In force

Personal-data processing policy

This document describes the BodyPace mobile app: what it stores, why it needs it, who else sees it, and how to take it out or delete it. The bodypace.app site is covered by a separate document. We tried to write it so that reading it once is enough.

Version 2026-08-31In force since 31 August 20269 minutes to read

1. What this document covers

It covers the BodyPace app: the account, the training diary, body measurements, and the access you grant a trainer. There is nothing else in the app today.

The parts we talk about as plans — food, habits, health — do not exist, neither in the interface nor in the database. We deliberately do not describe them here in advance: a policy that promises to process what does not exist protects nobody. When a section arrives, this document changes before it does, and you will see a new version and a new date.

The bodypace.app site is covered separately, in the site privacy policy. The site takes nothing from you and has no bearing on what you write in the app.

The app is free. We charge neither the people training nor the trainers, and we do not make money from your data — not through advertising, not by selling it, not by passing it on.

2. What we store

Only what the record needs in order to work. Below is the whole list; the app collects nothing beyond it.

The account. Your email address, the name you gave when registering, and a fingerprint of your password. We do not store the password itself and cannot recover or show it — only compare it with what you typed. If you sign in with Google or Apple we hold no password at all: instead we keep the identifier those services issue specifically for signing in to BodyPace. It gives no access to your mail or to your account with them.

Verification and sign-in. A mark that your address is confirmed, a counter of failed sign-in attempts, a temporary lock after a run of failures, and fingerprints of the six-digit verification and recovery codes. Codes live for fifteen minutes and are not stored in the clear.

Sessions. Fingerprints of the tokens the app uses to prove it is still you. The tokens themselves are not stored on the server. Every refresh issues a new token and retires the old one — and if the old one is ever presented again, the whole chain of sessions is closed.

Training. Programmes and workout templates, plans for particular days, the sessions you actually did and the sets in them: weight, repetitions, duration, distance and an “easy” or “hard” mark. Plus your notes on a session, on an exercise and on a single set, and when a session started and ended.

Body measurements. Height, weight, age, sex, activity level and goal — the figures you enter yourself. Beside them the app calculates and stores a daily calorie target: the formula, the basal rate, the activity factor and the resulting number. That is arithmetic on your own figures, not a medical opinion.

Trainer access. Who has access, which areas are open, what state it is in, the dates of the invitation, acceptance, refusal and revocation, the version of the consent you confirmed, and the reason for a refusal if the trainer gave one.

Technical. The created and last-changed dates on every record, a mark that you have been through the app's first-run introduction, and ordinary server logs — time of request and result. Logs are how we find failures and notice password guessing.

We do not request or store location.The app does not ask for access to contacts, photos, the camera or the microphone.There are no advertising identifiers, no behavioural analytics and no crash reporting.We do not collect diagnoses, prescriptions, test results or medication — there are no screens for them and no tables in the database.There are no payment details: the app is free and payments do not exist in it.

3. Why we need it

The account and the confirmed address are what make the records yours and nobody else's, and what let you get back in if you forget your password. The attempt counter and the lock protect you from somebody guessing it.

Training and measurements are the content of the app. We store them so that you can see your own history and a trainer can see what you opened to them. The calorie target is computed from your own figures and shown beside them.

The access data exists so that you can see at any moment who has what, and close it. The consent version is kept so that a year from now you can look at what you agreed to instead of trying to remember.

Server logs are for operation and safety: finding a failure, noticing a run of guesses. We do not use them to build a picture of a user.

4. What we do not do

This list is not a polite phrase. It is a set of things that exist neither in the code nor in the plans for the coming versions.

We do not sell data and do not pass it to advertisers, data brokers or insurers.We show no advertising and build no advertising profiles.We do not track you across other apps and websites.We do not train machine-learning models on your records.We do not read your records out of curiosity: access to the database belongs to those who need it to run the service, and it is limited.We pass data to nobody on our own initiative.
The one exception is a lawful demand we are obliged to obey. If that happens and the law does not forbid us from saying so, we will tell the person it concerns.

5. What a trainer sees

Nothing, until you open access. A trainer cannot find your record, look into it, or learn that it exists — not until you accept their invitation or they accept yours.

Once access is open, the trainer sees only the areas it covers: training, and body measurements if you left that area open. Of your notes they see only the ones you marked as visible to them.

