Privacy Policy
Draft — pending legal review. This policy describes how the app works today, but it is not final. Items shown like [THIS] must be filled in, and a qualified lawyer should review it before paid subscriptions start.
The short version
- We collect only what the app needs: a display name, a PIN (stored as a one-way hash), your questionnaire answers, and the workouts and measurements you log.
- Some of this — such as your sex, age, height, weight, injuries and measurements — can count as health-related data. We use it only to build your plan and show your progress.
- We do not sell your data, share it for advertising, or show ads. No third-party analytics or ad trackers.
- Our service providers are Cloudflare (hosting, database, AI) and Stripe (payments); AI requests may go to OpenAI or xAI instead if we switch them on (see AI processing). Stripe handles your card — we never see the full number.
- In the BindTrue iPhone app you can choose to connect Apple Health. We then keep daily activity totals in your account. They are never sold, never used for ads and never sent to AI, and disconnecting deletes them (see Apple Health).
- If you sign up with a friend’s invite link, we record who invited you and when, and that friend can see your public name (or only its first letter, until you choose one), when you joined and whether you have trained once — nothing else (see Invites).
- If you join a challenge, the other people in it see the public name you choose for challenges (never the name you sign in with), your entries and the photos or videos you add as proof. In a public challenge (an official one or the weekly challenge) that is the people in your league, up to 30 who joined the same week at your level. Photos and videos are for people 18 and older, and an automatic check looks at each one before others see it. Proof photos and videos are deleted 30 days after the challenge (or your run in it) ends (see Challenges).
- If you share a program you built, people who open its link — or everyone, if you publish it — see the program and the public name you chose, never your sign-in name. Its text is checked automatically first, by OpenAI’s moderation service and, before it is listed for everyone, by our AI provider (see Programs).
- In the Feed, other members can see your public profile (public name, handle, bio) and the workouts you share: with every member, with your followers (the default) or with no one. Never your sign-in name, questionnaire answers or weight. Comments, notes, bios and names can be checked automatically for harmful content (see Social).
- Delete your account any time in Profile → Delete account. Your data is removed from our live database right away.
- If you post on the ideas board, signed-in people see your idea, its votes and your public name. Help answers come from an AI that reads your question; requests you send with Contact support go to the owner (see Ideas, Help and support).
- BindTrue is not for anyone under 16.
1. Who we are
BindTrue (bindtrue.com) is operated by [COMPANY LEGAL NAME] (“BindTrue”, “we”, “us”). We are responsible for the personal data described in this policy. Questions or requests: [SUPPORT EMAIL].
2. What we collect
Information you give us
- Account
- Display name and your PIN. The PIN is stored only as a salted PBKDF2-SHA256 hash, so we cannot read it. We also create an internal account ID and record when the account was created.
- Questionnaire
- Sex, birth year (used to calculate age), height, weight, main goal, experience level, workouts per week and minutes per workout, where you train (equipment), daily activity level, and — if you choose to fill them in — free-text notes about injuries or limitations and what you want to achieve.
- Training and body data
- Your training plan and up to 4 earlier versions, completed sets, weights and reps, finished workouts, body measurements you log (such as weight or waist), and in-app settings (for example calculator inputs, exercise swaps and preferences).
- Apple Health (optional, iPhone app only)
- If you connect Apple Health in the BindTrue iPhone app, daily activity totals and the workouts recorded on your iPhone or Apple Watch. See Apple Health for the exact list.
- AI features
- If you use AI features such as AI plan updates or an AI coach, the requests and messages you send and the answers you receive.
- Subscription
- Your plan (monthly or yearly), status (trial, active, past due, canceled), trial and renewal dates, and the Stripe customer and subscription IDs that link your account to Stripe. See Payments.
- Invites
- Your personal invite code, made the first time the app shows your invite link. If you create an account with someone’s invite link, we store who invited you, when, and whether the link also invited you to a challenge. We use this, and whether they logged a workout or had a challenge entry count, to count the friends who joined with your link and trained once, which decides free use during the beta (see the Terms). We never read your contacts: you choose whom to send your link to, through your phone’s share menu or an app you pick (such as WhatsApp, Telegram or SMS), and that app’s own policy applies to what you send there.
