Backd — Consumer Health Data Privacy Policy
Effective date: October 1, 2026 · Last updated: October 2, 2026
This is a standalone, distinctly-linked notice about how Backd ("Backd," "we," "us") handles consumer health data under the Washington My Health My Data Act ("MHMDA") and Nevada SB 370. It supplements, and does not replace, our general Privacy Policy. Where this notice and the general Privacy Policy conflict on a question of consumer health data, this notice controls.
Backd is an accountability app: you set goals and submit photo or text proof of doing them, and you can share progress with buddies or groups. We wrote this notice to describe what Backd actually does, not a worst case. If you spot anything here that doesn't match your experience in the app, please tell us at support@backd.dev.
Backd is provided by Anson Antony, the developer of the Backd app. Backd is an app made by an individual, and business is done in his legal name; "Backd," "we" and "us" in this notice mean him. Our postal address is 1742 SW 38th Terrace, Gainesville, FL 32607.
1. Who this notice is for
This notice applies to you if you are a Washington consumer or a Nevada consumer under those states' health-data laws (broadly, an individual who is a resident of, or whose health data is collected in, that state, and who is acting in a personal/household capacity rather than as an employee or contractor). It also describes our practices generally, so consumers in other states can understand them too.
2. What "consumer health data" Backd actually touches
"Consumer health data" under these laws is personal information linked or reasonably linkable to a consumer that identifies that consumer's past, present, or future physical or mental health status. Importantly, this can include data that is not obviously medical — including precise location and activity data that could reveal or imply health (for example, that you went to a gym, a clinic, or a recovery meeting). Because of that broad definition, we treat the following Backd data as consumer health data, or as data that could be inferred to relate to health:
| Data | What it is in Backd | Where it goes |
|---|---|---|
| Apple Health result | The result "Verified with Apple Health", recording that Apple Health confirmed the check-in. No health value: no step count, no workout count, no measurement of any kind. | Stored with the check-in in your Backd account (Supabase) and shown to the buddy who reviews it. Your steps and workouts are shown only to you, on your device, and are never transmitted. See the on-device note below. |
| Apple Health raw samples | Your underlying step and workout samples in Apple Health. | Never leave your device. See Section 3. |
| Precise location at check-in | A single GPS point captured only at the moment you tap to check in for a location-proof goal, to confirm you were at a place (gym, library, class) — or, if you use it, once when you tap "Use my current location" to set a goal's place. | A rounded coordinate (~110 m / 3 decimals) is stored as the check-in's proof note (Supabase). Full precision is never stored. A goal place set from your current location is stored with the goal rounded to ~11 m (4 decimals), and a check-in against a goal place records only your approximate distance from it (for example, "~37 m") in the note your buddy sees. On a goal backed by a stake, your phone sends its reading to Backd's server, which keeps only the result and distance, not the coordinates. When you set or change a goal's place, the place's coordinates go to Apple Maps for the health-care check (Section 10). No background tracking. |
| Health-implying proof content | Photos or free-text notes you choose to submit as proof, plus goal titles, which may describe health or fitness activity (e.g., "ran 5k," "took my meds," "therapy"). | Stored as your user-generated content (Supabase). Shared only with the specific buddy you assign to a goal, per your settings. Each uploaded proof photo (the image only) is automatically screened by our image-safety provider, Sightengine, before your buddy can see it. |
| Phone number (if you opt in to SMS) | Used for SMS reminders. | Not health data by itself, but may be paired with goal titles that imply health. See Section 4. |
What we do not collect: We do not request or store Apple Clinical Health Records / medical records, diagnoses, prescriptions, lab results, or any Apple Health data beyond step count and workout read access. We do not infer health conditions, we do not build a health profile about you, and we do not track your location in the background.
3. Apple Health stays on your device
When a goal offers an Apple Health proof type and you choose it, Backd asks iOS for read-only access to your step count and workouts. If you grant it:
- Backd reads those samples on your device only, computes whether your goal was met, and persists only one thing: the result "Verified with Apple Health", stored with the check-in and shown to the buddy who reviews it. No step count, workout count or other health value is stored or transmitted — to your buddy or to any vendor.
- Your raw Apple Health samples never leave your device and are never uploaded to our servers, our AI vendor, your buddies, or anyone else.
- Backd has read-only access. It never writes to Apple Health.
- This feature is iOS-only and is offered only when enabled; on Android, in Expo Go, in the simulator, or when you decline, Backd simply falls back to photo proof.
You can revoke Apple Health access at any time in iOS Settings → Privacy & Security → Health → Backd, or Settings → Apps → Backd → Health.
4. How we collect consumer health data, and what we use it for
We collect it only because you take an action that needs it:
- You choose an Apple Health proof type and grant the iOS Health permission → we read steps/workouts on-device and store only the verdict string.
