BB Tracker Privacy Policy
1. Introduction & Our Privacy Commitment
Your privacy is not negotiable.
BB Tracker is built on a foundation of zero-knowledge architecture and maximum user privacy. We believe your health and fitness data belongs to you alone. We have designed our service so that we cannot access your sensitive data even if we wanted toβand we don't want to.
π Core Privacy Principles
- Zero-Knowledge Encryption: We cannot read your cycle information, blood work results, or workout data
- Data Minimization: We collect only what is absolutely essential for service functionality
- Anonymity by Design: Use pseudonyms; no real identity required
- No Selling, Ever: Your data will never be sold, shared for profit, or used for advertising
- Legal Resistance: We will rigorously challenge any legal request for your data
- Transparency: We publish what we collect, how we protect it, and what we can/cannot disclose
2. Who We Are
| Attribute |
Details |
| Service Name |
BB Tracker |
| Service Type |
Web-based SaaS platform for bodybuilding cycle tracking, blood work management, workout tracking, and fitness calculators |
| Legal Entity |
[TO BE SPECIFIED] |
| Jurisdiction |
Republic of South Africa |
| Governing Law |
Protection of Personal Information Act, 2013 (POPIA) |
| Website |
[TO BE SPECIFIED] |
| Contact Email |
[TO BE SPECIFIED] |
| Data Protection Officer |
[TO BE SPECIFIED] |
| Security Contact |
[TO BE SPECIFIED] |
3. Scope of This Policy
This Privacy Policy applies to:
- The BB Tracker web application (all subdomains)
- All services, features, and calculators provided through our platform
- Data collected through your use of our service
- Communications between you and BB Tracker
This policy does NOT apply to:
- Third-party websites linked from our service (review their privacy policies)
- Payment processors (see Section 9 for details)
- Your own use of exported data
4. Our Privacy-First Architecture
π Zero-Knowledge Encryption
What This Means: We have designed BB Tracker so that your most sensitive data is encrypted with keys derived from your password. We do not have access to these keys and cannot decrypt your data.
Technical Implementation:
- Client-Side Encryption: Sensitive health data (cycle information, blood work results, body measurements) is encrypted in your browser before being sent to our servers
- User-Derived Keys: Encryption keys are generated from your password using PBKDF2/Argon2id key derivation
- No Master Keys: We do not hold master decryption keys or password recovery backdoors
- Server-Side Blindness: Our servers store only encrypted ciphertext; we cannot read the plaintext
Legal Consequence: Even if compelled by a court order, we cannot provide decrypted health data because we do not possess the technical capability to decrypt it.
π Data Minimization
We collect only the minimum data necessary to provide core service functionality:
- β
Email address (for account recovery; anonymous email services accepted)
- β
Password (hashed, never stored in plaintext)
- β
Optional: Date of birth (encrypted, for age verification only)
- β
Optional: Gender (encrypted, for calculator accuracy only)
We do NOT collect:
- β Real names (pseudonyms strongly encouraged)
- β Physical addresses
- β Phone numbers (unless you explicitly provide and encrypt)
- β Government-issued IDs
- β Payment card details (handled entirely by payment processor)
- β Precise geolocation
- β Device fingerprints (beyond essential security)
- β Browsing history outside our service
π Anonymization & Pseudonymization
- Pseudonyms Encouraged: You are strongly encouraged to use an alias/pseudonym instead of your real name
- No Identity Verification: We do not require or verify your real identity
- Separated Databases: Profile data and authentication data are stored in separate encrypted databases
- Anonymous Email Accepted: You may use anonymous email services (ProtonMail, Tutanota, etc.)
5. Information We Collect (Minimized)
5.1 Personal Information (Encrypted)
| Data Type |
Purpose |
Encryption |
Required? |
| Email address |
Account recovery, transactional notifications |
In transit (TLS 1.3) |
Yes |
| Password |
Authentication |
Hashed (Argon2id), never stored plaintext |
Yes |
| Date of birth |
Age verification (18+ requirement) |
AES-256-GCM |
Optional |
| Gender |
Calculator accuracy |
AES-256-GCM |
Optional |
| Username/Alias |
Account identification |
None (public-facing) |
Yes |
π Privacy Note: We accept anonymous email addresses. You are not required to provide your real name or identity.
5.2 Health & Fitness Data (End-to-End Encrypted)
All of the following data is encrypted client-side before transmission and stored in encrypted format:
- Cycle information (compounds, dosages, schedules)
- Blood work results (hormone levels, lipids, liver/kidney function)
- Workout logs (exercises, sets, reps, weights)
- Body measurements (weight, body fat %, circumferences)
- Progress photos (encrypted before upload to Cloudflare R2)
- Notes and journal entries
π Zero-Knowledge Guarantee: We cannot access this data without your decryption key (derived from your password). This data is cryptographically useless to us, law enforcement, hackers, or anyone else without your password.
