Privacy Policy
Physique: Body Measurements
Last updated: 4 October 2026
Effective: 4 October 2026
Version: 1.0
Consumer Health Data Privacy Policy (Washington, Nevada, Connecticut and other states with consumer health data laws)
This policy explains how Physique handles your personal information. It covers the Physique iOS app, the Physique websites (getphysique.app and connect.getphysique.app), the Physique connection service for AI assistants (the "agent access" service, including the MCP server at https://connect.getphysique.app/mcp), and the physique command-line tool (the "CLI"). Together these are "Physique" or "the service".
If you live in Washington, Nevada or Connecticut, or anywhere else with a consumer health data law, also read our Consumer Health Data Privacy Policy, which is part of this policy.
Summary
- What Physique is. A private log for body measurements (weight, body fat, waist, chest and similar). It is a wellness tool, not a medical service.
- What we collect. Your sign-in details from Apple or Google (name, email, an account ID), the measurements and notes you enter, your display settings, basic app analytics and crash reports, and technical logs from our servers.
- Your measurements are sensitive. We treat them as health data. We use them only to show them back to you, sync them between your devices, and give them to an AI assistant if you connect one.
- No ads, no selling, no tracking. We do not sell your data, share it for advertising, show ads, or track you across other companies' apps or websites. Analytics never include your measurement values or notes, are not linked to your account, and can be turned off in Settings.
- AI assistants are your choice. An assistant can only see or change your data after you sign in and approve it. You can revoke access at any time on the connections page.
- Where it is stored. Your measurements are stored by Google Firebase in the European Union. Some supporting services (sign-in, analytics, crash reports) run on Google's servers in the United States.
- You are in control. You can view, edit and delete entries at any time, export everything as CSV or JSON, and delete your account in the app (Settings → Delete account). You can contact us at support@sergeytyo.com.
1. Who we are
Physique is developed and operated by Sergey Tyo, an individual developer based in New Zealand ("we", "us", "our"). We are the controller of the personal information described in this policy (the "agency" under the New Zealand Privacy Act 2020).
- Email: support@sergeytyo.com (for any privacy question or request, including from outside New Zealand)
We have not appointed a data protection officer; questions go directly to the developer at the address above.
The App Store name of the app is Physique: Body Measurements. You may also see the internal code name "MeasureMe" or the bundle identifier com.stapps.MeasureMe; they refer to the same app.
2. What information we collect
2.1 Account and sign-in information
You sign in with Sign in with Apple or Google Sign-In. Our sign-in provider, Google Firebase Authentication, receives from Apple or Google:
| Data | Source | Notes |
|---|---|---|
| Name | Apple or Google | Apple shares your name only the first time you sign in, and only if you choose to share it. |
| Email address | Apple or Google | With Apple you can choose Hide My Email; we then receive a private relay address (…@privaterelay.appleid.com) instead of your real address. |
| Provider account identifier | Apple or Google | A stable identifier for your Apple or Google account, used to recognise you when you sign in again. |
| Firebase user ID | Generated by Firebase | A random identifier for your Physique account. |
| Physique account ID | Generated by the app | A short code (for example 4F2A-9C81) shown in Settings so you can quote it to support. |
| Sign-in metadata | Firebase | Which sign-in method you use, when the account was created and when it last signed in. |
| Profile photo link | Google passes a link to your Google profile photo to Firebase Authentication. Physique does not display or use it. |
From Google we request only the basic sign-in permissions (openid, email, profile). We do not access your Gmail, Google Drive, contacts, calendar or any other Google data.
2.2 Measurements, notes and settings
This is the information you choose to enter:
- Measurement entries. Up to 19 body metrics per entry: weight, body fat %, muscle mass, body water %, and circumferences of the neck, shoulders, chest, biceps, forearms, waist (three positions), hips, thighs and calves. Each entry has the date and time it is "for" and when it was created and last changed.
- Notes. An optional free-text note on each entry, up to 500 characters.
- Settings. Your display units (kg or lb, cm or in), which measurements are shown and in what order, and which direction counts as progress for each measurement.
We treat measurement entries and notes as health-related, sensitive information (see section 3). Notes are free text; please do not put information in them that you do not want stored.