- Challenges (optional)
- If you start or join a challenge: the public name you choose for challenges, that you confirmed you are 16 or older (and, for photos and videos, 18 or older, with the time you confirmed it), the challenge (its name, goal, dates, the kind of proof it asks for, any team names or stake its starter wrote, and the prize they offer: its kind, name, note and photo, with the photo’s automatic check result), that you are a member, when you joined and your team, the entries you log (day, amount and an optional note), the photos or short videos you add as proof and the result of their automatic check (fine, flagged with the categories the check named, or not checked), the cheers you give, and the reports you make about entries (with the optional reason you write). In an official challenge or the weekly challenge also: your level (from your questionnaire, or the one you pick when you join), the day your run started and ended, your daily goal and your league. Your badges and points: which ones, what you earned them in and when. See Challenges for who sees what.
- Programs (optional)
- Programs you build (name, summary, goal, training style, level, weeks, the days with their exercises, sets, reps, rest and notes, a warm-up and cool-down), whether each one is private, shared by link or public, and the result of the automatic check when you share it; which shared programs you started and when; the ratings and short reviews you write; and the reports you make about programs or reviews (with the optional reason). See Programs for who sees what.
- Social (optional)
- Your public profile: a handle made from your public name (you can change it), an optional short bio, who may see your workouts (everyone, followers or only you) and whether your posts may show your body-weight change. The posts on your feed: for a finished workout the day’s title, minutes, number of exercises and sets and new personal records; weekly streak milestones; posts that other BindTrue features add for you (for example a program you published); and the notes you add. The people you follow and who follow you, the people you blocked, the kudos and comments you give and get, the reports you make (with the optional reason), in-app notifications, and your weekly streak goal and the free streak repairs you used. See Social for who sees what.
- Ideas, Help and support (optional)
- On the ideas board (Profile → Ideas & voting): the ideas you post (title and details), your votes, the reports you make about ideas (with the optional reason), and when. For each idea we also keep what our systems added: an AI summary, a category, whether it touches a sensitive area (such as money or personal data), the result of the automatic content check, and every status change with who or what decided it. In Help: the questions you ask are answered and then forgotten — the conversation stays in your browser’s memory while Help is open and is not stored on our servers. If you tap Contact support, we keep your request (topic and message), the help-chat turns you chose to attach, the owner’s answer and whether you have read it. See the ideas board for who sees what.
- Workout reminders (optional)
- If you turn on reminders, we store the time and weekdays you chose, your device’s time zone, and for each device (up to 5) the push address that your browser’s push service gives us (Apple, Google, Mozilla or Microsoft, depending on the browser). Reminders carry no content: the push service only delivers an empty signal, and your device then asks BindTrue for the text, so the push service never sees your plan or workouts. We do not keep the message-encryption keys browsers offer. Turn reminders off in Profile → Workout reminders and the push address is deleted; it is also deleted when a push service reports it expired, after repeated failed deliveries, and with your account. The time, weekdays and time zone you chose stay saved until you delete your account, so turning reminders back on restores your schedule.
Information collected automatically
- Session cookie
- A random sign-in token that keeps you logged in. We store only a hash of it on our side.
- Network and device data
- Your IP address, browser type and the pages or API calls requested, processed by Cloudflare to deliver the app, keep it secure and keep short-lived technical logs. For rate limits and PIN lockouts we store a salted one-way hash of your network address that expires within 24 hours.
- Local storage on your device
- Your browser keeps dismissed banners, a workout in progress, and your recent AI-coach conversation (last 20 messages). The recent coach messages are sent along with each new coach question so the coach can follow the conversation; the rest is not sent to us. Signing out or deleting your account clears it from that browser. When a session ends on its own (for example after you change your PIN on another device, or after 180 days), it is cleared too, except changes you made offline that have not reached your account yet: they stay in that browser for that account only and are sent when you sign in to it there again; after 14 days they are no longer sent and are deleted the next time BindTrue opens in that browser.