5.3 Technical Data (Minimized & Anonymized)
| Data Type |
Retention |
Anonymization |
Purpose |
| IP address |
24 hours |
Last octet removed after 24h, then deleted |
Abuse prevention, security |
| Browser/device type |
Aggregated only |
No individual tracking |
Service optimization |
| Session data |
Until logout |
Ephemeral, not logged |
Authentication state |
| Error logs |
30 days max |
Sanitized of personal info |
Debugging, service improvement |
| Access logs |
7 days |
Anonymized |
Security monitoring |
π« What We Do NOT Track:
- No persistent tracking cookies
- No cross-site tracking
- No advertising IDs
- No device fingerprinting (beyond essential security)
- No browsing history outside BB Tracker
- No social media connections
5.4 Analytics Data (Privacy-Respecting)
We use Cloudflare Analytics ONLYβa privacy-respecting analytics service that:
- Does not use cookies or track individual users
- Provides only aggregated, anonymized metrics
- Does not share data with third parties
- Respects Do Not Track (DNT) browser signals
- Can be disabled per-user upon request
We do NOT use:
- β Google Analytics
- β Facebook Pixel
- β Third-party advertising trackers
- β Any service that profiles individual users
6. Information We Do NOT Collect
Explicit Commitment: The following data is NEVER collected, stored, or processed by BB Tracker:
π« Identity Information
- Real names (unless you voluntarily provide in username)
- Government-issued identification (ID numbers, passport numbers, driver's licenses)
- Social security numbers or tax identification numbers
- Physical addresses or mailing addresses
- Phone numbers (unless you explicitly provide and encrypt)
π« Financial Information
- Credit card numbers
- Bank account details
- Payment card CVV/security codes
- Billing addresses (handled by payment processor only)
π« Biometric & Sensitive Personal Data
- Fingerprints, facial recognition data, or other biometric identifiers
- Genetic information
- Racial or ethnic origin
- Political opinions or affiliations
- Religious or philosophical beliefs
- Trade union membership
- Sexual orientation (beyond optional gender for calculators)
π« Location & Device Data
- Precise GPS coordinates or geolocation
- Device fingerprints (beyond essential security)
- Unique device identifiers (IMEI, MAC addresses)
- Wi-Fi network information
- Bluetooth connections
π« Behavioral & Social Data
- Browsing history outside BB Tracker
- Search queries outside our service
- Social media profiles or connections
- Contact lists or address books
- Communication content with third parties
Legal Consequence: We cannot disclose what we do not collect. If compelled to provide any of the above data, we will truthfully state that we do not possess it.
7. How We Use Your Information
We use your information strictly for the following purposes:
β
Permitted Uses
- Service Provision:
- Authenticate your account and maintain login sessions
- Store and retrieve your encrypted health and fitness data
- Perform calculations (body fat %, TDEE, one-rep max, etc.)
- Generate charts, graphs, and progress visualizations
- Enable data export and backup functionality
- Service Improvement:
- Analyze aggregated, anonymized usage patterns to improve features
- Debug errors and optimize performance
- Develop new calculators and tools based on user needs
- Security & Fraud Prevention:
- Detect and prevent unauthorized access, abuse, and attacks
- Monitor for suspicious activity and security threats
- Enforce our Terms of Service
- Legal Compliance:
- Comply with applicable laws and regulations (POPIA, tax laws)
- Respond to valid legal requests (see Section 14 for our resistance policy)
- Protect our legal rights and those of our users
- Essential Communications:
- Send transactional emails (account verification, password resets, security alerts)
- Notify you of material changes to our service or policies
- Respond to your support requests
β Prohibited Uses
We will NEVER use your information for:
- β Marketing, advertising, or promotional purposes
- β Selling or renting data to third parties
- β Profiling or behavioral targeting
- β Training AI/machine learning models (without explicit, informed consent)
- β Sharing with data brokers or aggregators
- β Cross-referencing with other databases to identify you
- β Any purpose not explicitly listed above
8. Legal Basis for Processing (POPIA)
Under the Protection of Personal Information Act (POPIA), we process your personal information based on the following lawful grounds:
8.1 Consent (Primary Basis)
- You provide explicit, informed, and freely given consent when you create an account and accept this Privacy Policy
- Consent is specific to each processing purpose
- You may withdraw consent at any time by deleting your account
8.2 Contract Performance
- Processing is necessary to provide the BB Tracker service you have requested
- Without processing your email and encrypted data, we cannot deliver the service
8.3 Legitimate Interests
- We have a legitimate interest in:
- Preventing fraud and abuse
- Improving service quality and security
- Defending our legal rights
- These interests are balanced against your privacy rights and do not override them
8.4 Legal Obligation
- We process data only when required by law (e.g., tax compliance, valid court orders)
- We will challenge any legal request that is overbroad or unjustified (see Section 14)
9. Data Sharing & Third Parties
π« We Do NOT Share Your Data Except:
BB Tracker operates on a strict no-sharing policy. Your data is not sold, rented, or shared for commercial purposes. We share data only in the following limited circumstances:
9.1 Essential Service Providers (Minimal Data Only)
| Provider |
Data Shared |
Purpose |
Safeguards |
| Cloudflare (Infrastructure) |
Encrypted data, anonymized IP addresses |
Hosting, CDN, DDoS protection |
Data Processing Agreement, encryption at rest, Cloudflare cannot decrypt user data |
| Payment Processor [TO BE SPECIFIED] |
Transaction ID, subscription status, email (hashed) |
Payment processing, subscription management |
PCI-DSS compliant, no health data shared, no access to BB Tracker account data |
| Email Service [TO BE SPECIFIED] |
Email address, transactional message content |
Transactional emails (password resets, security alerts) |
Encrypted in transit (TLS), no marketing emails, no data retention beyond delivery |
π Key Protections:
- No Health Data Shared: Cycle information, blood work, and workout data are never shared with any third party
- Encrypted Data Only: Service providers receive only encrypted ciphertext (useless without decryption keys)
- Data Processing Agreements: All providers are contractually bound to POPIA-compliant data protection standards
- Minimal Access: Providers have access only to data strictly necessary for their function
9.2 Legal Compulsion (Resisted)
We may be compelled to disclose data in response to:
- Valid court orders or subpoenas issued by South African courts
- Lawful requests from South African law enforcement or regulatory authorities
- Legal obligations under POPIA or other applicable laws
βοΈ Our Resistance Policy (See Section 14 for Full Details):
- We will rigorously challenge any legal request that is overbroad, unjustified, or violates user rights
- We will notify users of requests unless legally prohibited (gag order)
- We will provide only the minimum data legally required
- We will exhaust all legal appeals before complying
- We cannot provide decrypted health data (technical impossibility)
9.3 Business Transfers
In the event of a merger, acquisition, or sale of assets:
- Users will be notified 30 days in advance
- The acquiring entity must honor this Privacy Policy
- Users have the right to delete their accounts before the transfer
- Encrypted data remains encrypted (new entity cannot decrypt without user keys)
π« We Will NEVER:
- β Sell your data to advertisers, data brokers, or marketers
- β Share data with researchers without your explicit, informed consent
- β Provide data to third parties for commercial purposes
- β Voluntarily cooperate with non-compulsory legal requests
- β Disclose data to foreign governments (unless compelled by South African court recognizing foreign order)
- β Share data with social media platforms or analytics companies (beyond Cloudflare Analytics)
10. Your Rights Under POPIA
The Protection of Personal Information Act (POPIA) grants you comprehensive rights over your personal information. BB Tracker is committed to honoring these rights and making them easy to exercise.
