Privacy Policy
Last updated: August 29, 2026 · Aiclysm
Archived version, as published on August 29, 2026. It stays here so you can read exactly the text you agreed to. The policy in force is at aiclysm.com/privacy.html; every version is listed at aiclysm.com/privacy/.
1. Data Controller
The controller of your personal data is Aiclysm, the trade name of a sole trader registered in the Czech Republic (hereinafter "we", "us", "Aiclysm").
Contact for privacy inquiries: info@aiclysm.com
Supervisory authority: UOOU (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic · uoou.gov.cz
2. What Data We Collect
2.1 Account Data
Email address, password (stored as a secure hash), language preference, and subscription status. Authentication is handled via password-based login. Email verification codes are used during registration and password recovery. You can also sign in with your Google Account; in that case we receive only your email address, name and Google account identifier from Google, and Google receives no data about your use of the Service. We do not collect your name, phone number, or physical address unless you provide it voluntarily.
2.2 Health & Wearable Data
When you connect a wearable platform (Polar, Withings, Fitbit, Oura), we retrieve health-related data through their official APIs using OAuth 2.0, and we never access or store your login credentials. Garmin data is imported manually from the data export file you upload, as Garmin's official API is not yet available to us. The Strava integration was retired on 28 July 2026: the authorisation was revoked, the tokens deleted and the activity data we had received from Strava removed. Our Garmin watch app (Connect IQ) sends two measurements from a paired watch: your daily average stress and your Body Battery curve (morning peak, latest level, charged and drained). Nothing else leaves the watch, no heart rate, steps, location or activity files, and unpairing it stops the sending. Our Android app reads health data from Health Connect on your phone, with your explicit permission and only in the categories you grant: heart rate and HRV, sleep, steps and workouts, breathing rate and blood oxygen, body composition, blood pressure, body temperature and VO2max. It reads what other apps on that phone have already written there and writes nothing back, and you can switch the phone off as a data source in Settings at any time.
| Category | Examples | Source |
|---|---|---|
| Heart Rate & HRV | Resting HR, HRV (RMSSD/SDNN), max HR | Garmin (manual import), Polar, Fitbit (HRV+RHR); Withings (RHR only); Oura (HRV+RHR); MyBodyAI Android app (Health Connect) |
| Sleep | Sleep stages (deep, REM, light, awake), duration, sleep score | Garmin (manual import), Polar, Fitbit, Withings, Oura; MyBodyAI Android app (Health Connect) |
| Activity | Steps, active minutes, workouts, calories, distance | Garmin (manual import), Polar, Fitbit, Withings, Oura; MyBodyAI Android app (Health Connect) |
| Stress & Recovery | Stress score, body battery, daytime stress minutes, resilience level, device recovery score | Garmin (manual import); Garmin watch app (Connect IQ: daily average stress, Body Battery); Oura (daytime stress, resilience, recovery); Polar (recovery) |
| Respiratory | Respiratory rate, SpO2 | Garmin (manual import), Fitbit, Withings (SpO2); Polar (breathing rate); Oura (SpO2, breathing rate); MyBodyAI Android app (Health Connect) |
| Body Composition | Weight, body fat %, muscle mass, BMI | Withings, Fitbit, Garmin (manual import); MyBodyAI Android app (Health Connect) |
| Blood Pressure | Systolic, diastolic, heart pulse | Withings; MyBodyAI Android app (Health Connect) |
| Body Temperature | Skin temperature, body temperature deviation | Withings, Fitbit, Oura; MyBodyAI Android app (Health Connect) |
| Fitness & Cardiovascular | VO2max (cardio fitness), cardiovascular / vascular age, ECG atrial fibrillation detections | Fitbit (VO2max, ECG); Withings (vascular age); Oura (VO2max, cardiovascular age); Garmin (manual import: VO2max); MyBodyAI Android app (Health Connect: VO2max) |
2.3 Derived Health Indices
From the raw data above, our algorithms compute 12 proprietary health indices: Immunity, Recovery, Stress Load, Sleep Debt, Circadian Rhythm, ANS Balance, Body Alert, Overtraining, Respiratory, Morning Energy, Sleep Quality, Cardiac Efficiency — plus Body Status, Biological Age across 8 domains, and Training Load analysis. These are algorithmic estimates, not clinical measurements.
2.4 Billing Data
MyBodyAI+ is a paid subscription, processed securely by Stripe (stripe.com). We store only your subscription status and Stripe customer ID. We never see or store your credit card number. For Stripe’s privacy practices, see stripe.com/privacy.
2.5 Technical Data
IP address, browser type, device information, and server access logs. These are used for security, debugging, and service improvement. We do not use advertising or tracking cookies. For anonymous usage statistics, we use Umami — a self-hosted, cookie-free analytics tool that collects no personal data (see Section 13).
