BILT

Privacy Policy

Last updated: July 30, 2026

This policy explains what BiLT collects, why, and what we do with it. We've tried to write it in plain language. If anything is unclear, email [email protected].

Who we are

BiLT is a fitness tracking app developed by an independent developer ("BiLT," "we," "us"). The app is available on iOS and Android. For any privacy matter, contact us at [email protected].

What we collect

Account information

When you create an account, we collect your email address and a display name you choose. You can sign in with email and password, Google Sign-In, or Sign in with Apple. Authentication is handled by Firebase Authentication and the selected sign-in provider. BiLT does not receive or store your plaintext password.

Subscription and purchase information

If you start or manage a paid subscription, we receive the store, product, subscription status, and renewal or expiration information needed to provide the correct access. RevenueCat processes this subscription and entitlement information on our behalf. Apple or Google handles checkout; BiLT and RevenueCat do not receive your payment-card number.

Fitness and health data you enter

BiLT stores the training, cardio, body, and nutrition data you log in the app. This includes workouts, sets and reps, cardio sessions, body measurements, food entries, photos you choose to attach, and any notes or preferences you set.

Apple Health data (iOS, if you opt in)

If you enable Apple Health integration, BiLT reads the following from Apple HealthKit. This access is read-only — BiLT never writes to Apple Health:

When you first connect, BiLT reads up to the last 90 days of this data so your history is complete from the start; after that it reads only new data. It is used to import your cardio sessions and to show your body and activity trends inside the app. BiLT does not sell HealthKit data, use it for advertising, or share it with data brokers. It is shared with a service provider only when needed for a feature you explicitly request, including an AI feature after the separate consent described below. You can disable Apple Health integration at any time in BiLT's settings, and you can revoke BiLT's HealthKit permission at any time in iOS Settings → Privacy & Security → Health.

Health Connect data (Android, if you opt in)

If you enable Health Connect integration on Android, BiLT reads the following from Google Health Connect. This access is read-only — BiLT never writes to Health Connect:

When you first connect, BiLT reads up to the last 90 days of this data so your history is complete from the start. Reading entries older than 30 days uses Health Connect's historical-data permission (READ_HEALTH_DATA_HISTORY); after the first import, BiLT reads only new data. It is used to import your cardio sessions and to show your body and activity trends inside the app. This data is never sold, used for advertising, or shared with data brokers. It is shared with a service provider only when needed for a feature you explicitly request, including an AI feature after the separate consent described below. You can disable Health Connect integration at any time in BiLT's settings, and you can revoke BiLT's access at any time in the Health Connect app (Settings → Security & privacy → Health Connect, or Health Connect → App permissions).

Device and diagnostic information

When you submit feedback or a bug report, we collect basic device information (device model, OS version, BiLT version) and any screenshot or description you choose to attach. This helps us reproduce and fix issues.

What we don't collect

How your data is stored

Your data is stored locally on your device and synced to Google Firebase (Firestore and Firebase Storage), operated by Google, using your authenticated account. Data is encrypted in transit (TLS) and at rest. Firebase security rules tie your training, nutrition, and health logs to your authenticated account, so other users of the app cannot read them.

Who can access your data: you, through your authenticated account; we, the developer, where it is necessary to operate the service, provide support, or act on a request from you (for example, exporting or deleting your data) — administrative access bypasses the per-user security rules, so we limit its use to these purposes; Google, as the Firebase infrastructure and authentication provider; RevenueCat, for subscription and entitlement processing; and Atlassian/Trello, when you submit a support report, to hold the description, reply email, account identifier, diagnostics, and optional screenshot used to investigate it. Cloudflare and Anthropic process AI requests only as described below. We never sell your data or use it for advertising.

What we do with your data

Legal basis for processing (EEA / UK users)

If you are in the EEA or UK, we rely on the following legal bases under the GDPR / UK GDPR:

Where we rely on consent, you can withdraw it at any time; withdrawal does not affect processing carried out before then.

AI features

BiLT asks for explicit permission the first time you take an AI action. If you allow it, BiLT sends only the data needed for that request through a proxy operated on Cloudflare Workers to Anthropic's Claude API. The proxy authenticates and forwards the request so no provider API key is stored on your device. Declining is optional and does not affect non-AI features; BiLT may ask again after a later AI action. You can review the disclosure and revoke future AI processing in Settings. Revocation does not undo processing that already occurred.

Depending on the feature you choose, an AI request may contain your prompt or selected photo; nutrition data and calorie or macro targets; goals, preferences, and available equipment; workouts and strength progress; current program state; weigh-ins and body-composition trends; and food-log or adherence data. BiLT sends these categories only to generate the nutrition estimate, meal idea, workout, or coaching response you requested. AI output can be inaccurate and is not medical advice or a substitute for a qualified professional. These features do not make automated decisions that produce legal or similarly significant effects about you.

Retention and training. BiLT does not use the Cloudflare proxy to add AI request bodies or model responses to your account; a result is stored in Firebase only when the feature needs to save it in your BiLT history or you choose to save it. Cloudflare processes requests and limited service or security metadata under its service terms and privacy safeguards. Under Anthropic's standard commercial API terms, inputs and outputs are deleted from its backend within 30 days, unless longer retention is required for law, abuse prevention, or Usage Policy enforcement. Anthropic states that commercial API inputs and outputs are not used to train its generative models unless the commercial customer explicitly opts in or submits them as feedback. BiLT has not opted in and does not submit your AI requests as provider feedback.

Cloudflare and Anthropic act as processors for this purpose. Access is limited to operating, securing, and supporting the service; requests are encrypted in transit; and BiLT does not permit either processor to sell the submitted data or use it for advertising.

Where your data is processed (international transfers)

Our processors include Google (Firebase), Cloudflare (AI request proxying), Anthropic (the Claude API provider), RevenueCat (subscription and entitlement processing), and Atlassian/Trello (support reports you submit). They may process personal data in the United States or other locations where they operate. For users in the EEA or UK, we rely on an applicable adequacy decision, including the EU-US / UK Data Privacy Framework where the processor is certified, or contractual safeguards such as the European Commission's Standard Contractual Clauses with the UK Addendum. You can request information about the relevant safeguard by emailing [email protected].

How long we keep your data

We keep your account and the data you log for as long as your account is active, so the app can show your history. When you request account deletion, BiLT disables access and starts a durable deletion job. The job removes data owned by your account before deleting the authentication identity, then continues retrying any copies in shared social records until cleanup completes. Limited recovery copies age out under restricted backup, point-in-time-recovery, and storage-retention schedules and are not used to recreate a deleted account. Diagnostic and crash data is kept for up to 12 months. We may retain limited information for longer where the law requires it.

Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

We will respond to any request within one month. We won't charge you or treat you differently for exercising these rights.

If you're in the EEA, UK, California, or another jurisdiction with specific privacy laws (GDPR, UK GDPR, CCPA), those rights apply to you in full; the plain-language list above is how we honour them.

Right to complain. If you're in the EEA or UK and believe we've mishandled your data, you can lodge a complaint with your local data protection authority (in the EEA, find yours via the European Data Protection Board; in the UK, the Information Commissioner's Office at ico.org.uk). We'd appreciate the chance to put it right first — email [email protected].

Children

BiLT is not directed at children. We do not knowingly collect data from children under 13 (or, in the EEA, under the digital-consent age set by your country, which is between 13 and 16). If we learn we've collected such data without the required parental consent, we'll delete it.

Changes to this policy

If we materially change this policy, we'll update the "Last updated" date and, for significant changes, notify you in-app or by email.

Contact

Privacy questions: [email protected]
General questions: [email protected]