When you use the bodify.fit API, we collect:
Your data is used solely to operate the Service:
We share data only with necessary third-party providers:
We never sell your personal data or API keys to third parties.
When you use the body scan endpoints we receive and store: six body measurements (height, weight, chest, waist, hips), a gender value used only to fit the 3D mesh, an optional capture-mode label, and the consent flag you must confirm before a scan is accepted.
We do not receive or store any photo, video or depth data. In the mobile demo app, photo scans are processed entirely on your device and the photos are deleted immediately after the measurements are extracted — the API receives measurements only.
Measurements are sent to our mesh-generation service to produce a 3D mesh. The mesh is stored under an opaque identifier with an integrity checksum, scoped to your organization. Body scan data is never used to train models and is never sold.
Deleting it: DELETE /body/scans removes every body scan and stored mesh for your organization immediately, and the demo app exposes the same action as "Delete All Body Data". To remove a single person's scans, contact us and we will do it for you.
We retain your data only as long as necessary to provide the Service:
DELETE /body/scans or ask us toA self-service deletion API is available for body scan data: DELETE /body/scans immediately removes all of your organization's body scans and stored meshes. For any other data — including a single person's scans — contact us at support@bodify.fit and we will fulfil the request within 30 days.
API keys are stored as bcrypt hashes. All traffic is encrypted via HTTPS. We perform daily database backups, retained for 14 days, with a restore drill verified against a separate database.
You may request access to, correction of, or deletion of your personal data at any time by emailing support@bodify.fit. We respond within 30 days.
The Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us so we can delete it. This policy complies with the Children's Online Privacy Protection Act (COPPA).
The dashboard uses an httpOnly, secure session cookie for authentication. No client-side storage, tracking cookies, or analytics are employed.
We may update this policy. Material changes will be communicated via the email address associated with your account.
← Back to Sign Up