10.1 Right to Access π
What It Means: You have the right to know what personal information we hold about you.
How to Exercise:
- Log in to your account and navigate to Settings > Privacy > Download My Data
- Click "Request Data Export"
- You will receive a JSON file containing:
- All personal information (email, optional profile data)
- Encrypted health data (with decryption instructions)
- Account metadata (creation date, last login)
- Access logs (last 90 days)
Timeline: Data export is generated immediately and available for download within 24 hours.
10.2 Right to Correction βοΈ
What It Means: You have the right to correct inaccurate or incomplete personal information.
How to Exercise:
- Log in and navigate to Settings > Profile or the relevant data section
- Edit any field directly (changes are saved immediately)
- For encrypted health data, edit entries in the Cycle Tracker, Blood Work, or Workout sections
Timeline: Corrections are applied in real-time.
10.3 Right to Deletion (Right to Be Forgotten) ποΈ
What It Means: You have the right to request permanent deletion of your personal information.
How to Exercise:
- Log in and navigate to Settings > Privacy > Delete Account
- Click "Permanently Delete My Account"
- Confirm deletion by entering your password
- You will receive a confirmation email when deletion is complete
What Happens:
- Your account is immediately deactivated (you cannot log in)
- All personal information is permanently deleted within 30 days
- All encrypted health data is permanently deleted within 30 days
- Encryption keys are destroyed immediately (renders encrypted backups unrecoverable)
- Anonymized analytics data (no personal identifiers) may be retained in aggregated form
- Backups are overwritten within 30 days
Timeline: Deletion is completed within 30 days of request. You will receive email confirmation.
β οΈ Important: Deletion is permanent and irreversible. We cannot recover your data after deletion.
10.4 Right to Data Portability π¦
What It Means: You have the right to receive your personal information in a structured, machine-readable format and transmit it to another service.
How to Exercise:
- Use the "Download My Data" feature (see Right to Access above)
- Data is provided in JSON format (open standard, machine-readable)
- Includes both encrypted and decrypted versions (where applicable)
Use Cases:
- Migrate to a competing service
- Create personal backups
- Analyze your own data with third-party tools
10.5 Right to Object β
What It Means: You have the right to object to certain types of data processing.
How to Exercise:
- Object to Analytics: Navigate to Settings > Privacy > Analytics and toggle "Disable Analytics"
- Object to Transactional Emails: You cannot opt out of essential security emails (password resets, breach notifications), but you can opt out of service update emails in Settings > Notifications
- Object to Processing for Legitimate Interests: Contact our Data Protection Officer (see Section 19)
Timeline: Objections are honored immediately.
10.6 Right to Restrict Processing π
What It Means: You have the right to limit how we process your data in certain circumstances (e.g., while disputing accuracy).
How to Exercise:
- Contact our Data Protection Officer at [TO BE SPECIFIED]
- Specify which processing activities you wish to restrict and why
Timeline: We will respond within 30 days and implement restrictions where legally required.
10.7 Right to Withdraw Consent πͺ
What It Means: You have the right to withdraw consent for any processing based on consent.
How to Exercise:
- Withdraw All Consent: Delete your account (see Right to Deletion above)
- Withdraw Specific Consent: Contact our Data Protection Officer to withdraw consent for specific processing activities (e.g., analytics)
Timeline: Consent withdrawal is effective immediately.
10.8 Right to Lodge a Complaint π’
What It Means: You have the right to lodge a complaint with the South African Information Protection Regulator if you believe we have violated POPIA.
How to Exercise:
Information Protection Regulator South Africa
- Website: https://inforegulator.org.za
- Email: inforeg@justice.gov.za
- Phone: +27 (0)10 023 5200
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Our Commitment: We encourage you to contact us first so we can resolve any concerns directly. However, you have the unconditional right to lodge a complaint with the Regulator at any time.
