MyBodyLabby OX2 Labs

Privacy, without the fine-print games.

This policy explains what MyBodyLab collects, why it is needed, where it goes, and the controls you have.

Last updated: September 3, 2026

The short version: MyBodyLab does not sell personal data, show third-party ads, use IDFA, or track you across other companies’ apps and websites.

Who we are

MyBodyLab (“MBL”, “we”, “our”, or “us”) is a nutrition, body, fitness, and wellbeing app provided by OX2 Labs. This policy applies to the MyBodyLab iOS app, its extensions, and the services connected to your MyBodyLab account.

Account and profile

When you use Sign in with Apple, we receive an account identifier and, when Apple provides them, your name and email address. The email may be an Apple private relay address.

We store profile information you choose to provide, including age, biological sex, height, weight, goals, dietary preferences, activity level, units, and related plan settings. This data supports authentication, account sync, calculations, and personalized app features.

Meals, photos, voice, and AI

  • Meal records: photos, typed descriptions, voice transcripts, meal times, ingredients, calories, macro- and micronutrient estimates, caffeine information, ratings, feedback, analysis state, and AI-generated results may be stored with your account.
  • AI processing: when you request an analysis or chat feature, the necessary photo, text, and relevant context is sent through our backend to an AI infrastructure provider. Results are returned to and may be stored in your account.
  • Voice meal logging: MyBodyLab stores the resulting transcript like typed text. It does not retain the raw meal-dictation recording. Apple Speech may process the audio when on-device recognition is unavailable.
  • On-device captures: measurement-only body-frame images and Night-mode sound or motion samples remain on the device. Night recordings are not uploaded.

Health, fitness, body, sleep, and cycle data

With your permission, MyBodyLab can read selected Apple Health data, including steps, activity and basal energy, workouts, body measurements, sleep, heart information, VO₂ max, water and nutrition records, age, biological sex, and menstrual flow. Selected summaries, imported records, and derived values may sync to your account for history, cross-device functionality, calculations, and personalized insights. We do not upload every HealthKit sample.

When you separately grant write access, MyBodyLab can save height, weight, body-fat percentage, and lean mass to Apple Health. Health and HealthKit data is not used for third-party advertising or cross-app tracking.

We may also store information you choose to log, including weight and body-composition history, body and progress photos, soreness and other body signals, sleep sessions, menstrual flow and symptoms, health-condition notes, suspected meal relationships, and medication names.

Saved body and progress photos are protected behind the app’s privacy controls and backed up in private account storage. When you request body analysis, the necessary photo may be sent for AI processing. Body photos are never shown in MyBodyLab Town unless a separate sharing surface clearly asks you to publish media.

Location and places

If you grant location access, MyBodyLab may attach precise latitude and longitude to a meal or saved place. We use this to remember where meals were logged, organize place history, and personalize related features. If you enable distance in MyBodyLab Town, other members see an approximate distance rather than your exact coordinates.

MyBodyLab Town

Town is optional. It may store your display name, handle, avatar, in-app social graph, blocks, audience settings, posts, shared meal or workout information, photos, reactions, comments, and private support messages. Visibility follows the audience and sharing choices shown in the app. MyBodyLab does not access your phone address book.

Subscriptions

Apple processes payments. We receive StoreKit product, transaction, subscription, expiration, revocation, and entitlement information so we can provide and restore Pro access. We do not receive your payment-card number.

First-party app analytics

App-usage analytics is enabled by default. It may record an app-scoped installation identifier, your account identifier after sign-in, app version and build, distribution channel, OS version, locale, screens and journey steps, completion and exit points, coarse time and count buckets, feature outcomes, purchase events, diagnostic failure categories, and an optional one-tap answer about how you found MyBodyLab.

For Apple Ads installs, Apple may return normalized attribution data such as campaign, ad group, targeted keyword, ad, placement, and coarse country or region. This does not tell us the exact words a person typed. The short-lived Apple attribution token is sent through our backend for validation and is not stored. Campaign, ad-set, creative, or placement identifiers may also come from links you open.

To understand whether a campaign brings people who find lasting value, restricted first-party server analyses may join attribution and product outcomes with coarse profile categories you already provided, such as age band, biological sex, goal, dietary preference, activity level, unit system, and whether optional profile sections are filled. These profile fields do not ride on analytics event rows and are not sent to Apple Ads or another ad network.

Our analytics event filter excludes raw meal text, names, photos, recordings, health and body values, precise location, and free-form error messages. You can turn Share app usage off in Settings. Opting out stops new collection and clears events waiting on the device. Data already uploaded is deleted when you use Reset All Data or delete your account.

MyBodyLab does not include a third-party advertising analytics SDK and does not currently send these events to Meta or another ad network.

How we use data

  • Provide authentication, sync, backup, history, social, subscription, and support features.
  • Analyze meals and body inputs when you request AI processing.
  • Calculate nutrition, activity, recovery, and body-related summaries.
  • Personalize the plan, suggestions, and content shown to you.
  • Protect the service, diagnose failures, and understand where product journeys succeed or stop.

Service providers and disclosure

We use Apple for Sign in with Apple, HealthKit, StoreKit, push notifications, maps, and speech services; Supabase for authentication, databases, private file storage, and server functions; and AI model providers, including Google or OpenAI depending on the requested feature. They receive the information needed to perform the requested service under their applicable terms.

We may also disclose data when required by law, to protect users or the service, during a lawful business transfer, or when you deliberately publish or share content. We do not sell or rent personal data.

Storage, security, and retention

MyBodyLab keeps an offline copy of much of your data on your device and synchronizes account data using encrypted network connections. Server-side account boundaries and access controls restrict private records and media. Face ID can protect local access to body photos.

We retain account data while your account is active and as needed to provide the features you use. Deleted records may temporarily remain as synchronization markers. Limited copies may remain in backups, security logs, or records required by law until their normal expiry. AI providers may retain request data under their service and abuse-prevention terms.

Your choices

  • Edit profile and logged information in the app.
  • Control Town audiences and sharing categories.
  • Disable usage analytics in Settings.
  • Revoke Health, location, microphone, speech, photo, camera, motion, or notification permissions in iOS Settings.
  • Delete individual content, use Reset All Data, or delete your account from the app.

You may also contact us to ask about access, correction, or deletion of personal data, subject to applicable law.

Children and policy changes

MyBodyLab is not directed to children under 13, and we do not knowingly collect their personal information. We may update this policy when the product or law changes. The date at the top shows the latest revision.

Contact

Privacy email: dimabaranov98@gmail.com

Developer: OX2 Labs

App: MyBodyLab

Bundle identifier: com.ox2labs.itera