BindTrue
Terms Privacy Open app

Privacy Policy

Last updated: September 30, 2026 · Effective: [EFFECTIVE DATE]

Draft — pending legal review. This policy describes how the app works today, but it is not final. Items shown like [THIS] must be filled in, and a qualified lawyer should review it before paid subscriptions start.

The short version

  • We collect only what the app needs: a display name, a PIN (stored as a one-way hash), your questionnaire answers, and the workouts and measurements you log.
  • Some of this — such as your sex, age, height, weight, injuries and measurements — can count as health-related data. We use it only to build your plan and show your progress.
  • We do not sell your data, share it for advertising, or show ads. No third-party analytics or ad trackers.
  • Our service providers are Cloudflare (hosting, database, AI) and Stripe (payments); AI requests may go to OpenAI or xAI instead if we switch them on (see AI processing). Stripe handles your card — we never see the full number.
  • In the BindTrue iPhone app you can choose to connect Apple Health. We then keep daily activity totals in your account. They are never sold, never used for ads and never sent to AI, and disconnecting deletes them (see Apple Health).
  • If you sign up with a friend’s invite link, we record who invited you and when, and that friend can see your public name (or only its first letter, until you choose one), when you joined and whether you have trained once — nothing else (see Invites).
  • If you join a challenge, the other people in it see the public name you choose for challenges (never the name you sign in with), your entries and the photos or videos you add as proof. In a public challenge (an official one or the weekly challenge) that is the people in your league, up to 30 who joined the same week at your level. Photos and videos are for people 18 and older, and an automatic check looks at each one before others see it. Proof photos and videos are deleted 30 days after the challenge (or your run in it) ends (see Challenges).
  • If you share a program you built, people who open its link — or everyone, if you publish it — see the program and the public name you chose, never your sign-in name. Its text is checked automatically first, by OpenAI’s moderation service and, before it is listed for everyone, by our AI provider (see Programs).
  • In the Feed, other members can see your public profile (public name, handle, bio) and the workouts you share: with every member, with your followers (the default) or with no one. Never your sign-in name, questionnaire answers or weight. Comments, notes, bios and names can be checked automatically for harmful content (see Social).
  • Delete your account any time in Profile → Delete account. Your data is removed from our live database right away.
  • If you post on the ideas board, signed-in people see your idea, its votes and your public name. Help answers come from an AI that reads your question; requests you send with Contact support go to the owner (see Ideas, Help and support).
  • BindTrue is not for anyone under 16.

Contents

  1. Who we are
  2. What we collect
  3. How we use it
  4. Health-related data and Apple Health
  5. AI processing
  6. Who we share it with, Challenges, Programs, Social and the ideas board
  7. Payments
  8. Cookies and local storage
  9. How long we keep data
  10. Your choices and deletion
  11. US state privacy rights
  12. Visitors outside the US
  13. Children
  14. Security
  15. Changes to this policy
  16. Contact us

1. Who we are

BindTrue (bindtrue.com) is operated by [COMPANY LEGAL NAME] (“BindTrue”, “we”, “us”). We are responsible for the personal data described in this policy. Questions or requests: [SUPPORT EMAIL].

