Privacy Policy
Last updated: September 14, 2026 · Aiclysm
1. Data Controller
The controller of your personal data is Aiclysm, the trade name of a sole trader registered in the Czech Republic (hereinafter "we", "us", "Aiclysm").
Contact for privacy inquiries: support@aiclysm.com
Supervisory authority: UOOU (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic · uoou.gov.cz
2. What Data We Collect
2.1 Account Data
Email address, password (stored as a secure hash), language preference, and subscription status. Authentication is handled via password-based login. Email verification codes are used during registration and password recovery. You can also sign in with your Google Account; in that case we receive only your email address, name and Google account identifier from Google, and Google receives no data about your use of the Service. We do not collect your name, phone number, or physical address unless you provide it voluntarily.
2.2 Health & Wearable Data
When you connect a wearable platform (Polar, Withings, Fitbit, Oura), we retrieve health-related data through their official APIs using OAuth 2.0, and we never access or store your login credentials. Garmin data is imported manually from the data export file you upload, as Garmin's official API is not yet available to us. The Strava integration was retired on 28 July 2026: the authorisation was revoked, the tokens deleted and the activity data we had received from Strava removed. Our Garmin watch app (Connect IQ) sends two measurements from a paired watch: your daily average stress and your Body Battery curve (morning peak, latest level, charged and drained). Nothing else leaves the watch, no heart rate, steps, location or activity files, and unpairing it stops the sending. Our Android app reads health data from Health Connect on your phone, with your explicit permission and only in the categories you grant: heart rate and HRV, sleep, steps and workouts, breathing rate and blood oxygen, body composition, blood pressure, body temperature and VO2max. It reads what other apps on that phone have already written there and writes nothing back, and you can switch the phone off as a data source in Settings at any time.
| Category | Examples | Source |
|---|---|---|
| Heart Rate & HRV | Resting HR, HRV (RMSSD/SDNN), max HR | Garmin (manual import), Polar, Fitbit (HRV+RHR); Withings (RHR only); Oura (HRV+RHR); MyBodyAI Android app (Health Connect) |
| Sleep | Sleep stages (deep, REM, light, awake), duration, sleep score | Garmin (manual import), Polar, Fitbit, Withings, Oura; MyBodyAI Android app (Health Connect) |
| Activity | Steps, active minutes, workouts, calories, distance | Garmin (manual import), Polar, Fitbit, Withings, Oura; MyBodyAI Android app (Health Connect) |
| Stress & Recovery | Stress score, body battery, daytime stress minutes, resilience level, device recovery score | Garmin (manual import); Garmin watch app (Connect IQ: daily average stress, Body Battery); Oura (daytime stress, resilience, recovery); Polar (recovery) |
| Respiratory | Respiratory rate, SpO2 | Garmin (manual import), Fitbit, Withings (SpO2); Polar (breathing rate); Oura (SpO2, breathing rate); MyBodyAI Android app (Health Connect) |
| Body Composition | Weight, body fat %, muscle mass, BMI | Withings, Fitbit, Garmin (manual import); MyBodyAI Android app (Health Connect) |
| Blood Pressure | Systolic, diastolic, heart pulse | Withings; MyBodyAI Android app (Health Connect) |
| Body Temperature | Skin temperature, body temperature deviation | Withings, Fitbit, Oura; MyBodyAI Android app (Health Connect) |
| Fitness & Cardiovascular | VO2max (cardio fitness), cardiovascular / vascular age and the pulse-wave velocity it is derived from, ECG atrial fibrillation detections | Fitbit (VO2max, ECG); Withings (vascular age, pulse-wave velocity); Oura (VO2max, cardiovascular age); Garmin (manual import: VO2max); MyBodyAI Android app (Health Connect: VO2max) |
2.3 Derived Health Indices
From the raw data above, our algorithms compute 12 proprietary health indices: Immunity, Recovery, Stress Load, Sleep Debt, Circadian Rhythm, ANS Balance, Body Alert, Overtraining, Respiratory, Morning Energy, Sleep Quality, Cardiac Efficiency — plus Body Status, Biological Age across 8 domains, and Training Load analysis. These are algorithmic estimates, not clinical measurements.
2.4 Billing Data
MyBodyAI+ is a paid subscription, processed securely by Stripe (stripe.com). We store only your subscription status and Stripe customer ID. We never see or store your credit card number. For Stripe’s privacy practices, see stripe.com/privacy.
2.5 Technical Data
IP address, browser type, device information, and server access logs. These are used for security, debugging, and service improvement. We do not use advertising or tracking cookies. For usage statistics we use Umami, a self-hosted, cookie-free analytics tool (see Section 15). When you sign in with a passkey or an authenticator app, we store the public key of that passkey — never a private key or a fingerprint — and, so that we can tell you about a sign-in from a device you have not used before, the browser identification string of each device you sign in from.