What we do not collect
No email address or phone number at sign-up, no precise location, no contacts, no access to your camera or photo library (a photo or video you pick yourself as challenge proof is uploaded only when you choose to), no advertising IDs, and no third-party analytics or advertising trackers. (If you subscribe, Stripe collects an email address for receipts — see Payments.) The iPhone app reads Apple Health data only if you connect it, and only the types listed in Apple Health.
3. How we use it
- To provide the Service: build and adjust your plan, calculate calories and protein, show “last time” weights, save workouts and measurements, and draw progress charts.
- For AI features: to generate or update your plan and answer your questions (see AI processing).
- For billing: to run your free trial, start and renew subscriptions, handle failed payments and refunds, and decide which features you can use.
- For invites: to show you the friends who joined with your link and to apply the free-with-friends rule of the beta.
- For security: to protect accounts (PIN lockouts, rate limits), prevent fraud and abuse such as repeated free trials, and fix errors.
- To support you when you contact us.
- To improve BindTrue using aggregated, non-identifying statistics (for example how many plans were generated).
- To follow the law, for example tax and accounting rules for payments.
We do not use your data for advertising, we do not sell it, and we do not use it to make decisions about you that have legal or similarly significant effects (such as credit, insurance or employment).
4. Health-related data
Your sex, age, height, weight, injuries or limitations, measurements and workout history may be treated as health data or “consumer health data” under some laws (for example Washington’s My Health My Data Act, Nevada law, and other US state privacy laws). This section also serves as our consumer health data privacy notice.
- What: the questionnaire, training and body data listed in section 2.
- Why: only to provide the features you ask for — your plan, nutrition estimates, tracking and progress.
- Source: you, and — only if you connect it in the iPhone app — Apple Health on your own iPhone (see below). We do not buy or receive health data from anyone else.
- Consent: we collect it only when you choose to enter it. Free-text fields are optional.
- Sharing: only with our processors to run the Service: Cloudflare for storage and AI, and OpenAI or xAI for AI requests if we switch them on (see AI processing). We never sell it or share it for advertising.
- Your rights: you can see and edit your answers in the app, delete individual logs, delete your whole account, withdraw consent by deleting the data, and ask us which data we hold and who has processed it (see sections 10 and 11).
Apple Health (BindTrue iPhone app)
Connecting Apple Health is optional, and everything in BindTrue works without it. You choose in the iPhone app (Profile → Apple Health), and iOS then asks which data BindTrue may read and write. If you connect it:
- What BindTrue reads
- Active energy (active calories), steps, exercise minutes, and workouts (type, start and end time, duration, calories, and the name of the app or device that recorded them), from your iPhone and Apple Watch. Nothing else: BindTrue does not read heart rate, body weight or any other Apple Health data.
- What BindTrue writes
- Your finished BindTrue strength workouts: start and end time, and an estimate of the active calories burned — only when nothing else, such as an Apple Watch, has already measured that time, so calories are never counted twice.
- Why
- To show your activity in the app (today and the last 7 days), to adjust today’s food target to how much you really move, and to let your BindTrue workouts count in Apple Health.
- What we store
- One summary per calendar day: the daily totals above and the workouts of that day, plus your time zone. Never minute-by-minute samples. The summaries are stored in your BindTrue account in our Cloudflare database, encrypted in transit (HTTPS) and at rest, so you can see them on any device. Days older than 400 days are deleted automatically.
- What we never do
- We never sell Apple Health data, never use it for advertising, marketing or data mining, never share it with anyone else (Cloudflare only stores it for us as our database provider), and never send it to the AI plan or the AI coach. We do not store it in iCloud.
- How to stop
- In the iPhone app, Profile → Apple Health → Disconnect deletes every Apple Health summary stored in your BindTrue account right away and stops syncing on all your devices. (Signed in on the web, the same sheet offers “Delete Apple Health data”.) To stop BindTrue from reading Apple Health at all, also turn it off in iPhone Settings → Health → Data Access & Devices → BindTrue. Deleting your account deletes the summaries too. Your data in the Health app itself is not changed.
