BB Tracker Privacy Policy



1. Introduction & Our Privacy Commitment

Your privacy is not negotiable.

BB Tracker is built on a foundation of zero-knowledge architecture and maximum user privacy. We believe your health and fitness data belongs to you alone. We have designed our service so that we cannot access your sensitive data even if we wanted toβ€”and we don't want to.

πŸ”’ Core Privacy Principles

  • Zero-Knowledge Encryption: We cannot read your cycle information, blood work results, or workout data
  • Data Minimization: We collect only what is absolutely essential for service functionality
  • Anonymity by Design: Use pseudonyms; no real identity required
  • No Selling, Ever: Your data will never be sold, shared for profit, or used for advertising
  • Legal Resistance: We will rigorously challenge any legal request for your data
  • Transparency: We publish what we collect, how we protect it, and what we can/cannot disclose

2. Who We Are

Attribute Details
Service Name BB Tracker
Service Type Web-based SaaS platform for bodybuilding cycle tracking, blood work management, workout tracking, and fitness calculators
Legal Entity [TO BE SPECIFIED]
Jurisdiction Republic of South Africa
Governing Law Protection of Personal Information Act, 2013 (POPIA)
Website [TO BE SPECIFIED]
Contact Email [TO BE SPECIFIED]
Data Protection Officer [TO BE SPECIFIED]
Security Contact [TO BE SPECIFIED]

3. Scope of This Policy

This Privacy Policy applies to:

  • The BB Tracker web application (all subdomains)
  • All services, features, and calculators provided through our platform
  • Data collected through your use of our service
  • Communications between you and BB Tracker

This policy does NOT apply to:

  • Third-party websites linked from our service (review their privacy policies)
  • Payment processors (see Section 9 for details)
  • Your own use of exported data

4. Our Privacy-First Architecture

πŸ” Zero-Knowledge Encryption

What This Means: We have designed BB Tracker so that your most sensitive data is encrypted with keys derived from your password. We do not have access to these keys and cannot decrypt your data.

Technical Implementation:

  • Client-Side Encryption: Sensitive health data (cycle information, blood work results, body measurements) is encrypted in your browser before being sent to our servers
  • User-Derived Keys: Encryption keys are generated from your password using PBKDF2/Argon2id key derivation
  • No Master Keys: We do not hold master decryption keys or password recovery backdoors
  • Server-Side Blindness: Our servers store only encrypted ciphertext; we cannot read the plaintext

Legal Consequence: Even if compelled by a court order, we cannot provide decrypted health data because we do not possess the technical capability to decrypt it.

πŸ“‰ Data Minimization

We collect only the minimum data necessary to provide core service functionality:

  • βœ… Email address (for account recovery; anonymous email services accepted)
  • βœ… Password (hashed, never stored in plaintext)
  • βœ… Optional: Date of birth (encrypted, for age verification only)
  • βœ… Optional: Gender (encrypted, for calculator accuracy only)

We do NOT collect:

  • ❌ Real names (pseudonyms strongly encouraged)
  • ❌ Physical addresses
  • ❌ Phone numbers (unless you explicitly provide and encrypt)
  • ❌ Government-issued IDs
  • ❌ Payment card details (handled entirely by payment processor)
  • ❌ Precise geolocation
  • ❌ Device fingerprints (beyond essential security)
  • ❌ Browsing history outside our service

🎭 Anonymization & Pseudonymization

  • Pseudonyms Encouraged: You are strongly encouraged to use an alias/pseudonym instead of your real name
  • No Identity Verification: We do not require or verify your real identity
  • Separated Databases: Profile data and authentication data are stored in separate encrypted databases
  • Anonymous Email Accepted: You may use anonymous email services (ProtonMail, Tutanota, etc.)

5. Information We Collect (Minimized)

5.1 Personal Information (Encrypted)

Data Type Purpose Encryption Required?
Email address Account recovery, transactional notifications In transit (TLS 1.3) Yes
Password Authentication Hashed (Argon2id), never stored plaintext Yes
Date of birth Age verification (18+ requirement) AES-256-GCM Optional
Gender Calculator accuracy AES-256-GCM Optional
Username/Alias Account identification None (public-facing) Yes

πŸ”’ Privacy Note: We accept anonymous email addresses. You are not required to provide your real name or identity.

5.2 Health & Fitness Data (End-to-End Encrypted)

All of the following data is encrypted client-side before transmission and stored in encrypted format:

  • Cycle information (compounds, dosages, schedules)
  • Blood work results (hormone levels, lipids, liver/kidney function)
  • Workout logs (exercises, sets, reps, weights)
  • Body measurements (weight, body fat %, circumferences)
  • Progress photos (encrypted before upload to Cloudflare R2)
  • Notes and journal entries

πŸ” Zero-Knowledge Guarantee: We cannot access this data without your decryption key (derived from your password). This data is cryptographically useless to us, law enforcement, hackers, or anyone else without your password.

5.3 Technical Data (Minimized & Anonymized)

Data Type Retention Anonymization Purpose
IP address 24 hours Last octet removed after 24h, then deleted Abuse prevention, security
Browser/device type Aggregated only No individual tracking Service optimization
Session data Until logout Ephemeral, not logged Authentication state
Error logs 30 days max Sanitized of personal info Debugging, service improvement
Access logs 7 days Anonymized Security monitoring

🚫 What We Do NOT Track:

  • No persistent tracking cookies
  • No cross-site tracking
  • No advertising IDs
  • No device fingerprinting (beyond essential security)
  • No browsing history outside BB Tracker
  • No social media connections

5.4 Analytics Data (Privacy-Respecting)

We use Cloudflare Analytics ONLYβ€”a privacy-respecting analytics service that:

  • Does not use cookies or track individual users
  • Provides only aggregated, anonymized metrics
  • Does not share data with third parties
  • Respects Do Not Track (DNT) browser signals
  • Can be disabled per-user upon request

