FAQ
Body Status reads 11 health indices plus Morning Energy, recent trends and AI pattern analysis and condenses them into a single daily state — one of five levels from Alert to Peak Day. Acute signals (body warning signals, overtraining) weigh more than chronic ones (training load is intentionally excluded — it reflects long-term volume, not today). The system adapts to your personal baseline over time, so the more data you collect, the sharper it gets.
Polar, Fitbit, Withings and Oura sync automatically through their official APIs — log in once and data flows in. Oura is capped at 10 connected accounts until Oura approves the integration, so places are limited. Garmin works today through a manual ZIP export while I wait on the official Garmin Health API. On Android the phone itself can be a source: the MyBodyAI app, currently in closed testing, reads what your phone and the apps on it already write into Health Connect. WHOOP, COROS, Amazfit/Zepp and Suunto will be added the same way once their vendors open up API access.
Both, signal by signal. Connect a watch and a ring and MyBodyAI does not make you pick a winner: for every value it takes the source that measures it best, so your nights can come from the ring while training, daytime heart rate and steps come from the watch. Each number is stamped with the device it came from, so a value never silently swaps source behind your back. Two devices are never added up, only chosen between: the same walk recorded by a watch and a phone is one walk, and summing it would invent a day you did not have.
Partly, and only on Android for now. Through Health Connect we get what the phone itself records — mostly steps and movement — plus anything another app or device has written there. That is enough for activity and trends, but not for the scores built on your nights: sleep quality, HRV-based recovery and Body Alert need a device you actually wear while sleeping. You can switch the phone source on and off in Settings at any time, and turning it off is honoured server-side, not just hidden in the interface.
Premium is a subscription for about the price of one coffee a month (€2.99). Every new account starts with a 7-day free trial, no card needed.
The daily coach and its actions, tomorrow's readiness outlook with what is driving your illness risk, the whole Performance tab, full history with all graphs, the What-If simulator, day planner and biological-age what-if, all patterns from your records and the weekly report.
Yes. Cancel anytime in Settings, with no hidden fees. You keep access until the end of the period you already paid for.
Go to the Devices page and click Connect next to your provider. You'll be redirected to their official login (e.g. Polar Flow) to authorise MyBodyAI. The whole process takes under 60 seconds. Once connected, data syncs automatically — no manual uploads needed.
Instantly useful, personally precise in weeks. Our scoring is built on years of peer-reviewed research, so your results are meaningful from day one. Your personal calibration — adaptive weights, individual distributions — fine-tunes over 2–4 weeks. BioClass needs just 3 days of data to assign your first archetype.
Automatically every few hours, or on demand from the dashboard. On your first sync we pull up to 90 days of history from your wearable so you get meaningful insights right away.
MyBodyAI works in any mobile browser, it is a web app built for phones. There is also an Android app, currently in closed testing on Google Play: it adds Health Connect as a data source, push notifications and offline handling. You can ask for a test invite in Settings, and testers get Premium free while the test runs. An iOS app is not in progress.
Every day we compute 12 scores (0–100) from your raw wearable data: Immune Resilience, Recovery, Stress Load, Sleep Debt, Circadian Rhythm, Parasympathetic Tone, Overtraining, Respiratory Quality, Cardiac Fitness, Sleep Quality, Training Load and Body Alert. Morning Energy sits alongside them as a thirteenth signal, not one of the twelve. Each combines multiple biometric signals — for instance, Body Alert tracks simultaneous changes in resting heart rate, HRV, sleep architecture and SpO2. Scoring uses age- and gender-adjusted reference ranges from peer-reviewed studies.
Your autonomic nervous system has two branches: the sympathetic ("fight-or-flight") activates you during stress or exercise, and the parasympathetic ("rest-and-digest") recovers you during sleep. True sympathetic/parasympathetic balance needs frequency-domain HRV (LF/HF), which wrist wearables do not provide — so we score the parasympathetic side directly from time-domain HRV, low nocturnal heart rate and Morning Energy. Higher = a stronger "recovery" tone. Persistently low = the system is leaning sympathetic, which signals chronic stress, burnout risk and impaired recovery.
