← Back to Home

Privacy Policy

Last updated: December 8, 2025

Effective Date: December 8, 2025

1. Introduction

Beginnity ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered workout coaching service, including our mobile application and website (collectively, the "Service").

We understand that you are trusting us with sensitive health and fitness data. We take this responsibility seriously and are committed to transparency about our data practices.

By using the Service, you consent to the data practices described in this Privacy Policy and our Terms of Service. If you do not agree, please do not use the Service.

2. Data Controller

For the purposes of applicable data protection laws (including GDPR), the data controller of your personal information is:

Beginnity

2286 6th Avenue

San Diego, CA 92101

United States

Email: privacy@beginnity.com

EU Representative: As we do not currently have a physical presence in the European Union and do not systematically monitor EU residents on a large scale, we rely on the GDPR Article 27(2)(a) exemption and do not have a designated EU representative at this time. If you are an EU resident with privacy concerns, please contact us directly at privacy@beginnity.com.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Password (encrypted with Argon2id hashing)
  • Profile photo (optional)
  • Google account information (if using Google Sign-In)

3.2 Fitness Profile

During onboarding and app usage, we collect:

  • Primary fitness goal (longevity, strength, VO2Max, energy)
  • Fitness experience level (beginner, intermediate, advanced)
  • Workout frequency preferences
  • Gym type and available equipment
  • Age and gender (for workout personalization)

3.3 Health & Fitness Data

With your permission, we collect health data from connected wearables:

  • Sleep Data: Duration, sleep stages (light, deep, REM), sleep quality scores
  • Heart Rate: Resting heart rate, heart rate variability (HRV)
  • Recovery Metrics: Readiness scores, strain levels, recovery percentages
  • Workout History: Exercise type, duration, intensity, completion status
  • Biomarkers: Lab results you choose to upload (blood panels, hormone tests)

3.4 Device & Usage Information

We automatically collect:

  • Device type, operating system, and app version
  • IP address (anonymized/hashed in logs for GDPR compliance)
  • App usage patterns and feature interactions
  • Crash reports and performance data
  • Push notification interaction data

4. Apple HealthKit Data

When you connect Apple Health, we access the following HealthKit data types with your explicit permission:

  • Sleep Analysis: Time asleep, sleep stages, sleep start/end times
  • Heart Rate: Resting heart rate samples
  • Heart Rate Variability: HRV measurements
  • Workouts: Workout type, duration, calories burned

Our HealthKit Commitments

In compliance with Apple's HealthKit guidelines, we make the following commitments:

  • No Advertising: We will NEVER use HealthKit data for advertising or marketing
  • No Sale: We will NEVER sell HealthKit data to any third party
  • No Sharing Without Consent: HealthKit data will NOT be shared with third parties for any purpose without your explicit consent, except as necessary to provide the Service (AI workout generation via Anthropic API)
  • Purpose Limitation: HealthKit data is used ONLY for health, fitness, and workout optimization
  • No Data Mining: We do not use HealthKit data for data mining or building user profiles for purposes unrelated to the Service

You can revoke HealthKit access at any time through your iPhone's Settings → Health → Data Access & Devices → Beginnity.

5. How We Use Your Information

We use your information for the following purposes:

5.1 Service Delivery

  • Generate personalized AI workout prescriptions based on your recovery data
  • Sync data from connected wearable devices
  • Track workout completion and progress
  • Provide AI coach chat functionality
  • Send workout reminders and recovery insights (with your consent)

5.2 Account Management

  • Create and manage your account
  • Process subscription payments
  • Respond to support requests
  • Send transactional communications (password resets, subscription updates)

5.3 Improvement & Analytics

  • Analyze aggregate, anonymized usage patterns to improve the Service
  • Monitor app performance and fix bugs
  • Develop new features based on user behavior

5.4 Security & Compliance

  • Detect and prevent fraud, abuse, and security threats
  • Enforce our Terms of Service
  • Comply with legal obligations

7. Data Sharing & Third Parties

We do NOT sell your personal data. We never have and never will.

We share your information with the following categories of recipients:

7.1 Service Providers (Data Processors)

We use third-party services to operate Beginnity. These providers only access data necessary to perform their services and are contractually bound to protect your data:

ProviderPurposeData Accessed
VercelWeb hosting & deploymentServer logs, IP addresses
NeonDatabase hostingAll user data (encrypted at rest)
AnthropicAI workout generationRecovery metrics, fitness goals (pseudonymized)
Polar.shPayment processingEmail, billing info (not stored by us)
PostHogProduct analyticsUsage events, device info (anonymizable)
ResendTransactional emailEmail address, name
Cloudflare R2File storageBiomarker uploads (encrypted)
Upstash RedisRate limiting, session storageIP addresses (hashed), session IDs
HCaptchaBot preventionIP address, browser fingerprint

7.2 Wearable Device Providers

When you connect wearable devices (Oura, Whoop, Eight Sleep), we receive data from their APIs. Each provider has their own privacy policy governing their data practices. We do not share your Beginnity data back to these providers.

7.3 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government request. We will notify you of such requests when legally permitted and will challenge requests we believe are overbroad or unlawful.

8. AI Data Processing

We use Anthropic's Claude AI to generate personalized workout recommendations. Here is how your data is processed by AI:

8.1 What Data is Sent to AI

  • Recovery scores and readiness metrics (pseudonymized)
  • Sleep quality indicators (not raw sleep data)
  • Fitness goals and preferences
  • Workout history summary

Note: This data is pseudonymized (your user ID is replaced with a random identifier) but is not fully anonymized under GDPR as it could theoretically be re-identified when combined with other data.