5. AI processing
Who answers. AI plans, AI plan updates and the AI coach are answered by an AI model. By default this is Cloudflare Workers AI (open AI models that Cloudflare runs for us). We may switch AI requests to OpenAI (the maker of ChatGPT) or xAI (the maker of Grok). When one of them is on, it answers your AI requests, and Cloudflare Workers AI answers only if that service fails or is too slow.
What we send. For an AI plan or an AI update: your questionnaire answers (with age, height and weight converted to numbers), your injury/limitation and goal notes if you wrote any, the plan to personalize, and — for updates — a summary of your last 5 weeks of workouts and measurements. For the AI coach: your message, your recent coach conversation and training context (your questionnaire answers, your plan, your recent training numbers and body-weight entries). We never send your display name, your PIN or Apple Health data.
How providers handle it. We send requests to OpenAI and xAI with store: false, which tells them not to store the request and the answer for later retrieval. Their API data terms apply to what they receive; under those terms they may still keep requests for a limited time (usually up to 30 days), for example to detect abuse. Cloudflare processes requests under its data processing terms.
Automatic content check. When you post a comment or a note, or save a public name, handle or bio, its text may be sent to OpenAI’s moderation service (a safety classifier, not a chatbot) to check for harmful content such as harassment, hate or sexual content. Only that text is sent, without your name or account. If the check flags it, the text stays hidden from others until our team reviews it (a flagged public name or handle is refused). If the check is not available, the text is shown as usual and can still be reported.
In the iPhone app we ask for your permission once, before the first AI request on that device, and name the provider and what is sent; if you decline, the app keeps working without AI. The model’s answer is checked and saved as your plan. While the AI works on a plan or an update, and until you use or decline its result, we keep a copy of what we sent it and of its answer with the request. That copy is deleted as soon as the request ends (you apply or decline the result, choose another plan, or the request fails), and after 7 days at the latest. The record that the request happened (its status and dates, without that content) is deleted 2 days after it ended. Please avoid writing anything in free-text fields that you would not want processed to create your plan.
Ideas, Help and the owner’s weekly report. The same AI provider also reads: a new idea’s title and details, with the titles and summaries of other ideas on the board, to sum it up, sort it, spot a duplicate and flag sensitive areas; your Help question with your last few questions in that Help conversation and our help pages, to answer it; and, once a week, numbers about how the app is used (sign-ups, workouts, challenges, votes, open requests) with the titles of the most-voted ideas, to write a short report for the owner. We never send your name, public name, PIN or account ID with these. Ideas, Help questions and support requests also go through OpenAI’s content check (its moderation endpoint), which only answers whether a text looks abusive; a flagged idea waits for a person to review it. An AI never decides about payments, refunds, your account or legal matters: those go to the owner.
Voice coach (AI voice)
The voice coach in workout mode is off until you turn it on. It speaks with AI-generated voices: short clips made with OpenAI’s text-to-speech from a fixed list of coaching phrases we wrote (numbers, “two more”, rest and hold cues, exercise names). The voices are not real people. We make each clip once and keep it on our servers (Cloudflare R2); nothing about you is sent to make them — no name, answers, workouts or voice — and nothing about your workout leaves your device for the coach to talk: the app plays the stored clips. Clips your device has played are kept in its cache so the coach also works without signal. When a clip is not ready yet, your device’s own built-in voice reads the phrase instead. Your choices (on or off, voice, volume, tempo and which cues) are saved with your account’s app settings.
7. Payments
Checkout and the subscription management page are hosted by Stripe. Your card number and other payment details go directly to Stripe and are never stored on BindTrue’s servers. Stripe collects your email address (for receipts and renewal reminders), payment method and billing country or postal code. In our Stripe account we can see your email, card brand, last four digits and payment history, which we use only for billing and support. In the BindTrue database we keep just your subscription status, dates and Stripe IDs.