3. Legal Basis for Processing
We process your personal data on the following legal bases under the GDPR:
- Contract performance (Art. 6(1)(b)) — to provide the MyBodyAI service, manage your account, and process your subscription.
- Explicit consent (Art. 9(2)(a)) — for processing health data (special category data). You grant this consent when you create your account, and again whenever this policy changes. We record which version of this policy you agreed to. You can withdraw consent at any time by deleting your account in Settings.
- Legitimate interest (Art. 6(1)(f)) — for security, fraud prevention, and service improvement.
- Legal obligation (Art. 6(1)(c)) — for tax records, accounting obligations, and compliance with Czech law.
4. How We Use Your Data
- To compute and display your health indices on the MyBodyAI dashboard
- To manage your account and subscription
- To send essential service notifications (e.g., subscription expiry, security alerts)
- To improve our algorithms using anonymized and aggregated data
- To comply with legal obligations
- To ensure security and prevent abuse of our services
5. Data Sharing & Third Parties
We share your data only with the following categories of recipients, all bound by data processing agreements (DPAs):
- Hosting provider — server infrastructure located in the EU
- Wearable platform APIs — data flows are user-initiated via OAuth; each platform's privacy policy governs their data handling
- Stripe — payment processing (if you choose to support us). Stripe processes payment data under their own privacy policy. We receive only subscription status.
- Google (Google Ireland Ltd.) — optional sign-in provider. When you choose to sign in with Google, we receive your email address, name and account identifier from Google under their own privacy policy (policies.google.com/privacy). Transfers to the USA are covered by the EU-U.S. Data Privacy Framework. We never send Google your health data.
- Open Wearables API — our own middleware service that securely connects to wearable platforms via OAuth 2.0. Hosted on the same EU server.
- Health Connect (Android) — our Android app is published on Google Play. With your explicit permission it reads health data from Health Connect on your phone; that data stays on our servers and is never shared. Using the phone as a data source can be switched off in Settings.
- Sentry — error monitoring service (hosted in EU Frankfurt). Captures technical error reports (stack traces, browser type, URL) to help us fix bugs. No health data or personal identifiers are included in error reports. Sentry Privacy Policy.
- E-mail delivery (Forpsi, Czech Republic) — transactional e-mails and the weekly summary are sent through our mail provider's SMTP servers. The provider handles your e-mail address and the message body, which in the weekly summary contains your own scores. You can switch these e-mails off in Settings.
- Open-Meteo (Germany) — weather and air-quality lookups behind the "when and where to train" advice. We send coordinates rounded to roughly 1 km, and, if you search for a place by name, that search text. No name, no e-mail, no health data. Saving a location is optional and can be cleared in Settings.
- BigDataCloud (Australia) — turns coordinates into a place name so the app can show where a reading came from. Receives only coordinates rounded to roughly 1 km, no identifier. It sits outside the EEA, so the transfer relies on Standard Contractual Clauses, and it happens only when you set a location.
- Telegram (error alerts) — server error reports go to a private channel only the operator can read, so an outage is noticed within minutes. An error line can contain an account e-mail address. No wearable or health measurements are sent.
- GitHub (encrypted off-site backups) — an encrypted copy of the database backups is kept in a private repository so that losing the server is not losing your data. Archives are AES-256 encrypted before they leave the server; GitHub cannot read them.
- Push delivery (Google FCM for the Android app, browser push services for web push) — if you turn notifications on, the delivery service receives your device token and the short notification text, which can name a health state such as low recovery. Notifications stay off until you enable them, and turning them off removes the token.
- Play Integrity (Google) — when the Android app signs this phone in, Google Play services on the phone hand it a signed statement that the app is the one published on Google Play and that the phone's system is intact, and we send that statement to Google to have it read. It carries the app's package name and signing certificate, an attestation of the phone and your Google Play licence status for the app; no health data, and nothing that identifies you to us beyond the phone already signed in. Google keeps it for a fixed period under its own terms. We record one word per phone (recognised, modified, unrecognised) and nothing else.
We may disclose personal data to law enforcement or regulatory authorities only when required by law. We will notify you of such requests where legally permitted.
6. Provider-Specific Data Handling
Each wearable data provider has specific requirements for how we handle your data. We comply with all provider terms and policies:
| Provider | Data Caching | Deletion on Revocation | Attribution |
|---|---|---|---|
| Garmin (manual import) | Imported from your export | N/A | Data from your Garmin export |
| Polar | As needed for service | Tokens revoked, data deleted | Data sourced from Polar |
| Strava | Retired 28 July 2026 | Tokens revoked, data deleted | — |
| Withings | As needed for service | Prompt deletion | — |
| Fitbit | As needed for service | Prompt deletion | — |
| Oura | As needed for service | Prompt deletion | — |
The Strava integration was retired on 28 July 2026 and every activity record we had received from Strava was deleted from our systems. While it ran, Strava data was shown only to the user who authorized the connection, never to anyone else, and data that became unavailable was removed from our cache immediately.
