Physique

Privacy Policy

Physique: Body Measurements

Last updated: 4 October 2026
Effective: 4 October 2026
Version: 1.0

Consumer Health Data Privacy Policy (Washington, Nevada, Connecticut and other states with consumer health data laws)

This policy explains how Physique handles your personal information. It covers the Physique iOS app, the Physique websites (getphysique.app and connect.getphysique.app), the Physique connection service for AI assistants (the "agent access" service, including the MCP server at https://connect.getphysique.app/mcp), and the physique command-line tool (the "CLI"). Together these are "Physique" or "the service".

If you live in Washington, Nevada or Connecticut, or anywhere else with a consumer health data law, also read our Consumer Health Data Privacy Policy, which is part of this policy.


Summary


1. Who we are

Physique is developed and operated by Sergey Tyo, an individual developer based in New Zealand ("we", "us", "our"). We are the controller of the personal information described in this policy (the "agency" under the New Zealand Privacy Act 2020).

We have not appointed a data protection officer; questions go directly to the developer at the address above.

The App Store name of the app is Physique: Body Measurements. You may also see the internal code name "MeasureMe" or the bundle identifier com.stapps.MeasureMe; they refer to the same app.

2. What information we collect

2.1 Account and sign-in information

You sign in with Sign in with Apple or Google Sign-In. Our sign-in provider, Google Firebase Authentication, receives from Apple or Google:

DataSourceNotes
NameApple or GoogleApple shares your name only the first time you sign in, and only if you choose to share it.
Email addressApple or GoogleWith Apple you can choose Hide My Email; we then receive a private relay address (…@privaterelay.appleid.com) instead of your real address.
Provider account identifierApple or GoogleA stable identifier for your Apple or Google account, used to recognise you when you sign in again.
Firebase user IDGenerated by FirebaseA random identifier for your Physique account.
Physique account IDGenerated by the appA short code (for example 4F2A-9C81) shown in Settings so you can quote it to support.
Sign-in metadataFirebaseWhich sign-in method you use, when the account was created and when it last signed in.
Profile photo linkGoogleGoogle passes a link to your Google profile photo to Firebase Authentication. Physique does not display or use it.

From Google we request only the basic sign-in permissions (openid, email, profile). We do not access your Gmail, Google Drive, contacts, calendar or any other Google data.

2.2 Measurements, notes and settings

This is the information you choose to enter:

We treat measurement entries and notes as health-related, sensitive information (see section 3). Notes are free text; please do not put information in them that you do not want stored.

2.3 Account deletion requests

When you delete your account in the app, we store a deletion request containing your Firebase user ID, Physique account ID, email address, name, sign-in method, the reason you typed (required, 5 to 500 characters), the time of the request and the app version. We use it to carry out the deletion and to understand why people leave.

2.4 AI assistant connections (agent access)

If you connect an AI assistant or the CLI (see section 5), we store:

2.5 App analytics and crash reports

The released app uses Google Analytics for Firebase and Firebase Crashlytics.

Turning analytics off. Analytics is on by default. You can turn it off at any time in the app: Settings → Privacy → Share usage analytics. When it is off, the app stops collecting and sending analytics data. This switch covers analytics only; crash reports are still sent so that we can fix problems that make the app crash. Development (debug) builds send neither analytics nor crash reports.

2.6 Server logs and security data

When the app, a website, an AI assistant or the CLI contacts our servers, Google Cloud automatically records standard request logs: IP address, time, requested path, response status, response time and user-agent string. Our own server code logs only technical events. For example, for every AI-assistant tool call we log the tool name, the outcome, the duration and the assistant's domain (or "dcr" for self-registered apps), and never your user ID, entry IDs, measurement values, notes or tokens.

To prevent abuse we apply rate limits per connection and per IP address. Rate-limit counters are keyed by a one-way hash of the IP address, not the address itself.

2.7 Websites

The consent and connections pages on connect.getphysique.app use Firebase Authentication to sign you in with Apple or Google and keep you signed in (see section 14). Our websites do not use analytics, advertising cookies or third-party trackers. The consent and connections pages load Google's Firebase sign-in code from www.gstatic.com, and the Apple or Google sign-in window is operated by Apple or Google.

2.8 Support emails

If you email us, we receive your email address, your message and anything you attach, and we use them to answer you.

2.9 What we do not collect

Body measurements such as weight, body fat and waist size can reveal information about your health. Under the EU and UK GDPR this may be "data concerning health" (a special category of personal data), under California law it is "sensitive personal information", and under the Washington, Nevada and Connecticut laws it is "consumer health data". We treat all measurement entries and notes as health data, whichever law applies.

