phaze

Privacy at Phaze

Last updated and effective: September 30, 2026

Phaze is operated by Zeit Capital Ltda.

  • Ask only for what's necessary

    We collect what we need to run the app. We do not sell your data, and no health value ever goes to an advertiser or a data broker.

  • Your health data stays on your device and in your own cloud

    Your logs live in the app's own storage on your phone. Phaze runs no server that holds them. On iOS the app also keeps an encrypted daily copy in your own iCloud Drive, and on Android you can turn on an encrypted backup to your own Google Drive.

  • No medical data in advertising

    We never use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.

1. Who we are

Phaze is operated by Zeit Capital Ltda, a limited liability company organized under the laws of Brazil ("Phaze," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Phaze mobile application, the Apple Watch companion, our website at phaze.fit, and related services (together, the "Service").

Contact

  • Email (Privacy and Data Subject Rights): privacy@phaze.fit
  • Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
  • LGPD Encarregado de Dados (DPO for Brazil): Vinicius, privacy@phaze.fit
  • EU Representative (Art 27 GDPR): a representative will be appointed if and when our EU user base reaches the threshold that requires one. Until then, contact us directly at privacy@phaze.fit and we will respond within statutory timeframes.
  • UK Representative (UK GDPR Art 27): same status as the EU Representative above.

If you are in the European Economic Area, the United Kingdom, Brazil, or another jurisdiction with data-protection laws, additional rights and disclosures appear in Section 13.

2. Quick summary

This summary is informational only. The full text below governs.

  • We do not sell your personal information. We tell Meta, and on Android TikTok, when Phaze is installed, opened and subscribed to, so we can see which ad brought someone here. No health value is included, and we share nothing with data brokers. See Sections 6.3 and 8.
  • Health data is stored on your device. Phaze keeps no copy on its own servers. On iOS the app writes an encrypted copy to your own iCloud Drive once a day, and on Android you can enable Cloud Backup, which writes an encrypted archive to your own Google Drive. See Section 5. The one exception is Phaze storage, which you can choose for a backup with Phaze Pro on iOS. It keeps an end-to-end encrypted copy on our service that nobody at Phaze can open.
  • Community is optional. If you post there, what you write is stored on our service and shown to every member, and a post that names your medication, your dose or your weight is health information you chose to publish. Phaze never copies anything from your logs into a post. See Section 5.4.
  • We do not use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.
  • AI features (Ember chat, food scan, Daily Insights) send your data to Google Gemini through an edge service we operate. They stay off until you grant a separate permission, and you can withdraw it at any time. We do not train AI models on your data. Community uses Gemini too, to check and translate posts and replies, to write the replies of its AI characters and, if it is switched on, to write a daily thread inspired by public news from official health agencies or by a yearly day or season. That runs under Community's own consent, not under that permission. See Section 6.1.
  • You must be 18 or older to use Phaze.

3. Information we collect

3.1 Information you provide

  • Account information: Phaze has no login and no password. If you use Community, you choose a username for it, which every member of Community can see (the community bullet below, and Terms Section 4). You give a name and a date of birth during onboarding, and both stay on your device. You give an email address only if you choose to, when you send feedback or turn on profile sharing in Settings, Privacy.
  • Health and body data: weight, height, body composition entries, progress photos, goals, dietary preferences.
  • Medication data: GLP-1 (or other) medication name, dose, schedule, side effects, injection-site notes. Provided voluntarily.
  • Nutrition data: food logs, barcode scans, meal photos, voice-described meals, dietary preferences.
  • Activity data: exercise logs, hydration entries, fasting windows, sleep summaries.
  • Subscription information: purchase confirmations from Apple App Store or Google Play. We do not receive your full payment card number.
  • Communications: support emails, in-app feedback.
  • Community content (optional, Phaze app): if you use Community, we receive the username you choose, the text of each post (up to 600 characters) and each reply (up to 400), the topic you picked for a post, the language your app is set to, which is recorded as the language of what you wrote, your votes and, from before votes, your Cheer and Same reactions, the reports you file with their reason and an optional note of up to 200 characters, the members you hide, and which version of Community's terms and consent you accepted and when. Posts are text only: no photos and no links. There are no profile photos either, and Community stores no picture of you. What you write can include your medication, your dose, your weight or how you feel. If it does, that is health information you chose to publish, and Section 5.4 says where it is kept.
  • Your Community profile (optional, Phaze app): tapping your username in Community opens your profile. It shows your username, the month you joined, your tags, your karma unless you turned it off, and the posts and replies of yours that Community shows. You can also choose to show up to three fields the app already holds, so you never type them: your logging streak, the number of days in a row you have logged in Phaze; the medication you take, shown by its brand name, or with no name if you chose "other"; and your current dose, shown as a number and a unit, such as 0.5 mg. Each field has its own switch, which starts off, when you choose your username and in Settings, Community. The app fills in the value for you, sends it only while that switch is on, and updates it as it changes. Your medication and your dose are health information, and in a community about GLP-1 medication how steadily you log can say something about your health too. So we treat all three as special category health data that you choose to make public, and turning on each switch is your explicit consent to show that one field. Your profile shows only what this paragraph lists, and it never shows your weight, your body measurements, your side effects or your injection sites. You can take your karma off your profile and the leaderboard, and hide your Premium tag, in Settings, Community (Terms, Section 7A.8).
  • Community notifications (optional, Phaze app): if you have agreed to Community's terms and Phaze may show notifications on your iPhone, the app sends our service, with your member ID, your iPhone's push token from Apple, whether the app is a development build, the language your app is set to, your iPhone's time zone (for example "Europe/Berlin") and your two notification switches, which start on. The app sends them again when any of them changes, and otherwise about once a day when you open Phaze. Terms Section 7A.9 says what a notification says.

These Community disclosures also apply on Android. Its member ID is kept in encrypted preferences protected by Android Keystore. Optional notifications use Firebase Cloud Messaging. Turning off Phaze notifications in Android settings removes that phone from our list the next time you open Phaze.

3.2 Information collected automatically

  • Device information: device model, operating system version, app version, language, time zone, country (derived from store region), and a device-generated pseudonymous identifier used to link your usage events.
  • Diagnostics and product analytics: crash reports, performance traces, error logs, and product-analytics events. We do not send your email address, your name, or any medication name, dose, side effect, or injection site to our analytics or crash providers. Analytics events carry which screens you opened and which actions you took, plus your mood and energy ratings from a daily check-in and the name of a lab biomarker you added, never its value. Our analytics provider also records the screen of roughly 10% of sessions, with every text label, image, and input field masked before upload. All of this links to a device-generated identifier, so it is pseudonymous rather than anonymous. One switch in Settings, Privacy turns it all off. See Section 6.2.
  • Approximate location: city-level only, derived from IP. We do not collect precise GPS location.
  • Community membership (only if you open Community): the first time you open Community, or its page in Settings, Community, the app creates a random member ID and keeps it in the iOS Keychain. It does this even while Community is closed. While Community is open, our service stores that ID with the app platform, your phone's language and region setting (for example "en_US"), the date you first opened Community, and each date you opened Community or its Settings page. No name is given to you: you choose a username before you first post, reply or vote. This record is created the first time you open either one, before you post or agree to anything, because it marks the start of your open week. If you leave Community and later open Community or its Settings page again, the same record becomes active again, with no username until you choose a new one. If your access to Community was removed, the record stays removed. The member ID is not the device identifier used for analytics, crash reports and subscriptions, and the two are never joined.

3.3 Information from third parties

  • Apple HealthKit (iOS): if you connect HealthKit, we read the data types you authorize. See Section 7.
  • Google Health Connect (Android): if you connect Health Connect, we read the categories you authorize. Phaze currently requests: Steps (read), Weight (read and write), Active calories burned (read), Exercise session (read).
  • Google Drive (Android only): if you turn on Cloud Backup on Android, you authorize Phaze for the Drive AppData scope so it can write the backup file to your own Drive. We receive no other Drive content. Phaze has no Sign in with Apple and no Google sign-in, because Phaze has no login.

We do not buy data from data brokers and do not enrich your profile from external sources.

3.4 What we do NOT extract

  • No biometric identifiers. Phaze does not extract or store face geometry, facial landmarks, fingerprints, iris scans, voiceprints, speaker embeddings, gait analysis, or any other biometric identifier as defined by the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI statute, or similar laws. Food scans and progress photos are not processed for facial recognition. Voice transcription uses the platform speech APIs and does not create or retain a voiceprint on the Phaze side.
  • No precise location. We do not collect GPS coordinates or use geofencing. We do not geofence around health care facilities.
  • No third-party advertising IDs we use ourselves. The IDFA or advertising ID on your device is governed by the platform's privacy controls.

4. How we use your information

We process your information for the following purposes and on the following lawful bases (the lawful basis matters most under GDPR, UK GDPR, and LGPD; United States users may disregard the "Lawful basis" column).

