Body Journal
Privacy Policy

Body Journal is a personal health dashboard that pulls data from wearables and smart scales you connect, plus anything you log manually, into one place. This page explains what data we collect, why, and how it's handled.

What we collect

Account info. You sign in with Google or Apple. Google gives us your name, email address, and profile picture. Apple gives us your name and email the first time you sign in only — Apple doesn't hand it back on later sign-ins, so we store it then. If you choose Apple's "Hide My Email," we only ever see the private relay address it gives us, not your real one. Whichever provider you use, we also get a unique account identifier from it — that's how we recognize you on future visits.

Data from connected sources. If you connect a source, we pull the following on your behalf:

What you log yourself. Weight, body fat, BMI, meals (including food photos and text descriptions), and any notes you add.

Food photos. When you upload a photo to estimate a meal's macros, that image is sent to our AI provider (Anthropic) for analysis and is not stored by us — only the resulting calorie/macro estimate is saved once you confirm and log it.

How we use it

To show you your own dashboard, charts, and history — nothing else. Your recent health data is also sent to Anthropic's Claude API to generate the AI insight summaries and answer questions you ask the in-app assistant. This is the same data described above; nothing additional is collected for this purpose.

Who we share it with

We don't sell your data or share it for advertising. Data passes through these third parties strictly to provide the service:

Google user data & Limited Use

Signing in with Google only requests your basic profile (name, email, picture) to create and identify your account. Separately connecting Google Health as a data source — an optional, separate step from signing in — requests read-only access to your Google Health data as well: specifically your sleep, activity and fitness, and health metrics and measurements, using the googlehealth.sleep.readonly, googlehealth.activity_and_fitness.readonly, and googlehealth.health_metrics_and_measurements.readonly scopes.

We use this data solely to populate your personal dashboard, charts, and history, and — with the same data — to generate the optional AI insight summaries and answer questions you ask the in-app assistant. We do not use it for advertising, we do not sell it, and we do not transfer it to third parties except (a) the AI provider (Anthropic) strictly to produce the features you request, (b) our hosting provider (Railway) to store the application database, or (c) as required by law or to protect against abuse.

Body Journal's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. Human review of Google user data occurs only where you explicitly request it or where required for security or to comply with applicable law.

You can disconnect Google at any time from the app's header, which immediately stops further syncing, and deleting your account permanently erases all previously synced Google data as described under “Your choices.”

Apple Health (HealthKit)

In the iOS app, you can connect Apple Health as a data source. If you grant permission, the app reads the health and activity types listed above from your device's HealthKit store and sends them to our server so they appear on your dashboard, exactly like data from any other connected source. Access is read-only; the app never writes to Apple Health.

HealthKit data is used only to show you your own dashboard, charts, and history, and — with the same data — to generate the optional AI summaries you request. It is never used for advertising or any use-based data mining, never sold, and never shared with third parties except the AI provider (Anthropic) to produce the features you ask for and our hosting provider (Railway) to store the database. You can revoke the app's Health access at any time in the iOS Settings app under Privacy & Security → Health, and deleting your account erases all previously synced HealthKit data as described under “Your choices.”

Storage & security

Your data is stored in a database on our hosting provider's infrastructure. Sessions are managed with a signed, HTTP-only cookie; we don't use tracking or advertising cookies. Data connected from third-party sources is retained for as long as your account exists, so you can look back at your full history — nothing is automatically deleted or expired.

Your choices

You can disconnect any wearable or scale at any time from the app's header — this stops future syncing from that source immediately. You can delete individual manually-logged entries yourself. To delete your entire account, open Settings → Account from the header and use the delete-account option there; it immediately and permanently erases every record tied to your account — all connected-source data, manual logs, sessions, and the account itself — with no waiting period. If you'd rather have us do it, you can also email us at the address below.

Children's privacy

Body Journal is not directed at children under 13, and we don't knowingly collect data from them.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page.

Contact

Questions or deletion requests: support@bodyjournal.co