- You choose a location proof type and grant the iOS/Android location permission → we capture one point at check-in and store a rounded coordinate (or, for a goal with a place set, your approximate distance from that place).
- You tap "Use my current location" to set a goal's place → we read your location once and store that point with the goal, rounded to ~11 m.
- You submit a photo or note, or title a goal, that describes health activity → we store that content as your proof.
- You opt in to SMS reminders and provide a phone number → we use it to text you reminders that may include your goal titles.
We use this data only to:
- verify and record your check-ins and outcomes (the core of the app);
- show your progress to you, and to the specific buddy you assign to a goal (per your sharing settings);
- send reminders you turned on; and
- provide the optional AI proof review, only when it is run with your permission (Section 5).
We do not use consumer health data for advertising, for any cross-context behavioral advertising, to train our own profiling models, or to make decisions about your eligibility for anything. Backd has no advertising or attribution SDK installed. It does include two diagnostic/usage SDKs, both used only on our behalf: Sentry, for crash and error reports (the message is redacted and no account id is attached), and PostHog, for a fixed list of named product events linked to your Backd user id (no automatic screen or tap tracking, no session recording, IP-based location lookup off, IP address discarded). Neither receives any health data or location data: no Apple Health verdict or value, no coordinates, no distance from a place, and no goal titles, notes or proof content. One PostHog event — your first proof — records only a coarse proof category (photo, text, or automatic); it never says whether Apple Health or location was used.
5. The AI proof review — the most sensitive flow
Backd offers an optional AI proof review. It runs only when someone taps "Run AI check" on a proof — you, or the buddy reviewing your proof — and only if both that person and you have allowed AI checks (it does not run automatically). Backd then sends our AI vendor exactly this, to return an advisory result:
- the proof image, if there is one;
- the goal title, any proof instructions you set, and your note with the check-in;
- the goal's proof type (for example photo, Apple Health or location), the check-in's deadline and submission time, the proof source the app reported, and, for a goal that requires a live photo, the challenge code.
(In Coach chat, it also sends your free-text messages.) Apple Health check-ins are never sent for an AI check: the app doesn't offer it on them, and the server refuses them. For a location check-in, the note is the location note your buddy sees: a point rounded to about 110 m (for example "Checked in near 40.713, -74.006"), or, for a goal with a place, the place's label, your approximate distance from it and the reading's accuracy. Your full-precision coordinates are never sent. This is our highest-sensitivity data flow because that content can describe or imply health.
- The AI vendor is Hugging Face (Inference Providers), which routes the request to Featherless AI running the open Qwen3-VL-8B-Instruct vision model. As stated in our Privacy Policy (Section 5), neither keeps your photo, goal text or note after returning the result, and neither trains on it.
- The AI result is advisory only — you or your assigned buddy always make the real decision.
- This is a feature you can decline; Backd works without it. Turning AI proof review off in Settings withdraws your permission.
- This is separate from the automatic image-safety screening every uploaded proof photo goes through (Sightengine, image only — see Section 7), which does not use your goal text or note.
We treat the AI vendor as a contract-bound processor/service provider, not as a recipient we "sell" or "share" data with for the vendor's own purposes (see Section 7).
6. Consent: opt-in to collect, and separate consent to share
Under MHMDA, collecting consumer health data requires your consent unless it's strictly necessary to provide a product you asked for, and sharing it requires a separate, additional authorization.
- Collection consent (opt-in). Backd collects consumer health data only after you take an opt-in action — granting the iOS Health permission, granting the location permission, choosing a health/location proof type, opting in to SMS, or allowing AI proof review. The first time you use Apple Health proof, location proof (including "Use my current location" for a goal's place) or AI proof review, Backd shows its own consent screen for that one feature, not bundled with anything else and before any system permission prompt. It says what is read, why, and what is stored, and has a real "Not now". We keep a record of your answer with the version of the screen. We do not collect it by default, and we collect only what is necessary for the feature you chose.
- Connecticut. Connecticut's privacy law treats precise location and consumer health data as sensitive data that needs your opt-in consent before it is used. The same consent screens are how we ask.
- Withdrawing consent. You can withdraw it at any time in Settings on your iPhone (turn off Health or Location access for Backd), and Backd stops collecting that data. Turning AI proof review off in Backd's Settings withdraws that permission.
- Separate consent to share — and we don't share or sell. We do not sell consumer health data, and we do not "share" or "sell" it as those terms are defined under MHMDA, Nevada SB 370, or the CCPA. Because we don't share or sell it, we do not need, and do not ask for, a separate "valid authorization to share." If that ever changes, we will obtain the separate, specific authorization the law requires before any such sharing, and we will update this notice first.