PurposeWhat we doLawful basis (GDPR / LGPD)
Provide the ServiceRender your dashboards, store your logs, sync to your watch, calculate trendsPerformance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD
Process health dataStore and display weights, photos, medications, food, activityExplicit consent (Art 9(2)(a) GDPR) / Art 11(I) LGPD specific consent
AI features (Ember chat, food scan, recommendations)Send your input to AI providers named in Section 6 to generate responsesExplicit consent for special-category processing (Art 9(2)(a) / Art 11)
CommunityRun Community: your membership record and username, the feed, reactions, votes, karma, the leaderboard, search, reports, hidden members, and moderationPerformance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD
Health information in community postsStore what you post, check and translate it with Google Gemini, have Gemini write an AI character's reply to it, and show it to every member of CommunityExplicit consent (Art 9(2)(a) GDPR), given with the unticked checkbox on the "Before you post" screen / Art 11(I) LGPD specific and highlighted consent
Your Community profileShow other members your username, the month you joined, your tags, your karma unless you turned it off, and the posts and replies of yours Community shows, on one pagePerformance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD
Your logging streak, medication and dose on your Community profileStore each value while its own switch is on, and show it to the members who open your profileExplicit consent (Art 9(2)(a) GDPR), given separately for each field by turning on its switch, which starts off / Art 11(I) LGPD specific and highlighted consent
Community notificationsTell you on your iPhone, through Apple's push service, about replies and the day's upvotes. On by default once you have agreed to Community's terms, while Phaze may show notifications on your iPhone and you keep the switches onPerformance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD; reading your iPhone's push token is strictly necessary for these notifications, which are part of the Community you asked for (Art 5(3) ePrivacy Directive); you can switch it off at any time
Community after you leaveKeep your membership record reduced to its ID, its public token, its status, strike count, avatar number and kind, the open-week dates, until when your reports cannot hide a post at once, and when it was created and last changed, so that leaving and coming back does not start a new open week, does not lift a removal from Community, and does not undo a moderator turning down one of your reports; hold your old username for 30 days, with no member attached to it, so no one takes it over mid-conversation; keep the moderation log for 12 months, which holds nothing you wrote and no member ID, and names your public token on actions taken on your membership; and keep Community's work queue, where the record of a job to have an AI character answer one of your replies names the thread, the day and the first part of your public tokenLegitimate interest (Art 6(1)(f)) / Art 7(IX) LGPD; you may object
Cloud Backup (optional)Store an encrypted archive in your personal cloud storage if you enable itConsent (Art 6(1)(a)) / Art 7(I) LGPD
Phaze storage (optional, iOS, Phaze Pro)Keep an end-to-end encrypted copy of your Phaze data on our service each time you choose Phaze storage for a backup, and send it back to your iPhone when you restore itExplicit consent (Art 9(2)(a) GDPR), given each time you choose Phaze storage for a backup and withdrawn by deleting the backups / Art 11(I) LGPD specific and highlighted consent, given by the sentence under the Back up button
Subscription billingProcess purchases through Apple App Store and Google PlayPerformance of contract
Diagnostics and abuse preventionCrash reports, performance monitoring, securityLegitimate interest (Art 6(1)(f)) / Art 7(IX) LGPD; you may object
Communicate updatesService notices, policy changesLegitimate interest / Art 7(IX)
Comply with lawRespond to legal process; protect rightsLegal obligation (Art 6(1)(c)) / Art 7(II)

We do not use your information to: sell to third parties for monetary or other valuable consideration; show ads in Phaze; profile you to predict future behavior outside the Service; share with insurers, employers, or data brokers. The install-attribution events we share with Meta, and on Android with TikTok, are described in Section 8.

You may withdraw consent at any time by deleting the relevant data in-app, disabling the feature, or contacting privacy@phaze.fit. Withdrawal does not affect prior lawful processing.

5. Local storage and backups

5.1 On your device

Your health, medication, and progress photo data is stored on your device:

  • iOS: SwiftData persistent store with iOS Data Protection (NSFileProtectionCompleteUntilFirstUserAuthentication class). Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, your medical profile, and your dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly).
  • Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (cipher mode AES/GCM/NoPadding, 256-bit key, 12-byte IV, 128-bit tag) using a key generated and stored in the Android Keystore (hardware-backed where the device supports it). General preferences use Android Jetpack Security's EncryptedSharedPreferences (AES256_SIV for keys, AES256_GCM for values) with a Keystore-bound master key.

Phaze operates no server that stores the health records you keep in the app. Health information can still reach our service in two ways. If you post in Community, what you write is stored on a service we run so other members can read it, and a post that names your medication, your dose, your weight or how you feel is health information on our server. And if you turned on profile sharing and our team contacted you for product research, the notes our team writes about that contact can include what you chose to tell us. The app never copies anything from the records above into either one. Section 5.4 lists everything our service holds, Community included. The flows that leave your device are in Section 6: AI features, Community's checking, translation and AI character replies, analytics, optional Cloud Backup, and optional Health platform sync. If you choose Phaze storage for a backup, an end-to-end encrypted copy is also kept on a service we run, and only your devices and your recovery code can open it (Section 5.2).

5.2 Backups

How a backup works depends on your platform, and the two are not the same.

  • iOS: At most once a day, when you open Phaze on an iPhone signed in to iCloud, the app writes an encrypted copy of your Phaze data to Phaze's own folder in your iCloud Drive (iCloud.com.zeit.phaze). The copy holds everything you keep in Phaze, including your medications, your dose history, your logs and your progress photos, and the app keeps the copy it replaces as a second one. We have no access to your iCloud Drive, so we cannot read or retrieve these copies. An entry you delete stays in them until newer copies replace them. The app never replaces a copy with a smaller one on its own, so after you delete entries that can take a while. When you install Phaze on an iPhone signed in to the same iCloud account, it offers to restore your data from iCloud. Your data is also carried by Apple's iPhone Backup, which you control in iOS Settings. A device that used an older build may also hold one earlier archive in the same folder, which Settings, Data and Privacy, Device Backup lets you restore once or delete. Delete All Data removes the daily copies and that archive while iCloud Drive is on for Phaze, within the limits set out below.
  • Android: Cloud Backup is opt-in and off by default. When you enable it, an encrypted archive is written to the AppData folder of your own Google Drive. That folder is private to Phaze, application-scoped, and not visible in your normal Drive view. You pick the frequency: off, daily, or weekly.
  • Phaze storage (optional, iOS, Phaze Pro): when you tap Back up now in Settings, Data and Privacy, Device Backup and turn on Phaze storage for that backup, the app sends an end-to-end encrypted copy of everything you keep in Phaze, including your medications, your doses, your side effects and your progress photos, to a backup service we run. It happens only when you choose it for that backup. It is never automatic and it never syncs. The iPhones on your Apple Account share these backups, so you can restore one on a new iPhone.

In both cases the archive payload is encrypted with AES-256-GCM before it is written.

About the encryption key for iCloud and Google Drive archives. So that a backup can be restored on a new device without a separate passphrase, the encryption key is generated locally and stored alongside the encrypted payload inside the backup file. On iOS the daily copy also holds the key that unlocks the medical fields encrypted on your device (Section 5.1), such as your medications, doses, side effects and injection sites, so that a restore can read them. When iCloud Keychain is on, the app also keeps a copy of that key in your iCloud Keychain, so that a new iPhone on the same account can read the data it restores. This means the backup is protected by the security of your iCloud or Google account, not by a passphrase you hold. We do not support a user-supplied passphrase, and we do not describe this backup as readable only by you, because that would imply a key we cannot reach. If you require true zero-knowledge encryption, turn off iCloud Drive for Phaze on iOS, and do not enable Cloud Backup on Android.

Phaze storage is readable only by you. The key that opens it is made on your iPhone and kept in your iCloud Keychain and in a recovery code the app shows you. Our service never receives either one, and never receives the key that protects your medical fields in a form it can read. Nobody at Phaze can open these backups. If you lose both your recovery code and every device that holds the key in iCloud Keychain, nobody can open them, including Phaze, and we cannot find them for you, because Phaze has no accounts.

Phaze keeps no copy of the iCloud or Google Drive archives, which exist only in your own iCloud or Google Drive. The only backup our service holds is Phaze storage, and only when you choose it.

On Android, once Cloud Backup is enabled, it runs on the schedule you pick. You can change the frequency or switch it off at any time in Settings, Cloud Backup.

To remove a backup file: On iOS, Delete All Data removes the Phaze copies in your iCloud Drive only while iCloud Drive is on for Phaze, so use it before you turn iCloud Drive off. It cannot remove a copy that iCloud keeps only in the cloud to save space on the iPhone, and another iPhone signed in to the same iCloud account keeps writing its own copy until you delete the data on that iPhone too. To be sure every copy is gone, also delete Phaze's data in your iPhone's iCloud storage settings. On Android, Delete All Data removes the Cloud Backup file when that phone still has access to your Google Drive for Phaze, and you can switch Cloud Backup off in Settings. You can also delete the files yourself through Apple's or Google's data-management tools. To delete your Phaze storage backups, use Delete from Phaze in Settings, Data and Privacy, Device Backup, which deletes them from our service at once. Delete All Data asks whether to delete them too (Section 9).

5.3 What this means in plain language

  • Your data is stored on your device.
  • On iOS the app writes an encrypted copy of your data to your own iCloud Drive once a day (Section 5.2). On Android, Cloud Backup is off unless you turn it on, and then an encrypted file lives in your own Google Drive.
  • If you choose Phaze storage for a backup, an end-to-end encrypted copy is kept on our service. Nobody at Phaze can open it, and you can delete it at any time from Device Backup.
  • AI features and analytics described in Section 6 do transmit specific fields off your device.
  • Anything you post in Community is stored on our service and shown to other members until you delete it or leave Community.
  • Uninstalling the app removes on-device data. The iOS copies in your iCloud Drive, and an Android Cloud Backup file in your Google Drive, stay until they are deleted.
  • Uninstalling the app does not remove your community posts from our service. Leave Community first, or see Section 12.

5.4 What Phaze keeps on its own servers

We run one service of our own, on Cloudflare. It proxies the AI requests described in Section 6.1, runs Community, and holds a small set of records in a Cloudflare D1 database. An internal dashboard our team uses reads and writes the same database. Workers KV holds rate-limit counters, rankings entries, short-lived caches of food-scan, meal-description, food-search and recipe results, and, for Community, a marker of when you last looked at your replies. This is all of it. The app never copies a medication, dose, schedule, side effect, injection site, weight, height, or BMI from your records into any of them. Such a value can appear in two places only: in Community, when you type it into a post or reply yourself, and in the research notes below, when you tell it to our team.

There are two exceptions to that, and both are yours to choose. The app copies the medication and the current dose you choose to show on your Community profile, each only while its own switch is on (Section 3.1). And a separate backup service keeps your Phaze storage backups, in a storage bucket and a database of its own. Those backups hold all of your Phaze data, end-to-end encrypted so that our service cannot read it (the Phaze storage bullet below).

  • Profile sharing (optional): on iOS the profile-sharing card is pre-selected during onboarding and you can untick it there or switch it off at any time in Settings, Privacy. On Android it starts off and you switch it on yourself. When it is on, one row is stored for your device: a device-generated identifier, birth year and age band, biological sex, activity level, transformation goal, the reason behind that goal and what you tried before Phaze (each chosen from a fixed list during onboarding), stage, whether you have Phaze Pro, app platform, version and language, and your consent flags. An email address is stored in a separate table, and only if you gave one. Cloudflare adds the country, region, and city it resolved from the request itself. The app holds no location permission and asks for none. Switching the toggle off deletes the row, and so does Delete All Data.
  • Feedback and the feature roadmap: when you send quick in-app feedback, we store which screen you sent it from, your rating and, where the screen asks, how easy the task was, your message if you wrote one, an email address if you gave one, your device identifier, and the app platform, version, and language. The longer survey in Settings stores the same identifier and app details, your score, whether Phaze is the only GLP-1 app you use, the other apps you name, the features you use, your comments, and an email address if you gave one. When you vote on the public roadmap, we store a random voter ID that the app keeps for the roadmap only, which is not your device identifier, with each item you voted for and when. When you suggest a roadmap item, we store its title, its description if you wrote one, your voter ID, and the app platform, version, and language. Our team reads a suggestion before it appears, and your voter ID is never shown. A filter rejects a feedback message, a survey answer or a roadmap suggestion that mentions a medication, a dose, or a side effect before it is stored. To have a feedback message or a roadmap entry removed, email privacy@phaze.fit.
  • Lifestyle Score rankings (opt-in): if you join rankings, your device identifier, your Lifestyle Score, and your streak length are stored in Workers KV so a position can be calculated. Leaving rankings deletes the entry, and an entry that is not updated for 30 days expires by itself. This has nothing to do with Community below.
  • Research questions (optional): if you answer Phaze's short set of research questions, from Settings or from an in-app banner, we store one choice from a fixed list, up to two written answers of up to 280 characters each, where you answered from, the app platform, version, and your phone's language and region setting, and the time. No device identifier, email address or other identifier is stored with them. A filter refuses a written answer that mentions a medication, a dose or a side effect.
  • Research contact notes (internal): if you turned on profile sharing and our team contacts you for product research, our internal dashboard keeps, against your device identifier, a contact status and follow-up date, whether we left your profile out of research and why, notes our team writes (up to 2,000 characters each), and a log of each call, email, text or video contact with its outcome and an optional summary of up to 2,000 characters. These notes can record what you chose to tell us, which can include health information. They are deleted with your profile row, when you switch profile sharing off or use Delete All Data.
  • Community (optional, Phaze app): what Community keeps, record by record. Section 9 says how long each one lasts.
    • Member records: one row per member, holding:
      • your member ID;
      • a public token made from it with a secret key only our service holds, which is what other members' apps see instead of the ID;
      • your username, as you chose it;
      • an avatar number, and whether the row is a member, a Phaze AI character or Phaze staff;
      • your status (active, muted, removed, or left), your strike count and your badges;
      • whether Phaze's AI characters are turned off for you;
      • until when your reports cannot hide a post at once: 30 days after a moderator turns one of your reports down, or, if you leave Community, a day after the last post your reports hid that day;
      • the version and time of the terms and consent you accepted;
      • the date your app first confirmed you are old enough to join (never your age or date of birth);
      • the date you first opened Community and the date your open week ends;
      • the app platform and your phone's language and region setting;
      • your karma, for all time and for the current month, which our service recomputes every few minutes from the votes that count, and your two switches for showing your karma and your Premium tag;
      • the last time your app told our service you have Premium, which the Premium tag reads for seven days (a no is never stored);
      • when the row was created and last changed.
    • Usernames: your username in the form our service compares names in (lowercase, with look-alike letters and digits folded together and periods and underscores removed), your member ID, and when you chose it. This is what makes a username unique.
    • Username holds: a username that was given up, in that same compared form, why it was given up (changed through support, swapped for a chosen name, or its holder left Community), and the date it becomes free again. It does not record who held the name. It is written at the same moment as the change to that member's record, so for its 30 days the two could be matched by their times.
    • Posts and replies: each post or reply you write, with the topic of a post, the language your app was set to, its moderation status and a short reason (a code our checks set, or a label of up to 64 characters a moderator enters), the automated screening scores and the language the screening detected (never your words), whether a person or the system decided and when, when a moderator first upheld a report about it, its reply, reaction and vote counts, the number of open reports on it, a pin flag, an ID your app generates so a retry is not posted twice, and its times. The same records hold what Phaze's AI characters write, with which character wrote it, which model or pre-written line produced it, and, for an answer, which reply it answers.
    • Translations: the translations of each approved post and reply into Community's other seven languages. Where a translation fails our checks, a copy of the original text is kept in its place.
    • Reactions: which member gave which Cheer or Same to which post or reply.
    • Votes: which member voted which post or reply up or down, and when. Members are shown only an item's score, never below zero, and nobody is shown how many down votes anything received.
    • AI character cheers: the cheers Phaze's AI characters gave before Community moved to votes: which character cheered which post or reply, and when. No new cheer is written, and none is shown. They are kept apart from members' reactions and votes, so no number members see, including scores and karma, can include them.
    • Reports: each report, with the item reported, the reporting member's ID, the reason, the optional note, and its status and outcome. A report a moderator upheld counts as a confirmed breach against the author of the item (Terms, Section 7A.3), and the post or reply records when, so the breach still counts after the reporter leaves. Where a report hid the item at once (Terms, Section 7A.4), the time it did so.
    • Hidden members: your member ID and the public token of each member you hid.
    • Days in Community: the dates you opened Community or its Settings page, or posted, replied, reacted or voted there, with no time of day.
    • Your profile fields: your member ID; your logging streak, the medication you take (as one key from a fixed list) and your current dose (a number and a unit), each only while you have its switch on; when the row last changed; and a change number your app sends with each change (in practice the time of the change), so that a request that arrives late cannot show a value again after you switched it off. It holds numbers and keys from fixed lists, never any text you typed. Switching a field off deletes its value, and a row with every field off keeps only your member ID, the change number and when it changed. Leaving Community deletes the row.
    • Work queue: an item number, the kind of job, a name that stops the same job being queued twice, the number of attempts and an error code. That name can include an AI character's name and a date. For a job to have an AI character answer a reply you left on its thread, it holds the number of the thread, the first part of your public token and the day you replied, and it stays after you leave Community. A job is deleted 30 days after it last ran. No text and no member ID.
    • Notification devices: for each iPhone registered for Community notifications, its Apple push token, whether the app is a development build, the language your app is set to, your iPhone's time zone, your two switches, your member ID, and when it was registered and last changed. A member has at most five; a sixth replaces the one heard from least recently. The token is not the device identifier used for analytics, and the app sends it only to our service.
    • Notification queue: for each notification owed to you, your member ID, the reply it is about or the start of the day whose upvotes it counts, a name that stops it being queued twice, its status, attempts and an error code, and its times. It holds no text anyone wrote and no count: a notification's words are put together when it is sent, from the replier's username or the day's upvote count, and are not kept.
    • Moderation log: a line for each action a moderator takes on a post, a reply or a member, including a username change made through support; for each post or reply a report from a member in good standing hides at once, or our scheduled jobs hide because a report went unanswered for 20 hours, clear or delete under Section 9, or remove because the post it answered was removed; for each post or reply whose translations our scheduled jobs withdraw because a report that a translation was wrong went unanswered for 20 hours; for each post or reply shown again because every member whose report kept it hidden left Community; for each post or reply hidden because its author's access to Community was removed, or shown again because the removal was lifted; and for a removal from Community that five confirmed breaches, or a moderator's rejection under rule 2, 4, 5 or 9, bring. Each line holds the item number or, for an action on a member, that member's public token, the action, whether a person, the system or a scheduled job took it, a short label, when a moderator enters one or our service sets one, and the time. The checks that refuse, hold or publish a post as it is written add no line, and neither does the deletion of a post kept after your open week only until our checks could read it (Section 9). The log holds nothing you wrote and no member ID, and each line is deleted after 12 months.
    • AI characters, prompts and Notes: Phaze's own AI characters (their names, descriptions, illustrated portraits, the instructions they write under, their posting limits, and who at Phaze approved each one), the prompts written for them, Phaze's own Notes articles, and, when the daily thread inspired by the news is on, the public items it considered, from official health agencies or from its calendar of yearly days and seasons, with the verdict each was given. Nothing about members.
    • Workers KV: rate-limit counters, keyed by the first part of your public token or by a keyed hash of your IP address, which expire after one minute or after about 25 hours; and a marker of when you last looked at the replies to your posts, keyed by your public token, which expires after 400 days and is deleted when you leave Community. Your IP address is never written to the database.

