Last updated: August 2026
EveryBod Privacy Policy
This Privacy Policy explains how EveryBod, LLC, a California limited liability company ("EveryBod," "we," "us," or "our"), collects, uses, shares, retains, and protects information about you when you use the EveryBod mobile application, the everybodfit.com website, and related services (collectively, the "Service"). It also describes the choices and rights you have regarding your information.
By using the Service, you agree to the collection, use, sharing, and retention of information as described in this Privacy Policy. If you do not agree, do not use the Service.
1. Introduction and Scope
This Privacy Policy applies to information processed by EveryBod through the Service, including the iOS and Android app, the everybodfit.com website (marketing pages, sign-up, and the member/trainer dashboard), our backend systems, our customer support communications, and any related websites or marketing material that link to this Policy.
This Policy does NOT apply to:
- •third-party services, apps, or websites that you may access through the Service, which are governed by their own privacy policies;
- •information that you publish or share publicly outside of the Service.
2. Information We Collect
We collect the following categories of information:
Account Information
- •Name (or display name), and optionally a username.
- •Email address.
- •Password — stored only as a one-way salted hash; we never store or have access to your plaintext password.
- •Authentication metadata — sign-up date, login timestamps, device identifiers used for session security.
Profile and Body Information
- •Demographic data — age, gender (optional, self-reported).
- •Body metrics — height, weight, and (optionally) other body composition values.
- •Fitness goals — your stated goal categories (muscle, strength, endurance, weight loss, general fitness, other).
- •Equipment availability — what gear you have access to (full gym, dumbbells, bodyweight, etc.).
- •Training preferences — preferred training days, session duration, coach style, missed-workout style, intensity overrides, injury flags.
- •Optional public-profile information — if you make your profile public, your avatar, bio, fitness credentials, and social links become visible to other users. See "Community and Public Content" below.
Health and Fitness Data
- •Workouts — sets, reps, weights, RPE, completion status, rest times.
- •Nutrition entries — foods logged, calories, macros, meal type, timestamps.
- •Hydration — water intake, bottle size, daily goal.
- •Personal records — best lifts, milestones, and dates achieved.
- •Soreness and recovery — self-reported markers used to tune the program.
- •Apple Health data — if you connect Apple Health, we read and write data such as workouts, body metrics, and activity to keep the two in sync. You control this connection through iOS Settings.
Location — Zip / postal code only. We do NOT collect precise GPS coordinates and do NOT track your live location.
Usage and Device Data — feature interactions, screens viewed, session length collected via PostHog (pseudonymous, no direct identifiers). Device model, OS version, app version, language, and timezone collected for compatibility and performance.
Crash and Error Data — stack traces and diagnostic data captured when the app crashes, via Sentry. Direct identifiers are scrubbed.
Community and Public Content — if you use social features, your public profile (name, username, avatar, bio, credentials, social links), published workouts, follows, public personal records, and earned badges become visible to other users or the public, but only once you explicitly choose to publish them or make your profile public. Nothing here is public by default.
Trainer Mode Data — as a trainee, you can grant a specific trainer access to your workouts, nutrition, and/or in-app coach messaging, independently and only with your explicit consent; you can revoke access at any time in Settings. As a trainer, we process the data your trainees have consented to share so you can view and act on it, and we retain client-relationship and consent records to operate and audit the feature.
Communications — messages you send to the AI coach (including any health or lifestyle information you choose to share) and emails sent to legal@everybodfit.com.
We do NOT collect, and ask that you NOT submit, the following: government-issued ID numbers, Social Security numbers, payment-card numbers (handled by Apple), precise GPS, or biometric identifiers used for identity verification.
3. How We Use Information
We use the information we collect for the following purposes:
- •Provide the Service — create and authenticate your account, deliver workout and nutrition plans, generate AI coach responses, save progress, sync across devices, and support Trainer Mode's consented data sharing.
- •Personalize the Service — calculate calorie and macro targets, choose appropriate exercises, adjust intensity, surface relevant nudges and reminders.
- •Generate AI coaching responses — send relevant context and your message to our AI provider (Anthropic) to generate a reply.
