Effective date: 1st August 2026
Last updated: 20th August 2026
This Privacy Policy explains how Built Late PTY LTD ("Built," "we," "us," or "our") collects, uses, discloses, and protects information when you use the Built mobile application (the "App"). By creating an account or using the App, you agree to the collection and use of information in accordance with this Policy.
Built is a fitness and nutrition tracking app that helps you log workouts, track food and macros, monitor body metrics (like weight, steps, and sleep), and receive AI-generated coaching suggestions based on your own data. This Policy is written to reflect exactly what the App does - no more, and no less.
1. Information We Collect
1 .1 Account Information
When you create an account, we collect:
- Display name.
- Profile photo / avatar, if you choose to upload one (stored in cloud storage and served via a public URL).
- If you use Sign in with Apple: your Apple-issued identifier and the identity token Apple provides. We do not receive your Apple ID password. If you choose to hide your email through Apple's "Hide My Email" feature, we only receive the private relay address Apple generates.
- If you use Sign in with Google: your Google-issued identifier and the identity token Google provides. We do not receive your Google ID password or any other identifying data other than your email.
1 .2 Onboarding & Health Profile Information
Before creating an account, the App asks a series of onboarding questions to calculate a personalised calorie and macro plan. Once you finish onboarding and create an account, we store your answers, including:
- Biological sex (male / female / other), birth date, height, and starting body weight - used in a standard BMR formula (Mifflin–St Jeor) to calculate your calorie and macro targets.
- Fitness goal (lose, maintain, or gain weight), desired weight, and target pace (e.g., rate of weight change per week).
- Typical weekly workout frequency.
- Self-reported obstacles to your goals (e.g., time constraints, cravings) - used only to help tailor in-app coaching language, never shown back to you as raw data or shared externally.
- How you heard about the App and whether you've tried similar apps before (attribution information; never displayed within the App itself).
We keep these answers on file (rather than discarding them after the initial calculation) so that your targets can be recalculated as your weight changes over time, and so that in-app AI coaching can be tailored to what you've told us. You are not required to provide any of this information beyond what is necessary to use core features, but declining to answer will limit the App's ability to personalise your plan.
This information is sensitive information under Australian Privacy Principle (APP) 3.3. We only collect it with your consent, given by completing the onboarding flow, and we only use it for the purposes described in this Policy - calculating and personalising your targets and in-app coaching. We do not use it for any other purpose without asking you again.
1 .3 Nutrition & Food Data
- Daily food logs: meals, food items, quantities, and their calories/macros (protein, carbs, fat, and, where available, micronutrients like fiber, sugar, sodium, vitamins, and minerals), organised by day and meal type.
- Custom foods you create manually, including nutrition label information you enter (and, if applicable, barcode).
- Saved meals - named combinations of food items you can re-log with one tap.
- Food search and logging history, used to power "recent" and "frequent" food suggestions.
- Barcode scans and food photos, captured with your device camera (see Section 1.6).
- Daily wellness metrics: water intake, step count, body weight, and sleep hours, which you can enter manually or (for steps and sleep) sync automatically from Apple Health.
- Nutrition and wellness goals: calorie, macro, water, step, sleep, and weight goals you set, plus preferences like whether to "add back" calories burned during logged workouts.
1 .4 Workout & Fitness Data
- Workout templates and folders you create (names, exercises, estimated duration, organisation/order).
- Workout sessions you log, including exercise names, sets, reps, weight lifted, set type, and session duration.
- Weekly workout schedule (which template, if any, is assigned to each day of the week).
1 .5 Subscription & Payment Information
Built offers a free trial followed by a paid subscription. We use RevenueCat to manage subscriptions and Apple's App Store to process payments.
- We store your subscription status (trial, active, canceled, or expired), billing period (e.g., monthly/yearly), and relevant dates (trial start/end, current billing period).
- We do not collect or store your payment card details. All billing is handled directly by Apple through your App Store account. RevenueCat receives your App Store transaction/receipt data and an internal user identifier (derived from your account) to validate purchases and report entitlement status back to us.
1 .6 Camera & Photos
- If you use barcode scanning to log food, the barcode is read on-device and sent to our food-lookup service to retrieve nutrition information.
- If you use food photo recognition, the photo you capture is sent securely to our backend, which forwards it to a third-party AI image recognition provider for the sole purpose of identifying food items in the image. The photo is used only to generate a list of identified food names and confidence scores; it is not permanently stored by us or knowingly retained by the AI provider beyond what is necessary to process the request.
- If you upload a profile photo, it is stored securely in our cloud storage and used solely to display your avatar within the App.
