Privacy Policy
Last updated: August 20, 2026
1. About This Policy
This Privacy Policy explains how Acentro Systems LLC, a Pennsylvania limited liability company ("we," "us," or "our"), collects, uses, and shares information when you use Builtbody, stylized as "BLTBDY" ("the Service"), through our iOS app or website.
The Service is offered in the United States, Canada, the United Kingdom, the European Union and the wider European Economic Area, and a number of other European countries. We are based in the United States and store and process personal data there. If you are in the EEA or the UK, see Section 13 for the legal bases we rely on, your additional rights, and how we transfer data. If you are in Canada, see Section 14.
2. Information We Collect
Account information: When you create an account, we collect your email address and authentication credentials (or a token if you sign in with Apple). If you sign in with Apple and choose to hide your email, we receive a private relay address rather than your real one.
Profile and health data: During onboarding and regular use, you may provide body measurements (height, weight, and weight history), fitness goals and activity level, dietary preferences and restrictions, allergies, age, and sex. This data is used to personalize your coaching.
Content you create: Meals and workouts you log, notes you write for your coach, and your coaching conversation.
Photos: If you use photo-based meal logging, images are stored with your account to provide meal logging and history features. Photos are deleted when the associated records or your account are deleted.
Subscription information: Your subscription status, plan, and transaction history, received from Apple for purchases made in the iOS app, and from RevenueCat for purchases made on the web. We do not receive or store your payment card details.
Usage data: Information about how you interact with the Service, including screens viewed, features used, and progress through setup.
Device information: Device type, operating system, and timezone. We do not collect precise geolocation.
We do not collect Social Security numbers, driver's license numbers, financial account numbers, biometric identifiers, precise geolocation, or information about race, religion, union membership, or sexual orientation.
Categories of personal information we collect
The table below sets out what we collect by category, why we collect it, and who it is disclosed to. The category names are the statutory ones from the California Consumer Privacy Act (CCPA), which several other state privacy laws follow, so the same table answers the disclosure those laws call for. We collect all of it directly from you or automatically from your device, and we retain it for the periods described in Section 7.
| Category | Examples we collect | Business purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Email address, account ID, analytics identifier | Account creation, authentication, support, analytics | Infrastructure, analytics, and subscription providers |
| Customer records | Name, age, sex | Personalizing coaching | AI and infrastructure providers |
| Commercial information | Subscription plan, purchase and renewal history | Providing paid access, support, accounting | Apple, RevenueCat, Stripe |
| Internet or network activity | Screens viewed, features used, setup progress | Measuring and improving the Service | Analytics provider |
| Visual information | Meal photos you upload | Meal logging and history, generating coaching | AI and infrastructure providers |
| Sensitive personal information | Health and fitness data: body measurements, weight history, dietary restrictions and allergies, logged meals and workouts, and health-related content in your coaching conversation | Providing the coaching you asked for | AI and infrastructure providers |
| Inferences | Nutrition targets and plan recommendations derived from the above | Personalizing coaching | AI and infrastructure providers |
We use sensitive personal information only to provide the Service you requested and for the purposes listed above. We do not use or disclose it to infer characteristics about you, and we do not use it for any purpose that would require offering you a right to limit its use under the CCPA.
3. How We Use Your Information
- To provide, personalize, and improve the coaching experience.
- To generate AI-powered meal plans, workout plans, and coaching messages.
- To send proactive check-ins and notifications you have opted into.
- To process payments and manage your subscription.
- To communicate with you about your account or the Service.
- To measure how the Service is used and improve it.
- To keep the Service secure, prevent fraud and abuse, and enforce our Terms.
- To comply with legal obligations and to establish or defend legal claims.
4. Health and Fitness Data
Your health and fitness data is also covered by our Consumer Health Data Privacy Policy, which describes it in more detail and sets out additional rights. Where that policy differs from this one, it controls for consumer health data.
We treat your health and fitness data (body measurements, dietary information, workout history) with heightened care:
- This data is used to provide the coaching you asked for (calculating your targets, generating your plans, tracking your history) and to support and secure your account. We do not use it to improve the Service beyond delivering it to you.
- It is shared with OpenAI, our AI provider, solely as necessary to generate the coaching you requested, as described in Section 5.
- We do not sell your health or fitness data.
- We do not use your health data for advertising purposes.
- Health and fitness data is never included in the analytics events described in Section 5.
- Access within our organization is limited to what is necessary to operate, support, and secure the Service you requested.
