Bodyper Privacy Policy
Version: 1.0.0 Language: English (en) Effective at: 2026-09-26T16:30:00Z Status: Approved
1. Controller and contact
The controller of your personal data is Perplatform Oy, Business ID 3568783-4, Vilkastuksenkatu 7, 20320 Turku, Finland. Email: support@bodyper.com. You can write to us in English or Finnish.
This Policy covers the Bodyper mobile app, including use without an account (“guest use”), Bodyper accounts, our public website, synchronization, the exercise catalogue, subscriptions, reports and support. It does not cover the independent services of an app store or a sign-in provider, which have their own privacy notices. Contact us with privacy questions or requests about your rights. Please do not send passwords, identity documents or unnecessary health information by email.
2. Important points
- Your workouts, measurements, goals and private exercises are private to your account. Bodyper has no public social feed.
- You can use Bodyper without an account. Guest data stays on your device and is uploaded to an account only if you later sign in and choose to upload it.
- Body measurements and training information can reveal information about your health. An account needs your separate, explicit consent to cloud processing of this data, which you can withdraw at any time. Accepting the Terms is not this consent.
- You must be at least 16 years old to have an account (section 11).
- Apple or Google handles Premium payments. We receive the purchase evidence and status needed to verify your access, never your full card details.
- We do not sell personal data, use it for targeted advertising, send marketing emails or marketing notifications, or use third-party advertising analytics. The app does not use HealthKit, Health Connect, nutrition tracking or GPS.
- Our app, backend and websites send error and crash reports to Sentry. They do not contain your account identifier, email address, name or training data. In the app, Send crash reports is on by default, and you can turn it off in App settings → Privacy (section 3).
- Account export and deletion are free. Deleting your account or withdrawing your consent does not cancel an app-store subscription.
3. Personal data we process
Account and settings
We process an account identifier, your email address, your sign-in method, session and security information, and password-verification data handled by our authentication service (Supabase Auth). Sign in with Apple or Google can provide the identity and email or profile details you authorize in that flow; we never receive the password to your Apple or Google account. Apple may give us a private relay email address. Our authentication service sends account emails, such as sign-up confirmations, sign-in codes, password-recovery and email-change messages, through Resend.
An email address and a password, or an Apple or Google sign-in, are needed to create an account; without them we cannot provide one. If you start a Google or Apple sign-in but do not finish creating the account, our authentication service may already have created a basic sign-in record containing your provider identity and email address. It gives no access to Bodyper, and you can ask us to delete it.
Profile information includes your optional display name, language, time zone and unit preference. Device settings include theme, date and time formats, week start, workout settings and similar selections. Email changes and privacy requests also create verification and workflow records.
Using Bodyper without an account
When you choose Continue without an account, the app creates a separate local guest area on your device with a generated local identifier. No Bodyper account or authentication identity is created. The workouts, programs, custom exercises, body measurements, history, corrections, local statistics and settings you create as a guest are stored only on your device. Our servers do not receive them, and synchronization, subscriptions, server receipts and cloud processing are not used for guest data.
Without an account, the app still downloads the published exercise catalogue and exercise media from our backend. These requests carry no account identifier and no guest data. Like any internet request, they reveal standard technical information, such as your IP address and request details, to our hosting provider Vercel, and our backend uses the address briefly to limit abusive request rates. The published catalogue is the same for everyone. Unless you turn crash reporting off, the app also sends error and crash reports, which contain no guest workouts, measurements or other training data (see “Error and crash reports” below).
Training, body measurements and goals
You may record workout names and times, programs and workout days, selected exercises, repetitions, load, duration, distance, intensity, rest-related values, completion status, notes and corrections. Synchronization stores identifiers, ordering, revisions, timestamps, retry state and conflict information needed to avoid losing or duplicating changes.
Optional body measurements include weight, body-fat percentage and supported circumferences, such as waist, chest, hips, neck, upper arm, thigh and calf, with measurement dates and corrections. Goals can concern workout frequency, strength or a body measurement; goals are stored only in our cloud service. Values are stored in metric units; the units you see can differ.
Progress calculations produce training totals, exercise history, estimated strength, records, comparisons and weekly and monthly summaries. Reports and performance exports can contain these values. They describe your recorded training; they are not medical diagnoses or guarantees.
Private exercises and catalogue use
Your own exercises can include names, equipment, body regions, movement and tracking types, and notes. They belong to your account and are not published to other people. The exercise animations and thumbnails in the catalogue are catalogue content, not images of you. Catalogue media downloaded to your device supports browsing and offline playback.