We do NOT use:

  • ❌ Google Analytics
  • ❌ Facebook Pixel
  • ❌ Third-party advertising trackers
  • ❌ Any service that profiles individual users

6. Information We Do NOT Collect

Explicit Commitment: The following data is NEVER collected, stored, or processed by BB Tracker:

🚫 Identity Information

  • Real names (unless you voluntarily provide in username)
  • Government-issued identification (ID numbers, passport numbers, driver's licenses)
  • Social security numbers or tax identification numbers
  • Physical addresses or mailing addresses
  • Phone numbers (unless you explicitly provide and encrypt)

🚫 Financial Information

  • Credit card numbers
  • Bank account details
  • Payment card CVV/security codes
  • Billing addresses (handled by payment processor only)

🚫 Biometric & Sensitive Personal Data

  • Fingerprints, facial recognition data, or other biometric identifiers
  • Genetic information
  • Racial or ethnic origin
  • Political opinions or affiliations
  • Religious or philosophical beliefs
  • Trade union membership
  • Sexual orientation (beyond optional gender for calculators)

🚫 Location & Device Data

  • Precise GPS coordinates or geolocation
  • Device fingerprints (beyond essential security)
  • Unique device identifiers (IMEI, MAC addresses)
  • Wi-Fi network information
  • Bluetooth connections

🚫 Behavioral & Social Data

  • Browsing history outside BB Tracker
  • Search queries outside our service
  • Social media profiles or connections
  • Contact lists or address books
  • Communication content with third parties

Legal Consequence: We cannot disclose what we do not collect. If compelled to provide any of the above data, we will truthfully state that we do not possess it.


7. How We Use Your Information

We use your information strictly for the following purposes:

βœ… Permitted Uses

  1. Service Provision:
    • Authenticate your account and maintain login sessions
    • Store and retrieve your encrypted health and fitness data
    • Perform calculations (body fat %, TDEE, one-rep max, etc.)
    • Generate charts, graphs, and progress visualizations
    • Enable data export and backup functionality
  2. Service Improvement:
    • Analyze aggregated, anonymized usage patterns to improve features
    • Debug errors and optimize performance
    • Develop new calculators and tools based on user needs
  3. Security & Fraud Prevention:
    • Detect and prevent unauthorized access, abuse, and attacks
    • Monitor for suspicious activity and security threats
    • Enforce our Terms of Service
  4. Legal Compliance:
    • Comply with applicable laws and regulations (POPIA, tax laws)
    • Respond to valid legal requests (see Section 14 for our resistance policy)
    • Protect our legal rights and those of our users
  5. Essential Communications:
    • Send transactional emails (account verification, password resets, security alerts)
    • Notify you of material changes to our service or policies
    • Respond to your support requests

❌ Prohibited Uses

We will NEVER use your information for:

  • ❌ Marketing, advertising, or promotional purposes
  • ❌ Selling or renting data to third parties
  • ❌ Profiling or behavioral targeting
  • ❌ Training AI/machine learning models (without explicit, informed consent)
  • ❌ Sharing with data brokers or aggregators
  • ❌ Cross-referencing with other databases to identify you
  • ❌ Any purpose not explicitly listed above

Under the Protection of Personal Information Act (POPIA), we process your personal information based on the following lawful grounds:

8.1 Consent (Primary Basis)

  • You provide explicit, informed, and freely given consent when you create an account and accept this Privacy Policy
  • Consent is specific to each processing purpose
  • You may withdraw consent at any time by deleting your account

8.2 Contract Performance

  • Processing is necessary to provide the BB Tracker service you have requested
  • Without processing your email and encrypted data, we cannot deliver the service

8.3 Legitimate Interests

  • We have a legitimate interest in:
    • Preventing fraud and abuse
    • Improving service quality and security
    • Defending our legal rights
  • These interests are balanced against your privacy rights and do not override them

8.4 Legal Obligation

  • We process data only when required by law (e.g., tax compliance, valid court orders)
  • We will challenge any legal request that is overbroad or unjustified (see Section 14)

9. Data Sharing & Third Parties

🚫 We Do NOT Share Your Data Except:

BB Tracker operates on a strict no-sharing policy. Your data is not sold, rented, or shared for commercial purposes. We share data only in the following limited circumstances:

9.1 Essential Service Providers (Minimal Data Only)

Provider Data Shared Purpose Safeguards
Cloudflare (Infrastructure) Encrypted data, anonymized IP addresses Hosting, CDN, DDoS protection Data Processing Agreement, encryption at rest, Cloudflare cannot decrypt user data
Payment Processor [TO BE SPECIFIED] Transaction ID, subscription status, email (hashed) Payment processing, subscription management PCI-DSS compliant, no health data shared, no access to BB Tracker account data
Email Service [TO BE SPECIFIED] Email address, transactional message content Transactional emails (password resets, security alerts) Encrypted in transit (TLS), no marketing emails, no data retention beyond delivery

πŸ”’ Key Protections:

  • No Health Data Shared: Cycle information, blood work, and workout data are never shared with any third party
  • Encrypted Data Only: Service providers receive only encrypted ciphertext (useless without decryption keys)
  • Data Processing Agreements: All providers are contractually bound to POPIA-compliant data protection standards
  • Minimal Access: Providers have access only to data strictly necessary for their function

9.2 Legal Compulsion (Resisted)

We may be compelled to disclose data in response to:

  • Valid court orders or subpoenas issued by South African courts
  • Lawful requests from South African law enforcement or regulatory authorities
  • Legal obligations under POPIA or other applicable laws

βš–οΈ Our Resistance Policy (See Section 14 for Full Details):