    None of these records holds your device identifier, your email address or the name you give during onboarding, and none links to the profile or contact records above. When a post or a report has waited 12 or 20 hours for a person, and at once when a post or reply is held because it may show that someone is struggling, our service alerts a person on our team. An alert carries counts and times only: how many items are waiting and for how long, and for a post held because it may show someone is struggling, whether a post or a reply raised the alert and when the newest one was held. It never carries what anyone wrote, a username or a member ID. Your username is whatever you choose it to be, which is why Terms Section 4 asks you not to use your real name. The only things in these records close to a location are the region part of your phone's language setting and, while your iPhone is registered for Community notifications, its time zone, both described above. Community does not use the location Cloudflare derives from a request. With the feed, a thread, a post, a reply, a reaction, a vote, the leaderboard, a member's profile and a search, your app sends a yes-or-no flag saying whether you have Premium, which our service reads to decide whether the end of your open week applies. When it says yes with the feed, the leaderboard or when you open Community, our service writes down the time, at most once an hour, so that your Premium tag can show for seven days after it (Terms, Section 7A.8), and leaving Community deletes it. A no is never stored. When you search Community, your app sends the words you typed to our service to find matching posts and names. They are used only to answer that search, and they are not stored, logged or sent to analytics. While you choose a username, your app asks our service whether it is free once you stop typing. The name is compared with the usernames and holds above, and it is not stored, logged or sent to analytics. The app's analytics (Section 6.2) count what is done in Community, such as opening it, sending a post or reply, with a post's topic and whether it was published, held or refused, a vote up or down, a report with its reason, and a search with a rough count of its results. When a Community notification arrives while Phaze is open, the app's notification event records only its kind, "community_reply" or "community_upvotes". None of these events carries your member ID, your username, what anyone wrote, a report note, search words, or which post or member it was about. Crash reporting receives an error from Community only as a code, such as when our service refuses a request to leave. Your member ID, your username and what you post never go to Mixpanel, Sentry or RevenueCat. Session replay (Section 6.2) can record Community's screens like any other screen, with every text label masked on your phone first.

    On your phone, Community keeps your member ID in the iOS Keychain, and an encrypted copy of the pages you last read (AES-256-GCM, excluded from device and iCloud backup) so Community can show them offline. Posts waiting for review and posts that were refused are never cached. Reports, hides and deletions you make while offline wait in the same encrypted file until they can be sent. Once a day, while the phone is signed in to iCloud, the app also writes an encrypted copy of your Phaze data to Phaze's own folder in your iCloud account. That copy includes your member ID, so that restoring it lets you keep deleting what you wrote.

  • Phaze storage (optional, iOS, Phaze Pro): kept apart from everything above, by a separate service with its own storage:
    • in a Cloudflare R2 bucket (phaze-backups): each encrypted backup, with the exact time it was saved;
    • in a separate Cloudflare D1 database (phaze-backup): a random backup identifier your iPhone makes, each backup's encrypted summary, its size, a sequence number, and the days a backup was started, saved and last listed;
    • for a day or two, a one-way digest of each request to delete backups, so that a copied request cannot run twice;
    • in Workers KV, rate-limit counters keyed by a keyed hash of your IP address (for IPv6, of its /64 network), which expire within about 25 hours;
    • daily totals that name nobody.

    None of it holds your device identifier, your subscription identifier, an email address, your community member ID or your IP address, and our systems never store it beside, or join it to, the profile, contact or community records above. It can still be lined up with them in one way: the storage records when each backup was saved, and our app analytics and crash reports record when the app is in use, so the two times could be matched. The backup service keeps no request logs. Cloudflare's network sees the IP address of each request as it passes, as it does for all of our services. The backups are stored in the United States (Eastern North America).

  • Request logs and caches: our service logs the IP address, the route, and the size of each request, for reliability and rate limiting. It does not log the text of an Ember message, an insight, a photo, or any health value. A food-scan result is cached for 24 hours against a hash of the image; the image itself is not stored. Daily Insights are never cached or logged.

6. AI features, analytics, and other third-party processors

6.1 AI features

  • Ember (AI chat): when you send Ember a message, the message and a context record are sent through an edge service we operate on Cloudflare to Google Gemini. The context record is your own history, and it is broad. Depending on what you have logged, it can include your name, height, biological sex, activity level and goals; the last 30 days of daily logs, with nutrition, activity, mood, energy, hunger, food noise, sleep, and the side effects you recorded with their severity; 90 days of weight entries with exact values; your exercise entries; your body measurements and body composition; your lab results with their values; your milestones; the dates and notes on your progress photos; and your medication name, current dose, dose schedule, dose dates, cycle phase, and estimated medication level. Individual dose amounts, injection sites, and dose notes are held back. Progress photo images are not sent through Ember, only their dates and notes.
  • Food scan: when you scan a meal, the photo is sent through the same edge service to Google Gemini for nutrient estimation. Our service caches the returned estimate for 24 hours against a hash of the image, so the same photo is not analyzed twice. The photo itself is not stored, and no biometric identifier is extracted from it.
  • Voice meal description: spoken meals are transcribed by Apple Speech Recognition (iOS) or Android SpeechRecognizer. Both are system APIs whose routing Apple and Google control, and Phaze does not force on-device recognition, so on many devices and languages the audio does reach their speech services. The resulting transcript is then sent to Gemini for parsing into food entries.
  • Body composition estimate from photo: if you use this feature, the photo is sent through the edge service to Gemini and a numeric estimate comes back. A confirmation sheet tells you the photo is leaving your phone before it does. No biometric identifier is derived or stored.
  • Daily Insights (paid plans): if you have a paid plan and have granted the AI permission, Phaze sends 90 days of your own log through the edge service to Gemini and gets back a short written summary of the patterns in it. That payload carries your dose dates, side effects with severity, meals with their names and macros, daily totals, sleep, mood, energy, weights, your medication name, and your current dose. It does not carry per-dose amounts, injection sites, dose notes, progress photos, lab values, or body composition. It is never cached or logged on our servers. Every number in the result is re-checked against your own data on your device, and the insight is dropped if a number does not match.
  • Lab and DEXA document import: if you choose automatic extraction, the lab report or DEXA scan image you pick is sent through the edge service to Gemini. A confirmation sheet tells you the document is leaving your phone before it does. You review every extracted value before it is saved.
  • Data import: text you paste, or a file you pick from another app, is sent through the edge service to Gemini so Phaze can identify records for your review. That text can contain medication names and dose amounts.
  • Recommendations, milestones, streaks, and dose-cycle estimation: run on-device. No external service is called.
  • Community checking, translation and AI characters: if you post in Community, Gemini sees what you write in three ways, all through the same edge service. Nothing you write is sent until you have chosen a username and agreed to Community's consent.
    • Checking. The app refuses a post or reply with an email address, a phone number or a link before sending it, so such a post never reaches our service. Every other post and reply first goes through word rules on our service. Words that suggest you may be struggling are held for a person at once, without being sent. A post the other rules would refuse is sent to Gemini first, only to check whether it tells others in Community that you are struggling: if it does, it is held for a person instead, and otherwise it is refused and not stored. If Gemini does not answer that check, the post is refused and not stored. A post that passes the rules is sent to Gemini with our screening instructions, and a score for each rule comes back. Depending on the scores, the post is refused and not stored, held for a person, or published. During your first 48 hours, every post and reply the word rules do not refuse is held for a person, whatever the scores. If Gemini does not answer, the post waits for a person and is scored once Gemini answers again. Until then, a post that tells others in Community that you are struggling in words our rules do not know is not marked as one, and no one is alerted about it. After your open week, if you do not have Premium, a post is sent to Gemini only to check whether it tells others in Community that you are struggling. If it does, it is held for a person, and otherwise it is refused and not stored. If Gemini does not answer then, the words are kept out of sight until they can be checked, and deleted unless they show you are struggling.
    • Translation. Once a post or reply is approved, by a person or automatically, its text is sent to Gemini to be translated into Community's other seven languages. Each translation is checked before anyone sees it: the numbers, units and medication names must match the original. Where a translation fails, readers see the original.
    • AI characters. When a Phaze AI character answers a post or a reply, the text of that post or reply, its topic and its language are sent to Gemini, together with, on a thread a character started, the text of that thread. Its author's username is not sent. Gemini writes the reply under Phaze's instructions. The reply is then checked, by our word rules and by a second Gemini check that reads the reply beside the post or reply it answers and, on a character's thread, that thread, before it is stored. A character's reply to a post that is held waits with the post: the post's author can see it, and other members see it only if a person approves the post. No AI character answers a post or reply while it is held because it shows you may be struggling.
    • For checking only the text is sent, and for translation the text and the languages to translate it into: not your username, your member ID, your topic or your records. An AI character's reply is written from the text, its topic and its language, and nothing else of yours: not your username, your member ID, your records or your other posts. Report notes are never sent to Gemini.
    • This happens under the consent you give on the "Before you post" screen, not under the AI features permission. Withdrawing AI permission in Settings, Privacy does not stop it. Deleting a post or leaving Community does, and it removes what an AI character wrote in answer to you.
    • No AI character in Community is given your logs, your Ember chats or your medication records.
    • Threads inspired by the news. One of Phaze's AI characters may post one short thread a day inspired by something current: a public news item from an official health agency (the FDA, the EMA, the NIH or the WHO), or a yearly day or season. The thread states no news and passes nothing from the item on. It only asks members one question about their own experience or habits, and it is not medical advice. To write it, our service reads those agencies' public news feeds and sends Gemini the public item and the character's own recent threads. Nothing about any member is sent, and before it appears the thread is checked like every other character post, and against the item, so that nothing from the item is passed on.