2.3 Account deletion requests
When you delete your account in the app, we store a deletion request containing your Firebase user ID, Physique account ID, email address, name, sign-in method, the reason you typed (required, 5 to 500 characters), the time of the request and the app version. We use it to carry out the deletion and to understand why people leave.
2.4 AI assistant connections (agent access)
If you connect an AI assistant or the CLI (see section 5), we store:
- Connection records: your Firebase user ID, the name and identifier of the assistant app (for example "Claude" or "Physique CLI"), its website domain or a "recognized app" label, the domain it returns to after sign-in, the permissions you granted, and when the connection was created, last used and (if applicable) revoked.
- Tokens: access tokens, refresh tokens and authorisation codes. We store these only as one-way SHA-256 hashes, never in readable form.
- Pending sign-in requests: short-lived records of an authorisation in progress (assistant name, requested permissions, return address).
- Client registrations: when an assistant app registers itself with our server, we store its name, return addresses and technical settings, and a one-way hash of the IP address it registered from (used to enforce a registration limit). For assistants that publish a metadata document, we keep a cached copy of that public document.
2.5 App analytics and crash reports
The released app uses Google Analytics for Firebase and Firebase Crashlytics.
- Analytics records which screens you open and which actions you take (for example "entry created", "units changed", "sign-in failed"), with simple parameters such as counts, the chosen unit, or an error code. It also records device and app information (device model, iOS version, app version, language) and a random app-instance identifier. Google derives an approximate location (such as country or city) from your IP address; we do not receive your IP address or precise location from Analytics.
- Analytics is not linked to your identity. We do not send your user ID, account ID, name or email to Google Analytics, so analytics data is not connected to your Physique account.
- Analytics never includes your name, email, measurement values, entry IDs, notes or the reason you give for deleting your account.
- Crash reports (Crashlytics) contain the technical state of the app when it crashed: stack trace, device model, iOS version, app version, free memory and disk space, and a Crashlytics installation identifier. We do not attach your user ID, name or email to crash reports.
Turning analytics off. Analytics is on by default. You can turn it off at any time in the app: Settings → Privacy → Share usage analytics. When it is off, the app stops collecting and sending analytics data. This switch covers analytics only; crash reports are still sent so that we can fix problems that make the app crash. Development (debug) builds send neither analytics nor crash reports.
2.6 Server logs and security data
When the app, a website, an AI assistant or the CLI contacts our servers, Google Cloud automatically records standard request logs: IP address, time, requested path, response status, response time and user-agent string. Our own server code logs only technical events. For example, for every AI-assistant tool call we log the tool name, the outcome, the duration and the assistant's domain (or "dcr" for self-registered apps), and never your user ID, entry IDs, measurement values, notes or tokens.
To prevent abuse we apply rate limits per connection and per IP address. Rate-limit counters are keyed by a one-way hash of the IP address, not the address itself.
2.7 Websites
The consent and connections pages on connect.getphysique.app use Firebase Authentication to sign you in with Apple or Google and keep you signed in (see section 14). Our websites do not use analytics, advertising cookies or third-party trackers. The consent and connections pages load Google's Firebase sign-in code from www.gstatic.com, and the Apple or Google sign-in window is operated by Apple or Google.
2.8 Support emails
If you email us, we receive your email address, your message and anything you attach, and we use them to answer you.
2.9 What we do not collect
- No Apple Health (HealthKit). Physique does not read from or write to Apple Health. Everything you log is entered by you (or by an assistant you authorise).
- No location permission. We do not ask for or collect your precise location. (If analytics is on, Google Analytics derives an approximate location from your IP address, as described in section 2.5.)
- No photos, camera, microphone, contacts or calendar.
- No advertising. No ads, no advertising networks, no data brokers.
- No cross-app tracking. We do not track you across other companies' apps or websites and we do not ask for App Tracking Transparency permission, so iOS does not give the app your advertising identifier (IDFA).
- No payment information. There are no purchases in Physique today. If paid features are added, Apple handles payment and we will not receive your card details.
3. Health-related information and your consent
Body measurements such as weight, body fat and waist size can reveal information about your health. Under the EU and UK GDPR this may be "data concerning health" (a special category of personal data), under California law it is "sensitive personal information", and under the Washington, Nevada and Connecticut laws it is "consumer health data". We treat all measurement entries and notes as health data, whichever law applies.
