Privacy Policy
BodyLens · Effective June 1, 2026
1. Overview
BodyLens is an offline-first health tracking app. Your health data is stored locally on your device by default. This policy explains what data we collect, why, and how it is handled.
We do not sell your personal data to third parties.
2. Data We Collect
Data you enter
- Food diary entries (food name, calories, macronutrients, date)
- Daily body weight and body fat percentage
- Water intake, step count, and sleep duration
- Calorie burn (manually entered or imported)
- Workout activity logs
- Saved meals and recipes (synced to cloud when signed in)
- Nutrition targets, goal type (weight loss / gain), and app settings
- Profile information (name, age, sex, height, weight) — stored only on-device, never uploaded
Data from integrations (optional)
- Apple Health: Steps, sleep, calorie burn, weight, body fat percentage, and workout data — only when you grant permission. Read from HealthKit; never written back without your action.
- Strava: Activity name, type, duration, and distance from your connected Strava account. Requires explicit OAuth sign-in.
Camera and barcode data
- AI food scan: When you use the food photo scanner, the image is sent to our backend (Supabase edge function) for AI analysis. The image itself is not stored — only the identified food name, confidence score, and a hash of the image are saved locally on your device for scan history.
- Barcode scan: The barcode number is sent to Open Food Facts (openfoodfacts.org) to retrieve nutritional information. No personal data is included in this request.
Location data (optional)
- If you set up workout location reminders, BodyLens uses background location monitoring (iOS “Always” permission) to detect when you leave a saved workout location such as a gym or court. This triggers a smart recovery reminder notification.
- The names and coordinates (latitude, longitude, radius) of your saved locations are stored only on your device and are never uploaded to our servers.
- Location monitoring only occurs while you have saved locations set up. You can remove all locations at any time from Settings → Workout Locations, which also stops background monitoring.
Technical data
- Supabase authentication tokens (email address used to create your account)
- App usage metadata required for cloud sync
- Daily AI scan count (stored locally for rate-limiting purposes)
3. How We Use Your Data
- To display your diary, insights, and history within the app
- To sync your data across devices via Supabase (our cloud backend)
- To generate AI-powered weekly, monthly, and yearly insights using Claude (Anthropic)
- To send meal reminders and workout recovery alerts (only if enabled)
4. AI Features
- Weekly / monthly / yearly insights:Aggregated metrics (e.g. average calories, workout frequency, weight trend) are sent to Anthropic's Claude API to generate your narrative summary. Individual food entries and personal identifiers are not sent.
- AI food photo scan: A photo you take is sent to our backend for AI analysis to identify foods and estimate macros. The image is not stored on our servers after processing.
- Voice logging: Speech-to-text transcription is handled on-device by your operating system. The resulting text is parsed locally — no audio or text is sent to our servers.
Anthropic's data use is governed by their privacy policy.
5. Data Storage
- Local storage: All data is first stored on your device using SQLite. The app is fully functional without a network connection.
- Cloud backup: When signed in, the following data syncs to Supabase (hosted on AWS): daily logs, food diary entries, food database, saved meals and recipes, workout logs, and activity types. Supabase stores data in a region within the United States.
- On-device only (never uploaded): Profile data (name, photo, age, sex, height), workout location geo-fences, AI scan history, and scan usage counts are stored only on your device.
6. Data Sharing
We share data with the following third parties only as needed to operate the app:
- Supabase — cloud database and authentication
- Anthropic — AI insight generation (aggregated metrics only)
- Strava — if you connect your account
- Open Food Facts — barcode number sent when you scan a food product to retrieve nutritional data. No personal information is included.
We do not share data with advertisers, data brokers, or analytics platforms.
7. Your Rights
- Access: All data you've entered is visible directly in the app.
- Deletion: You can delete your account from Settings → Account → Delete Account. This permanently erases all cloud data and wipes the local database. Deletion is irreversible.
- Portability: Contact us to request an export of your data.
8. Children
BodyLens is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
9. Medical Disclaimer
BodyLens is not a medical device and does not provide medical advice. Content is for informational and educational purposes only. Always consult a qualified healthcare professional before making any health, nutrition, or fitness decisions.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via an in-app notice. Continued use of the app after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this policy? Email us at privacy@lenslabs.app.