10.9 Automated Decision-Making & Profiling
Our Policy: BB Tracker does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
- Calculators (TDEE, body fat %, etc.) are tools that you control; they do not make decisions about you
- We do not use AI or algorithms to profile, score, or make decisions about your access to services
11. Data Security & Encryption
π Military-Grade Security
BB Tracker employs defense-in-depth security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
11.1 Encryption Standards
| Layer |
Technology |
Standard |
Purpose |
| Data in Transit |
TLS 1.3 |
Perfect Forward Secrecy, AEAD ciphers |
Protects data traveling between your browser and our servers |
| Data at Rest (Sensitive) |
AES-256-GCM |
Client-side encryption, user-derived keys |
Protects health data stored on servers (we cannot decrypt) |
| Data at Rest (Database) |
AES-256 |
Cloudflare D1 encryption |
Protects database files from physical theft |
| Password Hashing |
Argon2id |
Memory-hard, GPU-resistant |
Protects passwords from brute-force attacks |
| File Storage |
AES-256-GCM |
Client-side encryption before upload |
Protects progress photos and documents |
11.2 Zero-Knowledge Architecture (Detailed)
How It Works:
- Key Derivation: When you create your account, your password is used to derive an encryption key using Argon2id (a memory-hard, GPU-resistant key derivation function)
- Client-Side Encryption: Before any sensitive health data leaves your browser, it is encrypted using AES-256-GCM with your derived key
- Server Storage: Our servers receive and store only encrypted ciphertextβwe never see the plaintext
- Decryption: When you log in, your password derives the same key, which decrypts your data in your browser
- No Master Keys: We do not store your encryption key, a master decryption key, or any password recovery backdoor
Legal Consequence: Even if compelled by a court order, we cannot decrypt your health data because:
- We do not possess your encryption key
- We do not possess a master key
- The key is derived from your password, which we do not store (only a hash)
- Decryption is technically impossible without your password
11.3 Access Controls
- Multi-Factor Authentication (2FA): Available via TOTP (Google Authenticator, Authy, etc.)
- Role-Based Access Control (RBAC): Internal systems follow principle of least privilege
- No Employee Access: BB Tracker employees cannot access your decrypted health data (technical impossibility)
- Audit Logs: All administrative actions are logged and reviewed
11.4 Infrastructure Security
- DDoS Protection: Cloudflare's enterprise-grade DDoS mitigation
- Web Application Firewall (WAF): Blocks common attacks (SQL injection, XSS, CSRF)
- Rate Limiting: Prevents brute-force attacks and abuse
- Automatic Security Updates: Infrastructure and dependencies are kept up-to-date
- Vulnerability Scanning: Regular automated and manual security assessments
11.5 Application Security
- Secure Coding Practices: OWASP Top 10 mitigations, input validation, output encoding
- Content Security Policy (CSP): Prevents XSS attacks
- HTTP Security Headers: HSTS, X-Frame-Options, X-Content-Type-Options
- CSRF Protection: Tokens on all state-changing requests
- SQL Injection Prevention: Parameterized queries, ORM usage
11.6 Security Audits & Testing
- Penetration Testing: Annual third-party security audits
- Vulnerability Disclosure Program: Responsible disclosure policy for security researchers
- Bug Bounty Program: [TO BE SPECIFIED - if implemented]
- Code Reviews: All code changes reviewed for security implications
11.7 Data Breach Response
In the unlikely event of a data breach:
- Immediate Containment: Breach is contained and systems secured
- Investigation: Forensic analysis to determine scope and impact
- User Notification: Affected users notified within 72 hours of discovery via email
- Regulator Notification: Information Protection Regulator notified within 72 hours (if required by POPIA)
- Transparency: Public disclosure of breach details (anonymized) on our website
- Remediation: Implement additional security measures to prevent recurrence
Notification Will Include:
- Nature of the breach (what data was affected)
- Likely consequences and risks
- Measures taken to mitigate harm
- Recommended actions for affected users (e.g., password reset)
- Contact information for questions
π Encryption Advantage: Because your health data is encrypted with keys we do not possess, a database breach would expose only useless ciphertext. Attackers cannot decrypt your cycle information, blood work, or workout data without your password.
12. Data Retention & Deletion
π
Retention Periods
BB Tracker follows a minimal retention policy: we keep data only as long as necessary for service provision or legal compliance.
12.1 Active Accounts
| Data Type |
Retention Period |
Rationale |
| Email address |
While account active |
Account recovery, transactional notifications |
| Password hash |
While account active |
Authentication |
| Encrypted health data |
While account active |
Service provision (you control this data) |
| Optional profile data |
While account active |
Calculator accuracy, personalization |
| Session data |
Until logout or expiration (7 days max) |
Authentication state |
| Anonymized IP logs |
24 hours |
Abuse prevention, security |
| Error logs |
30 days |
Debugging, service improvement |
| Access logs |
7 days |
Security monitoring |
12.2 Deleted Accounts
When you delete your account:
- Immediate Deactivation: Account is immediately deactivated (you cannot log in)
- Encryption Key Destruction: Your encryption keys are destroyed immediately, rendering all encrypted data permanently unrecoverable
- Data Deletion: All personal information and health data are permanently deleted within 30 days
- Backup Overwrite: Encrypted backups are overwritten within 30 days (after key destruction, backups are cryptographically useless)
- Confirmation: You receive an email confirmation when deletion is complete
β οΈ Permanent & Irreversible: Once deleted, your data cannot be recovered by you, us, or anyone else.
12.3 Inactive Accounts
To protect your privacy and comply with data minimization principles:
- Inactivity Threshold: No login for 2 years
- Warning Email: We send a warning email to your registered address 90 days before deletion
- Grace Period: You have 90 days to log in and prevent deletion
- Automatic Deletion: If no login within 90 days, account is permanently deleted (same process as user-initiated deletion)
Opt-Out: You can disable automatic deletion of inactive accounts in Settings > Privacy > Account Retention.