3. Legal Basis for Processing
We process your personal data on the following legal bases under the GDPR:
- Contract performance (Art. 6(1)(b)) — to provide the MyBodyAI service, manage your account, and process your subscription.
- Explicit consent (Art. 9(2)(a)) — for processing health data (special category data). You grant this consent when connecting a wearable platform. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)) — for security, fraud prevention, and service improvement.
- Legal obligation (Art. 6(1)(c)) — for tax records, accounting obligations, and compliance with Czech law.
4. How We Use Your Data
- To compute and display your health indices on the MyBodyAI dashboard
- To manage your account and subscription
- To send essential service notifications (e.g., subscription expiry, security alerts)
- To improve our algorithms using anonymized and aggregated data
- To comply with legal obligations
- To ensure security and prevent abuse of our services
5. Data Sharing & Third Parties
We share your data only with the following categories of recipients, all bound by data processing agreements (DPAs):
- Hosting provider — server infrastructure located in the EU
- Wearable platform APIs — data flows are user-initiated via OAuth; each platform's privacy policy governs their data handling
- Stripe — payment processing (if you choose to support us). Stripe processes payment data under their own privacy policy. We receive only subscription status.
- Google (Google Ireland Ltd.) — optional sign-in provider. When you choose to sign in with Google, we receive your email address, name and account identifier from Google under their own privacy policy (policies.google.com/privacy). Transfers to the USA are covered by the EU-U.S. Data Privacy Framework. We never send Google your health data.
- Open Wearables API — our own middleware service that securely connects to wearable platforms via OAuth 2.0. Hosted on the same EU server.
- Health Connect (Android) — our Android app is in closed testing on Google Play. With your explicit permission it reads health data from Health Connect on your phone; that data stays on our servers and is never shared. Using the phone as a data source can be switched off in Settings.
- Sentry — error monitoring service (hosted in EU Frankfurt). Captures technical error reports (stack traces, browser type, URL) to help us fix bugs. No health data or personal identifiers are included in error reports. Sentry Privacy Policy.
- E-mail delivery (Forpsi, Czech Republic) — transactional e-mails and the weekly summary are sent through our mail provider's SMTP servers. The provider handles your e-mail address and the message body, which in the weekly summary contains your own scores. You can switch these e-mails off in Settings.
- Open-Meteo (Germany) — weather and air-quality lookups behind the "when and where to train" advice. We send coordinates rounded to roughly 1 km, and, if you search for a place by name, that search text. No name, no e-mail, no health data. Saving a location is optional and can be cleared in Settings.
- BigDataCloud (Australia) — turns coordinates into a place name so the app can show where a reading came from. Receives only coordinates rounded to roughly 1 km, no identifier. It sits outside the EEA, so the transfer relies on Standard Contractual Clauses, and it happens only when you set a location.
- Telegram (error alerts) — server error reports go to a private channel only the operator can read, so an outage is noticed within minutes. An error line can contain an account e-mail address. No wearable or health measurements are sent.
- GitHub (encrypted off-site backups) — an encrypted copy of the database backups is kept in a private repository so that losing the server is not losing your data. Archives are AES-256 encrypted before they leave the server; GitHub cannot read them.
- Push delivery (Google FCM for the Android app, browser push services for web push) — if you turn notifications on, the delivery service receives your device token and the short notification text, which can name a health state such as low recovery. Notifications stay off until you enable them, and turning them off removes the token.
We may disclose personal data to law enforcement or regulatory authorities only when required by law. We will notify you of such requests where legally permitted.
6. Provider-Specific Data Handling
Each wearable data provider has specific requirements for how we handle your data. We comply with all provider terms and policies:
| Provider | Data Caching | Deletion on Revocation | Attribution |
|---|---|---|---|
| Garmin (manual import) | Imported from your export | N/A | Data from your Garmin export |
| Polar | As needed for service | Tokens revoked, data deleted | Data sourced from Polar |
| Strava | Retired 28 July 2026 | Tokens revoked, data deleted | — |
| Withings | As needed for service | Prompt deletion | — |
| Fitbit | As needed for service | Prompt deletion | — |
| Oura | As needed for service | Prompt deletion | — |
The Strava integration was retired on 28 July 2026 and every activity record we had received from Strava was deleted from our systems. While it ran, Strava data was shown only to the user who authorized the connection, never to anyone else, and data that became unavailable was removed from our cache immediately.
In addition to GDPR breach notification requirements (72 hours to supervisory authority), we will notify affected data providers within 24 hours of discovering a security breach, as required by their respective terms.