9. How long we keep data
- Account and training data
- Until you delete it or delete your account. Only your 5 most recent plans (the current one and up to 4 earlier versions) are kept.
- AI plan requests
- The copy of your answers (including injury notes) and training summary sent to the AI, and the AI’s answer: until the request ends (you apply or decline the result, choose another plan, or it fails), and never longer than 7 days. A record of the request without that content (its status and dates) is kept for 2 more days, so an applied AI plan can still be undone within 24 hours.
- Apple Health summaries
- Until you disconnect Apple Health or delete your account; days older than 400 days are deleted automatically.
- Invites
- Your invite code and the record of who invited whom: until one of the two accounts is deleted.
- Challenge photos and videos
- 30 days after the challenge’s last day, or sooner when you delete the entry, leave the challenge, are removed from it, the challenge is deleted, an admin removes the entry after a report, or you delete your account. Challenge entries (numbers and notes): until the challenge is deleted or you delete them, leave or delete your account. Reports about entries: until the entry, the challenge or the reporting account is deleted. Your public name and 16+ confirmation: until you delete your account.
- Programs
- Until you delete the program or your account. Who started a program, ratings and reviews: until the program or the account that made them is deleted (you can take your rating back at any time, except a review our moderators removed: it stays hidden until then, so it can’t be posted again). Reports about programs or reviews: until the program, the review or the reporting account is deleted.
- Social
- Your profile, follows, blocks, posts, kudos and comments: until you delete them (a comment, a follow, a block) or your account. A workout’s post goes when you delete that workout, within a few days. Notifications: read ones after 60 days, any after 180 days, and at most your 300 newest are kept. Reports and admin decisions: until the reported item, its author or the reporting account is deleted. Weekly streak goals and repairs: until you delete your account.
- Sign-in sessions
- Up to 180 days, or until you sign out or change your PIN.
- Ideas and votes
- Until you delete the idea (possible while it is New, Declined or Merged) or your account. When you delete your account, your ideas that are still waiting and your votes are deleted; ideas already Planned, being built or Shipped stay on the board without your name. Reports about ideas: until the idea or the reporting account is deleted. Records of moderation decisions (which item, the decision and the admin’s note): 2 years.
- Help and support
- Help conversations are not stored on our servers. Support requests and answers: until you delete them in Help or delete your account.
- The owner’s weekly reports
- Usage numbers and the titles of the most-voted ideas, without names: 1 year.
- Reminder settings
- The reminder time, weekdays and time zone: until you delete your account (they are kept when you turn reminders off).
- Push addresses
- Until you turn reminders off on that device (or everywhere) or delete your account. Addresses a push service reports as expired are deleted right away, and after 5 failed deliveries in a row.
- Security counters
- Hashed network addresses for rate limits and lockouts expire within 24 hours.
- Technical logs
- Kept by Cloudflare for a short period, typically no more than 30 days.
- Payment event records
- Stripe event IDs (no personal details) for 90 days, to avoid processing a payment event twice.
- Backups
- Deleted data can remain in encrypted database backups for up to 30 days before it is overwritten.
- Payment records at Stripe
- Kept by Stripe as required by tax, accounting and anti-fraud laws, under Stripe’s privacy policy.
10. Your choices and deletion
- Edit your questionnaire any time in Profile → Edit answers, and delete individual measurements in the Journal (also after a trial or subscription ends: choose “See my plan and history” on the subscribe screen).
- Challenges: delete any of your entries (with its photo or video), or leave a challenge (your entries, photos and videos in it are deleted). See Challenges.
- Programs: make a program private or delete it on its page in the Programs tab (people who already started it keep their copy), and change or remove your rating or review (a review our moderators removed stays removed; you can still change its stars).
- Social: change who sees your workouts (and your earlier posts) in Feed → your profile → Edit profile, change who sees one post or hide it from its menu, delete your comments, remove followers, block people, and switch off the body-weight change on posts. See Social.