- Consent. We process your health data on the basis of your explicit consent. You give it on the sign-in screen, which says: "By continuing, you agree to the Terms of Use, acknowledge the Privacy Policy, and consent to Physique processing the body measurements you add (health data) to provide the app. You can withdraw consent at any time by deleting your account." Choosing to continue with Apple or Google after reading this statement is your affirmative act of consent. We ask for this consent before any measurement can be stored.
- Purpose limitation. We use health data only to store it, show it to you, sync it between your devices and the services you sign in to, and provide it to an AI assistant or the CLI when you authorise one.
- Never for advertising or profiling. We do not use health data for advertising, marketing, profiling, automated decisions, or to infer anything about you beyond the numbers you entered.
- Withdrawing consent. You can withdraw consent at any time by deleting your account (Settings → Delete account), which deletes all your health data. You can also simply stop adding measurements, and delete any entry you no longer want us to hold. Withdrawal does not affect processing that happened before it. Because storing measurements is the purpose of the app, we cannot provide the service without this consent.
4. How we use information and our legal bases
The table below lists each purpose and, for people in the EEA, the UK and Switzerland, the legal basis we rely on.
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and secure your account; let you sign in on several devices | Account and sign-in information | Performance of our contract with you (the Terms of Use) |
| Store, sync, display and export your measurements, notes and settings | Measurements, notes, settings | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) and performance of contract |
| Connect AI assistants and the CLI at your request; enforce the permissions you granted | Connection records, hashed tokens, measurements | Your explicit consent (given on the consent screen) and performance of contract |
| Process account deletion requests | Deletion request | Performance of contract; legal obligation (honouring your erasure rights) |
| Understand how the app is used and improve it | Analytics data (not linked to your identity) | Legitimate interests (improving a product we offer, using data that is not linked to your account and contains no measurement values). You can object at any time with the in-app switch (Settings → Privacy → Share usage analytics). |
| Find and fix crashes and errors | Crash reports, server logs | Legitimate interests (keeping the service working) |
| Protect the service against abuse, fraud and attacks; enforce rate limits | Server logs, hashed IP addresses, connection records | Legitimate interests (security) |
| Answer your questions and requests | Support emails | Legitimate interests (helping you); performance of contract |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any relevant data | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights; you can ask us for details and you can object (see section 10).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
You are not legally required to give us any personal information. Sign-in information is needed to create an account, and your consent is needed to store measurements; without them you cannot use Physique. Analytics is optional.
5. AI assistants and agent access
Physique lets you connect AI assistants (such as Claude, ChatGPT, Cursor or VS Code, or any app that supports the Model Context Protocol) and the physique CLI to your account.
5.1 How a connection is made
- You add the Physique server address (
https://connect.getphysique.app/mcp) to your assistant, or runphysique login. - Your browser opens our consent page. It shows which app is asking, where you will be sent back, and the permissions requested.
- You sign in with the same Apple or Google account you use in the app and choose Allow (or Deny).
- Only then does the assistant receive a token that lets it call Physique's tools on your behalf.
An assistant cannot connect to an account that has never signed in to the iOS app, and connections stop working as soon as you request account deletion.
5.2 What an assistant can see and do
| Permission | What the assistant can do |
|---|---|
measurements:read ("See and export your measurements, notes, units and settings") | Read your entries (values, dates, notes, entry IDs), trends for a metric, your units and measurement settings, the number of entries, and export all entries as CSV or JSON. |
measurements:write ("Add, edit and delete measurement entries, and change your units and measurement settings") | Create, change and permanently delete entries and notes, and change your units, which measurements are shown, their order and their progress direction. |
An assistant cannot: see your email address or name through Physique; change how you sign in; delete your account; see or manage your other connections; read tokens; or give itself more permissions. The CLI's --read-only login asks for read permission only.
5.3 Where your data goes
- When an assistant calls a Physique tool, we return the result to that assistant. From then on, the assistant's provider (for example Anthropic for Claude, OpenAI for ChatGPT, or the maker of your code editor) processes it under its own privacy policy and terms, which may include sending it to an AI model, storing it in your chat history, or using it as their terms allow. Please read your assistant provider's privacy policy and settings.
