Legal · v2026-05-19
Privacy Policy
Last updated: May 19, 2026
BFRST ("we", "us", "our") is operated by Gil Barda. This Privacy Policy explains how we collect, use, and protect your information when you use the BFRST mobile application and the BFRST web console (together, "the Service"). It applies to athletes, club staff, and any other users of the Service.
This policy is written to satisfy our duties under the EU GDPR, the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA), and the Israeli Privacy Protection Law 5741-1981. If you are reading this from another jurisdiction, the rights granted here are extended to you on a best-effort basis.
Effective date: May 19, 2026. Version: 2026-05-19.
Privacy contact: gilbardaw01@gmail.com
Data Protection Officer (DPO): Gil Barda — gilbardaw01@gmail.com
Quick summary
We process your data to give you AI coaching across mental, strength & conditioning, recovery, and nutrition modules.
We do not sell your personal data. We do not share it with advertisers.
AI providers receive your messages to generate replies, but they do not train on your data and do not retain it for their own purposes.
Sensitive health data (sleep, HRV, pain, mood, body measurements) is treated as a special category under GDPR Article 9 and is encrypted at rest.
You can delete your account and all linked data at any time from inside the app or by emailing us.
Mental coaching content is never shared with club staff. Club staff only see data inside their professional specialty (a dietitian sees nutrition, a physio sees recovery).
1. What we collect
We organise the data we collect into the following categories:
(a) Account information. Email, display name, optional phone, password hash, account creation date, locale, time zone, role (athlete / staff / admin / owner), club membership status.
(b) Profile and onboarding answers. Sport, position, competitive level, performance intent, age, sex (optional), height, weight, body fat (optional), goals, target events, training days per week, team practice duration, gym session duration, training types, dietary preferences, allergies, injury history, medication notes you choose to share.
(c) Coaching conversations. Text and voice messages exchanged with the AI coach (mental, strength, recovery, nutrition). Voice is transcribed to text in transit; the audio is not stored.
(d) Plans and logs. Generated training plans, nutrition plans, recovery routines, daily check-ins, workout feedback, RPE, pain logs, alcohol log entries, mood and stress check-ins, calendar events you create.
(e) Wearable / health-app data (only with your explicit consent). Heart rate, HRV, sleep stages, resting heart rate, training load, calories burned, steps, body composition. Sources include Apple Health, Google Health Connect, Whoop, Garmin, and any other connector you authorise. We pull only the metrics needed for the active coaches.
(f) Inferences and derived signals. Readiness scores, ACWR (acute:chronic workload ratio), fatigue scores, biomotor profile, hierarchy-of-priorities flags, periodization tags. These are produced from your inputs and improve recommendations.
(g) Usage data. Sessions per week, screens visited, feature interactions, push notification opens, crash reports, app version, OS version, device model, locale.
(h) Survey and research responses. If you opt in to research programs, your voluntary survey responses.
(i) Anonymous research data (opt-in). Anonymized versions of coaching conversations, with identifiers (name, email, phone, address) automatically stripped before storage. Cannot be linked back to you.
(j) Technical logs. IP address, device identifier, request timestamps, error traces. Used for security and debugging only; pruned within 30 days.
2. Why we process it (lawful bases under GDPR)
Performance of a contract (Art. 6(1)(b)): to deliver the coaching service you signed up for, generate plans, run conversations, sync your calendar.
Consent (Art. 6(1)(a)): wearable data, marketing emails, anonymous research data — toggled in Settings, revocable at any time.
Legitimate interest (Art. 6(1)(f)): app analytics for stability, fraud prevention, abuse moderation. Balanced against your rights; we use only minimum necessary signals.
Special-category health data (Art. 9(2)(a)): processed only with your explicit consent, given when you connect a wearable or share an injury / medication note.
Compliance with legal obligation (Art. 6(1)(c)): tax, accounting, response to lawful authority requests.
3. How we use your data
To run AI coaching conversations and to generate, adjust, and update your training, nutrition, recovery, and mental plans.
To compute readiness, fatigue, ACWR, and other inferences that personalise the next plan.
To sync events between your calendar, your training plan, and your nutrition plan (Sprint 25 cross-coach replan pipeline).
To send you push notifications and reminders you opted into.
To analyse aggregate, anonymised usage patterns and improve the product.
To run research on athletic performance — only with anonymous, opt-in data and never with mental coaching content.
To prevent abuse, secure the service, and enforce our Terms.
To communicate with you about your account and material changes to the Service.
4. AI processing and AI training
BFRST uses third-party large language model providers (currently OpenAI) to generate coaching responses. When you send a message or trigger a plan generation, the necessary context is forwarded to the provider, a response is generated, and the response is returned to you and stored in your account.
Operational inference spend is monitored for abuse prevention and cost visibility, but we do not apply a fixed per-athlete monetary daily quota by default. We may introduce optional quotas operationally later; if we do, we will update this policy.
We do not authorise our AI providers to use your data to train their models. Our API agreements explicitly opt out of training on customer content. The provider may retain prompts and completions for a short period (typically 30 days) for abuse monitoring on their side, after which they are deleted.
BFRST itself may use your data to personalise your experience (e.g., the athlete memory layer that recalls your prior conversations). We do not pool your data with other users to train a model that would be served to others. Anonymous research data (opt-in only) is the only data that may be used to develop new product features, with all identifiers removed.
AI inferences (readiness scores, biomotor classifications, hierarchy-of-priorities flags) are automated processing. These do not produce legal effects and are not used for solely automated decisions about you within the meaning of GDPR Article 22. You can always view the underlying inputs and override coach recommendations.