5. How We Share Your Information
We share personal information with service providers who process it on our behalf, under contracts that limit them to our instructions:
- AI processing (OpenAI): Builtbody's coaching is powered by OpenAI. To generate your coach's responses, meal plans, workout plans, check-ins, and safety screening, we send OpenAI the information you provide in the app: your profile details (name, age, sex, height, weight, and weight history), fitness goals and activity level, nutrition targets, dietary preferences and allergies, logged meals and workouts, photos you attach to messages, personal notes you add for your coach, and your coaching conversation. We collect these details during setup because they are necessary to personalize the coaching Service you requested. Separately, before you create an account, we ask for explicit permission to share the categories shown on the sign-up screen with OpenAI, and no data is sent to OpenAI before you agree. That permission is an additional transparency control, not the legal basis for processing necessary to provide the Service, and it does not authorize uses outside this policy. OpenAI processes this data as a service provider under its API terms. Data sent through the API is not used to train OpenAI's models unless we opt in, which we do not do, and we do not enable optional application-state retention. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days, or longer when required by law or reasonably necessary to protect its services or third parties from harm. If you no longer want your data shared with OpenAI, you can close your account in Settings or ask us to close it for you. Closing your account stops future AI processing and removes your data from our systems as described in Section 7.
- Payment and subscription processing: Apple is the seller of record for purchases made in the iOS app. Purchases made on the web are handled by RevenueCat, which takes payment through its payment processor, Stripe. RevenueCat manages subscription status for both. We receive subscription state from them; we do not receive your payment card details.
- Infrastructure: Neon (managed Postgres database), Cloudflare R2 (photo and file storage, and encrypted database backups), and Hatchbox (application hosting). These providers hold your data at rest so the Service can run; they do not access it for their own purposes.
- Email delivery (Resend): account emails such as password resets are delivered through Resend, which receives your email address and the contents of that message. Resend does not receive health or fitness data.
- Error monitoring (Honeybadger): when the app hits an error, diagnostic information is sent to Honeybadger so we can fix it. Credentials, email addresses, and health and body fields are filtered out before anything leaves the server, so Honeybadger does not receive your health data.
- Push notifications (Apple): if you enable notifications, your device's push token and the text of each notification travel through the Apple Push Notification service to reach your device. Notification text can reference your coaching (a check-in question, a protein reminder), so we keep delivery records short-lived: every record is deleted within about a week, and account-linked records are selected for immediate deletion when you delete your account.
- Product analytics (PostHog): We use PostHog to measure how people move through the app, for example which setup step someone stops at. These events record your progress through the app and the platform you used, never the health or fitness information you enter. Analytics events are linked to a randomly generated identifier and, once you have an account, to your account identifier.
Aside from the providers named above, no other third party receives your personal data. We do not use advertising networks or data marketplaces.
We may also disclose personal information when we believe it is required to comply with law or legal process, to enforce our Terms, to protect the rights, safety, or property of our users or others, or in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you before your information becomes subject to a different privacy policy.
We do not sell or share your personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and comparable state laws. We have not done so in the preceding 12 months, including for anyone under 16. We do not use third-party advertising trackers and we do not offer financial incentives in exchange for personal information.
6. Cookies and Similar Technologies
Our web application uses cookies for two purposes:
- Essential: authentication, session management, and security.
- Analytics: the same session cookie carries a randomly generated identifier used to measure how people move through setup and the app, as described in Section 5. This identifier is not linked to any advertising network.
If you are visiting from Europe or the United Kingdom, we do not create that analytics identifier and we record no product analytics about your visit before you sign in. The essential session state and ordinary server logs that any website produces still exist, but no analytics events do. That is why you are not asked to accept cookies: there is no analytics to accept. Once you have an account, analytics events are keyed to your account identifier and ride the session cookie that signing in already requires.
We do not use advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings, though the Service will not function correctly without the essential ones.
Do Not Track and Global Privacy Control
We do not sell or share personal information, so there is no such activity for an opt-out preference signal to stop. Where our website receives a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of sale and sharing, which we already do not engage in. We do not respond to browser "Do Not Track" signals, as no common standard for them has been adopted.
7. Data Retention
We retain your data for as long as your account is active. When you delete your account in Settings, deletion from our active production systems is immediate and permanent (your data is erased, not flagged as inactive), and we stop sending your information to OpenAI.
