Skip to content

Privacy Policy

EFFECTIVE AUGUST 27, 2026 · VERSION 4.0 · BILDBOT INC.

Bildbot Inc. ("Bild Health," "we," "us") provides the Bild Health applications and website for adults taking GLP-1 medications. The Services process sensitive information: the medication you take, the doses you log, your protocol activity, and changes in your body composition. This Privacy Policy describes the information we collect, where it is stored, the parties to whom it is disclosed, and the rights and choices available to you.

1. Scope

This Policy applies to the Bild Health mobile applications for iOS and Android (together, the "App") and the bildhealth.com website (the "Site," and together with the App, the "Services"). Where a practice is platform-specific, this Policy identifies the platform. The Services are offered in the United States to individuals 18 years of age or older. Bild Health is a consumer wellness product. It is not a healthcare provider, is not a medical device, and is not a covered entity or business associate under HIPAA; HIPAA therefore does not apply to the Services. We apply the protections described in this Policy as a matter of policy, and we treat state consumer-health-data statutes as our minimum standard. The Services provide education, not medical advice; consult your prescriber for all medication decisions.

Because Bild Health is a product specifically for people using GLP-1 medications, the fact that you hold an account may itself indicate information about your health. For that reason, we apply the protections of our Consumer Health Data Privacy Policy to account information as well as to the health information you record.

2. Information we collect

Information you provide in the App:

  • Medication information — medication names, doses, schedules, shot logs, injection sites, related notes, and dose reminder settings.
  • Daily protocol logs — protein, water, lifting, and cardio entries.
  • Intake and goal information — height, weight, goal weight, birth date, sex, and onboarding questionnaire answers.
  • Body measurements you log — weight, body fat percentage, lean mass, and fat mass.
  • Profile details — an optional display name and profile photo, stored on your device.
  • Post-crash feedback (iOS) — an optional free-text note you may submit after an App crash, which is filtered on your device to remove identifying and health values before transmission. The filter is pattern-based and cannot catch everything, so avoid typing health details you do not want transmitted.

Account information. The App can be used without an account, and browsing the Site requires none. An account is required only for purchases and the signed-in account area on the Site, and for App features that depend on one, such as cross-device sync where offered. When you create an account, we collect the name, email address, and credentials you register — or, if you sign in through a supported third-party sign-in provider, the email address that provider shares with us — and we assign your account an opaque identifier. Account information is stored on our servers; credentials are stored in hashed form.

Information collected with your permission or at your direction:

  • Platform health data — weight, body fat percentage, lean mass, and height, read on a read-only basis from Apple Health (iOS) or Health Connect (Android) with your device-level permission. These values are used to display your charts and are not copied to our servers unless you enable cross-device sync and expressly include them (Section 4).
  • DEXA scan results — scan date, body fat percentage, lean mass, fat mass, total mass, and bone mass, imported only if you connect your BodySpec account or import a report. BodySpec is a service you hold an account with directly; connecting it is your instruction to that provider to share your scan data with the App.

Information collected automatically:

  • Usage analytics — anonymous event names (for example, "shot_logged"), screen names, device model, and operating-system version, keyed to an anonymous, device-scoped identifier.
  • Crash and diagnostic data — crash reports, error traces, a small sample of app-performance measurements, device model, and operating-system version, keyed to the same anonymous identifier on iOS and to a separate anonymous identifier on Android. Reports are filtered on your device to remove identifying information and health values before transmission.
  • Purchase and subscription state — whether a subscription is active, via the applicable app marketplace and our subscription-management provider.
  • Advertising attribution — if you installed the App after tapping one of our Apple Search Ads, the campaign, ad group, or keyword identifier that preceded the installation. This is provided to us by Apple and is stored against an anonymous, install-scoped identifier; no advertising identifier and no health data are involved. See Section 3.

Information collected on the Site:

  • Waitlist email — if you join the Android waitlist, the email address you submit, used solely to send the single notification described at the point of collection.
  • Web account and billing information — if you sign in or purchase on the Site, your account information and subscription records. Payment card details are collected and processed by our payment processor; we do not receive or store card numbers.
  • Cookies and similar technologies — as described in Section 9.
  • Feedback you send us — if you use a feedback form, the message you write and any email address you provide with it, stored on our servers so we can read and respond. Please do not include health details you do not want stored with the message.

