Privacy Policy for Bodymodo
This Privacy Policy explains how Bodymodo ("Bodymodo", "the App", "we", "us", or "our") collects, uses, protects, and deletes information when you use the Bodymodo Android app.
Bodymodo is provided by the Developer Team. In this policy, "Developer Team" means the team responsible for building, operating, and supporting Bodymodo.
This policy is written to describe the app as it works today, optional account Cloud sync when it is available, and ad-supported versions of the app when ads are enabled. It is not legal advice.
1. Information We Collect
1.1 Account information
You can use Bodymodo as a guest without creating an account. If you create an account or sign in, Bodymodo uses Firebase Authentication and may collect:
- Email address
- Firebase Authentication user ID
- Google Sign-In token when you choose Google Sign-In
This information is used for sign-in, account management, and account deletion.
Bodymodo does not create a Firebase anonymous account for guests. Guest data is stored on your device under a local guest identifier and is not tied to your email unless you later create or sign into an account on that same device.
1.2 Fitness, health, and wellness data stored on your device
Bodymodo stores the following information locally in the app database on your device:
- Profile details such as age, gender, height, weight, goal weight, body type, fitness goal, training environment, fitness level, weekly workout frequency, preferred workout length, equipment, limitations, activity level, and dietary preferences
- Workout history such as dates, durations, exercise lists, completion status, difficulty ratings, and energy levels
- Program, challenge, active workout, and custom workout progress
- Weight logs and body measurements
- Nutrition settings, meal logs, meal plans, and water intake
- Optional progress-photo records saved as local content references
- Consent history and privacy-control settings
- Reminder settings for workouts, water, streaks, and other local reminders
- Adaptive daily check-in entries such as energy, mood, time budget, soreness, available equipment, and friction
- Accepted program repair adjustments
- Local coach memory signals (preferences inferred from your in-app actions, such as preferred or avoided exercises and rescue-mode habits)
This local fitness and wellness data stays on your device unless you create or sign into an account and explicitly turn on Cloud sync when that feature is available. If you uninstall the App, clear app data, or delete local data from Profile, local guest data and local account-scoped data are removed from that device.
1.3 Optional Cloud sync
If you create an account and turn on Cloud sync in Profile > Cloud sync, Bodymodo uses Firebase Cloud Firestore to back up selected data tied to that account and keep it in sync across your signed-in devices. Cloud sync is off by default, account-only, unavailable to guests, and separate from AI, analytics, and advertising choices.
Synced data can include your profile, workouts and workout history, active programs and challenges, nutrition and water logs, weight and body-measurement logs, custom workouts, exercise library state, nutrition settings, workout-coach preferences, daily check-ins, adaptive program adjustments, and user-selected daily meal-plan rows.
Progress-photo files are not uploaded by Cloud sync. Bodymodo also does not attach a device identifier or advertising identifier to synced fitness records.
Synced data is encrypted in transit, stored privately under your account, and protected by Firebase Authentication, Firestore Security Rules, and Firebase App Check. It is not made public, sold, or shared with third parties for advertising. You can turn Cloud sync off at any time; the app keeps working offline and your local data stays on the device. Synced cloud data is retained while your account exists unless you use Delete my data, delete your account, or request data deletion.
1.4 Optional AI workout generation
If you grant AI consent and ask Bodymodo to generate or adapt a workout, a limited workout-generation prompt may be sent through Firebase AI Logic / Gemini. That prompt can include information such as your goal, environment, fitness level, energy level, age, weight, goal weight, preferred workout length, equipment, limitations, activity level, body type, recent difficulty ratings, and recent exercise IDs.
The AI response is used to show the workout in the App. If you decline or revoke AI consent, Bodymodo uses local rule-based workout generation and does not send profile details to Firebase AI / Gemini for workout generation.
1.5 Crash diagnostics
Bodymodo uses Firebase Crashlytics to diagnose crashes and serious app errors. Crash reports can include:
- Crash stack traces
- Device model
- Android version
- App version
- Non-personal warning and error logs
Crash reports are used to find and fix bugs. The Developer Team does not intentionally add your name, email, detailed meals, body measurements, progress photos, or full local fitness history to crash reports.
1.6 Optional analytics
If you grant analytics consent, Bodymodo uses Firebase Analytics to understand whether the beta is reliable and useful. Analytics events can include onboarding started or finished, workout started or finished, program or challenge started or completed, meal logged, reminder enabled, daily check-in completed, adaptive mode selected, rescue workout started or finished, program repair shown or accepted, weekly story viewed, and coach memory reset.
Analytics events may include app and device information, a Firebase app-instance identifier, content IDs, and high-level interaction metadata such as meal type, workout source, or exercise count. Analytics events do not include your name, email address, body measurements, detailed meal entries, workout notes, progress photos, or full local fitness history.
If you decline or revoke analytics consent, Bodymodo does not record Firebase Analytics events.
