Security
How BodyComp protects what it holds, and how to tell us about a problem.
Where your data is
Your log lives on your iPhone and in your own private iCloud database, which Apple runs for your Apple Account and which we can't read. Progress photos stay on your phone. Our server holds an account record, your consent choices, your purchase history, monthly AI usage counts, chat and its moderation records, push tokens, and the sign-in tokens for the wearables you connect; the Privacy Policy lists all 40 tables.
In transit and at rest
- Everything between the app and our server, and between our server and every other service, travels over HTTPS.
- WHOOP, Oura and Google Health tokens on our server are encrypted with AES-256-GCM. The key is held in the server's environment, not in the database, so a copy of the database alone doesn't reveal them.
- On your phone, your session token and Apple's sign-in identifier for you sit in the iOS Keychain, never in a file and never in your data export. They aren't marked device-only, so an encrypted iPhone backup includes them.
- Session tokens and Apple identity tokens are removed from our logs, and request headers aren't logged at all.
- App Store purchase receipts are checked on our server against Apple's root certificate.
Sign-in
You sign in with Apple. Your session lasts up to 30 days and renews about once a day while you use the app, for up to 180 days. Deleting your account ends every session at once. One limit: the app can't end a session on another device short of deleting your account, but we will end every session if you ask.
Our dashboard
Every dashboard login, administrator or moderator, has its own username, a hashed password and a single-use code from an authenticator app. Logins are rate-limited, every action checks where it came from, and every time a reviewer is shown reported material is recorded.
If something goes wrong
If personal data on our server is exposed, we tell the relevant authority within 72 hours where the law requires it, and tell the people affected directly where there is a real risk to them.
Report a problem
Found a security problem? Email [email protected] with "Security" in the subject, with what you found and how to reproduce it. We reply within 2 business days.