2. What we collect

Information you give us

Account
Display name and your PIN. The PIN is stored only as a salted PBKDF2-SHA256 hash, so we cannot read it. We also create an internal account ID and record when the account was created.
Questionnaire
Sex, birth year (used to calculate age), height, weight, main goal, experience level, workouts per week and minutes per workout, where you train (equipment), daily activity level, and — if you choose to fill them in — free-text notes about injuries or limitations and what you want to achieve.
Training and body data
Your training plan and up to 4 earlier versions, completed sets, weights and reps, finished workouts, body measurements you log (such as weight or waist), and in-app settings (for example calculator inputs, exercise swaps and preferences).
Apple Health (optional, iPhone app only)
If you connect Apple Health in the BindTrue iPhone app, daily activity totals and the workouts recorded on your iPhone or Apple Watch. See Apple Health for the exact list.
AI features
If you use AI features such as AI plan updates or an AI coach, the requests and messages you send and the answers you receive.
Subscription
Your plan (monthly or yearly), status (trial, active, past due, canceled), trial and renewal dates, and the Stripe customer and subscription IDs that link your account to Stripe. See Payments.
Invites
Your personal invite code, made the first time the app shows your invite link. If you create an account with someone’s invite link, we store who invited you, when, and whether the link also invited you to a challenge. We use this, and whether they logged a workout or had a challenge entry count, to count the friends who joined with your link and trained once, which decides free use during the beta (see the Terms). We never read your contacts: you choose whom to send your link to, through your phone’s share menu or an app you pick (such as WhatsApp, Telegram or SMS), and that app’s own policy applies to what you send there.
Challenges (optional)
If you start or join a challenge: the public name you choose for challenges, that you confirmed you are 16 or older (and, for photos and videos, 18 or older, with the time you confirmed it), the challenge (its name, goal, dates, the kind of proof it asks for, any team names or stake its starter wrote, and the prize they offer: its kind, name, note and photo, with the photo’s automatic check result), that you are a member, when you joined and your team, the entries you log (day, amount and an optional note), the photos or short videos you add as proof and the result of their automatic check (fine, flagged with the categories the check named, or not checked), the cheers you give, and the reports you make about entries (with the optional reason you write). In an official challenge or the weekly challenge also: your level (from your questionnaire, or the one you pick when you join), the day your run started and ended, your daily goal and your league. Your badges and points: which ones, what you earned them in and when. See Challenges for who sees what.
Programs (optional)
Programs you build (name, summary, goal, training style, level, weeks, the days with their exercises, sets, reps, rest and notes, a warm-up and cool-down), whether each one is private, shared by link or public, and the result of the automatic check when you share it; which shared programs you started and when; the ratings and short reviews you write; and the reports you make about programs or reviews (with the optional reason). See Programs for who sees what.
Social (optional)
Your public profile: a handle made from your public name (you can change it), an optional short bio, who may see your workouts (everyone, followers or only you) and whether your posts may show your body-weight change. The posts on your feed: for a finished workout the day’s title, minutes, number of exercises and sets and new personal records; weekly streak milestones; posts that other BindTrue features add for you (for example a program you published); and the notes you add. The people you follow and who follow you, the people you blocked, the kudos and comments you give and get, the reports you make (with the optional reason), in-app notifications, and your weekly streak goal and the free streak repairs you used. See Social for who sees what.
Ideas, Help and support (optional)
On the ideas board (Profile → Ideas & voting): the ideas you post (title and details), your votes, the reports you make about ideas (with the optional reason), and when. For each idea we also keep what our systems added: an AI summary, a category, whether it touches a sensitive area (such as money or personal data), the result of the automatic content check, and every status change with who or what decided it. In Help: the questions you ask are answered and then forgotten — the conversation stays in your browser’s memory while Help is open and is not stored on our servers. If you tap Contact support, we keep your request (topic and message), the help-chat turns you chose to attach, the owner’s answer and whether you have read it. See the ideas board for who sees what.
Workout reminders (optional)
If you turn on reminders, we store the time and weekdays you chose, your device’s time zone, and for each device (up to 5) the push address that your browser’s push service gives us (Apple, Google, Mozilla or Microsoft, depending on the browser). Reminders carry no content: the push service only delivers an empty signal, and your device then asks BindTrue for the text, so the push service never sees your plan or workouts. We do not keep the message-encryption keys browsers offer. Turn reminders off in Profile → Workout reminders and the push address is deleted; it is also deleted when a push service reports it expired, after repeated failed deliveries, and with your account. The time, weekdays and time zone you chose stay saved until you delete your account, so turning reminders back on restores your schedule.

Information collected automatically

Session cookie
A random sign-in token that keeps you logged in. We store only a hash of it on our side.
Network and device data
Your IP address, browser type and the pages or API calls requested, processed by Cloudflare to deliver the app, keep it secure and keep short-lived technical logs. For rate limits and PIN lockouts we store a salted one-way hash of your network address that expires within 24 hours.
Local storage on your device
Your browser keeps dismissed banners, a workout in progress, and your recent AI-coach conversation (last 20 messages). The recent coach messages are sent along with each new coach question so the coach can follow the conversation; the rest is not sent to us. Signing out or deleting your account clears it from that browser. When a session ends on its own (for example after you change your PIN on another device, or after 180 days), it is cleared too, except changes you made offline that have not reached your account yet: they stay in that browser for that account only and are sent when you sign in to it there again; after 14 days they are no longer sent and are deleted the next time BindTrue opens in that browser.

What we do not collect

No email address or phone number at sign-up, no precise location, no contacts, no access to your camera or photo library (a photo or video you pick yourself as challenge proof is uploaded only when you choose to), no advertising IDs, and no third-party analytics or advertising trackers. (If you subscribe, Stripe collects an email address for receipts — see Payments.) The iPhone app reads Apple Health data only if you connect it, and only the types listed in Apple Health.

3. How we use it

  • To provide the Service: build and adjust your plan, calculate calories and protein, show “last time” weights, save workouts and measurements, and draw progress charts.
  • For AI features: to generate or update your plan and answer your questions (see AI processing).
  • For billing: to run your free trial, start and renew subscriptions, handle failed payments and refunds, and decide which features you can use.
  • For invites: to show you the friends who joined with your link and to apply the free-with-friends rule of the beta.
  • For security: to protect accounts (PIN lockouts, rate limits), prevent fraud and abuse such as repeated free trials, and fix errors.
  • To support you when you contact us.
  • To improve BindTrue using aggregated, non-identifying statistics (for example how many plans were generated).
  • To follow the law, for example tax and accounting rules for payments.