  • We will rigorously challenge any legal request that is overbroad, unjustified, or violates user rights
  • We will notify users of requests unless legally prohibited (gag order)
  • We will provide only the minimum data legally required
  • We will exhaust all legal appeals before complying
  • We cannot provide decrypted health data (technical impossibility)

9.3 Business Transfers

In the event of a merger, acquisition, or sale of assets:

  • Users will be notified 30 days in advance
  • The acquiring entity must honor this Privacy Policy
  • Users have the right to delete their accounts before the transfer
  • Encrypted data remains encrypted (new entity cannot decrypt without user keys)

🚫 We Will NEVER:

  • ❌ Sell your data to advertisers, data brokers, or marketers
  • ❌ Share data with researchers without your explicit, informed consent
  • ❌ Provide data to third parties for commercial purposes
  • ❌ Voluntarily cooperate with non-compulsory legal requests
  • ❌ Disclose data to foreign governments (unless compelled by South African court recognizing foreign order)
  • ❌ Share data with social media platforms or analytics companies (beyond Cloudflare Analytics)

10. Your Rights Under POPIA

The Protection of Personal Information Act (POPIA) grants you comprehensive rights over your personal information. BB Tracker is committed to honoring these rights and making them easy to exercise.

10.1 Right to Access πŸ”

What It Means: You have the right to know what personal information we hold about you.

How to Exercise:

  • Log in to your account and navigate to Settings > Privacy > Download My Data
  • Click "Request Data Export"
  • You will receive a JSON file containing:
    • All personal information (email, optional profile data)
    • Encrypted health data (with decryption instructions)
    • Account metadata (creation date, last login)
    • Access logs (last 90 days)

Timeline: Data export is generated immediately and available for download within 24 hours.

10.2 Right to Correction ✏️

What It Means: You have the right to correct inaccurate or incomplete personal information.

How to Exercise:

  • Log in and navigate to Settings > Profile or the relevant data section
  • Edit any field directly (changes are saved immediately)
  • For encrypted health data, edit entries in the Cycle Tracker, Blood Work, or Workout sections

Timeline: Corrections are applied in real-time.

10.3 Right to Deletion (Right to Be Forgotten) πŸ—‘οΈ

What It Means: You have the right to request permanent deletion of your personal information.

How to Exercise:

  • Log in and navigate to Settings > Privacy > Delete Account
  • Click "Permanently Delete My Account"
  • Confirm deletion by entering your password
  • You will receive a confirmation email when deletion is complete

What Happens:

  1. Your account is immediately deactivated (you cannot log in)
  2. All personal information is permanently deleted within 30 days
  3. All encrypted health data is permanently deleted within 30 days
  4. Encryption keys are destroyed immediately (renders encrypted backups unrecoverable)
  5. Anonymized analytics data (no personal identifiers) may be retained in aggregated form
  6. Backups are overwritten within 30 days

Timeline: Deletion is completed within 30 days of request. You will receive email confirmation.

⚠️ Important: Deletion is permanent and irreversible. We cannot recover your data after deletion.

10.4 Right to Data Portability πŸ“¦

What It Means: You have the right to receive your personal information in a structured, machine-readable format and transmit it to another service.

How to Exercise:

  • Use the "Download My Data" feature (see Right to Access above)
  • Data is provided in JSON format (open standard, machine-readable)
  • Includes both encrypted and decrypted versions (where applicable)

Use Cases:

  • Migrate to a competing service
  • Create personal backups
  • Analyze your own data with third-party tools

10.5 Right to Object β›”

What It Means: You have the right to object to certain types of data processing.

How to Exercise:

  • Object to Analytics: Navigate to Settings > Privacy > Analytics and toggle "Disable Analytics"
  • Object to Transactional Emails: You cannot opt out of essential security emails (password resets, breach notifications), but you can opt out of service update emails in Settings > Notifications
  • Object to Processing for Legitimate Interests: Contact our Data Protection Officer (see Section 19)

Timeline: Objections are honored immediately.

10.6 Right to Restrict Processing πŸ”’

What It Means: You have the right to limit how we process your data in certain circumstances (e.g., while disputing accuracy).

How to Exercise:

  • Contact our Data Protection Officer at [TO BE SPECIFIED]
  • Specify which processing activities you wish to restrict and why

Timeline: We will respond within 30 days and implement restrictions where legally required.

10.7 Right to Withdraw Consent πŸšͺ

What It Means: You have the right to withdraw consent for any processing based on consent.

How to Exercise:

  • Withdraw All Consent: Delete your account (see Right to Deletion above)
  • Withdraw Specific Consent: Contact our Data Protection Officer to withdraw consent for specific processing activities (e.g., analytics)

Timeline: Consent withdrawal is effective immediately.

10.8 Right to Lodge a Complaint πŸ“’

What It Means: You have the right to lodge a complaint with the South African Information Protection Regulator if you believe we have violated POPIA.

How to Exercise:

Information Protection Regulator South Africa

  • Website: https://inforegulator.org.za
  • Email: inforeg@justice.gov.za
  • Phone: +27 (0)10 023 5200
  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Our Commitment: We encourage you to contact us first so we can resolve any concerns directly. However, you have the unconditional right to lodge a complaint with the Regulator at any time.

10.9 Automated Decision-Making & Profiling

Our Policy: BB Tracker does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.