3. What we do not do

  • We do not sell your personal data for money.
  • The App contains no advertising, and no health data, account data, or crash data is used for or shared for advertising.
  • Measuring our own advertising. We measure which of our own ads led to an installation of the App, and whether that installation resulted in a subscription, so that we know where to spend. Two mechanisms are used, both provided by Apple, and neither uses a tracking identifier. Apple Search Ads attribution tells us the campaign, ad group, or keyword that preceded an installation. Apple's SKAdNetwork has your device's operating system — not the App — send an advertising network an anonymous, aggregated report containing a single number indicating how far through setup an installation progressed and whether a subscription was purchased; Apple withholds that number entirely unless enough installations are grouped together for it to be anonymous. We receive and retain copies of these anonymous, aggregated reports, and we record whether an attributed installation led to a subscription. Neither mechanism includes health data, your name, your email address, or an advertising identifier, and neither can be traced back to you. The App does not ask permission to track you, does not use the iOS Advertising Identifier (IDFA), and does not use device fingerprinting.
  • The Site may use advertising cookies for retargeting, as described in Section 9, with the opt-out rights described there and in Section 11. Advertising cookies never receive health data or account data.
  • Our analytics and crash reports do not include health values: no weights, doses, scan results, or injection sites. The only note that can ever accompany a report is the optional post-crash note described in Section 2, which is filtered on your device before transmission.
  • We do not use data read from platform health services (Apple Health or Health Connect) for advertising, marketing, data mining, or the training of artificial-intelligence or machine-learning models, and we do not disclose it to third parties.
  • The App reads from platform health services; it does not write to them. If a writing feature is added, your device's operating system will request your permission separately, and this Policy will be updated before the feature ships.
  • We do not attach your name or email address to analytics, crash reports, or purchase records; each operates on opaque or anonymous identifiers.

4. Where your information is stored

On your device. By default, everything you enter in the App — shots, schedules, daily logs, goals, intake answers, and imported DEXA results — is stored on your device with the strongest file protection the platform provides — encrypted whenever the device is locked — and is excluded from device backups by design. Your health entries therefore do not travel into your iCloud or Google backup, and a backup restore will not bring them back; to keep your own copy, use Settings → Manage My Data → Prepare my export (iOS) or Export my data (Android). On iOS, app preferences that are not health information (your display name, unit choices, screen layout) are included in your iCloud backup, which is encrypted and associated with your Apple ID; Bild Health cannot read your backups. On Android, the App opts out of device backup entirely, so neither your health entries nor your preferences are included in a Google backup. BodySpec sign-in tokens are stored in the platform's secure credential store (iOS Keychain; Android Keystore), marked non-transferable so they do not move to another device. Without cross-device sync enabled, the App does not synchronize your data between devices: a fresh installation on a second device starts empty.

Cross-device sync (optional; explicit consent required). The Services may offer synchronization of your data across your signed-in devices and the Site. Sync is off unless you turn it on, and we will ask for your explicit consent first, on a dedicated screen that identifies the categories to be synced — such as body measurements (weight, body fat percentage, lean mass, fat mass), medication and protocol logs, goals, and imported DEXA results. That consent is never bundled into acceptance of these documents and is not a condition of using the Services; declining leaves every other feature available. If measurements read from Apple Health or Health Connect are to be included, that inclusion is requested expressly, and such data remains subject to the restrictions in Section 3 — it is never used for advertising, marketing, data mining, or model training, and we do not store Apple Health data in iCloud. When sync is enabled, the categories you approved are stored on our servers, encrypted and associated with your account, to make your data available to you across devices. We may also derive de-identified and aggregated data from synced data and use it as described in Section 6 — including to develop, train, and improve our current and future artificial-intelligence and machine-learning models; identifiable synced data is never used for training without the separate consent described in Section 6. You may withdraw consent at any time by disabling sync, which deletes the server copy of your identifiable data; your on-device data is unaffected.

On our servers. Our servers store: your account record (the name you registered, if any; email address; hashed credentials; opaque identifier); session records, including the IP address and browser type of each sign-in; subscription and entitlement state; payment records for purchases made on the Site (excluding card numbers), together with the raw event notifications our payment and subscription providers send us about purchases; transactional email logs; the waitlist entries described above; feedback messages you send us; the advertising-attribution records described in Sections 2 and 3; operational security records (rate-limiting entries, which include IP addresses, and an administrative audit log); and — only if you have enabled cross-device sync — the synced categories described above. Our servers store no other health data, though a feedback message contains whatever you chose to type into it. If our server-side practices change beyond this, we will update this Policy and provide notice in the App before any additional health data leaves your device.

5. How we use information

We use information to: compute your targets (protein, hydration) from your intake; chart weight, body fat, and lean mass; estimate medication levels from the doses you have logged and, if you told us at signup that you were already taking your medication, from the start date and schedule you provided (see the Methodology page); schedule and track shots; provide cross-device synchronization where you have enabled it; create and administer your account; process and manage your subscription; send transactional email related to your account or purchase; maintain the security and stability of the Services; and understand product usage in aggregate.

