Privacy.
Effective 27 August 2026. This page describes the app as it ships today and this website as it runs today. If either changes, this page changes with it.
BodyLeap reads your health, sleep and training history and works out what today is for. All of that happens on your phone. Your readiness, recovery and sleep are not uploaded to us, and there is no server side copy of them to lose.
We built it this way on purpose. Health data is among the most revealing and most targeted information there is, and the ordinary way an app handles it, by sending it to a server, is the ordinary way it ends up breached, sold, or used to judge you. The most dependable protection is for the data never to leave your device, so that is how BodyLeap works.
This page has two halves, because they are genuinely different. The first describes the app, which processes your health data entirely on your own device. The second describes this website, which is the only place BodyLeap receives anything from you at all, and only if you fill in one of its two forms.
What the app reads
With your permission, BodyLeap reads data from Apple Health on iPhone and Health Connect on Android. The iPhone and Android apps only read: they never write anything back. The one part of BodyLeap that writes is the Apple Watch app, and only when you use it: a workout you record on the Watch is saved into Apple Health, the way any Watch workout app saves a session. The Watch section below spells that out. Here is the complete list of what is read, because "and related measurements" is not good enough for a page like this one.
On iPhone, from Apple Health: heart rate, heart rate variability, resting heart rate, sleep, respiratory rate, sleeping wrist temperature, VO2 max, your workouts, running power, step count, walking and running distance, workout routes, and biological sex. Your date of birth is behind a separate prompt that only appears if you ask the app to fill in your age.
A workout route is location data, and it deserves its own sentence rather than a place in a list. A route is the GPS trace of where a recorded run or ride went. When you open an outdoor workout, BodyLeap reads its route and keeps a minimized route shape in the same encrypted, backup-excluded database as everything else, so the route can be drawn again without asking twice. No timestamps, altitude, speed or accuracy values are stored with it, the shape never leaves your phone, and you can remove it from BodyLeap at any time without touching the original in Apple Health or Health Connect. On Android the shape is stored only after you tap Import route and approve Health Connect's own consent screen for that one workout. If you also tap to see the route on a map, the map section below describes exactly what that fetches and from whom.
On Android, from Health Connect: heart rate variability, resting heart rate, heart rate, sleep sessions, respiratory rate, steps, exercise sessions, distance, active calories burned, elevation gained and VO2 max, plus the standard Health Connect permission to read records older than thirty days.
You can revoke any of these permissions at any time in your phone's settings, and the app keeps working with whatever remains, saying honestly when a reading is thin.
Where it is kept
On the device, in an encrypted database. The database is excluded from phone backups on both platforms, so no copy of it leaves the device even during a backup. There is no cloud sync.
What the app sends
Nothing, to us. The app contains no analytics service and no third party crash reporter, and a check runs before every release that refuses to ship the build if any file we write so much as opens a network connection. Crash reports reach us only through Apple's and Google's own platform mechanisms, which you control in your phone's settings and which do not contain your health data.
The written explanation on your daily card is generated by a model running on your own phone: Apple's on-device intelligence on iPhone, and Google's on-device Gemini Nano on Android phones that have it. Nothing is sent to us or to anyone else to produce it. On an eligible Android phone, opening an AI note screen for the first time can prompt Android to download that Google model in the background through Google's own service; BodyLeap sends nothing in that exchange and none of your data is involved, but the download itself does reach the network. On a phone without an on-device model, BodyLeap shows its plain rules-based text instead, built the same way, on the device. One more deliberate exception: if you choose to copy an AI note, after a confirmation, the text goes onto your device's clipboard like any text you copy, and where it travels from there is your choice, not something BodyLeap sends anywhere.
Beyond that model download, one more thing reaches the network, and it should be said here rather than discovered. If you tap to see a run drawn on a map on iPhone, your phone asks Apple's map service for the map tiles around that route, which tells Apple roughly where the run took place. That request happens only on that tap, the app says so before it makes it, and no other map provider is involved. Android never fetches map tiles: it draws the stored route shape offline. If you never open the map, the request never happens.
The Apple Watch app
BodyLeap has an Apple Watch app. If you install and use it, your active plan is sent from the phone to the Watch over Apple's direct device link, so the Watch can show today's session and guide a workout with the phone left at home. When you finish a session on the Watch, it reports that one completion back to the phone the same way. No server is involved in any of this: the two devices talk to each other, the Watch app contains no network code at all, and nothing about the sync reaches us or the internet.