- We do not send your data to any AI model provider ourselves. Data leaves Physique for an assistant only as a response to a tool call made with a token you authorised.
- The assistant decides which tools to call based on your instructions and its own behaviour. Treat what an assistant says about your data with care; it may misread or misstate it.
- The CLI runs on your computer. It stores its refresh token in a file in your user configuration folder (
~/.config/physique/credentials.jsonor the Windows equivalent), readable only by your user account. Anyone with access to that file can access your measurements until you log out or revoke the connection.
5.4 Revoking access
You can revoke any connection at any time at https://connect.getphysique.app/connections (also linked from the app: Settings → Connect AI assistants → Manage connections). physique logout revokes the CLI's connection. Revocation stops the assistant from making new requests immediately (access tokens are rejected and cannot be renewed). It does not delete data the assistant provider already received; ask them to delete it under their own policy.
5.5 Logs
For each tool call we log the tool name, the outcome, how long it took and the assistant's domain. These logs contain no user ID, measurement values, notes, entry IDs or tokens.
6. Who we share information with
We do not sell your personal information and we do not share it for cross-context behavioural advertising (as those terms are defined in California law). We do not disclose it to data brokers or advertisers.
6.1 Service providers (processors)
These companies process personal information on our behalf, under contracts that limit their use of it to providing their service to us:
| Provider | Service | Data involved | Location |
|---|---|---|---|
| Google LLC / Google Ireland Ltd (Firebase and Google Cloud) | Cloud Firestore database | Measurements, notes, settings, profile, deletion requests, connection records | EU multi-region eur3 (Belgium and the Netherlands) |
| Cloud Functions (agent access server) | Data in transit for tool calls and sign-in | europe-west1 (Belgium) | |
| Firebase Authentication | Account and sign-in information | Google global infrastructure, including the United States | |
| Firebase Hosting | Website and consent pages; request logs | Global content delivery network | |
| Google Analytics for Firebase | Analytics data | United States | |
| Firebase Crashlytics | Crash reports | United States | |
| Cloud Logging | Server request logs and tool-call logs | Google Cloud (global) | |
| Cloudflare, Inc. | Domain registrar and DNS for getphysique.app (DNS only; Cloudflare does not proxy or see the content of your traffic to Physique) | DNS lookups | Global |
We receive and answer support requests by email.
6.2 Apple and Google as sign-in providers
When you use Sign in with Apple or Google Sign-In, Apple or Google authenticates you and tells us the result. Their own privacy policies apply to that sign-in. Apple also distributes the app through the App Store and may provide us with aggregated, anonymous download and usage statistics if you have agreed to share them with app developers in iOS settings.
6.3 AI assistants you connect
When you authorise an assistant, we disclose your data to it at your direction (see section 5). The assistant's provider is not our processor; it is an independent recipient chosen by you.
6.4 Legal reasons and business transfers
We may disclose information if we believe in good faith that the law requires it (for example a valid court order), to protect the rights, safety or property of users, us or others, or to investigate fraud or security issues. Where the law allows, we will tell you about a request for your data.
If Physique is sold, transferred or merged, your information may be transferred to the new owner. They must keep honouring this policy or ask for your consent, and we will notify you before your information becomes subject to a different policy.
7. Where your information is stored and international transfers
We are based in New Zealand. Your measurements, notes, settings and connection records are stored in Google Cloud Firestore in the European Union (multi-region eur3, Belgium and the Netherlands), and our agent-access server runs in Belgium (europe-west1). Sign-in, analytics and crash reporting are operated by Google, including in the United States. Our websites are served from Google's global network.
- From the EEA, UK and Switzerland to New Zealand: the European Commission, the UK and Switzerland recognise New Zealand as providing an adequate level of protection.
- To the United States: Google LLC participates in the EU-U.S. Data Privacy Framework (and its UK Extension and the Swiss-U.S. framework) and also uses the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) in its data processing terms.
- From New Zealand and Australia: we take reasonable steps to make sure overseas recipients protect your information in a way comparable to the New Zealand Privacy Act 2020 (Information Privacy Principle 12) and the Australian Privacy Principles (APP 8), mainly through Google's data processing terms.
