Consumer Health Data Privacy Policy
Zuletzt aktualisiert und gültig ab: 2. September 2026. Betrieben von Zeit Capital Ltda.
Inhalt
- 1. What is "Consumer Health Data"
- 2. Categories of Consumer Health Data we collect
- 3. Purposes for collection and processing
- 4. Where your data is stored
- 5. Categories of third parties with whom we share Consumer Health Data
- 6. AI features: additional disclosures
- 7. Retention
- 8. Your rights
- 9. Security
- 10. Consent
- 11. Children
- 12. Changes to this Policy
- 13. Contact
This Consumer Health Data Privacy Policy explains how Zeit Capital Ltda ("Phaze," "we," "us," or "our") collects, uses, shares, and protects "consumer health data" of users of the Phaze mobile application, the Apple Watch companion, and the phaze.fit website (the "Service").
This Policy is provided in addition to our Privacy Policy and Terms of Service, and is intended to satisfy the requirements of the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (SB 370), the Connecticut Data Privacy Act as amended for consumer health data, the California Confidentiality of Medical Information Act (CMIA) where applicable, and similar state consumer health data laws.
If you are a resident of one of these states, you have specific rights summarized in Section 8.
Important: Phaze is not a HIPAA "covered entity" or "business associate," and the Health Insurance Portability and Accountability Act (HIPAA) does not directly regulate our processing of your data. We do not claim to be HIPAA-compliant. Instead, we describe below the specific practices we apply to your consumer health data.
1. What is "Consumer Health Data"
For the purposes of this Policy, "Consumer Health Data" means personal information that identifies your past, present, or future physical or mental health status, including data that is derived or inferred from non-health information, such as:
- Body measurements (weight, height, body composition entries)
- Progress photos showing your body
- Medication information you log (including GLP-1 medications such as Wegovy, Ozempic, Mounjaro, Zepbound, or Saxenda)
- Dose schedule and side-effect entries you record
- Food, hydration, and nutrient logs
- Exercise, activity, and sleep entries
- Fasting and meal-timing windows
- Goals and progress narratives
- Data shared with Phaze via Apple HealthKit or Google Health Connect (if you authorize)
2. Categories of Consumer Health Data we collect
| Category | Source | Examples |
|---|---|---|
| Body measurements | You; HealthKit / Health Connect | Weight, body fat %, lean mass, waist |
| Progress photos | You | Front, side, back photos you save |
| Medication entries | You | Drug name, dose, schedule, side effects, injection site |
| Nutrition | You; food databases | Food logs, meal photos, voice descriptions, water |
| Activity | You; HealthKit / Health Connect | Workouts, steps, active minutes |
| Sleep and fasting | You; HealthKit / Health Connect | Sleep summaries, fasting windows |
| Inferred information | Phaze processing | Trend lines, goal progress, recommendation triggers |
| Conversational health data | You (AI chat) | Nachrichten, die du an Ember sendest, und der Kontextdatensatz aus deiner eigenen Historie, der mitgeht (Abschnitt 5) |
3. Purposes for collection and processing
We process Consumer Health Data only to:
- Provide the Service to you (display dashboards, log entries, sync, charts)
- Generate insights, summaries, and personalized recommendations for your use
- Power AI features (Ember chat, food scan) that you choose to use
- Allow you to export your data (PDF reports, sharing)
- Sync data across your devices (with your authorization)
- Back up your data to your personal cloud storage if you enable Cloud Backup
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not process Consumer Health Data to: serve advertising, build advertising profiles, sell to third parties, share with data brokers, share with insurers or employers, or train AI models on your data.
4. Where your data is stored
4.1 On-device default
Consumer Health Data is stored on your device by default.
- iOS: SwiftData persistent store with iOS Data Protection. Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, medical profile, dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain.
- Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (256-bit key, 12-byte IV, 128-bit tag) using a key stored in the Android Keystore. Preferences use Jetpack Security EncryptedSharedPreferences.
