.

18

Updates

We may update this Privacy Policy as the product, law, or our data practices change. If changes are material, we will provide notice when required by law and update the date above.

19

Contact

For privacy requests, deletion requests, or questions, contact support@bodym.me.

Questions or requests?

Email support@bodym.me for privacy requests, account deletion requests, billing questions, or legal notices.