You can ask us for more information about these safeguards.
8. How long we keep information
| Information | How long |
|---|---|
| Profile, measurements, notes and settings | Until you delete them or your account. Individual entries you delete are removed from the live database immediately. |
| Database recovery copies | Our database keeps a rolling 7-day recovery window (point-in-time recovery). Deleted data disappears from it within 7 days. We do not keep longer backups. |
| Copy on your device | The app keeps an offline copy of your data in its private storage on your device so it works without a connection. It is deleted when you sign out (including the automatic sign-out after an account deletion request) or delete the app. |
| Your account after you ask to delete it | We complete the deletion within 30 days of your request. Until then, signing back in with the same account cancels the request. |
| Account deletion request record | Kept for 90 days after the deletion is completed, as a record that it happened, then deleted. |
| Sign-in accounts with no Physique data (for example someone who signs in on our consent page but never uses the app) | Deleted automatically after 30 days without activity. |
| Pending authorisation requests and authorisation codes | Valid 10 minutes; deleted within about a day after they expire. |
| Access tokens | Valid 1 hour; deleted within about a day after they expire. |
| AI assistant connections and refresh tokens | While the connection is active. A connection expires after 90 days without use and in any case one year after it was made. Expired connections are deleted; revoked connections are deleted 30 days after revocation. |
| Rate-limit counters (hashed IP or connection) | Deleted about 2 days after the counting window ends. |
| Cached metadata documents of assistant apps | Up to 30 days after the last successful refresh. |
| Self-registered assistant app records (including a hash of the registering IP address) | Deleted 90 days after their last use, once no active connection uses them. |
| Server request logs and tool-call logs | 30 days (Google Cloud Logging default retention). |
| Analytics data | Event-level data is kept no longer than 14 months. Aggregated reports that do not identify anyone may be kept longer. |
| Crash reports | 90 days (Crashlytics retention). |
| Support emails | 2 years after the last message in the conversation. |
| CLI credentials on your computer | Until you run physique logout or delete the file. |
We may keep information longer where the law requires it or to establish, exercise or defend legal claims, and only for that purpose.
9. How we protect information
- All connections to the app, websites and servers are encrypted in transit (HTTPS/TLS). Google encrypts stored data at rest.
- Database access rules let a signed-in user read and write only their own data. Agent-access records cannot be read by the app or websites at all.
- Tokens, authorisation codes and client secrets are stored only as one-way hashes. Sign-in uses OAuth 2.1 with PKCE, connections are limited to the permissions you approve, and a reused old refresh token revokes the whole connection.
- Approving a connection requires a fresh sign-in (no older than 5 minutes).
- Rate limits protect against abuse. The database has delete protection and a 7-day recovery window.
- Only the developer has administrative access to production systems.
No system is perfectly secure. If a data breach affects your personal information, we will notify you and the relevant authorities as the law requires.
10. Your rights and how to use them
10.1 Tools available to everyone
Wherever you live, you can:
- See and correct your measurements, notes and settings in the app at any time, and edit or delete any entry.
- Export all your entries as CSV or JSON with the CLI (
physique export) or by asking a connected AI assistant to run the export tool. You can also ask us by email for a copy of all your data. - Delete your account in the app: Settings → Delete account. This deletes your profile, measurements, notes, settings, AI assistant connections and your sign-in account.
- Revoke AI assistant access at https://connect.getphysique.app/connections.
- Turn off analytics in Settings → Privacy → Share usage analytics.
- Contact us at support@sergeytyo.com to exercise any right below. We offer these rights to all users, even where a law does not require it.
10.2 How we handle requests
- We may need to confirm that the request comes from the account holder. Usually we ask you to email us from the address linked to your account, or to quote the account ID shown in Settings. We will not ask for more information than we need.
- You can use an authorised agent (for example under California law). We will ask for proof of the agent's authority and may ask you to confirm your identity directly.
- We respond within 30 days, or sooner where a law requires it (for example 20 working days under the New Zealand Privacy Act, 15 days to confirm processing under the Brazilian LGPD). Where a law allows an extension (for example a further two months under the GDPR, or a further 45 days under California law), we will tell you why.
- Requests are free. We may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, where the law allows.
