BAD KARMA Privacy Policy Product: bad-karma/core Version: 2.4 Effective: September 30, 2026 1. Scope and current release This Privacy Policy explains how the BAD KARMA application and related services (the "App") collect, use, store, share, and delete information. The App provides personal fitness, nutrition, training, and optional Crew features. Billing checkout is not active in this release. Statements below about billing are identified as future or intended behavior. BAD KARMA is not presented as a HIPAA covered health care provider or health plan. That does not remove other privacy, security, breach-notification, or consumer-protection obligations that may apply. 2. Information you provide Account information may include your email address, display name, initials, authentication records, and account identifiers. Private fitness and wellness information may include training sessions, exercise history, Food entries, calorie and macronutrient data, bodyweight and measurements, goals, and related private settings. Food, bodyweight, and training data may sync privately to cloud storage for an authenticated account. Medication administration logs, hunger entries, and progress photos are currently kept in local app state unless you export them. They are not intentionally shared with Crew. An export you create is controlled by you. Crew and shared information may include Crew membership and roles, display identity, training summaries you choose to share, status, messages, reactions, invitations, and other shared activity. Crew content is separate from private account data and is visible to authorized Crew members according to the feature's access controls. Private Heckle media may include audio or video you deliberately record and send to an intended recipient. It is stored in private object storage for its controlled delivery lifecycle. Metadata needed to deliver, expire, prove deletion, and investigate failures may be processed separately. 3. Technical and security information We process information needed to operate and secure the App, such as session and authentication tokens, device or browser attributes, app version, timestamps, network and error metadata, rate-limit data, and pseudonymous security or fraud signals. If you enable Crew notifications, we also store a push subscription for your device: an endpoint address and delivery keys issued by your browser or operating system so our notification service can deliver Crew activity to that device. A push subscription identifies your device for delivery only, does not contain your name, and is removed when you disable notifications on that device or when delivery permanently fails. We do not need full private Food, bodyweight, or training payloads in routine operational logs. 4. How information is used We use information to authenticate accounts; operate local, private, and Crew features; sync authorized private data; deliver user-requested Heckles; maintain reliability and security; diagnose failures; enforce access controls; comply with law; and support account, legal acceptance, and, if later activated, billing and deletion workflows. We do not sell personal information or use private health and fitness information for third-party advertising. 5. Cloud storage, local storage, and revisions Some data remains in browser or installed-app storage on a device. Some authenticated private data, including Food, bodyweight, and training data, may sync to private cloud database records. Shared Crew data is stored in cloud systems so authorized Crew members can use it. Private Heckle media is stored in private object storage. Safety backups, replacement snapshots, synchronization revisions, tombstones, and recovery records may exist during ordinary operation. They are used to prevent accidental loss, resolve conflicts, or prove lifecycle state. The account deletion contract treats private user-content backups and revisions as deletion targets where applicable; operational migration or schema evidence that does not identify a user is treated separately. 6. Service providers and disclosures We use service providers for app hosting, authentication, database, private object storage, network delivery, and reliability. If paid checkout is activated later, a payment processor will process payment and subscription information. We may disclose information when required by law, to protect rights or safety, to investigate abuse or security incidents, or as part of a business transfer subject to applicable protections. Crew content is shared with authorized members as directed by the feature and your actions. Private account data is not Crew content merely because you belong to a Crew. Crash reports. When the app hits an error, it sends a short crash report to Sentry, a service we use to find and fix bugs. A report holds the type of error, a short error message with personal details removed, which part of our code failed, the app version, the screen you were on, and your browser and device type. It never includes your name, email, account id, crew, food, workouts, weights, messages, photos, or the web address you were on, and we ask Sentry not to store your IP address. 