Privacy Policy
Last updated 30 July 2026
Bodyra Privacy Policy. This document describes how we collect, use, store, and protect your personal data when you use the Bodyra application. Bodyra asks you to photograph your body and analyses those photographs automatically. Photographs of your body, and the measurements derived from them, are sensitive personal data, and this policy explains in plain terms what happens to them, where they go, and how you can control or delete them.
Definitions
The Publisher: Star 48, BATIMENT MYKONOS, 137 Avenue de la Lanterne, 06200 Nice, France. The Publisher is the data controller for the processing described in this policy and can be reached at stephane@star48.io.
The Application: the Bodyra mobile application for iOS, together with the web pages and online services offered by the Publisher at https://bodyra-app.com.
The User: the person using the Application and its services.
A Scan: the operation in which the User photographs themselves from the front and from the back so that the Application can produce an Assessment. Users are invited to repeat a Scan roughly every three weeks.
An Assessment: the result of the automated visual analysis of a Scan, namely a score from 1 to 5 for each of seven muscle regions, a front-to-back balance indicator, a left-right symmetry indicator, and an estimate of body composition.
Nature of collected data
In the context of using the Application, the Publisher may collect the following categories of data concerning its Users:
- Account and identification data. Your email address, display name, and user identifier, obtained when you create an account through Firebase Authentication using Sign in with Apple or Sign in with Google.
- Onboarding data about your body and your training. Gender, age, height, current weight, target weight, primary goal, experience level, number of training days per week, available equipment, obstacles you report, focus areas, and your preferred units.
- Photographs. One front photograph and one back photograph for each Scan. Optionally, a profile photograph. Optionally, photographs you choose to attach to a workout session you have completed.
- Assessment data. The muscle region scores, balance and symmetry indicators, and body-composition estimate produced from your Scan, together with the workout plan generated from them and the history of your previous Scans.
- Training data. The sessions you complete or skip, the reason you give for skipping a session, the rating from 1 to 5 you give a session, and any free-text comment you write about it.
- Subscription data. Whether your account holds an active Bodyra Pro entitlement, and the status of that entitlement, as reported to us by RevenueCat.
- Technical and connection data. Device platform, application version, timezone offset, and error logs.
What we do not collect. We do not collect your postal address or telephone number. We do not collect your payment card details: subscriptions are sold and charged by Apple, and Apple does not pass card details to us. We do not collect your location, and where a photograph carries location metadata we remove that metadata before the photograph is analysed, as described below.
Legal bases for processing
Under Article 6 of the General Data Protection Regulation, and Article 9 where sensitive data is concerned, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)). Creating and maintaining your account, storing your onboarding answers, generating and rebuilding your workout plan, recording your completed and skipped sessions, and checking whether your account holds an active Bodyra Pro entitlement. Without this data the Application cannot provide the service you asked for.
- Your explicit consent (Article 6(1)(a) and Article 9(2)(a)). Taking, uploading, storing, and automatically analysing photographs of your body, and storing the body measurements derived from them. Because an assessment of your muscle development and body composition can reveal information about your physical condition, we treat this data as sensitive and rely on your explicit consent rather than on any other basis. You give that consent by choosing to take a Scan; you are never obliged to.
- Our legitimate interests (Article 6(1)(f)). Keeping the Application secure, detecting and diagnosing technical faults through error monitoring, preventing abuse and fraudulent use of accounts, and reviewing the quality of the automated analysis so that it can be improved. We balance these interests against your rights and limit the data used for them to what is necessary.
- Compliance with a legal obligation (Article 6(1)(c)). Meeting our accounting and tax obligations, and responding to a lawful request from a competent regulatory or judicial authority.
Withdrawing your consent. You may withdraw your consent to photograph processing at any time by turning off photo retention, deleting your Scans, or deleting your account, as described in the section on your controls below. Withdrawal takes effect for the future and does not affect processing carried out before you withdrew. If you withdraw your consent, the Application can no longer produce new Assessments for you.
How your body photographs are processed
Upload and storage. When you take a Scan, the front and back photographs are uploaded from your device to Firebase Storage, a Google Cloud service that we use as our file store. They are not posted anywhere, shown to other users, or shared with anyone other than the processors listed in this policy.
Metadata removal. Before any analysis takes place, our server strips the EXIF metadata from the image file. That includes any GPS coordinates, camera identifiers, and timestamps that your device may have embedded in the photograph.
Automated analysis. The stripped photographs are then sent to Google's Gemini API, which returns the visual assessment. The resulting scores and indicators are stored in our database, MongoDB Atlas. We also retain the raw response returned by the model for quality auditing, so that we can investigate assessments that look wrong and improve the analysis.
Where the processing happens. Our application programming interface runs on Google Cloud Run in the us-central1 region, in the United States. See the section on international transfers below.
Access to the image files. Photographs are not served from public links. When the Application needs to show you one of your own images, it requests a signed link that carries an expiry date and stops working once that date passes.