The table below lists each purpose and, for people in the EEA, the UK and Switzerland, the legal basis we rely on.

PurposeData usedLegal basis (GDPR / UK GDPR)
Create and secure your account; let you sign in on several devicesAccount and sign-in informationPerformance of our contract with you (the Terms of Use)
Store, sync, display and export your measurements, notes and settingsMeasurements, notes, settingsYour explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) and performance of contract
Connect AI assistants and the CLI at your request; enforce the permissions you grantedConnection records, hashed tokens, measurementsYour explicit consent (given on the consent screen) and performance of contract
Process account deletion requestsDeletion requestPerformance of contract; legal obligation (honouring your erasure rights)
Understand how the app is used and improve itAnalytics data (not linked to your identity)Legitimate interests (improving a product we offer, using data that is not linked to your account and contains no measurement values). You can object at any time with the in-app switch (Settings → Privacy → Share usage analytics).
Find and fix crashes and errorsCrash reports, server logsLegitimate interests (keeping the service working)
Protect the service against abuse, fraud and attacks; enforce rate limitsServer logs, hashed IP addresses, connection recordsLegitimate interests (security)
Answer your questions and requestsSupport emailsLegitimate interests (helping you); performance of contract
Comply with law, respond to lawful requests, establish or defend legal claimsAny relevant dataLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights; you can ask us for details and you can object (see section 10).

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

You are not legally required to give us any personal information. Sign-in information is needed to create an account, and your consent is needed to store measurements; without them you cannot use Physique. Analytics is optional.

5. AI assistants and agent access

Physique lets you connect AI assistants (such as Claude, ChatGPT, Cursor or VS Code, or any app that supports the Model Context Protocol) and the physique CLI to your account.

5.1 How a connection is made

  1. You add the Physique server address (https://connect.getphysique.app/mcp) to your assistant, or run physique login.
  2. Your browser opens our consent page. It shows which app is asking, where you will be sent back, and the permissions requested.
  3. You sign in with the same Apple or Google account you use in the app and choose Allow (or Deny).
  4. Only then does the assistant receive a token that lets it call Physique's tools on your behalf.

An assistant cannot connect to an account that has never signed in to the iOS app, and connections stop working as soon as you request account deletion.

5.2 What an assistant can see and do

PermissionWhat the assistant can do
measurements:read ("See and export your measurements, notes, units and settings")Read your entries (values, dates, notes, entry IDs), trends for a metric, your units and measurement settings, the number of entries, and export all entries as CSV or JSON.
measurements:write ("Add, edit and delete measurement entries, and change your units and measurement settings")Create, change and permanently delete entries and notes, and change your units, which measurements are shown, their order and their progress direction.

An assistant cannot: see your email address or name through Physique; change how you sign in; delete your account; see or manage your other connections; read tokens; or give itself more permissions. The CLI's --read-only login asks for read permission only.

5.3 Where your data goes

5.4 Revoking access

You can revoke any connection at any time at https://connect.getphysique.app/connections (also linked from the app: Settings → Connect AI assistants → Manage connections). physique logout revokes the CLI's connection. Revocation stops the assistant from making new requests immediately (access tokens are rejected and cannot be renewed). It does not delete data the assistant provider already received; ask them to delete it under their own policy.

5.5 Logs

For each tool call we log the tool name, the outcome, how long it took and the assistant's domain. These logs contain no user ID, measurement values, notes, entry IDs or tokens.

6. Who we share information with

We do not sell your personal information and we do not share it for cross-context behavioural advertising (as those terms are defined in California law). We do not disclose it to data brokers or advertisers.

6.1 Service providers (processors)

These companies process personal information on our behalf, under contracts that limit their use of it to providing their service to us:

ProviderServiceData involvedLocation
Google LLC / Google Ireland Ltd (Firebase and Google Cloud)Cloud Firestore databaseMeasurements, notes, settings, profile, deletion requests, connection recordsEU multi-region eur3 (Belgium and the Netherlands)
Cloud Functions (agent access server)Data in transit for tool calls and sign-ineurope-west1 (Belgium)
Firebase AuthenticationAccount and sign-in informationGoogle global infrastructure, including the United States
Firebase HostingWebsite and consent pages; request logsGlobal content delivery network
Google Analytics for FirebaseAnalytics dataUnited States
Firebase CrashlyticsCrash reportsUnited States
Cloud LoggingServer request logs and tool-call logsGoogle Cloud (global)
Cloudflare, Inc.Domain registrar and DNS for getphysique.app (DNS only; Cloudflare does not proxy or see the content of your traffic to Physique)DNS lookupsGlobal

We receive and answer support requests by email.

