EFFECTIVE SEPTEMBER 2, 2026
Privacy Policy
BodyDash processes camera video and body movement on your iPhone or iPad to control the game and create highlights. It never uploads a recording automatically. You can choose whether to share limited usage analytics. The Secret Menu is hidden by default and intended for invited internal and external testers. Every submission is voluntary.
Who we are
BodyDash is provided by Purple Fern LLC. Questions and privacy requests can be sent to bodydash@purplefernllc.com.
Information used on your iPhone or iPad
With Camera permission, BodyDash uses your selected camera for movement controls and a silent local run recording. Apple's Vision framework derives body-joint coordinates on the iPhone or iPad. Camera video may include your face, body, and surroundings. BodyDash does not perform face recognition, identify people, create biometric templates, or infer health conditions. It never requests or records microphone audio. A red REC indicator remains visible during the run.
If you connect a dedicated TV or monitor through AirPlay or a compatible wired route before a run, BodyDash sends the live camera view through that local route during camera runs. The TV presents the same run screens and visual states as the iPhone or iPad, responsively adapted for a 16:9 display. It shows the same large labeled viewfinder, body-joint dots, and coaching during setup, countdown, and tracking or reconnect recovery. During gameplay, it shows the same smaller camera picture in picture as the iPhone or iPad. Live pixels are hidden on Home, run summary, Results, device fallback, connection loss, demo, and replay. The TV can also play the completed highlight, including its recorded camera video. That is playback of the locally reconstructed recording, not a live camera feed. The TV uses bounded copies from the existing device-owned camera output. It does not create a second camera connection or recording. Those pixels stay on the user-selected local display route and are never synced or uploaded to Purple Fern LLC or any cloud service by this feature. Camera permission and all controls stay on the iPhone or iPad.
Local files can include silent camera video, reconstructed game video and game audio, run manifests, gameplay totals, compact pose logs, and performance logs. They stay in the app's private container unless you deliberately save or share a highlight, or submit an eligible run with a bug report or benchmark. A distributed build keeps only the newest completed normal camera attempt's authenticated artifacts. A newer attempt replaces the prior one, even if its camera recording failed. Expired temporary rolling segments are removed during a run. Corrupt or unfinished diagnostic files can remain until you use Delete All or uninstall BodyDash. Copies saved to Photos or sent through another app must be deleted from that destination separately.
Saving, sharing, and local deletion
BodyDash saves a highlight to Photos only after you choose Save to Photos and grant add-only permission. If you choose Other Apps, BodyDash opens the standard system share sheet. BodyDash does not directly send your video to Instagram or TikTok. A service receives the video only if you select it in the share sheet, and that service's privacy practices then apply.
BodyDash automatically removes expired temporary rolling segments. After normal-run files safely finish, bounded retention keeps only the newest completed camera attempt's authenticated artifacts. A newer attempt replaces the prior one, even if its camera recording failed. In Privacy & Storage, choose DELETE ALL RETAINED FILES to remove retained videos, reconstructed media, pose logs, manifests, and partial files. This does not reset cumulative game preferences or statistics. You can revoke Camera or Add to Photos access in iOS or iPadOS Settings under BodyDash.
Limited usage analytics
If analytics is enabled, BodyDash sends:
- A random event ID and random app-session ID
- Event time, app version, build number, system version, and broad device class
- App-open and run-start events, including the selected mode, course, and character
- Aggregate run duration, score, moves, hits, coins, and completion reason
- Counts of tracking loss, camera issues, calibration drift, and canceled countdowns
- The accepted legal-notice version and whether analytics uses consent or legitimate interests
Analytics does not include camera video, audio, images, raw frames, body-joint coordinates, precise location, advertising identifiers, local run IDs, filenames, report text, or submission IDs. BodyDash does not use analytics to track you across other companies' apps or websites, and it does not sell personal data or show ads.
Analytics uses a separate anonymous Supabase Auth identity to validate requests and apply rate limits. Its ID is not placed in analytics rows or reused as a submission owner ID. Supabase network and security logs can contain that anonymous ID, IP address, user agent, and request details.
When the App Store storefront is Australia, Brazil, Japan, South Korea, Mexico, New Zealand, or the United States, BodyDash provides notice before enabling limited first-party analytics where local law permits. Every other valid, new, or unresolved storefront requires an opt-in before analytics starts. An App Store storefront is a routing signal, not proof of where you live.
You can turn analytics off at any time in Privacy & Storage. Turning it off stops new collection and deletes unsent analytics from the iPhone or iPad. A request already sent before you turned analytics off can still finish. Where applicable, Purple Fern LLC relies on consent. Where permitted, it relies on legitimate interests in understanding feature use, finding reliability problems, and improving BodyDash.
Bug reports and benchmark submissions
File uploads require a short-lived upload code with bounded quotas. A text-only bug report does not require a code.
Bug reports and benchmark contributions use separate screens. Report a Problem selects the latest finalized camera attempt, not an older run. If that attempt's camera recording failed, its run manifest and saved diagnostics can be attached without video. If no finalized attempt is available, a report contains only the text you type. A successfully recorded run includes its silent camera video and manifest, plus any available body-position and performance diagnostics. Those available diagnostics are included automatically. Before uploading video, you must confirm that everyone visible is you or agreed to the upload. Contribute Run accepts only a successfully recorded run. Bug reports are never reused as benchmark data.
