Privacy Policy
MassFrame · Effective 28 September 2026
The short version
- Your training notebook lives in the app on your phone. There is no account and no server holding a copy.
- Apple Health is read and written only with your permission, and is never used for advertising or sold.
- Photographs leave only when you ask: a progress photo, with four body figures that may have come from Apple Health, to be read or drawn from; and a meal photo, to be read for what is in it. Each goes through a relay we run to OpenAI, after you have agreed, and each can be turned off at any time.
- No analytics, no tracking, no advertising, no location.
1. Controller and contact details
The controller responsible for the processing of personal data described in this policy is Baston Apps ("we", "us", "our"), an independent software developer established in Türkiye.
All privacy enquiries, including requests to exercise the rights described in clause 11, should be sent to support@bastonapps.com.
This policy applies to the MassFrame application for iOS (the "Application") and to this website. It does not apply to the practices of Apple, OpenAI, or any other third party, which are governed by their own policies.
Where the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, or the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") applies to you, this policy is intended to satisfy the respective information obligations.
2. The notebook on your device
Everything you write in the Application is stored in a database inside the Application on your device, and nowhere else. That includes your training sessions, sets and personal records; bodyweight entries and body-composition figures; notes; the training plans you adopt or build; progress photographs; meal photographs and what was read from them; the readings and picture described in clause 5; and the profile the Application asks for when a notebook is opened — your first name, biological sex, height, date of birth, target weight, training goal, activity level, nutrition targets, and preferences.
None of this is transmitted to us. We have no account system, no sign-in, no synchronisation service and no server that holds a copy, and we are not able to access your notebook. It is included in your device backup according to your own iOS backup settings, which are outside our control.
If you add the Application's widgets to your Home Screen or Lock Screen, the Application also writes a small summary for them — today's session and sets, the day's calories and protein, your latest weight and its trend, body fat and when the next check-in is due — to a container on your device that only the Application and its own widgets can read. It never contains a photograph, it never leaves your device, and on the Lock Screen its figures stay hidden until the device is unlocked.
Take it all with you in the Application's settings exports the whole notebook to a file you can keep. Erase deletes the whole notebook, including every photograph, permanently. Deleting the Application does the same.
3. Apple Health data
What is read. With your permission, given through the iOS Health permission sheet, the Application reads the following from Apple Health (HealthKit): body mass, body-fat percentage, active energy, height, date of birth and biological sex. Weights and body-fat readings are read so that they appear on the day they were measured, labelled with the app or device that recorded them; height, date of birth and sex so that your profile need not be typed twice; and active energy only to suggest an activity level for your nutrition targets, which you may accept or ignore. What is read is written into the notebook on your device, marked as having come from Health, and removed from the notebook if it is deleted in Health.
What is written. With your permission, and each behind its own switch in the Application's settings, the Application writes to Apple Health: a workout when you stamp a session as completed; a weight you type into the Application; and the energy, protein, carbohydrate and fat of a meal it has read. It never writes back anything it read from Health, and never writes the body-fat or lean-mass estimates it reads from photographs.
Data obtained from Apple Health is never used for advertising, marketing or similar purposes, is never sold, is never disclosed to a data broker, and is never transmitted to us. The one case in which a figure that came from Health can leave your device is the reading described in clause 5: the four figures sent with a progress photograph — sex, age, height and weight — are the ones held in your notebook at that moment, and some of them may have arrived from Health. They are sent only when you ask for a reading, only after you have given the explicit consent described in clause 5, and only to produce that reading for you.
Permission may be reviewed or withdrawn at any time in Settings → Health → Data Access & Devices → MassFrame.
4. Photographs
Progress and meal photographs taken with the camera or chosen from your photo library are copied into the Application's own storage on your device, not into your photo library, and are protected by your device passcode using iOS complete file protection. iOS asks your permission before the Application may use the camera or read from your photo library, and either may be withdrawn in Settings → MassFrame.
A photograph stays on your device unless you ask for a reading or the picture described in the next clause. Deleting a photograph in the Application deletes it, and deletes anything that was read or drawn from it.