Your circadian rhythm is your body's internal 24-hour clock that regulates when you feel sleepy and alert. We measure it by tracking the consistency of your bedtime, wake time and sleep duration. A study of nearly 61,000 people (Windred et al., 2024) found that regular sleep timing predicts a 20 % reduction in all-cause mortality — making it a stronger predictor than sleep duration alone. Even small improvements in regularity (going to bed within the same 30-minute window each night) have measurable health benefits.
Sleep Debt tracks the cumulative gap between how much you sleep and how much your body needs. Your personal optimal duration is calculated from population norms (National Sleep Foundation) blended with your own data — nights where you feel rested reveal your true need. The debt accumulates non-linearly: research by Van Dongen et al. (2003) showed that 14 days of sleeping 6 hours equals the cognitive impairment of 2 full nights without sleep. Recovery is also non-linear — you can't fully "pay off" a week of debt in one weekend.
Recovery is an HRV-based composite that measures whether your autonomic nervous system has reset after yesterday's stress. It combines nocturnal HRV, resting heart rate, sleep quality and cumulative training load — it tells you "is my body ready for hard training today?" Morning Energy is your charge level at wake-up: for Garmin we read the native Body Battery signal, for Fitbit, Polar, Withings and Oura we estimate it from overnight HRV, sleep duration and resting heart rate (lower confidence). It tells you "how much did I actually recharge overnight?" You can have good Recovery (HRV bounced back) but low Morning Energy (poor overnight charge), for example after alcohol.
It uses the Acute:Chronic Workload Ratio (ACWR) model by Gabbett (2016): your training load from the last 7 days compared to the last 28 days. A ratio above 1.5 significantly increases injury risk; the protective "sweet spot" is 0.8–1.3. We also factor in HRV suppression, sleep quality and resting HR trends. Murray et al. (2017) showed that exponentially weighted moving averages make this model even more sensitive to sudden load spikes.
We monitor your nocturnal oxygen saturation (SpO2) trends and deep sleep proportion — both are proxies for breathing quality during sleep. Drops in SpO2 below your baseline, increased desaturation events, or reduced deep sleep percentage can indicate developing respiratory infection, sleep-disordered breathing or altitude stress. Chung et al. (2012) validated that nocturnal SpO2 patterns are a sensitive and specific marker for respiratory health in clinical settings.
It's an estimate of how old your body actually is, regardless of your birth date. We calculate it across eight domains — cardiovascular, body composition, recovery, sleep, stress resilience, autonomic balance, physical activity and VO2max — each using age- and sex-stratified reference data from published studies. You might be 40 on paper but 34 inside, or the other way around.
The system monitors multiple biometric signals simultaneously — resting heart rate, HRV, sleep architecture, SpO2 and morning energy. When several of these shift together in a characteristic pattern, it flags that your body may be under stress. Published research (Mishra et al., Nature Biomedical Engineering 2020) demonstrated that wearable data can detect physiological changes before symptoms appear. MyBodyAI uses similar principles to identify unusual patterns and alert you early.
BioClass is a gamification layer built on real health data. Your 12 indices are grouped into five domains — Defense, Cardiac, Recovery, Sleep, and Strain. Your three strongest metrics determine your archetype (there are 32, from Oracle to Paladin). But here's the twist: to evolve your class through three tiers (Awakened → Mastered → Ascended), you have to improve your three weakest metrics. Once you reach Ascended, the cycle resets with a new class. It's an infinite loop that rewards real health improvement, not just logging in.
The Adaptive Engine calibrates to you in four stages. Day 1: we use population norms as your baseline. After 2–4 weeks of data, your personal baseline replaces population averages. At 2 months, the system adjusts how much weight each metric carries in your Body Status — based on which signals best predict how you feel. After 6+ months, it builds a personal illness signature — the unique biometric pattern your body shows before getting sick. It also adapts to activity context (a high resting HR after a hard workout is expected, not alarming) and calibrates against your daily self-reports.
Self-reports are optional daily check-ins where you tell the system how you feel — energy, mood, physical well-being, sleep subjective quality. After about 14 entries, the AI uses this data to calibrate which biometric signals best predict your subjective state. For example, it might learn that your energy correlates most with deep sleep percentage rather than total sleep hours. This subjective feedback loop makes Body Status and other scores more personally meaningful over time.