- Buddies / groups are you sharing, not us selling. When proof for an assigned goal is visible to a buddy you chose, that is you directing disclosure to a person you selected — it is not a sale or a third-party share by us.
- Processors are not "sharing." Sending data to the vendors in Section 7 to run the app on our behalf is processing under contract, not a sale or share.
7. Who receives data, and why it is not a "sale" or "share"
We use a small set of vendors strictly as service providers / processors under contract. None of them is permitted to use your data for their own purposes, and we receive no money or other valuable consideration for any disclosure. Accordingly, we do not sell or share your personal or consumer health information.
Who touches consumer health data or precise location:
- Supabase — our first-party backend; stores all account data, proof media, rounded location notes, the distance results of staked location check-ins, goal places and their health-care check results, derived health results (the verdict string), consent records, phone numbers, and message content. For a staked location goal, Backd's server (on Supabase) receives your phone's reading to check it against the goal's place, and keeps only the result and distance.
- Apple Health, on your device — read-only, on device. Apple does not receive your health data through Backd; it stays on your phone.
- Apple Maps — when you set or change a goal's place, receives the coordinates of that place to look for health-care places nearby (Section 10). If you set the place with "Use my current location", that point is where you were. It receives no Apple Health data and no check-in readings. A typed address you look up also goes to your phone's map service to find the place.
- AI vendor (Hugging Face, routed to Featherless AI) — only when the AI review is run with your permission (Section 5): the proof image, goal text, your note (which for a location check-in is the rounded location note or your approximate distance from the place, and for an Apple Health check-in only "Verified via Apple Health."), the proof type, and the check-in's times; and Coach chat.
Who receives other data relevant to this notice (none of these receive Apple Health data or location data):
- Sightengine — automatic image-safety screening; receives each uploaded proof photo (the image only) — no name, email, goal, note or account id — to screen it for nudity/sexual content, gore and violence before your buddy can see it. No Apple Health value is sent, though a photo you submit may itself show health-related activity.
- Sentry — crash and error reports; the message is redacted and no account id is attached. No health data and no location data.
- PostHog — a fixed list of named product events linked to your Backd user id; no health data, no location data, and no goal/note/proof content (see Section 4).
- Twilio — SMS reminders; receives your phone number and goal titles only if you opt in.
- Expo push → Apple (APNs) / Google (FCM) — push token + notification text, to deliver notifications.
- Resend — account emails, such as password resets (the account's email address), and stake emails: a copy of your stake agreement when you turn a stake on and a confirmation when you turn one off, which name the goal and the amount. A goal title you wrote could imply health; no Apple Health value or location is sent.
- RevenueCat — subscriptions; receives your Backd user id as the app-user id. No health data.
- Stripe — only for money stakes; no health or location data.
- Google Calendar / Canvas LMS — only if you connect them, using your authorization/token. No health data is sent to them.
8. Retention and deletion
Retention. We keep consumer health data only as long as needed for the feature you used and your account:
- Derived Apple Health results and rounded location notes are retained with the related check-in, and so are the result and distance of a staked location check-in.
- A goal's place and its health-care check result (whether it passed, when, the point checked, and your confirmation) are kept with the goal and deleted with the goal or your account.
- Your consent records for Apple Health and location are kept while your account exists and deleted with it.
- Proof media is deleted once your proof has been reviewed — shortly after an approval, and after a 48-hour appeal window if the proof was sent back. Your setting in Settings → proof-media retention is the outside limit for a photo nobody reviews: "never store media" means the photo is never uploaded at all, and 30/60/90 days is the point past which it is purged regardless. The check-in record and the review decision remain; only the image is deleted. Exception: a photo that the automatic image-safety screening flagged is held (kept, hidden from your buddy) for a person to review; while under review it is excluded from this schedule and from "Delete all proof media," and if it is reported under 18 U.S.C. § 2258A it is preserved for as long as that law requires (one year). See the retention table in the Privacy Policy for the full statement.
- Raw Apple Health samples are never retained by us — they never leave your device.
Deletion — what exists today. You can delete your data in-app:
- Settings → Delete account runs a server-side Edge Function that removes your proof media from storage and cascades the deletion of all your database rows — including derived health results, rounded location notes, check-ins, goals, proof, and buddy links. This is permanent.
- Settings → Delete all proof media removes stored proof photos while keeping your check-in history (a photo held for safety review is kept until that review ends — see above).
- You can revoke Health or Location permission at any time in your device settings.
You also have the right under MHMDA to request that we delete your consumer health data, including directing our processors to delete it. To make a deletion or other rights request, email support@backd.dev; we will honor it using the in-app deletion mechanism above and by instructing our processors.
