BuddyPrivacy Policy

Privacy Policy

Last updated: 1 June 2026

We use a third-party AI provider (Anthropic) to power our Yves feature. We only send your information to it after you agree.

1. Introduction

Buddy Symptom Tracker (“Buddy”, “we”, “us”, or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web platform (collectively, the “Service”).

This policy is drafted in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa. If you have any questions or concerns about this policy or our practices regarding your personal information, please contact us at hello@peakmovement.co.za.

2. What Data We Collect

We collect information that you provide directly to us, as well as data generated through your use of the Service. This includes:

  • Identity and contact data: Full name, email address, phone number, and profession (for practitioners).
  • Health and symptom data: Daily check-in metrics including pain level, sleep quality, stress level, energy level, mood ratings, medication adherence, and free-text notes describing symptoms or concerns.
  • Clinical context: Primary complaint, health history notes, treatment frequency, and appointment dates shared by you or your practitioner.
  • Technical data: Device type, operating system, IP address, and app usage analytics (collected anonymously where possible).

3. How We Use Your Data (including AI)

We process your personal information for the following lawful purposes under POPIA:

  • Clinical care: To enable your registered healthcare practitioner to review your symptom trends, track your progress, and make informed clinical decisions.
  • AI-assisted pattern detection: To identify trends, correlations, and potential red flags in your symptom data using automated analysis, which supports but does not replace clinical judgment.
  • Service improvement: To maintain, secure, and improve the functionality, performance, and reliability of the Service.
  • Legal compliance: To comply with applicable laws, regulations, and professional healthcare standards in South Africa.

Automated decision-making (including AI triage and urgency scoring) is used to flag potential concerns for your practitioner. A qualified human clinician always reviews flagged outcomes before any clinical action is taken.

4. AI features and third-party processing

Buddy offers an AI powered triage assistant called Yves. This section explains what information Yves collects, how it is collected, how it is used, and who processes it on our behalf.

  • What we collect through Yves: When you use Yves, you provide symptom details, check in responses, and free text messages you type into the chat. We also store the triage assessment that Yves generates from those inputs.
  • How we collect it: We collect this information directly from what you type or select inside the app. We do not collect health information from your device or from other apps without your input.
  • How we use it: We use your Yves inputs to analyse your symptoms, generate a supportive response, and flag concerning symptoms to your registered practitioner as an alert.
  • Who we share it with: The contents of your Yves conversations are sent to Anthropic, the AI model provider we use to power Yves. Anthropic acts as a data processor on our behalf and does not use your data to train its models. Anthropic is contractually bound to protect your information to a standard equivalent to this policy. In addition, to suggest a suitable exercise program from your check-ins, the same symptom and check-in information may be processed by Google through our platform provider, Lovable. Google and Lovable act as our data processors and use your data only to provide this feature, not to train their own models. We also share alert and check in data with your own practitioner so they can review flagged concerns. Where your practitioner has configured one, alert data may also be sent to that practitioner's chosen webhook endpoint.
  • Consent: You must explicitly agree before any of your information is sent to these AI providers (Anthropic and Google). You can withdraw or change your consent at any time in your profile. If you withdraw consent, Yves and AI-assisted program suggestions are disabled and no further data is sent to any AI provider.
  • Retention: Your Yves conversation history is stored so that you and your practitioner can review it. You can request deletion of this history at any time by contacting us.
  • What Yves is not: Yves does not provide a medical diagnosis and does not replace professional advice or emergency care. If you have an urgent medical concern, contact your practitioner or emergency services immediately.

Garmin Health Data

If you choose to connect a Garmin device to Buddy, this section explains exactly what Garmin data we receive, how it is collected, how it is used, who processes it, and how long we keep it. Garmin is a registered trademark of Garmin Ltd. Buddy is not affiliated with or endorsed by Garmin.