5. Readings: your physique, the six-month picture, and your meals
The Application can read a front-on progress photograph for visible muscular development, can draw a picture of how you may look six months on from the same photograph, and can read a photograph of a meal for the foods in it and their estimated energy and macronutrients. These are the only processing in the Application that sends personal data off your device, and each happens only when you ask for it.
What is sent. For a reading: one photograph, cropped to the frame you chose, and four figures — biological sex, age in years, height and weight. For a picture: the same photograph, and the weight, body-fat percentage and lean-mass figures for today and for six months on, as worked out in clause 6. For a meal: the photograph and the hour of the day it was eaten, with a random number the Application created when it was installed, used only to limit how many meals a day can be read. It is not derived from your device or linked to you, and a new one is made if the Application is reinstalled. No name, no date and nothing else from the notebook is sent with any of these.
Where it goes. The Application sends it, over an encrypted connection, to a relay service we operate, hosted for us by Supabase, Inc. The relay holds the credentials for the model provider so that the Application never does; it forwards the request to OpenAI, L.L.C. ("OpenAI"), whose models read the photograph or draw from it, and returns the result to your device. The relay stores nothing, keeps no copy of any request or response, and logs no content — on a failure it records only a status code. To limit use, it keeps in memory, for no more than a day, a count of requests per network address and, for meals, per the random number above; the counts are not written to storage and are discarded when the relay restarts.
What comes back and where it is kept. A physique reading returns scores for each muscle group, an overall score and two sentences. A picture returns one image. A meal reading returns the foods seen, their portions, and their estimated energy, protein, carbohydrate and fat. Both are stored in the notebook on your device, with the name of the model that produced them, and are deleted with the photograph they came from, with Erase, or with the Application.
OpenAI's handling. OpenAI processes the data as our processor under its API terms. It does not use data submitted through its API to train its models. It may retain the submitted data for up to thirty days to monitor for abuse and misuse, after which it is deleted, save where retention is required by law. We have asked that requests not be stored beyond that purpose.
Purpose: producing the reading or the picture you asked for.
Legal basis: your consent, under Article 6(1)(a) GDPR and the corresponding provisions of KVKK, and — to the extent that a photograph of your body together with your body-composition figures constitutes data concerning health — your explicit consent under Article 9(2)(a) GDPR. The Application asks for that consent, in the Application, before the first photograph is sent, and states there what is sent, what is kept and who reads it; meal photographs have a consent of their own. You may withdraw either at any time with the switches Read photographs off this phone and Read meal photographs off this phone in the Application's settings; withdrawal stops any further sending and does not affect the lawfulness of what was sent before.
What the result is. The physique reading is a visual estimate of muscular development produced by a machine-learning model, the picture is a machine's drawing from your photograph and your figures, and a meal reading is an estimate from a photograph, which cannot weigh anything. Neither is a medical assessment, a diagnosis, or a prediction, and the Application labels them as such. No decision with legal or similarly significant effect on you is made by them.
6. Figures worked out on your device
Body-fat percentage, lean mass, the fat-free mass index, the band it places you in, estimated one-repetition maximums, the six-month projection, your daily energy and protein targets, and the activity level suggested from Apple Health are calculations performed on your device from figures you supplied or that arrived from Apple Health. They are not sent anywhere in order to be calculated. They are estimates from population formulas and can be wrong; the Application says so where it shows them.
7. Purchases
The Application is currently offered without charge and nothing in it is for sale. It contains the software library of RevenueCat, Inc., which would verify a purchase if one were offered; while nothing is sold, it is not activated and sends nothing. If paid features are introduced, this clause will be updated before they are, and payment will be processed by Apple — we would not receive your payment card details, billing address or Apple Account credentials.
8. Reminders
Training and photograph reminders are local notifications scheduled on your device by the Application, with your permission through the iOS notification sheet. No push notification service is used, and no notification passes through any server. Permission may be withdrawn in Settings → Notifications → MassFrame.