We do not use your data for advertising, we do not sell it, and we do not use it to make decisions about you that have legal or similarly significant effects (such as credit, insurance or employment).

4. Health-related data

Your sex, age, height, weight, injuries or limitations, measurements and workout history may be treated as health data or “consumer health data” under some laws (for example Washington’s My Health My Data Act, Nevada law, and other US state privacy laws). This section also serves as our consumer health data privacy notice.

  • What: the questionnaire, training and body data listed in section 2.
  • Why: only to provide the features you ask for — your plan, nutrition estimates, tracking and progress.
  • Source: you, and — only if you connect it in the iPhone app — Apple Health on your own iPhone (see below). We do not buy or receive health data from anyone else.
  • Consent: we collect it only when you choose to enter it. Free-text fields are optional.
  • Sharing: only with our processors to run the Service: Cloudflare for storage and AI, and OpenAI or xAI for AI requests if we switch them on (see AI processing). We never sell it or share it for advertising.
  • Your rights: you can see and edit your answers in the app, delete individual logs, delete your whole account, withdraw consent by deleting the data, and ask us which data we hold and who has processed it (see sections 10 and 11).

Apple Health (BindTrue iPhone app)

Connecting Apple Health is optional, and everything in BindTrue works without it. You choose in the iPhone app (Profile → Apple Health), and iOS then asks which data BindTrue may read and write. If you connect it:

What BindTrue reads
Active energy (active calories), steps, exercise minutes, and workouts (type, start and end time, duration, calories, and the name of the app or device that recorded them), from your iPhone and Apple Watch. Nothing else: BindTrue does not read heart rate, body weight or any other Apple Health data.
What BindTrue writes
Your finished BindTrue strength workouts: start and end time, and an estimate of the active calories burned — only when nothing else, such as an Apple Watch, has already measured that time, so calories are never counted twice.
Why
To show your activity in the app (today and the last 7 days), to adjust today’s food target to how much you really move, and to let your BindTrue workouts count in Apple Health.
What we store
One summary per calendar day: the daily totals above and the workouts of that day, plus your time zone. Never minute-by-minute samples. The summaries are stored in your BindTrue account in our Cloudflare database, encrypted in transit (HTTPS) and at rest, so you can see them on any device. Days older than 400 days are deleted automatically.
What we never do
We never sell Apple Health data, never use it for advertising, marketing or data mining, never share it with anyone else (Cloudflare only stores it for us as our database provider), and never send it to the AI plan or the AI coach. We do not store it in iCloud.
How to stop
In the iPhone app, Profile → Apple Health → Disconnect deletes every Apple Health summary stored in your BindTrue account right away and stops syncing on all your devices. (Signed in on the web, the same sheet offers “Delete Apple Health data”.) To stop BindTrue from reading Apple Health at all, also turn it off in iPhone Settings → Health → Data Access & Devices → BindTrue. Deleting your account deletes the summaries too. Your data in the Health app itself is not changed.

5. AI processing

Who answers. AI plans, AI plan updates and the AI coach are answered by an AI model. By default this is Cloudflare Workers AI (open AI models that Cloudflare runs for us). We may switch AI requests to OpenAI (the maker of ChatGPT) or xAI (the maker of Grok). When one of them is on, it answers your AI requests, and Cloudflare Workers AI answers only if that service fails or is too slow.

What we send. For an AI plan or an AI update: your questionnaire answers (with age, height and weight converted to numbers), your injury/limitation and goal notes if you wrote any, the plan to personalize, and — for updates — a summary of your last 5 weeks of workouts and measurements. For the AI coach: your message, your recent coach conversation and training context (your questionnaire answers, your plan, your recent training numbers and body-weight entries). We never send your display name, your PIN or Apple Health data.

How providers handle it. We send requests to OpenAI and xAI with store: false, which tells them not to store the request and the answer for later retrieval. Their API data terms apply to what they receive; under those terms they may still keep requests for a limited time (usually up to 30 days), for example to detect abuse. Cloudflare processes requests under its data processing terms.

Automatic content check. When you post a comment or a note, or save a public name, handle or bio, its text may be sent to OpenAI’s moderation service (a safety classifier, not a chatbot) to check for harmful content such as harassment, hate or sexual content. Only that text is sent, without your name or account. If the check flags it, the text stays hidden from others until our team reviews it (a flagged public name or handle is refused). If the check is not available, the text is shown as usual and can still be reported.