  • Calculators (TDEE, body fat %, etc.) are tools that you control; they do not make decisions about you
  • We do not use AI or algorithms to profile, score, or make decisions about your access to services

11. Data Security & Encryption

πŸ” Military-Grade Security

BB Tracker employs defense-in-depth security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

11.1 Encryption Standards

Layer Technology Standard Purpose
Data in Transit TLS 1.3 Perfect Forward Secrecy, AEAD ciphers Protects data traveling between your browser and our servers
Data at Rest (Sensitive) AES-256-GCM Client-side encryption, user-derived keys Protects health data stored on servers (we cannot decrypt)
Data at Rest (Database) AES-256 Cloudflare D1 encryption Protects database files from physical theft
Password Hashing Argon2id Memory-hard, GPU-resistant Protects passwords from brute-force attacks
File Storage AES-256-GCM Client-side encryption before upload Protects progress photos and documents

11.2 Zero-Knowledge Architecture (Detailed)

How It Works:

  1. Key Derivation: When you create your account, your password is used to derive an encryption key using Argon2id (a memory-hard, GPU-resistant key derivation function)
  2. Client-Side Encryption: Before any sensitive health data leaves your browser, it is encrypted using AES-256-GCM with your derived key
  3. Server Storage: Our servers receive and store only encrypted ciphertextβ€”we never see the plaintext
  4. Decryption: When you log in, your password derives the same key, which decrypts your data in your browser
  5. No Master Keys: We do not store your encryption key, a master decryption key, or any password recovery backdoor

Legal Consequence: Even if compelled by a court order, we cannot decrypt your health data because:

  • We do not possess your encryption key
  • We do not possess a master key
  • The key is derived from your password, which we do not store (only a hash)
  • Decryption is technically impossible without your password

11.3 Access Controls

  • Multi-Factor Authentication (2FA): Available via TOTP (Google Authenticator, Authy, etc.)
  • Role-Based Access Control (RBAC): Internal systems follow principle of least privilege
  • No Employee Access: BB Tracker employees cannot access your decrypted health data (technical impossibility)
  • Audit Logs: All administrative actions are logged and reviewed

11.4 Infrastructure Security

  • DDoS Protection: Cloudflare's enterprise-grade DDoS mitigation
  • Web Application Firewall (WAF): Blocks common attacks (SQL injection, XSS, CSRF)
  • Rate Limiting: Prevents brute-force attacks and abuse
  • Automatic Security Updates: Infrastructure and dependencies are kept up-to-date
  • Vulnerability Scanning: Regular automated and manual security assessments

11.5 Application Security

  • Secure Coding Practices: OWASP Top 10 mitigations, input validation, output encoding
  • Content Security Policy (CSP): Prevents XSS attacks
  • HTTP Security Headers: HSTS, X-Frame-Options, X-Content-Type-Options
  • CSRF Protection: Tokens on all state-changing requests
  • SQL Injection Prevention: Parameterized queries, ORM usage

11.6 Security Audits & Testing

  • Penetration Testing: Annual third-party security audits
  • Vulnerability Disclosure Program: Responsible disclosure policy for security researchers
  • Bug Bounty Program: [TO BE SPECIFIED - if implemented]
  • Code Reviews: All code changes reviewed for security implications

11.7 Data Breach Response

In the unlikely event of a data breach:

  1. Immediate Containment: Breach is contained and systems secured
  2. Investigation: Forensic analysis to determine scope and impact
  3. User Notification: Affected users notified within 72 hours of discovery via email
  4. Regulator Notification: Information Protection Regulator notified within 72 hours (if required by POPIA)
  5. Transparency: Public disclosure of breach details (anonymized) on our website
  6. Remediation: Implement additional security measures to prevent recurrence

Notification Will Include:

  • Nature of the breach (what data was affected)
  • Likely consequences and risks
  • Measures taken to mitigate harm
  • Recommended actions for affected users (e.g., password reset)
  • Contact information for questions

πŸ”’ Encryption Advantage: Because your health data is encrypted with keys we do not possess, a database breach would expose only useless ciphertext. Attackers cannot decrypt your cycle information, blood work, or workout data without your password.


12. Data Retention & Deletion

πŸ“… Retention Periods

BB Tracker follows a minimal retention policy: we keep data only as long as necessary for service provision or legal compliance.

12.1 Active Accounts

Data Type Retention Period Rationale
Email address While account active Account recovery, transactional notifications
Password hash While account active Authentication
Encrypted health data While account active Service provision (you control this data)
Optional profile data While account active Calculator accuracy, personalization
Session data Until logout or expiration (7 days max) Authentication state
Anonymized IP logs 24 hours Abuse prevention, security
Error logs 30 days Debugging, service improvement
Access logs 7 days Security monitoring

12.2 Deleted Accounts

When you delete your account:

  1. Immediate Deactivation: Account is immediately deactivated (you cannot log in)
  2. Encryption Key Destruction: Your encryption keys are destroyed immediately, rendering all encrypted data permanently unrecoverable
  3. Data Deletion: All personal information and health data are permanently deleted within 30 days
  4. Backup Overwrite: Encrypted backups are overwritten within 30 days (after key destruction, backups are cryptographically useless)
  5. Confirmation: You receive an email confirmation when deletion is complete

⚠️ Permanent & Irreversible: Once deleted, your data cannot be recovered by you, us, or anyone else.

12.3 Inactive Accounts

To protect your privacy and comply with data minimization principles:

  • Inactivity Threshold: No login for 2 years
  • Warning Email: We send a warning email to your registered address 90 days before deletion
  • Grace Period: You have 90 days to log in and prevent deletion
  • Automatic Deletion: If no login within 90 days, account is permanently deleted (same process as user-initiated deletion)

Opt-Out: You can disable automatic deletion of inactive accounts in Settings > Privacy > Account Retention.

