Backd — Consumer Health Data Privacy Policy

Effective date: October 1, 2026 · Last updated: October 2, 2026

This is a standalone, distinctly-linked notice about how Backd ("Backd," "we," "us") handles consumer health data under the Washington My Health My Data Act ("MHMDA") and Nevada SB 370. It supplements, and does not replace, our general Privacy Policy. Where this notice and the general Privacy Policy conflict on a question of consumer health data, this notice controls.

Backd is an accountability app: you set goals and submit photo or text proof of doing them, and you can share progress with buddies or groups. We wrote this notice to describe what Backd actually does, not a worst case. If you spot anything here that doesn't match your experience in the app, please tell us at support@backd.dev.

Backd is provided by Anson Antony, the developer of the Backd app. Backd is an app made by an individual, and business is done in his legal name; "Backd," "we" and "us" in this notice mean him. Our postal address is 1742 SW 38th Terrace, Gainesville, FL 32607.


1. Who this notice is for

This notice applies to you if you are a Washington consumer or a Nevada consumer under those states' health-data laws (broadly, an individual who is a resident of, or whose health data is collected in, that state, and who is acting in a personal/household capacity rather than as an employee or contractor). It also describes our practices generally, so consumers in other states can understand them too.


2. What "consumer health data" Backd actually touches

"Consumer health data" under these laws is personal information linked or reasonably linkable to a consumer that identifies that consumer's past, present, or future physical or mental health status. Importantly, this can include data that is not obviously medical — including precise location and activity data that could reveal or imply health (for example, that you went to a gym, a clinic, or a recovery meeting). Because of that broad definition, we treat the following Backd data as consumer health data, or as data that could be inferred to relate to health:

DataWhat it is in BackdWhere it goes
Apple Health resultThe result "Verified with Apple Health", recording that Apple Health confirmed the check-in. No health value: no step count, no workout count, no measurement of any kind.Stored with the check-in in your Backd account (Supabase) and shown to the buddy who reviews it. Your steps and workouts are shown only to you, on your device, and are never transmitted. See the on-device note below.
Apple Health raw samplesYour underlying step and workout samples in Apple Health.Never leave your device. See Section 3.
Precise location at check-inA single GPS point captured only at the moment you tap to check in for a location-proof goal, to confirm you were at a place (gym, library, class) — or, if you use it, once when you tap "Use my current location" to set a goal's place.A rounded coordinate (~110 m / 3 decimals) is stored as the check-in's proof note (Supabase). Full precision is never stored. A goal place set from your current location is stored with the goal rounded to ~11 m (4 decimals), and a check-in against a goal place records only your approximate distance from it (for example, "~37 m") in the note your buddy sees. On a goal backed by a stake, your phone sends its reading to Backd's server, which keeps only the result and distance, not the coordinates. When you set or change a goal's place, the place's coordinates go to Apple Maps for the health-care check (Section 10). No background tracking.
Health-implying proof contentPhotos or free-text notes you choose to submit as proof, plus goal titles, which may describe health or fitness activity (e.g., "ran 5k," "took my meds," "therapy").Stored as your user-generated content (Supabase). Shared only with the specific buddy you assign to a goal, per your settings. Each uploaded proof photo (the image only) is automatically screened by our image-safety provider, Sightengine, before your buddy can see it.
Phone number (if you opt in to SMS)Used for SMS reminders.Not health data by itself, but may be paired with goal titles that imply health. See Section 4.

What we do not collect: We do not request or store Apple Clinical Health Records / medical records, diagnoses, prescriptions, lab results, or any Apple Health data beyond step count and workout read access. We do not infer health conditions, we do not build a health profile about you, and we do not track your location in the background.


3. Apple Health stays on your device

When a goal offers an Apple Health proof type and you choose it, Backd asks iOS for read-only access to your step count and workouts. If you grant it:

You can revoke Apple Health access at any time in iOS Settings → Privacy & Security → Health → Backd, or Settings → Apps → Backd → Health.


4. How we collect consumer health data, and what we use it for

We collect it only because you take an action that needs it:

We use this data only to:

We do not use consumer health data for advertising, for any cross-context behavioral advertising, to train our own profiling models, or to make decisions about your eligibility for anything. Backd has no advertising or attribution SDK installed. It does include two diagnostic/usage SDKs, both used only on our behalf: Sentry, for crash and error reports (the message is redacted and no account id is attached), and PostHog, for a fixed list of named product events linked to your Backd user id (no automatic screen or tap tracking, no session recording, IP-based location lookup off, IP address discarded). Neither receives any health data or location data: no Apple Health verdict or value, no coordinates, no distance from a place, and no goal titles, notes or proof content. One PostHog event — your first proof — records only a coarse proof category (photo, text, or automatic); it never says whether Apple Health or location was used.