Important about AI features:

  • AI responses can be inaccurate, incomplete, or out of date. Ember does not provide medical advice, dose recommendations, contraindication guidance, or symptom triage. Our edge service screens every message first, and answers a dosing, drug-interaction, or symptom-triage question with a referral to your provider instead of calling Gemini at all. For dosing decisions, side-effect concerns, or any clinical question, contact your prescribing healthcare provider.
  • We do not train any model on your data. We use Google's paid Gemini API, and Google's terms for that tier state that prompts and responses sent to it are not used to train Google's models.
  • AI features stay off until you agree. The first time a feature needs to send data to Gemini, Phaze shows what will be sent and asks for permission, and records which version of that disclosure you agreed to and when. Settings, Privacy has an AI features switch and a Withdraw AI permission button. Withdrawing stops every AI feature at once and clears the insights already generated. Community's checking and translation are separate, and run under Community's own consent described above.
  • Following the EU AI Act Article 50, Ember responses carry a per-output "AI-generated" label, Daily Insights carry an "AI generated" label, and AI food-scan estimates are marked with an AI badge. In Community, a post shown in translation is marked "Translated automatically", with the original one tap away. Posts and replies by Phaze's AI characters carry no label of their own. Instead, the "Before you post" step, which opens before your first post, reply or vote, says that some members are Phaze AI characters and that their profiles say so, and each character's profile shows the tag "Phaze AI" beside its name. Our service also marks everything a character writes, and every translation, as AI-generated in the data it sends to the app.

6.2 Analytics, crash reporting, and attribution

We use the following third-party tools. Each one receives the categories described.

ToolPurposeWhat is sentWhere
MixpanelProduct analyticsPseudonymized event payloads linked to a device-generated identifier. No email address and no name. Events carry which screen you opened and which action you took, plus your mood and energy ratings from a daily check-in and the name of a lab biomarker you added. Weight values, water amounts, meal macros, food names, medication names and dose amounts are not sent. User properties include your medication administration type ("injectable", "oral", or "none"), days since start, subscription state, and app version. The combination is pseudonymous, not anonymous, because all events for one device link to the same identifier.United States
Mixpanel Session ReplayScreen recording of sampled sessionsA replay of the app's screen for about 10% of sessions, chosen at random, uploaded and linked to the same device identifier as your events. Every text label, image, web view, map, and input field is masked on your device before a frame is uploaded, so a medication name, a dose, a side effect, or an injection site is redacted before it leaves the phone. Turning analytics off in Settings, Privacy stops the recording.United States
SentryCrash and error monitoringCrash reports, error stacks, navigation and UI-click breadcrumbs, and a snapshot of the on-screen view hierarchy at the moment of a crash. Medication identifiers, doses, side-effect entries, injection-site notes, and your medical profile are matched and removed from breadcrumbs and event payloads before transmission, and a breadcrumb that matches is dropped whole. Your name and email are stripped. The user identifier is a device-scoped ID. Administration type is attached as a context field. The same analytics switch in Settings, Privacy turns crash reporting off.United States
RevenueCatSubscription stateSubscription identifiers, purchase confirmations, RevenueCat customer ID (mapped to your Mixpanel distinct ID). No health values.United States
Meta (Facebook) Aggregated Event Measurement SDKInstall and conversion attributionApp install, app launch, and conversion events, for example a subscription. Each event carries an identifier the SDK creates and stores on your device, plus basic device information such as model and OS version. No medication, dose, weight, or food values. The advertising ID (IDFA on iOS, GAID on Android) is not collected; that is switched off in our configuration. On iOS, Phaze shows Apple's App Tracking Transparency prompt for this attribution. Declining it moves the SDK to its aggregate measurement path, and events are still sent.United States
TikTok Business SDK (Android only)Install and conversion attributionApp install, app launch, two-day retention, and purchase events, all tracked automatically by the SDK. No medication, dose, weight, or food values. This SDK is not present in the iOS app.United States
Backup storageUser-controlled storageEncrypted archive (see Section 5.2): the daily copy on iOS, and Cloud Backup on Android if you turn it on.Your own iCloud Drive (iOS) or Google Drive AppData folder (Android)
App distributionApple App Store, Google PlayStandard store telemetryUnited States, Ireland (EU)
Phaze edge serviceCloudflare Workers, D1 and KVProxies the AI requests in Section 6.1, runs Community, and holds the records in Section 5.4. Logs the IP address, route, and size of each request. Does not log message text or health values. Community's log lines record what kind of action happened and its outcome, never the text, your member ID or your username.United States, Cloudflare global edge
Apple Push Notification serviceCommunity notifications on iOS, on by default once you have agreed to Community's terms, while Phaze may show notifications on your iPhone and you keep the switches onYour iPhone's push token and each notification: the title "Community", who replied (their username) or how many upvotes you got that day, and a link to the thread or to Community. Never what anyone wrote, no member ID and no health values.United States
Google Firebase Cloud Messaging (Android)Optional Community notifications on AndroidFCM token, Firebase installation ID, and each notification's title, body and link. The body may contain a replier's username or the day's upvote count. No post text, member ID, medication or dose values.United States
Food dataUSDA FoodData Central, Open Food FactsNutrient lookups. USDA searches go through our edge service, so USDA sees our server and not you. Open Food Facts barcode lookups go straight from your device, so it sees your IP address. We send a food name or a barcode, never your weight or your medication.United States, Europe
Recipes (Android)SpoonacularRecipe queriesUnited States
Health platformsApple HealthKit, Google Health Connect (only if you authorize)Read and write of the categories you authorizeOn your device

We do not engage providers other than those listed above for the processing of your personal information. We require each provider to (i) act only on our instructions, (ii) implement appropriate security, (iii) not use your data for their own purposes other than aggregate statistics necessary for the service, and (iv) honor your deletion requests passed through us.

Those requirements bind the providers that process data on our behalf. Some recipients in the table are not our processors and act under their own terms and privacy policies: Apple and Google, for the app stores, Apple's push service and your own iCloud Drive or Google Drive; Meta and TikTok, for the install attribution events; and the food and recipe databases (USDA, Open Food Facts and Spoonacular), for your lookups. Each receives only what the table says. A deletion request you send us does not reach them, and each one's privacy policy says what it keeps and how to ask it to delete it.

6.3 What about advertising trackers?

In the Phaze mobile app we use the Meta Aggregated Event Measurement SDK on both platforms, and the TikTok Business SDK on Android, for install attribution. They tell us which campaign brought a new user to Phaze. They are not used to serve advertising inside Phaze, and no health value is sent to either. On iOS, Phaze shows Apple's App Tracking Transparency prompt for Meta attribution. We do not embed Meta Pixel, TikTok web pixel, Snap Pixel, Google Ads conversion tags, Pinterest tag, or LinkedIn Insight tag on phaze.fit. We do not sell your personal information.

7. Apple HealthKit and Google Health Connect

Phaze integrates with Apple HealthKit (iOS, watchOS) and Google Health Connect (Android) only if you authorize it. You choose which categories to share. You can revoke this access at any time from your device system settings.

In accordance with Apple's HealthKit terms (Apple Developer Program License Agreement section 5.1.4) and Google's Health Connect terms:

  • We do not use HealthKit or Health Connect data for advertising or other use-based data mining purposes other than improving health, medical, and fitness management, or for the purpose of medical research.
  • We do not sell HealthKit or Health Connect data to advertising platforms, data brokers, or information resellers.
  • We do not share HealthKit or Health Connect data with third parties for advertising or marketing purposes.
  • We do not use HealthKit or Health Connect data to identify users beyond what is necessary for personalization within Phaze.
  • We will not access an end user's HealthKit or Health Connect data without their authorization.