Subscription information
We process the store and product, billing period, purchase evidence and transaction history, verification and acknowledgement status, the start, end and status of your access, renewal, refund and revocation events, restore and reconciliation records, and any Premium access granted by us manually. Restricted purchase evidence is stored encrypted and separately from normal account data. Stores send status updates that keep your access correct. Their own purchase and account records follow their privacy policies.
Support and contact messages
In-app contact, bug reports and feature requests can contain a title, message, category, reproduction details or suggestions, a reply email address if you give one, app version, build, platform and language, status and our replies. If you choose a screenshot, only that image is uploaded. The upload process normalizes the image and removes its metadata; the image stays private to your account and authorized support staff.
The contact form on our website processes your name, email address, topic, message and language. It does not accept attachments or access your account. Cloudflare Turnstile checks that the form is not being used by a bot; its result is verified before Resend delivers the message to our support inbox. Messages sent through the form are not stored in our database, but they are kept in our support mailbox. Ordinary emails to support can include attachments you choose to send. Please do not include passwords, other people's information or unnecessary health details in any support message.
Account export and export-ready email
When you request an account export, we prepare a private ZIP file from the account data stored on our servers. If email notification is available, we send an operational message to your current verified account email address through Resend when the export is ready. It explains when the file expires and how to download it in the app. It is not a marketing message.
The email has no attachment, workout details, account identifier or private download link, and its help-page link does not give access to your data. Downloading still requires signing in to the app. If the email fails, you can still download an available export in the app before it expires.
We record delivery attempts, timestamps, language, delivery status and a fingerprint of the message to prevent duplicate or misdirected notifications, but not another copy of your email address or the message text. Resend processes the recipient address, the message and delivery information; it does not receive the ZIP file. Deleting your account removes our notification records, but cannot recall an email already delivered to your mailbox.
Legal choices, operations and security
When you register or sign in, we record the Terms version and language you agreed to, the Privacy Policy version presented to you, the action you took and the server time. We also record your cloud-consent choices, including any withdrawal, with the statement version shown. Restoring a session or updating the app never creates such a record. A later new or changed document requires a separate review.
When you continue without an account, the app records on your device the Terms and Privacy Policy versions and content hashes shown to you. This record is not sent to us. If you later register or sign in, a separate account record is made; the guest record is not converted into one.
Our backend processes request identifiers, timestamps, error codes, job status, limited security information and records of actions taken by our authorized staff. Our hosting providers process network information, such as IP addresses and request details. Our application logs are designed to leave out tokens, purchase evidence, message contents and training values.
Our internal dashboard shows service and subscription totals; it is not advertising analytics. The app's rating prompt uses timing and attempt counters stored on your device. We do not learn whether you rated Bodyper or what rating you gave through that prompt.
Error and crash reports
We use Sentry, a service of Functional Software, Inc., to detect and fix errors and crashes in the mobile app, our backend and our websites (the public website and the Admin Console used by our staff). We use Sentry only for error and crash reports, not for performance tracing, session replay, screenshots, profiling, analytics or advertising.
Mobile app. A report can contain the type of error; the stack trace (the program code involved); fixed technical details of the error or a stable failure code; the route patterns of the screens you visited before the error, such as “history/:workoutId”, without the actual identifiers; the app's name, version, build and bundle identifier; the environment, such as production; the time; the name, version and build of your device's operating system, its kernel version and whether the device is rooted or jailbroken; the device model, family and brand, processor architecture and number of processors, screen size, density and orientation, whether it is an emulator, its total and free memory and whether memory is low; your language and region setting, time zone and 24-hour-clock setting; when the app started and whether it was in the foreground; identifiers of the app's program files that are needed to read the stack trace; and the fixed user label “anonymous”, which is the same for everyone.
Mobile reports never contain your account identifier, email address, name or device name; workout, measurement or other training data or notes; legal or billing information; authentication tokens or request contents; web addresses with query strings or fragments; or screenshots, logs or accessibility settings. The app does not add your IP address to reports; Sentry receives the network address of the connection when a report is delivered, as any internet service does, and our Sentry projects are set not to store IP addresses. Sentry's software can create a technical device identifier for crashes of the app's native Android or iOS code (on Android, a random installation identifier; on iOS, a code specific to Bodyper). The app removes these identifiers from every report on your device before it is sent. Reports waiting to be sent are stored temporarily on your device.