We also use information to improve the Services, including testing, research, internal analytics, and product development and improvement — including, without limitation, the development and improvement of Bild Health's current and future artificial-intelligence and machine-learning algorithms and models. For this purpose we use account information, usage and diagnostic data, and de-identified or aggregated data; identifiable consumer health data is used for model training only with the separate opt-in consent described in Section 6. The purposes for which consumer health data is collected are enumerated in the Consumer Health Data Privacy Policy.

6. Artificial intelligence and model training

Bild Health does not currently use your data to train any artificial-intelligence or machine-learning model. The following governs any such use:

  • De-identified and aggregated data. We may use de-identified and aggregated data — data that can no longer reasonably be linked to you — to develop, train, and improve Bild Health's current and future artificial-intelligence and machine-learning algorithms and models, and to improve the Services, without separate consent. We maintain de-identified data without attempting to re-identify it, and we contractually prohibit any recipient from attempting re-identification.
  • Identifiable data requires separate consent. Because your entries constitute consumer health data, any use of identifiable data for model training would require your consent through a dedicated opt-in screen in the App — never bundled into acceptance of the Terms of Use or this Policy, and never a condition of using the Services. Declining would not affect the Services available to you, and consent could be withdrawn at any time in Settings → Manage My Data.
  • Excluded regardless of consent. Data read from platform health services (Apple Health or Health Connect) is not used for model training under any circumstances, whether identifiable or de-identified.
  • Third-party AI providers. If a future feature transmitted your identifiable data to a third-party artificial-intelligence provider, we would disclose what is transmitted and to whom and obtain your separate, explicit permission first. We do not provide identifiable health data to any third party for that party's own model training.

This Policy will be updated, with notice in the App, before any training use of identifiable data begins.

7. Analytics and diagnostics

We use a product-analytics service to understand which features are used. Events are named for the action taken and carry no health values; screens are reported by generic name. Analytics operate on an anonymous, device-scoped identifier that is not linked to your account, name, or email address.

We use a crash- and error-reporting service to measure stability. Reports contain technical diagnostic information — including a small sample of app-performance measurements — and are filtered on your device to remove identifying information and health values before transmission. On iOS, the only identifier attached is the same anonymous analytics identifier; on Android, the crash service uses its own separate anonymous identifier. Session replay and screen recording are not used.

8. Disclosure of information

  • Apple and Google (App Store and Google Play, platform health services, device backup) — purchase billing, on-device health reads, and your device backup, each governed by your agreements with the platform and your device settings.
  • Subscription-management provider — receives anonymous purchase and subscription state, keyed to an opaque identifier; receives no name, email address, or health data.
  • Payment processor (Site purchases) — collects and processes payment card details; we receive confirmation and subscription records, not card numbers.
  • Product-analytics provider — receives the anonymous usage events described in Section 7; receives no health values and no identity.
  • Crash- and error-reporting provider — receives the filtered diagnostic reports described in Section 7.
  • Email-delivery provider — transmits transactional email to the address on your account or waitlist entry.
  • Cloud-hosting and database providers — host the Site and the server records described in Section 4, including synced data where you have enabled cross-device sync; they act as processors under our documented instructions and are contractually bound to the standards of this Policy.
  • Advertising services (Site only) — if advertising cookies are active and you have not opted out, receive Site browsing data for the retargeting described in Section 9; they receive no health data, no account information, and nothing from the App.
  • BodySpec — a service you connect at your direction; your DEXA data flows from BodySpec to your device via their interface. We do not send your data to BodySpec.
  • Legal requirements and safety — we may disclose information where required by law, legal process, or to protect the rights, safety, or property of users, the public, or Bild Health, in each case subject to the consent requirements of applicable consumer-health-data law.
  • Corporate transactions — if Bildbot Inc. is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; consumer health data would be transferred only subject to the commitments of this Policy and any consent required by applicable law.

Each service provider is bound by contract to protect your information at a standard at least as protective as this Policy. Specific affiliates with whom consumer health data is shared are listed in the Consumer Health Data Privacy Policy (currently: none). Affiliate product links (for example, smart scales) are outbound links only; the retailer receives no information about you from us, and any commission we may earn is disclosed at the link.

9. Cookies and Site technologies

The Site uses cookies and similar technologies, operated through web-analytics and tag-management services, to measure Site traffic and usage. The Site may also use advertising cookies and pixels to support retargeting — showing advertisements for Bild Health to Site visitors on other websites and platforms. Advertising cookies observe Site browsing only; they receive no health data, no account information, and nothing from the App.