  • What we collect from Garmin: via the Garmin Health API we receive daily wellness summaries, sleep summaries, heart rate variability (HRV), stress details, epoch summaries, user metrics, and activity summaries (including distance). We do not receive raw GPS tracks, contacts, messages, or payment information.
  • How it is collected: you authorise the connection via Garmin Connect using OAuth 2.0 with PKCE. After you consent, Garmin pushes new data to Buddy's secure webhook endpoint as it becomes available. Buddy does not scrape or pull data from your Garmin account outside of this authorised push flow.
  • How we use it: Garmin data is displayed to you in the app, shared with the healthcare practitioner linked to your account for clinical review, and — only if you have separately consented to AI features — used as contextual signal (e.g. HRV, resting heart rate, and sleep deltas) for the Yves triage assistant.
  • Who processes Garmin data on our behalf: cloud infrastructure (Supabase / Cloudflare) for hosting and encrypted storage; Anthropic (Claude models) as an AI processor for Yves, only when you have consented to AI features; and Google (via the Lovable AI Gateway) for exercise-program suggestions, only when you have consented to AI features. All processors are bound by data processing agreements, use your data solely to provide the requested feature, and do not use your Garmin data to train AI models.
  • Selling and advertising: we do not sell, rent, trade, or use your Garmin data for advertising, marketing profiling, or any purpose other than the ones listed above.
  • Storage and security: Garmin access and refresh tokens and all synced Garmin data are encrypted at rest and transmitted over TLS 1.2 or higher. Access is restricted by role-based policies so only you, your linked practitioner, and authorised Buddy support staff can view your data.
  • Retention: Garmin data is retained while your Garmin connection is active and for the duration of your therapeutic relationship with your practitioner, plus any statutory healthcare retention period applicable in South Africa. When you disconnect Garmin, we delete your Garmin OAuth tokens immediately and stop receiving new data.
  • Your control: you can disconnect Garmin at any time from Profile → Wearables inside Buddy, or from Garmin Connect → Settings → Connected Apps. Buddy automatically honours Garmin's deregistration and user-permissions-change webhooks: if you revoke access on Garmin's side, we remove the corresponding token on our side. You may also request deletion of any Garmin data we hold by emailing hello@peakmovement.co.za.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. Your health data is shared only under the following limited circumstances:

  • With your practitioner: Symptom data, check-ins, and AI-generated insights are shared exclusively with the healthcare practitioner linked to your account, based on your explicit consent given at registration.
  • Service providers: We engage trusted third-party providers (e.g. cloud hosting, analytics) under strict data-processing agreements that comply with POPIA. These providers process data only on our instructions and do not use it for their own purposes.
  • Legal obligations: We may disclose information if required by law, court order, or to protect the vital interests of you or another person.

6. Data Security and Encryption

Protecting your health information is our highest priority. We implement appropriate technical and organisational measures consistent with POPIA’s security safeguards principle, including:

  • Encryption in transit: All data transmitted between your device and our servers is protected using TLS 1.2 or higher.
  • Encryption at rest: Health records and personally identifiable information stored in our databases are encrypted at rest.
  • Access controls: Role-based access ensures that only your registered practitioner and authorised support staff can view your data. Practitioners authenticate via secure login credentials.
  • Audit logging: We maintain logs of access to sensitive data to detect and investigate unauthorised access attempts.
  • Regular security reviews: We conduct periodic assessments of our infrastructure, dependencies, and procedures to address emerging threats.

7. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Health data is typically retained for the duration of your therapeutic relationship with your practitioner, plus any statutory retention period applicable to healthcare records in South Africa. When data is no longer required, it is securely deleted or anonymised.

8. Your Rights Under POPIA

As a data subject under POPIA, you have the following rights regarding your personal information:

  • Right of access: You may request a copy of the personal information we hold about you.
  • Right to correction: You may request that we correct any inaccurate or outdated information.
  • Right to deletion: You may request deletion of your personal information, subject to legal retention requirements and your practitioner’s professional obligations. You can also permanently delete your account and all associated data yourself at any time from the Profile screen in the app.
  • Right to object: You may object to the processing of your personal information in certain circumstances.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

To exercise any of these rights, please email us at hello@peakmovement.co.za. We will respond within the timeframe prescribed by POPIA.

9. Children's Privacy

The Service is not intended for individuals under the age of 18 without the involvement of a parent, guardian, or registered healthcare practitioner. If we become aware that we have collected personal information from a minor without appropriate consent, we will take steps to delete that information promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes via the app or email. The “Last updated” date at the top of this page indicates when the policy was last revised.

11. Contact Us

If you have any questions about this Privacy Policy, our data practices, or your rights under POPIA, please contact our Information Officer:

Email: hello@peakmovement.co.za

Business: Peak Movement

Website: buddytracker.netlify.app

© 2026 Peak Movement. All rights reserved. Built with care in South Africa.