| Data | Retention |
|---|---|
| Account and profile, including body measurements and dietary information | Until account deletion, then erased immediately |
| Coaching conversation, logged meals and workouts, plans, weight history | Until account deletion, then erased immediately |
| Meal and message photos | Until you delete the record, or account deletion, then purged from storage |
| Encrypted database backups | Rolling 30 days, so residual copies age out within 30 days of deletion |
| Subscription and transaction records | Our local record of your subscription status is deleted with your account; Apple, RevenueCat, and Stripe retain their own transaction records under their policies for as long as tax and accounting rules require |
| Product analytics events (no health data) | Retained by our analytics provider under its own schedule; keyed to a random identifier before sign-in and to your account identifier after |
| Error diagnostics (no health data) | Retained by our error-monitoring provider under its own schedule |
| Push notification delivery records (device token and notification text) | No more than about a week; account-linked records are selected for immediate deletion when you delete your account |
| OpenAI abuse-monitoring logs | Up to 30 days, held by OpenAI and not deletable by us on request; see Section 5 |
Account deletion does not immediately erase any transient copies OpenAI may hold in its abuse-monitoring logs. OpenAI does not provide us with an API for deleting an individual end user's entries from those logs; they age out under the retention period and exceptions described in Section 5.
In deciding how long to keep information, we consider its amount, nature, and sensitivity, the potential risk from unauthorized use or disclosure, the purposes we process it for, whether we can achieve those purposes another way, and applicable legal requirements.
8. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, access controls limiting who on our team can reach production data, and authentication protections on your account.
Some data is also encrypted at the application level, before it is written to the database. Those fields are stored as ciphertext rather than readable text, so they remain unreadable to anyone who reaches the database without also holding our encryption keys. This covers your coaching conversation, the summaries your coach keeps of earlier conversations, your dietary restrictions and allergies, the notes you write for your coach, and your device's push notification token. Your other records, including your logged meals and workouts, your weight history, your meal and workout plans, and the profile details used to calculate your targets, are protected by the encryption at rest and the access controls described above rather than by application-level encryption.
However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
If a breach occurs that puts your personal data at risk, we will notify you and any authority we are required to notify, without undue delay after we become aware of it, and tell you what happened and what you can do about it.
9. Your Privacy Rights
Depending on where you live, you may have the right to:
- Know and access: learn what personal information we have collected about you, the categories of sources, the purposes, the categories of third parties we disclose to, and obtain a copy.
- Correct: ask us to fix inaccurate personal information.
- Delete: ask us to delete personal information we hold about you.
- Portability: receive your data in a portable format.
- Opt out of the sale or sharing of personal information, targeted advertising, and profiling with legal or similarly significant effects. We do not engage in any of these.
- Limit the use of sensitive personal information. As described in Section 2, we use it only to provide the Service you requested.
- Cease collection or sharing of consumer health data. Because that processing is necessary to provide AI coaching, you can stop it by closing your account in Settings or asking us to close it for you.
- Non-discrimination: we will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.
If you are in the EEA or the UK, Section 13 sets out further rights, including restriction of processing, objection, and the right to complain to a supervisory authority. If you are in Canada, see Section 14.
How to submit a request
You can delete your account and its data at any time in Settings. For any other request, email [email protected]. We will verify your request by confirming control of the email address on your account, and may ask for additional information if we cannot verify you that way. We respond within 45 days and may extend by another 45 days where permitted, with notice to you.
Authorized agents
You may use an authorized agent to submit a request on your behalf. We will ask the agent for written proof of authorization and may ask you to verify your identity with us directly.
Appeals
If we decline your request, you may appeal by replying to our decision or emailing [email protected] with "Privacy Appeal" in the subject line. We will respond in writing within 45 days with our decision and the reasons for it. If we deny your appeal, you may contact your state attorney general.
10. Apple Health / HealthKit
Connecting Apple Health is optional. Builtbody reads nothing from it until you grant permission in iOS, and you can turn the integration off in Settings or revoke access at any time in the iOS Health app.
If you connect Apple Health, we read a daily summary of a limited set of metrics: steps, active energy burned, sleep duration, resting heart rate, heart rate variability, and body weight. We store one figure per metric per day rather than the underlying readings, which can number in the thousands. We do not write anything back to Apple Health, and we do not read any other category from it, including workouts recorded by other apps, clinical records, or reproductive health data.
Health data read this way informs your coaching in the same way as the activity you log yourself, which means it is included in what we send to OpenAI as described in Section 5, and it is covered by the same retention and deletion rules as the rest of your account data. We do not use HealthKit data for advertising, and we do not share it with third parties for advertising or data-mining purposes.
11. Children's Privacy
The Service is intended for adults. You must be at least 18 years old to use it, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it and close the account. If you believe a minor has provided us information, contact [email protected].
12. Where Your Data Is Processed
We are based in the United States and store and process personal information there. If you use the Service from Canada, the United Kingdom, or the European Economic Area, your personal data is transferred to the United States, which has not received an adequacy decision from the European Commission.
For those transfers we rely on the European Commission's Standard Contractual Clauses (implementing decision 2021/914), and the UK Addendum for transfers from the United Kingdom, incorporated into our agreements with the providers named in Section 5. To request more detail about these safeguards, email [email protected].