Wir betreiben keinen Server, der deine Consumer Health Data speichert. Wir betreiben allerdings einen eigenen Dienst auf Cloudflare. Er leitet die KI-Anfragen aus Abschnitt 6 weiter und hält einen kleinen Satz Datensätze: eine optionale Profilzeile (Altersspanne, Geburtsjahr, biologisches Geschlecht, Aktivitätsniveau, Transformationsziel, Phase, Einwilligungsmarkierungen sowie Land, Region und Stadt, die Cloudflare aus der Anfrage auflöst), eine E-Mail-Adresse in einer eigenen Tabelle, falls du eine angegeben hast, In-App-Feedback, Stimmen auf der öffentlichen Roadmap und einen optionalen Ranking-Eintrag mit deinem Lifestyle-Score und deiner Streak. Weder Medikament noch Dosis, Zeitplan, Nebenwirkung, Injektionsstelle, Gewicht, Größe oder BMI wird jemals in diese Datensätze geschrieben. Abschnitt 5.4 unserer Datenschutzerklärung beschreibt sie vollständig.
4.2 Backups
Wie ein Backup funktioniert, hängt von deiner Plattform ab:
- iOS: Phaze lädt kein eigenes Backup mehr hoch. Deine Daten trägt Apples iPhone-Backup, das du in den iOS-Einstellungen steuerst. Ein Gerät aus einer älteren Version kann noch ein Archiv im Phaze-iCloud-Container (iCloud.com.zeit.phaze) halten; unter Einstellungen, Daten und Datenschutz, Gerätebackup kannst du es einmal wiederherstellen oder löschen.
- Android: Cloud-Backup ist optional und standardmäßig aus. Bei Aktivierung wird ein verschlüsseltes Archiv in den AppData-Ordner deines eigenen Google Drive geschrieben, der Phaze-privat, app-gebunden und in deiner allgemeinen Drive-Ansicht nicht sichtbar ist.
The archive is encrypted with AES-256-GCM before upload.
About the encryption key. So that you can restore the backup on a new device without managing a separate passphrase, the encryption key is generated locally and stored alongside the encrypted payload in the same backup file. This means the security of the backup file is bound to the security of your iCloud or Google account, not to a separate passphrase you hold. We do not market Cloud Backup as protected only for you or as having no key access by us. If you require true zero-knowledge encryption, do not enable Cloud Backup. We may add a user-passphrase option in a future release.
We do not retain a server-side Phaze copy of the backup outside your own iCloud or Google account.
4.3 What does leave your device
- Cloud-Backup unter Android, wenn du es aktivierst: in den AppData-Ordner deines eigenen Google Drive. Unter iOS lädt die App kein eigenes Backup hoch.
- KI-Funktionen: siehe Abschnitt 6. Ember sendet deine Nachricht zusammen mit einem umfangreichen Kontextdatensatz aus deiner eigenen Historie, Mahlzeiten-Scan und Körperzusammensetzungs-Schätzung senden Fotos, Daily Insights sendet 90 Tage deiner Aufzeichnungen, und der Dokumentimport sendet das ausgewählte Labor- oder DEXA-Bild.
- Health platforms, if you authorize them: Apple HealthKit (iOS) or Google Health Connect (Android) read and write through the system framework.
- Analyse und Absturzberichte: siehe Abschnitt 5. Die Produktanalyse enthält keine Gewichtswerte, Wassermengen, Mahlzeiten-Makros, Lebensmittelnamen, Medikamentennamen oder Dosismengen. Die Sitzungsaufzeichnung lädt eine maskierte Bildschirmaufnahme eines Stichprobenanteils der Sitzungen hoch.
- PDF report export, milestone share, or screenshot share: if you initiate them.
4.4 HealthKit and Health Connect
Phaze reads these platforms only with your authorization. We do not store a separate server-side copy of HealthKit or Health Connect data. We do not use this data for advertising, marketing, sale, data mining, or user identification outside Phaze.