A run manifest can include app, build, system, device, display, accessibility, and game settings; a local run ID; gameplay controls, events, and totals; body-derived crop and torso measurements; and local artifact names. It does not contain camera frames. For Secret Menu file uploads, the server stores a one-way digest of the code, a non-identifying grant label, limits, and usage counts, not the raw code.
Attachments are stored in private Supabase Storage. The service verifies their exact size and SHA-256 digest, then applies strict validation to the QuickTime MOV container signature and bounded JSON or CSV structure. MP4 camera files and files that fail these checks are rejected. These checks confirm integrity and format, but no security check can guarantee that a file is harmless.
Purple Fern LLC will use bug reports to provide support, secure the service, and fix faults. Voluntary benchmarks will be processed with your consent to evaluate and improve BodyDash tracking. If a recording includes another person, submit it only with their permission. Submitted media and pose data will not be used for identifying people, advertising, health inference, or training unrelated products.
You keep ownership of a benchmark submission. By submitting it, you give Purple Fern LLC permission to host, copy, review, and analyze it only to operate, evaluate, and improve BodyDash. This permission ends when the submission is deleted, except for de-identified aggregate findings. A successful submission will receive a receipt ID that can be used to manage or delete it.
Service providers and network information
This BodyDash website is hosted through OpenAI Sites and Cloudflare infrastructure. When you visit it, those providers may process your IP address, user agent, requested page, request time, and routing or security metadata to deliver and protect the site.
BodyDash uses Supabase for anonymous authentication, database services, Edge Functions, and private file storage. The current hosted project uses Supabase Free and is in the Central EU region in Frankfurt, Germany. Supabase and network providers receive technical routing and security information, such as an IP address, user agent, anonymous Auth ID, and request metadata, when handling a request. BodyDash does not put IP addresses or derived network locations in its analytics or submission tables.
At launch, BodyDash may request a small set of numeric game-balance settings. That request does not contain camera video, run data, body-joint coordinates, or other user content. If the request fails or the response is invalid, BodyDash uses settings included with the app.
Supabase network logs may attach an IP-derived country, region, or city to a request. This is why BodyDash conservatively lists Coarse Location in its App Store privacy details. BodyDash does not request GPS or Location Services, and it does not store precise or derived location in its analytics or submission tables.
Analytics uses a temporary anonymous session that is not saved across app processes. Submissions use a separate anonymous owner session stored securely on the iPhone or iPad so you can list or delete recent submissions.
Review Supabase's privacy notice, subprocessor list, and data processing terms. Those terms include contractual protections for international transfers where required.
Retention and deletion
- Unsent analytics stays in a bounded local queue. Events older than 6 days are discarded when the app next checks the queue.
- Raw server analytics is scheduled for deletion after 90 days.
- Anonymous Auth identities that do not own submissions are scheduled for deletion after 7 days.
- The current Supabase Free plan makes project API and database logs available to Purple Fern LLC for 1 day. Supabase may keep separate operational or security records under its own policies.
- Pending uploads are scheduled for deletion after 24 hours, bug-only reports after 30 days, and benchmarks after 365 days unless deletion is requested sooner or law requires otherwise.
- Temporary deletion-retry records are scheduled for removal after about 28 hours. Private deletion confirmations and unused upload grants are scheduled for removal after 30 days. Request-rate records are scheduled for removal after 2 days.
Submission receipt IDs, purposes, and scheduled deletion dates stay on the iPhone or iPad until deletion is confirmed, you remove the local receipt, or you uninstall BodyDash. Removing a local receipt does not delete server data.
When you delete a submission, BodyDash deletes its active database record and uploaded files from private Storage. If the request fails, the iPhone or iPad keeps the receipt so you can retry. The current Supabase Free plan does not provide customer-accessible automatic backups. Supabase says it may retain up to seven daily backups for a Free project that can become accessible after an upgrade. Data deleted from the active service may remain temporarily in provider-maintained backups or logs until those copies expire under the provider's terms. See Supabase's current backup explanation.
Your choices and rights
You can:
- Leave analytics off where an opt-in is shown
- Turn analytics off in Privacy & Storage in every region
- Delete retained local run files
- Revoke Camera or Photos Add Only access in system Settings
- Send a text-only bug report when no finalized run can be attached, attach failed-run diagnostics without video when available, cancel an upload, or request deletion using its receipt
Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing, receive a portable copy, withdraw consent, and complain to a privacy regulator. Contact bodydash@purplefernllc.com. We may need limited information to locate and verify a request.
Children's privacy
BodyDash is not directed to children under 13. Purple Fern LLC does not knowingly collect personal information from children through analytics or submission features. Do not submit information for a child unless a parent or guardian is authorized to provide any consent required by local law.
Security and changes
Server data travels over HTTPS/TLS. Supabase encrypts hard disks at rest with AES-256. BodyDash uses SHA-256 to confirm that uploaded bytes match the files prepared by the app on the iPhone or iPad. SHA-256 checks file integrity; it is not encryption.
BodyDash also uses Apple platform file protection, rate limits, and restricted database and Storage roles. Uploads use private Storage, short-lived one-file upload tokens, strict file limits, and format validation. No security control can guarantee absolute protection.
We may update this policy when features, service providers, or legal obligations change. The effective date identifies the current version. If a material change requires a new choice, BodyDash will show an updated notice before the affected processing begins.