phaze

Privacy at Phaze

Last updated and effective: September 2, 2026

Phaze is operated by Zeit Capital Ltda.

  • Ask only for what's necessary

    We collect what we need to run the app. We do not sell your data and we do not share it with advertisers or data brokers.

  • Your health data stays on your device

    Your logs live in the app's own storage on your phone. Phaze runs no server that holds them. On Android you can turn on an encrypted backup to your own Google Drive.

  • No medical data in advertising

    We never use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.

1. Who we are

Phaze is operated by Zeit Capital Ltda, a limited liability company organized under the laws of Brazil ("Phaze," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Phaze mobile application, the Apple Watch companion, our website at phaze.fit, and related services (together, the "Service").

Contact

  • Email (Privacy and Data Subject Rights): privacy@phaze.fit
  • Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
  • LGPD Encarregado de Dados (DPO for Brazil): Vinicius, privacy@phaze.fit
  • EU Representative (Art 27 GDPR): a representative will be appointed if and when our EU user base reaches the threshold that requires one. Until then, contact us directly at privacy@phaze.fit and we will respond within statutory timeframes.
  • UK Representative (UK GDPR Art 27): same status as the EU Representative above.

If you are in the European Economic Area, the United Kingdom, Brazil, or another jurisdiction with data-protection laws, additional rights and disclosures appear in Section 13.

2. Quick summary

This summary is informational only. The full text below governs.

  • We do not sell your personal information.
  • We do not share your personal information with advertisers or data brokers.
  • Health data is stored on your device. Phaze keeps no copy on its own servers. On Android you can enable Cloud Backup, which writes an encrypted archive to your own Google Drive. See Section 5.
  • We do not use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.
  • AI features (Ember chat, food scan, Daily Insights) send your data to Google Gemini through an edge service we operate. They stay off until you grant a separate permission, and you can withdraw it at any time. We do not train AI models on your data.
  • You must be 18 or older to use Phaze.

3. Information we collect

3.1 Information you provide

  • Account information: Phaze has no login. There is no username and no password. You give a name and a date of birth during onboarding, and both stay on your device. You give an email address only if you choose to, when you send feedback or turn on profile sharing in Settings, Privacy.
  • Health and body data: weight, height, body composition entries, progress photos, goals, dietary preferences.
  • Medication data: GLP-1 (or other) medication name, dose, schedule, side effects, injection-site notes. Provided voluntarily.
  • Nutrition data: food logs, barcode scans, meal photos, voice-described meals, dietary preferences.
  • Activity data: exercise logs, hydration entries, fasting windows, sleep summaries.
  • Subscription information: purchase confirmations from Apple App Store or Google Play. We do not receive your full payment card number.
  • Communications: support emails, in-app feedback.

3.2 Information collected automatically

  • Device information: device model, operating system version, app version, language, time zone, country (derived from store region), and a device-generated pseudonymous identifier used to link your usage events.
  • Diagnostics and product analytics: crash reports, performance traces, error logs, and product-analytics events. We do not send your email address, your name, or any medication name, dose, side effect, or injection site to our analytics or crash providers. Analytics events carry which screens you opened and which actions you took, plus your mood and energy ratings from a daily check-in and the name of a lab biomarker you added, never its value. Our analytics provider also records the screen of roughly 10% of sessions, with every text label, image, and input field masked before upload. All of this links to a device-generated identifier, so it is pseudonymous rather than anonymous. One switch in Settings, Privacy turns it all off. See Section 6.2.
  • Approximate location: city-level only, derived from IP. We do not collect precise GPS location.

3.3 Information from third parties

  • Apple HealthKit (iOS): if you connect HealthKit, we read the data types you authorize. See Section 7.
  • Google Health Connect (Android): if you connect Health Connect, we read the categories you authorize. Phaze currently requests: Steps (read), Weight (read and write), Active calories burned (read), Exercise session (read).
  • Google Drive (Android only): if you turn on Cloud Backup on Android, you authorize Phaze for the Drive AppData scope so it can write the backup file to your own Drive. We receive no other Drive content. Phaze has no Sign in with Apple and no Google sign-in for a Phaze account, because Phaze has no accounts.