12.4 Legal Holds

In rare circumstances, we may be legally required to retain data beyond normal retention periods:

  • Valid Legal Hold: Court order, subpoena, or regulatory investigation
  • User Notification: You will be notified of the legal hold unless prohibited by law (gag order)
  • Minimal Scope: Only data specifically required by the legal hold is retained
  • Immediate Deletion: Data is deleted immediately when the legal hold is lifted

12.5 Aggregated Analytics

  • Anonymized Data: Aggregated, anonymized analytics (e.g., "500 users logged in today") may be retained indefinitely
  • No Personal Identifiers: This data cannot be linked back to individual users
  • POPIA Compliance: Anonymized data is not considered "personal information" under POPIA

13. Cookies & Tracking

πŸͺ Minimal Cookie Usage

BB Tracker uses only essential cookies required for service functionality. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

13.1 Essential Cookies (Required)

Cookie Name Purpose Duration Type
auth_token Authentication (keeps you logged in) 7 days or until logout HTTP-only, Secure, SameSite=Strict
csrf_token Security (prevents CSRF attacks) Session Secure, SameSite=Strict
cookie_consent Stores your cookie consent preference 1 year Standard

πŸ”’ Security Features:

  • HTTP-only: Cannot be accessed by JavaScript (prevents XSS attacks)
  • Secure: Transmitted only over HTTPS
  • SameSite=Strict: Prevents CSRF attacks

13.2 Analytics (Privacy-Respecting)

We use Cloudflare Analytics only, which:

  • Does not use cookies
  • Does not track individual users
  • Provides only aggregated, anonymized metrics (page views, geographic region, browser type)
  • Respects Do Not Track (DNT) browser signals
  • Does not share data with third parties

Opt-Out: You can disable analytics for your account in Settings > Privacy > Analytics.

13.3 What We Do NOT Use

  • ❌ Google Analytics
  • ❌ Facebook Pixel
  • ❌ Advertising cookies (Google Ads, Facebook Ads, etc.)
  • ❌ Third-party tracking cookies
  • ❌ Cross-site tracking
  • ❌ Retargeting/remarketing cookies
  • ❌ Social media widgets (like buttons, share buttons)
  • ❌ Fingerprinting scripts

13.4 Managing Cookies

Browser Controls: You can control cookies through your browser settings:

  • Block All Cookies: BB Tracker will not function (authentication requires cookies)
  • Block Third-Party Cookies: Recommended; BB Tracker does not use third-party cookies
  • Clear Cookies: Clears your authentication session (you will be logged out)

Do Not Track (DNT): We respect DNT signals and disable Cloudflare Analytics for users with DNT enabled.


βš–οΈ Our Commitment to Resisting Overreach

BB Tracker is committed to vigorously defending your privacy against legal requests for user data. We recognize that health and fitness dataβ€”particularly cycle informationβ€”is highly sensitive and potentially legally problematic in some jurisdictions.

14.1 Our Legal Resistance Policy

When we receive a legal request for user data (subpoena, court order, warrant, regulatory demand), we will:

  1. Rigorously Challenge: We will challenge any request that is:
    • Overbroad or lacks specificity
    • Not supported by valid legal authority
    • Violates user rights under POPIA or the South African Constitution
    • Seeks data we do not possess or cannot technically provide
  2. Notify Users: We will notify affected users of the request as soon as legally permissible, including:
    • Nature of the request (who is requesting, what data is sought)
    • Legal basis for the request
    • Our response and any challenges filed
    • User's right to independently challenge the request
  3. Minimize Disclosure: If compelled to comply, we will:
    • Provide only the minimum data legally required
    • Seek to narrow the scope of the request through legal motions
    • Redact or anonymize data where legally permissible
    • Exhaust all legal appeals before complying
  4. Transparency: We will publish details of the request in our annual Transparency Report (see Section 20)

14.2 Technical Limitations on Disclosure

What We CAN Be Compelled to Provide (Limited):

Data Type Availability Usefulness to Requester
Email address Yes (if not deleted) Can identify user if real email used
Account creation date Yes Minimal investigative value
Last login date Yes (approximate) Minimal investigative value
Subscription status Yes Minimal investigative value
Encrypted health data Yes (ciphertext only) Cryptographically useless without decryption key
Anonymized IP logs Only if within 24-hour window Last octet removed; limited geolocation accuracy

What We CANNOT Provide (Technical Impossibility):

Data Type Reason
Decrypted health data (cycle info, blood work, workouts) We do not possess decryption keys; keys are derived from user's password, which we do not store
User's real identity Not collected (if user used pseudonym and anonymous email)
Deleted data Permanently erased; cryptographically unrecoverable after key destruction
Data we never collected Real names, addresses, phone numbers, payment details, precise geolocation, browsing history (see Section 6)
Plaintext passwords Only hashed with Argon2id; computationally infeasible to reverse

14.3 Zero-Knowledge Legal Defense

Key Legal Argument: We will assert that we cannot comply with requests for decrypted health data because:

  1. Technical Impossibility: Decryption keys are derived from user passwords using Argon2id; we do not store passwords (only hashes)
  2. No Master Keys: We do not possess master decryption keys or backdoors
  3. User-Controlled Encryption: Only the user possesses the ability to decrypt their data
  4. Good Faith Design: Our zero-knowledge architecture was designed for user privacy, not to obstruct justice

Legal Precedent: Courts in various jurisdictions have recognized that service providers cannot be compelled to provide data they do not possess or cannot technically access (e.g., Apple Inc. v. FBI, 2016).

14.4 User Notification Exceptions

We will notify users of legal requests unless:

  • Gag Order: We are legally prohibited from disclosure (e.g., national security letter, court-ordered gag)
  • Imminent Harm: Notification would create imminent risk of death or serious bodily harm
  • Obstruction of Justice: Court determines notification would obstruct an ongoing investigation

Delayed Notification: If prohibited from immediate notification, we will notify users as soon as the gag order expires or is lifted.

