Privacy Note

Welcome to BShape's Privacy Policy! We appreciate your trust and are committed to protecting and respecting your privacy. This policy sets out the foundation on which any personal data we collect from you, or that you provide to us, will be processed.

Please read this privacy note carefully before using the BShape mobile application or web portal (the "Service") operated by BShape ("us", "we", or "our").

Last Updated: Sunday 27 August 2023

Types of Information Collected

In the process of offering you a state-of-the-art, personalized AI coaching experience with BShape, it is pivotal for us to understand and process certain data points. Below is a detailed explanation of the nature and categories of data we may collect during your journey with us:

Personal Information: When you initiate your relationship with BShape, you furnish us with basic identification markers like your name, email address, and potentially, a profile picture or gender, if you opt to provide them. This information is vital to create and maintain your unique account, enabling us to tailor our services to suit your preferences.

User-Generated Content: As you navigate through our platform, you are given opportunities to input various data, which play a fundamental role in refining our recommendations and feedback. This encompasses your daily food intake records, fitness milestones, health objectives, dietary preferences and restrictions, feedback on our AI's advice, and any wellness or health concerns or questions you might discuss with our AI coach.

Health Kit Integration: With our integration of HealthKit, we can access specific health metrics you've permitted us to view, such as calorie intake, sleep patterns, and step counts. By doing so, we aim to offer a more comprehensive analysis and feedback mechanism, intertwining your manual inputs with passive health tracking, ensuring you receive an overarching health overview.

Interactivity Data: We take note of the patterns, frequency, and nature of your interactions with our AI models. This includes the queries you pose, the responses you find most beneficial, and the areas where you seek more insight. This assists us in continuously refining our AI's capabilities and understanding to better serve your needs.

Technical Metrics: In the backdrop, without any active input from your side, we might also collect certain technical data. This encapsulates the device type you access our services from, its operating system, the specific browser you're using, IP address, and the general geographical area from which you're accessing our platform. These metrics aid us in optimizing our service's performance and addressing any device-specific issues.

Financial Safeguards: While we integrate Stripe to manage subscription-related transactions, it's imperative to clarify that we do not hold onto or process your direct payment information, such as your credit card or bank account details. Our system might remember the transaction ID or subscription type for service continuity and support, but the actual financial data remains securely within Stripe's infrastructure.

It's of paramount importance to emphasize that the cornerstone of BShape's data collection is to enrich the user experience, ensuring our AI coach meets your wellness and fitness aspirations effectively. We do not harbor intentions of monetizing your data for advertising, nor do we entertain third-party data sale endeavors. Your trust is sacred, and our practices are continually aligned to honor this faith you place in us.

Utilization of Collected Information

At BShape, we view the data collection process as a pivotal component in our quest to forge a symbiotic relationship with our users, meticulously designed to serve you better with each interaction. The breadth and depth of information gathered underpin several facets of our service architecture:

Personalization Paradigm: One of the hallmarks of our platform is the capability to deliver a bespoke coaching experience. The nuanced data we garner about your health goals, dietary preferences, and interactions with the AI coach fuels our algorithmic strategies. This ensures that the advice, feedback, and guidance you receive resonate with your unique health journey, fostering an environment of meaningful and productive engagement.

Innovative Iterations: BShape is not static. It's a dynamic entity that thrives on evolution. Your interaction data, ranging from the questions posed to our AI models to the settings you configure, offers us invaluable insights into user expectations and areas of potential enhancement. Such insights drive our research and development initiatives, enabling us to introduce innovative features, refine existing ones, and ensure our platform remains at the forefront of digital health coaching.

Communicative Clarity: Beyond the immediate scope of coaching, we understand the significance of keeping our user base informed. By leveraging the contact details you provide, we can seamlessly update you about pivotal developments within BShape. Whether it's the introduction of a new feature, critical security advisories, or general updates about our platform's trajectory, our objective is to ensure you remain in the know, forging a transparent channel of communication.

Security and Integrity: In today's digital landscape, the sanctity and security of user data cannot be overstated. Beyond merely storing your data securely, we proactively utilize it to engineer a robust defense mechanism. Recognizing patterns, verifying user identities, anticipating unauthorized access attempts, and preempting potential breaches are just a few measures in our extensive arsenal designed to ensure your digital well-being while interacting with BShape.

Operational Excellence: The myriad technical metrics we gather, while often unnoticeable to the user, play an instrumental role in achieving operational excellence. By discerning the devices, browsers, and systems our users prefer, we can optimize our platform to deliver a consistently smooth and intuitive experience across all touchpoints. Furthermore, such data helps us swiftly identify, diagnose, and rectify any potential technical glitches, ensuring minimal service disruption.

Every shred of data we collate serves a definitive purpose, meticulously aligned with our commitment to offer you a premier, secure, and progressive health coaching experience. As custodians of your data, our mission transcends mere storage; it's about wielding this data responsibly to amplify your journey towards optimal health and well-being.

