BestYou Privacy Policy

Effective Date: March 20, 2026

Hello! During your journey with BestYou, you'll discover the power of personalized health insights and AI-driven recommendations to achieve your wellness goals. It's a very personal journey! To give you the best support, we collect personal information from you along the way.

This Privacy Policy ("Policy") describes how PNP Corp d/b/a BestYou Traing Corp ("BestYou," "we," "our," or "us") collects, uses, discloses, and otherwise processes your personal information when you use our Services (use of our mobile app, website, and other interactions you may have with us). This includes your choices and rights regarding your personal information.

BestYou is operated by PNP Corp d/b/a BestYou Training Corp ("PNP Corp"). For data protection purposes, PNP Corp d/b/a BestYou Training Corp is the data controller.

Important: You must be at least 16 years old to use BestYou. Do not use these Services if you are under the age of 16. Our Services are not designed nor otherwise intended for children or anyone under 16.

We implement technical measures to prevent individuals under 16 years of age from creating an account or otherwise using our Services. If we become aware that an individual under 16 may have provided us with personal information, we will investigate and if applicable, take steps to remove the data and delete that individual's account.

What's New in this Version

This Policy updates our previous version (September 30, 2025) with the following changes:

  • New section on AI Processing & Third-Party Integrations, including user-directed sharing via MCP
  • Updated data sharing disclosures for ChatGPT and OpenClaw integrations
  • New data sharing consent section describing how consent is obtained and withdrawn
  • Updated data retention details for MCP API keys and audit logs
  • New privacy right to disconnect third-party AI services

Quick Links to Information about Your Privacy

What information does BestYou collect? BestYou collects information from you directly when you create an account, use our Services, and through third parties. More detail
How does BestYou use the information it collects? BestYou uses your information to provide personalized health recommendations, AI insights, and improve our Services. More detail
Does BestYou sell my information? BestYou does not sell your personal information. We may share aggregated, de-identified data for research purposes only. More detail
How does BestYou share my information? BestYou shares your information with service providers and partners necessary to provide our Services. More detail
What are my privacy rights? You have rights to access, correct, delete, and control how your information is used. More detail

Personal Information We Collect

We may collect personal information directly from you, automatically through your use of the Services, and from third-parties.

Personal Information We Collect Directly from You

Account and Profile Information

This includes your:

  • Name, email address, and password
  • Date of birth and gender
  • Profile image or photo (if you choose to provide one)
  • General location information (country/zip code)
  • Health and fitness goals

Sign in with Apple

When you choose Sign in with Apple, we receive a privacy-preserving relay email (if you select "Hide My Email") and a stable Apple-provided user identifier for your account.

We use this identifier solely to authenticate you and operate your account. We do not sell or share it for advertising.

Health and Activity Data

Certain features allow you to voluntarily share information about your health and activities:

  • Dietary habits, food intake, and nutrition goals
  • Physical activity data (steps, workouts, exercise routines)
  • Biometric data (height, weight, BMI, body measurements)
  • Sleep patterns and quality metrics
  • Health conditions and medical information
  • Progress photos and achievement data
  • Fitness level and activity goals
  • Notes and reflections about your progress and mindset

Note: Health and Activity Data may include sensitive personal information when it indicates or allows someone to infer a health condition.

Communications and Interactions

  • Email correspondence and support requests
  • Feedback and survey responses
  • Community forum posts and social interactions
  • User-to-user messages and shared content
  • Event registration and participation information

Payment Information

If you purchase premium features, payment information is collected by our third-party payment processors. BestYou does not directly store payment card information. Subscriptions are billed by Apple; we receive payment status from Apple, not full card details.

Subscriptions (In-App Purchases)

Payments are processed by Apple via In-App Purchase. BestYou does not store your card details.

You can manage or cancel your subscription in Settings → [your name] → Subscriptions.

Personal Information We Collect Automatically

Usage and Device Data

  • Device information (type, operating system, app version)
  • IP address and general location information
  • App usage patterns, features accessed, and time spent
  • Performance data and error logs
  • Network and carrier information

BestYou does not track you across other companies' apps and websites for advertising.

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience and analyze usage. These include:

  • Required Cookies: Essential for app functionality and security
  • Functional Cookies: Enhance features and analyze usage
  • Analytics Cookies: Help us understand user behavior and improve our services

You can manage cookie preferences through your browser settings or app preferences.

Personal Information We Receive From Third Parties

Connected Health Devices

With your permission, we may collect data from:

  • Fitness trackers and wearable devices
  • Smart scales and body composition monitors
  • Heart rate monitors and sleep tracking devices
  • Continuous glucose monitors
  • Health platforms (Apple Health, Google Fit, Samsung Health)

HealthKit (Apple Health)

With your explicit permission, BestYou reads select categories from Apple HealthKit to power health features.