14.5 User Rights in Legal Proceedings

If your data is subject to a legal request, you have the right to:

  • Independent Legal Counsel: Retain your own attorney to challenge the request
  • Intervene in Proceedings: File motions to quash or narrow the request
  • Delete Data: Delete your account before the compliance deadline (if legally permissible and no legal hold is in place)
  • Export Data: Download your data before disclosure

Our Support: We will provide you with:

  • Copy of the legal request (if not prohibited)
  • Timeline for compliance
  • Information about your legal options
  • Reasonable time to seek legal counsel before compliance

14.6 Transparency Report

We will publish an annual Transparency Report disclosing:

  • Number of Legal Requests Received: Broken down by type (subpoena, warrant, court order, regulatory demand)
  • Requesting Entities: Government agencies, law enforcement, private litigants (anonymized if required)
  • Requests Challenged: Number and percentage of requests we challenged
  • Requests Complied With: Number and percentage of requests we complied with (fully or partially)
  • Data Disclosed: Types of data disclosed (aggregated, no individual user details)
  • User Notifications Sent: Number of users notified of requests
  • Gag Orders: Number of requests subject to gag orders (if legally permissible to disclose)

First Report: Published within 12 months of service launch.

14.7 Warrant Canary

[OPTIONAL - LEGAL REVIEW REQUIRED]

As of [DATE], BB Tracker has:

  • βœ… Not received any national security letters or FISA orders
  • βœ… Not received any gag orders prohibiting disclosure of legal requests
  • βœ… Not been compelled to implement backdoors or weaken encryption
  • βœ… Not received any requests from foreign intelligence agencies

Update Frequency: This statement will be updated quarterly. Absence of an updated statement may indicate we are subject to a gag order.

⚠️ Legal Disclaimer: Warrant canaries are legally untested in South Africa. This statement is provided for transparency but may not be legally enforceable.

14.8 International Legal Requests

Foreign Government Requests:

  • We will not comply with requests from foreign governments unless:
    • Recognized by a South African court through mutual legal assistance treaty (MLAT)
    • Accompanied by a valid South African court order
  • We will challenge any attempt to enforce foreign legal process directly

Extraterritorial Jurisdiction:

  • BB Tracker is a South African company governed by South African law
  • We will assert jurisdictional defenses against extraterritorial legal requests
  • Users in other countries should be aware that their local laws may not apply to our service

15. International Data Transfers

🌍 Cross-Border Data Processing

BB Tracker uses Cloudflare's global network for hosting and content delivery. This means your data may be processed on servers located outside South Africa, including in the European Union, United States, and other jurisdictions.

15.1 Legal Basis for Transfers

Under POPIA, cross-border transfers of personal information are permitted when:

  1. Adequate Safeguards: The recipient country has adequate data protection laws, or we have implemented appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules)
  2. User Consent: You have provided explicit consent to the transfer
  3. Necessary for Contract: The transfer is necessary to perform our contract with you (providing the BB Tracker service)

Our Compliance:

  • Cloudflare Data Processing Agreement: Cloudflare is contractually bound to GDPR and POPIA-compliant data protection standards
  • Standard Contractual Clauses: Cloudflare has implemented EU Standard Contractual Clauses (recognized under POPIA)
  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256); sensitive health data is encrypted end-to-end

15.2 Encryption Protects Regardless of Location

Key Point: Because your sensitive health data is encrypted with keys we do not possess, the physical location of servers is largely irrelevant to your privacy:

  • Encrypted Data: Servers in any jurisdiction store only encrypted ciphertext
  • No Decryption Keys: We cannot decrypt your data, and neither can foreign governments or Cloudflare
  • Legal Requests: Even if a foreign government compels Cloudflare to disclose data, they receive only useless ciphertext

15.3 Cloudflare's Privacy Commitments

Cloudflare has publicly committed to:

  • No Data Mining: Cloudflare does not mine customer data for advertising or other purposes
  • Transparency: Cloudflare publishes transparency reports on legal requests
  • Legal Resistance: Cloudflare challenges overbroad or unjustified legal requests
  • GDPR Compliance: Cloudflare is GDPR-compliant (GDPR is aligned with POPIA)

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

15.4 User Rights Across Borders

Your rights under POPIA apply regardless of where your data is physically processed:

  • Right to access, correction, deletion, portability, objection (see Section 10)
  • Right to lodge a complaint with the South African Information Protection Regulator
  • Right to be notified of data breaches

15.5 EU & California Users

GDPR (European Union):

  • POPIA is aligned with GDPR; your GDPR rights are honored
  • You have the right to lodge a complaint with your local Data Protection Authority
  • Cross-border transfers are covered by Standard Contractual Clauses

CCPA (California, USA):

  • California residents have rights under the California Consumer Privacy Act
  • Right to know, delete, opt-out of sale (we do not sell data)
  • Contact our Data Protection Officer to exercise CCPA rights

16. Children's Privacy

🚫 Service Prohibited for Minors

BB Tracker is strictly prohibited for users under the age of 18 years.

16.1 Age Verification

  • Signup Requirement: Users must confirm they are 18 years or older during account creation
  • Optional Date of Birth: If provided, date of birth is verified to ensure user is 18+
  • No Marketing to Minors: We do not knowingly market to or target individuals under 18

16.2 Immediate Deletion of Minor's Data

If we discover that a user is under 18:

  1. Immediate Account Suspension: Account is immediately deactivated
  2. Permanent Deletion: All data is permanently deleted within 24 hours
  3. No Retention: No data is retained for any purpose
  4. Parental Notification: If we have contact information for a parent/guardian, we will notify them of the deletion

16.3 Reporting Underage Users

If you believe a user is under 18, please contact us immediately at [TO BE SPECIFIED].

16.4 Legal Rationale

BB Tracker is designed for tracking bodybuilding cycles, which may involve substances that are:

  • Illegal for minors to possess or use
  • Require medical supervision
  • Pose health risks to developing bodies

We do not endorse or encourage illegal activity. Our age restriction is designed to comply with applicable laws and protect minors from harm.