7. International Data Transfers
Your data is primarily stored on servers within the European Union. When data is transferred outside the EEA, we rely on EU Standard Contractual Clauses (SCCs) or adequacy decisions to ensure an adequate level of protection.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Health & wearable data | Until account deletion or integration disconnection |
| Computed health indices | Until account deletion |
| Billing records | 10 years (Czech tax law) |
| Server logs (web access, application, sync) | 30 days |
| Backup archives on the server | 30 days |
| Encrypted off-site backup copy (GitHub) | Older archives stay in the off-site version history; encrypted, used only for disaster recovery |
| First-run milestones (sign-up, connecting a source, first result) | Until account deletion |
| First-run activity (each attempt to connect, taps on a source we do not support) | 12 months, or until account deletion |
| Free-trial fingerprint | Kept after account deletion |
After account deletion, all personal data is permanently erased from our live systems, and from the backup archives held on the server, within 30 days. The encrypted off-site copy at GitHub also keeps earlier archives in its version history, so a backup taken before your deletion can survive there for longer. Those archives are AES-256 encrypted before they leave the server, GitHub cannot read them, and they are used only to rebuild the service after the loss of the server. Anonymized and aggregated data (which can no longer identify you) may be retained indefinitely for statistical purposes.
One thing outlives the deletion: a one-way fingerprint (keyed hash) of your e-mail address, recorded when you receive the free trial. It cannot be turned back into an address and is never used to contact you or to rebuild an account. Its only purpose is to keep the free trial at one per person, so that deleting an account and registering again does not hand out another one. We keep no e-mail address, name or account identifier alongside it.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.2+)
- Password-based authentication with secure hashing, and time-limited email verification codes for registration and password recovery, plus optional Google Sign-In (OAuth 2.0 / OpenID Connect)
- Optional two-factor authentication (TOTP authenticator apps and WebAuthn passkeys) with one-time recovery codes
- OAuth 2.0 for wearable integrations — we never store your third-party credentials
- Regular security reviews and updates
- Breach notification to UOOU within 72 hours per GDPR Article 33, and to affected data providers within 24 hours
- OAuth tokens and API credentials encrypted at rest
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15) — obtain a copy of your personal data
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — request deletion of your data ("right to be forgotten")
- Restriction (Art. 18) — restrict processing in certain circumstances
- Portability (Art. 20) — receive your data in a structured, machine-readable format
- Objection (Art. 21) — object to processing based on legitimate interest
- Withdraw consent (Art. 7(3)) — withdraw consent for health data processing at any time, without affecting prior processing
- Complaint — lodge a complaint with UOOU or the supervisory authority of your EU member state
To exercise any of these rights, contact us at info@aiclysm.com. We will respond within 30 days.
You can also exercise these rights directly in the app: go to your Dashboard and use Export My Data to download all your data in JSON format, or Delete Account to permanently erase your account and all associated data.
11. Automated Decision-Making & Profiling
MyBodyAI uses automated processing to compute health indices (such as Recovery, Stress Load, Body Alert, Biological Age) from your wearable data. These scores are generated algorithmically based on published research and personalized to your historical data. No decisions with legal or similarly significant effects are made solely based on automated processing. All outputs are informational wellness insights, not medical diagnoses. You have the right to request human review of any automated assessment by contacting us.
12. Children's Data
MyBodyAI is not intended for users under 15 years of age (in accordance with Czech law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
13. Cookies
We use only essential cookies necessary for the functioning of the service (session cookies, language preference). We do not use advertising or tracking cookies. No cookie consent banner is required for strictly necessary cookies under the ePrivacy Directive.
We use Umami, a privacy-focused, self-hosted web analytics tool, to understand website usage. Umami does not use cookies, does not collect personally identifiable information (PII), and does not track users across websites. All analytics data is stored on our own servers within the EU. No data is shared with third parties.
Separately from Umami, and only for accounts that are signed in, we record a handful of milestones from your first run: when the account was created, when it first signed in, which first-run screens were reached, when a data source was connected and how that attempt ended, and when the first day of data and the first result arrived. These are tied to your account, so unlike Umami they are not anonymous. They exist so we can see where people get stuck setting the app up. No page views, no free text, no tracking across sites. They are included in a data export and are deleted with the account.
Affiliate Links
Some links on this site are affiliate links, the pages that carry them say so, and the network behind them may set a cookie to attribute a possible purchase to us. Every other outbound link sets no affiliate cookie and earns us nothing. Either way we do not share your MyBodyAI account data with them. See our Affiliate Disclosure.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last updated" date at the top of this page will be revised accordingly.
15. Contact
Aiclysm
Prague, Czech Republic
Email: info@aiclysm.com
Web: aiclysm.com