Security principles

Protection starts with
a clear product boundary.

BestBody treats health and fitness information as personal data. Access, sharing and connected-data permissions should remain proportionate to the feature a person has chosen to use.

Last reviewed: 12 September 2026. This page explains the public security boundary without publishing operational information that could make protections easier to defeat. It does not claim an external certification or independent security audit.

Accounts and public forms are different boundaries

The public contact and access forms do not accept an account password or payment details. Submitted fields are validated and length-limited before processing. Never send a password, access token or payment information through a BestBody public form.

Connected data requires permission

Apple Health and Android Health Connect data is accessed only after the relevant platform permission is granted. A person can review or withdraw those permissions through the originating platform settings. BestBody does not imply direct access to every wearable brand or every data category.

Sharing remains deliberate

Individuals choose what to share with a coach for that relationship. Team wellbeing views are designed around suitable aggregate participation rather than exposing a member’s private weight, meals or health records. Sharing choices should be reviewed before they are enabled.

Provenance supports data integrity

Food, activity and health records retain source and timing context where relevant so reference values, user edits, device estimates and AI-assisted interpretation can be distinguished. No security control, sensor reading or data source is presented as infallible.

Security is an ongoing practice

Threats, platforms and the product can change. Security therefore requires continuing review, careful handling of reports and clear user choices rather than a one-off badge. More implementation detail will be published only where it helps users without weakening the boundary.

Report a concern

Use the contact page and choose “Security concern”. Do not include passwords, access tokens, medical information or live exploit details in the initial message. The BestBody team can arrange an appropriate route for sensitive technical detail.

Also read Privacy, Data Sources, Safety and Limitations.