17. Health Data Special Protections

πŸ₯ Sensitivity Acknowledgment

We recognize that the health and fitness data you track on BB Trackerβ€”particularly cycle information (anabolic steroid use) and blood work resultsβ€”is:

  • Highly Sensitive: Disclosure could result in legal consequences, employment discrimination, or social stigma
  • Legally Problematic: Possession and use of certain substances may be illegal in some jurisdictions
  • Medically Confidential: Blood work and health metrics are protected health information

Our Commitment: We have designed BB Tracker with maximum privacy protections specifically to safeguard this sensitive data.

17.1 End-to-End Encryption (Zero-Knowledge)

All health data is encrypted end-to-end:

  • Client-Side Encryption: Data is encrypted in your browser before transmission
  • User-Controlled Keys: Encryption keys are derived from your password; we do not possess them
  • Server-Side Blindness: Our servers store only encrypted ciphertext; we cannot read the plaintext
  • Legal Protection: We cannot disclose decrypted health data even if compelled by court order (technical impossibility)

Encrypted Data Includes:

  • Cycle information (compounds, dosages, schedules, cycle logs)
  • Blood work results (hormone levels, lipids, liver/kidney function, CBC)
  • Workout logs (exercises, sets, reps, weights, notes)
  • Body measurements (weight, body fat %, circumferences, progress photos)
  • Journal entries and notes

17.2 No Sharing with Third Parties

Absolute Prohibition:

  • Health data is NEVER shared with any third party under any circumstances
  • Not shared with payment processors, email services, or cloud infrastructure providers (they receive only encrypted ciphertext)
  • Not shared with researchers, healthcare providers, or government agencies (unless you explicitly export and share it yourself)
  • Not used for marketing, advertising, profiling, or any commercial purpose

17.3 No Medical Advice or Healthcare Services

Important Disclaimers:

  • Not a Healthcare Provider: BB Tracker is a personal tracking tool, not a medical service
  • No Medical Advice: We do not provide medical advice, diagnosis, or treatment recommendations
  • No Doctor-Patient Relationship: Use of BB Tracker does not create a doctor-patient relationship
  • Consult Healthcare Professionals: Always consult qualified healthcare professionals for medical advice

Legal Consequence: Because we are not a healthcare provider, we are not subject to healthcare-specific data disclosure requirements (e.g., subpoenas for medical records in litigation).

17.4 Legal Status of Tracked Substances

Disclaimer:

  • No Endorsement of Illegal Activity: BB Tracker does not endorse, encourage, or facilitate illegal possession or use of controlled substances
  • User Responsibility: You are solely responsible for compliance with applicable laws in your jurisdiction
  • Legal Use Cases: BB Tracker is designed for:
    • Legal testosterone replacement therapy (TRT) under medical supervision
    • Harm reduction and health monitoring for individuals who choose to use performance-enhancing substances
    • Educational and research purposes
    • Tracking legal supplements and training programs

We Do Not Verify:

  • Whether substances you track are legal in your jurisdiction
  • Whether you have a prescription or medical authorization
  • Whether your use complies with applicable laws

17.5 Harm Reduction Philosophy

Our Approach:

  • Non-Judgmental: We do not morally police or judge user activities
  • Privacy-First: We believe privacy is essential for harm reduction (users are more likely to track honestly if they trust their data is private)
  • Safety-Focused: By enabling accurate tracking of cycles and blood work, we help users make informed decisions and monitor health markers
  • No Reporting: We do not report user activities to law enforcement, employers, or other third parties

17.6 Research & Aggregated Data

Current Policy:

  • We do NOT use your health data for research purposes
  • We do NOT share aggregated health data with researchers or third parties

Future Considerations:

If we ever consider using anonymized, aggregated health data for research (e.g., "What percentage of users experience elevated liver enzymes on Compound X?"), we will:

  • Seek explicit, informed consent from users through an opt-in process
  • Ensure data is fully anonymized (cannot be linked back to individuals)
  • Publish research findings publicly (open access)
  • Allow users to opt-out at any time
  • Provide detailed information about the research purpose, methodology, and data usage

No Current Research: As of the effective date of this policy, we are NOT conducting any research using user data.


18. Changes to This Policy

πŸ“ Policy Updates

We may update this Privacy Policy from time to time to reflect:

  • Changes in applicable laws or regulations (e.g., amendments to POPIA)
  • New features or services
  • Improvements to our privacy practices
  • User feedback and requests

18.1 Notification of Changes

Material Changes (changes that reduce your privacy protections or expand data collection):

  • 30 Days' Advance Notice: We will notify you 30 days before the changes take effect via:
    • Email to your registered address
    • Prominent notice on the BB Tracker website and application
  • Explicit Consent Required: If changes materially reduce your privacy protections, we will seek your explicit consent before applying the changes to your account
  • Right to Object: You have the right to delete your account if you disagree with the changes (see Section 10.3)

Non-Material Changes (clarifications, formatting, minor updates):

  • Immediate Effect: Non-material changes take effect immediately upon posting
  • Notification: We will update the "Last Updated" date at the top of this policy
  • No Consent Required: Your continued use of the service constitutes acceptance of non-material changes

18.2 Version History

We maintain a version history of this Privacy Policy:

  • Current Version: Always available at [TO BE SPECIFIED - URL]
  • Previous Versions: Archived and accessible at [TO BE SPECIFIED - URL]
  • Change Log: Summary of changes between versions

18.3 Your Options

If you disagree with changes to this Privacy Policy:

  1. Delete Your Account: Exercise your Right to Deletion (see Section 10.3) before the changes take effect
  2. Export Your Data: Download your data before deletion (see Section 10.4)
  3. Contact Us: Reach out to our Data Protection Officer to discuss your concerns