Other photographs. Only the front and back Scan photographs are sent for automated analysis. A profile photograph, or a photograph you attach to a workout session you have finished, is stored so that it can be displayed back to you inside the Application, and is not submitted for assessment.
Automated visual analysis and human review
The analysis is automated. The assessment of your Scan is produced by an automated visual analysis model. The workout plan that follows is then generated by a deterministic algorithm from the assessment results and from the answers you gave during onboarding. Both steps run without human intervention.
No routine human review of photographs. No one at Star 48 looks at your photographs in the normal operation of the Application. There is no manual review step, no moderation queue, and no internal browsing of user images. In exceptional cases a person at Star 48 may need to access a photograph, for example if you contact us about a problem with a specific Scan, if we must investigate a technical fault affecting uploads or analysis, or if we must investigate a suspected misuse of the service. We limit such access to what is strictly necessary for the purpose at hand.
Quality auditing. The raw responses retained for quality auditing are text records of what the model returned. A person at Star 48 may read those text records when checking the quality of the analysis. Reading them does not require opening the corresponding photograph.
Effects of the automated processing. The output of the analysis is a training assessment and a workout plan. It does not produce a legal effect concerning you and does not otherwise significantly affect you within the meaning of Article 22 of the GDPR. You remain free to disregard the plan, to redo a Scan, or to stop using the Application. If you believe an assessment is wrong, you can write to us at stephane@star48.io.
Not a medical device. Bodyra is not a medical device. The assessment, the body-composition estimate, and the workout plan are fitness estimates produced by software. They are not a diagnosis, not a medical opinion, and not medical advice, and they must not be used as a substitute for consulting a qualified health professional.
Your controls over photographs and Scan retention
The Application gives you direct control over what happens to your images:
- Do not keep Scan photographs. A setting lets you choose not to retain Scan photographs at all. When it is enabled, each front and back photograph is deleted as soon as the assessment for that Scan has been completed. The resulting scores and your progress history remain, so the Application still works, but the images themselves are not kept.
- Delete a single Scan. You can delete any individual Scan at any time. Deleting a Scan removes its photographs from storage and the Scan from your history. The scores derived from it remain in our records, detached from any image, until you delete your account.
- Delete all Scans. You can delete all of your Scans at once, at any time.
- Delete your account. Deleting your account removes your database records, your stored photographs, and your authentication account. See the section on account deletion below.
How deletion is carried out. Deletion is executed against our live systems: the database records are removed and the stored image files are deleted from Firebase Storage. Our hosting and database providers operate their own backup systems, and a copy may persist there until those backups expire under the provider's own schedule.
Communication of personal data to third parties
No sale, no advertising. We do not sell your personal data. We do not share it with advertising networks, data brokers, or analytics companies for advertising purposes, and the Application contains no advertising trackers. Your photographs are never used to promote the Application.
Processors acting on our behalf. We use the following service providers, each of which processes data only for the purpose stated and only on our instructions:
- Google Firebase — authentication (Sign in with Apple, Sign in with Google) and storage of image files.
- Google Gemini API — the automated visual assessment of Scan photographs.
- Google Cloud Run — hosting of our application programming interface, in the us-central1 region, United States.
- MongoDB Atlas — the database holding your account records, onboarding answers, assessments, plans, and training history.
- RevenueCat — management of your Bodyra Pro subscription status.
- Sentry — error and crash monitoring, which receives technical data and error logs.
- Apple — sale and billing of the Bodyra Pro subscription through the App Store.
Disclosure required by law. Your data may be disclosed pursuant to a law, a regulation, or a decision of a competent regulatory or judicial authority.
Mergers and acquisitions. In the event that we take part in a merger, acquisition, or any other form of asset transfer, we commit to guaranteeing the confidentiality of your personal data and to informing you before it is transferred or becomes subject to a new privacy policy.
International transfer of data to the United States
Your data is processed in the United States. We state this plainly. Our application programming interface runs on Google Cloud Run in the us-central1 region, which is located in the United States. Your photographs are analysed by Google's Gemini API, and our database, file storage, subscription management, and error monitoring are operated by providers based in the United States. This means your account data, your onboarding answers, your body photographs, and the assessments derived from them are transferred outside the European Economic Area and processed there.
Transfer mechanism. For these transfers we rely on the data processing terms published by each of these providers, which incorporate the European Commission's Standard Contractual Clauses for transfers of personal data to countries outside the European Economic Area.
What this means for you. United States law does not provide the same framework of protection as European Union law, and public authorities in the United States may, in certain circumstances, be able to compel a provider to give access to data held there. We cannot guarantee otherwise. If you are not comfortable with your body photographs being processed in the United States, you should not use the Scan feature of the Application.
Purpose of reusing collected personal data
Collected data is used to provide the Application, to produce your assessments and workout plans, to keep the service secure and functioning, to audit the quality of the automated analysis, and to compile statistics that help us understand how the Application is used and improve it.