Everything is grounded in published science. Key references include: ESC/NASPE standards for HRV (Shaffer 2017), the Health eHeart Study for resting heart rate norms (Avram 2019, 92,457 adults), Ohayon's meta-analysis of sleep architecture across age groups (2004), ACSM guidelines and NHANES data for body composition, the Lancet 2022 meta-analysis linking VO2max to mortality, Gabbett's ACWR model for overtraining (2016), Mishra et al.'s work on pre-symptomatic illness detection from wearables (Nature 2020), and Windred et al.'s finding that sleep regularity predicts mortality (2024, 60,977 participants). In total, our algorithms reference 30+ peer-reviewed studies. All thresholds are stratified by age and sex.
Most health metrics change naturally with age. Resting heart rate, HRV, deep sleep percentage, body fat, VO2max — they all have well-documented age trajectories. We use published percentile tables (Health eHeart for HR, Nunan 2010 for HRV, Ohayon 2004 for sleep, ACSM for body composition, Cooper Institute for VO2max) to score you against people of your age and sex. For example, an HRV of 35 ms is concerning for a 25-year-old but normal for a 55-year-old. Women receive a +5 bpm resting heart rate adjustment (Avram 2019, Cleveland Clinic) and higher deep sleep targets based on the SIESTA study. HRV scoring uses a population-normed sigmoid curve (Shaffer 2017). This ensures fair scoring regardless of demographics.
No. MyBodyAI is a wellness analytics tool, not a medical device. It provides health insights from wearable data for informational and educational purposes. It is not intended to diagnose, treat, prevent or cure any disease. If you have medical concerns, always consult a qualified healthcare professional. Our algorithms are based on peer-reviewed research, but wearable sensor accuracy varies and individual results may differ from clinical measurements.
The system continuously calibrates to your personal data. The more data it has, the better it recognises your normal patterns and flags deviations. Results improve over the first 2–4 weeks as your personal baseline develops. False positives can occur — especially after intense training or travel — which is why we always provide context alongside the alert.
Yes — security is a core design principle, not an afterthought. Each user's health data lives in its own isolated database — completely separate from other users. All communication is encrypted with TLS 1.3 (the latest standard) with HSTS preload. Authentication tokens are hashed with scrypt, the application runs in non-root containers, and we enforce rate limiting, CSRF protection, and automated intrusion detection on every layer. Suspicious activity is automatically detected and blocked in real time. Every admin action is recorded in an immutable audit log. We never sell, share or monetise your health information. You can export all your data or permanently delete your account at any time — fully GDPR compliant.
Our security stack includes: TLS 1.3 encryption for all data in transit, per-user isolated databases for health data, parameterised database queries preventing SQL injection, scrypt-hashed authentication tokens, optional two-factor authentication (TOTP authenticator apps and WebAuthn passkeys for biometric sign-in), non-root Docker containers, UFW firewall, rate limiting on all API endpoints, CSRF protection with dual JSON and header validation, anti-enumeration responses (login never reveals whether an email exists), auto-escaped templates preventing XSS, a 128-character cryptographic secret key, and complete audit logging of all administrative actions. We follow OWASP security best practices throughout.
Yes, and I recommend it for health data. In Settings → Security you can add a passkey (fingerprint, Face ID or Windows Hello) or an authenticator app, plus one-time recovery codes for when you lose your device. Passkeys are phishing-resistant and your biometrics never leave your device, I only ever store a public key, never your fingerprint or face. Two-factor is optional and off by default; once on, signing in takes your password and then your second factor. Google sign-in respects it too: after Google confirms who you are, you still enter your second factor.
Yes. You can sign in with your Google Account instead of a password. We receive only your email address, name and Google account identifier — never your health data, and Google gets no data about your use of MyBodyAI. The email sign-in code always keeps working as a fallback, so a Google outage can never lock you out.
No. The 7-day trial starts with your account and no card is asked for. A card is only needed when you decide to subscribe after it ends.
Yes. In Settings → Data & Privacy you can export all your health data as a JSON file or permanently delete your entire account and all associated data. Deletion is immediate and irreversible — in compliance with GDPR's "right to be forgotten". Automated backups may retain residual data for up to 30 days before being purged.
MyBodyAI is built by Aiclysm, a solo-developer project based in Prague, Czech Republic. It started as a personal tool to make sense of years of wearable data and evolved into a full health analytics platform. The project is driven by a genuine passion for evidence-based health — not investor pressure or ad revenue.