19. Contact & Complaints

πŸ“§ How to Reach Us

Purpose Contact Response Time
General Privacy Questions Email: [TO BE SPECIFIED] Within 5 business days
Data Protection Officer Name: [TO BE SPECIFIED]
Email: [TO BE SPECIFIED]
Responsibilities: POPIA compliance, user rights requests, privacy policy questions
Within 30 days (as required by POPIA)
Security Issues & Vulnerability Disclosure Email: [TO BE SPECIFIED - security@bbtracker.com]
PGP Key: [TO BE SPECIFIED - if available]
Within 24 hours for critical security issues
Legal Requests & Law Enforcement Email: [TO BE SPECIFIED - legal@bbtracker.com]
Note: We will rigorously challenge any legal request (see Section 14)
As required by law

Mailing Address:

[TO BE SPECIFIED]
[City, Postal Code]
Republic of South Africa

19.1 Exercising Your Rights

To exercise your rights under POPIA (access, correction, deletion, portability, objection, restriction):

  1. Self-Service (Preferred): Use the tools in Settings > Privacy for immediate action
  2. Email Request: Contact our Data Protection Officer at [TO BE SPECIFIED]
  3. Include: Your registered email address and specific request
  4. Verification: We may request additional information to verify your identity (to prevent unauthorized access)

Response Timeline: We will respond within 30 days as required by POPIA.

19.2 Complaints & Disputes

Internal Resolution (Preferred):

  • Contact our Data Protection Officer at [TO BE SPECIFIED]
  • We will investigate and respond within 30 days
  • We are committed to resolving complaints fairly and transparently

External Complaint (Your Right):

If you are not satisfied with our response, you have the right to lodge a complaint with:

Information Protection Regulator South Africa

  • Website: https://inforegulator.org.za
  • Email: inforeg@justice.gov.za
  • Phone: +27 (0)10 023 5200
  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

No Retaliation: We will not retaliate against you for lodging a complaint with the Regulator or exercising your rights under POPIA.


20. Transparency & Accountability

πŸ“Š Our Commitment to Transparency

BB Tracker is committed to radical transparency about our privacy practices, data handling, and legal requests.

20.1 Annual Transparency Report

We will publish an Annual Transparency Report disclosing:

Legal Requests:

  • Number of legal requests received (subpoenas, warrants, court orders, regulatory demands)
  • Breakdown by requesting entity (law enforcement, government agencies, private litigants)
  • Number of requests challenged
  • Number of requests complied with (fully or partially)
  • Types of data disclosed (aggregated, no individual user details)
  • Number of user notifications sent
  • Number of requests subject to gag orders (if legally permissible to disclose)

Data Breaches:

  • Number of data breaches (if any)
  • Nature and scope of breaches
  • Number of users affected
  • Remediation measures taken

User Rights Requests:

  • Number of access, correction, deletion, portability, objection, and restriction requests
  • Average response time
  • Number of requests granted vs. denied

Service Statistics:

  • Total number of active users (anonymized, aggregated)
  • Data retention statistics (average account age, deletion rate)
  • Security incidents and responses

First Report: Published within 12 months of service launch.
Publication: Available at [TO BE SPECIFIED - URL]

20.2 Public Security Audits

  • Annual Penetration Testing: We will conduct annual third-party security audits
  • Public Summary: We will publish a summary of audit findings (vulnerabilities will be disclosed only after remediation)
  • Continuous Improvement: Audit findings will inform ongoing security enhancements

20.3 Open-Source Commitment

Where feasible and secure, we will:

  • Use open-source encryption libraries (auditable by security researchers)
  • Publish technical documentation of our encryption architecture
  • Contribute to privacy-enhancing technologies in the open-source community

20.4 User Feedback & Continuous Improvement

  • Privacy Feedback: We welcome user feedback on our privacy practices at [TO BE SPECIFIED]
  • Feature Requests: Users can request privacy-enhancing features
  • Policy Updates: User feedback will inform updates to this Privacy Policy

20.5 Accountability Measures

  • Data Protection Officer: Responsible for POPIA compliance and user rights
  • Internal Audits: Regular internal reviews of data handling practices
  • Employee Training: All employees trained on POPIA requirements and privacy best practices
  • Incident Response Plan: Documented procedures for data breaches and security incidents

Summary: Your Privacy in Plain Language

What We Collect:

  • βœ… Email address (can be anonymous)
  • βœ… Password (hashed, never stored in plaintext)
  • βœ… Optional: Date of birth, gender (encrypted)
  • βœ… Health data (cycle info, blood work, workouts) β€” encrypted end-to-end

What We Do NOT Collect:

  • ❌ Real names, addresses, phone numbers, government IDs
  • ❌ Payment card details
  • ❌ Precise geolocation, browsing history, device fingerprints

How We Protect Your Data:

  • πŸ” End-to-end encryption for all sensitive health data (we cannot decrypt it)
  • πŸ”’ TLS 1.3 for data in transit
  • πŸ›‘οΈ Argon2id password hashing (GPU-resistant)
  • 🚫 No tracking cookies or third-party analytics (Cloudflare Analytics only)

Your Rights:

  • πŸ” Access: Download all your data in JSON format
  • ✏️ Correction: Edit any data in real-time
  • πŸ—‘οΈ Deletion: Permanently delete your account and all data within 30 days
  • πŸ“¦ Portability: Export data in machine-readable format
  • β›” Object: Opt-out of analytics or non-essential processing
  • πŸ“’ Complain: Lodge a complaint with the Information Protection Regulator

Legal Requests:

  • βš–οΈ We will rigorously challenge any legal request for your data
  • πŸ“§ We will notify you of requests (unless legally prohibited)
  • πŸ” We cannot provide decrypted health data (technical impossibility)
  • πŸ“Š We publish an annual transparency report

Contact:

  • Privacy Questions: [TO BE SPECIFIED]
  • Data Protection Officer: [TO BE SPECIFIED]
  • Security Issues: [TO BE SPECIFIED]

Effective Date & Acceptance

By creating an account and using BB Tracker, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Your privacy is our priority. We will never compromise it.


END OF PRIVACY POLICY