- We will never discriminate against you for exercising your rights.
10.3 European Economic Area, United Kingdom and Switzerland
Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection (revFADP) you have the right to:
- access your personal data and receive a copy;
- rectification of inaccurate data;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability: receive the data you gave us in a structured, machine-readable format (CSV or JSON) or have it sent to another controller;
- object to processing based on legitimate interests, including analytics;
- withdraw consent at any time, without affecting earlier processing;
- lodge a complaint with a data protection authority, in particular in the country where you live or work. In the UK this is the Information Commissioner's Office (ico.org.uk); in Switzerland the Federal Data Protection and Information Commissioner (FDPIC).
10.4 United States
California (CCPA as amended by the CPRA). This part is our notice at collection and privacy notice for California residents.
| Category (CCPA) | Examples | Collected? | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers | Name, email, Firebase user ID, account ID, app-instance identifier (not linked to your account), IP address | Yes | Google (Firebase, Google Cloud), Cloudflare (DNS), assistants you authorise |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email | Yes | |
| Sensitive personal information | Health-related measurements and notes; account sign-in (account plus access credentials) | Yes | Google; assistants you authorise |
| Internet or other electronic network activity | App usage events, server logs | Yes | |
| Geolocation data | Approximate region inferred from IP address (not precise geolocation) | Yes (approximate only) | |
| Commercial information | None today (no purchases) | No | — |
| Biometric, audio/visual, professional, education information | — | No | — |
| Inferences / profiles | — | No | — |
Sources, purposes and retention are described in sections 2, 4 and 8. We have not sold or shared personal information (including sensitive personal information) in the last 12 months, and we do not knowingly sell or share the information of consumers under 16. We use sensitive personal information only for the purposes allowed by Cal. Code Regs. tit. 11, § 7027(m) (providing the service you asked for, security and integrity), so the "right to limit" does not apply; if you ask, we will confirm this in writing.
You have the right to know what we collect, use and disclose, to access it, to delete it, to correct it, to opt out of sale or sharing (which we do not do), to limit the use of sensitive personal information, and not to be discriminated against for using these rights. Use section 10.1 and 10.2 to exercise them.
Other US states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws have similar rights: to confirm whether we process their data, to access, correct and delete it, to obtain a portable copy, and to opt out of targeted advertising, sale and profiling with significant effects (we do none of these). We process sensitive data only with your consent. If we decline your request, you can appeal by replying to our decision with the subject line "Privacy appeal"; we will respond within the time your state's law requires (generally 45 to 60 days), and if you are not satisfied you may contact your state attorney general.
Consumer health data. See the Consumer Health Data Privacy Policy below.
10.5 New Zealand
Under the Privacy Act 2020 you can ask to access and correct your personal information. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).
10.6 Australia
We handle personal information in line with the Australian Privacy Principles. You can ask to access or correct your information. If you have a complaint, contact us first; we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
10.7 Canada
Under PIPEDA and provincial laws you can access and correct your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information.
10.8 Brazil
Under the LGPD you have the right to confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about the entities we share data with, information about the consequences of refusing consent, and withdrawal of consent. You can complain to the Autoridade Nacional de Proteção de Dados (ANPD). The legal bases in section 4 correspond to LGPD bases (consent, including specific and highlighted consent for sensitive health data; contract; legitimate interest; legal obligation).
10.9 Japan, South Korea and other countries
If you are in Japan (Act on the Protection of Personal Information) or South Korea (Personal Information Protection Act), you can request disclosure, correction, suspension of use and deletion of your information, and you consent to the international transfers described in section 7 by using the service; you may withdraw that consent by deleting your account. Wherever you live, if your local law gives you privacy rights, contact us and we will honour them.
11. Consumer Health Data Privacy Policy
This section is our Consumer Health Data Privacy Policy under the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 (NRS 603A.400 and following) and the consumer health data provisions of the Connecticut Data Privacy Act. It applies to consumers in those states and, as a matter of our own practice, to everyone. It is available directly at https://getphysique.app/privacy#consumer-health-data and is linked from the app and the website.
Consumer health data we collect. Body measurements you enter (weight, body fat %, muscle mass, body water %, and body circumferences), the dates and times of those entries, and notes you attach to them. Analytics events record that a feature was used (for example "entry created") but never the values, and we do not use them to infer anything about your health.