1 .7 Apple Health (HealthKit) Data
With your explicit permission (requested via the standard iOS Health permission prompt), the App can:
- Read your step count and sleep analysis data from Apple Health to automatically populate your daily activity and sleep logs.
- Write your logged body weight to Apple Health, if you choose to save it there.
We do not use HealthKit data for advertising, marketing, or any purpose unrelated to the health and fitness features you use within the App, and we do not sell HealthKit data to third parties or data brokers. HealthKit data is only used to power the features described above and, in aggregate/derived form, may be included in the data summarised for the optional AI coaching feature described in Section 1.8. You can revoke Health access at any time in the iOS Settings app under Privacy & Security → Health → Built.
1 .8 AI-Generated Coaching Suggestions
The App includes a feature that generates personalised coaching suggestions using a third-party AI language model. When you request suggestions:
- The App sends a summary of your recent (up to 90 days) food logs, workout sessions, wellness metrics, and goals - along with findings the App has already computed locally (e.g., identified "wins," "blockers," and consistency scores) - to our backend, which forwards this summary to that provider's API.
- The provider processes this data solely to generate the text of your coaching suggestions and returns it to the App for display. This feature is rate-limited (3 requests per day) to control cost and usage.
- No directly identifying information (such as your name or email) is included in the data sent to the provider - only your fitness and nutrition data summaries.
1 .9 Information Collected Automatically
- Usage/technical data inherent to standard app operation, such as IP address and request metadata processed transiently by our backend infrastructure (Supabase) and its underlying cloud hosting provider, and by third-party APIs when you perform actions like food search.
- Rate-limiting records: an internal counter of how many times you've called certain features (e.g., food search, barcode scan, AI suggestions) within a time window, used only to prevent abuse.
- Advertising conversion measurement (Meta Pixel). We use Meta's Pixel/Conversions API to measure the performance of our own advertising campaigns - for example, to see whether someone who saw or clicked one of our ads went on to install the App or start a subscription. This sends limited event data (such as the fact that an install or purchase occurred) along with identifiers like your device's advertising ID, or a hashed version of your email if you complete a purchase, to Meta. We do not upload your personal information to Meta to build audiences or lookalike audiences, and this data is used only to measure our own ad performance - not for any other purpose.
Aside from the advertising conversion measurement described above, we do not use third-party analytics/tracking SDKs or cross-app/cross-site tracking technologies, and we do not display third-party ads in the App.
1 .10 Voice & Natural Language Logging
The App lets you log workouts and food using spoken or typed natural language (e.g., "3 sets of bench press at 80kg" or "chicken wrap for lunch") instead of manual form entry.
- If you use voice input, speech-to-text conversion happens on your device - we do not receive or transmit raw audio recordings of your voice.
- The resulting text is sent to our backend, which forwards it to a third-party AI language model provider to parse it into structured log entries (exercises, sets/reps/weight, or food items/quantities). This may be a different provider than the one described in Section 1.8. The parsed result is then saved to your account the same way a manually entered log would be.
- Once parsing is complete, only the resulting structured log data is retained - the transcribed text itself is not stored beyond what's needed to process the request.
2. How We Use Your Information
We use the information described above to:
- Create and manage your account and authenticate you.
- Calculate and update your personalised calorie, macro, water, step, sleep, and weight targets.
- Let you log, view, and edit your food, workouts, and wellness data across sessions and devices.
- Power search and recommendation features (e.g., recent/frequent foods, food database search, barcode/photo recognition).
- Generate AI-powered coaching suggestions.
- Process and manage your subscription, free trial, and billing status.
- Maintain the security, integrity, and reliability of the App (e.g., rate limiting, fraud prevention, debugging).
- Communicate with you about your account (e.g., password reset emails, email change confirmations).
- Comply with legal obligations.
We do not sell your personal information, and we do not use your health, nutrition, or fitness data to serve you advertising, either within the App or elsewhere.
3. Who We Share Information With
We share information only as necessary to provide the App's functionality, and never for advertising purposes.