We do not buy data from data brokers and do not enrich your profile from external sources.

3.4 What we do NOT extract

  • No biometric identifiers. Phaze does not extract or store face geometry, facial landmarks, fingerprints, iris scans, voiceprints, speaker embeddings, gait analysis, or any other biometric identifier as defined by the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI statute, or similar laws. Food scans and progress photos are not processed for facial recognition. Voice transcription uses the platform speech APIs and does not create or retain a voiceprint on the Phaze side.
  • No precise location. We do not collect GPS coordinates or use geofencing. We do not geofence around health care facilities.
  • No third-party advertising IDs we use ourselves. The IDFA or advertising ID on your device is governed by the platform's privacy controls.

4. How we use your information

We process your information for the following purposes and on the following lawful bases (the lawful basis matters most under GDPR, UK GDPR, and LGPD; United States users may disregard the "Lawful basis" column).

PurposeWhat we doLawful basis (GDPR / LGPD)
Provide the ServiceRender your dashboards, store your logs, sync to your watch, calculate trendsPerformance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD
Process health dataStore and display weights, photos, medications, food, activityExplicit consent (Art 9(2)(a) GDPR) / Art 11(I) LGPD specific consent
AI features (Ember chat, food scan, recommendations)Send your input to AI providers named in Section 6 to generate responsesExplicit consent for special-category processing (Art 9(2)(a) / Art 11)
Cloud Backup (optional)Store an encrypted archive in your personal cloud storage if you enable itConsent (Art 6(1)(a)) / Art 7(I) LGPD
Subscription billingProcess purchases through Apple App Store and Google PlayPerformance of contract
Diagnostics and abuse preventionCrash reports, performance monitoring, securityLegitimate interest (Art 6(1)(f)) / Art 7(IX) LGPD; you may object
Communicate updatesService notices, policy changesLegitimate interest / Art 7(IX)
Comply with lawRespond to legal process; protect rightsLegal obligation (Art 6(1)(c)) / Art 7(II)

We do not use your information to: sell to third parties for monetary or other valuable consideration; serve targeted advertising; profile you to predict future behavior outside the Service; share with insurers, employers, or data brokers.

You may withdraw consent at any time by deleting the relevant data in-app, disabling the feature, or contacting privacy@phaze.fit. Withdrawal does not affect prior lawful processing.

5. Local storage and Cloud Backup

5.1 Default: on device

Your health, medication, and progress photo data is stored on your device:

  • iOS: SwiftData persistent store with iOS Data Protection (NSFileProtectionCompleteUntilFirstUserAuthentication class). Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, your medical profile, and your dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly).
  • Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (cipher mode AES/GCM/NoPadding, 256-bit key, 12-byte IV, 128-bit tag) using a key generated and stored in the Android Keystore (hardware-backed where the device supports it). General preferences use Android Jetpack Security's EncryptedSharedPreferences (AES256_SIV for keys, AES256_GCM for values) with a Keystore-bound master key.

Phaze operates no server that stores your health records. A small amount of other information does reach a service we run, and Section 5.4 lists all of it. The flows that leave your device are in Section 6: AI features, analytics, optional Cloud Backup, and optional Health platform sync.

5.2 Backups

How a backup works depends on your platform, and the two are not the same.

  • iOS: Phaze no longer uploads a backup of its own. Your data is carried by Apple's iPhone Backup, which you control in iOS Settings and which restores at device setup. Settings, Data and Privacy, Device Backup explains this and offers nothing else, because there is nothing else for the app to control. A device that used an older build may still hold one archive in the Phaze iCloud container (iCloud.com.zeit.phaze). That screen lets you restore it once or delete it, and Delete All Data removes it too.
  • Android: Cloud Backup is opt-in and off by default. When you enable it, an encrypted archive is written to the AppData folder of your own Google Drive. That folder is private to Phaze, application-scoped, and not visible in your normal Drive view. You pick the frequency: off, daily, or weekly.