In addition to GDPR breach notification requirements (72 hours to supervisory authority), we will notify affected data providers within 24 hours of discovering a security breach, as required by their respective terms.
7. International Data Transfers
Your data is primarily stored on servers within the European Union. When data is transferred outside the EEA, we rely on EU Standard Contractual Clauses (SCCs) or adequacy decisions to ensure an adequate level of protection.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Health & wearable data | Until account deletion or integration disconnection |
| Computed health indices | Until account deletion |
| Billing records | 10 years (Czech tax law) |
| Server logs (web access, application, sync) | 30 days |
| Backup archives on the server | 30 days |
| Encrypted off-site backup copy (GitHub) | Older archives stay in the off-site version history; encrypted, used only for disaster recovery |
| Administrator actions (who changed what on an account, with the administrator's IP) | Kept indefinitely — it is the record of who touched your data |
| Website and in-app analytics (Umami) | Currently kept without a time limit; anonymous, see Section 15 |
| First-run milestones (sign-up, connecting a source, first result) | Until account deletion |
| First-run activity (each attempt to connect, taps on a source we do not support) | 12 months, or until account deletion |
| Free-trial fingerprint | Kept after account deletion |
After account deletion, your personal data is permanently erased from our live systems, and from the backup archives held on the server, within 30 days. Three things named in the table above outlive it: the billing records Czech tax law makes us keep for ten years, the administrator log of who touched your data, and the one-way fingerprint described below. The encrypted off-site copy at GitHub also keeps earlier archives in its version history, so a backup taken before your deletion can survive there for longer. Those archives are AES-256 encrypted before they leave the server, GitHub cannot read them, and they are used only to rebuild the service after the loss of the server. Anonymized and aggregated data (which can no longer identify you) may be retained indefinitely for statistical purposes.
That fingerprint deserves its own paragraph: it is a one-way (keyed hash) form of your e-mail address, recorded when you receive the free trial. It cannot be turned back into an address and is never used to contact you or to rebuild an account. Its only purpose is to keep the free trial at one per person, so that deleting an account and registering again does not hand out another one. We keep no e-mail address, name or account identifier alongside it.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.2+)
- Password-based authentication with secure hashing, and time-limited email verification codes for registration and password recovery, plus optional Google Sign-In (OAuth 2.0 / OpenID Connect)
- Optional two-factor authentication (TOTP authenticator apps and WebAuthn passkeys) with one-time recovery codes
- OAuth 2.0 for wearable integrations — we never store your third-party credentials
- Regular security reviews and updates
- Breach notification to UOOU within 72 hours per GDPR Article 33, and to affected data providers within 24 hours
- OAuth tokens and API credentials encrypted at rest
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15) — obtain a copy of your personal data
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — request deletion of your data ("right to be forgotten")
- Restriction (Art. 18) — restrict processing in certain circumstances
- Portability (Art. 20) — receive your data in a structured, machine-readable format
- Objection (Art. 21) — object to processing based on legitimate interest
- Withdraw consent (Art. 7(3)) — withdraw consent for health data processing at any time, without affecting prior processing
- Complaint — lodge a complaint with UOOU or the supervisory authority of your EU member state
To exercise any of these rights, contact us at support@aiclysm.com. We will respond within 30 days.
You can also exercise these rights directly in the app: go to your Dashboard and use Export My Data to download all your data in JSON format, or Delete Account to permanently erase your account and all associated data.
11. If You Live in the United Kingdom
The United Kingdom left the EU and took the same rules into its own law, the UK GDPR together with the Data Protection Act 2018. Every right in Section 10 is yours in the same form and on the same legal bases, and a request from the United Kingdom is handled exactly like a request from inside the EU.
Two things are specific to you. Your supervisory authority is the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk, and you may complain to it instead of to the Czech UOOU named in Section 1. And the servers that hold and process your data are in the European Economic Area, which the United Kingdom recognises as offering an adequate level of protection, so nothing further is required of you for it to reach us; where something does travel beyond the EEA, Section 7 says on what basis.
12. If You Live in California
California gives its residents their own rights over personal information, under the California Consumer Privacy Act as amended by the California Privacy Rights Act. A sole trader of our size is below the revenue and volume thresholds that make those rules binding, so what follows is our own commitment rather than a duty imposed on us. It is written here because the answer would be the same either way, and because you should not have to guess.