12.4 Legal Holds
In rare circumstances, we may be legally required to retain data beyond normal retention periods:
- Valid Legal Hold: Court order, subpoena, or regulatory investigation
- User Notification: You will be notified of the legal hold unless prohibited by law (gag order)
- Minimal Scope: Only data specifically required by the legal hold is retained
- Immediate Deletion: Data is deleted immediately when the legal hold is lifted
12.5 Aggregated Analytics
- Anonymized Data: Aggregated, anonymized analytics (e.g., "500 users logged in today") may be retained indefinitely
- No Personal Identifiers: This data cannot be linked back to individual users
- POPIA Compliance: Anonymized data is not considered "personal information" under POPIA
13. Cookies & Tracking
πͺ Minimal Cookie Usage
BB Tracker uses only essential cookies required for service functionality. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
13.1 Essential Cookies (Required)
| Cookie Name |
Purpose |
Duration |
Type |
auth_token |
Authentication (keeps you logged in) |
7 days or until logout |
HTTP-only, Secure, SameSite=Strict |
csrf_token |
Security (prevents CSRF attacks) |
Session |
Secure, SameSite=Strict |
cookie_consent |
Stores your cookie consent preference |
1 year |
Standard |
π Security Features:
- HTTP-only: Cannot be accessed by JavaScript (prevents XSS attacks)
- Secure: Transmitted only over HTTPS
- SameSite=Strict: Prevents CSRF attacks
13.2 Analytics (Privacy-Respecting)
We use Cloudflare Analytics only, which:
- Does not use cookies
- Does not track individual users
- Provides only aggregated, anonymized metrics (page views, geographic region, browser type)
- Respects Do Not Track (DNT) browser signals
- Does not share data with third parties
Opt-Out: You can disable analytics for your account in Settings > Privacy > Analytics.
13.3 What We Do NOT Use
- β Google Analytics
- β Facebook Pixel
- β Advertising cookies (Google Ads, Facebook Ads, etc.)
- β Third-party tracking cookies
- β Cross-site tracking
- β Retargeting/remarketing cookies
- β Social media widgets (like buttons, share buttons)
- β Fingerprinting scripts
13.4 Managing Cookies
Browser Controls: You can control cookies through your browser settings:
- Block All Cookies: BB Tracker will not function (authentication requires cookies)
- Block Third-Party Cookies: Recommended; BB Tracker does not use third-party cookies
- Clear Cookies: Clears your authentication session (you will be logged out)
Do Not Track (DNT): We respect DNT signals and disable Cloudflare Analytics for users with DNT enabled.
14. Legal Requests & Disclosure Resistance
βοΈ Our Commitment to Resisting Overreach
BB Tracker is committed to vigorously defending your privacy against legal requests for user data. We recognize that health and fitness dataβparticularly cycle informationβis highly sensitive and potentially legally problematic in some jurisdictions.
14.1 Our Legal Resistance Policy
When we receive a legal request for user data (subpoena, court order, warrant, regulatory demand), we will:
- Rigorously Challenge: We will challenge any request that is:
- Overbroad or lacks specificity
- Not supported by valid legal authority
- Violates user rights under POPIA or the South African Constitution
- Seeks data we do not possess or cannot technically provide
- Notify Users: We will notify affected users of the request as soon as legally permissible, including:
- Nature of the request (who is requesting, what data is sought)
- Legal basis for the request
- Our response and any challenges filed
- User's right to independently challenge the request
- Minimize Disclosure: If compelled to comply, we will:
- Provide only the minimum data legally required
- Seek to narrow the scope of the request through legal motions
- Redact or anonymize data where legally permissible
- Exhaust all legal appeals before complying
- Transparency: We will publish details of the request in our annual Transparency Report (see Section 20)
14.2 Technical Limitations on Disclosure
What We CAN Be Compelled to Provide (Limited):
| Data Type |
Availability |
Usefulness to Requester |
| Email address |
Yes (if not deleted) |
Can identify user if real email used |
| Account creation date |
Yes |
Minimal investigative value |
| Last login date |
Yes (approximate) |
Minimal investigative value |
| Subscription status |
Yes |
Minimal investigative value |
| Encrypted health data |
Yes (ciphertext only) |
Cryptographically useless without decryption key |
| Anonymized IP logs |
Only if within 24-hour window |
Last octet removed; limited geolocation accuracy |
What We CANNOT Provide (Technical Impossibility):
| Data Type |
Reason |
| Decrypted health data (cycle info, blood work, workouts) |
We do not possess decryption keys; keys are derived from user's password, which we do not store |
| User's real identity |
Not collected (if user used pseudonym and anonymous email) |
| Deleted data |
Permanently erased; cryptographically unrecoverable after key destruction |
| Data we never collected |
Real names, addresses, phone numbers, payment details, precise geolocation, browsing history (see Section 6) |
| Plaintext passwords |
Only hashed with Argon2id; computationally infeasible to reverse |
14.3 Zero-Knowledge Legal Defense
Key Legal Argument: We will assert that we cannot comply with requests for decrypted health data because:
- Technical Impossibility: Decryption keys are derived from user passwords using Argon2id; we do not store passwords (only hashes)
- No Master Keys: We do not possess master decryption keys or backdoors
- User-Controlled Encryption: Only the user possesses the ability to decrypt their data
- Good Faith Design: Our zero-knowledge architecture was designed for user privacy, not to obstruct justice
Legal Precedent: Courts in various jurisdictions have recognized that service providers cannot be compelled to provide data they do not possess or cannot technically access (e.g., Apple Inc. v. FBI, 2016).
14.4 User Notification Exceptions
We will notify users of legal requests unless:
- Gag Order: We are legally prohibited from disclosure (e.g., national security letter, court-ordered gag)
- Imminent Harm: Notification would create imminent risk of death or serious bodily harm
- Obstruction of Justice: Court determines notification would obstruct an ongoing investigation
Delayed Notification: If prohibited from immediate notification, we will notify users as soon as the gag order expires or is lifted.