Send crash reports. In the app, App settings → Privacy → Send crash reports is on by default. The choice applies to the whole device, including when you use Bodyper without an account, and the app remembers it. If you turn it off, the app stops sending reports immediately, deletes any reports still waiting on your device, and sends none while it stays off, including reports about problems that happened while it was off. Reinstalling the app turns the setting back on.
Backend. Reports from our backend contain the error type and a scrubbed error message, the stack trace, the software release, the environment, the time, and the HTTP method and route pattern of the request, such as “/api/v1/history/:workoutId”. They contain no account or other identifiers, no request contents and no IP addresses.
Websites. Our websites send reports through our own server, so Sentry does not receive your browser's IP address. Reports contain the error type and a scrubbed message, the stack trace, the page address as a route pattern without query strings or fragments, recent page navigations and network requests reduced to their route patterns, the software release and environment, and can contain the name and version of your browser and operating system. Error reporting on the websites sets no cookies and stores nothing in your browser.
Sentry stores reports in its EU data region in Germany and deletes them after up to 90 days (section 8). Reports cannot be linked to your account, so deleting your account does not require a separate step at Sentry.
4. Where data comes from and who receives it
Personal data comes from you, your device and the changes you record, from Apple or Google when you use them to sign in or buy, and from our service providers when they report security, billing or delivery status. We do not obtain your medical records from anyone.
We use the following service providers. Unless stated otherwise, they process personal data only on our behalf and under our instructions, under data processing agreements.
| Recipient | Role and data involved |
|---|---|
| Supabase | Authentication, account database and private file storage, including synchronized training data, exports and support images. Guest data is not stored here. |
| Vercel | Hosting of our backend and websites, request processing and related technical and security records, including catalogue and media requests made without an account. |
| Resend | Delivery of account emails, website contact-form messages and export-ready notifications: recipient, message, language and delivery details. No export file, training data or private download link. |
| Sentry | Error and crash reports from the app, backend and websites (section 3), stored in Sentry's EU data region in Germany for up to 90 days. |
| Cloudflare Turnstile | Bot checks on the website contact form, using technical signals from your browser and network, such as your IP address and browser details, but not your message. Cloudflare also uses these signals as an independent controller to improve its bot detection. |
| Hostinger | Hosting of the support@bodyper.com mailbox: messages, replies, attachments you choose to send and email metadata. The mailbox is not forwarded to another service. |
| Apple and Google | Sign-in, app distribution, purchases and purchase verification, and the optional rating prompt. They act as independent controllers for their own services under their own privacy policies. |
| Authorized staff | Our own authorized personnel, with access limited to what their support and operations tasks require. Your private workout information is never made public. |
We may disclose information to authorities or professional advisers where a valid legal obligation or a justified legal matter requires it, limited to what is necessary. If our business is transferred, applicable data-protection obligations continue to apply and we will tell you about the change. These possibilities never mean that deleted account data is kept indefinitely.
We do not sell personal data or use it for targeted advertising. We do not send marketing emails or marketing or promotional notifications. We use email only for service-related communications, such as account security, export notifications, support and required service notices. Optional timer notifications only tell you that a rest timer has finished (section 7). Your training and health data is never sold or provided to employers, insurers or data brokers.
5. Purposes and legal bases
The table shows our purposes and the legal bases under the EU General Data Protection Regulation (GDPR). Where data can concern your health, we also need one of the conditions in Article 9 GDPR; the table names it.
