Privacy policy
Last updated 21 July 2026
This page is a plain-language draft written by the Back At It team. It has not yet been reviewed by a lawyer. We are publishing it because being clear with you now beats saying nothing, and we will update it once counsel has been through it.
This explains what Back At It collects, why we collect it, who we share it with, and what you can do about it. Health information is the most personal thing you can hand an app, and we would rather over-explain than leave you guessing.
What we collect
Things you give us. Your name, username, email and password; your answers to the intake questions; and anything you choose to log.
- Body and training data: weight, measurements, workouts, sets and reps, steps, water, sleep
- Nutrition: food entries, macros, meal plans
- Health data you opt into logging: health conditions, medications, hormone therapy and injections, lab results, blood pressure, blood glucose, menstrual cycle, pain entries
- Journal entries and progress photos
- Messages you send through the app
Files you upload. If you use the data import feature, we read the export file you upload from another app (Apple Health, Fitbit, Google Fit, Strava, MyFitnessPal, Cronometer or Lose It) to bring your history across. We do not connect to those services or sync from them in the background. You upload a file, we read it, that is the whole relationship.
Payment details. Handled by Stripe. We never see or store your card number.
Basic operational data. The minimum needed to run and secure the service, such as request logs and rate-limit counters.
Why we collect it
- To run the features you asked for: your plan, your targets, your dashboard, your history
- To show you your own data back over time
- To operate the social parts you choose to switch on
- To take payment and manage your membership
- To keep the service secure and prevent abuse
Who we share it with
We use a small number of service providers to run the app. They only get what they need to do their job.
- Supabase - the database, your login, and access control. This is where your account and logged data live.
- Vercel - hosting the app itself.
- Cloudflare R2 - storage for progress photos and other media you upload.
- Stripe - payments and subscription billing.
- Upstash - rate limiting, which sees request counters rather than your content.
- MuscleWiki - exercise information and demo videos. We send a search term, not anything about you.
- Spoonacular - recipe and restaurant menu information. We send a search term, not anything about you.
- USDA FoodData Central - public nutrition data for ingredient lookups. We send an ingredient name, not anything about you.
- Spotify - only if you connect it, and only to show and control what is playing.
We may also share information with other users, but only what you choose to make visible through a social feature; where the law requires it, or to protect someone's safety; and if the business is ever sold or merged, in which case we will tell you.
What is not here. There is no AI provider processing your data: the coaching messages in the app are written in advance, not generated from anything you have logged. There is no advertising network, no analytics tracker, and no wearable API pulling from your devices.
Consumer health data
Some of what you can log is consumer health data- information that relates to your physical or mental health. Laws like Washington's My Health My Data Act and Nevada's health-data law give this information extra protection, and we hold it to that standard for everyone, wherever you live.
The health data we hold is only what you choose to log. Depending on which trackers you turn on, that can include:
- Hormone therapy and injections (TRT), and GLP medication reminders and doses
- Menstrual cycle dates and symptoms, and any cycle or ovulation estimates we calculate from them
- Blood glucose and blood pressure readings
- Lab and bloodwork results you enter
- Pain entries, health conditions, and medications
- Body measurements, weight, sleep, and mood or energy check-ins
- Any custom tracker you create, and the readings you log against it
- Journal entries and progress photos, where you describe how you feel
How we use it. Only to give you your own information back and to run the wellness features you asked for - your plan, your targets, your history, your estimates. It is general wellness and education, never medical advice (see our medical disclaimer).
Who can see it. Your clinical entries are owner-only: they are protected at the database level so that no other user, and no Back At It administrator, has row-level access to them. A coach can see your health data only if you turn on medical sharing yourself, and you can turn it back off at any time. The service providers listed above only process data to run the app under contract, never for their own purposes.
Consent. We collect health data on the basis of your consent, which you give by choosing to log it. You can withdraw that consent at any time by deleting the entries, hiding the tracker, or deleting your account.
Your health-data rights. You can confirm what health data we hold and get a copy (including who it has been shared with); correct it from the screen where you logged it; delete it, or delete your account to remove all of it; and withdraw your consent to collection. We will never deny you service or charge you differently for exercising these rights. To exercise one, use the controls in the app or contact us. If we decline a request you may appeal by contacting us again, and Washington and Nevada residents may also raise the matter with their state Attorney General.
Your choices
- See and edit almost everything you have logged, from the screen where you logged it
- Export your data from your account settings
- Deactivate your account, which hides it while you decide
- Delete your account and its data from your account settings
- Choose what is visible to other users, per journal entry and in your privacy settings
- Disconnect Spotify at any time
Depending on where you live you may have additional rights over your data, including the right to have health information deleted. Use the controls above or contact us and we will honour them.
How long we keep it
We keep your data while your account is open. When you delete your account we remove your data, including your uploaded media, on the schedule described in your account settings. Some records may persist briefly in backups, and we may keep the minimum needed to meet a legal obligation.
Security
Your data is encrypted in transit and at rest, and every table that holds your information is protected by row-level rules so that one account cannot read another's. Your clinical entries, including health conditions, medications, lab results and journals, are owner-only: no administrator has row-level access to them. No system is perfect, and we will tell you if something goes wrong that affects you.
Age
You must be 21 or older to use Back At It. We do not knowingly collect information from anyone under 18. If we learn we have, we delete it.
Changes
We will update this page and change the date at the top. For anything significant we will tell you in the app or by email.
Contact
Reach us through the contact options in your account settings. See also our terms and medical disclaimer.