Privacy Policy

Version 2026-08-26 · Effective August 26, 2026

BodIworK is owned and operated by Things I Work LLC ("we", "us"). This Privacy Policy explains what information BodIworK collects, why, and the choices you have. BodIworK is currently an invitation-only pilot. Where practices differ between clients and practitioners, we call that out.

Information we collect

When you book a session (clients):

  • Your name, phone number, and email address, provided at the time of booking.
  • Booking details: session date and time, service, notes you include, and booking status.
  • Session amounts and tips your practitioner records after a session, for their own bookkeeping. BodIworK does not process payments between practitioners and clients during the pilot, and never stores payment card data.

If you create a BodIworK account:

  • Your display name, email address, and profile image, obtained through Google Sign-In, and your Google account identifier, used to identify your account.
  • Your phone number, if you choose to verify it.
  • Profile details you add, such as a bio or photo.

For practitioners, additionally:

  • Business location information (address, city, state, ZIP).
  • Professional details: modalities, specialties, certifications, and rates.
  • Booking preferences (schedule mode, buffers, lead time, confirmation settings) and gallery images.
  • Subscription billing records: your Stripe customer and subscription identifiers, plan tier, and billing status. Card data is handled entirely by Stripe and never touches BodIworK systems.

Client records practitioners keep (CRM):

  • Practitioners may maintain records about their clients: name, phone, email, preferred contact channel, session history, notes, tags, an optional birthday, and outreach history.
  • Practitioners are responsible for the client information they enter and for using it appropriately.

AI features:

  • When you use AI-powered features (feedback, session notes, the Concierge assistant, digests), the text you provide is processed to extract structured preferences such as pressure, preferred modalities, focus areas, and session duration.
  • Raw text submitted for preference extraction is retained for up to 90 days and then permanently redacted; extracted preferences are stored in your preference profile.

Other data:

  • If you opt in to browser push notifications, we store your browser’s push subscription (endpoint and delivery keys).
  • If you participate in the referral program, we store your referral code, referral relationships, and credit history.
  • Basic technical and usage data needed to operate and secure the service, and aggregated feature-usage statistics used internally to improve the product. These statistics do not include the contents of your client records or notes.

How we use information

  • To provide booking, scheduling, and client-relationship features.
  • To send service-related messages such as confirmations and notifications you have enabled.
  • To generate message drafts and AI suggestions you review before sending.
  • To personalize booking and session recommendations from preferences you or your practitioner record.
  • To manage practitioner subscriptions and administer referral credits.
  • To secure, debug, and improve the service.

Calendar Integration

If you choose to connect your Google Calendar (or any other calendar provider we support), BodIworK accesses limited calendar information to help you avoid double-booking and to keep your appointments in sync across the tools you use.

What we access:

  • The start and end times of events on the calendars you select.
  • Whether each event is marked all-day, tentative, or confirmed.
  • Whether you have marked an event as "free" rather than busy, and the category Google assigns it (for example a birthday or working-location entry) — so those do not block your availability.
  • Your own attendance status on invitations you received: only whether you declined, so a declined invitation does not block your availability. We do not receive the guest list, or any other person’s name, email address, or response.
  • The calendar identifier and name (so you can choose which calendars count as "busy").
  • A calendar event identifier for any event we create on your calendar (so we can update or remove it if your appointment changes).

What we do not access, even though the API may offer it:

  • The titles, descriptions, locations, or attachments of your calendar events.
  • The guest list of your calendar events — any other attendee’s name, email address, or response status.
  • Any personal communication in event invitations.
  • Calendars you have not explicitly selected for sync.

Why we access this:

  • To show your real availability to your clients — events you have on your connected calendar appear as "busy" so clients cannot book over them.
  • To add your BodIworK appointments to your calendar, so you see them alongside the rest of your day. The events we create carry the appointment's own details — service, client, time, notes, and location — and no attendee list.
  • To prevent double-bookings when you accept an external meeting at the same time a client is booking with you.

How we store it:

  • We encrypt calendar busy-time data in storage and process it in our hosted infrastructure.
  • Refresh and access tokens are encrypted before being written to storage.
  • Tokens are not logged, displayed in our user interface, or sent to any third party other than the calendar provider itself, except as necessary for debugging or monitoring with appropriate safeguards and access controls.

How long we keep it:

  • Active calendar busy-time entries are kept for the period needed to compute your availability.
  • When you disconnect a calendar, we generally delete cached busy-time entries and stored tokens for that calendar shortly after disconnect.
  • BodIworK appointments we have written to your external calendar are not deleted on disconnect — those events belong to your calendar account, and you control them from there.

Your controls:

  • You can disconnect your calendar at any time from Schedule → Manage Calendars → Disconnect.
  • You can choose which of your calendars are read for busy-time information, and which one of them BodIworK appointment events are written to (calendars you own; your primary calendar unless you pick another). You can turn this write-back on or off for the connection at any time.
  • You can revoke BodIworK’s access at any time directly from your calendar provider’s account controls — for Google Calendar at https://myaccount.google.com/permissions, and for Microsoft accounts under "Apps and services that can access your data" at https://account.live.com/consent/Manage.

