Your privacy matters to us
Welcome to BodAI ("we," "our," or "us"). We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our health and fitness application and related services.
BodAI is an AI-powered fitness application that provides personalized exercise programs and health guidance. Due to the nature of our service, we process health-related information which requires special protection under data protection laws.
This policy complies with the General Data Protection Regulation (GDPR), the Norwegian Personal Data Act (Personopplysningsloven), and other applicable data protection laws.
BodAI is the data controller responsible for your personal data. We are based in Norway and comply with applicable Norwegian and European Union data protection laws.
Contact Information:
Email: privacy@bodai.no
We collect the following categories of personal data:
Note: We do not store your credit card details. All payment processing is handled securely by Stripe.
Important: Health data is considered "special category data" under GDPR Article 9 and requires your explicit consent to process.
We collect the following health-related information to provide personalized fitness guidance:
This health information is essential for us to:
By providing health information and using our service, you explicitly consent to our processing of this special category data for the purposes described. You may withdraw this consent at any time by deleting your account, though this will affect our ability to provide personalized services.
We use trusted third-party services to operate BodAI. Each processor is bound by data protection agreements and processes data only as instructed by us.
Purpose: Core infrastructure
Privacy Policy: policies.google.com/privacy
Purpose: AI-powered features
Privacy Policy: openai.com/privacy
Purpose: Payment processing
Privacy Policy: stripe.com/privacy
Purpose: Email delivery
Privacy Policy: resend.com/legal/privacy-policy
Purpose: Exercise videos
Privacy Policy: policies.google.com/privacy
BodAI uses artificial intelligence to provide personalized health and fitness guidance. It's important you understand how this works:
Our AI assists in generating exercise recommendations, but these are suggestions for educational purposes only. We do not make fully automated decisions that have legal or similarly significant effects on you under GDPR Article 22.
Our AI includes safety protocols to detect red flags for serious medical conditions and will recommend consulting healthcare professionals when appropriate. The AI is not a replacement for professional medical advice.
Important: AI-generated content is for educational purposes only and does not constitute medical advice. Always consult a qualified healthcare provider for medical concerns.
We use your information for the following purposes:
We process your data based on the following legal grounds under GDPR:
For processing health data (special category data) and optional profile information. You can withdraw consent at any time.
For account management, service delivery, and subscription processing - necessary to fulfill our agreement with you.
For analytics, service improvement, and security measures - balanced against your rights and freedoms.
For maintaining financial records and complying with applicable laws.
We retain your data for specific periods based on its purpose:
| Data Type | Retention Period |
|---|---|
| Account & Profile Data | Until you delete your account |
| Health Information | Until you delete your account |
| Exercise Programs | Until you delete your account |
| Chat History | 12 months after last activity, or until account deletion |
| Payment Records | 7 years (legal requirement) |
| Analytics Data | 26 months |
| Authentication Codes | 1 hour (automatically deleted) |
When you delete your account, we will erase your personal data within 30 days, except where retention is required by law (e.g., financial records).
We may share your information in the following circumstances:
With the third-party services listed in Section 5, who process data on our behalf under strict contractual obligations.
When required by law, court order, or governmental authority, or to protect our legal rights.
In connection with a merger, acquisition, or sale of assets, where your data may be transferred to the new entity (you would be notified of such transfer).
For any other purpose with your explicit consent.
We do not sell your personal data. We never sell, rent, or trade your personal information to third parties for their marketing purposes.
BodAI is based in Norway, within the European Economic Area (EEA). However, some of our service providers operate outside the EEA:
When transferring data outside the EEA, we ensure appropriate safeguards are in place:
You may request a copy of the safeguards we use for international transfers by contacting us at privacy@bodai.no.
Under GDPR, you have the following rights regarding your personal data:
Request a copy of your personal data we hold.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ("right to be forgotten").
Request limitation of processing in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time (this won't affect prior processing).
How to Exercise Your Rights: You can export your data and delete your account directly from the Privacy section in your Profile settings. For other requests, contact us at privacy@bodai.no. We will respond within 30 days.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
While we strive to protect your data, no method of transmission or storage is 100% secure. If you become aware of any security issues, please contact us immediately at privacy@bodai.no.
Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@bodai.no. We will promptly delete such information from our systems.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
When we make material changes, we will:
We encourage you to review this policy periodically. Continued use of our service after changes constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
BodAI Privacy Team
We aim to respond to all inquiries within 30 days. For urgent matters related to data security, please indicate this in your subject line.
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority.
We encourage you to contact us first at privacy@bodai.no so we can try to resolve your concern directly.
© 2025 BodAI. All rights reserved.
This policy is effective as of December 2025.