5. The AI proof review — the most sensitive flow

Backd offers an optional AI proof review. It runs only when someone taps "Run AI check" on a proof — you, or the buddy reviewing your proof — and only if both that person and you have allowed AI checks (it does not run automatically). Backd then sends our AI vendor exactly this, to return an advisory result:

(In Coach chat, it also sends your free-text messages.) Apple Health check-ins are never sent for an AI check: the app doesn't offer it on them, and the server refuses them. For a location check-in, the note is the location note your buddy sees: a point rounded to about 110 m (for example "Checked in near 40.713, -74.006"), or, for a goal with a place, the place's label, your approximate distance from it and the reading's accuracy. Your full-precision coordinates are never sent. This is our highest-sensitivity data flow because that content can describe or imply health.

We treat the AI vendor as a contract-bound processor/service provider, not as a recipient we "sell" or "share" data with for the vendor's own purposes (see Section 7).


6. Consent: opt-in to collect, and separate consent to share

Under MHMDA, collecting consumer health data requires your consent unless it's strictly necessary to provide a product you asked for, and sharing it requires a separate, additional authorization.


7. Who receives data, and why it is not a "sale" or "share"

We use a small set of vendors strictly as service providers / processors under contract. None of them is permitted to use your data for their own purposes, and we receive no money or other valuable consideration for any disclosure. Accordingly, we do not sell or share your personal or consumer health information.

Who touches consumer health data or precise location:

Who receives other data relevant to this notice (none of these receive Apple Health data or location data):


8. Retention and deletion

Retention. We keep consumer health data only as long as needed for the feature you used and your account:

Deletion — what exists today. You can delete your data in-app:

You also have the right under MHMDA to request that we delete your consumer health data, including directing our processors to delete it. To make a deletion or other rights request, email support@backd.dev; we will honor it using the in-app deletion mechanism above and by instructing our processors.

What does not exist yet (we will not over-claim):


9. Your rights

Subject to verification of your request, you have the right to:

How to exercise them. Email support@backd.dev. You may use an authorized agent. We will respond within the timeframe required by law and will not charge you for a first request within the relevant period.

Appeals. If we deny your request, you may appeal by replying to our decision or emailing support@backd.dev with "Appeal" in the subject. If we deny your appeal, you may contact the Washington State Attorney General (for MHMDA) or the Nevada Attorney General (for SB 370).

Washington MHMDA — private right of action

Washington's My Health My Data Act includes a private right of action: a violation of the Act is enforceable as an unfair or deceptive act under Washington's Consumer Protection Act (RCW 19.86), which means an individual consumer may bring a lawsuit in addition to enforcement by the Washington Attorney General. We take this seriously, which is why this notice is written to match Backd's real behavior. If you believe we have mishandled your consumer health data, please contact us first at support@backd.dev so we can address it.


10. We do not geofence around health-care facilities

MHMDA prohibits implementing a geofence around any entity that provides in-person health-care services to identify, track, collect data from, or send notifications to consumers near such a location.

Backd does not do this. Backd:

Any "be at / avoid this place" rule is a place you configure for your own goal (e.g., your gym or library), evaluated only against the single point you capture at check-in.

Health-care places can't be goal places

Washington's law bans a geofence around a place that provides in-person health care when it is used to collect health data or track people seeking care, and consent doesn't change that. Backd never lets a health-care provider be a goal's place. When you set or change a location goal's place:


11. Children and students

Backd's audience includes students, and some users may be under 13. A birth-year age gate is live in every current build and blocks self-registration outright for a stated birth year under 13 — there is no verifiable-parental-consent path, so no under-13 user can reach the Health proof feature (or any feature) at all. The age question is a neutral year picker with no preset value and no hint about any age limit; a blocked person's birth year is discarded, and an account Sign in with Apple had already created is deleted with its data. Where Apple's age signal is available, the same block applies when Apple says a user is under 13. Backd is not directed to children under 13. We do not knowingly collect consumer health data from a child under 13.


12. Changes to this notice

If we materially change how we handle consumer health data, we will update this notice and revise the effective date above, and — where the law requires — obtain your consent before the new use.

13. Contact

Questions or requests about consumer health data: