Effective Date: July 28, 2026

This Privacy Policy explains how BodyFuture ("we," "our," or "us") collects, uses, stores, and protects your personal information when you use the BodyFuture mobile application. We are committed to handling your data transparently and responsibly.


1. Information We Collect

1.1 Information You Provide Directly

Category Examples
Account information Name, email address, profile photo (optional)
Body profile Date of birth, gender, height, weight, activity level, calorie and steps goals
Meal data Food items logged, meal names, calorie and macronutrient entries, timestamps
Journey data Journey name, goal type, start date, before/after photographs you upload
Weight logs Body weight entries with date and time
Feedback Messages submitted through the Contact Us form
App settings Selected language, unit system, notification preferences

1.2 Information Collected Automatically

Category Details
Usage analytics Screen views, feature usage events, session duration — collected in aggregate and anonymized
Anonymous device identifier A randomly generated ID assigned at first launch, not linked to your identity
App lifecycle events App launch and foreground/background transitions
Subscription status Active/inactive subscription state, verified via the App Store

1.3 Information from Apple Health (With Your Permission)

With your explicit authorization, we read the following Apple Health data types:

This data is displayed to you within the App and used to calculate your daily calorie balance and activity goals. It is never used for advertising and is never shared with third parties for any purpose other than operating the App. Your authorization can be revoked at any time in iOS Settings → Health → Data Access & Devices.

1.4 Photographs and AI Processing

BodyFuture uses two AI-powered features that require sending a photo to a third-party AI provider:

AI Vision (body transformation visualization). When you take or upload a photo to generate a future-self visualization, we send the photo — together with your current height, weight, gender, age, and target weight goal — to OpenAI (primary provider) or Google Gemini (used only if OpenAI is unavailable) via their image-generation APIs, over an encrypted connection. Before your first use of this feature, we show an in-app screen explaining exactly what is sent and to whom, and generation only proceeds after you tap to consent.

AI Food Recognition. When you photograph a meal to auto-log it, we send the photo to OpenAI via its vision API to identify food items and estimate nutrition. No body-profile data accompanies this request.

In both cases:

Face Data. The App's AI Vision feature uses Apple's on-device Vision framework to detect whether a face is present in a photo you provide, so we can ask you to retake the photo if no face is visible. This check runs entirely on your device and produces only a temporary result. BodyFuture does not collect, generate, store, share, or transmit any face data — including facial landmarks, face geometry, face templates, faceprints, or any other biometric identifier — and does not use face data to identify you. No face data is retained; the detection result is discarded as soon as the photo is checked. The photo you submit is sent to our AI image-generation providers to create your visualization, as described above, but no separate face or biometric data is derived from it or shared.

Sharing. No face data is shared with any third party. The photo you submit is sent to our AI image-generation providers (OpenAI, Google Gemini) solely to generate the visualization you requested, as described above.

Storage and retention. We do not store your photo, the detected face region, or the mask on our servers at any point — they are processed in memory and discarded once your request completes. The final generated image is saved locally on your device only; our servers store only a filename reference to it, never the image itself.

Deletion. Because nothing is retained on our servers, there is nothing to delete. The locally stored result is removed when you delete the associated journey or uninstall the App.

1.5 Guest (Anonymous) Sessions

If you use the App without signing in, an anonymous identifier is created and associated with your data. If you later sign in with an account, your guest data may be merged or cleared depending on the sign-in flow. Signing out or uninstalling without registering may result in permanent loss of guest data.


2. How We Use Your Information