14.5 User Rights in Legal Proceedings
If your data is subject to a legal request, you have the right to:
- Independent Legal Counsel: Retain your own attorney to challenge the request
- Intervene in Proceedings: File motions to quash or narrow the request
- Delete Data: Delete your account before the compliance deadline (if legally permissible and no legal hold is in place)
- Export Data: Download your data before disclosure
Our Support: We will provide you with:
- Copy of the legal request (if not prohibited)
- Timeline for compliance
- Information about your legal options
- Reasonable time to seek legal counsel before compliance
14.6 Transparency Report
We will publish an annual Transparency Report disclosing:
- Number of Legal Requests Received: Broken down by type (subpoena, warrant, court order, regulatory demand)
- Requesting Entities: Government agencies, law enforcement, private litigants (anonymized if required)
- Requests Challenged: Number and percentage of requests we challenged
- Requests Complied With: Number and percentage of requests we complied with (fully or partially)
- Data Disclosed: Types of data disclosed (aggregated, no individual user details)
- User Notifications Sent: Number of users notified of requests
- Gag Orders: Number of requests subject to gag orders (if legally permissible to disclose)
First Report: Published within 12 months of service launch.
14.7 Warrant Canary
[OPTIONAL - LEGAL REVIEW REQUIRED]
As of [DATE], BB Tracker has:
- β
Not received any national security letters or FISA orders
- β
Not received any gag orders prohibiting disclosure of legal requests
- β
Not been compelled to implement backdoors or weaken encryption
- β
Not received any requests from foreign intelligence agencies
Update Frequency: This statement will be updated quarterly. Absence of an updated statement may indicate we are subject to a gag order.
β οΈ Legal Disclaimer: Warrant canaries are legally untested in South Africa. This statement is provided for transparency but may not be legally enforceable.
14.8 International Legal Requests
Foreign Government Requests:
- We will not comply with requests from foreign governments unless:
- Recognized by a South African court through mutual legal assistance treaty (MLAT)
- Accompanied by a valid South African court order
- We will challenge any attempt to enforce foreign legal process directly
Extraterritorial Jurisdiction:
- BB Tracker is a South African company governed by South African law
- We will assert jurisdictional defenses against extraterritorial legal requests
- Users in other countries should be aware that their local laws may not apply to our service
15. International Data Transfers
π Cross-Border Data Processing
BB Tracker uses Cloudflare's global network for hosting and content delivery. This means your data may be processed on servers located outside South Africa, including in the European Union, United States, and other jurisdictions.
15.1 Legal Basis for Transfers
Under POPIA, cross-border transfers of personal information are permitted when:
- Adequate Safeguards: The recipient country has adequate data protection laws, or we have implemented appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules)
- User Consent: You have provided explicit consent to the transfer
- Necessary for Contract: The transfer is necessary to perform our contract with you (providing the BB Tracker service)
Our Compliance:
- Cloudflare Data Processing Agreement: Cloudflare is contractually bound to GDPR and POPIA-compliant data protection standards
- Standard Contractual Clauses: Cloudflare has implemented EU Standard Contractual Clauses (recognized under POPIA)
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256); sensitive health data is encrypted end-to-end
15.2 Encryption Protects Regardless of Location
Key Point: Because your sensitive health data is encrypted with keys we do not possess, the physical location of servers is largely irrelevant to your privacy:
- Encrypted Data: Servers in any jurisdiction store only encrypted ciphertext
- No Decryption Keys: We cannot decrypt your data, and neither can foreign governments or Cloudflare
- Legal Requests: Even if a foreign government compels Cloudflare to disclose data, they receive only useless ciphertext
15.3 Cloudflare's Privacy Commitments
Cloudflare has publicly committed to:
- No Data Mining: Cloudflare does not mine customer data for advertising or other purposes
- Transparency: Cloudflare publishes transparency reports on legal requests
- Legal Resistance: Cloudflare challenges overbroad or unjustified legal requests
- GDPR Compliance: Cloudflare is GDPR-compliant (GDPR is aligned with POPIA)
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
15.4 User Rights Across Borders
Your rights under POPIA apply regardless of where your data is physically processed:
- Right to access, correction, deletion, portability, objection (see Section 10)
- Right to lodge a complaint with the South African Information Protection Regulator
- Right to be notified of data breaches
15.5 EU & California Users
GDPR (European Union):
- POPIA is aligned with GDPR; your GDPR rights are honored
- You have the right to lodge a complaint with your local Data Protection Authority
- Cross-border transfers are covered by Standard Contractual Clauses
CCPA (California, USA):
- California residents have rights under the California Consumer Privacy Act
- Right to know, delete, opt-out of sale (we do not sell data)
- Contact our Data Protection Officer to exercise CCPA rights
16. Children's Privacy
π« Service Prohibited for Minors
BB Tracker is strictly prohibited for users under the age of 18 years.
16.1 Age Verification
- Signup Requirement: Users must confirm they are 18 years or older during account creation
- Optional Date of Birth: If provided, date of birth is verified to ensure user is 18+
- No Marketing to Minors: We do not knowingly market to or target individuals under 18
16.2 Immediate Deletion of Minor's Data
If we discover that a user is under 18:
- Immediate Account Suspension: Account is immediately deactivated
- Permanent Deletion: All data is permanently deleted within 24 hours
- No Retention: No data is retained for any purpose
- Parental Notification: If we have contact information for a parent/guardian, we will notify them of the deletion
16.3 Reporting Underage Users
If you believe a user is under 18, please contact us immediately at [TO BE SPECIFIED].
16.4 Legal Rationale
BB Tracker is designed for tracking bodybuilding cycles, which may involve substances that are:
- Illegal for minors to possess or use
- Require medical supervision
- Pose health risks to developing bodies
We do not endorse or encourage illegal activity. Our age restriction is designed to comply with applicable laws and protect minors from harm.