In the iPhone app we ask for your permission once, before the first AI request on that device, and name the provider and what is sent; if you decline, the app keeps working without AI. The model’s answer is checked and saved as your plan. While the AI works on a plan or an update, and until you use or decline its result, we keep a copy of what we sent it and of its answer with the request. That copy is deleted as soon as the request ends (you apply or decline the result, choose another plan, or the request fails), and after 7 days at the latest. The record that the request happened (its status and dates, without that content) is deleted 2 days after it ended. Please avoid writing anything in free-text fields that you would not want processed to create your plan.

Ideas, Help and the owner’s weekly report. The same AI provider also reads: a new idea’s title and details, with the titles and summaries of other ideas on the board, to sum it up, sort it, spot a duplicate and flag sensitive areas; your Help question with your last few questions in that Help conversation and our help pages, to answer it; and, once a week, numbers about how the app is used (sign-ups, workouts, challenges, votes, open requests) with the titles of the most-voted ideas, to write a short report for the owner. We never send your name, public name, PIN or account ID with these. Ideas, Help questions and support requests also go through OpenAI’s content check (its moderation endpoint), which only answers whether a text looks abusive; a flagged idea waits for a person to review it. An AI never decides about payments, refunds, your account or legal matters: those go to the owner.

Voice coach (AI voice)

The voice coach in workout mode is off until you turn it on. It speaks with AI-generated voices: short clips made with OpenAI’s text-to-speech from a fixed list of coaching phrases we wrote (numbers, “two more”, rest and hold cues, exercise names). The voices are not real people. We make each clip once and keep it on our servers (Cloudflare R2); nothing about you is sent to make them — no name, answers, workouts or voice — and nothing about your workout leaves your device for the coach to talk: the app plays the stored clips. Clips your device has played are kept in its cache so the coach also works without signal. When a clip is not ready yet, your device’s own built-in voice reads the phrase instead. Your choices (on or off, voice, volume, tempo and which cues) are saved with your account’s app settings.

6. Who we share it with

We share personal data only with service providers that process it for us under contracts that limit its use:

Cloudflare, Inc.
Hosting, content delivery, security, the D1 database where your account and training data are stored, R2 storage for challenge proof photos and videos and prize photos, Workers AI for AI features, and short-term technical logs. Cloudflare privacy policy.
OpenAI and xAI (only if we switch AI requests to them)
OpenAI (the maker of ChatGPT) or xAI (the maker of Grok) answers AI plan and AI coach requests while we have it switched on, with Cloudflare Workers AI as the backup. OpenAI’s moderation service may also check the text of comments, notes, bios and names (see Automatic content check). It receives what AI processing describes, under its API data terms: OpenAI business data, xAI data processing addendum.
OpenAI moderation (the automatic check of challenge proofs)
While we have it switched on, each proof photo and prize photo, and a small still frame the app takes from each proof video, is sent to OpenAI’s moderation service, which answers only whether it breaks its content rules and in which categories. Nothing else about you goes with it: no name, account or challenge. Its API data terms apply: OpenAI business data. The title and description of the weekly challenge are written by the AI provider in use, with no personal data in the request.
Stripe, Inc.
Payment processing, subscriptions, receipts and fraud prevention. For some purposes (such as fraud prevention and legal compliance) Stripe acts as an independent controller. Stripe privacy policy.
Push services (only if you turn on workout reminders)
Apple, Google (Firebase Cloud Messaging), Mozilla or Microsoft — whichever your browser uses — receive your device’s push address and an empty message at reminder time, signed by our server. They can see that a reminder was sent to your device and when, but no content.
Google Fonts
The app’s typefaces are loaded from Google’s font servers, which receive your IP address and browser information when fonts are downloaded. Google privacy policy.

Friends and invites. The person whose invite link you used to sign up sees your public name (until you choose one, only the first letter of your sign-in name, never the name itself), the date you joined and whether you have trained once (a logged workout or a challenge entry that counts) — never your answers, plan, workouts or measurements. In the same way you see the friends who signed up with your link.

We may also disclose data if the law requires it, to protect the safety and rights of our users or others, or as part of a merger, acquisition or sale of the Service (we will tell you before your data becomes subject to a different privacy policy). YouTube technique videos open on YouTube only when you tap a link, and YouTube’s policies then apply.

We do not sell personal data, and we do not “share” it for cross-context behavioral advertising as those terms are defined in California law.