Protection Measures for your Data

Encryption Excellence: Foremost in our arsenal of protective measures is state-of-the-art encryption. All delicate user data, encompassing preferences, dietary specifics, health metrics from HealthKit such as calories and sleep patterns, and personalized goals, are subjected to robust encryption protocols. This high-grade encryption ensures that even in the hypothetical event of a data breach, the acquired data remains unintelligible and indecipherable, thereby protecting its inherent confidentiality.

State-of-the-Art Cloud Security: Utilizing Firebase services like Auth, Firestore, and Cloud Functions, BShape leverages Google's advanced security infrastructure. Firebase offers a multi-layered security environment that ensures data integrity and protection against unauthorized access. These services come with built-in security features that adapt and evolve in response to new threats, ensuring that your data remains protected at all times.

Regularized Reviews: Data security is an evolving discipline. As such, our technical team conducts regular audits and reviews of our security infrastructure. These periodic assessments allow us to identify potential vulnerabilities, fortify existing defenses, and integrate the latest in security technology, ensuring our protective measures remain contemporary and robust.

Strict Access Protocols: We operate on a principle of least privilege. This means that only a select few within our organization, those whose roles necessitate it, are granted access to sensitive user data.

BShape's commitment to data protection is holistic, encompassing both cutting-edge technology and organizational best practices. We view your trust not just as a gift but as a responsibility—one that we are deeply committed to upholding through rigorous, relentless, and responsive data protection measures.In the intricate and interconnected landscape of digital health, data protection isn't just a regulatory mandate; it's a moral imperative. BShape is acutely aware of the profundity and sensitivity of the information you entrust us with. Recognizing this, we have implemented a multifaceted data protection framework meticulously designed to ensure the sanctity, security, and confidentiality of your data:

Disclosure Paradigms

At BShape, we don't just collect data; we cherish the responsibility that accompanies its guardianship. It is a testament to our unwavering commitment to data privacy that we have crafted stringent protocols around data sharing and disclosure. While the essence of our service revolves around trust, it's paramount for us to outline scenarios where data might be unveiled, albeit reluctantly.

First and foremost, the sanctity of your data is non-negotiable. We never entertain thoughts of trading, renting, or selling your cherished information to third-party entities for commercial gains. Instead, our philosophy is founded upon a doctrine of minimal exposure, revealing data only when absolutely necessary.

However, in the vast, interconnected web of legal and regulatory frameworks, there could arise specific instances where we might be legally obligated to disclose some data. Such situations could stem from legal proceedings, court orders, or other binding governmental mandates. But even in such instances, we adhere to a principle of proportionality, disclosing only the absolute minimum required.

Additionally, on rare occasions, should a scenario arise where sharing some information could potentially enhance the services we offer or present a beneficial opportunity for our users, such disclosures would only materialize with your explicit, informed, and unambiguous consent.

While the digital world might be rife with ambiguities, our stance on data disclosure is clear-cut, rooted in respect, responsibility, and unwavering dedication to your privacy.

Strategic Collaboration with Third-Party Services

In the pursuit of redefining service standards, BShape strategically collaborates with select third-party service providers. These partnerships are meticulously chosen to amplify specific functionalities of our platform, reinforcing our commitment to delivering a user-centric and secure experience.

Stripe: At the forefront of our financial transactions is Stripe, a universally recognized payment gateway. Entrusted with managing the intricate processes of our subscription payments, Stripe is integrated solely for its payment handling prowess. Their stringent security protocols ensure that every transaction on BShape is not only seamless but also fortified against security vulnerabilities.

Firebase: Strengthening the structural framework of BShape is Firebase, a distinguished cloud-based suite offering multiple tools for modern digital platforms. We specifically employ Firebase for its reliable user authentication mechanisms and agile data storage solutions. This ensures that users enjoy a frictionless experience while knowing their data is managed securely.

OpenAI: Venturing into the realms of artificial intelligence, we've integrated OpenAI's gpt-3.5-turbo and gpt-4 models into BShape. These advanced models underpin our AI coaching system, facilitating personalized interactions. We collaborate with OpenAI to ensure users benefit from intelligent responses without compromising on data security.

It's essential to emphasize that our association with these third-party services is strictly functional. We share only pertinent information required for the operational aspects of these services, always prioritizing user data protection and minimizing data footprints. As you engage with BShape, it's also essential to recognize that these service providers operate within their specific terms and privacy policies. While we endeavor to align with partners that share our dedication to user privacy, we advocate for users to acquaint themselves with the terms governing these third-party integrations.

BShape's mission is intricately woven with trust, transparency, and technological excellence. Our strategic alliances, with the likes of Stripe, Firebase, and OpenAI, reflect this commitment. We cherish the trust you bestow upon us and continually strive to uphold this bond, ensuring that our collaborations always resonate with our core values and your expectations.

Your Data Rights and Empowerment

At BShape, we fundamentally believe that you, as our user, are at the heart of everything we do, and this principle extends robustly to your data rights. Recognizing the pivotal role that data plays in today's digital age, we're committed to ensuring you have comprehensive control and clarity over the data you share with us.

Access and Review: You have the unequivocal right to request and review any personal information that we may have stored about you. This ensures you have a transparent view of the data that serves as the foundation for our interactions.

