1. What this policy covers
This policy explains what data the Bakyasri service collects from you, why it collects that data, how long it is kept, and what your rights are over it. It applies to the web product, the mobile applications, and any camera-connected rigs installed at a gym that use the service.
2. What we collect, and why
2.1 Camera feed
The pose model that measures your form runs on the device where the camera is - your phone, your laptop or the gym floor rig. Raw video is not uploaded from that device by default. Only joint-coordinate data - the numeric position of your joints per frame - leaves the device.
If, for a specific feature such as a coaching review, you choose to record a workout, that video is stored under your account with an explicit label and can be deleted at any time.
2.2 Pose and workout data
We keep the derived pose events - joint angles, form scores, rep counts, drift flags - so the product can measure trends across your workouts and adapt your plan. These records are tied to your account.
2.3 Account information
Name, email address, chosen account type, billing information where applicable, and the workout history we record on your behalf. In gym deployments, your trainer and floor manager can also see summarised form data on the trainer dashboard, under a role-based access model.
2.4 Technical logs
Standard server logs - device type, IP address, request times - so we can keep the service reliable and secure. We do not sell logs, and we do not use them to build advertising profiles.
3. What we do not do
- We do not sell your data to advertisers.
- We do not use your workout data to train third-party models.
- We do not upload camera video from your device by default.
- We do not read camera feeds outside a workout session.
- We do not identify individuals across gyms without your account link.
4. Retention
Pose event records are retained for twelve months by default, so the adaptive plan has enough history to work from. Optional recorded workouts you save are kept until you delete them, or until your account is closed. Billing records are kept for the period required by the applicable statutory retention rules.
5. Encryption and access
All data in transit is protected with TLS 1.2 or higher. Data at rest in our production data store is encrypted using AES-256. Access to production data is limited to a small number of engineers under a documented least-privilege policy.
6. Sub-processors
We use a small set of infrastructure and communication vendors to run the service - a cloud infrastructure provider for hosting and storage, a transactional email provider for account and system messages, and a payment processor where billing applies. Contracted terms with these vendors reflect the standards described above.
7. Gym deployments
In gym deployments, the gym is a joint controller of the member data it uploads into the product. The gym decides who at the club can see the trainer dashboard, and configures the roles. We provide the tools; the gym operates the day-to-day access controls at the club level.
8. Your rights
You can:
- Request a copy of your account data.
- Request correction of inaccurate account information.
- Delete your account, which triggers deletion of your pose data outside statutory retention obligations.
- Withdraw consent for optional data, such as saved recorded workouts.
To exercise any of these rights, reach out through the contact page.
9. Children
The service is not directed at children under 16. We do not knowingly collect data from anyone under 16. If a gym enrolls a member under 16, parental or guardian consent is required by the gym before pose data is captured.
10. Changes to this policy
If we change this policy in a way that materially affects how your data is handled, we will notify you through your account or by email before the change takes effect.