17. Health Data Special Protections
π₯ Sensitivity Acknowledgment
We recognize that the health and fitness data you track on BB Trackerβparticularly cycle information (anabolic steroid use) and blood work resultsβis:
- Highly Sensitive: Disclosure could result in legal consequences, employment discrimination, or social stigma
- Legally Problematic: Possession and use of certain substances may be illegal in some jurisdictions
- Medically Confidential: Blood work and health metrics are protected health information
Our Commitment: We have designed BB Tracker with maximum privacy protections specifically to safeguard this sensitive data.
17.1 End-to-End Encryption (Zero-Knowledge)
All health data is encrypted end-to-end:
- Client-Side Encryption: Data is encrypted in your browser before transmission
- User-Controlled Keys: Encryption keys are derived from your password; we do not possess them
- Server-Side Blindness: Our servers store only encrypted ciphertext; we cannot read the plaintext
- Legal Protection: We cannot disclose decrypted health data even if compelled by court order (technical impossibility)
Encrypted Data Includes:
- Cycle information (compounds, dosages, schedules, cycle logs)
- Blood work results (hormone levels, lipids, liver/kidney function, CBC)
- Workout logs (exercises, sets, reps, weights, notes)
- Body measurements (weight, body fat %, circumferences, progress photos)
- Journal entries and notes
17.2 No Sharing with Third Parties
Absolute Prohibition:
- Health data is NEVER shared with any third party under any circumstances
- Not shared with payment processors, email services, or cloud infrastructure providers (they receive only encrypted ciphertext)
- Not shared with researchers, healthcare providers, or government agencies (unless you explicitly export and share it yourself)
- Not used for marketing, advertising, profiling, or any commercial purpose
17.3 No Medical Advice or Healthcare Services
Important Disclaimers:
- Not a Healthcare Provider: BB Tracker is a personal tracking tool, not a medical service
- No Medical Advice: We do not provide medical advice, diagnosis, or treatment recommendations
- No Doctor-Patient Relationship: Use of BB Tracker does not create a doctor-patient relationship
- Consult Healthcare Professionals: Always consult qualified healthcare professionals for medical advice
Legal Consequence: Because we are not a healthcare provider, we are not subject to healthcare-specific data disclosure requirements (e.g., subpoenas for medical records in litigation).
17.4 Legal Status of Tracked Substances
Disclaimer:
- No Endorsement of Illegal Activity: BB Tracker does not endorse, encourage, or facilitate illegal possession or use of controlled substances
- User Responsibility: You are solely responsible for compliance with applicable laws in your jurisdiction
- Legal Use Cases: BB Tracker is designed for:
- Legal testosterone replacement therapy (TRT) under medical supervision
- Harm reduction and health monitoring for individuals who choose to use performance-enhancing substances
- Educational and research purposes
- Tracking legal supplements and training programs
We Do Not Verify:
- Whether substances you track are legal in your jurisdiction
- Whether you have a prescription or medical authorization
- Whether your use complies with applicable laws
17.5 Harm Reduction Philosophy
Our Approach:
- Non-Judgmental: We do not morally police or judge user activities
- Privacy-First: We believe privacy is essential for harm reduction (users are more likely to track honestly if they trust their data is private)
- Safety-Focused: By enabling accurate tracking of cycles and blood work, we help users make informed decisions and monitor health markers
- No Reporting: We do not report user activities to law enforcement, employers, or other third parties
17.6 Research & Aggregated Data
Current Policy:
- We do NOT use your health data for research purposes
- We do NOT share aggregated health data with researchers or third parties
Future Considerations:
If we ever consider using anonymized, aggregated health data for research (e.g., "What percentage of users experience elevated liver enzymes on Compound X?"), we will:
- Seek explicit, informed consent from users through an opt-in process
- Ensure data is fully anonymized (cannot be linked back to individuals)
- Publish research findings publicly (open access)
- Allow users to opt-out at any time
- Provide detailed information about the research purpose, methodology, and data usage
No Current Research: As of the effective date of this policy, we are NOT conducting any research using user data.
18. Changes to This Policy
π Policy Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in applicable laws or regulations (e.g., amendments to POPIA)
- New features or services
- Improvements to our privacy practices
- User feedback and requests
18.1 Notification of Changes
Material Changes (changes that reduce your privacy protections or expand data collection):
- 30 Days' Advance Notice: We will notify you 30 days before the changes take effect via:
- Email to your registered address
- Prominent notice on the BB Tracker website and application
- Explicit Consent Required: If changes materially reduce your privacy protections, we will seek your explicit consent before applying the changes to your account
- Right to Object: You have the right to delete your account if you disagree with the changes (see Section 10.3)
Non-Material Changes (clarifications, formatting, minor updates):
- Immediate Effect: Non-material changes take effect immediately upon posting
- Notification: We will update the "Last Updated" date at the top of this policy
- No Consent Required: Your continued use of the service constitutes acceptance of non-material changes
18.2 Version History
We maintain a version history of this Privacy Policy:
- Current Version: Always available at [TO BE SPECIFIED - URL]
- Previous Versions: Archived and accessible at [TO BE SPECIFIED - URL]
- Change Log: Summary of changes between versions
18.3 Your Options
If you disagree with changes to this Privacy Policy:
- Delete Your Account: Exercise your Right to Deletion (see Section 10.3) before the changes take effect
- Export Your Data: Download your data before deletion (see Section 10.4)
- Contact Us: Reach out to our Data Protection Officer to discuss your concerns
π§ How to Reach Us
| Purpose |
Contact |
Response Time |
| General Privacy Questions |
Email: [TO BE SPECIFIED] |
Within 5 business days |
| Data Protection Officer |
Name: [TO BE SPECIFIED] Email: [TO BE SPECIFIED] Responsibilities: POPIA compliance, user rights requests, privacy policy questions |
Within 30 days (as required by POPIA) |
| Security Issues & Vulnerability Disclosure |
Email: [TO BE SPECIFIED - security@bbtracker.com] PGP Key: [TO BE SPECIFIED - if available] |
Within 24 hours for critical security issues |
| Legal Requests & Law Enforcement |
Email: [TO BE SPECIFIED - legal@bbtracker.com] Note: We will rigorously challenge any legal request (see Section 14) |
As required by law |
Mailing Address:
[TO BE SPECIFIED]
[City, Postal Code]
Republic of South Africa
19.1 Exercising Your Rights
To exercise your rights under POPIA (access, correction, deletion, portability, objection, restriction):
- Self-Service (Preferred): Use the tools in Settings > Privacy for immediate action
- Email Request: Contact our Data Protection Officer at [TO BE SPECIFIED]
- Include: Your registered email address and specific request
- Verification: We may request additional information to verify your identity (to prevent unauthorized access)
Response Timeline: We will respond within 30 days as required by POPIA.