9. Data we do not process
We do not collect, and have no means of collecting:
- your name, email address, postal address, or telephone number — the first name you may give the Application stays on your device;
- your notebook, or any figure, note, plan or photograph in it, except the photographs and figures you ask to have read or drawn from, as described in clause 5;
- any data read from Apple Health, except the figures sent with a progress photograph as described in clauses 3 and 5;
- precise or approximate geolocation data;
- device identifiers, advertising identifiers, or usage analytics of any kind — the random number sent with a meal is made by the Application, not taken from your device.
We operate no analytics service, crash reporting service, advertising software, or social network software development kit, and we maintain no user accounts. The Application makes network requests of one kind, those described in clause 5, and makes them only when you ask.
10. Recipients, third parties and international transfers
The following third parties process personal data in connection with the Application:
- OpenAI, L.L.C. — reading a progress or meal photograph and drawing a picture from a progress photograph, as our processor, in the United States. Privacy policy · API data handling
- Supabase, Inc. — hosting the relay described in clause 5, which passes each request through without storing it, as our processor. Privacy policy
- Apple Inc. and Apple Distribution International Ltd. — distribution of the Application and Apple Health, as independent controllers under their own policies. Privacy policy
We do not sell personal data. We do not disclose personal data to any other recipient except where required to comply with a legal obligation or to establish, exercise, or defend legal claims.
We are established in Türkiye and hold no personal data ourselves. The photographs and figures described in clause 5 are transferred to OpenAI in the United States, and pass through Supabase infrastructure, when you ask for a reading or a picture. For transfers from the European Economic Area and the United Kingdom, OpenAI and Supabase rely on the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU–US Data Privacy Framework. Apple may transfer data outside your country of residence under the mechanisms set out in its own policies.
11. Retention
Your notebook remains on your device until you erase it or delete the Application. We retain no personal data ourselves. Photographs and figures sent for a reading or a picture are held by OpenAI for no longer than thirty days for abuse monitoring and then deleted, and are not stored by the relay at all; the relay's request counts described in clause 5 are held in memory for no more than a day.
12. Security
Photographs are stored under iOS complete file protection, so they are inaccessible while the device is locked; the notebook database is protected by the device's own encryption. The transfers in clause 5 are made over transport-layer encryption to a relay that authenticates each request, holds no stored data, and keeps the provider's credentials on the server so they are never present in the Application.
13. Your rights
Subject to the conditions and exceptions in applicable law, you have the right to request access to personal data concerning you, its rectification or erasure, the restriction of its processing, and its portability; to object to processing; and, where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. If you are in Türkiye, the rights set out in Article 11 KVKK apply to you.
Because the Application maintains no account and we hold no data, the effective controls are in your hands:
- Access and portability. Everything is in the Application on your device, where you can read it, and Take it all with you exports it to a file.
- Erasure. Delete any entry or photograph in the Application; Erase in its settings removes the whole notebook; deleting the Application removes everything.
- Withdrawing consent to the readings. Turn off Read photographs off this phone or Read meal photographs off this phone in the Application's settings.
- Apple Health. Change what the Application may read or write in Settings → Health → Data Access & Devices.
Requests concerning data held by OpenAI or Apple should be directed to those parties using the contact details in their policies. You may address a request to us at support@bastonapps.com, and we will respond within the period required by applicable law, including where our response is that the data you have asked about is not data we hold.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of an alleged infringement. In Türkiye the competent authority is the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
14. Children
The Application is not directed to children under 13, or under 16 in the European Economic Area, and is not submitted to the App Store Kids Category. We do not knowingly process personal data relating to such children. If you believe that a child has provided personal data in connection with the Application, please contact us so that we can assist.
15. Changes to this policy
This policy may be updated to reflect changes to the Application, to the third parties it relies on, or to applicable law. The effective date at the top of this page will be updated accordingly, and material changes will be identified in the Application's release notes. The Application links to this page from its settings.
16. Contact
Questions about this policy, or about any processing described in it, may be sent to support@bastonapps.com.