5. Sub-processors
We rely on the following sub-processors. Each is bound by data-processing agreements (DPAs) with confidentiality, security, and deletion obligations:
Supabase, Inc. (USA, EU, Singapore regions) — primary database, authentication, storage, edge functions.
OpenAI, OpenAI Ireland (USA / EU) — large language model inference for coaching conversations and plan generation. Training-on-customer-data is contractually disabled.
Apple Inc. (USA) — Apple Health integration (you authorise specific metrics on-device).
Google LLC (USA, EU) — Google Health Connect integration (you authorise specific metrics on-device).
Whoop, Inc. (USA) — heart rate, HRV, recovery, strain (only if you connect Whoop).
Oura Health Oy (Finland / EU) — sleep, readiness, HRV, activity data (only if you connect Oura).
Garmin Ltd. (USA / Switzerland) — activity, sleep, heart rate (only if you connect Garmin).
Strava, Inc. (USA) — activity and training metrics (only if you connect Strava).
Polar Electro Oy (Finland / EU) — activity and training metrics (only if you connect Polar).
Apple App Store & Google Play — app distribution; each storefront processes the account/device identifiers required for installs, updates, and billing (when applicable), under its own privacy terms.
Google Maps Platform (Google LLC) — map rendering where the mobile app exposes Google Maps SDK features (API credentials are gated per platform).
Expo / EAS (USA) — over-the-air updates and push notification delivery.
Sentry (Functional Software, Inc.) (USA/EU) — crash reporting and runtime error diagnostics with direct identifiers stripped.
Cross-border transfers from the EU/EEA / UK to the USA rely on the EU-US Data Privacy Framework where applicable, and on Standard Contractual Clauses where not. A current sub-processor list can be requested at any time from gilbardaw01@gmail.com.
6. Data sharing inside the Service
With club staff — only if you join a club. Sharing rules:
A club dietitian sees only your nutrition data.
A club physiotherapist or recovery coach sees only your recovery and pain data.
A strength & conditioning coach sees only your training data and biomotor profile.
Mental coaching conversations are never shared with club staff, regardless of staff role.
You can block specific fields per module from your privacy dashboard (Settings → Privacy & Data).
You can leave a club at any time; the club loses access immediately.
With other users — none. We do not run a social feed.
With third parties for marketing — never. We do not sell or rent personal data.
7. Storage, security, retention
Data is stored on Supabase (cloud infrastructure on AWS / GCP). Encryption in transit uses TLS 1.2+. Encryption at rest is provided by Supabase / underlying cloud provider (AES-256). Row-level security policies enforce per-user isolation at the database layer.
Retention defaults:
Account data and coaching content: retained while your account is active.
Audit logs (login, security events): up to 12 months.
Crash and error logs: up to 30 days.
AI provider transient logs (held by the provider): up to 30 days, then deleted by the provider.
Anonymous research data: indefinitely (cannot be linked back to you).
After account deletion: personal data is removed within 30 days. Backups are purged on the next backup cycle (max 90 days).
8. Your rights
You have the following rights, regardless of where you live:
Access — view your data inside the app, or request a structured export.
Rectification — correct inaccurate data via the profile screen or by contacting us.
Erasure ("right to be forgotten") — delete your account from inside the app or by emailing gilbardaw01@gmail.com. Personal data is removed within 30 days.
Portability — request a machine-readable export (JSON) of your data; delivered within 30 days.
Restriction of processing — pause certain processing while a dispute is resolved.
Objection — object to processing based on legitimate interest; we will stop unless we show compelling grounds.
Withdraw consent — toggle off wearable connections, anonymous research, or marketing emails at any time.
Complaint — lodge a complaint with your local data protection authority (e.g., the Irish DPC for EU users, the ICO for UK users, the PPA for Israeli users, your state Attorney General for US users).
California residents (CCPA / CPRA): You have the right to know what personal information we collect, request its deletion, and opt out of "sales" or "shares" of personal information. We do not sell or share your personal information for cross-context behavioural advertising. You may exercise these rights without discrimination.
We respond to verifiable rights requests within 30 days (extendable by 60 days for complex requests, with notice).
9. Children and minors
BFRST allows account creation for users aged 13 and older. Users under 13 are blocked from registration. Users aged 13-15 require verifiable parental consent by email before they can access the app experience.
For ages 13-15, we store a minimal legal audit trail of parental approval (parent email, timestamp, IP, user-agent, and legal-document versions). This record is retained for 7 years after account deletion to satisfy legal compliance obligations.
Age is self-declared from date of birth provided at signup. We do not use location-based age estimation (GeoIP) for this control.
10. International transfers
Some of our sub-processors are based in the United States. We rely on the EU-US Data Privacy Framework, the UK extension to it, and Standard Contractual Clauses approved by the European Commission to legitimise these transfers. You may request a copy of the SCCs we rely on by emailing gilbardaw01@gmail.com.
11. Cookies and analytics (web console)
The mobile app does not use cookies. The web console at https://app.bfrst.io uses strictly necessary cookies for authentication and session continuity. We do not use third-party advertising cookies. Aggregate, anonymised analytics are collected to monitor product health.
12. Changes to this policy
We may update this Privacy Policy as the Service evolves. Material changes (new sub-processor, new data category, new purpose of processing) will be announced inside the app and by email. The version field above and the registry in `legal_versions` allow you to verify which version you accepted.
13. Contact us
For privacy questions, data subject requests, or to reach the DPO:
Gil Barda
gilbardaw01@gmail.com