Sharing:

  • We do not sell your calendar data.
  • We do not share the calendar information we read with other practitioners, clients, or third parties. (Appointments we write to your connected calendar go only to that calendar provider, at your instruction — that is the sync itself.)
  • We do not use your calendar data for advertising, marketing, or training artificial intelligence models.

BodIworK’s use of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Who we share information with

Your practitioner. When you book a session, your name, phone number, email address, and booking details are shared with the practitioner you are booking with. This is required to deliver the service.

Service providers. We share data with a small set of providers, only to the extent needed to operate the platform:

  • Google. Sign-in (your email, name, and profile image), optional Calendar sync as described above, and our hosting infrastructure — Google Cloud Platform (Cloud SQL, Pub/Sub, Cloud Run, Cloud Storage for profile and gallery images, Secret Manager, and Cloud Key Management Service). Google’s role as our infrastructure provider is governed by their Cloud Privacy Notice (https://cloud.google.com/terms/cloud-privacy-notice); your interaction with Google Sign-In and Calendar is also subject to Google’s own Privacy Policy and Terms.
  • Microsoft. Optional Outlook / Microsoft 365 calendar sync, as an alternative to Google Calendar: the same limited calendar access described under "Calendar Integration" — busy times read from the calendars you select, and your appointments written to your calendar. Your interaction with your Microsoft account is subject to Microsoft’s own Privacy Statement (https://privacy.microsoft.com/privacystatement).
  • Stripe. Practitioner subscription billing only: plan tier, customer and subscription identifiers, and invoice data. All payment card data is collected and stored by Stripe under its PCI-DSS compliance program.
  • Twilio. SMS delivery for phone verification: your phone number and the one-time verification code.
  • Resend. Delivery of transactional email such as booking confirmations, reschedules, and cancellations: recipient name, email address, booking details, and calendar attachments.
  • Anthropic (Claude). Powers our AI features. Depending on the feature, this can include feedback text, session notes, booking context, and client first names where the feature needs them (for example, the Concierge assistant discussing today’s schedule, or practice digests). Under our service agreement, Anthropic does not use this data to train its models.

We do not sell your personal data. We have no integrations with advertising networks, third-party behavioral analytics platforms, or social-media tracking pixels, and the fonts on our site are self-hosted (no font requests go to third parties).

No health information

Do not give BodIworK any health information. BodIworK is not intended to store protected health information, and we ask that neither clients nor practitioners enter health conditions, diagnoses, medications, injuries, treatment details, or any other medical information anywhere in the product — including booking notes, feedback, client records, and AI features. If you keep health records for your practice, keep them in a system designed for that purpose.

How we protect information

  • Data is stored in our hosted database infrastructure with access controls.
  • Calendar sync tokens are encrypted at rest; phone verification codes are stored only as one-way hashes and never in plain text.
  • Signed-in sessions use signed tokens that expire automatically.
  • BodIworK never stores payment card numbers; all card data is handled by Stripe.

Data retention and deletion

We keep information for as long as your account is active or as needed to provide the service. Raw text submitted to AI preference extraction is permanently redacted after at most 90 days.

You can delete your account yourself in Settings → Account ("Delete my account"). Your account is deactivated immediately and permanently deleted after a 30-day grace period; signing in during those 30 days lets you restore it. You can erase your AI preference memory at any time from the same page, and if you cannot sign in you can request deletion by emailing privacy@bodiwork.org. Deletion requests are logged and tracked through completion, and we confirm by email when deletion is complete.

A small set of records survives account deletion, each for a specific reason: billing and tax records (a legal obligation — kept with your identifiers replaced by a pseudonymous hash); the record of your consent acceptances and of the deletion request itself (proof we honored them, pseudonymized the same way); email opt-out addresses (honoring an opt-out requires remembering the address); and feedback reports, which are detached from the deleted account. Bookings you made with a practitioner remain part of that practitioner’s own business records, with your notes removed and your account no longer linked.

Backups are retained on a fixed schedule and age out automatically; data removed by a deletion request disappears from backups as they expire rather than being rewritten in place.

Communications

BodIworK sends service-related messages about your account and bookings, such as confirmations and digest summaries — not marketing. Practitioners may use BodIworK’s outreach tools to contact their own clients; that outreach is managed by the practitioner, not by BodIworK. You can turn browser push notifications off entirely, or disable individual notification types, at any time in your notification preferences.

Your choices

You can update your profile, disconnect a connected calendar, adjust or disable push notifications, and opt out of non-essential messages. In Settings → Account you can download a copy of your data as a machine-readable file ("Export my data"), erase your AI preference memory, and delete your account. If you don’t have an account — or can’t sign in — you can request access to or deletion of your data by contacting privacy@bodiwork.org.

Changes to this policy

We may update this Privacy Policy. When we do, we will publish a new version with a new effective date. Material changes may require you to re-accept before continuing.

Contact

Privacy questions can be sent to privacy@bodiwork.org.

BodIworK
TermsPrivacyFAQ