A workout you record on the Watch behaves like a workout from any Watch workout app: with your permission, it reads your heart rate during the session and saves the finished workout, with its duration, heart rate, energy and, for an outdoor run or ride, its GPS route, into Apple Health. That is the one place BodyLeap writes to Apple Health, it happens only for sessions you chose to record, and you can view and delete those workouts in Apple Health like any other. Recording an outdoor route uses the Watch's location during that workout, behind its own permission prompt, and only while the session runs. During an outdoor run or ride the Watch can also use its motion and fitness sensors, including the barometric altimeter, to show your climb and grade live. Those readings stay on the device, are never sent to a BodyLeap server, and add nothing stored beyond the workout Apple Health already saves.
Your location, for one sunset time
One optional screen uses your location: the fasting screen can show what time the sun sets where you are, and you reach it only if you turn fasting support on yourself. The app asks for while-using permission, reads a rough position once, computes the sunset time on the device, and throws the position away: it is never stored and never sent anywhere, and BodyLeap never asks for background or always-on location. If you say no, you can type a place instead and the screen works the same. If you never open that screen, BodyLeap never asks for your location at all.
What you can export
The app never sends anything on its own, but it does let you send things deliberately. You can export a workout or a training summary, save a plan as a PDF, or put a plan in your calendar as a dated file. Those exports contain what you would expect them to: durations, distances, paces, heart rate and zones, training load, splits, and in a plan export your own heart rate zone ranges in beats per minute.
Every one of those is a deliberate action you take, the app tells you what the file contains before it leaves, and where it goes next is entirely your choice. We never receive a copy. If you send an export to another app or another person, that data is then in their hands and this notice no longer governs it.
Accounts
The app works without an account. There is no sign up, no online profile, and no identity anywhere for your body data to be attached to. The athlete details you give the app, things like your name, date of birth and height, are stored on your phone in the same encrypted database as everything else, and they are not sent to us.
We plan to add optional group features, where you can share workouts and challenges with friends you invite. Those will need an account, because ranking and sharing need a server. That account will be optional, it will only be created if you ask for it, and it will never receive your readiness, recovery, sleep or any other health measurement. Those stay on your device whether you have an account or not.
If you use the optional sign in with Apple step to fill in your name, that request goes to Apple alone, no BodyLeap account is created, and the result is stored only on your device.
Who can see it
No coach and no other user can see your readiness, recovery or sleep. There is no mechanism for it. If sharing is ever added, it will be a separate, explicit, opt in data plane. You would choose it, you would choose what it covers, and the app would keep working exactly as it does now if you never touched it.
Selling and advertising
Your data is not sold and is not used for advertising. There is no advertising in the app.
Deleting your data
Delete the app and your BodyLeap data goes with it. You can also wipe everything the app has computed without deleting the app, under Settings, About, Delete all BodyLeap data. There is no server copy of your health data to ask us to erase. Data you granted from Apple Health or Health Connect stays in those services under your control, as it was before.
Who is responsible
The data controller for this website is Andreas Mavrocordatos, Luxembourg, trading as BodyLeap. That means one identifiable person decides what this website collects and why, and that person is who you hold to it. You can reach him through the contact form on the support page, which is read by a person and not by a system.
For the app itself there is very little to control. Your health data is processed on your own device, under your own control, and we neither receive it nor could retrieve it.
What the website collects
Reading these pages requires nothing from you. There is no analytics service, no advertising network and no tracking pixel anywhere on this site. One third party script exists in total: Cloudflare's Turnstile check, which belongs to the two forms and loads only when you begin one, never for reading a page. We do not build a profile of visitors and we cannot tell you apart from anyone else who reads a page.
Two forms do collect something, because they cannot work otherwise.
The contact form on the support page sends us the message you typed, the category you picked, and your email address if you chose to give one. The address is optional and is used only to reply to you.
The Android beta request on the beta page sends us the Google account address you want to test with, and the fact that you ticked the consent box, with the date and time. Google Play runs closed testing from a list of approved addresses, so the address has to exist on a list for the app to reach you. Giving it is not optional if you want Android access, and it is the only reason we ask.