Performance monitoring. When analytics consent is granted, Bodymodo also uses Firebase Performance Monitoring to measure app reliability and speed. It can collect automatic performance traces such as app start time, screen rendering, and the timing, success, and size of network requests to Bodymodo's service providers, along with app and device information and a Firebase installation identifier. Performance monitoring does not collect your name, email address, body measurements, detailed meal entries, workout notes, progress photos, or full local fitness history, and it does not record the contents of network requests. If you decline or revoke analytics consent, Bodymodo does not collect performance-monitoring data.
1.7 Notifications and reminders
If you enable reminders, Bodymodo schedules them locally on your device using Android notification and background-work features. Reminder settings are stored on your device. Reminder content is not sent to Bodymodo servers.
1.8 Advertising in ad-supported versions
Ad-supported versions of Bodymodo may show ads through Google AdMob / Google Mobile Ads SDK. Bodymodo uses Google's User Messaging Platform where required to request and manage advertising privacy choices before ad requests are made.
When ads are enabled, Google AdMob may automatically collect, receive, or share information such as:
- IP address, which may be used to estimate general location
- Ad and app interactions, such as ad requests, impressions, taps, and rewarded-video completion
- Diagnostic information, such as app, SDK, device, and ad-delivery performance
- Device or other identifiers, including the Android Advertising ID or app set identifiers when available and permitted
Google says Google Mobile Ads SDK data is encrypted in transit and may be used for advertising, analytics, and fraud prevention, security, and compliance. Bodymodo does not send health, fitness, nutrition, profile, photo, workout, progress, reminder, email, Firebase UID, or free-text note values to AdMob as ad targeting parameters or custom ad request metadata.
Rewarded ads, if enabled, are optional and user-initiated. They are not required for onboarding, privacy controls, account deletion, workout execution, nutrition logging, safety information, or other core app functionality.
1.9 App integrity and abuse prevention
Bodymodo uses Firebase App Check with the Play Integrity provider to help verify that requests to Firebase-backed services come from the genuine Bodymodo app. Firebase App Check / Play Integrity may process app and device integrity attestation, Firebase user agent data, app/device metadata, and Firebase installation information to issue App Check tokens. Bodymodo uses this for security, abuse prevention, and platform compliance, not for Bodymodo-owned advertising profiles.
2. Information We Do Not Collect
Bodymodo does not collect or use:
- GPS or precise location
- Camera or microphone data
- Contacts or calendar data
- Payment card or billing information
- Data from other health, fitness, or social apps
- Health, fitness, nutrition, workout, progress, or profile content for ad targeting or data-broker sale
Bodymodo does not sell personal information or rent personal information. In ad-supported versions, advertising identifiers and ad interaction data may be processed by Google AdMob as described in Section 1.8.
3. How We Use Information
Bodymodo uses information only to:
- Let you use the App as a guest
- Let you create, sign into, manage, and delete an account
- Save and display your profile, workouts, programs, meals, water, measurements, progress, and reminders
- Back up, restore, and sync selected account data across signed-in devices if you turn on Cloud sync
- Generate personalized workouts locally, or through Firebase AI / Gemini when you grant AI consent
- Export or delete your local Bodymodo data when you choose those actions
- Diagnose and fix crashes and serious errors
- Understand aggregate beta usage and app performance when analytics consent is granted
- Request, show, measure, and protect ads in ad-supported versions when advertising privacy choices and feature flags allow it
- Comply with legal, safety, security, and platform obligations
Bodymodo does not use your health, fitness, nutrition, workout, progress, photo, or profile content to send marketing emails, build Bodymodo-owned advertising profiles, train Bodymodo-owned AI models, or sell data to data brokers.
4. Third-Party Services
Bodymodo uses the following Google services:
| Service | Purpose | Information involved |
|---|---|---|
| Firebase Authentication | Sign-in and account management | Email address, password handled by Firebase, Firebase user ID |
| Google Sign-In | Optional faster sign-in | Google identity token for sign-in |
| Firebase Crashlytics | Crash diagnostics | Crash traces, device model, OS version, app version, diagnostic logs |
| Firebase Analytics | Optional analytics | App interactions, app/device information, Firebase app-instance identifier |
| Firebase Performance Monitoring | Optional app performance and reliability metrics | Performance traces, network-request timing, app/device information, Firebase installation identifier |
| Firebase AI Logic / Gemini | Optional AI workout generation | Limited workout prompt and generated response |
| Firebase Cloud Firestore | Optional account Cloud sync | Selected account fitness, nutrition, profile, progress, and settings records when Cloud sync is turned on |
| Firebase Remote Config | Operator kill switches and rollout controls | Firebase installation/app metadata for config fetches; no workout, nutrition, profile, or progress payloads |
| Firebase App Check / Play Integrity | App and device integrity checks to protect Firebase-backed services from abuse | Firebase user agent and Play Integrity attestation token used to issue App Check tokens |
| Google User Messaging Platform | Advertising privacy choices where required | Consent status, privacy choices, and regional privacy-message signals |
| Google AdMob / Google Mobile Ads SDK | Ads in ad-supported versions | IP address/general location estimate, ad interactions, diagnostics, device or other identifiers, and Advertising ID when available and permitted |
These services are provided by Google LLC and are governed by Google's applicable terms and policies, including Google's Privacy Policy. Firebase services may process information on Google infrastructure outside your country or region.