8.2 What is NOT Sent

  • Your name or email address
  • Raw biometric data
  • Account credentials
  • Payment information

8.3 AI Training

Your personal health data is NOT used to train AI models. When using Anthropic's API, data is processed for your request only and is not retained for model training per Anthropic's API data usage policy.

8.4 Automated Decision-Making

AI-generated workout recommendations are suggestions only. You are not legally or contractually obligated to follow them. You can always request a different workout or modify recommendations to suit your needs.

9. Cookies & Tracking Technologies

9.1 What We Use

TechnologyPurposeDuration
Session CookiesKeep you logged inSession / 30 days
PostHog AnalyticsUsage analytics, feature tracking1 year
Local StorageApp preferences, onboarding statePersistent

9.2 What We Don't Use

  • Third-party advertising cookies
  • Cross-site tracking
  • Retargeting pixels
  • Social media tracking widgets

9.3 Managing Cookies

You can control cookies through your browser settings. Disabling cookies may affect certain features of the Service (e.g., staying logged in). For PostHog analytics, we respect Do Not Track (DNT) browser signals.

10. Data Security

We implement industry-standard security measures to protect your data:

10.1 Technical Measures

  • Encryption in Transit: All data transmitted via HTTPS/TLS 1.3
  • Encryption at Rest: Database encryption, biomarker files encrypted in storage
  • Password Security: Argon2id hashing (industry-leading algorithm)
  • Access Control: Row-Level Security (RLS) ensures users can only access their own data
  • Rate Limiting: Protection against brute force and abuse
  • CSRF Protection: All mutations protected against cross-site request forgery

10.2 Organizational Measures

  • Principle of least privilege for data access
  • Regular security reviews and updates
  • Secure development practices
  • Incident response procedures

10.3 Data Breach Response

In the unlikely event of a data breach, we will notify affected users within 72 hours via email. We will also notify relevant supervisory authorities as required by GDPR and other applicable laws.

11. Data Retention

Data TypeRetention PeriodAfter Account Deletion
Account InformationWhile account is activeDeleted within 30 days
Health & Fitness DataWhile account is activeDeleted within 30 days
Biomarker UploadsWhile account is activeDeleted within 30 days
Workout HistoryWhile account is activeDeleted within 30 days
Analytics (Aggregated)2 yearsRetained (anonymized)
Security Logs90 daysRetained for security
Payment Records7 years (legal requirement)Retained for tax/legal
Backups30 days rollingPurged in next backup cycle

We may retain data longer if required for legal proceedings, regulatory compliance, or legitimate business purposes (e.g., fraud prevention).

12. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data, subject to legal retention requirements.

Right to Data Portability

Receive your data in a structured, machine-readable format (JSON or CSV).

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time for processing based on consent (e.g., HealthKit access).

To exercise your rights: Email privacy@beginnity.com with your request. We will respond within 30 days (GDPR) or 45 days (CCPA).

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

13.1 Right to Know

You have the right to know what categories of personal information we collect, the sources, business purposes, and third parties we share it with. This is described in Sections 3, 5, and 7 of this Privacy Policy.

13.2 Right to Delete

You may request deletion of your personal information. We will comply within 45 days, unless an exception applies (e.g., legal obligations, security, ongoing transactions).

13.3 Right to Opt-Out of Sale

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Therefore, no opt-out is necessary.

13.4 Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights. You will not receive different pricing or quality of service for making privacy requests.

13.5 Authorized Agents

You may designate an authorized agent to submit requests on your behalf. We will require verification of your identity and the agent's authorization.

13.6 Sensitive Personal Information

Health and fitness data is considered sensitive personal information under CPRA. We use this data only to provide the Service (workout recommendations based on recovery data) and do not use it for purposes requiring a "limit use" opt-out.

14. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

14.1 Data Protection Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. A list of EEA authorities is available at edpb.europa.eu.

14.2 Legal Basis Summary

See Section 6 for our legal bases for processing your data under GDPR.

14.3 Withdrawal of Consent

For processing based on consent (health data, HealthKit access), you can withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw:

  • HealthKit: iPhone Settings → Health → Data Access → Beginnity
  • Email Marketing: Unsubscribe link in any email or Settings in app
  • Account Data: Delete your account in Settings

14.4 Response Times

We will respond to GDPR data subject requests within 30 days. If we need more time due to complexity, we will notify you within 30 days and may extend by an additional 60 days maximum.

15. International Data Transfers

Beginnity is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States.

15.1 Transfer Mechanisms

For transfers from the EEA/UK/Switzerland to the US, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (2021 version, Module 2: Controller to Processor)
  • Data processing agreements with our service providers that include SCCs
  • Your explicit consent for health data transfers

Copies of our Standard Contractual Clauses are available upon request at privacy@beginnity.com.

15.2 Data Protection

We apply the same security measures regardless of where your data is processed. All our service providers are contractually required to protect your data per applicable data protection laws.

16. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18.

Age Verification: During account creation, users self-certify that they are at least 18 years old by accepting our Terms of Service. While we do not employ technical age verification systems, we take reasonable measures to prevent access by minors.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@beginnity.com. We will immediately delete the account and all associated data, and notify the email address on file.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to your registered email address
  • Display a notice within the app

Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated Privacy Policy. If you disagree with changes, you should stop using the Service and delete your account.

18. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Inquiries & Data Requests:

privacy@beginnity.com

General Support:

hello@beginnity.com

Mailing Address:

Beginnity
Attn: Privacy Team
2286 6th Avenue
San Diego, CA 92101
United States

For GDPR-related requests, we aim to respond within 30 days.
For CCPA-related requests, we aim to respond within 45 days.

By using Beginnity, you acknowledge that you have read and understood this Privacy Policy. This policy should be read together with our Terms of Service.

Privacy Policy - Beginnity