BioForm AI — Privacy Policy
Overview
This policy covers BioForm AI: the iPhone app, the web interface at console.bioform.app where coaches and clients review shared scans, and this website.
BioForm AI measures posture and movement on your device. It is local-first, and that claim is specifically about your captures: your photos, video, pose landmarks, measurements, and profile stay on your phone. They leave only if you deliberately share them with a connection or back them up to your own cloud.
Two things do reach our servers regardless, and we'd rather say so here than bury it: if you create an account, your email address is stored so we can sign you in; and whenever the app talks to our cloud, our providers record ordinary connection metadata such as IP address and timestamp. Neither involves your captures. Both are described in full below.
Personal information we collect
Information you provide.
- Account data — your email address (for magic-link sign-in), or the Apple ID relay address if you use Sign in with Apple.
- Profile data — name, role (self-trainer, coach/practitioner, client), date of birth, height, biological sex, injury history, and training goals. Some of this is health-related information; see Sensitive information below.
- Captures — posture photos, movement video, and the body-pose landmarks derived from them (Apple Vision — body only, no face data).
- Derived measurements — joint angles, alignment markers, severity indicators, and other values computed from your captures.
- Shared content — comments and annotations you or your connections add to shared media.
Collected automatically. BioForm AI contains no analytics, telemetry, crash-reporting, advertising, or tracking SDKs. We do not log your in-app activity. However, when the app contacts our cloud (only for sign-in, sharing, or connections), our infrastructure providers record standard server-side connection metadata — IP address, timestamp, and request information — as an ordinary part of operating and securing a network service. Apple may also provide us with aggregated crash and performance reports through App Store Connect if you have enabled sharing those with developers in your iOS settings; that is a setting you control on your device.
Sensitive information. Some of what BioForm AI handles is sensitive, and it's worth being precise about why, because two different rules are in play.
As biometric data: California's CCPA expressly names "gait patterns or rhythms" in its definition of biometric information — and BioForm measures gait. That definition is about purpose, though: it covers such characteristics where they are used, or intended to be used, to establish an individual's identity, and they become sensitive personal information only where processed to uniquely identify a consumer. We do neither. We measure your gait to tell you about your movement, never to identify you or anyone else, and we build no identifier templates.
As health data: separately from any of that, information collected and analyzed concerning your health can be sensitive personal information in its own right. Your injury history is plainly health-related, and your movement measurements may be too. We therefore treat this data as sensitive regardless of the biometric question, rather than resting on the identity argument above.
What that means in practice: it stays on your device by default; we use it to produce the measurements and comparisons you asked for; we never sell it, share it for advertising, or use it to build a profile of you for any other purpose. The one exception is research contribution — which is off by default, happens only if you deliberately switch it on, and which you can switch off again at any time. If you want us to limit our use of your sensitive information further, contact us (see Your privacy rights).
We would rather tell you where the law is unsettled than imply more certainty than exists. Whether these measurements count as "health data" under Cal. Civ. Code §1798.140(ae)(2)(B), and whether deriving severity indicators amounts to "inferring characteristics" under §1798.121(d), are genuinely open questions. We have taken the cautious side of both — treating the data as sensitive — so that however they are resolved, what we actually do with your data does not change.
Where your data lives
On-device (never leaves your phone unless you act). Captures, landmarks, derived measurements, and your profile are stored in the app's local database. Core analysis runs entirely on-device.
When you share with a connection. If you invite another user or share media across an accepted connection, the shared media — including the video itself, where you share a video — is uploaded to our cloud (Supabase) along with any comments and annotations, so the other person can see it. This is the main reason your capture data reaches our cloud, and it only happens because you chose to share. Local copies of shared data are a cache of the cloud record. How long that uploaded copy lives is described under Retention & deletion below.
Account & sign-in. Sharing requires an account. We use email magic-link sign-in and Sign in with Apple (via Supabase Auth). Your email address is stored to manage your account.
Backup (optional, your cloud). You can back up your data to your own iCloud or Google Drive. That copy lives in your personal cloud account under its terms, not ours.
Research (optional, off by default). If you explicitly opt in to research contribution, contributed data may be used to improve the models. This is off unless you turn it on, and you can turn it off again at any time.
How we use your information
We use your information only to: provide the app and its measurement features; operate sharing and connections you initiate; create and secure your account; respond to your support requests; keep the service secure and prevent abuse; comply with law; and — only if you opt in — improve our models through research contribution.
We do not use your information for advertising, marketing profiling, or automated decision-making that produces legal or similarly significant effects about you.