Challenges: what the other people see

Challenges are optional. There are challenges with friends (started by someone, joined with their invite link or code) and public ones: the official BindTrue challenges and the weekly challenge, which anyone signed in can join. In a public challenge you are put in a small league with up to 30 people who joined in the same week at the same level; “the other members” below then means the people in your league. Anyone can see how many people take part in an official challenge, and nothing else about them. When you start or join a challenge, the other members of that challenge — and only they — can see:

  • the public name you chose for challenges (such as “Anna K.”), that you are in the challenge, your team if it has teams, and your place on its leaderboard, team board or league table (in a public challenge: on how many of your days you reached your own daily goal, and your total);
  • your entries in that challenge (day, amount and note) and the photos or videos you add to them as proof;
  • the cheers you give there.

They never see the name you sign in with (together with your PIN it is how you sign in, so the app asks for a different public name and refuses your sign-in name), your internal account ID, the exact time you logged an entry, your profile, questionnaire answers, plan, weight, measurements, workouts or anything from other challenges. Only the person who started a challenge also gets the members’ internal IDs and entry times, which the app uses to let them remove a member.

16 or older, and 18 or older for photos and videos
Challenges are only for people 16 and older. We keep that you confirmed it: the box when you create an account, or a one-time question before your first challenge. A birth year in your questionnaire that shows you are 16 or older counts too. Adding or viewing proof photos and videos, and joining a challenge that asks for them, is only for people 18 and older: a birth year in your questionnaire decides when you gave one, otherwise we keep that you confirmed you are 18 or older.
Proof photos and videos
Stored privately in our Cloudflare R2 storage. Only signed-in members of that challenge (in a public challenge: of your league) who are 18 or older can open them; there are no public links. Before a photo is uploaded, the app resizes it and saves a fresh copy, which drops its hidden details such as the location where it was taken. Videos are uploaded as recorded and can include details your phone saved with them, such as the location — check your camera settings if that matters to you.
The automatic check
Before others can see a proof, the photo (or a still frame of the video, taken by the app) is checked automatically (see OpenAI moderation). If the check flags it, the entry is hidden from everyone but you and does not count until one of our admins has looked at it; the person who started the challenge and our admins are told that an entry is waiting. If the check can’t run, the proof is shown and an admin looks at it later. Admins who look at a flagged or unchecked proof see the same details as for a report (below). We keep the check’s result with the entry, as long as the entry.
Prizes
The person who started a challenge may offer a prize. Its members see what it is (a surprise shows only that it is one), the note and the photo, and who offers it. The photo is stored privately in our Cloudflare R2 storage, only members of that challenge can open it, and it is checked automatically like proofs: if the check flags it, only the person who uploaded it sees it. It is deleted when they remove it or the prize, with the challenge, and 30 days after the challenge ends. BindTrue doesn’t handle the prize: arranging it is between the members.
Badges, points, teams and stakes
Badges (for example a 7-day streak, a completed challenge or a league medal) and points are shown to you. In a public challenge (an official one or the weekly challenge), your entries and league medals can appear in your Feed with the challenge’s name, for the people your Feed setting allows (see Social); a challenge with friends never posts anything to the Feed, so its name and your entries there stay with its members. A stake (such as “Loser buys coffee”) is text the starter writes for fun: BindTrue never handles money between members.
Invite links and codes
Anyone who has a challenge’s invite link or code can see a short preview before joining: the challenge name, the public name of the person who started it, how many people are in it, its dates, its goal, whether proof is needed, and any team names, stake and prize name its starter set (a surprise prize stays a surprise). Nothing else. The person who started it can make a new code at any time, and the old link stops working.
The person who started the challenge
can hide an entry from the others (you and they still see it), remove members (their entries, photos and videos in that challenge are deleted, and we keep a note that they were removed so they can’t join that challenge again), end the challenge early or delete it (all its entries, photos and videos are deleted).
Reports
Any member can report someone else’s entry (for example a photo that breaks the rules), with an optional short reason. The report goes to BindTrue’s admins, not to the person who posted it, who is not told who reported it. To decide, an admin can open that entry with its note and its photo or video while the report is open, and sees the challenge and the public and sign-in names of the people involved. The admin then removes the entry (its photo or video is deleted at once, and its author and the person who started the challenge see that moderators removed it) or closes the report without changes; an admin can also delete a whole challenge. We keep each report and the decision until the entry, the challenge or the reporting account is deleted.
How long it is kept
Proof photos and videos are deleted 30 days after the challenge’s last day; in an official challenge, 30 days after the last day of your run. The entries themselves (numbers and notes) stay so the results can still be seen, until the challenge is deleted or you delete them or your account. Badges stay until you delete your account.
Your choices
Delete one of your entries (its photo or video is deleted too), leave a challenge (your entries, photos and videos in it are deleted), or delete your account (your entries, photos and videos in every challenge are deleted, and so is every challenge you started, with everyone’s entries, photos and videos in it, and your badges).

Please share only what you are comfortable with other members seeing, and follow the content rules in our Terms: no nudity, no people who have not agreed to be filmed or photographed, nothing illegal.

