Consumer Health Data Privacy Policy
Last updated and effective: September 2, 2026. Operated by Zeit Capital Ltda.
Contents
- 1. What is "Consumer Health Data"
- 2. Categories of Consumer Health Data we collect
- 3. Purposes for collection and processing
- 4. Where your data is stored
- 5. Categories of third parties with whom we share Consumer Health Data
- 6. AI features: additional disclosures
- 7. Retention
- 8. Your rights
- 9. Security
- 10. Consent
- 11. Children
- 12. Changes to this Policy
- 13. Contact
This Consumer Health Data Privacy Policy explains how Zeit Capital Ltda ("Phaze," "we," "us," or "our") collects, uses, shares, and protects "consumer health data" of users of the Phaze mobile application, the Apple Watch companion, and the phaze.fit website (the "Service").
This Policy is provided in addition to our Privacy Policy and Terms of Service, and is intended to satisfy the requirements of the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (SB 370), the Connecticut Data Privacy Act as amended for consumer health data, the California Confidentiality of Medical Information Act (CMIA) where applicable, and similar state consumer health data laws.
If you are a resident of one of these states, you have specific rights summarized in Section 8.
Important: Phaze is not a HIPAA "covered entity" or "business associate," and the Health Insurance Portability and Accountability Act (HIPAA) does not directly regulate our processing of your data. We do not claim to be HIPAA-compliant. Instead, we describe below the specific practices we apply to your consumer health data.
1. What is "Consumer Health Data"
For the purposes of this Policy, "Consumer Health Data" means personal information that identifies your past, present, or future physical or mental health status, including data that is derived or inferred from non-health information, such as:
- Body measurements (weight, height, body composition entries)
- Progress photos showing your body
- Medication information you log (including GLP-1 medications such as Wegovy, Ozempic, Mounjaro, Zepbound, or Saxenda)
- Dose schedule and side-effect entries you record
- Food, hydration, and nutrient logs
- Exercise, activity, and sleep entries
- Fasting and meal-timing windows
- Goals and progress narratives
- Data shared with Phaze via Apple HealthKit or Google Health Connect (if you authorize)
2. Categories of Consumer Health Data we collect
| Category | Source | Examples |
|---|---|---|
| Body measurements | You; HealthKit / Health Connect | Weight, body fat %, lean mass, waist |
| Progress photos | You | Front, side, back photos you save |
| Medication entries | You | Drug name, dose, schedule, side effects, injection site |
| Nutrition | You; food databases | Food logs, meal photos, voice descriptions, water |
| Activity | You; HealthKit / Health Connect | Workouts, steps, active minutes |
| Sleep and fasting | You; HealthKit / Health Connect | Sleep summaries, fasting windows |
| Inferred information | Phaze processing | Trend lines, goal progress, recommendation triggers |
| Conversational health data | You (AI chat) | Messages you send to Ember, and the context record from your own history that goes with them (Section 5) |
3. Purposes for collection and processing
We process Consumer Health Data only to:
- Provide the Service to you (display dashboards, log entries, sync, charts)
- Generate insights, summaries, and personalized recommendations for your use
- Power AI features (Ember chat, food scan) that you choose to use
- Allow you to export your data (PDF reports, sharing)
- Sync data across your devices (with your authorization)
- Back up your data to your personal cloud storage if you enable Cloud Backup
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not process Consumer Health Data to: serve advertising, build advertising profiles, sell to third parties, share with data brokers, share with insurers or employers, or train AI models on your data.
4. Where your data is stored
4.1 On-device default
Consumer Health Data is stored on your device by default.
- iOS: SwiftData persistent store with iOS Data Protection. Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, medical profile, dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain.
- Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (256-bit key, 12-byte IV, 128-bit tag) using a key stored in the Android Keystore. Preferences use Jetpack Security EncryptedSharedPreferences.