5. Categories of third parties with whom we share Consumer Health Data
We share Consumer Health Data only with the following categories of recipients, and only as needed to operate the Service:
| Recipient | Purpose | What is sent | Where |
|---|---|---|---|
| Google (Gemini, via Cloudflare Workers edge service) | Ember chat, food image recognition, body-composition estimate from photo | Deine Nachricht und ein umfangreicher Kontextdatensatz aus deiner eigenen Historie: Profil und Ziele, 30 Tage Tageseinträge mit Stimmung, Energie, Hunger, Food Noise, Schlaf sowie Nebenwirkungen und Schweregrad, 90 Tage Gewichtseinträge mit exakten Werten, Trainingseinträge, Körpermaße und Körperzusammensetzung, Laborwerte samt Werten, Meilensteine, Daten und Notizen der Fortschrittsfotos sowie Medikamentenname, aktuelle Dosis, Dosisplan, Dosistermine, Zyklusphase und geschätzter Medikamentenspiegel. Einzeldosismengen, Injektionsstellen und Dosisnotizen bleiben zurück, und Bilder der Fortschrittsfotos gehen nicht über Ember. Mahlzeiten-Scan und Körperzusammensetzungs-Schätzung senden das Foto selbst. Daily Insights sendet 90 Tage deiner Aufzeichnungen, einschließlich Dosistermine, Nebenwirkungen und Mahlzeiten mit Namen und Makros. Der Dokumentimport sendet das ausgewählte Labor- oder DEXA-Bild. | United States, Cloudflare global edge |
| Apple (iOS) / Google (Android) system speech APIs | Voice meal description transcription | Audio routed by SFSpeechRecognizer (iOS) or SpeechRecognizer (Android); may transit to Apple or Google services depending on device and language | Per platform |
| Google Drive (nur Android, wenn Cloud-Backup aktiviert ist) | User-controlled backup of your data | Encrypted archive of your data (Section 4) | Der AppData-Ordner deines eigenen Google Drive |
| Apple HealthKit (iOS) / Google Health Connect (Android), only if authorized | Sync of authorized data categories | Reads and writes performed locally through the system framework | On your device |
| Mixpanel | Product analytics | Pseudonymisierte Ereignisse, gebunden an eine geräteseitig erzeugte Kennung, ohne E-Mail und ohne Namen. Die Ereignisse enthalten, welchen Screen du geöffnet und welche Aktion du ausgeführt hast, dazu deine Stimmungs- und Energiewerte aus dem täglichen Check-in und den Namen eines angelegten Laborwerts. Gewichtswerte, Wassermengen, Mahlzeiten-Makros, Lebensmittelnamen, Medikamentennamen und Dosismengen werden nicht gesendet. Nutzereigenschaften umfassen die Verabreichungsart. Das ist Pseudonymisierung, keine Anonymisierung: Alle Ereignisse eines Geräts hängen an derselben Kennung. | United States |
| Mixpanel Session Replay | Bildschirmaufzeichnung stichprobenartiger Sitzungen | Eine Bildschirmaufnahme von rund 10% der Sitzungen, zufällig gewählt und mit derselben Gerätekennung wie deine Ereignisse verknüpft. Jeder Text, jedes Bild, jede Web-Ansicht, jede Karte und jedes Eingabefeld wird auf deinem Gerät maskiert, bevor ein Einzelbild hochgeladen wird, sodass ein Medikamentenname, eine Dosis, eine Nebenwirkung oder eine Injektionsstelle geschwärzt ist, bevor sie das Telefon verlässt. Der Analyse-Schalter unter Einstellungen, Datenschutz beendet die Aufzeichnung. | Vereinigte Staaten |
| Sentry | Crash and error monitoring | Absturzberichte, Stack-Traces, Navigations-Breadcrumbs und eine Momentaufnahme der Ansichtshierarchie auf dem Bildschirm zum Zeitpunkt des Absturzes. Medikamentenkennungen, Dosen, Nebenwirkungseinträge, Notizen zur Injektionsstelle und das medizinische Profil werden vor der Übertragung erkannt und aus den Ereignissen entfernt; ein passender Breadcrumb wird ganz verworfen. Name und E-Mail werden entfernt. Die Kennung ist eine gerätebezogene ID; die Verabreichungsart wird als Kontext angehängt. Der Analyse-Schalter unter Einstellungen, Datenschutz schaltet auch die Absturzberichte ab. | United States |
| RevenueCat | Subscription management | Subscription identifiers, purchase events. No health values. | United States |
| Meta Aggregated Event Measurement SDK | App install and conversion attribution | Installations- und Conversion-Ereignisse. Keine Gesundheitswerte. Die Erfassung der Werbe-ID ist in unserer Konfiguration abgeschaltet. Unter iOS zeigt Phaze für diese Zuordnung Apples App-Tracking-Transparenz-Abfrage. | United States |