In both cases a Cloudflare Turnstile check separates people from bots. Its script loads the moment you start the form, by focusing a field or touching it, not when you open the page, so simply reading either page sends Cloudflare nothing. From the moment it loads, Turnstile receives your IP address and basic signals from your browser, processed by Cloudflare to score the request. We receive only the pass or fail result. We do not store your IP address ourselves; a short lived, one way hash of it is used to limit how many submissions can come from one place in a few minutes, and it cannot be turned back into an address.
Cloudflare also keeps standard request logs for the site, as any host does, to serve pages and to defend against attack. We keep no separate copy of them.
Why, and on what basis
Under the UK GDPR and the EU GDPR we rely on these lawful bases:
- Answering your message: legitimate interests, Article 6(1)(f). Someone who writes to us expects a reply, and reading and answering is the least we can do with what they sent.
- The Android beta list: your consent, Article 6(1)(a), given by ticking the box on the form. You can withdraw it at any time and we will remove the address, which also ends your access to the test.
- Turnstile, rate limiting and request logs: legitimate interests, Article 6(1)(f), in keeping a small site from being flooded by automated abuse.
We do not ask for and do not want health data through either form. Please do not put readings in a message; we never need them to help you.
Nothing here is used for automated decision making or profiling. No decision about you is made by a machine on this website.
Who else handles it
Three companies process data on our behalf, under contracts that bind them to our instructions:
- Cloudflare, Inc. hosts this site and runs Turnstile. It also stores the Android request list in a database we control on its platform.
- Resend delivers the email that carries your form submission to us, and the automatic confirmation back to you.
- Our email provider holds the mailbox those messages land in, in the ordinary way any business mailbox does.
Nobody else receives it. We do not sell data, we do not share it for advertising, and there is no advertising on this site or in the app.
Cloudflare and Resend are United States companies, so processing may take place outside the United Kingdom and the European Economic Area. Those transfers are covered by the standard contractual clauses in their data processing agreements, which is the safeguard the GDPR provides for exactly this.
Separately, and only if you install the app: Apple and Google run their own beta distribution, TestFlight and Google Play, and each is a controller in its own right for what it collects when you install through it. Their terms and privacy policies cover that part, not this notice.
How long we keep it
- A contact message stays in the mailbox while we deal with it and for up to twelve months after the last exchange, so we can pick up a thread you return to. Then it is deleted.
- An Android beta address stays on the approved list while your access lasts, because Play testing works from that list. We remove it when you ask, and within thirty days of your access ending or the test closing.
- The rate limiting hash is never read again once its ten minute window passes, and the expired rows are deleted by the sweep that runs with the next submission. On a quiet day a dead hash may sit until someone next uses a form, which is why this sentence says exactly that instead of "within minutes".
- Turnstile signals and request logs are held by Cloudflare under its own retention policy. We do not receive or keep them.
What your browser stores
This site sets no cookies and runs no tracking storage of any kind. It does remember two small things locally, in your browser and only there:
- Your theme choice, dark or light, if you use the toggle, so the site does not fight you on the next page. It is one word in local storage.
- Whether you have already seen the opening animation in this tab, so it plays once rather than every time. It is one flag in session storage, and it disappears when you close the tab.
Neither is sent anywhere, neither identifies you, and both exist purely to do what you just asked the interface to do. Clearing your browser storage removes them.
Your rights
Where we hold data about you, which in practice means a message you sent or an address on the Android list, you have the right to ask for a copy of it, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on your consent you can withdraw it at any time, and withdrawing it does not make anything we did beforehand unlawful.
Ask through the contact form and we will answer within one month. There is no charge.
If you think we have handled your data badly, you can complain to a data protection authority. Because we are established in Luxembourg, the authority responsible for us is the Commission nationale pour la protection des données. You can also complain to the authority in your own country instead, which for readers in the European Union is the supervisory authority where you live, and in the United Kingdom is the Information Commissioner's Office. We would rather you told us first, and we will take it seriously, but the right is yours either way.
The app is a different matter. We cannot give you a copy of your health data or delete it for you, because we have never had it. It is on your phone, and the section on deleting your data above explains how to remove it.
Contact
Questions about any of this, including any request about your rights, reach a person through the contact form on the support page.
If this notice changes, the effective date at the top changes with it, and a change that affects what we collect or why will be described rather than quietly folded in.