Advertising cookies are not used for visitors in Washington, Nevada, or Connecticut, based on approximate location, in keeping with those states' consumer-health-data laws. Elsewhere, you may opt out of advertising cookies through your browser's cookie controls, the industry opt-out tools at aboutads.info, or by emailing privacy@bildhealth.com. You can additionally control all cookies through your browser settings; the Site remains usable with cookies disabled. Signed-in areas of the Site use strictly necessary session cookies to keep you signed in, which are not subject to opt-out because the signed-in Site does not function without them.

10. Your rights and choices

  • Access — your health data is displayed in the App. Your account email is shown in Settings.
  • ExportSettings → Manage My Data → Prepare my export (iOS) or Export my data (Android) produces a single file containing everything the App stores on your device: intake answers, shots, schedules, daily logs, goals, DEXA scans, reminders, and settings. A formatted, readable PDF copy is also available on the same screen. BodySpec sign-in tokens are excluded because they are credentials rather than information about you.
  • Correct — edit entries on the screen where they were made.
  • Delete on-device data — individual entries in place, or Settings → Manage My Data → Delete all my data, which erases everything the App stores on the device, including your BodySpec sign-in.
  • Disable sync — if you have enabled cross-device sync, disabling it (Settings → Manage My Data) deletes the synced copy from our servers; your on-device data is unaffected.
  • Delete your account — if you have created one: on the Site, in your account page, or on iOS in Settings → Manage My Data. Deletion removes your account record, sessions, entitlement state, and any synced data from our servers. (The Android App currently has no accounts, so Android-only use leaves no account on our servers to delete.) Our payment processor retains its own records of completed payments as required for tax, accounting, and audit purposes.
  • Withdraw permissions — disconnect BodySpec in Settings → DEXA Scans; revoke health-data access in your platform's health settings (the App links there from Settings).

Two items are managed by your platform rather than by us: your platform health permission (revocable as described above) and an app-marketplace subscription (cancellable in your App Store or Google Play subscription settings). Subscriptions purchased on the Site are managed through the billing portal in your account.

For any other request: privacy@bildhealth.com. We respond within 30 days, and you may appeal an outcome by replying "appeal."

11. United States state privacy rights

Consumer health data (Washington, Nevada, Connecticut). Residents of these states have rights under consumer-health-data statutes, including the rights to access, delete, and withdraw consent, and to appeal. These are set out in the standalone Consumer Health Data Privacy Policy, linked below.

Comprehensive state privacy laws (California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comparable statutes). Where these laws apply, residents have rights to know, access, correct, delete, and obtain a portable copy of personal data, and to opt out of sales, sharing for targeted advertising, and certain profiling. We do not sell personal data for money and do not engage in profiling that produces legal or similarly significant effects. The Site's use of advertising cookies for retargeting may constitute "sharing" or "targeted advertising" under these laws: you may opt out through the browser and industry controls described in Section 9 or by contacting privacy@bildhealth.com, each of which we honor as required by law. California residents: the categories of personal information we collect and disclose are as described in Sections 2 and 8; the only "sharing" as defined by the CCPA is the Site advertising activity described in Section 9, which involves Site browsing data only; we do not use or disclose sensitive personal information for purposes requiring a right to limit — sensitive information never reaches advertising services.

We do not discriminate against any user for exercising a privacy right. Exercise any right through the in-App controls above or at privacy@bildhealth.com; if we decline a request, you may appeal by replying "appeal," and unresolved appeals may be raised with your state Attorney General.

12. Security and retention

On-device data is protected by device encryption; your health entries additionally use the strongest file protection the platform provides and are excluded from device backups; BodySpec tokens reside in the platform's secure credential store and are marked non-transferable. Server records are encrypted in transit and at rest and are limited to the categories described in Section 4. Retention of health data follows your choices: on-device health data remains on your device until you delete it, and is not carried into your device backup, and synced data remains on our servers until you disable sync or delete your account, whichever comes first. Account records are retained until you delete your account; our payment processor retains its own transaction records thereafter as required by law. Anonymous analytics are retained for 12 months. In the event of an unauthorized disclosure of identifiable health information, we will provide the notifications required by the FTC Health Breach Notification Rule.

13. Children

The Services are for adults 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor is using the Services, contact us and we will delete the information.

14. Changes to this Policy

We may modify this Policy at any time, without prior notice to you. The effective date at the top of this page is the date of the most recent version and changes whenever the Policy does; the current version is always available at this location. Modifications operate prospectively from the date of posting. Notwithstanding the foregoing, if a modification would materially expand the collection or sharing of consumer health data, we will obtain any consent that applicable law requires before the new practice begins.

Contact

Bildbot Inc. · privacy@bildhealth.com