Programs: what other people see

Programs you build are private until you share them. Then:

Shared by link
Anyone with the link sees a short preview before signing in (the program’s name and summary, your public name, days a week, weeks, level and style, how many people started it and its rating) and, once signed in, the whole program. It is not listed anywhere.
Public
Listed in the app’s Community for everyone signed in, with the same details.
Never shown
The name you sign in with, your internal account ID, your profile, answers, plan or workouts. The program shows how many people started it, never who.
Starting a program
When someone starts your program, a copy becomes their plan, with your public name as its author. It stays their plan if you later change, hide or delete the program; if you delete your account, your public name is removed from those copies. Starting a public program also adds a post to your feed, seen by the people who can see your posts (see Social); starting a program shared by link does not.
Automatic checks
When you share or publish a program, its text (name, summary, day names, reps and notes) and your public name are sent to OpenAI’s moderation service; when you publish it for everyone, the program is also sent to our AI provider for a safety review (see AI processing). Reviews you write are checked by the moderation service too. These requests carry only that text — never your sign-in name, PIN or account ID.
Ratings, reviews and reports
Your star rating counts toward the program’s average; your review is shown with your public name. Anyone who can see a program can report it or a review to our admins, who see the program or review, the public and sign-in names of its author and of the people who reported it, and may remove it. The author is not told who reported it.
Search engines
Programs made by users are not published for search engines: a share link opens our main page, and the program itself loads only in the app.

Social: profiles, the feed and comments

The Feed is optional. Everything here is shown only inside BindTrue to signed-in members: profiles and posts are not public web pages and are not indexed by search engines.

Your public profile
Any signed-in member who finds you (by your public name or handle, or through suggestions such as people in the same challenge, the person who invited you or people you invited) can see your public name, your handle, your bio and how many people you follow and follow you. Your weekly streak and how many workouts you did this month are shown only to the people who can see your workouts (below). Nobody else ever sees your sign-in name, your questionnaire answers, your plan, your weight or measurements, or your internal account ID.
Who sees your posts
You choose in Edit profile: Everyone (every signed-in member; public workouts can also appear in Discover, a short list of recent public highlights), Followers (the default: people who follow you) or Only me. A post keeps the choice in effect when it was made; you can change it for each post, and when you narrow the setting you can narrow your earlier posts too. The “Post to my feed” switch after a workout changes that workout’s post. The people who can see a post also see its kudos (who gave them) and its comments. A body-weight change appears on your workout posts only if you turn that on, and only as the change since your first check-in, never your weight.
Follows and blocks
Follows are open: anyone signed in can follow you. The people you follow and your followers are listed on your profile. You can remove a follower, and you can block someone: you then no longer see each other’s profiles, posts, comments or kudos in BindTrue, the follows between you end, and neither of you gets notifications from the other. The person is not told.
Your profile link
If you share your profile link (https://bindtrue.com/?u=your-handle), anyone who opens it sees your public name and handle and an invitation to join; nothing else about you. If the link also carries your invite code, a friend who signs up with it counts as invited by you (see Invites).
Notifications
In-app notifications tell you about kudos, comments and new followers, and other BindTrue features may add their own (for example a challenge invite). They are shown only to you, never from people you blocked or who blocked you. They are not sent as phone notifications.
Reports and review
Anyone can report a comment, a post or a profile to BindTrue’s admins, with an optional reason. The person reported is not told who reported them. Admins see the reported content, its author’s public name, handle and internal account ID and the reports, and may remove the content or reset a public name, handle or bio (the person then chooses a new public name). Text flagged by the automatic check waits for the same review, visible only to its author.

The ideas board: what other people see

Everyone signed in to BindTrue can see an idea you post: its title and details, its AI summary and category, how many votes it has, its status and the owner’s notes, the date, and your public name (until you choose one, only the first letter of your sign-in name, never the name itself). Nobody sees who voted for what. An idea the automatic check flags is shown only to you until a person reviews it. Our admins also see the name you sign in with and the reports about an idea, to moderate it. Ideas are shown only inside the app, to signed-in people: they are not public web pages. Planned ideas, with their text, can be read by the automated tool that helps build BindTrue. Support requests are seen only by you and our admins.

7. Payments

Checkout and the subscription management page are hosted by Stripe. Your card number and other payment details go directly to Stripe and are never stored on BindTrue’s servers. Stripe collects your email address (for receipts and renewal reminders), payment method and billing country or postal code. In our Stripe account we can see your email, card brand, last four digits and payment history, which we use only for billing and support. In the BindTrue database we keep just your subscription status, dates and Stripe IDs.