| Purpose | Legal basis |
|---|---|
| Creating and running your account: sign-in, account security, profile and settings, and service emails such as sign-in codes and export notifications | Performance of our contract with you (Article 6(1)(b)). |
| Cloud processing of your training, body-measurement and goal data: storage, backup, synchronization between your devices, progress calculations, goals, reports and the Premium analyses you request | Performance of our contract with you (Article 6(1)(b)) and, because this data can concern your health, your explicit consent (Article 9(2)(a)), given with the separate cloud choice. |
| Guest use: sending the published catalogue and media to the app | Performance of our contract with you for guest use (Article 6(1)(b)). |
| Verifying purchases and managing Premium access | Performance of our contract with you (Article 6(1)(b)). |
| Keeping purchase evidence for up to 90 days after a purchase ends, to handle refunds, disputes and fraud | Our legitimate interest in handling disputes and preventing fraud (Article 6(1)(f)). |
| Security and abuse prevention: request-rate limits, hosting and security logs, bot checks on the website contact form, and staff access controls and audit logs | Our legitimate interest in protecting Bodyper, its users and their data (Article 6(1)(f)). |
| Error and crash reports | Our legitimate interest in detecting and fixing faults and keeping Bodyper secure (Article 6(1)(f)). In the app, you can object at any time by turning off Send crash reports. |
| Support requests, including website contact-form messages | Performance of our contract with you where the request concerns your use of Bodyper (Article 6(1)(b)); otherwise our legitimate interest in answering you (Article 6(1)(f)). |
| Health details you choose to include in a support message | Your explicit consent, given by sending them (Article 9(2)(a)). We use them only to handle that request, and you can ask us to delete them at any time. |
| Records of your legal choices: the Terms and Privacy Policy versions you agreed to or were shown, and your cloud-consent history | Our legal obligation to be able to demonstrate consent (Articles 6(1)(c) and 7(1)) and our legitimate interest in showing which Terms apply (Article 6(1)(f)). |
| Handling your privacy requests, deletion receipts and protection against restoring deleted accounts from backups | Our legal obligations under data-protection law (Article 6(1)(c)). |
| Legal claims and requests from authorities | Legal obligation (Article 6(1)(c)) or our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f)); for health data, Article 9(2)(f). |
Where we rely on legitimate interests, we have weighed them against your interests and rights, and we process only the minimum data needed. You can object to such processing (section 10). Data that stays only on your device, such as guest data and the timer-notification setting, is not processed by us.
6. Cloud consent and withdrawal
Creating or using an account requires a separate, initially unticked choice that allows cloud processing of your training and body-measurement data. Selecting the sign-in or registration button accepts the Terms and presents this Policy; it does not make the cloud choice. The choice covers one purpose: storing and processing this data in our cloud service to back it up, synchronize it between your devices and calculate the progress, goals and reports you request. It covers no other purpose. A new purpose would need a separate choice, and a new Privacy Policy alone never grants one. If you do not want cloud processing, you can use Bodyper without an account, with the core features working on your device.
You can withdraw your consent at any time in Account settings → Privacy choices, which shows the statement version, your current choice and what withdrawal means before you confirm. Withdrawal:
- stops uploads from all your devices, and queued work or another device cannot restore the withdrawn data;
- erases the cloud copies of your workouts, programs, workout days, corrections, measurements, private exercises, goals, progress snapshots and reports; goals exist only in the cloud, so they are deleted permanently;
- keeps the data already stored on your devices; and
- pauses ordinary account use. You can still export your data, delete your account and contact support.
When you turn cloud processing back on, the app asks which data kept on the device you want to upload again, and nothing is uploaded until you choose. A temporary loss of network connection is not withdrawal: after a valid consent, workouts you record offline synchronize later.
Withdrawal does not affect the lawfulness of processing before it, and it does not cancel a subscription.
If you register or sign in on a device that holds guest data, the account's Terms agreement, Privacy Policy presentation and cloud choice come first. The app then lists your guest data by category, with every category preselected, and asks you to choose Upload to my account or Keep on this device only. Nothing is uploaded until you choose to upload. Uploaded guest data becomes account data: it is processed under your cloud consent and follows this Policy's rules for account data. If an upload is interrupted, the guest data stays on the device. If you keep it on the device, it stays in the guest area and is available the next time the device is signed out of an account.
The choices described in this Policy are available in the current version of the app. If you use an older version, update the app or contact us.
7. Storage on your device and device permissions
The app keeps a local database separated by account, including a separate guest area when you use Bodyper without an account, pending synchronization work, settings and a catalogue and media cache. Sign-in secrets are kept in the platform's secure storage. Do not assume that every local workout file is encrypted separately from your device's own protection; protect your device with its access controls.
Signing out keeps the data of each account on the device separate, including work that has not yet synchronized. Uninstalling the app is not a request to delete your cloud account. An export or screenshot that you save or share outside Bodyper is controlled by you and the destination you choose; deleting your account cannot recall a file you sent to someone else.
Guest data is kept in the app's private storage on your device. Android app backup and device transfer are disabled for the local database, and on iOS it is excluded from device backups. You can delete all local guest data in Settings, and uninstalling the app also removes it. We cannot recover deleted guest data, because no server copy exists. Signing out never moves account data into the guest area, and the guest area never shows account data.