- •Improve the Service — analyze aggregated, de-identified usage patterns to fix bugs, prioritize features, and improve recommendation quality.
- •Improve our AI models — only with anonymized aggregate data, never with personally identifiable content, except as described in Section 5.
- •Process payments and subscriptions — for both consumer and Trainer subscription tiers, via Apple's App Store and RevenueCat.
- •Transactional emails — account confirmations, password resets, billing notices, material changes to terms.
- •Marketing emails — only to users who explicitly opted in. Every marketing email contains an unsubscribe link, and we record opt-in / opt-out timestamps.
- •Security, fraud prevention, and abuse mitigation.
- •Legal and compliance — comply with applicable laws, regulations, court orders, and lawful requests; enforce our Terms; protect the rights, safety, and property of EveryBod, our users, and third parties.
4. Data Sharing
We do not sell your personal data in the ordinary course of business. We share information only as described below:
Service Providers
- •Supabase — managed PostgreSQL database hosting (United States). Stores account, profile, workout, nutrition, hydration, community, Trainer Mode, and message data.
- •Fly.io — hosts our backend API server (United States).
- •Vercel — hosts the everybodfit.com website (United States).
- •Anthropic — AI inference API. Receives the message context required to generate a coach reply. See Section 5.
- •Apple — payments, subscriptions, and refunds via the iOS App Store. We do not see your full payment information.
- •RevenueCat — subscription and entitlement management. Receives purchase and subscription-status events, not your payment-card information.
- •Resend — transactional email delivery.
- •Sentry — crash and error reporting. Configured to scrub direct identifiers.
- •PostHog — product analytics. Events are pseudonymous and do not include direct identifiers such as name or email.
- •USDA FoodData Central / Open Food Facts — public nutrition databases we query on your behalf when you search for or scan a food; we do not send them information that identifies you.
Each provider is bound by contractual data-protection obligations.
Trainer Mode — we share your fitness and/or nutrition data with a trainer, and share a trainer's coaching messages with you, only according to the granular consent described in Section 2. A trainer is not a service provider of ours — they are another user you've chosen to share specific data with.
Community and Public Content — content you choose to publish or make public is shared with other users of the Service, and, for a public profile, with anyone who can access it, as a direct result of your own choice to publish it.
Legal Compliance — we may disclose information when reasonably necessary to comply with subpoenas, court orders, or other legal process; to enforce our agreements; to protect the rights, safety, or property of EveryBod, our users, or the public; or to detect and address fraud or security issues.
Business Transfers — If EveryBod is involved in a merger, acquisition, asset sale, financing, or bankruptcy, your information may be shared or transferred as a business asset. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy. You will be given the option to delete your account and data before any transfer if the acquiring entity's privacy practices materially differ from ours.
With Your Consent — we will share information with additional third parties only with your explicit consent (e.g., if you authorize an integration with Apple Health, grant a trainer access, or make your profile or a workout public).
We do NOT share your data with advertisers, ad networks, data brokers, insurance companies, or employers.
5. AI Coach Conversations
When you send a message to the AI coach:
- •The message text, plus a curated subset of your profile and recent activity necessary to produce a useful reply (e.g., your goal, training level, recent workouts, recent meals) is transmitted to Anthropic's API over an encrypted connection.
- •Anthropic processes the prompt and returns a response, which we display in-app and store in your message history within the Service.
- •Per our agreement with Anthropic, your messages are NOT used to train Anthropic's general-purpose foundation models without your separate consent. Anthropic may retain logs for a limited period for abuse-monitoring and debugging.
- •We may retain coach messages within the Service to provide conversation history, audit safety, and improve our own coaching prompts and routing logic. We use these messages in aggregate, anonymized form for product improvement; we do not link individual messages to you in marketing or analytics.
- •If a trainer has set a message for your workout or Home screen under Trainer Mode, that message displays in place of the AI-generated one; it is written by your trainer, not generated by AI.
Do NOT submit information to the AI coach that you do not want stored, transmitted to Anthropic, or potentially reviewed by EveryBod personnel for safety or quality assurance.