8. Cookies and local storage

  • One strictly necessary cookie (fit_s) keeps you signed in. It is HttpOnly, sent only over HTTPS, and lasts up to 180 days or until you sign out.
  • Local storage in your browser keeps interface preferences, a workout in progress and your recent AI-coach conversation. So the app keeps working without a signal, it also keeps a copy of your plan and recent training data on your device, plus any changes you make offline until they sync to your account. In the iPhone app it also remembers whether you connected Apple Health on that device and whether you allowed AI features there. An invite code from a link you opened is kept there for up to 30 days, until an account is created or signed in on that device. If you open a challenge invite link before signing in, the invite code is kept until you join (at most 7 days). If you open someone’s profile link before signing in, their handle is kept in that browser tab until you sign up or sign in there, so the app can offer to follow them. A program link opened before signing in is kept in that browser tab until you sign up or sign in (at most 7 days), and the program builder keeps a draft you have not saved yet on that device. It is cleared when you sign out. If your session ends on its own before your offline changes have synced, only those changes stay on the device, for your account alone: they sync when you sign in there again, and after 14 days they are dropped (deleted the next time BindTrue opens there).
  • Voice coach clips your device has played are kept in the app’s offline cache so the coach works without signal. They are the same for everyone and contain no personal data.
  • We use no analytics, advertising or tracking cookies. Stripe’s checkout pages use their own cookies for security and fraud prevention.
  • Because we do not sell or share data for advertising, there is nothing to opt out of — but we treat Global Privacy Control signals as a valid opt-out request anyway.

9. How long we keep data

Account and training data
Until you delete it or delete your account. Only your 5 most recent plans (the current one and up to 4 earlier versions) are kept.
AI plan requests
The copy of your answers (including injury notes) and training summary sent to the AI, and the AI’s answer: until the request ends (you apply or decline the result, choose another plan, or it fails), and never longer than 7 days. A record of the request without that content (its status and dates) is kept for 2 more days, so an applied AI plan can still be undone within 24 hours.
Apple Health summaries
Until you disconnect Apple Health or delete your account; days older than 400 days are deleted automatically.
Invites
Your invite code and the record of who invited whom: until one of the two accounts is deleted.
Challenge photos and videos
30 days after the challenge’s last day, or sooner when you delete the entry, leave the challenge, are removed from it, the challenge is deleted, an admin removes the entry after a report, or you delete your account. Challenge entries (numbers and notes): until the challenge is deleted or you delete them, leave or delete your account. Reports about entries: until the entry, the challenge or the reporting account is deleted. Your public name and 16+ confirmation: until you delete your account.
Programs
Until you delete the program or your account. Who started a program, ratings and reviews: until the program or the account that made them is deleted (you can take your rating back at any time, except a review our moderators removed: it stays hidden until then, so it can’t be posted again). Reports about programs or reviews: until the program, the review or the reporting account is deleted.
Social
Your profile, follows, blocks, posts, kudos and comments: until you delete them (a comment, a follow, a block) or your account. A workout’s post goes when you delete that workout, within a few days. Notifications: read ones after 60 days, any after 180 days, and at most your 300 newest are kept. Reports and admin decisions: until the reported item, its author or the reporting account is deleted. Weekly streak goals and repairs: until you delete your account.
Sign-in sessions
Up to 180 days, or until you sign out or change your PIN.
Ideas and votes
Until you delete the idea (possible while it is New, Declined or Merged) or your account. When you delete your account, your ideas that are still waiting and your votes are deleted; ideas already Planned, being built or Shipped stay on the board without your name. Reports about ideas: until the idea or the reporting account is deleted. Records of moderation decisions (which item, the decision and the admin’s note): 2 years.
Help and support
Help conversations are not stored on our servers. Support requests and answers: until you delete them in Help or delete your account.
The owner’s weekly reports
Usage numbers and the titles of the most-voted ideas, without names: 1 year.
Reminder settings
The reminder time, weekdays and time zone: until you delete your account (they are kept when you turn reminders off).
Push addresses
Until you turn reminders off on that device (or everywhere) or delete your account. Addresses a push service reports as expired are deleted right away, and after 5 failed deliveries in a row.
Security counters
Hashed network addresses for rate limits and lockouts expire within 24 hours.
Technical logs
Kept by Cloudflare for a short period, typically no more than 30 days.
Payment event records
Stripe event IDs (no personal details) for 90 days, to avoid processing a payment event twice.
Backups
Deleted data can remain in encrypted database backups for up to 30 days before it is overwritten.
Payment records at Stripe
Kept by Stripe as required by tax, accounting and anti-fraud laws, under Stripe’s privacy policy.