| TikTok Business SDK (nur Android) | App install and conversion attribution | Installations- und Conversion-Ereignisse. Keine Gesundheitswerte. Dieses SDK ist in der iOS-App nicht enthalten. | United States |
| Apple App Store, Google Play | Distribution and IAP | Standard store telemetry, purchase confirmations | United States, Ireland |
| USDA FoodData Central, Open Food Facts, Spoonacular (Android) | Food and recipe lookups | Der abgefragte Lebensmittelname oder Barcode. USDA-Suchen laufen über unseren Edge-Dienst, USDA sieht also unseren Server und nicht dich; Open-Food-Facts-Abfragen gehen direkt von deinem Gerät, dieser Dienst sieht also deine IP-Adresse. Wir senden deine Gesundheitswerte nicht an diese Datenbanken. | United States, Europe |
| Cloudflare (Phaze-Edge-Dienst und D1) | KI-Weiterleitung und die Datensätze aus Abschnitt 4.1 | IP-Adresse, Route und Größe jeder Anfrage. Weder Nachrichtentext noch Gesundheitswerte werden protokolliert. Optionale Profil-, Kontakt-, Feedback-, Roadmap- und Ranking-Datensätze wie in Abschnitt 4.1 beschrieben. | Vereinigte Staaten, globales Cloudflare-Edge |
| Legal and regulatory | Comply with valid legal process | As legally required | As applicable |
Wir "verkaufen" keine Verbraucher-Gesundheitsdaten und senden keinen Wert zu Medikament, Dosis, Gewicht, Nebenwirkung oder sonstiger Gesundheit an eine Werbeplattform. Wir teilen Meta und unter Android TikTok allerdings mit, wann Phaze installiert, geöffnet und abonniert wird, damit wir wissen, welche Anzeige jemanden hergebracht hat. Diese Ereignisse tragen eine Kennung, die das Attributions-SDK erzeugt und auf deinem Gerät speichert. Weil Phaze ein GLP-1-Tracker ist, kann allein die Tatsache, dass du es installiert hast, etwas über deine Gesundheit nahelegen. Deshalb behaupten wir nicht, dass dies nicht unter "Teilen" für kontextübergreifende verhaltensbasierte Werbung fällt. Wir betreiben kein Geofencing im Umkreis von 600 Metern um eine Gesundheitseinrichtung.
Wir verlangen von jedem Empfänger, dass er (i) nur nach unseren Weisungen handelt, (ii) angemessene Sicherheit umsetzt, (iii) deine Consumer Health Data nicht für eigene Zwecke jenseits der für seinen Dienst nötigen aggregierten Statistiken nutzt und (iv) über uns weitergegebene Löschanfragen erfüllt. Das Meta-Attributions-SDK ist mit abgeschalteter Werbe-ID-Erfassung konfiguriert. Keines der Attributions-SDKs erhält einen Gesundheitswert.
6. AI features: additional disclosures
Phaze includes AI-driven features:
- Ember (AI chat companion), routed through a Phaze edge service (Cloudflare Workers) to Google Gemini
- Food scan (image recognition for meal logging), routed through the edge service to Google Gemini Vision
- Body composition estimate from photo, routed through the edge service to Gemini Vision
- Voice meal description, transcribed by the platform speech API, then sent to Gemini for parsing
- Daily Insights (kostenpflichtige Tarife), sendet 90 Tage deiner eigenen Aufzeichnungen über den Edge-Dienst an Gemini und liefert eine kurze Zusammenfassung zurück. Sie wird auf unseren Servern nie zwischengespeichert oder protokolliert, und jede Zahl darin wird auf deinem Gerät nachgerechnet.
- Import von Labor- und DEXA-Dokumenten, sendet das ausgewählte Dokumentbild nach einem Bestätigungsblatt über den Edge-Dienst an Gemini und lässt dich jeden erkannten Wert vor dem Speichern prüfen. Der Datenimport sendet eingefügten Text auf demselben Weg.
Important about AI features:
- AI responses can be inaccurate or out of date. Treat them as informational only.
- Wir trainieren kein Modell mit deinen Daten. Wir nutzen Googles kostenpflichtige Gemini-API, und Googles Bedingungen für diese Stufe besagen, dass an sie gesendete Prompts und Antworten nicht zum Training von Googles Modellen verwendet werden. Unser Edge-Dienst prüft außerdem jede Chat-Nachricht vor der Weiterleitung und beantwortet eine Frage zu Dosierung, Wechselwirkung oder Symptomtriage mit einem Verweis auf deine Behandelnden, ohne Gemini überhaupt aufzurufen. Bei Daily Insights verwirft der Dienst jeden erzeugten Insight, der wie eine medizinische Aussage klingt, und dein Gerät rechnet jede verbleibende Zahl gegen deine eigenen Daten nach und verwirft den Insight, wenn eine Zahl nicht stimmt.