In the categories California uses, we collect: identifiers (your email address and account identifier, and, if you sign in with Google, your name and Google account identifier); commercial information (which subscription you hold and whether it is paid, which Stripe keeps for us); internet and network activity (which screens of the app you open, your device and browser, and server access logs); coarse geolocation, derived from your IP address to the level of a city and never a precise position; and sensitive personal information, which here means health data: heart rate and its variability, sleep, activity, breathing, blood oxygen, body composition, blood pressure, temperature, and everything we compute from them. Section 2 has the detail, Section 4 says what each kind is for, and Section 8 says how long it stays.
California lets you limit how sensitive personal information is used. Ours has a single use: producing the health indices and insights you opened the app to see. We do not use it to infer characteristics about you for anyone else’s purposes, and we disclose it to no one for a purpose you would have cause to limit. There is no secondary use to switch off, which is why you will not find a switch.
We do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done either in the twelve months before the date at the top of this page, and we have nothing to do it with: the site carries no advertising cookies and nothing that follows you between sites. The one exception is the attribution cookie an affiliate network may set on the pages that say so (see Affiliate Links); it records that a visit came from us, carries nothing from your MyBodyAI account, and is not advertising. We do not knowingly sell or share the personal information of anyone under 16, and the service is not intended for anyone under 15 at all (Section 14).
Your rights are to know what we hold and what we do with it, to receive a copy, to have it corrected, to have it deleted, to limit sensitive personal information, and not to be treated differently for using any of them. We run no loyalty programme, and nothing about your account or your price changes because you asked. Export My Data and Delete Account in the app answer the first two and the fourth immediately, without passing through anyone. For anything else, write to support@aiclysm.com. We reply within 45 days and will tell you if we need the further 45 days California allows. You may appoint an authorised agent to ask on your behalf; we will ask for written proof of the appointment and confirm it with you directly.
Requests are verified the only way we can verify them: they must come from the email address the account uses, or from inside the app while you are signed in. We hold no other identifying information to check you against, and we will not start collecting some in order to run a check. Your data is held on servers in the European Union, so using MyBodyAI from California means it is transferred there; Section 5 names the recipients that sit anywhere else, and Section 7 says on what basis anything travels beyond the EEA. If you live in Washington, Nevada or Connecticut, your health data has a separate document of its own: the Consumer Health Data Policy.
13. Automated Decision-Making & Profiling
MyBodyAI uses automated processing to compute health indices (such as Recovery, Stress Load, Body Alert, Biological Age) from your wearable data. These scores are generated algorithmically based on published research and personalized to your historical data. No decisions with legal or similarly significant effects are made solely based on automated processing. All outputs are informational wellness insights, not medical diagnoses. You have the right to request human review of any automated assessment by contacting us.
14. Children's Data
MyBodyAI is not intended for users under 15 years of age (in accordance with Czech law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
15. Cookies
The cookies we set ourselves are strictly necessary for the service to work: a session cookie and your language preference. We set no advertising cookies and nothing that follows you between sites, and no consent banner is required for strictly necessary cookies under the ePrivacy Directive. One cookie you may meet here is not ours: pages carrying an affiliate link say so, and if you follow such a link the network behind it may set its own attribution cookie. It records that the visit came from us, carries nothing from your MyBodyAI account, and is set only if you click. The Affiliate Links section below has the detail.
We use Umami, a privacy-focused, self-hosted web analytics tool, to understand website usage. Umami sets no cookies, stores no IP address and no account identifier, and does not track visitors across websites. It does record, per visit, an approximate location derived from the IP address — country, region and city — together with the browser, operating system, device type, screen size and language. Inside the app it also records a small number of named events, such as agreeing to connect a wearable or reaching a step of the first-run guide; these carry no account identifier and cannot be traced back to you. All of it is stored on our own servers within the EU, is not shared with anyone, and is currently kept without a time limit.
Separately from Umami, and only for accounts that are signed in, we record a handful of milestones from your first run: when the account was created, when it first signed in, which first-run screens were reached, when a data source was connected and how that attempt ended, and when the first day of data and the first result arrived. These are tied to your account, so unlike Umami they are not anonymous. They exist so we can see where people get stuck setting the app up. No page views, no free text, no tracking across sites. They are included in a data export and are deleted with the account.
Affiliate Links
Some links on this site are affiliate links, the pages that carry them say so, and the network behind them may set a cookie to attribute a possible purchase to us. Every other outbound link sets no affiliate cookie and earns us nothing. Either way we do not share your MyBodyAI account data with them. See our Affiliate Disclosure.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top of this page will be revised accordingly.
When a change affects what we do with your data, we ask you to agree again in the app and we record which version of this policy you agreed to. A revision that only adds information — such as Sections 11 and 12, which describe rights that residents of the United Kingdom and California already had — moves the date at the top of this page without asking you to agree to anything again. Every version of this policy stays published under the date it was issued at aiclysm.com/privacy/, so the text you agreed to is always there to read.
17. Contact
Aiclysm
Prague, Czech Republic
Email: support@aiclysm.com
Web: aiclysm.com