In both cases the archive payload is encrypted with AES-256-GCM before it is written.

About the encryption key. So that a backup can be restored on a new device without a separate passphrase, the encryption key is generated locally and stored alongside the encrypted payload inside the backup file. This means the backup is protected by the security of your iCloud or Google account, not by a passphrase you hold. We do not support a user-supplied passphrase, and we do not describe this backup as readable only by you, because that would imply a key we cannot reach. If you require true zero-knowledge encryption, do not enable Cloud Backup.

Phaze keeps no copy of any backup. The archive exists only in your own iCloud or Google Drive.

On Android, once Cloud Backup is enabled, it runs on the schedule you pick. You can change the frequency or switch it off at any time in Settings, Cloud Backup.

To remove a backup file: Delete All Data in the app removes the Phaze backup file as part of the same action, on both platforms. You can also switch Cloud Backup off in Settings and delete the file yourself through Apple's or Google's data-management tools.

5.3 What this means in plain language

  • Default: on device.
  • On iOS the app uploads nothing of its own. On Android, Cloud Backup is off unless you turn it on, and then an encrypted file lives in your own Google Drive.
  • AI features and analytics described in Section 6 do transmit specific fields off your device.
  • Uninstalling the app removes on-device data. An Android Cloud Backup file persists in your Google Drive until it is deleted.

5.4 What Phaze keeps on its own servers

We run one service of our own, on Cloudflare. It proxies the AI requests described in Section 6.1, and it holds a small set of records in a Cloudflare D1 database. This is all of it. No medication, dose, schedule, side effect, injection site, weight, height, or BMI is ever written to any of these records.

  • Profile sharing (opt-in, off by default): if you switch profile sharing on in Settings, Privacy, one row is stored for your device: a device-generated identifier, birth year and age band, biological sex, activity level, transformation goal, stage, app platform, version and language, and your consent flags. An email address is stored in a separate table, and only if you gave one. Cloudflare adds the country, region, and city it resolved from the request itself. The app holds no location permission and asks for none. Switching the toggle off deletes the row, and so does Delete All Data.
  • Feedback and the feature roadmap: when you send in-app feedback or vote on the public roadmap, we store your rating, your message if you wrote one, an email address if you gave one, your device identifier, and the app platform, version, and language. A filter rejects a feedback message that mentions a medication, a dose, or a side effect before it is stored. To have a feedback message or a roadmap entry removed, email privacy@phaze.fit.
  • Community rankings (opt-in): if you join rankings, your device identifier, your Lifestyle Score, and your streak length are stored so a position can be calculated. Leaving rankings deletes the entry.
  • Request logs and caches: our service logs the IP address, the route, and the size of each request, for reliability and rate limiting. It does not log the text of an Ember message, an insight, a photo, or any health value. A food-scan result is cached for 24 hours against a hash of the image; the image itself is not stored. Daily Insights are never cached or logged.