10. Your choices and deletion

  • Edit your questionnaire any time in Profile → Edit answers, and delete individual measurements in the Journal (also after a trial or subscription ends: choose “See my plan and history” on the subscribe screen).
  • Challenges: delete any of your entries (with its photo or video), or leave a challenge (your entries, photos and videos in it are deleted). See Challenges.
  • Programs: make a program private or delete it on its page in the Programs tab (people who already started it keep their copy), and change or remove your rating or review (a review our moderators removed stays removed; you can still change its stars).
  • Social: change who sees your workouts (and your earlier posts) in Feed → your profile → Edit profile, change who sees one post or hide it from its menu, delete your comments, remove followers, block people, and switch off the body-weight change on posts. See Social.
  • Ideas and support: delete an idea of yours while it is still New (open it on the board → Delete my idea), and delete any of your support requests in Help.
  • Disconnect Apple Health in Profile → Apple Health. This deletes the Apple Health summaries stored in your account right away (see Apple Health).
  • Delete your account in Profile → Delete account (enter your PIN to confirm). This immediately removes your profile, plans, workouts, measurements, settings, sessions, invite records and subscription record from our live database, deletes your challenge entries, photos and videos and the challenges you started, your public profile, posts, follows, blocks, kudos, comments, reports and notifications, your support requests, your votes and your ideas that are still waiting (ideas already on the roadmap stay without your name), deletes the programs you built (with their ratings, reviews and reports) and your ratings and reviews of other programs, and ends your subscription so you are not charged again.
  • Get a copy of your data or ask any other privacy question by emailing [SUPPORT EMAIL] with the subject “Privacy request”.

Because accounts use only a name and PIN, we need to confirm a request really comes from you. We may ask you to confirm it from inside your signed-in account, or ask for details only the account owner would know. We will not ask for your PIN by email.

11. US state privacy rights

Depending on where you live — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Washington, Nevada and other states with privacy laws — you may have the right to:

  • know what personal data we collect, use and disclose, and get a copy in a portable format;
  • correct inaccurate data;
  • delete your data;
  • opt out of the sale of personal data, targeted advertising and profiling (we do none of these);
  • limit the use of sensitive personal data (we already use it only to provide the Service);
  • withdraw consent for health data processing;
  • not be discriminated against for using these rights;
  • appeal if we decline your request — reply to our decision with “Appeal” in the subject. If we deny the appeal, you can contact your state attorney general.

To use these rights, email [SUPPORT EMAIL]. You may use an authorized agent; we may ask the agent for proof of authorization and confirm the request with you. We respond within the time the law requires (for example 45 days in California).

California notice at collection

In the past 12 months we have collected these categories of personal information: identifiers (display name, internal account ID, IP address, Stripe IDs); commercial information (subscription and purchase history); characteristics of protected classifications (sex and age); sensitive personal information (health-related fitness data, and your PIN as a hashed account credential); internet or network activity (technical logs); and inferences (your recommended plan and calorie targets). We collect them from you and your device for the purposes in section 3, disclose them only to the service providers in section 6, and keep them for the periods in section 9. We do not sell or share personal information, including that of consumers under 16.

12. Visitors outside the US

BindTrue is operated from the United States and runs on Cloudflare’s global network, so your data may be processed in the US and other countries. Our providers use recognized safeguards such as Standard Contractual Clauses for international transfers.

If laws such as the EU or UK GDPR apply to you, our legal bases are: performing our contract with you (running the Service and billing), your explicit consent (health-related data you choose to enter), our legitimate interests (security, fraud prevention, improving the Service), and legal obligations (tax and accounting). You have the rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent at any time, and lodge a complaint with your local data protection authority.

13. Children

BindTrue is not directed to children, and you must be at least 16 to use it: we ask you to confirm it when you create an account (and before your first challenge, if your account is older than that question). We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us at [SUPPORT EMAIL] and we will delete it.

14. Security

  • All traffic is encrypted with HTTPS, and data is encrypted at rest by our hosting provider.
  • PINs are stored as salted, slow PBKDF2 hashes; sign-in tokens are stored only as hashes; the session cookie is HttpOnly and Secure.
  • Every account can only read and change its own data. Only a small number of authorized BindTrue administrators can access account records, and only for support, security or billing.
  • Repeated wrong PINs lock the account temporarily, and requests are rate limited.
  • No system is perfectly secure. Use a PIN you do not use elsewhere, and sign out on shared devices. If a breach affects your data, we will notify you and the authorities as the law requires.

15. Changes to this policy

We will update this policy when the app or the law changes. If a change is material, we will tell you in the app before it takes effect and, where required, ask for your consent. The “Last updated” date shows the current version.

16. Contact us

[COMPANY LEGAL NAME]
[MAILING ADDRESS]
Email: [SUPPORT EMAIL] (subject “Privacy request”)

© 2026 [COMPANY LEGAL NAME] Terms of Service Back to BindTrue