BoraFit ("BoraFit", "we", "us") is a nutrition and weight-tracking app. This policy explains what data we collect, why, how we protect it, and what choices you have. We try to keep this short and plain.
Current status. There is no account creation or email signup on this site. We do run product analytics on these pages (see Section 1) so we can tell which parts of the page people read. The rest of this policy describes how the service handles data when it is running, and applies to existing data from the previous version.
1. Information we collect
We collect only what BoraFit needs to do its job. That covers these categories:
- Historical early-access information. The site no longer accepts email signups. If you previously joined the early-access list, we may still hold the email address, interest, language, and campaign attribution you submitted. That submission did not create an account and collected no health data.
- Account information. When you sign up, our auth provider (Clerk) stores your name, email address, and (if you sign in with Google) a unique Google account identifier. We do not receive or store your Google password.
- Health and fitness data you log. Body weight, height, sex, date of birth, activity level, food log entries (including the foods, portions, dates, and any photos you upload), water intake, and any goals or strategies you set in the app.
- Progress photos, if you choose to take them. Front, side and back photographs of your body, each with the date you added it. These are optional in the strictest sense: nothing in the app requires one, no week is marked incomplete without one, and you can use every other part of BoraFit without ever adding any. You pick them from your phone's photo library — the app has no camera — and you can remove any of them at any time, which erases the file. They are stored as files, separately from the rest of your data, and are never used to train anything or shown to anyone but you and a coach you have granted access to.
- Google Health data, if you connect it. When you authorize BoraFit to read from Google Health, we receive weight readings (and optionally body-fat readings) associated with your Google account. See Section 4 for the specific rules that apply to this data.
- Product analytics and session replay. We use PostHog to record anonymized events and session replays (interactions, clicks, page views) so we can understand how the app is used and fix bugs. Replays mask password fields and any element we tag as sensitive. This is active on this marketing site too, including while signups are closed. PostHog is loaded through our own domain (
/bf-relay) rather than a third-party domain, so requests are first-party; this is for reliability of measurement, not to bypass your choices. See Section 9 for how to opt out.
2. How we use your information
- To operate the core features of BoraFit (logging food, tracking weight, computing macro targets, suggesting AI-parsed meals).
- To show your progress photos back to you side by side, and to show them to a coach you have granted access to. That access is the same permission that covers your weight: a coach you have not shared weight with cannot see your photos, and ending a coach's access ends it for the photos too. A coach can only look — they cannot delete a photo of you. Only you can.
- To sync your weight readings from Google Health into your BoraFit history when you choose to connect that integration.
- To improve the app: diagnose crashes, measure feature usage, prioritize improvements.
- To honor support, access, or deletion requests from people who previously joined the early-access list.
- To send you essential service notifications (e.g. account changes). We do not send marketing email.
- To comply with legal obligations and protect against fraud or abuse.
We do not sell your personal data. We do not use your health data to target advertising. We do not allow advertisers on BoraFit.
3. Artificial intelligence features
BoraFit uses Google's Gemini AI to interpret typed meal descriptions and photos of meals into structured nutrition data. When you use these features:
- The text you type and the photo you upload are sent to Google's Gemini API for processing.
- We do not send your name, email, or other identifying account information along with these requests.
- Google's handling of this data is governed by their API terms; we use Gemini configured for the lowest available data retention.
- The structured output (the food entries Gemini suggests) is stored only if you choose to log it.
4. Google user data
If you choose to connect Google Health, BoraFit requests access to the googlehealth.health_metrics_and_measurements.readonly scope. This scope allows BoraFit to read body weight and body composition measurements from your Google account. We do not write to your Google account, and we do not request any other Google scopes for the Health integration.
BoraFit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means:
- Google Health data is used only to provide and improve user-facing features visible inside the BoraFit app.
- We do not transfer this data to third parties except as needed to provide the service, or for security purposes, or to comply with applicable law.
- We do not use this data to serve advertising.
- We do not allow humans to read this data unless we have your explicit consent, it is necessary for security or fraud-prevention purposes, it is required by law, or the data has been aggregated and anonymized.
The Google Health integration is not available yet — today every weight reading in BoraFit is one you entered yourself. If and when you connect it, you will be able to disconnect at any time from inside the app, or revoke access directly from your Google Account permissions page. On disconnecting, we stop fetching new readings; readings already imported remain in your BoraFit history unless you delete them.
5. Who processes your data on our behalf
BoraFit is a small operation. We rely on these processors to run the service. Each is bound to handle your data only on our instructions:
- Cloudflare: application hosting, edge compute, and (R2) file storage for progress photos.
- Clerk: user authentication and session management.
- Google (Gemini): AI parsing of meal text and photos when you use those features.
- Google (Health API): only if you connect Google Health to BoraFit.
- PostHog: product analytics and anonymized session replay.
- Open Food Facts and USDA: public food databases used to look up nutrition values. We send the barcode or search term you provide, and they return public nutrition data. They do not receive your identity.
6. Where your data is stored
Your data is stored on our providers' distributed infrastructure. Data may be processed in any country where our processors operate. By using BoraFit you consent to this international processing. We rely on standard contractual clauses and equivalent safeguards where required.
7. How long we keep your data
We keep historical early-access information until you ask us to remove it or it is no longer needed. We keep account data for as long as your account is active. If you delete your account, we delete the personal data tied to it within 30 days, except where we are legally required to retain it. Aggregated, fully anonymized analytics may be retained indefinitely because it can no longer be linked to you.
8. Security
We use industry-standard security practices: TLS encryption for all traffic, encryption at rest in our database, OAuth-based access tokens (we never see your Google password), and least-privilege access controls. No system is perfectly secure, and we cannot guarantee absolute protection against every possible threat.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you. Profile → Your data → Export everything produces one JSON file containing every weigh-in, food, log entry, calorie target and check-in we hold, along with a record of everyone you have granted access to — including access you have since removed. Progress photos are listed there too — the pictures themselves are files and cannot travel inside a JSON document, so each one you still have comes with a private download link that works for 24 hours from the moment you export. Photos you removed are listed with the date you removed them and no link, because the file is already gone.
- Correct inaccurate data.
- Delete your data ("right to be forgotten"). Profile → Delete account erases it immediately and permanently: there is no soft-delete and no recovery window, and any coach loses access at once. This includes the photo files themselves, which are deleted from storage before your account is; if for any reason they cannot be, the deletion stops with nothing removed and tells you to try again, rather than reporting a completeness it did not achieve. You can also email the address below.
- Remove a single progress photo without deleting anything else. The file is erased when you remove it — we keep only the fact that a photo existed on that date and that you removed it, so your export can still account for it.
- Object to or restrict certain processing.
- Export your data in a portable format — the same export described above.
- Withdraw consent at any time (for example, by disconnecting Google Health).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at the email below. We will respond within 30 days.
Opting out of analytics. Enabling "Do Not Track" or "Global Privacy Control" in your browser stops PostHog from recording your visit. You can also email us and we will delete any recording associated with you.
10. Children
BoraFit is not directed to children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this policy as the product evolves. When we make material changes, we will update the "Effective" date at the top and (where appropriate) notify you inside the app or by email. Continued use of BoraFit after a change means you accept the updated policy.
12. Contact
Questions about this policy, or requests under your data rights: [email protected].
See also our Terms of Service.