We operate no server that stores your Consumer Health Data. We do run one service of our own on Cloudflare. It proxies the AI requests in Section 6 and holds a small set of records: an opt-in profile row (age band, birth year, biological sex, activity level, transformation goal, stage, consent flags, and the country, region, and city Cloudflare resolves from the request), an email address in a separate table if you gave one, in-app feedback, public roadmap votes, and an opt-in rankings entry with your Lifestyle Score and streak. No medication, dose, schedule, side effect, injection site, weight, height, or BMI is ever written to any of those records. Section 5.4 of our Privacy Policy describes them in full.
4.2 Backups
How a backup works depends on your platform:
- iOS: Phaze no longer uploads a backup of its own. Your data is carried by Apple's iPhone Backup, which you control in iOS Settings. A device that used an older build may still hold one archive in the Phaze iCloud container (iCloud.com.zeit.phaze); Settings, Data and Privacy, Device Backup lets you restore it once or delete it.
- Android: Cloud Backup is opt-in and off by default. When enabled, an encrypted archive is written to the AppData folder of your own Google Drive, which is private to Phaze, application-scoped, and not visible in your general Drive view.
The archive is encrypted with AES-256-GCM before upload.
About the encryption key. So that you can restore the backup on a new device without managing a separate passphrase, the encryption key is generated locally and stored alongside the encrypted payload in the same backup file. This means the security of the backup file is bound to the security of your iCloud or Google account, not to a separate passphrase you hold. We do not market Cloud Backup as protected only for you or as having no key access by us. If you require true zero-knowledge encryption, do not enable Cloud Backup. We may add a user-passphrase option in a future release.
We do not retain a server-side Phaze copy of the backup outside your own iCloud or Google account.
4.3 What does leave your device
- Cloud Backup on Android, if you enable it: to your own Google Drive AppData folder. On iOS the app uploads no backup of its own.
- AI features: see Section 6. Ember sends your message together with a broad context record drawn from your own history, food scan and body-composition estimate send photos, Daily Insights sends 90 days of your log, and document import sends the lab or DEXA image you pick.
- Health platforms, if you authorize them: Apple HealthKit (iOS) or Google Health Connect (Android) read and write through the system framework.
- Analytics and crash reporting: see Section 5. Product analytics carry no weight values, water amounts, meal macros, food names, medication names, or dose amounts. Session replay uploads a masked screen recording of a sampled share of sessions.
- PDF report export, milestone share, or screenshot share: if you initiate them.
4.4 HealthKit and Health Connect
Phaze reads these platforms only with your authorization. We do not store a separate server-side copy of HealthKit or Health Connect data. We do not use this data for advertising, marketing, sale, data mining, or user identification outside Phaze.
5. Categories of third parties with whom we share Consumer Health Data
We share Consumer Health Data only with the following categories of recipients, and only as needed to operate the Service:
| Recipient | Purpose | What is sent | Where |
|---|---|---|---|
| Google (Gemini, via Cloudflare Workers edge service) | Ember chat, food image recognition, body-composition estimate from photo | Your message, and a broad context record drawn from your own history: profile and goals, 30 days of daily logs with mood, energy, hunger, food noise, sleep and side effects and their severity, 90 days of weight entries with exact values, exercise entries, body measurements and composition, lab results with their values, milestones, the dates and notes on progress photos, and your medication name, current dose, dose schedule, dose dates, cycle phase, and estimated medication level. Per-dose amounts, injection sites, and dose notes are held back, and progress photo images are not sent through Ember. Food scan and body-composition estimate send the photo itself. Daily Insights sends 90 days of your log, including dose dates, side effects, and meals with their names and macros. Document import sends the lab or DEXA image you pick. | United States, Cloudflare global edge |
| Apple (iOS) / Google (Android) system speech APIs | Voice meal description transcription | Audio routed by SFSpeechRecognizer (iOS) or SpeechRecognizer (Android); may transit to Apple or Google services depending on device and language | Per platform |
| Google Drive (Android only, if Cloud Backup is enabled) | User-controlled backup of your data | Encrypted archive of your data (Section 4) | Your own Google Drive AppData folder |