HealthKit and Health Connect data is stored on your device. What Phaze records from them, such as weights and activity, becomes part of your Phaze data, so it is included in the encrypted daily copy on iOS and, if you enable Cloud Backup, in the encrypted Android archive (Section 5.2).

8. Sharing

We share personal information only in these limited cases:

  • With your direction: when you choose to export a PDF report, share a milestone card, send a screenshot, or grant a feature access to your data.
  • With other members of Community: when you post or reply, every member of Community can read it, under your username, in the original and in seven translations. Other members' apps receive your username, an avatar number, your tags, your karma unless you turn it off, and your public token. They never receive your member ID. Every post you write carries the same username, so your posts can be linked to each other, and to you by anyone who recognises the name. Tapping your username opens your Community profile (Section 3.1), which puts the posts and replies of yours that Community shows on one page, with the month you joined and your tags. If you switch on your logging streak, your medication or your dose, treat each field you switched on as public: every member who opens your profile can see it, except members you hid and members who hid you. When you reply to a member's post, they may get a notification on their iPhone that shows your username.
  • With processors: the third-party providers listed in Section 6, bound by data-processing terms.
  • For legal reasons: to comply with valid legal process (subpoena, court order), respond to government requests where required by law, or protect the safety and rights of Phaze, our users, or the public. We narrow disclosures to what is legally required.
  • Business transfer: if Phaze is acquired, merged, or assets transferred, your information may be transferred to the successor entity subject to this Policy. You will be notified of any material change in handling.

We do not "sell" your personal information as that term is defined under the California Consumer Privacy Act, Washington My Health My Data Act, Connecticut Data Privacy Act, Texas Data Privacy and Security Act, or any other applicable law. We do share app install, app launch, and subscription events with Meta on both platforms, and with TikTok on Android, so we can tell which ad brought someone to Phaze. Each event carries an identifier the attribution SDK creates and stores on your device, plus basic device information such as model and OS version. No medication, dose, weight, food, or other health value is included. Meta and TikTok can use these events to measure and target advertising on their own platforms, which some state laws count as "sharing" for "cross-context behavioral advertising." We do not show ads inside Phaze.

9. Retention

CategoryRetention
Records on our own servers (Section 5.4)Profile and contact rows until you switch profile sharing off or use Delete All Data. Rankings until you leave, or 30 days after your entry was last updated. Feedback and roadmap entries until you ask us to remove them. Community records: see the rows below.
Phaze storage backupsThe newest three of your backups; the newest one that is at least a week older than your latest, and the one that will next take its place, so that a copy is always on its way to being a week old; and at most one earlier copy, kept when a new backup is much smaller than the one before it. An upload that never finished is removed within seven days. Everything is deleted after two years with no backup, list or restore. Device Backup shows that date and warns you in its last 60 days. If Phaze may show notifications, your iPhone also shows one reminder 30 days before. It is made on your iPhone, and we send no email or other message from our servers, because Phaze has no account to send one to. Delete from Phaze deletes the backups at once, and so does Delete All Data when you choose it, waiting until your phone is next online if it is offline. Anything left in storage is purged within 30 days, and the database's recovery history keeps the index rows for up to 30 days more. A deleted backup's random identifier, with nothing else, is kept for seven days so that a copied upload cannot bring it back. The digest of a deletion request is kept for a day or two, and the rate-limit counters for about 25 hours.
Research answersNo time limit. They carry no identifier, so we cannot find one person's answers to remove them.
Research contact notesUntil your profile row is deleted, when you switch profile sharing off or use Delete All Data.
Health, medication, body, nutrition, activity data you logOn your device until you delete it. On iOS, in the daily copies in your iCloud Drive until newer copies replace them or they are deleted (Section 5.2). In an Android Cloud Backup until the backup is deleted. Not stored on our servers. The one exception is a Phaze storage backup you choose, which our service keeps end-to-end encrypted and cannot read (see the Phaze storage row).
Community posts and replies that are publishedUntil you delete them or leave Community.
Community posts and replies held for reviewIf no one approves them, the text and the screening scores are cleared 30 days after posting. This includes posts held because they show you may be struggling.
Community posts and replies refused automaticallyNever stored.
Community posts and replies refused after your open week while our checks were unavailableKept out of sight, never shown to anyone and never counted, until our checks can read them. Deleted then, unless they show you are struggling, in which case they are held for a person like the posts held for review above. If the checks stay unavailable, the text is cleared 30 days after it was written.
Community posts and replies a moderator rejectsThe text, the screening scores and any translations are cleared at once. If the rejection removed your access to Community, the translations are cleared at once, but the text and the screening scores are kept 90 days after the rejection while your access stays removed, like the rest of what you published, so that a second look has them to read. If the removal is lifted, they are cleared within minutes. An empty row with the reason stays until you delete it or leave Community.
Community posts and replies hidden after a report, by a moderator, or because your access to Community was removedKept out of sight of other members. The text, the screening scores and any translations are cleared 30 days after the item was hidden, or 90 days after it while your access to Community stays removed, so that a second look has them to read. While a report about the item is still waiting for a person, they are kept until a person has decided, and the 30 or 90 days then run from that decision, because a person cannot decide on words that are gone. If the removal is lifted, the posts and replies whose text is still kept are shown again. An empty row stays until you delete it or leave Community.
Community posts and replies you deleteThe text, its translations and its reactions are removed at once, and so is the note on any report about it, and so is anything a Phaze AI character wrote in answer to it. The empty row is removed about 30 days later, together with any replies other members left under a deleted post and their translations, reactions and reports. If a moderator had confirmed a breach in the item, its empty row is removed only once both 30 days have passed since you deleted it and 37 days since that decision, so that the breach counts for as long as Terms Section 7A.3 says it does, and a deleted post is kept the same way while such a reply sits under it.
Community translationsUntil the item is deleted, a moderator rejects it, its text is cleared under the rows above, or its author leaves Community. Where a translation failed our checks, what is kept is a copy of the original.
Community reactionsUntil you take the reaction back, the item is deleted, or you or its author leave Community.
Community votesUntil you take the vote back, the item is deleted, or you or its author leave Community.
Your karma and tagsRecomputed every few minutes from the votes and posts that count. Leaving Community resets your karma to zero and deletes your tags and the time your app last said you have Premium.
Cheers from Phaze's AI charactersUntil the post or reply is deleted, or its author leaves Community. A cheer on a post a moderator rejects, or on a post that may show its author is struggling, is removed sooner.
Community reportsUntil you or the author of the reported item leave Community, or the reported item's empty row is removed. The note is cleared when the author deletes the item.
Members you hid in CommunityUntil you show them again, or either of you leaves Community.
Days you were in CommunityUntil you leave Community.
Your logging streak, medication and dose on your Community profileEach while its own switch is on. Switching one off deletes it from our servers at once, even while Community is closed, and leaving Community and Delete All Data delete all three. If you are removed from Community, no member can see them from that moment, and they are deleted at once, or, for a removal made from our moderation console, by our scheduled cleanup, which runs every few minutes and deletes any that are left for a member who has left or been removed.
Your community usernameWhile you are a member. When you leave, or when support changes it at your request, the old username is held for 30 days, in the compared form described in Section 5.4 and with no member attached to it, so that no one can take it over mid-conversation. The hold is deleted once the 30 days are up, or sooner if a person on our support team releases it.
Your Community membership recordWhile you are a member. When you leave, it is reduced to your member ID, its public token, the status "left" (or "removed", if your access to Community had been removed), your strike count, your avatar number, whether the row is a member's, the open-week dates, until when your reports cannot hide a post at once (at most 30 days ahead), and when it was created and last changed. That is kept with no time limit so that leaving and coming back does not start a new open week, and so that leaving does not lift a removal or undo a moderator turning down one of your reports. If you open Community or its page in Settings, Community again, the record becomes active again, with no username until you choose a new one, unless your access had been removed.
Community's moderation log12 months from each line, then deleted. It holds nothing you wrote and no member ID. A line about an action on your membership, such as a pause, a removal or a username change, names your public token.
Community's work queue30 days after each job last ran, then deleted. It holds nothing you wrote and no member ID. Where a job was queued to have an AI character answer a reply you left on its thread, it keeps the thread, the day and the first part of your public token for those 30 days, and leaving Community does not remove that sooner.
Community notification devicesUntil you leave Community, use Delete All Data or turn off Phaze's notifications in iOS Settings (then the next time you open Phaze), or 180 days after the app last updated the record. Deleted at once when Apple reports that the token no longer works, and when your access to Community is removed, or, for a removal made from our moderation console, by our scheduled cleanup within minutes. Turning both switches off stops the notifications and keeps the iPhone on the list with both off.
Community's notification queue30 days after each notification was queued, then deleted. Leaving Community deletes yours at once. A reply notification not sent within six hours, and a daily count not sent by 10 in the evening, is dropped unsent.
Community's rate-limit counters and last-read marker (Workers KV)Rate-limit counters: one minute, or about 25 hours. The marker of when you last looked at your replies: 400 days, and deleted when you leave Community.
Database recovery historyCloudflare D1 keeps a point-in-time recovery history of our database for up to 30 days, so Community content we remove can stay in that history for up to 30 days more. It is not readable by other members.
Community on your phoneThe encrypted copy of the pages you read is deleted when you leave Community or use Delete All Data. Your member ID stays in the Keychain after you leave, so you can come back, and is removed by Delete All Data. The push token and your notification switches stay in the app's settings on your phone until Delete All Data.
Subscription records7 years (tax and accounting obligations)
Diagnostic and crash logs90 days, sanitized
Support correspondence24 months from last message
Aggregated, irreversibly anonymized statisticsRetained indefinitely (no longer personal data)
Legal holdAs required by law
Edge request logs, rate-limit counters, and the result cachesCloudflare's log retention window. Food-scan, meal-description and food-search results are cached for 24 hours, and recipe results for six hours.