How we share your information
- Service providers (sub-processors) — Apple (Sign in with Apple, iCloud backup, App Store), Supabase (cloud database, authentication, storage for shared content), Google (Drive backup — only if you choose it), Cloudflare (website hosting and email routing). They process data on our behalf to run the service.
- People you share with — anyone you deliberately share media or scans with through a connection, which is the entire point of the sharing feature.
- Legal and safety — law enforcement or other parties where we believe in good faith it is necessary to comply with law, enforce our Terms, or protect the rights, safety, or property of you, us, or others.
- Business transfers — if BioForm AI is ever involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We would notify you of any such change in control of your data.
What we never do. We do not sell your personal information, we do not "share" it for cross-context behavioral advertising, we run no ads or ad identifiers, we use no third-party trackers, no analytics cookies and no advertising cookies anywhere, and we do not collect face data. The web interface sets one kind of cookie only: a first-party session cookie that keeps you signed in. It is strictly necessary for the site to work, it is not used to track you, and signing out clears it.
Retention & deletion
On your device. Local data persists until you delete a scan or uninstall the app (uninstall wipes the app's local storage). Source video you capture for yourself is deleted on the device once it has been processed into frames and measurements.
In our cloud. This covers shared media; account, connection, and consent records are covered under account deletion below. Sharing a video uploads it to our storage so the recipient can download it. We want to be exact about how long that copy lives, because the honest answer is less tidy than "it's deleted automatically":
- Deletion is currently triggered by the person who shared, not by a timer. The sharer runs a cleanup from the app's settings, which removes eligible videos from our storage where it can — see the cancellation note below for a case where it currently cannot. A video becomes eligible once the recipient has downloaded it and 24 hours have passed, or once it is more than 30 days old and still present.
- Until that cleanup is run, the uploaded video remains in our storage. As of 2026-08-21 there is no scheduled job deleting it for you. An automatic sweep is planned, and this policy will be updated to describe it when it exists.
- Cancelling a share immediately stops the recipient from downloading it. Be aware, though, that the uploaded file itself is not currently removed when you cancel — a known limitation in how our storage permissions work means the cleanup pass cannot delete a cancelled share's file (verified 2026-08-21). The file stays in our storage, unreachable by the recipient, until we ship the fix. We are not going to describe this as deleted when it isn't. If you want a cancelled share's file removed now, contact us.
- The thumbnail is deliberately kept after the video is deleted, so the recipient's inbox entry still shows what the share was. A still image from your video therefore outlives the video itself.
- Deleting your account does not remove everything, and you should know which parts persist. Account and sharing records are removed. But two categories are deliberately kept:
- Consent and policy-acceptance records. When you accept these documents, or when a practitioner records your consent, we write an append-only entry — who accepted what version, and when. These are retained as evidence that consent was given, which is a legitimate basis for keeping records even after a deletion request. They carry an identifier and a name snapshot, never your scans, media, or measurements.
- Consent-evidence images, where a practitioner uploaded a photograph of a signed paper form, are retained on the same basis.
- Separately, and unlike the above, uploaded share files can be left behind for the technical reasons described earlier on this page — that is a limitation we intend to fix, not a deliberate retention policy.
If you want your data removed and are unsure what survives, contact us and we will tell you exactly what is held and remove whatever we are able to.
If you have shared a video and want it removed from our storage now, run the cleanup in settings, or contact us and we will action it.
More generally, we keep personal information only as long as needed for the purpose it was collected — providing the service to you — plus any period required to meet legal obligations, resolve disputes, or enforce our agreements. When it is no longer needed, we delete or anonymize it. You can request deletion at any time (see Your privacy rights).
Security
We use technical and organizational safeguards designed to protect your information: on-device storage in the iOS application sandbox, encryption in transit, and database access controls (row-level security) so that cloud records are reachable only by the accounts entitled to them. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
International data transfer
We are based in the United States, and our cloud database is currently hosted in the Americas region. If you use BioForm AI from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those of your country. The controller is BioForm AI LLC, a Connecticut company (see Contact). [Not final — the operator's country of residence is expected to change, and the transfer mechanism for any material EU/UK user base is still to be confirmed with counsel.]
Your privacy rights
Depending on where you live, you may have the right to: know what personal information we collect and how we use it; access a copy of it; correct inaccurate information; delete it; opt out of sale, sharing for targeted advertising, or profiling (we do none of these); appeal a decision we make on your request; and not be discriminated against for exercising any of these rights.
Some of these laws apply only to businesses above certain revenue or user-volume thresholds, which BioForm AI does not currently meet. We describe and honor these rights regardless of whether we are strictly required to.