| Apple HealthKit (iOS) / Google Health Connect (Android), only if authorized | Sync of authorized data categories | Reads and writes performed locally through the system framework | On your device |
| Mixpanel | Product analytics | Pseudonymized event payloads keyed to a device-generated identifier, with no email and no name. Events carry which screen you opened and which action you took, plus your mood and energy ratings from a daily check-in and the name of a lab biomarker you added. Weight values, water amounts, meal macros, food names, medication names, and dose amounts are not sent. User properties include medication administration type. This is pseudonymization, not anonymization: all events for one device link to the same identifier. | United States |
| Mixpanel Session Replay | Screen recording of sampled sessions | A screen recording of about 10% of sessions, chosen at random and linked to the same device identifier as your events. Every text label, image, web view, map, and input field is masked on your device before a frame is uploaded, so a medication name, a dose, a side effect, or an injection site is redacted before it leaves the phone. The analytics switch in Settings, Privacy stops the recording. | United States |
| Sentry | Crash and error monitoring | Crash reports, stack traces, navigation breadcrumbs, and a snapshot of the on-screen view hierarchy at the moment of a crash. Medication identifiers, doses, side-effect entries, injection-site notes, and the medical profile are matched and removed from event payloads before transmission, and a breadcrumb that matches is dropped whole. Name and email are stripped. The identifier is a device-scoped ID; administration type is attached as context. The analytics switch in Settings, Privacy turns crash reporting off as well. | United States |
| RevenueCat | Subscription management | Subscription identifiers, purchase events. No health values. | United States |
| Meta Aggregated Event Measurement SDK | App install and conversion attribution | Install and conversion events. No health values. Advertising-ID collection is switched off in our configuration. On iOS, Phaze shows Apple's App Tracking Transparency prompt for this attribution. | United States |
| TikTok Business SDK (Android only) | App install and conversion attribution | Install and conversion events. No health values. This SDK is not present in the iOS app. | United States |
| Apple App Store, Google Play | Distribution and IAP | Standard store telemetry, purchase confirmations | United States, Ireland |
| USDA FoodData Central, Open Food Facts, Spoonacular (Android) | Food and recipe lookups | The food name or barcode you looked up. USDA searches go through our edge service, so USDA sees our server and not you; Open Food Facts barcode lookups go straight from your device, so it sees your IP address. We do not send your health values to these databases. | United States, Europe |
| Cloudflare (Phaze edge service and D1) | AI proxying, and the records in Section 4.1 | The IP address, route, and size of each request. No message text and no health values are logged. Opt-in profile, contact, feedback, roadmap, and rankings records as described in Section 4.1. | United States, Cloudflare global edge |
| Legal and regulatory | Comply with valid legal process | As legally required | As applicable |
We do not "sell" Consumer Health Data, and we send no medication, dose, weight, side effect, or other health value to an advertising platform. We do tell Meta, and on Android TikTok, when Phaze is installed, opened, and subscribed to, so we can tell which ad brought someone here. Those events carry an identifier the attribution SDK creates and stores on your device. Because Phaze is a GLP-1 tracker, the fact that you installed it can itself suggest something about your health, so we do not claim this falls outside "sharing" for cross-context behavioral advertising. We do not engage in geofencing within 2,000 feet of any health care facility.
We require each recipient to (i) act only on our instructions, (ii) implement appropriate security, (iii) not use your Consumer Health Data for their own purposes other than aggregate statistics necessary for their service, and (iv) honor deletion requests passed through us. The Meta attribution SDK is configured with advertising-ID collection switched off. Neither attribution SDK receives any health value.
6. AI features: additional disclosures
Phaze includes AI-driven features:
- Ember (AI chat companion), routed through a Phaze edge service (Cloudflare Workers) to Google Gemini
- Food scan (image recognition for meal logging), routed through the edge service to Google Gemini Vision
- Body composition estimate from photo, routed through the edge service to Gemini Vision
- Voice meal description, transcribed by the platform speech API, then sent to Gemini for parsing
- Daily Insights (paid plans), which sends 90 days of your own log through the edge service to Gemini and returns a short written summary. It is never cached or logged on our servers, and every number in it is re-checked on your device.