OAuth connections expire for several reasons: the provider rotated its security credentials (their keys, not your password), you revoked access in the provider's account settings, your provider account changed (e.g. password reset), or the connection went unused long enough that the provider invalidated the refresh token. None of these mean anything is wrong with your data — it stays in MyBodyAI. Just click Reconnect and grant access again.
The reconnect button redirects through app.aiclysm.com (where providers send their OAuth callbacks). Ad blockers and privacy extensions sometimes treat that subdomain as a tracker and silently block the redirect. Try: (1) disable your ad blocker for aiclysm.com just in this tab and retry; (2) try a different browser or an incognito window; (3) check the browser console for a blocked-request message. If it still fails, your browser may be blocking third-party cookies — allow them for aiclysm.com and your provider's domain (e.g. withings.com).
The provider (Withings, Fitbit, Polar) handles its own login independently of MyBodyAI. Common causes: two-factor authentication is asking for a code you haven't entered yet; the provider needs to verify a new device by email; the provider's session timed out. Complete the provider's flow in full — including any "Verify your email" steps — before you reach the "Allow MyBodyAI" screen. If the provider screen never loads, it's a network or browser issue on your side, not ours.
These mean the OAuth handshake didn't complete cleanly. Most common reasons: you waited too long on the provider's login page (the security token has a short lifetime), you opened the same provider in two tabs and one of them already used the token, you used the browser back button mid-flow, or you clicked "Deny" / "Cancel" on the provider's consent screen. The fix is always the same: close any leftover tabs, return to the Devices page in MyBodyAI, click Connect again, and complete the flow without pausing.
Three things to try in order: (1) hard-refresh the dashboard page (Ctrl+Shift+R or Cmd+Shift+R) — the connection list is cached briefly. (2) Check that you signed in to the correct provider account: if you have two Withings accounts and accidentally used the wrong one, MyBodyAI now syncs from that wrong account. Log out of the provider in a separate tab, then reconnect with the right account. (3) If neither helps after 5 minutes, it's a server-side issue — email support@aiclysm.com with the provider name and your email.
The most common reasons depend on the provider: (a) Polar — your account has no paired watch or strap, so the API returns no records. Pair a device in Polar Flow first; data usually starts flowing within an hour after Polar's next sync. (b) Fitbit — your authorisation predates our newer scopes (cardio_fitness, ECG), so the provider blocks those endpoints. Disconnect, then Connect again to grant the new scopes. (c) Any provider — you wear the device but don't open the provider's phone app. Most providers only push to the cloud when their app syncs. Open it, wait a few minutes, then check MyBodyAI.
This usually means the provider's server is having a temporary problem during the token exchange step (the moment we trade your authorisation code for an access token). It is almost always transient. Wait 5–10 minutes and click Connect again. You can check the provider's status page (e.g. status.withings.com) to confirm whether they are reporting an outage. If the error persists for more than an hour, email support@aiclysm.com — there may be a configuration issue on our side that needs human attention.
Some corporate firewalls and content filters block fitness-provider domains (wbsapi.withings.net, api.fitbit.com, polaraccesslink.com, …) because they consume bandwidth and aren't work-related. The OAuth flow needs to reach both your provider and our callback at app.aiclysm.com. Try the connection from a different network: a mobile hotspot, your home Wi-Fi, or a personal device. Once connected, the OAuth-based providers (Withings, Fitbit, Polar) sync server-to-server and your work network does not affect them. Garmin is different — its history file upload happens through your browser, so you also need to do uploads from a network that allows access.
Yes. The cleanest way: in MyBodyAI go to Devices, click Disconnect on the current connection, then Connect again — you'll be sent to the provider's login where you sign in with the new account. Important: data already pulled from the old account stays in your MyBodyAI history (so trends remain continuous). New data flows from the new account from the moment of reconnect. If you want a clean break with no history mixing, email support@aiclysm.com and ask for a data reset before switching.
Email support@aiclysm.com with: (1) which provider you are trying to connect, (2) the email address linked to your MyBodyAI account, (3) the approximate time you tried and any error message you saw on screen, (4) which browser and device you used. We can look at the server logs for that exact attempt and tell you whether the failure was on the provider's side, on ours, or on yours. We don't need or want screenshots of any provider passwords — only the error text.