6.2 Apple and Google as sign-in providers

When you use Sign in with Apple or Google Sign-In, Apple or Google authenticates you and tells us the result. Their own privacy policies apply to that sign-in. Apple also distributes the app through the App Store and may provide us with aggregated, anonymous download and usage statistics if you have agreed to share them with app developers in iOS settings.

6.3 AI assistants you connect

When you authorise an assistant, we disclose your data to it at your direction (see section 5). The assistant's provider is not our processor; it is an independent recipient chosen by you.

We may disclose information if we believe in good faith that the law requires it (for example a valid court order), to protect the rights, safety or property of users, us or others, or to investigate fraud or security issues. Where the law allows, we will tell you about a request for your data.

If Physique is sold, transferred or merged, your information may be transferred to the new owner. They must keep honouring this policy or ask for your consent, and we will notify you before your information becomes subject to a different policy.

7. Where your information is stored and international transfers

We are based in New Zealand. Your measurements, notes, settings and connection records are stored in Google Cloud Firestore in the European Union (multi-region eur3, Belgium and the Netherlands), and our agent-access server runs in Belgium (europe-west1). Sign-in, analytics and crash reporting are operated by Google, including in the United States. Our websites are served from Google's global network.

You can ask us for more information about these safeguards.

8. How long we keep information

InformationHow long
Profile, measurements, notes and settingsUntil you delete them or your account. Individual entries you delete are removed from the live database immediately.
Database recovery copiesOur database keeps a rolling 7-day recovery window (point-in-time recovery). Deleted data disappears from it within 7 days. We do not keep longer backups.
Copy on your deviceThe app keeps an offline copy of your data in its private storage on your device so it works without a connection. It is deleted when you sign out (including the automatic sign-out after an account deletion request) or delete the app.
Your account after you ask to delete itWe complete the deletion within 30 days of your request. Until then, signing back in with the same account cancels the request.
Account deletion request recordKept for 90 days after the deletion is completed, as a record that it happened, then deleted.
Sign-in accounts with no Physique data (for example someone who signs in on our consent page but never uses the app)Deleted automatically after 30 days without activity.
Pending authorisation requests and authorisation codesValid 10 minutes; deleted within about a day after they expire.
Access tokensValid 1 hour; deleted within about a day after they expire.
AI assistant connections and refresh tokensWhile the connection is active. A connection expires after 90 days without use and in any case one year after it was made. Expired connections are deleted; revoked connections are deleted 30 days after revocation.
Rate-limit counters (hashed IP or connection)Deleted about 2 days after the counting window ends.
Cached metadata documents of assistant appsUp to 30 days after the last successful refresh.
Self-registered assistant app records (including a hash of the registering IP address)Deleted 90 days after their last use, once no active connection uses them.
Server request logs and tool-call logs30 days (Google Cloud Logging default retention).
Analytics dataEvent-level data is kept no longer than 14 months. Aggregated reports that do not identify anyone may be kept longer.
Crash reports90 days (Crashlytics retention).
Support emails2 years after the last message in the conversation.
CLI credentials on your computerUntil you run physique logout or delete the file.

We may keep information longer where the law requires it or to establish, exercise or defend legal claims, and only for that purpose.

9. How we protect information

No system is perfectly secure. If a data breach affects your personal information, we will notify you and the relevant authorities as the law requires.

10. Your rights and how to use them

10.1 Tools available to everyone

Wherever you live, you can:

10.2 How we handle requests

10.3 European Economic Area, United Kingdom and Switzerland

Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection (revFADP) you have the right to:

10.4 United States

California (CCPA as amended by the CPRA). This part is our notice at collection and privacy notice for California residents.

Category (CCPA)ExamplesCollected?Disclosed for a business purpose to
IdentifiersName, email, Firebase user ID, account ID, app-instance identifier (not linked to your account), IP addressYesGoogle (Firebase, Google Cloud), Cloudflare (DNS), assistants you authorise
Customer records (Cal. Civ. Code § 1798.80(e))Name, emailYesGoogle
Sensitive personal informationHealth-related measurements and notes; account sign-in (account plus access credentials)YesGoogle; assistants you authorise
Internet or other electronic network activityApp usage events, server logsYesGoogle
Geolocation dataApproximate region inferred from IP address (not precise geolocation)Yes (approximate only)Google
Commercial informationNone today (no purchases)No—
Biometric, audio/visual, professional, education information—No—
Inferences / profiles—No—

Sources, purposes and retention are described in sections 2, 4 and 8. We have not sold or shared personal information (including sensitive personal information) in the last 12 months, and we do not knowingly sell or share the information of consumers under 16. We use sensitive personal information only for the purposes allowed by Cal. Code Regs. tit. 11, § 7027(m) (providing the service you asked for, security and integrity), so the "right to limit" does not apply; if you ask, we will confirm this in writing.