- Lab and DEXA document import, which sends the document image you pick through the edge service to Gemini after a confirmation sheet, and lets you review every extracted value before it is saved. Data import sends pasted text the same way.
Important about AI features:
- AI responses can be inaccurate or out of date. Treat them as informational only.
- We do not train any model on your data. We use Google's paid Gemini API, and Google's terms for that tier state that prompts and responses sent to it are not used to train Google's models. Our edge service also screens every chat message before it is forwarded, and answers a dosing, drug-interaction, or symptom-triage question with a referral to your provider instead of calling Gemini at all. For Daily Insights, the service drops any generated insight that reads as a medical claim, and your device re-checks every number in what remains against your own data and discards the insight if a number does not match.
- Ember will not knowingly provide dosing advice, contraindication guidance, side-effect triage, or any clinical recommendation. For any medical question, contact your prescribing healthcare provider.
- AI features stay off until you agree. The first time a feature needs to send data to Gemini, Phaze shows what will be sent and asks for permission, and records which version of that disclosure you agreed to and when. Settings, Privacy has an AI features switch and a Withdraw AI permission button. Withdrawing stops every AI feature at once and clears the insights already generated.
In accordance with the EU AI Act Article 50 transparency requirements, AI-generated outputs are labeled as AI in the interface, and you are informed when you interact with an AI system. Ember responses carry a per-output "AI-generated" label, and AI food-scan estimates are marked with an AI badge.
7. Retention
| Category | Retention |
|---|---|
| Consumer Health Data on your device | Until you delete it, or you uninstall the app |
| Consumer Health Data in your Cloud Backup | Android only. Until the backup file is deleted from your Google Drive AppData folder, which Delete All Data does for you. |
| Records on the Phaze edge service | No Consumer Health Data is stored there. The opt-in profile, contact, feedback, roadmap, and rankings records in Section 4.1 are kept until you switch the relevant option off, use Delete All Data, or ask us to remove them. Request logs follow Cloudflare's retention window; the food-scan result cache expires after 24 hours. |
| AI provider transient retention | Per provider policy; we contractually require deletion within their normal log windows; we do not retain a copy ourselves |
| Aggregated, irreversibly anonymized statistics | Indefinite (no longer Consumer Health Data) |
| Legal hold | As required by law |
8. Your rights
8.1 Washington (My Health My Data Act)
You have the right to:
- Confirm whether Phaze is processing your Consumer Health Data
- Access your Consumer Health Data
- Request deletion of your Consumer Health Data: Phaze will delete the data within 30 days and direct any service provider or processor to do the same
- Withdraw consent: you may withdraw consent to processing or sharing at any time; withdrawal does not affect prior lawful processing
- Appeal a denial of any of the above
Submit requests by email to privacy@phaze.fit. You can also use Settings, Privacy, Delete Everything, Delete All Data in the app. That one action removes the data on your device, deletes any Phaze backup file from your iCloud or Google Drive, cancels scheduled reminders, opts your device out of analytics and crash reporting, and deletes the profile and contact rows described in Section 4.1. Because Phaze has no account, we verify a request by matching the details you give us to the records we hold, such as a device identifier or the email address on a profile or feedback row. We respond within the timeframes required by law, generally 45 days, extendable once.
If we deny a request, we will explain why and how to appeal within 45 days. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/file-complaint.
Geofencing. Phaze does not use geofences within 2,000 feet of any in-person health care service or facility.
8.2 Nevada (SB 370)
Nevada residents have the right to confirmation, access, deletion, opt-out of sale, and opt-out of sharing for targeted advertising. Phaze does not sell Consumer Health Data and does not engage in targeted advertising. Submit requests to privacy@phaze.fit.
8.3 Connecticut, Colorado, Virginia, Texas, Oregon, and other state laws
Residents of these states have rights including access, correction, deletion, portability, opt-out of sale, opt-out of targeted advertising, and the right to limit the use of sensitive data including consumer health data. Phaze does not sell or engage in targeted advertising and processes sensitive data only with your opt-in consent. Submit requests to privacy@phaze.fit. Universal opt-out signals (GPC) are honored where required.
