Legal
Privacy
Version 1.0 · Last updated 13 July 2026 · Template copy pending legal review before store launch.
Boostly is local-first and privacy-first, designed to align with the Australian Privacy Principles (Privacy Act 1988) and GDPR-style rights.
1. On-device by default
Your profile, workouts, meals, and shopping data live on your device. Nothing leaves it until you enable an online feature.
2. Opt-in, per feature
Cloud backup/sync, the social feed, leaderboards, and challenges are each explicitly opt-in. Nothing social is ever shared by default, and opting out later removes your entries — the app actively retracts leaderboard rows, un-shares your stats snapshot, and deletes shared feed history.
3. Your data is yours
Export everything as JSON at any time, in-app. Request full deletion of any server-side data in-app or via the data-deletion form — actioned within 30 days.
4. We do not sell personal data
Ever. There are no advertising SDKs in v1; any future analytics will be aggregate, minimal, and opt-in.
5. What the server sees (when you opt in)
- Your account identifier (email, display name, public handle).
- The minimum for the feature you enabled — a leaderboard entry is one score, not your training log; a feed item is the summary you chose to share.
- User-contributed prices you choose to submit (moderated before use).
- Payment, if/when subscriptions exist, is handled by the app store — never by us.
6. Security
Server data is encrypted in transit (TLS) and at rest; admin access is role-restricted and audit-logged.
7. Children
Boostly is not directed at children under 16. Targets for users under 18 carry an additional "consult a guardian and professional" notice.
Contact
Privacy questions and requests: privacy@boostly.fitness.