BodyBlind – Privacy Policy
Last Updated: July 11, 2026
1. Introduction
Welcome to BodyBlind, a service operated by PoomAt. We recognize that your movement media, body information, and athletic performance are deeply personal. This Privacy Policy explains how we use your information to create reference videos, form feedback, and live coaching experiences while protecting your data under high global standards. Our goal is not just to comply with laws, but to proactively improve our systems to protect your privacy.
2. Information We Collect & Why
2.1 Movement & Visual Data
To provide personalized reference videos, form feedback, and coaching features, we process:
- Visual Attributes: We process visible body proportions, movement positions, equipment, and uploaded photo/video details. This data is used exclusively to create your requested reference video or feedback and does not serve as a permanent biometric identifier.
- Practice Clips: Videos selected for Form Match are analyzed on your device and are not uploaded to BodyBlind storage. For an Apple-linked account, the resulting scores and coaching notes may be saved to your private history. Guest results remain in the current app session.
- Live Coach Camera: Live camera frames are analyzed on your device to estimate movement landmarks. Raw Live Coach frames are not uploaded. If remote voice is available, the short coaching cue text—not the camera frame—is sent for speech synthesis; otherwise the device voice is used.
2.2 Account & Technical Info
- Identity: Email and name (via Apple Sign-In) to manage your credits and history.
- Transactions and Notifications: App Store transaction identifiers and a device notification token are processed to issue unlocks, prevent duplicate crediting, handle refunds, and deliver requested status alerts.
- Security, Notifications, and SDK Diagnostics: Firebase and our processing providers may generate limited request, timestamp, network, installation, device/app, notification-token, and error records needed to secure and operate the Service. The on-device ML Kit pose SDK also collects per-install identifiers, device/app details, performance, API configuration, feature events, and error codes for diagnostics and SDK usage analytics. Raw Live Coach and Form Match frames are processed locally and are not uploaded as part of that diagnostic collection. The App does not include Firebase Analytics, advertising analytics, or cross-app tracking.
3. Personalized Processing & Privacy by Design
BodyBlind uses a privacy-first architecture. Your data is handled as follows:
- Purpose Limitation: Your photos and videos are used only to provide, secure, and troubleshoot the reference, feedback, or coaching experience you request. BodyBlind does not use your personal likeness to train a generalized BodyBlind model.
- Local-First Processing: Practice clips and Live Coach camera frames stay on your device. A source photo is uploaded only when you request a generated reference.
- Service Providers: We use Firebase for authentication, database, storage, and notifications; Apple for Sign in with Apple and StoreKit; an image/video generation provider for requested references; and a speech provider for eligible remote coaching voice. They receive only the data needed for that function.
- Proactive Improvement: If we identify that any regional law (such as GDPR in Europe or BIPA in the US) requires stronger protections, we commit to evolving our App's architecture to exceed those requirements.
4. Data Storage & Worldwide Rights
We honor your data rights regardless of where you live:
- Storage and Deletion: Source photos and generated references remain in your private library until you delete the guide or account. Account deletion removes the active profile, media, analyses, and user credit ledger from BodyBlind's primary cloud stores. A generated output may remain temporarily with a processing provider under that provider's security and retention controls.
- Limited Anti-Abuse Retention: To enforce the one-time Apple-linked welcome credit, we retain a keyed, one-way marker derived from the Apple provider identifier after account deletion. Separate purpose-bound one-way markers may also retain purchase, remote-voice, posture-history, and generated-media quota totals. These markers are not email addresses, cannot be used to sign in, and are used only to prevent repeated claims, replay, or service-cost limit resets. Rolling voice, posture, and generation quota records receive an expiry no later than 48 hours after their latest use and are then removed on Firebase's asynchronous TTL schedule. One-time welcome, lifetime Sandbox-credit, transaction/refund, and deleted-account integrity markers may be kept longer because deleting them would re-enable replay or repeated grants.
- Deletion Integrity: We retain a one-way marker derived from the deleted Firebase account identifier so delayed backend events cannot recreate a profile after deletion. It cannot be used to authenticate or recover the deleted account.
- Purchase Integrity: Limited verified App Store transaction and refund event markers may be retained where needed to prevent duplicate crediting, honor a refund, resolve a dispute, or meet legal and accounting obligations.
- Global Compliance: We adhere to the principles of GDPR (EU), CCPA/CPRA (California), and LGPD (Brazil). If our Service is found to be non-compliant in your specific region, we will immediately limit service while we upgrade our systems to meet those local standards.
5. Data Security
We treat your reference videos and training media as high-value assets. We use TLS for data in transit, provider-managed encryption at rest, account-scoped access rules, short-lived upload reservations, and automated deletion workflows. Human access is restricted and is used only when necessary for security, legal obligations, or support you request.
6. Contact & Data Protection
For any privacy-related inquiries or to exercise your data rights, please contact our Data Protection Officer at:
Email: support@poomat.com
7. Children's Privacy
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us.
8. Your Choices
You can deny camera or notification permission, use on-device Form Match without uploading a practice clip, delete individual references, or delete your account in the App. Deleting a guest profile also deletes its anonymous Firebase identity and starts the same cloud-data cleanup workflow. No electronic transmission or storage system is completely risk-free.
9. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us:
By email: support@poomat.com