Bodymodo uses Google AdMob as the advertising provider in ad-supported versions. Bodymodo does not use ad mediation networks unless a future policy update says otherwise.
5. Sharing and Disclosure
Bodymodo does not sell your personal information.
Information may be processed by Google services listed above only for the purposes described in this policy. The Developer Team may also disclose information if required by law, to protect rights and safety, to investigate abuse, or as part of a merger, acquisition, reorganization, or transfer of the App, where allowed by applicable law.
When Cloud sync is enabled, selected account data is processed by Firebase Cloud Firestore only to provide backup, restore, deletion, and multi-device sync. When ads are enabled, Google AdMob may collect or share SDK data for advertising, analytics, and fraud prevention, security, and compliance. Bodymodo does not share your detailed local or synced fitness, nutrition, workout, progress, photo, or profile content with AdMob for ad targeting.
6. Retention and Deletion
- Guest and local fitness data: Stored on your device until you delete it, clear app data, or uninstall Bodymodo.
- Account email and Firebase user ID: Stored while your account exists and deleted when your account is deleted, subject to Firebase and legal retention rules.
- Cloud sync records: Stored while your account exists and Cloud sync is enabled or previously used. Turning Cloud sync off stops new sync activity but does not by itself delete existing cloud records; using Delete my data, deleting your account, or requesting data deletion removes or schedules deletion of synced records where available.
- AI workout-generation requests: Processed by Firebase AI Logic / Gemini according to Google's applicable terms and retention controls.
- Crash reports: Retained according to Firebase Crashlytics settings.
- Analytics events: Collected only after analytics consent and retained according to Firebase / Google Analytics settings.
- Performance-monitoring data: Collected only after analytics consent and retained according to Firebase Performance Monitoring settings.
- Advertising data: Processed by Google AdMob / Google Mobile Ads SDK according to Google's applicable advertising, privacy, and retention controls when ads are enabled.
- Feedback messages: If you send feedback, your email app may include device, app, and session details in the message body. Feedback is used for support and beta improvement.
7. Your Choices and Rights
You can:
- Use Bodymodo as a guest without an account
- Turn Cloud sync on or off from Profile > Cloud sync when it is available
- Review or change AI and analytics consent in Profile > Privacy controls
- Review advertising privacy choices in Profile > Privacy controls when AdMob privacy options are available, and use Android settings to reset or delete your device advertising ID where supported
- Export readable, JSON, or CSV copies of local Bodymodo data from Profile
- Delete local profile, workout, meal, measurement, reminder, and progress data from Profile
- Delete an account from Profile when signed in
- Submit privacy, support, or account-deletion requests through the in-app feedback/contact flow or through the Bodymodo contact channel listed on the app store listing
GDPR Privacy Rights
EEA and UK users may have GDPR rights, including rights to access, correct, delete, restrict, object to, or export certain personal information.
California Privacy Rights
California residents may have CCPA/CPRA rights, including rights to access, correct, delete, and export certain personal information. Bodymodo does not sell personal information. When ads are enabled, eligible users may have additional choices for advertising data through the in-app advertising privacy options or Android advertising ID controls.
The Developer Team will respond to valid privacy requests within 30 days unless a different period is required or allowed by applicable law.
8. Age Eligibility and Children's Privacy
Bodymodo is intended for users who are 18 years of age or older. It is not intended for children or minors under 18 and is not intended for the Google Play Families program. The Developer Team does not knowingly collect personal information from children or minors under 18. If you believe a child or minor has provided personal information through Bodymodo, contact the Developer Team and the information will be deleted where required.
9. Security
The Developer Team uses reasonable technical and organizational measures to protect information. Firebase services use protections such as encrypted transmission, and local Bodymodo data is protected by Android app sandboxing.
No app, network, or storage system is completely secure. If the Developer Team becomes aware of a data breach affecting your information, users will be notified as required by applicable law.
10. International Transfers
Google services used by Bodymodo may process information on servers in the United States or other countries. Data-protection laws in those countries may differ from the laws where you live. The Developer Team relies on Google Firebase controls and applicable safeguards for those transfers.
11. Changes to This Policy
The Developer Team may update this Privacy Policy from time to time. When the policy changes, the "Last updated" date will be changed. If changes are material, Bodymodo may ask you to review and accept the updated legal documents before continuing to use affected features.
12. Contact
For privacy questions, support requests, or account-deletion requests, contact the Developer Team through the in-app feedback/contact flow or the Bodymodo contact channel listed on the app store listing. You can also email us at support@bodymodo.com, or visit the account and data deletion page at https://bodymodo.com/deletion.html.