13. Notice to Users in the European Economic Area and the United Kingdom
Controller
Acentro Systems LLC is the controller of the personal data described in this policy for the purposes of the EU General Data Protection Regulation and the UK GDPR. Our contact details are in Section 16.
Several other European countries where the Service is available (including Albania, Bosnia and Herzegovina, Kosovo, Moldova, Montenegro, North Macedonia, Serbia, and Ukraine) have data protection laws modelled on the GDPR. We extend the rights and protections described in this section to users in those countries as well, rather than treating the same data differently by border.
We have not appointed a Data Protection Officer. We have assessed our processing against Article 37 GDPR and do not meet the criteria that make one mandatory. Privacy matters are handled directly by our team at the address in Section 16.
Legal bases for processing
The GDPR requires a legal basis for each purpose we process your personal data for. Ours are set out below.
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: email address, authentication credentials | Creating and securing your account | Performance of a contract (Art. 6(1)(b)) |
| Profile data: name, age, sex, height, weight and weight history, goals, activity level, nutrition targets | Calculating your targets and personalizing your coaching | Performance of a contract (Art. 6(1)(b)) |
| Coaching conversation, logged meals and workouts, plans, meal photos | Delivering the coaching Service you signed up for | Performance of a contract (Art. 6(1)(b)) |
| Dietary restrictions and allergies | Tailoring meal plans, and avoiding foods that could harm you | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)). Optional, and given separately in Profile |
| Subscription and transaction records | Providing paid access, and meeting tax and accounting duties | Performance of a contract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) |
| Usage and device data, error diagnostics | Keeping the Service working, secure, and free of abuse | Legitimate interests (Art. 6(1)(f)) |
| Product analytics, once you have an account | Understanding how people use the Service | Legitimate interests (Art. 6(1)(f)). We do not run analytics on anonymous visitors in Europe at all |
| Push notification token | Sending check-ins and reminders you asked for | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms and concluded that it is not. You may object to that processing at any time, as described below.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Dietary restrictions and allergies are optional: you can clear them in Profile, which deletes them, and the rest of the Service continues to work.
Your rights
In addition to the rights in Section 9, you may ask us to:
- Restrict processing while a dispute about accuracy or our legitimate interests is resolved.
- Object to processing we carry out on the basis of legitimate interests.
- Provide your data in a portable form, or transmit it to another controller where technically feasible.
- Withdraw consent you have given, at any time.
We respond to these requests within one month. Where a request is complex or you have made several, we may extend by two further months and will tell you why within the first month. There is no charge.
Automated processing
Your coaching is generated by an AI model, which is automated processing. It does not produce legal effects or similarly significant effects for you: the Service cannot deny you credit, employment, insurance, healthcare, or any comparable benefit, and every recommendation is advisory. You decide whether to act on it, and you can ask your coach to explain any recommendation. We do not use your personal data for profiling beyond generating the coaching you requested.
Complaints
If you believe we have processed your personal data unlawfully, you may lodge a complaint with your local supervisory authority. In the EEA you can find yours through the European Data Protection Board at edpb.europa.eu. In the United Kingdom it is the Information Commissioner's Office at ico.org.uk. We would rather hear from you first, so email [email protected] and we will try to put it right.
14. Notice to Users in Canada
We process personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for residents of Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25.
We collect and use personal information for the purposes described in Section 3, and we rely on your consent to do so. For sensitive information (your health and fitness data, and your dietary restrictions and allergies), that consent is express: your health and fitness data is collected as part of the coaching you signed up for and is described to you before you provide it, and dietary information is optional and given separately in Profile. You may withdraw consent at any time, subject to legal and contractual limits, by clearing the relevant information or deleting your account.
Your personal information is stored and processed in the United States and may be accessible to United States courts and law enforcement under the laws of that country. Section 12 describes the safeguards we apply to those transfers.
You may request access to your personal information and correction of inaccuracies, and you may ask how we handle it, by emailing [email protected]. Where a decision is made about you by automated means, you may request information about it and submit observations, as described in Section 13.
The person accountable for personal information at Acentro Systems LLC, including as privacy officer for the purposes of Quebec Law 25, can be reached at [email protected]. If we do not resolve your concern, you may complain to the Office of the Privacy Commissioner of Canada, or for Quebec residents, to the Commission d'accès à l'information du Québec.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date at the top reflects the most recent revision.
16. Contact
If you have questions about this Privacy Policy or your data, contact us at [email protected] or write to Acentro Systems LLC, 309 Jamestown St., Sugar Grove, PA 16350.