  • Storage: HealthKit data is stored locally on your device. BestYou does not upload raw HealthKit records (e.g., individual workouts, sleep sessions, raw glucose readings, GPS routes) to our servers.
  • Limited Aggregates Sent: During onboarding (and when you request updated insights), the app may send only aggregated 60-day summaries—sleep averages and sleep stage percentages, glucose mean/variability/time-in-range (if applicable), weekly workout minutes, and VO₂ max (if available)— to generate recommendations.
  • Prohibited Uses: HealthKit data is used only to improve health, fitness, and wellness features and is not used for advertising, marketing, or data brokerage, and is not shared with third parties except service providers that help deliver these health features under strict contracts.
  • Your Control: You can revoke Health permissions at any time in Health app → Profile → Apps → BestYou or Settings → Health → Data Access & Devices → BestYou, and you can clear BestYou's local health data in-app.

Other Sources

  • Service providers and business partners
  • Research partners and survey platforms
  • Social media platforms (when you connect accounts)
  • Other BestYou users (shared content and achievements)
  • Public health databases and research institutions

How We Use Your Information

Provide and Improve Our Services

  • Deliver personalized AI-powered health recommendations and insights
  • Track your progress toward health and fitness goals
  • Provide customized meal plans, workout routines, and coaching
  • Maintain and improve our algorithms and AI models
  • Ensure app functionality, security, and performance
  • Provide customer support and technical assistance

AI Insights Processing

To generate health insights and goals, BestYou may process the aggregated, de-identified statistics described above using our own models and trusted AI service providers under data-processing agreements. Raw HealthKit records and personal identifiers are not provided to AI providers.

Personalization and AI Enhancement

  • Analyze health patterns and provide intelligent recommendations
  • Customize content and features based on your goals and preferences
  • Develop and improve our machine learning and AI systems
  • Test new features and measure their effectiveness

Communication and Engagement

  • Send important account and service updates
  • Provide health tips, motivational content, and educational materials
  • Respond to your questions and support requests
  • Facilitate community interactions and social features

Research and Analytics

  • Conduct health and wellness research using aggregated, de-identified data
  • Analyze usage patterns to improve user experience
  • Measure the effectiveness of health interventions and recommendations
  • Contribute to scientific understanding of health behaviors (with anonymized data)

Legal and Security

  • Comply with legal obligations and regulatory requirements
  • Protect against fraud, unauthorized access, and security threats
  • Enforce our terms of service and policies
  • Respond to legal requests and protect our rights

AI Processing & Third-Party Integrations

AI Processing of Your Health Data

BestYou uses third-party AI services (currently Google Gemini and OpenAI) to power your 19 health agents and generate personalized insights, briefings, and coaching recommendations. When we process your data through these services:

  • We send aggregated health summaries, not raw HealthKit records or personal identifiers.
  • All AI providers operate under data-processing agreements that prohibit using your data to train their general-purpose models.
  • Processing occurs on secure, encrypted connections.

User-Directed Sharing with Third-Party AI Services

When you connect a third-party AI service (such as ChatGPT or OpenClaw) to your BestYou account, you direct us to share certain processed health insights with that service. This is a separate category from how we share data with our own service providers — this sharing is initiated and controlled by you.

What is shared:

  • Daily briefings (coaching narrative, readiness score, day type)
  • Weekly summaries (domain scores for nutrition, strength, activity, and biometrics; trends and achievements)
  • Progress snapshots (health domain scores, top insights, recommendations)
  • Action plans (scheduled workout blocks, meal details with macros, nutrition targets)
  • Workout generation results (stateless; not stored on our servers)
  • Meal analysis results (stateless; not stored on our servers)

What is never shared through MCP:

  • Raw HealthKit records (heart rate samples, step counts, workout GPS routes, etc.)
  • Body weight or body composition data
  • Medication or pharmaceutical plan names
  • Internal identifiers, timing data, or system architecture details
  • Your account password or authentication credentials

HealthKit-Derived Data

When you connect a third-party AI service, processed insights derived from your HealthKit data — including readiness scores, sleep quality scores, cardiac fitness scores, and activity summaries — may be shared with that service. Raw HealthKit records are never shared. This sharing occurs only when you explicitly create an API key or link your account, and you may revoke access at any time.

Third-party data practices: Once your data is received by a third-party AI service, that service's own privacy policy governs its use. BestYou does not control how third-party services store, process, or retain your data.

How We Share Your Information

We do not sell your personal information. We may share your information only in the following circumstances:

Service Providers and Partners

  • Cloud hosting and data storage providers
  • AI and machine learning service providers
  • Payment processors and billing services
  • Customer support platforms
  • Analytics and performance monitoring services
  • Security and fraud prevention services

These providers are contractually required to protect your information and use it only for providing services to us.

Other BestYou Users

We may share information with other users only when you choose to:

  • Use social features like friend connections or community forums
  • Share achievements, progress, or content publicly
  • Participate in challenges or group activities

You can control these sharing settings in your account preferences.