Data aggregation
Aggregation with non-personal data. We may produce and use aggregated information, combined in such a way that an individual User can no longer be identified, together with non-personal information, in order to analyse how the Application is used, to measure the quality of the assessments, and for other internal business purposes. Aggregated information is not used for advertising, and it is not built from your photographs being shown to anyone.
Data received from your sign-in provider. When you connect your account using Sign in with Apple or Sign in with Google, that service provides us with the profile and login information you have authorised it to disclose, typically an email address, a display name, and a user identifier. If you use Sign in with Apple and choose to hide your email address, we receive a relay address rather than your real one, and that is the address we will use to contact you.
Collection of identity data
Use of the Application requires registration and prior identification through Sign in with Apple or Sign in with Google. Your personal data, such as your name and email address, is used to operate your account, to make your assessments and plans available to you across sessions, and to fulfil our legal obligations resulting from the services, under the Terms of Service or any other applicable condition.
You will not provide false personal information and will not create an account for someone else without their permission. You must only upload photographs of yourself. Your contact details must always be accurate and up to date.
Retention of technical data
Technical data, including device platform, application version, timezone offset, and error logs collected through our error monitoring provider, is retained for the period strictly necessary to achieve the purposes mentioned above, namely diagnosing faults and keeping the Application secure.
Retention of personal data and anonymization
During the contractual relationship. In accordance with Article 5(1)(e) of the General Data Protection Regulation and Article 6-5° of Act No. 78-17 of 6 January 1978 relating to information technology, files, and freedoms, personal data processed for one or more specific purposes shall not be kept beyond the time necessary for the fulfilment of those purposes.
Photographs. Scan photographs are kept for as long as you keep the corresponding Scan in your account, unless you have turned off photo retention, in which case they are deleted as soon as the assessment is complete. Assessments, plans, training history, and the raw model responses retained for quality auditing are kept for as long as your account exists, so that you can follow your progress over successive Scans, and are deleted when your account is deleted.
After account deletion. When you delete your account we do not keep a copy of your personal data for later reuse. Deletion removes your records from our database, your images from storage, and your authentication account. We keep no anonymised profile of you afterwards. Records that we are legally required to keep, such as those relating to a purchase, are held by Apple as the seller rather than by us.
Effective deletion. You have a right of deletion which you can exercise at any time, directly from the Application through the Scan and account deletion controls, or by contacting the Publisher.
Account deletion
On request. The User may delete their account at any time, through the account deletion option in the account settings of the Application, or by simple request to the Publisher at stephane@star48.io.
What deletion removes. Deleting your account removes your database records, including your onboarding answers, assessments, plans, and training history, the photographs stored for your account, and your authentication account with our identity provider. Your subscription itself is managed by Apple: deleting your Bodyra account does not cancel an active App Store subscription, which you must cancel through your Apple account settings.
In case of violation of the Terms of Service. In case of violation of one or more provisions of the Terms of Service, the Publisher reserves the right to terminate or restrict, without prior warning and at its sole discretion, your use of and access to the services, to your account, and to all applications.
Your rights and how to exercise them
Under the General Data Protection Regulation you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to certain processing, to receive your data in a portable format, and to withdraw a consent you have given.
Many of these rights can be exercised directly in the Application: you can correct your onboarding answers, delete an individual Scan or all of your Scans, turn off photo retention, and delete your account. For anything else, write to us at stephane@star48.io. We will respond within one month, which may be extended where a request is complex, and we may ask you to confirm your identity before acting on a request concerning your photographs.
If you believe your data has been handled unlawfully, you have the right to lodge a complaint with a supervisory authority. In France, that authority is the Commission Nationale de l'Informatique et des Libertés (CNIL), www.cnil.fr.
Security and breach notification
We commit to implement appropriate technical and organisational measures to ensure a level of security adapted to the risks, taking into account the sensitivity of body photographs. In particular, photographs are stored in a private file store rather than on public links, are served only through short-lived signed URLs, have their metadata stripped before analysis, and are accessible internally only where necessary for the limited reasons described above.
We do not claim any security certification, audit, or standard that we have not implemented, and no system can be described as impossible to breach.
In the event of a personal data breach, we will notify the competent supervisory authority and, where the breach is likely to result in a high risk to your rights and freedoms, we will inform you, in accordance with Articles 33 and 34 of the General Data Protection Regulation.
Minimum age
Bodyra is not intended for children. You must be at least 16 years old to create an account, and the Application does not accept an age below 16 during onboarding.
We do not knowingly collect personal data, and in particular do not knowingly collect photographs, from anyone under 16. If you believe that a person under 16 has created an account, write to us at stephane@star48.io and we will delete the account and its data.
Changes to this policy
We may update this policy as the Application changes. The date at the top of the page always shows when it was last revised.
Where a change materially affects how your photographs or body measurements are processed, we will tell you inside the Application before the change takes effect, and where the law requires it we will ask for your consent again.
Contact
For any question relating to this Privacy Policy, or to exercise your rights, please contact us at stephane@star48.io.
Star 48, BATIMENT MYKONOS, 137 Avenue de la Lanterne, 06200 Nice, France. https://bodyra-app.com