The Timer notifications setting is optional and off by default. If you turn it on, the app asks for your device's notification permission where required, and your device can then show a notification when a running rest timer ends while Bodyper is not open on your screen. These are local notifications, scheduled and shown by your device's operating system (Android or iOS); they are not sent from our servers. No push token is created, and no notification data or identifier is sent to us or to any push service, such as Firebase Cloud Messaging or Apple Push Notification service; no personal data leaves your device for this feature. The notification text is generic and does not include exercise names, weights or other training details, including on your lock screen. The setting and any scheduled notification are kept only on your device, and timer notifications work the same way with or without an account. You can turn them off in the app, or revoke Bodyper's notification permission in your device settings, at any time.
The photo picker is used only if you choose an attachment. Manual distance tracking does not use GPS. Bodyper does not use camera scanning, your microphone or contacts, Apple Health or Health Connect. Our websites use no advertising or analytics cookies; the security services they rely on process the technical information needed to operate them, and error reporting on the websites sets no cookies (section 3).
8. Retention and deletion
We keep account data while your account exists and delete it when you delete your account. Account data includes your identity and profile, synchronized training data and measurements, private exercises, goals, reports, support history and images, and your legal-choice records. Corrections, change history and synchronization records are kept while the account exists so that your data can be reconciled and explained accurately. If you withdraw your cloud consent, your cloud training data is erased earlier (section 6).
Guest data is kept only on your device, until you delete it in Settings, uninstall the app, or upload it to an account after signing in. We keep no server copy of it.
| Other data | Retention |
|---|---|
| Account export ZIP | 24 hours after it is ready. Downloading requires recent sign-in and a short-lived, single-use authorization; the export-ready email does not contain the file. |
| Premium PDF/CSV performance files | Deleted 24 hours after they are created. You can create a new file while the underlying records and your Premium access remain. A download link can expire sooner than the file. |
| Purchase evidence and store event notifications | Purchase evidence is kept while the purchase is active and deleted 90 days after it ends by expiring, being refunded or being revoked. Store event notifications are deleted 90 days after we process them. An unresolved store event can delay deletion until it has been reviewed. |
| Staff action logs | Up to 12 months. Entries that identify you are deleted when your account is deleted. |
| Deletion receipt and restore-protection marker | Up to 30 days after your account is deleted, to prevent a restored backup from bringing the account back. The marker is a keyed code, not an anonymous copy of your account. |
| Database backups | Our database provider keeps daily backups for a rolling period, currently 7 days. Deleted data disappears from backups as they are replaced, and if a backup is ever restored, completed deletions are applied again first. |
| Support emails and their attachments | Deleted 12 months after the conversation is resolved. In-app support history is account data, kept as described above. |
| Error and crash reports | Up to 90 days in Sentry. |
| Email content and delivery records at Resend | 30 days. |
| Hosting request logs | Up to 30 days at Vercel and, currently, up to 7 days at Supabase. Providers can keep limited security records longer under their own policies. |
Export-ready notification records are deleted with your account. Messages already delivered to your mailbox do not disappear when an export expires. We do not keep a copy of a deleted profile or purchase history for account recovery. Our email host's own backup copies of the support mailbox and Cloudflare's Turnstile data follow those providers' schedules.
An accepted deletion request restricts account access immediately; physical erasure can take a little more processing time. If a usable Sign in with Apple token exists, we use it to revoke Bodyper's access to your Apple ID. If it was never kept, we explain how to disconnect Bodyper in your Apple ID settings instead of claiming that it was revoked automatically. A deletion receipt does not mean that every provider or device copy has already been erased. Cancel a store subscription separately. Records controlled by Apple and Google follow their own policies, and files you saved or shared outside Bodyper stay where you put them.
9. Where data is processed and how it is protected
Bodyper is operated from Finland. Our database and file storage are hosted by Supabase in the eu-west-1 region (Ireland), and our backend runs on Vercel in its Dublin region. Some of our service providers, or their subprocessors, also process personal data outside the European Economic Area (EEA), mainly in the United States:
- Vercel, Cloudflare, Resend and Sentry are certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision. Their data processing agreements also include the European Commission's Standard Contractual Clauses.
- Resend stores email content and delivery records in the United States.
- Sentry stores reports in its EU data region in Germany; Sentry's US company and its subprocessors can access them under its agreement with us.
- Supabase and Hostinger use Standard Contractual Clauses for any processing outside the EEA.
- Vercel's global network can handle a request in a location near you.
- Apple and Google are responsible for their own international transfers.
Contact support@bodyper.com to get more information about these safeguards, including a copy of the relevant clauses.