Research and Health Advancement

We may share aggregated, de-identified data with research institutions and public health organizations to advance health science and improve wellness outcomes. This data cannot be used to identify you personally.

Legal Requirements and Safety

  • When required by law or legal process
  • To protect the safety and security of our users
  • To prevent fraud or illegal activities
  • In connection with business transfers or acquisitions

Third-Party AI Services (at Your Direction)

When you connect a third-party AI service to your BestYou account by creating an API key or linking your account, we share processed health insights with that service as described in "User-Directed Sharing with Third-Party AI Services" above. This sharing is initiated by you and can be revoked at any time.

Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

Access and Portability

Request a copy of the personal information we hold about you in a portable format.

Correction

Request correction of inaccurate or incomplete information.

Deletion

Request deletion of your personal information (subject to certain legal exceptions).

Restriction and Objection

Request limitation of processing or object to certain types of data use.

Withdraw Consent

Withdraw consent for processing where consent is the legal basis.

Data Protection Rights

Rights against discrimination for exercising your privacy rights and the right to appeal decisions.

Disconnect Third-Party AI Services

Revoke API keys or unlink third-party accounts at any time in the BestYou app (More > Connected Apps). Revocation is immediate — no new data will be shared. To request that a third-party service delete data already received, contact that service directly.

How to Exercise Your Rights

To exercise these rights, please contact us:

  • Email: support@bestyou.ai
  • Through your account settings in the app
  • Write to us at our address below

We will respond to your request within 30 days.

Data Deletion & Reset

You can delete your account and associated server data in the app (More → Profile → Delete Account) or by emailing privacy@bestyou.ai

To revoke HealthKit access or delete Health data stored by the Health app, go to Health app → Profile → Apps → BestYou or Settings → Health → Data Access & Devices → BestYou.

Data Security

We implement comprehensive security measures to protect your personal information:

  • End-to-end encryption for data transmission and storage
  • Multi-factor authentication and access controls
  • Regular security audits and penetration testing
  • Employee training on data protection and privacy
  • Secure cloud infrastructure with industry-leading providers
  • Continuous monitoring for security threats and vulnerabilities

While we maintain robust security measures, no system is completely secure. We encourage you to protect your account credentials and notify us immediately of any suspected unauthorized access.

Data Retention

We retain your personal information for as long as necessary to:

  • Provide our Services and maintain your account
  • Comply with legal and regulatory requirements
  • Resolve disputes and enforce our agreements
  • Improve our Services and AI algorithms

Specific Retention Periods

  • On-device Health data: remains on your device until you delete it in the app or revoke Health permissions.
  • Aggregated insight summaries sent to server: retained for ≤ 24 months (or your chosen period) to provide longitudinal insights, then deleted or irreversibly de-identified.
  • Server logs & security events: retained for ≤ 30 days (or your policy) unless required longer for security or legal obligations.
  • MCP API keys: Stored (as cryptographic hashes, never plaintext) until revoked by you or expired (default 90 days). Revoked and expired keys are permanently deleted.
  • MCP audit logs: Key creation, usage, and revocation events retained for up to 12 months for security and compliance purposes.
  • Third-party retention: Data shared with third-party AI services is subject to that service's retention policy. BestYou cannot delete data that has already been transmitted to a third party.

When we no longer need your personal information, we will securely delete or anonymize it. You can request deletion of your account and associated data at any time through your account settings or by contacting us.

How You Consent to Data Sharing

BestYou obtains your explicit consent before sharing data with third-party AI services:

OpenClaw / MCP API Keys

When you create an API key in the BestYou app, you review a data sharing disclosure that describes what data will be shared and with whom. Creating the key constitutes your consent.

ChatGPT

When you generate a linking code and enter it on the ChatGPT authorization page, you review the requested access scopes and a data sharing disclosure. Completing the linking flow constitutes your consent.

Withdrawing Consent

Revoke your API key or unlink your account at any time. This immediately stops new data sharing.

International Data Transfers

BestYou is headquartered in the United States and has service providers worldwide. Your personal information may be transferred to and processed in countries with different data protection laws than your country of residence.

When we transfer your information internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and adequacy decisions where applicable.

Children's Privacy

Our Services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we discover that we have collected information from a child under 16, we will promptly delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy in our app and on our website, and updating the "Effective Date" above. We encourage you to review this Privacy Policy regularly.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

PNP Corp d/b/a BestYou Training Corp
Data Protection Officer
Email: support@bestyou.ai
Privacy Email: privacy@bestyou.ai
Address: Chicago, IL, United States
Terms of Use: https://www.bestyou.ai/terms

For Privacy Rights Requests:
Visit your account settings in the BestYou app or email privacy@bestyou.ai with "PRIVACY REQUEST" in the subject line.