19.2 Complaints & Disputes
Internal Resolution (Preferred):
- Contact our Data Protection Officer at [TO BE SPECIFIED]
- We will investigate and respond within 30 days
- We are committed to resolving complaints fairly and transparently
External Complaint (Your Right):
If you are not satisfied with our response, you have the right to lodge a complaint with:
Information Protection Regulator South Africa
- Website: https://inforegulator.org.za
- Email: inforeg@justice.gov.za
- Phone: +27 (0)10 023 5200
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
No Retaliation: We will not retaliate against you for lodging a complaint with the Regulator or exercising your rights under POPIA.
20. Transparency & Accountability
π Our Commitment to Transparency
BB Tracker is committed to radical transparency about our privacy practices, data handling, and legal requests.
20.1 Annual Transparency Report
We will publish an Annual Transparency Report disclosing:
Legal Requests:
- Number of legal requests received (subpoenas, warrants, court orders, regulatory demands)
- Breakdown by requesting entity (law enforcement, government agencies, private litigants)
- Number of requests challenged
- Number of requests complied with (fully or partially)
- Types of data disclosed (aggregated, no individual user details)
- Number of user notifications sent
- Number of requests subject to gag orders (if legally permissible to disclose)
Data Breaches:
- Number of data breaches (if any)
- Nature and scope of breaches
- Number of users affected
- Remediation measures taken
User Rights Requests:
- Number of access, correction, deletion, portability, objection, and restriction requests
- Average response time
- Number of requests granted vs. denied
Service Statistics:
- Total number of active users (anonymized, aggregated)
- Data retention statistics (average account age, deletion rate)
- Security incidents and responses
First Report: Published within 12 months of service launch.
Publication: Available at [TO BE SPECIFIED - URL]
20.2 Public Security Audits
- Annual Penetration Testing: We will conduct annual third-party security audits
- Public Summary: We will publish a summary of audit findings (vulnerabilities will be disclosed only after remediation)
- Continuous Improvement: Audit findings will inform ongoing security enhancements
20.3 Open-Source Commitment
Where feasible and secure, we will:
- Use open-source encryption libraries (auditable by security researchers)
- Publish technical documentation of our encryption architecture
- Contribute to privacy-enhancing technologies in the open-source community
20.4 User Feedback & Continuous Improvement
- Privacy Feedback: We welcome user feedback on our privacy practices at [TO BE SPECIFIED]
- Feature Requests: Users can request privacy-enhancing features
- Policy Updates: User feedback will inform updates to this Privacy Policy
20.5 Accountability Measures
- Data Protection Officer: Responsible for POPIA compliance and user rights
- Internal Audits: Regular internal reviews of data handling practices
- Employee Training: All employees trained on POPIA requirements and privacy best practices
- Incident Response Plan: Documented procedures for data breaches and security incidents
Summary: Your Privacy in Plain Language
What We Collect:
- β
Email address (can be anonymous)
- β
Password (hashed, never stored in plaintext)
- β
Optional: Date of birth, gender (encrypted)
- β
Health data (cycle info, blood work, workouts) β encrypted end-to-end
What We Do NOT Collect:
- β Real names, addresses, phone numbers, government IDs
- β Payment card details
- β Precise geolocation, browsing history, device fingerprints
How We Protect Your Data:
- π End-to-end encryption for all sensitive health data (we cannot decrypt it)
- π TLS 1.3 for data in transit
- π‘οΈ Argon2id password hashing (GPU-resistant)
- π« No tracking cookies or third-party analytics (Cloudflare Analytics only)
Your Rights:
- π Access: Download all your data in JSON format
- βοΈ Correction: Edit any data in real-time
- ποΈ Deletion: Permanently delete your account and all data within 30 days
- π¦ Portability: Export data in machine-readable format
- β Object: Opt-out of analytics or non-essential processing
- π’ Complain: Lodge a complaint with the Information Protection Regulator
Legal Requests:
- βοΈ We will rigorously challenge any legal request for your data
- π§ We will notify you of requests (unless legally prohibited)
- π We cannot provide decrypted health data (technical impossibility)
- π We publish an annual transparency report
Contact:
- Privacy Questions: [TO BE SPECIFIED]
- Data Protection Officer: [TO BE SPECIFIED]
- Security Issues: [TO BE SPECIFIED]
Effective Date & Acceptance
By creating an account and using BB Tracker, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Your privacy is our priority. We will never compromise it.
END OF PRIVACY POLICY