Our service providers ("subprocessors") include:
Supabase
Backend database, authentication, file storage, and serverless functions
All account, profile, nutrition, workout, and subscription data described above (Supabase is our primary data processor and host)
Apple
Sign in with Apple; App Store subscription billing; Apple Health integration
Apple ID identity token (if used); App Store purchase/transaction data; HealthKit data (only with your permission, and only on-device/through Apple's frameworks)
RevenueCat
Subscription and entitlement management
An internal user identifier; App Store purchase/transaction and entitlement data
Third-party AI language model provider (coaching)
Generates AI coaching suggestion text
De-identified summaries of your recent food, workout, and wellness data (see Section 1.8)
Third-party AI language model provider (voice/text logging)
Parses voice/natural-language log entries into structured food and workout data
Transcribed text from voice/natural-language logging (see Section 1.10)
Third-party AI image recognition provider
Identifies food items in photos you choose to submit
The photo you submit for food recognition
Third-party food database
Food nutrition database search results
Your search query or scanned barcode (not your account identity, beyond what's inherent in an authenticated API call routed through our backend)
Meta (Meta Pixel / Conversions API)
Measures the performance of our own advertising campaigns
Install/purchase event data and associated identifiers (e.g., advertising ID, or a hashed version of your email for purchase events) - see Section 1.9
We may also disclose information if required to do so by law, subpoena, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.
We do not sell your personal information to third parties. Aside from the limited advertising conversion measurement described in Section 1.9 - which we use solely to measure our own ad performance, not to build audiences or profiles about you - we do not share your information with third parties for their own advertising or marketing purposes.
If Built is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will notify you of any such change and any resulting change in how your information is handled.
4. Data Storage & Security
- Your data is stored in a managed Postgres database (via Supabase) protected by row-level security policies, meaning the database itself enforces that you can only access your own records - no user can query another user's data through the API.
- Data in transit is encrypted via HTTPS/TLS. Passwords are hashed, never stored or transmitted in plain text.
- Sensitive operations (e.g., permanently deleting an account, managing subscriptions, calling AI features) are performed through server-side functions using credentials that are never exposed to the App or your device.
- Profile photos are stored in a storage bucket where you may only write to a folder scoped to your own account.
While we take reasonable technical and organisational measures to protect your information, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
Data breach notification. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.
5. Data Retention
We retain your information for as long as your account is active, so that the App can function (e.g., recalculating targets, showing your history, powering AI coaching). If you delete your account:
- Your profile, onboarding answers, nutrition goals, food logs, custom foods, saved meals, workout templates/sessions/schedule, subscription record, and avatar image(s) are permanently deleted from our active systems, generally within a short period of initiating deletion.
- Some information may be retained where required by law (e.g., transaction records Apple or RevenueCat are obligated to retain for tax, accounting, or fraud-prevention purposes), or in encrypted backups for a limited period, after which it is purged in the ordinary course of backup rotation.
- Aggregated or de-identified information that can no longer be linked to you may be retained indefinitely (e.g., a food item you searched for may remain in a shared, non-personal food database cache used to speed up search for all users, but this cache does not retain any link to your account).
6. Your Rights and Choices
- Access & correction: You can view and edit most of your data directly in the App (profile, goals, logs, workouts, etc.).
- Deletion: You can permanently delete your account and all associated personal data at any time from within the App's account settings. This action is irreversible.
- Health data permissions: You can revoke the App's access to Apple Health at any time via iOS Settings → Privacy & Security → Health → Built.
- Camera/Photo permissions: You can revoke camera access via iOS Settings → Built → Camera. Declining will disable barcode scanning and photo-based food recognition, but you can still log food manually.
- Marketing communications: We do not send marketing emails unrelated to your account (e.g., we only send transactional emails like password resets or email-change confirmations).
- Depending on your jurisdiction (e.g., under the GDPR, UK GDPR, or California's CCPA/CPRA), you may have additional rights, including the right to request a copy of your data, request correction or deletion, object to or restrict certain processing, and lodge a complaint with a supervisory authority. To exercise these rights, contact us using the information in Section 11.
- Complaints (Australia): If you're not satisfied with how we've handled your personal information, contact us first using the details in Section 11 and we'll respond within a reasonable time. If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
7. Children's Privacy
Built is not directed to, and is not intended for use by, children under the age of 13 (or the minimum age required in your jurisdiction, e.g., 16 in certain regions). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
8. International Data Transfers
Our service providers - listed with the categories of data each receives in Section 3 - may store or process data in countries other than your own, including the United States and Australia. Where required, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for such transfers.
9. Third-Party Links and Services
The App integrates with third-party food databases to return nutrition search results. These providers' own privacy practices govern the data they process on their end. We encourage you to review their respective privacy policies if you have questions about how they handle search queries.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. If we make material changes, we will notify you through the App or by other reasonable means before the changes take effect. The "Last updated" date at the top of this Policy indicates when it was last revised.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us at:
Built Late PTY LTD
Email: contact@usebuilt.app
Address: PO BOX 186, Pottsville, NSW 2489 Australia.