7. AI Features BAD KARMA uses Anthropic's Claude API to provide AI Coach and AI Food features. When you use these features, BAD KARMA sends Anthropic your request and a limited amount of relevant app information needed to generate the response. Depending on the feature, this may include your training program, training and workout history, adherence information, nutrition and body-composition information, recovery information already recorded in BAD KARMA, goals, Coach memory notes you chose to save, food descriptions, and sanitized food images. We limit what is sent to Anthropic. We do not send authentication tokens, email addresses, billing information, Crew messages or Heckles, medication or dose information, private notes other than the Coach memory notes described below, progress photos, or original image metadata. Anthropic currently retains API inputs and outputs for up to 30 days under our organization's API retention setting, subject to its policies and limited legal, safety, and security exceptions. Anthropic does not use commercial API inputs or outputs to train its models by default. AI Coach can suggest changes to your training plan. A suggestion changes nothing until you review it and tap Apply, and you can undo it. AI Coach only changes your plan from today forward and never edits past workouts, Food, or Crew data. AI Food produces a proposal that you must review and explicitly apply before your nutrition log changes. Coach memory. If you ask AI Coach to remember something, such as a goal, your schedule, your equipment, or something to work around like a sore shoulder, we store that note privately with your account and send it to Anthropic with your AI Coach requests. You can see, edit, and delete these notes in Settings, and they are deleted with your account. 8. Billing and retention No Stripe checkout, charge, subscription, or billing portal is active in this Stage D release. If billing is later activated, payment-card details are intended to be handled by the payment processor rather than stored as full card data in BAD KARMA systems. Billing and accounting records may later be retained for seven years. Security and fraud records may later be retained for 12 months after the relevant event or investigation closes. Deletion receipts may be retained for 30 days. Non-user-identifying migration and schema evidence may be retained indefinitely. These periods describe the frozen later-stage retention contract and do not imply that inactive billing events have occurred. Other data is retained as needed to provide the current service, preserve integrity, meet legal obligations, resolve disputes, or enforce agreements. Local data remains until the user resets it, imports replacement data, clears app storage, or loses that storage. 9. Reset this device Reset this device removes or replaces local device state according to the screen shown before confirmation. It does not delete the authenticated account or guarantee deletion of cloud records, backups, revisions, Crew content, or private object storage. Cloud data may sync back after sign-in. Export data you need before resetting. 10. Account and cloud-data deletion You can delete your account and cloud data in Settings, Account & privacy, Delete account. You confirm with a code sent to your email and by typing DELETE. Deletion signs you out everywhere and removes your login, profile, private cloud data (including synced food, bodyweight and training data, private backups and revisions), your Heckle media and photos, and your karma, reactions, votes and Crew memberships. If you own a Crew, ownership passes to the member who has been in it longest; a Crew with no other members is deleted. If a paid subscription that can still renew exists, deletion waits until it is cancelled, and deletion does not create an automatic refund. Shared Crew history may survive in de-identified form so another person's history and conversation context are not erased. Private media deletion must include exact deleted-path acknowledgement and independent absence proof before account deletion can be marked complete. A deletion receipt may remain for 30 days as described above. 11. Your choices You can view current Terms and Privacy versions in Settings, export local app data, change optional settings, sign out, and reset this device. The in-app export covers app data stored on that device; a self-serve export tool for cloud-synced data is not yet available, and you can request a copy of your cloud-synced data or Crew content you posted by contacting us. You can choose whether to share specific Crew content and whether to record or send a Heckle. Depending on applicable law, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information. You can delete your account in the app at any time, or contact us for other requests. 12. Security We use access controls, private storage, row-level database restrictions, minimized runtime privileges, and other safeguards appropriate to the service. No storage or transmission method is completely secure. If an incident occurs, we will assess and respond under applicable requirements. 13. Children The App is intended for adults. You must be at least 18 years old, or the age of majority where you live if higher. We do not knowingly offer the App to children. 14. International processing Service providers may process information in locations different from where you live. We use them to operate the App subject to applicable contractual and legal requirements. 15. Material changes and acceptance The current required tuple binds product ID, Terms version, Privacy version, the exact SHA-256 hash of each canonical document, timestamp, and explicit acceptance method. A material change requires a new versioned acceptance. Continued use, navigation, or a prior timestamp-only acceptance does not accept materially changed policy bytes. 16. Contact Questions or privacy requests can be sent to bmayo7@gmail.com.