8.4 California (CCPA / CPRA / CMIA)
California residents have all rights described in Section 13.3 of our Privacy Policy, including the right to limit use of sensitive personal information (which includes Consumer Health Data). We process your Consumer Health Data only as needed to provide the Service you requested.
For purposes of the California Confidentiality of Medical Information Act (CMIA, Cal. Civ. Code sections 56 et seq.), to the extent Phaze qualifies as a "provider of health care" as defined in the statute, the medical information you provide is processed under the safeguards described in this Policy and disclosed only as permitted by law or with your authorization.
8.5 Brazil (LGPD)
Brazilian residents may exercise rights under LGPD Article 18 (confirmation, access, correction, anonymization or deletion, portability, sharing information, consent revocation). Submit to privacy@phaze.fit or the Encarregado (Vinicius) at privacy@phaze.fit. ANPD: gov.br/anpd.
8.6 EU / UK / EEA
EU and UK residents may exercise rights under GDPR Articles 15 to 22, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects.
9. Security
We apply the following safeguards to Consumer Health Data:
- Encryption at rest: AES-256-GCM for sensitive medical fields on device and for Cloud Backup archives
- Encryption in transit: TLS 1.3
- Platform key storage: Apple Keychain on iOS (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly); Android Keystore on Android (hardware-backed where available)
- Crash-report scrubbing: Sentry breadcrumbs and event payloads are scrubbed to remove medication identifiers, doses, side-effect entries, injection-site notes, and medical profile before transmission
- Vendor diligence: processors are reviewed before engagement and subject to data-processing terms
- Access controls: role-based access to internal tools
- Code review and testing: code review and automated test coverage prior to releases that affect data handling
- We do not currently hold an independent security certification or audit attestation (for example, ISO 27001). We do not claim certifications we do not hold.
- Product-analytics events and session replays are linked to a device-scoped pseudonymous identifier, as disclosed in Section 5. This is pseudonymization, not anonymization, and it remains subject to the rights and obligations described in this Policy and in our Privacy Policy.
No method of transmission or storage is perfectly secure. If we discover a security incident that compromises the confidentiality of your Consumer Health Data, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318) within 60 days of discovery, the EU GDPR Article 33 and 34 (within 72 hours for the supervisory authority), the LGPD Article 48, and applicable US state breach-notification laws.
10. Consent
Phaze has no account. The first time a feature needs to process Consumer Health Data off your device, we ask for consent in the app, show what will be sent, and record which version of that disclosure you agreed to and when. You may withdraw consent at any time by:
- Switching the feature off in Settings, Privacy: the AI features switch, the Withdraw AI permission button, the analytics switch, or the profile-sharing switch
- Deleting the relevant data
- Using Settings, Privacy, Delete Everything, Delete All Data
- Emailing privacy@phaze.fit to withdraw consent for any specific processing
Withdrawal does not affect prior lawful processing.
For sale or sharing of Consumer Health Data, we obtain separate, signed valid authorization prior to any such activity. We do not currently sell or share Consumer Health Data, so no such authorization is requested.
11. Children
The Service is intended for adults aged 18 and over. We do not knowingly collect Consumer Health Data from anyone under 18. If we learn we have collected data from a person under 18, we delete it promptly.
12. Changes to this Policy
We will post material changes here with a new "Last updated" date and notify you in-app or by email at least 30 days before they take effect, unless a shorter timeframe is required by law.
13. Contact
- Email: privacy@phaze.fit
- In-app: Settings, Privacy, Consumer Health Data Requests
- Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
- Brazilian Encarregado: Vinicius (privacy@phaze.fit)
- EU / UK Representative: not currently appointed; will be appointed if and when our EU or UK user base reaches the threshold that requires one. Until then, contact privacy@phaze.fit.
If we deny your request, you may appeal at privacy@phaze.fit; if the appeal is denied, you may contact your state attorney general (in the United States), the Information Commissioner's Office (UK), your EU member-state supervisory authority, or the ANPD (Brazil).