Privacy Policy
Privacy policy for the BodyWision app and website.
- 1. Controller The controller responsible for processing personal data is BodyWision GmbH, Vienna, Austria, Email: office@bodywision.com. Further company information is available in the Legal Notice.
- 2. Scope of this privacy policy This privacy policy explains how BodyWision processes personal data in connection with the BodyWision app, the website, Early Access communication, support, and related technical services. BodyWision is an Early Access app for securely storing, organizing, analyzing, interpreting, and explaining personal health records in an understandable way. Health data is particularly sensitive. We process health data only where this is necessary for the functions selected by users and where users have given their explicit consent. This consent can be withdrawn at any time with effect for the future. Without this consent, core health-related functions may not be available or may be available only in a limited form.
- 3. Data we process Depending on how BodyWision is used, we may process in particular: account and login data, such as email address, account ID, and technical identifiers; profile information, settings, and consent records; uploaded medical documents, medical reports, physician letters, lab results, and similar records; content identified, recognized, extracted, or structured from those records; health information entered by users; diagnoses where they appear in uploaded records or are entered by users; medications, allergies, symptoms, previous operations or procedures, nutrition information, and other information provided by users; text inputs and chat content; AI-generated summaries, explanations, analyses, structured outputs, topic priorities, indicators, and AI responses; Health Summaries, nutrition analyses, and structured evaluations during setup; notes, questions, and preparation materials for medical appointments; technical logs, security events, and product-related usage data; website, contact, Early Access, and newsletter data. Apple Health / HealthKit data is processed only if users have separately granted BodyWision access to Apple Health. Consent to AI data processing does not replace the separate Apple Health permission.
- 4. Purposes and legal bases We process personal data in particular to provide, operate, and secure the app; manage the internal BodyWision account; store, structure, and display personal health records; provide AI functions requested by users; manage consents, support requests, exports, and deletion requests; improve app stability, security, and usability; operate the website and process contact, Early Access, and newsletter requests; and perform optional website analytics and campaign measurement only after consent. Depending on the processing activity, the legal bases are in particular Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures), Art. 6(1)(f) GDPR (legitimate interests in operation, security, and improvement), Art. 6(1)(c) GDPR (legal obligations), and Art. 6(1)(a) GDPR (consent). Health data is processed on the basis of explicit consent pursuant to Art. 9(2)(a) GDPR.
- 5. Storage of the personal health record The personal health record is stored encrypted on the user device. Where users use cloud sync or backup functions, the data is transmitted and stored with end-to-end encryption. The required keys are protected by the user-side key management. BodyWision has no access to the encrypted personal health record and cannot view these stored health records in plain text. App-related infrastructure, cloud sync, backup functions, and stored health data are operated or stored in data centers within the EU or EEA. Cloud sync and backup data also remain encrypted in technical backups. Deleted data may remain in encrypted backups for technical reasons for up to three months and is then deleted or overwritten as part of the usual backup cycles. Where users use AI functions, the content required for the respective AI request may be processed in plain text for that specific request as described in section 6.
- 6. AI functions BodyWision uses an external AI service provided by Microsoft Azure for certain AI features, in particular Microsoft Azure AI Foundry and/or the Microsoft Azure OpenAI Service. The service runs in a Microsoft Azure environment used by BodyWision. Content is not sent by BodyWision directly to OpenAI, but is processed exclusively through the Microsoft Azure service used by BodyWision. AI features may be used, for example, in the Health Coach, in the analysis of health documents, in Health Summaries, in nutrition analyses, or in structured evaluations during setup. AI processing only takes place after users have consented to AI data processing. AI features are used where users use an AI-supported feature or where an AI-assisted evaluation is required during setup. Without consent to AI data processing, BodyWision cannot be set up and cannot be used meaningfully. When users use an AI feature, or when BodyWision needs an AI-assisted evaluation during setup, the required content may be transmitted through the BodyWision backend to Microsoft Azure and processed there. This may include in particular text input, chat content, uploaded document content, information identified or structured from those documents, health information, nutrition information, diagnoses, medications, allergies, symptoms, previous operations or procedures, or other information users provide. For an AI request, only the part of the data that is required for the specific request or feature is processed. The entire health record of a user is not transferred to the AI infrastructure unless this is required for the specific feature. The transmission takes place solely to process the respective request, structure, summarize, or explain content, or provide an AI-assisted response in the app. The required content is processed in plain text for the specific AI operation. The AI response is then returned to the app. BodyWision does not permanently store prompts, AI responses, or the transmitted content in the BodyWision backend, does not log them for analysis or training purposes, and does not use them for tracking or general product analytics. The content is forwarded directly for processing. Where an AI response is stored in the app, it is stored again in encrypted form as part of the user-protected health record. Microsoft processes this data as a technical service provider under the applicable Microsoft Azure privacy and security terms. According to Microsoft, customer data from Azure OpenAI and Azure AI Foundry is not used to improve or train the underlying AI models unless explicit permission or instruction has been given. Apple Health / HealthKit data can only be included if users have separately allowed BodyWision to access Apple Health. Consent to AI data processing does not replace this Apple Health permission. Please enter only information in AI features that users actually want to use for the specific request. AI-supported content is intended to support understanding, personal health documentation, and preparation for medical appointments. BodyWision does not make automated decisions that have legal effects or similarly significant effects. AI outputs do not replace medical advice, diagnosis, or treatment by physicians or other qualified healthcare professionals and must not be understood as a basis for medical decision-making.
- 7. Family profiles and data of other persons Users may create profiles for other persons, such as children or relatives. Health data of other persons may be uploaded or managed only if users are authorized to do so, in particular on the basis of consent, parental responsibility, legal representation, or comparable legal authority. Users are responsible for informing affected persons about the use of BodyWision and this privacy policy where required. Minors may not create their own account and may not use BodyWision themselves.