Correction of Inaccuracies: Human and technical errors are a reality of the digital world. If you identify any inaccuracies or inconsistencies in your data, you are entitled to seek timely rectifications, ensuring that our interactions remain grounded in accurate and updated information.

Data Erasure: The choice to be forgotten is yours. Should you decide to sever ties, you can request the deletion of your personal data from our systems. While we respect this choice wholeheartedly, it's essential to understand that certain legal or operational constraints might mandate the retention of specific data fragments. In such instances, we will ensure the maximum possible data erasure within the confines of these constraints.

Express Concerns and Objections: Open dialogue lies at the core of our relationship. If you harbor any reservations or concerns about our data handling practices, we earnestly urge you to communicate these feelings. Your feedback is instrumental, not just in resolving individual concerns, but also in refining our broader data management paradigms.

Opt-Out and Preferences: Beyond the rights mentioned above, you also possess the autonomy to define how we engage with you. Be it communication preferences, data sharing boundaries, or other specific nuances, our systems are designed to respect and reflect your choices.

Institutionalizing these rights is our way of upholding the trust you repose in BShape. We see these not merely as regulatory checkboxes but as cornerstones of an ethically sound and user-centric digital engagement model. As always, our teams remain at your disposal, ready to facilitate, clarify, and enact your data rights at every juncture of our journey together.

Data Retention Protocols

Navigating the intricate landscapes of the digital world, BShape ardently believes in the principle of minimalism when it comes to data storage. We understand the paramount importance of data, both to us and more critically, to you, our user. It's with this consciousness that we have architected our data retention policies, always putting your security and privacy at the forefront.

Purpose-Driven Retention: At the core of our retention philosophy is purpose. Personal information that you entrust to us is retained only as long as it serves an active role in enhancing, delivering, and maintaining the services you've chosen. This ensures that your data isn't left dormant or unnecessarily stored without serving any tangible objective.

Legal and Regulatory Adherence: While we strive for minimalism, there are times when specific pieces of data might need to be stored longer. Such decisions often stem from regulatory obligations, legal disputes, or compliance requirements. In these instances, we assure you that the continued retention is done with the utmost care, safeguarded against unauthorized access and potential threats.

Business-Centric Considerations: There may be instances where data aids our understanding of user preferences, system improvements, or facilitates historical analytics. In such scenarios, while data might be retained, it's often anonymized or aggregated to ensure individual privacy remains uncompromised.

User-Initiated Deletion Requests: Recognizing the evolving nature of user preferences, we also honor data deletion requests from users, unless specific constraints prevent us from doing so. In such cases, we transparently communicate the reasons and durations for which the data might remain in our systems.

Data Archiving and Backup: To ensure service continuity and mitigate potential data loss scenarios, certain data may be archived or backed up. However, such measures are taken with reinforced security layers, and access to these backups is stringently controlled.

BShape's holistic approach to data retention is a reflection of our dedication to upholding the twin pillars of transparency and accountability. We want you to have complete peace of mind, knowing that your data, while immensely valuable, is always treated with the reverence and responsibility it deserves.

Amendments to Privacy Stipulations

As we navigate the ever-evolving tapestry of the digital domain, it's imperative for us at BShape to remain agile and adaptive, ensuring our practices align with both the changing technological environment and shifting regulatory landscapes. This very dynamism, combined with our commitment to safeguarding your trust, sometimes necessitates recalibrations in our privacy protocols.

Adaptability and Responsiveness: The heart of our approach to privacy is a commitment to adaptation. With the burgeoning advancements in technology, digital frameworks, and user expectations, we recognize the need to continuously monitor, assess, and update our policies. This ensures that our strategies remain both relevant and robust in safeguarding your personal data.

Notification and Transparency: While the digital space's nature might call for periodic policy adjustments, our dedication to transparency remains unwavering. Should any amendments be made to our Privacy Policy, not only will the revised version find its place on this page, but we also commit to proactively reaching out and notifying our user base. We believe in making sure that our community remains informed, empowered, and confident in the decisions they make.

Engagement and Feedback Loop: Recognizing the invaluable insights our users can provide, any significant policy change will be accompanied by a period where user feedback is actively solicited. This ensures that our community's voice is not only heard but also integrated into the heart of our policy-making process.

Historical Reference and Archiving: For those interested in tracking the evolution of our privacy stance, we intend to maintain an archive of previous policy versions. This library will provide a historical perspective, showcasing our commitment to continuous improvement and adherence to best practices.

Periodic Reviews and Self-Audits: Beyond reacting to external changes, our team conducts routine internal reviews of our privacy provisions. This introspective approach allows us to preemptively identify areas of potential improvement and reinforces our proactive stance on user data protection.

At BShape, our goal is not merely to adapt to the digital world's changing dynamics but to be trailblazers in establishing a gold standard for user privacy and data protection. By regularly revisiting this page and engaging with our communications, you ensure that you remain abreast of our unwavering dedication to your privacy's sanctity.

Engaging with BShape

For clarifications, concerns, or feedback regarding this Privacy Policy or any other aspect of our service, please reach out to us at: hello@bshape.ai