Privacy Policy
Effective date: 15 August 2026
Jobgeerds, trading as Body Memory, is responsible for the processing described in this policy. Jobgeerds is established in the Netherlands. Body Memory is a wellness and body-awareness product for athletes. It is not a medical device, diagnostic service or emergency service and does not diagnose or treat medical conditions.
Information we process
Depending on the features you choose to use, Body Memory processes:
- Account and profile information, including your email address and athlete profile.
- Body-zone selections and physical observations you record.
- Daily check-ins, notes and personal body-history entries.
- Injury and recovery logs, including recovery actions and progress records.
- Training context, schedules and workouts you enter or choose to import.
- Training schedule photos, screenshots or documents you select for import, and the schedule extracted from them.
- Subscription status for Body Memory Pro. Payments are taken by Apple; we do not receive your card details.
- Notification preferences, synchronization records, app events and technical records needed to operate, secure and troubleshoot the service.
- Messages or requests you send to support or privacy contacts.
Body Memory is a wellness product rather than a medical one, but injury, pain, recovery, body-state and body-zone entries, and patterns derived from them, reveal information about physical health. We conservatively treat them as health data and special-category personal data under Article 9 of the GDPR. This information is held to the same standard as the rest of your account information, is never sold, and is never used for advertising or profiling by third parties. You decide what to record, and you can leave any of it out.
Why we process information
- To create and secure your account.
- To store and synchronize the history you choose to record.
- To provide check-ins, body-history, recovery, training and notification features.
- To generate the personal summaries and patterns you request from your own history, including the AI-assisted features described below.
- To read a training schedule from a file you choose to import.
- To manage subscriptions and restore purchases.
- To understand which features are used, using our own product-event records rather than a third-party analytics or advertising service.
- To maintain security, reliability and synchronization and to troubleshoot failures.
- To respond to support, privacy and account-deletion requests.
Where the GDPR applies, account creation, storage, synchronization and requested features rely on Article 6(1)(b), performance of the service contract. Security and privacy-minimal operational records rely on Article 6(1)(f), our legitimate interests in operating and protecting the service. Legal records use Article 6(1)(c) where required. Health-data processing additionally relies on your separate explicit consent under Article 9(2)(a). That consent starts unchecked, is versioned and time-stamped, and is not bundled with the Terms or this policy.
AI-assisted features
Two Body Memory features are produced with the help of OpenAI, which acts as a service provider processing information on our instructions. Both are optional. Each one explains what will be sent and requires separate explicit consent before the first transmission. You can decline and continue using Body Memory without those AI features.
Weekly Story. When you open your Weekly Story, we send a summary of your recent Body Memory signals so that a short narrative can be written from them. This summary contains check-in dates, good, attention and pain states, body zones and notes for the current and previous week; training type and load; injury area and date; recovery trends; and Body Memory score and pattern-confidence values. It does not contain your name, email address, account identifier, subscription identifier, device identifier or any database record identifiers. If you decline, Body Memory writes your weekly summary on your device instead.
Training schedule import.PDF and DOCX files are uploaded to private Supabase Storage and parsed deterministically by Body Memory's authenticated Supabase function; they are not sent to OpenAI. Screenshots and photos are sent to OpenAI only after separate explicit consent. JPEG and PNG metadata containers, including EXIF location data, are removed on the device. If safe removal cannot be verified, the image is rejected rather than uploaded. A schedule can also be typed or pasted.
After a schedule has been read successfully, the uploaded photo or document is deleted from our storage and from the app on your device. The schedule extracted from it is kept in your account until you delete it or delete your account. If reading the file fails, the file is kept so that you can retry, and you can remove it at any time.
We keep a record of each AI request, covering timing, the model used and token counts rather than the content of the request, together with an encrypted copy of the generated text so that a summary does not have to be produced twice. Both are deleted when you delete your account. OpenAI's own handling and retention of the information we send is governed by its applicable terms and policies and is not controlled by Body Memory; deleting your Body Memory account does not delete records held by OpenAI.
Infrastructure and service providers
Body Memory uses Supabase as a service provider for account authentication, database storage, file storage, synchronization and related backend functions. OpenAI is used for the AI-assisted features described above. RevenueCat is used to manage subscription and entitlement status and receives an opaque Body Memory app-user identifier plus subscription and transaction status; purchases are processed by Apple. Sign in with Apple and Google authentication may provide account email and profile information to Supabase. Apple may provide a full name on first authorization. Body Memory does not use advertising pixels, third-party analytics or session replay in the app or on this website. We do not name optional services as active processors unless they are enabled in production.
International processing
The repository does not establish every production processing location. Some service providers may process information outside the European Economic Area. In particular, information sent for the AI-assisted features described above is processed by OpenAI on infrastructure that may be located outside the EEA, including in the United States. Where the GDPR applies, a provider must be enabled only after an applicable transfer mechanism and safeguards are confirmed. Current regions, subprocessors and contractual safeguards must be checked against current production provider settings.
Weekly AI cache entries are eligible for reuse for 24 hours, or seven days for weekly stories, when encrypted caching is configured. The repository does not prove a scheduled physical purge immediately after expiry; expired rows remain subject to account deletion. Successfully processed training sources are deleted automatically. A failed source may remain for retry until you remove it or delete the account. Provider backup, support, security, RevenueCat and OpenAI retention periods require production confirmation.
Retention and deletion
Account and app information is retained while your account is active and as needed to provide the service. Support, security and operational records are retained only for as long as reasonably needed for their purpose or to meet applicable legal obligations. We do not state a fixed retention period where the applicable operational or legal period depends on the record and its purpose.
You can initiate deletion in the app by opening You, selecting the settings button, choosing Delete accountand completing the confirmation steps. This permanently deletes the account and associated Body Memory records, including check-ins, injury and recovery logs, body-history entries, training schedules and their uploaded source files, notification settings, subscription entitlement records, product events and AI request and cache records. It also clears local app state. Workouts imported from Apple Health are removed from Body Memory on the device; deleting a Body Memory account does not delete the original records held in Apple Health. Deleting your account does not cancel a subscription billed by Apple, and does not delete records held by OpenAI, Apple or RevenueCat under their own terms. Limited records may remain where retention is required by law or within a service provider's normal backup lifecycle.
Your privacy rights
You can withdraw health-data consent in You → Settings → Support & legal. Because Body Memory cannot provide its body-history service without processing that data, withdrawal stops future consent-based processing and permanently deletes the Body Memory account and associated records.
Subject to applicable law, including the GDPR where it applies, you may have rights to access, correct, delete or restrict processing of your personal information, object to certain processing, receive portable data, and withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority. To exercise a right, contact privacy@bodymemory.app.
Children
You must be at least 16 years old to use Body Memory independently. A person under 16 may use Body Memory only with consent from a parent or legal guardian where that use is permitted and such consent is required by applicable law. If we learn that information was provided without the required consent, it can be reported to privacy@bodymemory.app so appropriate action can be taken.
Security
We use technical and organizational measures intended to protect personal information. No internet or storage system can be guaranteed completely secure, and we do not claim security or compliance certifications that have not been independently confirmed.
Changes to this policy
We may update this policy when Body Memory or applicable requirements change. The current effective date will be published at the top of this page.
Contact
Privacy questions and requests can be sent to privacy@bodymemory.app.