- Ember will not knowingly provide dosing advice, contraindication guidance, side-effect triage, or any clinical recommendation. For any medical question, contact your prescribing healthcare provider.
- KI-Funktionen bleiben aus, bis du zustimmst. Wenn eine Funktion zum ersten Mal Daten an Gemini senden will, zeigt Phaze, was gesendet wird, fragt um Erlaubnis und hält fest, welcher Fassung dieses Hinweises du wann zugestimmt hast. Unter Einstellungen, Datenschutz gibt es einen Schalter für KI-Funktionen und eine Schaltfläche KI-Erlaubnis widerrufen. Ein Widerruf stoppt alle KI-Funktionen auf einmal und löscht die bereits erzeugten Insights.
In accordance with the EU AI Act Article 50 transparency requirements, AI-generated outputs are labeled as AI in the interface, and you are informed when you interact with an AI system. Ember responses carry a per-output "AI-generated" label, and AI food-scan estimates are marked with an AI badge.
7. Retention
| Category | Retention |
|---|---|
| Consumer Health Data on your device | Until you delete it, or you uninstall the app |
| Consumer Health Data in your Cloud Backup | Nur Android. Bis die Backup-Datei aus dem AppData-Ordner deines Google Drive gelöscht ist, was Alle Daten löschen für dich erledigt. |
| Datensätze im Phaze-Edge-Dienst | Dort werden keine Consumer Health Data gespeichert. Die optionalen Profil-, Kontakt-, Feedback-, Roadmap- und Ranking-Datensätze aus Abschnitt 4.1 bleiben, bis du die jeweilige Option abschaltest, Alle Daten löschen nutzt oder ihre Entfernung verlangst. Anfrageprotokolle folgen dem Aufbewahrungsfenster von Cloudflare; der Mahlzeiten-Scan-Cache läuft nach 24 Stunden ab. |
| AI provider transient retention | Per provider policy; we contractually require deletion within their normal log windows; we do not retain a copy ourselves |
| Aggregated, irreversibly anonymized statistics | Indefinite (no longer Consumer Health Data) |
| Legal hold | As required by law |
8. Your rights
8.1 Washington (My Health My Data Act)
You have the right to:
- Confirm whether Phaze is processing your Consumer Health Data
- Access your Consumer Health Data
- Request deletion of your Consumer Health Data: Phaze will delete the data within 30 days and direct any service provider or processor to do the same
- Withdraw consent: you may withdraw consent to processing or sharing at any time; withdrawal does not affect prior lawful processing
- Appeal a denial of any of the above
Submit requests by email to privacy@phaze.fit. Du kannst auch Einstellungen, Datenschutz, Alles löschen, Alle Daten löschen in der App nutzen. Dieser eine Schritt entfernt die Daten auf deinem Gerät, löscht jede Phaze-Backup-Datei aus deinem iCloud oder Google Drive, sagt geplante Erinnerungen ab, meldet dein Gerät von Analyse und Absturzberichten ab und löscht die in Abschnitt 4.1 beschriebenen Profil- und Kontaktzeilen. Da Phaze kein Konto hat, prüfen wir eine Anfrage, indem wir die von dir genannten Angaben mit unseren Datensätzen abgleichen, etwa einer Gerätekennung oder der E-Mail-Adresse in einer Profil- oder Feedback-Zeile. Wir antworten innerhalb der gesetzlichen Fristen, in der Regel 45 Tage, einmal verlängerbar.
If we deny a request, we will explain why and how to appeal within 45 days. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/file-complaint.
Geofencing. Phaze does not use geofences within 2,000 feet of any in-person health care service or facility.
8.2 Nevada (SB 370)
Nevada residents have the right to confirmation, access, deletion, opt-out of sale, and opt-out of sharing for targeted advertising. Phaze does not sell Consumer Health Data and does not engage in targeted advertising. Submit requests to privacy@phaze.fit.
8.3 Connecticut, Colorado, Virginia, Texas, Oregon, and other state laws
Residents of these states have rights including access, correction, deletion, portability, opt-out of sale, opt-out of targeted advertising, and the right to limit the use of sensitive data including consumer health data. Phaze does not sell or engage in targeted advertising and processes sensitive data only with your opt-in consent. Submit requests to privacy@phaze.fit. Universal opt-out signals (GPC) are honored where required.