How to exercise them. Email feedback@bioform.app with what you'd like to do. Because most of your data never leaves your device, you can already do much of this yourself in the app — delete individual scans, delete shared content, or uninstall to remove local data entirely. For anything in our cloud (your account, shares, connections), email us and we will action it.
Verification. We may need to verify that a request is really from you — normally by confirming control of the email address on the account. We will not ask for government ID for a routine request. You may use an authorized agent where state law allows; we may ask for proof of their authority.
Do Not Track and Global Privacy Control. We do not track you across other sites or services, so there is nothing for these signals to opt you out of. Our website honors Global Privacy Control signals where applicable.
Children
BioForm AI is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us and we will delete it. Users under 18 should have a parent or guardian review this policy; where a practitioner captures media of a minor client, obtaining parental consent is that practitioner's responsibility (see the Terms at Terms & Conditions, §5, and the client consent form at the client consent form).
Other sites and services
Our website and app may link to services operated by third parties (for example, Apple's App Store or your cloud-backup provider). We do not control those services and are not responsible for their privacy practices. We encourage you to read their policies.
Categories of personal information (CCPA reference)
For California residents, the table below maps what we collect to the statutory categories in Cal. Civ. Code §1798.140. Most of it comes directly from you or is generated from your captures on your device; the exception is server connection metadata, which our infrastructure providers record automatically when the app contacts our cloud. Where a row says data reaches Supabase "when you share," that is conditional on your choice to share — it does not happen otherwise.
| CCPA category | What that means here | Source | Purpose | Disclosed to | Sold / shared |
|---|---|---|---|---|---|
| Identifiers | Email address, Apple relay address, account ID | From you | Account creation, sign-in, sharing | Supabase (auth/database), Apple (Sign in with Apple) | No |
| Customer records (§1798.80) | Name, height, biological sex | From you | Provide measurement features | Stays on your device. Your display name only may accompany a consent record | No |
| Protected classifications | Date of birth / age, biological sex | From you | Age-appropriate measurement baselines | Stays on your device | No |
| Biometric information | Body-pose landmarks, posture, gait and movement measurements | Generated on your device | The core measurement feature | Stays on your device, except measurements attached to something you share, which reach Supabase and your recipient | No |
| Audio/electronic/visual | Posture photos and movement video | Captured on your device | The core measurement feature | Stays on your device, except media you share, which reaches Supabase and your recipient | No |
| Internet/network activity | Server connection metadata (IP, timestamp, request info) | Recorded automatically by our providers when the app contacts our cloud | Operating and securing the service | Supabase (app and cloud traffic); Cloudflare (our website and coach console only, not app traffic) | No |
| Professional information | Your role (coach/practitioner, client, self-trainer) | From you | Feature availability | Stays on your device | No |
| Inferences | Derived angles, alignment markers, severity indicators | Generated on your device | The core measurement feature | Stays on your device, except those attached to something you share | No |
| Sensitive personal information | Injury history, health-related profile fields, biometric measurements | From you / generated on your device | Provide measurement features | Injury history and health profile fields stay on your device; shared measurements reach Supabase and your recipient | No |
We do not use or disclose sensitive personal information beyond what is needed to provide the service you asked for — in plain terms, to give you your measurements — with the single exception of research contribution, which is off unless you turn it on. In the preceding 12 months we have not sold personal information, and have not shared it for cross-context behavioural advertising — those being the specific things the CCPA means by those words. Sending your media to someone through a connection is a disclosure you direct, to a recipient you choose, and is neither of the above.
On CCPA §1798.121 specifically: that section gives you a right to limit how a business uses sensitive personal information. Whether it is formally engaged here depends on unsettled questions — whether these measurements are "health data," and whether deriving severity indicators counts as "inferring characteristics" (§1798.121(d) excludes processing done without that purpose, leaving such data treated as ordinary personal information under the rest of the Act). We are not waiting for the answer. We apply the limitation voluntarily, as a matter of how we've chosen to operate rather than a concession that the section applies. You can ask us to limit our use of your sensitive information whichever way the legal question lands.
Changes to this policy
We may update this policy. When we make a material change we will notify you — by email where you have an account with us, and by updating the effective date above. Continued use of the app after an update constitutes acceptance of the revised policy; where the app requires active re-acceptance, you will be prompted.
Contact
Who is responsible for your data. BioForm AI is operated by BioForm AI LLC, a Connecticut single-member limited liability company, at 2389 Main St, Ste 100, Glastonbury, CT 06033-4617, United States. BioForm AI LLC is the controller of the personal information described in this policy.
Questions about this privacy policy, or to exercise a privacy right: feedback@bioform.app.