- Ideas and support: delete an idea of yours while it is still New (open it on the board → Delete my idea), and delete any of your support requests in Help.
- Disconnect Apple Health in Profile → Apple Health. This deletes the Apple Health summaries stored in your account right away (see Apple Health).
- Delete your account in Profile → Delete account (enter your PIN to confirm). This immediately removes your profile, plans, workouts, measurements, settings, sessions, invite records and subscription record from our live database, deletes your challenge entries, photos and videos and the challenges you started, your public profile, posts, follows, blocks, kudos, comments, reports and notifications, your support requests, your votes and your ideas that are still waiting (ideas already on the roadmap stay without your name), deletes the programs you built (with their ratings, reviews and reports) and your ratings and reviews of other programs, and ends your subscription so you are not charged again.
- Get a copy of your data or ask any other privacy question by emailing [SUPPORT EMAIL] with the subject “Privacy request”.
Because accounts use only a name and PIN, we need to confirm a request really comes from you. We may ask you to confirm it from inside your signed-in account, or ask for details only the account owner would know. We will not ask for your PIN by email.
11. US state privacy rights
Depending on where you live — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Washington, Nevada and other states with privacy laws — you may have the right to:
- know what personal data we collect, use and disclose, and get a copy in a portable format;
- correct inaccurate data;
- delete your data;
- opt out of the sale of personal data, targeted advertising and profiling (we do none of these);
- limit the use of sensitive personal data (we already use it only to provide the Service);
- withdraw consent for health data processing;
- not be discriminated against for using these rights;
- appeal if we decline your request — reply to our decision with “Appeal” in the subject. If we deny the appeal, you can contact your state attorney general.
To use these rights, email [SUPPORT EMAIL]. You may use an authorized agent; we may ask the agent for proof of authorization and confirm the request with you. We respond within the time the law requires (for example 45 days in California).
California notice at collection
In the past 12 months we have collected these categories of personal information: identifiers (display name, internal account ID, IP address, Stripe IDs); commercial information (subscription and purchase history); characteristics of protected classifications (sex and age); sensitive personal information (health-related fitness data, and your PIN as a hashed account credential); internet or network activity (technical logs); and inferences (your recommended plan and calorie targets). We collect them from you and your device for the purposes in section 3, disclose them only to the service providers in section 6, and keep them for the periods in section 9. We do not sell or share personal information, including that of consumers under 16.
12. Visitors outside the US
BindTrue is operated from the United States and runs on Cloudflare’s global network, so your data may be processed in the US and other countries. Our providers use recognized safeguards such as Standard Contractual Clauses for international transfers.
If laws such as the EU or UK GDPR apply to you, our legal bases are: performing our contract with you (running the Service and billing), your explicit consent (health-related data you choose to enter), our legitimate interests (security, fraud prevention, improving the Service), and legal obligations (tax and accounting). You have the rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent at any time, and lodge a complaint with your local data protection authority.
13. Children
BindTrue is not directed to children, and you must be at least 16 to use it: we ask you to confirm it when you create an account (and before your first challenge, if your account is older than that question). We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us at [SUPPORT EMAIL] and we will delete it.
14. Security
- All traffic is encrypted with HTTPS, and data is encrypted at rest by our hosting provider.
- PINs are stored as salted, slow PBKDF2 hashes; sign-in tokens are stored only as hashes; the session cookie is HttpOnly and Secure.
- Every account can only read and change its own data. Only a small number of authorized BindTrue administrators can access account records, and only for support, security or billing.
- Repeated wrong PINs lock the account temporarily, and requests are rate limited.
- No system is perfectly secure. Use a PIN you do not use elsewhere, and sign out on shared devices. If a breach affects your data, we will notify you and the authorities as the law requires.
15. Changes to this policy
We will update this policy when the app or the law changes. If a change is material, we will tell you in the app before it takes effect and, where required, ask for your consent. The “Last updated” date shows the current version.
16. Contact us
[COMPANY LEGAL NAME]
[MAILING ADDRESS]
Email: [SUPPORT EMAIL] (subject “Privacy request”)