You have the right to know what we collect, use and disclose, to access it, to delete it, to correct it, to opt out of sale or sharing (which we do not do), to limit the use of sensitive personal information, and not to be discriminated against for using these rights. Use section 10.1 and 10.2 to exercise them.

Other US states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws have similar rights: to confirm whether we process their data, to access, correct and delete it, to obtain a portable copy, and to opt out of targeted advertising, sale and profiling with significant effects (we do none of these). We process sensitive data only with your consent. If we decline your request, you can appeal by replying to our decision with the subject line "Privacy appeal"; we will respond within the time your state's law requires (generally 45 to 60 days), and if you are not satisfied you may contact your state attorney general.

Consumer health data. See the Consumer Health Data Privacy Policy below.

10.5 New Zealand

Under the Privacy Act 2020 you can ask to access and correct your personal information. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).

10.6 Australia

We handle personal information in line with the Australian Privacy Principles. You can ask to access or correct your information. If you have a complaint, contact us first; we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

10.7 Canada

Under PIPEDA and provincial laws you can access and correct your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information.

10.8 Brazil

Under the LGPD you have the right to confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary data, portability, information about the entities we share data with, information about the consequences of refusing consent, and withdrawal of consent. You can complain to the Autoridade Nacional de Proteção de Dados (ANPD). The legal bases in section 4 correspond to LGPD bases (consent, including specific and highlighted consent for sensitive health data; contract; legitimate interest; legal obligation).

10.9 Japan, South Korea and other countries

If you are in Japan (Act on the Protection of Personal Information) or South Korea (Personal Information Protection Act), you can request disclosure, correction, suspension of use and deletion of your information, and you consent to the international transfers described in section 7 by using the service; you may withdraw that consent by deleting your account. Wherever you live, if your local law gives you privacy rights, contact us and we will honour them.

11. Consumer Health Data Privacy Policy

This section is our Consumer Health Data Privacy Policy under the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 (NRS 603A.400 and following) and the consumer health data provisions of the Connecticut Data Privacy Act. It applies to consumers in those states and, as a matter of our own practice, to everyone. It is available directly at https://getphysique.app/privacy#consumer-health-data and is linked from the app and the website.

Consumer health data we collect. Body measurements you enter (weight, body fat %, muscle mass, body water %, and body circumferences), the dates and times of those entries, and notes you attach to them. Analytics events record that a feature was used (for example "entry created") but never the values, and we do not use them to infer anything about your health.

Sources. You, when you enter data in the app; and AI assistants or the CLI acting on your instructions with permissions you granted.

Consent. You consent to the collection of consumer health data on the sign-in screen (see section 3), and to each sharing with an AI assistant on our consent screen. You can withdraw consent by deleting your account, or by revoking an assistant's connection.

Purposes. To store, display, sync and export your data, to provide it to assistants you authorise, to keep the service secure. Analytics never contains measurement values or notes. We collect and use consumer health data only as necessary to provide the service you asked for, or with your consent.

Who we share it with.

Your rights. You can confirm whether we collect, share or sell your consumer health data; access it, including a list of all third parties and affiliates with whom we shared or sold it and an active email address or other contact for each; withdraw your consent; and have it deleted (including from our processors and from any third parties we shared it with, where we are able to notify them). Exercise these rights in the app (section 10.1) or by emailing support@sergeytyo.com. We aim to respond within 30 days and always within 45 days (extendable once by 45 days where reasonably necessary, with notice). If we deny your request, you can appeal by replying with "Health data appeal" in the subject line; we will respond to your appeal within 45 days. If your appeal is denied, you can contact the Washington State Attorney General (atg.wa.gov), the Nevada Attorney General (ag.nv.gov) or the Connecticut Attorney General (portal.ct.gov/ag), as applicable.

Geofencing. We do not use geofencing around health care facilities or any other location.

12. Children

Physique is not directed at children. You must be at least 16 years old to use it (see the Terms of Use). We do not knowingly collect personal information from children under 13 (under 16 in the EEA, the UK and other places where a higher age applies). If you believe a child has given us personal information, contact us and we will delete it.

13. Apple and Google specific disclosures

14. Cookies, browser storage and tracking signals

15. Changes to this policy

We may update this policy when the service or the law changes. The "Last updated" date at the top shows the latest version. If a change is material (for example a new use of your health data or a new type of recipient), we will tell you in the app or by email before it takes effect and, where the law requires, ask for your consent again. Previous versions are available on request.

16. Contact

Questions, requests or complaints: support@sergeytyo.com

Sergey Tyo, New Zealand