6. Health Data
Workouts, nutrition entries, hydration logs, body metrics, and self-reported soreness or injury data are treated as sensitive personal information.
- •Encryption. Health and fitness data is encrypted in transit (TLS 1.2+) and encrypted at rest by our database provider.
- •Use restrictions. We do NOT sell health or fitness data, share it with advertisers or ad networks, share it with insurance companies, or share it with prospective employers.
- •Access controls. Access to health and fitness data within EveryBod is limited to personnel who need it to operate, secure, debug, or improve the Service, and is logged. A trainer's access is additionally limited to exactly what you've consented to share.
- •Improvement. Aggregated, de-identified health and fitness data may be used to improve recommendation algorithms, AI prompts, and the Service generally — never in a form that re-identifies an individual user.
7. Data as a Business Asset
We want to be transparent: in modern software businesses, user data has economic value and may be considered a business asset in any transaction involving the company. With that in mind:
- •Personal data — data that identifies or is reasonably linkable to you (e.g., name, email, body metrics, individual workout logs) — will only be transferred to a successor entity that agrees, by contract or by operation of law, to be bound by privacy protections at least as protective as this Policy.
- •Anonymized and aggregated data — data that, alone or in combination with other reasonably available information, cannot be used to identify a specific individual — may be transferred, licensed, or sold as part of a business transaction without individual notice.
- •Pre-transfer notification. Before the transfer of personal data in connection with a business transaction, we will notify affected users by email and in-app at least thirty (30) days in advance and provide instructions to export or delete their data before the transfer takes effect.
- •Limits. Nothing in this Section authorizes the sale of personal data in the ordinary course of business; transfers are limited to genuine business transactions described in Section 4.
8. Data Valuation and Monetization
EveryBod may, in the future, monetize anonymized aggregate data insights — for example, providing anonymous population-level fitness, recovery, or nutrition trend data to research institutions, public-health organizations, academic partners, or commercial partners.
- •Such data products will NEVER include personally identifiable information.
- •We will provide users with at least thirty (30) days advance notice via in-app message and an updated Privacy Policy before launching any new category of data monetization.
- •Opt out. You may opt out of having your anonymized data included in any commercial data product by emailing legal@everybodfit.com from the address on your account. Opting out of data-product inclusion does NOT affect your ability to use the Service.
- •Anonymized data already incorporated into a third-party product before your opt-out request cannot be retroactively removed; however, we will exclude your data from future builds.
9. Data Retention
- •Active accounts. We retain account, profile, and Service data for as long as your account is active.
- •Account deletion. When you delete your account or request deletion, we will delete or de-identify your personal data within thirty (30) days, except where we are legally required to retain certain records longer (e.g., billing and tax records for the period required by law).
- •Backups. Personal data may persist in encrypted backups for a limited period after deletion until those backups expire on their normal rotation schedule.
- •Anonymized aggregate data. Data that has been aggregated or de-identified may be retained indefinitely as described in this Policy and in our Terms.
- •Trainer Mode records. If you were a trainee, a record that a relationship with a trainer existed and its consent history may be retained for audit purposes even after you revoke consent or the relationship ends, though the trainer loses visibility into any new activity from that point forward.
10. User Rights
You have the following rights with respect to your personal data:
- •Right to access. Request a copy of the personal data we hold about you.
- •Right to correct. Ask us to update inaccurate or incomplete data — most fields are editable directly in the Service.
- •Right to delete. Request deletion of your account and associated personal data. We will complete the deletion within 30 days, subject to legal retention obligations.
- •Right to portability. Request an export of your data in a structured, commonly used, machine-readable format.
- •Right to opt out of marketing. Use the unsubscribe link in any marketing email, or email legal@everybodfit.com.
- •Right to control visibility. Change your profile and workout-sharing settings, or revoke a trainer's data access, at any time in Settings — no need to email us for these.
- •Right to pre-transfer notification. In the event of a business sale or transfer involving your personal data, you have the right to be notified at least thirty (30) days in advance, as described in Sections 4 and 7.