On Android, a Community notification device is removed when you leave, use Delete All Data, or revoke Phaze notification permission and next open the app; otherwise it expires 180 days after its last update. If Firebase says its token no longer works, we remove the device after that delivery attempt. Turning both in-app switches off stops delivery but keeps the device registered with both off. The encrypted Community page cache is erased when you leave or use Delete All Data. Community-only Leave keeps your encrypted member ID for a later return; Delete All Data removes it, while a pending server-erasure marker stays until deletion is confirmed. Disabling Community notifications or revoking permission deletes the local FCM token.

When you use Delete All Data in the app, one action removes the data on your device, deletes the Phaze backup files it can reach in your iCloud Drive or Google Drive (Section 5.2 explains when it cannot), cancels every scheduled reminder, opts your device out of analytics, session replay, and crash reporting, and deletes your profile and contact rows from our servers. It also asks our service to remove everything you wrote in Community, the same as Leave Community. If your phone is offline at that moment, the app keeps only the identifiers and pending deletion markers needed to complete server erasure, including your former Community member ID and, on Android, this device's profile ID, and sends the request again each time you open Phaze until our service confirms it. If you uninstall Phaze before that happens, the request is lost with the app. In that case, email privacy@phaze.fit (Section 12). If you have Phaze storage backups, Delete All Data asks whether to delete them too. If you say yes, it deletes the backups every one of your iPhones saved up to that moment, and your recovery code stops working. A key made on another iPhone that had not reached this one yet is not covered, and backups another iPhone makes later are kept. If you say no, the backups and their key stay, and the key also stays on this iPhone until you sign out of iCloud on it. To have a feedback message or a roadmap entry removed, email privacy@phaze.fit. Subscription and tax records are kept where the law requires.

If an iPhone is offline during Delete All Data, its separate request to delete the server profile and contact row can fail without an automatic retry. Email privacy@phaze.fit to complete that deletion. Android keeps a pending device-ID marker and retries that profile deletion when the app next opens online.

10. Security

We implement reasonable administrative, technical, and physical safeguards:

  • AES-256-GCM at rest on device and for backup archives
  • End-to-end encryption for Phaze storage: each backup is encrypted on your iPhone with AES-256-GCM under a key our service never receives, and your iPhone signs each request it makes to the backup service
  • TLS 1.3 in transit
  • Apple Keychain and iOS Data Protection (iOS)
  • Android Keystore plus EncryptedSharedPreferences (Android)
  • Role-based access control on internal tools
  • Code review and automated tests before a release that changes how data is handled
  • Vendor diligence on processors

Phaze storage has two limits we want you to know. Our service can see the size of each backup, to the mebibyte, and when it was saved, and those times could be matched with our analytics (Section 5.4). And replacing your recovery code protects you against a lost iPhone only once that iPhone is removed from your Apple Account, because the new key reaches every device still signed in to it.

No method of transmission or storage is perfectly secure. We do not claim to be HIPAA-compliant, and Phaze is not a HIPAA-covered entity.

Breach notification. If we discover a security incident that compromises the confidentiality of your personal information, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318), GDPR Article 33 and 34, LGPD Article 48, and applicable state breach-notification laws. Where required, we will notify affected individuals within 60 days of discovery (HBNR) and applicable regulators within 72 hours (GDPR).

11. Children

Phaze is intended for users 18 years of age or older. Onboarding asks for a date of birth and will not let you continue if it puts you under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact privacy@phaze.fit and we will delete it.

Community checks your age before you join and is not open to anyone under 16. It uses the date of birth in your profile, or on iOS 26 and later the age range you or a parent chose to share through Apple, or it asks you once for your date of birth. Our service is told only that you are old enough to join, never your age, your age range or your date of birth.

If we discover that we have collected personal information from a person under 18, we will delete that information promptly.

12. Your choices and rights

You have the following choices regardless of where you live:

  • Access and export: view your data in-app. Settings, Privacy, Export Data gives a JSON file of your logs; that file leaves medical fields out for security, so use Settings, My Report for a PDF that includes your medication, your recent doses, and your side effects.
  • Correct: edit any entry in-app.
  • Delete: delete individual entries, or use Settings, Privacy, Delete Everything, Delete All Data. That one action removes the data on your device, deletes the Phaze backup files it can reach in your iCloud Drive or Google Drive (Section 5.2 explains when it cannot), cancels scheduled reminders, opts your device out of analytics and crash reporting, and deletes your profile and contact rows from our servers. It also leaves Community for you, and asks whether to delete your Phaze storage backups (Section 9).
  • Disable AI features: Settings, Privacy has an AI features switch and a Withdraw AI permission button. Withdrawing stops every AI feature at once and clears the insights already generated. It does not stop Community's checking and translation, which run under Community's own consent (Section 6.1).
  • Delete a community post or reply: tap Delete on anything you wrote, in Community or under Yours. The text goes at once. Section 9 has the rest.
  • Leave Community: Settings, Community, Leave Community. In one step, our service deletes every post and reply you wrote, the replies other members left under your posts, the translations of all of them, what Phaze's AI characters wrote in answer to you, your reactions and votes, the votes on what you wrote, your karma, the reports you filed and the reports about what you wrote, the members you hid and the hides other members set on you, the days you were present, your username, your consent record, the fields on your profile, the iPhones registered for Community notifications and every notification queued for you. Your username is then held for 30 days before anyone can take it, unless a person on our support team releases it sooner. What else is kept, and why, is in Section 9. Leaving works after your open week has ended and while Community is closed. If your access to Community had been removed, leaving deletes what you wrote but does not restore your access. Otherwise, if you open Community or its page in Settings, Community again after leaving, you become a member again, and you choose a new username before you write.
  • Change your community username: write to support@phaze.fit. A person makes the change, under the same rules as a new username (Terms Section 4), and your old username is held for 30 days before anyone can take it, unless a person on our support team releases it sooner. The app has no way to change it.
  • Stop showing your logging streak, your medication or your dose: turn that field's switch off in Settings, Community. The value is deleted from our servers at once, even while Community is closed.
  • Stop Community notifications: on each iPhone, turn off Replies to me or Upvotes, once a day in Settings, Community, Notifications, which changes that iPhone only, or turn off Phaze's notifications in iOS Settings, which also takes that iPhone off our list the next time you open Phaze.
  • If you no longer have the phone you posted from: email privacy@phaze.fit with the username your posts show now. We keep only a member's current username. A username that was given up is kept for 30 days with no member attached to it, so an old username may not lead us to you. We look the username up and remove what it wrote the same way Leave Community does. A username is public, so we may ask you for details that only the author would know, such as roughly when and in which topics you posted, before we delete.
  • Ask for a second look at a Community decision: write to support@phaze.fit if a post of yours was held or removed, or your access was restricted, and you think it was a mistake. A person reviews it.
  • Delete your Phaze storage backups: Settings, Data and Privacy, Device Backup, Delete from Phaze deletes them from our service at once.
  • Get a copy of a Phaze storage backup: restore it on your iPhone. We cannot give you a readable copy, because we have none.
  • Disconnect HealthKit or Health Connect: revoke from device system settings.
  • Stop backups: on Android, toggle it off in Settings, Cloud Backup. On iOS, first remove the copies already written: use Delete All Data, which also removes the data on your device, or delete Phaze's data in your iPhone's iCloud storage settings. Then turn off iCloud Drive for Phaze in your iPhone's iCloud settings, which stops the daily copy. Once iCloud Drive is off for Phaze, Delete All Data can no longer reach the copies.
  • Opt out of analytics: Settings, Privacy has one switch that turns off product analytics, session replay, and crash reporting together. That switch does not cover the install-attribution SDKs. For those, use your platform's controls: App Tracking Transparency on iOS, and the advertising ID controls in Android settings. Declining App Tracking Transparency moves Meta to its aggregate measurement path. It does not stop install and launch events from being sent.
  • Push notifications: disable in device system settings.

To exercise any right not available in-app, email privacy@phaze.fit. We will verify your identity (typically by matching to the email of record) and respond within the timeframe required by your local law (generally 30 days under GDPR, 15 days under LGPD, 45 days under CCPA). If we cannot complete the request in that time, we will tell you why and what timeframe applies. You may appoint an authorized agent under CCPA and CPRA.