A trainer can build and change your future programmes and sessions and write notes — those appear in your record with their name and the date. Past entries a trainer cannot change: the result is written by you.

Access is revoked in one step, without giving a reason. After that the trainer stops seeing new entries. The history stays with you in full — including the trainer's notes, with their authorship.

We do not check trainers' qualifications and are not answerable for the content of their programmes. Who gets into your record is your decision.

6. Who else is involved

Some jobs are done by outside services so that the app can work. The full list is below. Each of them receives exactly what its job requires and nothing more.

There are no other services in the app: no analytics, no advertising networks, no crash-reporting systems.

Resend — sends the letters carrying verification and recovery codes. Receives your email address and the text of the letter.Google — sign-in with a Google account, if you use it. Google tells us an identifier and an email address; it learns nothing about what you do inside the app.Apple — sign-in with an Apple ID, on the same terms. If you hid your address with “Hide My Email”, we receive the relay address and never see the real one.Firebase — holds the keys the app uses to confirm a Google sign-in. Your records never reach Firebase.The hosting provider for the server and the database — the ground all of this runs on.
The host for the server has not been chosen yet, and we are not naming one in advance rather than write something untrue. As soon as the choice is made, the provider and the country will be named here and the document will take a new version.

7. What stays on your device

The diary is written on the device first and only then goes to the server. That is deliberate: a set is logged in a gym, where there may be no signal.

So your phone holds a local copy of your records, and the session keys live in the system's secure storage — Keychain on iOS, Keystore on Android. We have no access to that storage: the operating system controls it.

If you delete the app, the local copy and the session keys go with it. The records on the server stay — to remove those you delete the account.

8. How long we keep it

Records are kept for as long as the account exists. A diary is useful because it remembers; deleting history on a schedule would defeat the very thing people keep one for.

Verification and recovery codes live fifteen minutes and are retired the first time they are used. A session refreshes while you use the app and closes when you sign out.

When you delete the account, we delete your records. Copies may remain in database backups for a time — that is a property of backups anywhere; they are overwritten as they rotate and are used for nothing except recovery after a failure.

Notes a trainer wrote in your record are deleted along with the record. The trainer does not keep a copy.

9. Your rights

The data is yours. You may find out what is held about you, receive it in a readable form, correct what is wrong, and delete all of it along with the account.

There are no buttons in the app for export and deletion yet — we do it by letter. Write to privacy@bodypace.app from the address the account is registered to and say what you need. We answer within thirty days, usually sooner.

Revoking a trainer's access needs no letter: it is one step on the “My trainer” screen, instant, and no reason is required.

Find out what data exists about you.Receive a copy of your records.Correct anything inaccurate.Delete the account and the records.Revoke access you granted somebody.
Export and delete buttons will be in the app itself before it is published in the stores — that is their requirement, and we agree with it. Until the app is out, a letter remains a working route.

10. How we protect it

Passwords are stored as a fingerprint produced by Argon2id, an algorithm built for exactly this. The original password cannot be recovered from it.

Verification codes and session tokens are stored as fingerprints too, rather than in the clear: a database in the wrong hands must not hand over live access. Traffic between the app and the server runs over a protected connection.

Sessions are built so that theft is visible: every refresh issues a new token and retires the previous one, and presenting a retired one closes the whole chain.

None of this makes the system invulnerable, and we do not claim it does. If a breach happens anyway, we will tell the people it touched and describe what occurred.

11. Age

The app is meant for people of sixteen and over. We do not verify age at registration — it cannot be done reliably — but we do not build for children either: there is no children's content and no mechanism for a parent's consent.

If it turns out an account belongs to somebody under sixteen, write to us and we will delete the account and the records.

12. Changes and contact

This document will change: the app grows, and every new section changes what we store. The rule is simple — the document changes before the feature, not after it.

Every version carries its date in the heading. Earlier versions stay available at their own addresses, so you can look at what was in force when you agreed to it.

The operator is not registered yet: the project has no legal entity. As soon as there is one, its name and address will be given here and the document will take a new version.

Questions, export and deletion requests, complaints — privacy@bodypace.app. We answer by letter.

A question about this document — write to the channel. We will answer, and we will fix the wording if it is murky.