- •Right to pre-transfer deletion. Upon receiving notice of a business transfer, you may request deletion of your personal data before the transfer takes effect. Requests must be submitted by emailing legal@everybodfit.com within twenty-one (21) days of the notification.
To exercise any of these rights, email legal@everybodfit.com from the address on file. We may need to verify your identity before fulfilling certain requests.
California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- •Right to know. Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have shared the information.
- •Right to delete. Request deletion of your personal information, subject to legal exceptions.
- •Right to correct. Request correction of inaccurate personal information.
- •Right to opt out of "sale" or "sharing." EveryBod does NOT sell personal information in the ordinary course of business as that term is used under the CCPA, and we do not "share" personal information for cross-context behavioral advertising.
- •Right to limit use of sensitive personal information. You may direct us to limit use of sensitive personal information (e.g., health data) to purposes necessary to provide the Service.
- •Right to non-discrimination for exercising any of these rights.
- •Notice of business transfers. Under CCPA, you have the right to know if your personal information is sold or disclosed and to whom. In the event of a business transfer described in Sections 4 and 7, California residents will be notified and may opt out of the transfer of their personal information.
A "sale" of personal information in the ordinary course of business is distinct from the transfer of personal information as part of a business merger, acquisition, or similar transaction. Such transfers are addressed separately under applicable law and in this Policy.
You may exercise any of these rights by emailing legal@everybodfit.com. You may also designate an authorized agent in writing to make a request on your behalf.
International Users (EU / EEA / UK)
The Service is currently offered only to residents of the United States. We do not currently direct the Service to, or knowingly process the personal data of, residents of the European Economic Area, the United Kingdom, or Switzerland, and we have not yet built the operational processes needed to fully support GDPR/UK GDPR data-subject requests. If you access the Service from outside the United States despite this, your data will be processed in the United States under this Policy — contact legal@everybodfit.com with any concerns and we will do our best to accommodate a legitimate request. This section will be expanded with full GDPR/UK GDPR provisions before we intentionally offer the Service internationally.
11. Children's Privacy
The Service is intended for users aged 18 and older. We do NOT knowingly collect personal information from anyone under 18.
If we learn that a user is under 18, we will delete the account and associated personal data. If you are a parent or guardian who believes your child under 18 has provided us with personal information, please contact legal@everybodfit.com and we will promptly investigate and delete.
12. Marketing Opt-In
Marketing emails are sent only to users who explicitly opted in during registration or in account settings. We record the timestamp of your opt-in.
Every marketing email contains a one-click unsubscribe link. You may also email legal@everybodfit.com to be removed from marketing lists. We will record the timestamp of your withdrawal of consent and act on it within ten (10) business days, except for transactional and account-related emails which are necessary to operate the Service.
13. Cookies and Tracking
The EveryBod mobile app does not use cookies. The everybodfit.com website uses only strictly necessary cookies (e.g., to keep you signed in) — no advertising cookies, no third-party advertising trackers, and no cross-site behavioral advertising, on either the app or the website.
Our analytics provider (PostHog) uses pseudonymous device identifiers, not third-party cookies, to attribute events to a session. You may opt out of analytics by emailing legal@everybodfit.com.
14. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction:
- •TLS 1.2+ for all data in transit;
- •encryption at rest via our managed database provider;
- •least-privilege access controls and audit logging for personnel;
- •routine security reviews and dependency monitoring;
- •offline backups with restricted access.
No system is perfectly secure. In the event of a personal-data breach that creates a meaningful risk to affected users, we will notify regulators and affected users within seventy-two (72) hours of becoming aware of the breach, or sooner if required by applicable law.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days advance notice by email and through an in-app notification before the changes take effect. The "Last updated" date at the top of this Policy reflects the most recent revision.
If you do not agree to a material change, your remedy is to stop using the Service and to delete your account before the change takes effect.
16. Contact
For questions about this Privacy Policy, to exercise any of your rights, or to reach our Data Protection Officer:
EveryBod, LLC Attn: Privacy / Data Protection Officer 6344 Lexington Ave Los Angeles, CA 90038 legal@everybodfit.com
We aim to respond to verified privacy requests within thirty (30) days.