13. Jurisdiction-specific notices

13.1 European Economic Area and United Kingdom (GDPR / UK GDPR)

Controller and representatives: Zeit Capital Ltda. EU Representative: not currently appointed; see Section 1 for status and contact route. UK Representative: not currently appointed; see Section 1.

Lawful basis: see Section 4 table. We rely on explicit consent for special category health data (Art 9(2)(a) GDPR).

Your rights: access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), portability (Art 20), object (Art 21), withdraw consent (Art 7(3)), and not be subject to solely automated decisions with legal or similarly significant effects (Art 22). Automated decision-making: AI-generated suggestions in Ember and food scan are decision-support, not solely automated decisions with legal effects. You can disable them and continue using Phaze. In Community, automated checks can refuse a post or hold it for a person, and a report from a member in good standing can hide a post until a person reviews it (Terms, Section 7A.4). Only a person can count a breach against you. The seven-day pause after three confirmed breaches, the removal of your access after five, and the removal of your access when a moderator rejects a post of yours under rule 2, 4, 5 or 9 follow from those decisions by a fixed rule (Terms, Sections 7A.2 and 7A.3). A moderator can also pause your posting or remove your access directly, and that is a decision by a person too.

International transfers: We are based in Brazil. Your data may be transferred to the United States or other jurisdictions where our processors operate. We rely on EU Standard Contractual Clauses with our processors and, where a processor is certified, on the EU-U.S. Data Privacy Framework. Contact privacy@phaze.fit for details of the safeguards in place for a specific transfer.

Complaints: you may lodge a complaint with the supervisory authority of your habitual residence. For UK users: the Information Commissioner's Office (ico.org.uk). Cookies and similar technologies on phaze.fit are covered in Section 14.

13.2 Brazil (LGPD)

Controller: Zeit Capital Ltda, registered in Brazil. Encarregado de Dados: Vinicius, privacy@phaze.fit.

Legal bases: Article 7 (general) and Article 11 (sensitive data: health, biometric where applicable). We rely on specific consent (Art 11(I)) for health data.

Community. Health data you publish in Community rests on consent given in the form Article 11(I) asks for: specific and highlighted. The first time you start a post or a reply, the "Before you post" screen shows four short lines, one of which says that some members are Phaze AI characters, and a single checkbox, which starts unticked: "I consent to Phaze storing and processing what I post, including health information, as described." Under "More details" on the same screen, the section "What happens to what you write" names each purpose (storing the post, checking it, translating it, having an AI character reply to some posts, and showing it to other members), names the processor (Google Gemini), and says the data is stored on servers in the United States. The checkbox is for this consent alone: you accept the Terms and the Community Guidelines by pressing "Agree and continue", which cannot be pressed until the box is ticked. The consent is also kept apart from the AI features permission. The app records your answer on your phone and sends it to our service to be recorded there. Our service stores and processes no post or reply until it has recorded your consent to the current version. You revoke it by deleting a post or by leaving Community (Section 12). We never communicate or share health data from Community with another controller to obtain an economic advantage (Art 11 §4).

Your rights (Art 18): confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; deletion of data processed with consent; information about public and private entities with whom we share; information about the possibility of not providing consent; revocation of consent.

International transfers: we use standard contractual clauses approved by ANPD (Resolucao CD/ANPD no 19/2024) for cross-border transfers where applicable.

ANPD: you may submit a complaint to the Autoridade Nacional de Protecao de Dados (gov.br/anpd).

13.3 California (CCPA / CPRA)

We collect the following CCPA categories of personal information:

CategoryExamples
Identifiersname, email, device ID, community member ID and username, and the push token used for Community notifications
Customer recordsaccount profile
Internet/network activityapp usage, crash logs
Geolocation (approximate)city-level from IP
Audiovoice meal descriptions (transient)
Sensoryprogress photos
Sensitive Personal Information (SPI)health information, progress photos

Sale and share: we do not sell personal information (including SPI) for money or other valuable consideration. We do disclose app install, app launch, and subscription events to Meta, and on Android to TikTok, for advertising attribution. Each event carries an identifier the attribution SDK creates and stores on your device, plus basic device information. No SPI and no health value is included. Because Meta and TikTok can use these events for their own ad measurement and targeting, we treat this as a "share" for cross-context behavioral advertising rather than claim it falls outside the definition. Sources are: directly from you, from your device, from Apple HealthKit or Google Health Connect if you authorize. Business purposes are as listed in Section 4. Disclosure to other third parties is limited to the processors listed in Section 6, in their service-provider capacity, and, if you post in Community, the other members of Community, at your direction (Section 8).

Phaze storage: a Phaze storage backup is sensitive personal information that we keep only to provide the backup you asked for. We never sell or share it, and we cannot read it.

Your CCPA rights: know, access, delete, correct, opt-out of sale or share, limit use of Sensitive Personal Information, no retaliation, authorized agent. We do not sell. No setting in Phaze stops the attribution sharing described above: declining App Tracking Transparency on iOS moves Meta to its aggregate measurement path, and the advertising ID controls in Android settings govern only your device's advertising ID, but in both cases the attribution events are still sent. Submit requests to privacy@phaze.fit. Premium subscription tiers ("Phaze Pro") are payment for additional features, not a "financial incentive" tied to data collection. Shine the Light: you may request information about disclosures of personal information to third parties for direct marketing. We make none.

Universal opt-out signals (GPC): we honor Global Privacy Control signals on phaze.fit.

13.4 Washington (My Health My Data Act)

See the Consumer Health Data Privacy Policy for the disclosures required by the Washington My Health My Data Act, including categories of consumer health data, purposes, third parties, your right to withdraw consent, delete, and appeal.

13.5 Other US states (CO, CT, VA, UT, TX, OR, MT, IA, DE, NJ, MD, MN, NH, RI, TN, NV)

Residents of these states have rights including access, correction, deletion, portability, and opt-out of targeted advertising or sale. We do not sell personal information. The install-attribution events described in Section 13.3 may count as targeted advertising under some of these laws. No setting in Phaze stops them, and Section 13.3 explains what the iOS and Android controls change and what they do not. Health information is treated as sensitive data and we obtain opt-in consent before processing. Universal opt-out signals are honored where required. Submit requests to privacy@phaze.fit.

13.6 Japan (APPI)

Health data is treated as special care-required personal information and processed only with your opt-in consent. International transfer recipients and their data-protection frameworks are disclosed in Section 6.

13.7 China (PIPL)

Phaze does not actively offer the Service in mainland China. The Simplified Chinese localization is provided for users in other regions. Users in mainland China should not use the Service.

14. Cookies and similar technologies (phaze.fit)

The phaze.fit website uses:

  • Strictly necessary cookies: a country cookie set from your IP-derived country header, used for locale and pricing routing; a sidebar_state cookie that remembers whether the documentation sidebar is open; a cookie_consent cookie that records your answer to the notice below; and a gpc cookie set when your browser sends a Global Privacy Control signal.
  • First-party performance and analytics: Vercel Analytics and Vercel Speed Insights, which use first-party storage and do not load third-party tracking pixels.

When you open phaze.fit from a link in the Phaze app, we count the visit by app screen, page, platform and language, in aggregate, and the count keeps no IP address, cookie or other identifier.

We do not embed Meta Pixel, TikTok Pixel, Snap Pixel, Google Ads conversion tag, Pinterest tag, or LinkedIn Insight tag on phaze.fit, so the website shares nothing for cross-context behavioral advertising. The app's install-attribution events, which we treat as such a share, are described below and in Section 8.

phaze.fit sets no optional cookies, so the banner is a notice with a single acknowledgement rather than an accept-or-reject choice. A Global Privacy Control signal is treated as a rejection without prompting you. Your Privacy Choices in the footer reopens the notice, and you can clear cookies from your browser settings at any time.

The Phaze mobile app uses the Meta Aggregated Event Measurement SDK on both platforms and the TikTok Business SDK on Android, for install attribution. On iOS, Phaze shows Apple's App Tracking Transparency prompt for Meta attribution. We do not use these SDKs to serve personalized advertising within Phaze, and we do not embed advertising tags on phaze.fit.

15. Changes to this Policy

We will post material changes here and notify you in-app or by email at least 30 days before they take effect, except where a shorter timeframe is required by law. We will not apply material new uses to data we already hold without obtaining your consent where required.

A new optional feature applies to you from when you first use it. The version of September 30, 2026 adds new optional features: Community, with its notifications, its thread inspired by the news and the fields you can show on your profile, and Phaze storage for backups. It takes effect on that date because it changes nothing about how we use data we already hold, and each of those features starts only once you use it.

16. Contact

Questions, requests, complaints:

  • Email: privacy@phaze.fit
  • Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
  • Brazilian Encarregado: Vinicius (privacy@phaze.fit)
  • EU Representative: not currently appointed (see Section 1)
  • UK Representative: not currently appointed (see Section 1)

We aim to respond to all requests within 30 days, or sooner where required by law.

Phaze is not a medical device. The Service does not provide medical advice, diagnosis, or treatment. Always consult your healthcare provider regarding medications, dosing, or symptoms.

Back to Home