We protect your data with authenticated, account-scoped access, restricted and audited staff access, private storage, encrypted connections, minimized logs and error reports, short-lived download access and controls against lost or duplicated changes. No service can promise absolute security. If a personal data breach occurs, we handle it and notify the supervisory authority and you as the law requires.
10. Your rights
Subject to the conditions of the law, you have the right to access your data, to have it corrected or erased, to restrict its processing and to receive it in a portable format. You also have the right to object to processing based on our legitimate interests. Where processing is based on your consent, you can withdraw it at any time, without affecting processing before the withdrawal. We may check your identity in a proportionate way so that we do not disclose or delete another person's data.
The free account export covers the account data stored on our servers. Synchronize pending changes first if you want them included. It contains your account and profile, programs, workout days, workouts and corrections, completed history, measurements and their changes, goals, private exercises, stored report snapshots, subscription information, support records and available support images. Reports are included as structured records, not as copies of every PDF or CSV file you created. Sign-in secrets and protected purchase evidence are not included.
The export is separate from Premium PDF/CSV performance reports. It is available for 24 hours and is downloaded in the app after recent sign-in; the export-ready email is only a notification. A missing or delayed email does not extend the export's availability or prevent you from downloading an available export in the app.
Without an account, we hold no copy of your guest data, so there is no account export or server-side deletion to request for it. You control it on your device: you can export workouts as CSV and delete all local guest data in Settings. You can still contact us about privacy, including the technical request data processed by our hosting provider.
Error and crash reports cannot be linked to you by us, so we cannot find or delete them on request unless you give us details that identify a specific report. They are deleted automatically within 90 days.
Contact support@bodyper.com to use your rights. We respond within one month. If we need more time, as the law allows, we tell you why within that month. You can lodge a complaint with the data protection supervisory authority where you live or work, or with Finland's Office of the Data Protection Ombudsman. In the United Kingdom, you can complain to the Information Commissioner's Office.
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. No decision about your health, eligibility, employment or insurance is made from your Bodyper charts.
11. Children
You must be at least 16 years old to create or use a Bodyper account. We do not knowingly keep account data of anyone under 16. We do not ask for your date of birth or verify ages, but the Terms require account holders to confirm that they are at least 16.
People under 16 can use Bodyper without an account. Their training data then stays on their device. The app still downloads the exercise catalogue and, unless crash reporting is turned off, sends error and crash reports, which contain no training data and do not identify anyone.
If we learn that an account belongs to someone under 16, we close the account and delete its data. Before deletion, we may give the account holder a short opportunity to export their data, unless the law requires prompt deletion, as it does for children under 13 in the United States. Parents or guardians who believe that their child has created an account can contact support@bodyper.com.
12. Additional information for residents of certain US states
Some US state laws, such as Washington's My Health My Data Act and Nevada's consumer health data law, give residents specific rights over consumer health data. For Bodyper, this means body measurements and training, goal, progress and report data that could indicate your physical health.
- What we collect and why: the data described in section 3, which you enter or which the app calculates from your entries, only to provide the features you request, to keep them secure and to meet legal obligations.
- Consent: we collect and process this data in our cloud service only with your consent, given with the cloud choice, or where it is necessary to provide the service you requested.
- Sharing: we do not sell consumer health data. We share it only with the service providers that process it on our behalf (section 4), and when the law requires. We do not share it with affiliates.
- Your rights: you can ask us to confirm whether we collect or share your consumer health data, to give you a copy of it and a list of the recipients, and to delete it, including copies held by our service providers. You can withdraw your consent at any time (section 6).
Email support@bodyper.com to make a request. We respond within 45 days; if we need up to 45 more days, we tell you why within the first 45 days. If we deny your request, you can appeal by replying to our decision with “Appeal” in the subject line. We decide on an appeal within 45 days and explain the outcome. If you are not satisfied, you can contact your state Attorney General.
13. Changes to this Policy and language
Each published version has a stable archived copy and an effective date. Account settings distinguish the version presented to you from the newest version. For guest use, the version presented to you is recorded only on your device. If we publish a new or changed Privacy Policy, we ask you to review it and acknowledge it separately, and we ask for new consent where needed. “Presented” or “acknowledged” does not mean that you read every paragraph or agreed to every processing purpose.
Our legal documents are published in English only. Contact support@bodyper.com if you need an accessible copy, help understanding this Policy, or answers to privacy questions in Finnish.