8.4 California (CCPA / CPRA / CMIA)
California residents have all rights described in Section 13.3 of our Privacy Policy, including the right to limit use of sensitive personal information (which includes Consumer Health Data). We process your Consumer Health Data only as needed to provide the Service you requested.
For purposes of the California Confidentiality of Medical Information Act (CMIA, Cal. Civ. Code sections 56 et seq.), to the extent Phaze qualifies as a "provider of health care" as defined in the statute, the medical information you provide is processed under the safeguards described in this Policy and disclosed only as permitted by law or with your authorization.
8.5 Brazil (LGPD)
Brazilian residents may exercise rights under LGPD Article 18 (confirmation, access, correction, anonymization or deletion, portability, sharing information, consent revocation). Submit to privacy@phaze.fit or the Encarregado (Vinicius) at privacy@phaze.fit. ANPD: gov.br/anpd.
8.6 EU / UK / EEA
EU and UK residents may exercise rights under GDPR Articles 15 to 22, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects.
9. Security
We apply the following safeguards to Consumer Health Data:
- Encryption at rest: AES-256-GCM for sensitive medical fields on device and for Cloud Backup archives
- Encryption in transit: TLS 1.3
- Platform key storage: Apple Keychain on iOS (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly); Android Keystore on Android (hardware-backed where available)
- Crash-report scrubbing: Sentry breadcrumbs and event payloads are scrubbed to remove medication identifiers, doses, side-effect entries, injection-site notes, and medical profile before transmission
- Vendor diligence: processors are reviewed before engagement and subject to data-processing terms
- Access controls: role-based access to internal tools
- Code review and testing: code review and automated test coverage prior to releases that affect data handling
- We do not currently hold an independent security certification or audit attestation (for example, ISO 27001). We do not claim certifications we do not hold.
- Produktanalyse-Ereignisse und Sitzungsaufzeichnungen sind an eine gerätebezogene pseudonyme Kennung gebunden, wie in Abschnitt 5 offengelegt. Das ist Pseudonymisierung, keine Anonymisierung, und unterliegt weiterhin den in dieser Richtlinie und in unserer Datenschutzerklärung beschriebenen Rechten und Pflichten.
No method of transmission or storage is perfectly secure. If we discover a security incident that compromises the confidentiality of your Consumer Health Data, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318) within 60 days of discovery, the EU GDPR Article 33 and 34 (within 72 hours for the supervisory authority), the LGPD Article 48, and applicable US state breach-notification laws.
10. Consent
Phaze hat kein Konto. Wenn eine Funktion zum ersten Mal Consumer Health Data außerhalb deines Geräts verarbeiten will, holen wir in der App die Einwilligung ein, zeigen, was gesendet wird, und halten fest, welcher Fassung dieses Hinweises du wann zugestimmt hast. Du kannst die Einwilligung jederzeit widerrufen, indem du:
- die Funktion unter Einstellungen, Datenschutz abschaltest: den Schalter für KI-Funktionen, die Schaltfläche KI-Erlaubnis widerrufen, den Analyse-Schalter oder den Schalter für Profilfreigabe
- Deleting the relevant data
- Einstellungen, Datenschutz, Alles löschen, Alle Daten löschen nutzt
- Emailing privacy@phaze.fit to withdraw consent for any specific processing
Withdrawal does not affect prior lawful processing.
For sale or sharing of Consumer Health Data, we obtain separate, signed valid authorization prior to any such activity. We do not currently sell or share Consumer Health Data, so no such authorization is requested.
11. Children
The Service is intended for adults aged 18 and over. We do not knowingly collect Consumer Health Data from anyone under 18. If we learn we have collected data from a person under 18, we delete it promptly.
12. Changes to this Policy
We will post material changes here with a new "Last updated" date and notify you in-app or by email at least 30 days before they take effect, unless a shorter timeframe is required by law.
13. Contact
- Email: privacy@phaze.fit
- In-app: Settings, Privacy, Consumer Health Data Requests
- Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
- Brazilian Encarregado: Vinicius (privacy@phaze.fit)
- EU / UK Representative: not currently appointed; will be appointed if and when our EU or UK user base reaches the threshold that requires one. Until then, contact privacy@phaze.fit.
If we deny your request, you may appeal at privacy@phaze.fit; if the appeal is denied, you may contact your state attorney general (in the United States), the Information Commissioner's Office (UK), your EU member-state supervisory authority, or the ANPD (Brazil).