- 8. App usage data We do not use external tracking tools in the app for advertising or marketing purposes. To provide, secure, stabilize, and further develop the app, technical and product-related usage data may be processed, such as technical events, function calls, status information, or app-internal workflows. Any evaluations are performed with data minimization in mind and, where possible, in aggregated form. Medical content is not used for advertising, marketing tracking, or general product analytics. It is processed only where necessary for requested app and AI functions, security, or legally required processes.
- 9. Website, cookies, and tracking When visiting the website, technical data required for operation, security, and display may be processed, such as IP address, browser and device data, pages accessed, and time of access. The website uses technically necessary storage technologies, in particular to provide the website and store privacy settings. Optional analytics and marketing technologies are loaded only if users have consented via the cookie banner or privacy settings. Without consent, no optional tracking or marketing technologies are activated. Consent can be withdrawn or changed at any time via the privacy settings. Website tracking is separate from the app. Health data, medical documents, app content, prompts, and AI outputs are not transferred to Google, Meta, or other marketing services for advertising or tracking purposes.
- 10. Early Access and newsletter If users sign up for Early Access, product information, or newsletters, we process the contact details provided to handle the registration and send corresponding information. We use Brevo as a service provider for this purpose. Processing is based on consent or pre-contractual communication. Users can unsubscribe at any time.
- 11. Support and contact If users contact BodyWision, we process the data submitted to handle the request. Support may be provided by email and, where offered, via WhatsApp Business. These channels are intended for technical and organizational questions. Users should not send medical documents, findings, or sensitive health information via email, WhatsApp, or comparable support channels unless BodyWision expressly provides a secure channel intended for this purpose. When using WhatsApp Business, WhatsApp or Meta may process personal data of their own, in particular communication metadata. The privacy information of WhatsApp or Meta also applies to such processing.
- 12. Service providers and recipients We use service providers where this is necessary for operation, security, provision, support, communication, AI functions, app stores, newsletters, or website functions. This may include service providers in the areas of hosting and infrastructure, cloud sync and backup, AI processing, email, support and communication, Early Access and newsletters, app stores, website delivery, security, and optional campaign measurement. For AI functions, we use Microsoft Azure AI Foundry and/or the Microsoft Azure OpenAI Service as a technical service provider. Where required, we enter into data processing agreements with processors.
- 13. App stores The app is downloaded via the Apple App Store or Google Play Store. Apple and Google may process their own personal data in this context, such as account, device, download, usage, or payment information. The privacy policies of the respective app store provider apply to this processing. By downloading the app, Apple and Google do not receive access to the personal health record stored in BodyWision, uploaded medical documents, or health data inside the app.
- 14. International data transfers The app-related infrastructure for stored health data, cloud sync, backup, and AI processing is operated in EU/EEA regions. AI processing is carried out through the Microsoft Azure environment used by BodyWision in EU/EEA regions. BodyWision does not send content directly to OpenAI. For individual service providers outside the app, in particular in connection with app stores, website delivery, communication, security, WhatsApp Business, or optional tracking, processing outside the EU or EEA cannot be ruled out. This concerns in particular website, app store, communication, security, or tracking data, but not the end-to-end encrypted health record stored in the app in plain text. Where data is transferred to third countries, this is done on the basis of appropriate legal mechanisms, such as an adequacy decision, EU standard contractual clauses, additional safeguards, or explicit consent where required.
- 15. Retention, deletion, and export We store personal data only for as long as necessary for the respective purposes, the use of BodyWision, or legal requirements. Users can delete or export individual items and health data in the app where the respective function is available. Full deletion of the account and the data stored by BodyWision can be requested by email or support request. We process deletion requests and delete the affected data unless legal retention obligations or legitimate reasons for further storage prevent deletion. Deleted cloud sync or backup data may remain in encrypted backups for technical reasons for up to three months and is then deleted or overwritten. Withdrawal of consent to the processing of health data or deletion of core health data may mean that BodyWision can no longer be used or can be used only in a limited form. Consent to AI data processing can be withdrawn in Settings with effect for the future. Without consent to AI data processing, BodyWision cannot be set up and cannot be used meaningfully. If users withdraw this consent, BodyWision signs this device out and removes the local app data on this device. Data that has already been synchronized remains stored in the cloud. If Cloud Sync is disabled or unavailable, local data that has not been synchronized may be lost. The app then restarts, and users can set up BodyWision again and consent again. Account and data deletion information
- 16. Data security We implement technical and organizational measures to protect personal data, especially health data, appropriately. These include in particular encrypted data transmission, encrypted storage of the personal health record, end-to-end encrypted cloud sync and end-to-end encrypted backups, keys protected on the user side, no plain-text access by BodyWision to stored health records, operation of app-related infrastructure in EU/EEA regions, access restrictions, role and permission concepts, technical safeguards against unauthorized access, and operational security measures. Despite appropriate safeguards, no digital processing can be completely risk-free.
- 17. User rights In accordance with applicable data protection laws, users have in particular the rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. Consents, in particular to the processing of health data and to AI data processing, can be withdrawn with effect for the future. Consent to AI data processing can also be withdrawn in the app settings. Requests can be submitted via the contact function provided in the app or by email to office@bodywision.com. Users also have the right to lodge a complaint with a data protection supervisory authority. For BodyWision, the Austrian Data Protection Authority is generally responsible.
- 18. Changes to this privacy policy We may amend this privacy policy, in particular if the app, website, data processing, service providers, or legal requirements change. The current version is available in the app and/or on the website. We will provide appropriate notice of material changes.
Last updated: June 2026