What does not exist yet (we will not over-claim):
- There is currently no public web deletion URL — deletion is done in-app or by emailing us.
- An in-app data export exists (Settings → Export data produces a JSON file of your data via the share sheet); there is no separate web-based export portal. For a copy of your data without the app, email support@backd.dev.
9. Your rights
Subject to verification of your request, you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data, and access that data;
- Get a list of the third parties (including processors/affiliates) with whom we have shared or to whom we have sold your consumer health data — for Backd, this is the service providers in Section 7, because we do not sell or share;
- Withdraw consent to our collection and any sharing of your consumer health data;
- Delete your consumer health data (see Section 8); and
- Not be discriminated against for exercising these rights.
How to exercise them. Email support@backd.dev. You may use an authorized agent. We will respond within the timeframe required by law and will not charge you for a first request within the relevant period.
Appeals. If we deny your request, you may appeal by replying to our decision or emailing support@backd.dev with "Appeal" in the subject. If we deny your appeal, you may contact the Washington State Attorney General (for MHMDA) or the Nevada Attorney General (for SB 370).
Washington MHMDA — private right of action
Washington's My Health My Data Act includes a private right of action: a violation of the Act is enforceable as an unfair or deceptive act under Washington's Consumer Protection Act (RCW 19.86), which means an individual consumer may bring a lawsuit in addition to enforcement by the Washington Attorney General. We take this seriously, which is why this notice is written to match Backd's real behavior. If you believe we have mishandled your consumer health data, please contact us first at support@backd.dev so we can address it.
10. We do not geofence around health-care facilities
MHMDA prohibits implementing a geofence around any entity that provides in-person health-care services to identify, track, collect data from, or send notifications to consumers near such a location.
Backd does not do this. Backd:
- captures location only as a single point at the moment you tap to check in for a location-proof goal you set up, or when you tap "Use my current location" to set a goal's place — never in the background;
- does not create any geofence around hospitals, clinics, pharmacies, reproductive- or sexual-health facilities, mental-health or substance-use facilities, or any other health-care provider;
- refuses health-care places as goal places (below);
- does not track, target, or notify you based on proximity to any health-care facility; and
- rounds stored location to ~110 m and strips GPS/EXIF metadata from proof photos before upload, so a stored check-in does not pinpoint you. (A goal place set from your current location is stored rounded to ~11 m, and a check-in against a goal place records only your approximate distance from it, e.g. "~37 m".)
Any "be at / avoid this place" rule is a place you configure for your own goal (e.g., your gym or library), evaluated only against the single point you capture at check-in.
Health-care places can't be goal places
Washington's law bans a geofence around a place that provides in-person health care when it is used to collect health data or track people seeking care, and consent doesn't change that. Backd never lets a health-care provider be a goal's place. When you set or change a location goal's place:
- Backd sends the place's coordinates to Apple Maps and looks for a health-care provider at the place itself: within 100 m of the point you chose (allowing for GPS and map error), places Apple Maps lists as hospitals or pharmacies, and places whose names show a clinic, urgent care, doctor, dentist, therapist, medical or health center, lab or similar provider. The place's own name or label is checked the same way.
- If it finds one, Backd refuses the place. Choose a different place for the goal. A place that merely sits near a provider, like a gym down the street from a clinic, isn't refused: the goal's geofence is around the gym, not the clinic.
- You also confirm one line: "This place isn't a health-care provider."
- Backd saves the result with the goal's place: whether it passed, when, the point checked, and your confirmation.
- Backd's server won't accept a location-checked stake whose place hasn't passed the check for its current point.
- A place saved before October 1, 2026 is checked the next time it's used for a location check-in.
11. Children and students
Backd's audience includes students, and some users may be under 13. A birth-year age gate is live in every current build and blocks self-registration outright for a stated birth year under 13 — there is no verifiable-parental-consent path, so no under-13 user can reach the Health proof feature (or any feature) at all. The age question is a neutral year picker with no preset value and no hint about any age limit; a blocked person's birth year is discarded, and an account Sign in with Apple had already created is deleted with its data. Where Apple's age signal is available, the same block applies when Apple says a user is under 13. Backd is not directed to children under 13. We do not knowingly collect consumer health data from a child under 13.
12. Changes to this notice
If we materially change how we handle consumer health data, we will update this notice and revise the effective date above, and — where the law requires — obtain your consent before the new use.
13. Contact
Questions or requests about consumer health data:
- Email: support@backd.dev
- Mail: Anson Antony, the developer of the Backd app, 1742 SW 38th Terrace, Gainesville, FL 32607
- Governing law: Florida, as our Terms of Service (Section 16) state. That choice doesn't take away any right you have under Washington's My Health My Data Act, Nevada SB 370, or another law of the place where you live that can't be given up by agreement.