Sources. You, when you enter data in the app; and AI assistants or the CLI acting on your instructions with permissions you granted.
Consent. You consent to the collection of consumer health data on the sign-in screen (see section 3), and to each sharing with an AI assistant on our consent screen. You can withdraw consent by deleting your account, or by revoking an assistant's connection.
Purposes. To store, display, sync and export your data, to provide it to assistants you authorise, to keep the service secure. Analytics never contains measurement values or notes. We collect and use consumer health data only as necessary to provide the service you asked for, or with your consent.
Who we share it with.
- Processors: Google (Firebase and Google Cloud), as described in section 6.1, solely to provide the service to us.
- Third parties you choose: the AI assistant providers you connect, only after you approve the connection on our consent screen. That approval is your consent to the sharing, and you can withdraw it at any time by revoking the connection.
- Affiliates: we have none.
- We do not sell consumer health data, and we do not share it for advertising.
Your rights. You can confirm whether we collect, share or sell your consumer health data; access it, including a list of all third parties and affiliates with whom we shared or sold it and an active email address or other contact for each; withdraw your consent; and have it deleted (including from our processors and from any third parties we shared it with, where we are able to notify them). Exercise these rights in the app (section 10.1) or by emailing support@sergeytyo.com. We aim to respond within 30 days and always within 45 days (extendable once by 45 days where reasonably necessary, with notice). If we deny your request, you can appeal by replying with "Health data appeal" in the subject line; we will respond to your appeal within 45 days. If your appeal is denied, you can contact the Washington State Attorney General (atg.wa.gov), the Nevada Attorney General (ag.nv.gov) or the Connecticut Attorney General (portal.ct.gov/ag), as applicable.
Geofencing. We do not use geofencing around health care facilities or any other location.
12. Children
Physique is not directed at children. You must be at least 16 years old to use it (see the Terms of Use). We do not knowingly collect personal information from children under 13 (under 16 in the EEA, the UK and other places where a higher age applies). If you believe a child has given us personal information, contact us and we will delete it.
13. Apple and Google specific disclosures
- In-app account deletion. As required by App Store Review Guideline 5.1.1(v), you can start account deletion inside the app (Settings → Delete account). You do not need to contact us or visit a website.
- Sign in with Apple and Hide My Email. If you use Hide My Email, we only receive a relay address. We do not try to discover your real address. Emails we send to the relay address are forwarded by Apple, and you can turn forwarding off in your Apple Account settings. If you stop using Sign in with Apple for Physique in your Apple settings, you will need to sign in again.
- Google API Services User Data Policy. Physique's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice we receive only your basic profile (name, email, profile identifier) through Google Sign-In; we use it only to create and secure your account and to show you which account you are signed in with; we do not use it for advertising, do not sell it, do not transfer it to others except as needed to provide the service, comply with law or as part of a merger or acquisition, and do not allow humans to read it except with your consent, for security, to comply with law, or for internal operations on aggregated and anonymised data.
- App Store privacy details. The "App Privacy" section of our App Store listing summarises the data described in this policy.
14. Cookies, browser storage and tracking signals
- App. The app does not use cookies. It stores your sign-in session and an offline copy of your data in its private storage on your device.
- Websites. The consent page (
/connect) keeps your sign-in in session storage, which is cleared when you close the tab. The connections page (/connections) keeps you signed in using the browser's local storage until you sign out. These are strictly necessary for the pages to work, so we do not ask for consent to them. Apple and Google may set their own cookies in their sign-in windows. We use no analytics or advertising cookies. If that ever changes, we will update this policy and ask for consent where required. - Do Not Track and Global Privacy Control. We do not track you across sites, so there is nothing for a Do Not Track signal to switch off. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing; since we do neither, no further change is needed.
15. Changes to this policy
We may update this policy when the service or the law changes. The "Last updated" date at the top shows the latest version. If a change is material (for example a new use of your health data or a new type of recipient), we will tell you in the app or by email before it takes effect and, where the law requires, ask for your consent again. Previous versions are available on request.
16. Contact
Questions, requests or complaints: support@sergeytyo.com
Sergey Tyo, New Zealand