6. AI features, analytics, and other third-party processors

6.1 AI features

  • Ember (AI chat): when you send Ember a message, the message and a context record are sent through an edge service we operate on Cloudflare to Google Gemini. The context record is your own history, and it is broad. Depending on what you have logged, it can include your name, height, biological sex, activity level and goals; the last 30 days of daily logs, with nutrition, activity, mood, energy, hunger, food noise, sleep, and the side effects you recorded with their severity; 90 days of weight entries with exact values; your exercise entries; your body measurements and body composition; your lab results with their values; your milestones; the dates and notes on your progress photos; and your medication name, current dose, dose schedule, dose dates, cycle phase, and estimated medication level. Individual dose amounts, injection sites, and dose notes are held back. Progress photo images are not sent through Ember, only their dates and notes.
  • Food scan: when you scan a meal, the photo is sent through the same edge service to Google Gemini for nutrient estimation. Our service caches the returned estimate for 24 hours against a hash of the image, so the same photo is not analyzed twice. The photo itself is not stored, and no biometric identifier is extracted from it.
  • Voice meal description: spoken meals are transcribed by Apple Speech Recognition (iOS) or Android SpeechRecognizer. Both are system APIs whose routing Apple and Google control, and Phaze does not force on-device recognition, so on many devices and languages the audio does reach their speech services. The resulting transcript is then sent to Gemini for parsing into food entries.
  • Body composition estimate from photo: if you use this feature, the photo is sent through the edge service to Gemini and a numeric estimate comes back. A confirmation sheet tells you the photo is leaving your phone before it does. No biometric identifier is derived or stored.
  • Daily Insights (paid plans): if you have a paid plan and have granted the AI permission, Phaze sends 90 days of your own log through the edge service to Gemini and gets back a short written summary of the patterns in it. That payload carries your dose dates, side effects with severity, meals with their names and macros, daily totals, sleep, mood, energy, weights, your medication name, and your current dose. It does not carry per-dose amounts, injection sites, dose notes, progress photos, lab values, or body composition. It is never cached or logged on our servers. Every number in the result is re-checked against your own data on your device, and the insight is dropped if a number does not match.
  • Lab and DEXA document import: if you choose automatic extraction, the lab report or DEXA scan image you pick is sent through the edge service to Gemini. A confirmation sheet tells you the document is leaving your phone before it does. You review every extracted value before it is saved.
  • Data import: text you paste, or a file you pick from another app, is sent through the edge service to Gemini so Phaze can identify records for your review. That text can contain medication names and dose amounts.
  • Recommendations, milestones, streaks, and dose-cycle estimation: run on-device. No external service is called.

Important about AI features:

  • AI responses can be inaccurate, incomplete, or out of date. Ember does not provide medical advice, dose recommendations, contraindication guidance, or symptom triage. Our edge service screens every message first, and answers a dosing, drug-interaction, or symptom-triage question with a referral to your provider instead of calling Gemini at all. For dosing decisions, side-effect concerns, or any clinical question, contact your prescribing healthcare provider.
  • We do not train any model on your data. We use Google's paid Gemini API, and Google's terms for that tier state that prompts and responses sent to it are not used to train Google's models.
  • AI features stay off until you agree. The first time a feature needs to send data to Gemini, Phaze shows what will be sent and asks for permission, and records which version of that disclosure you agreed to and when. Settings, Privacy has an AI features switch and a Withdraw AI permission button. Withdrawing stops every AI feature at once and clears the insights already generated.
  • AI-generated outputs are labeled as such in the interface per the EU AI Act Article 50. Ember responses carry a per-output "AI-generated" label, and AI food-scan estimates are marked with an AI badge.

6.2 Analytics, crash reporting, and attribution

We use the following third-party tools. Each one receives the categories described.

ToolPurposeWhat is sentWhere
MixpanelProduct analyticsPseudonymized event payloads linked to a device-generated identifier. No email address and no name. Events carry which screen you opened and which action you took, plus your mood and energy ratings from a daily check-in and the name of a lab biomarker you added. Weight values, water amounts, meal macros, food names, medication names and dose amounts are not sent. User properties include your medication administration type ("injectable", "oral", or "none"), days since start, subscription state, and app version. The combination is pseudonymous, not anonymous, because all events for one device link to the same identifier.United States
Mixpanel Session ReplayScreen recording of sampled sessionsA replay of the app's screen for about 10% of sessions, chosen at random, uploaded and linked to the same device identifier as your events. Every text label, image, web view, map, and input field is masked on your device before a frame is uploaded, so a medication name, a dose, a side effect, or an injection site is redacted before it leaves the phone. Turning analytics off in Settings, Privacy stops the recording.United States
SentryCrash and error monitoringCrash reports, error stacks, navigation and UI-click breadcrumbs, and a snapshot of the on-screen view hierarchy at the moment of a crash. Medication identifiers, doses, side-effect entries, injection-site notes, and your medical profile are matched and removed from breadcrumbs and event payloads before transmission, and a breadcrumb that matches is dropped whole. Your name and email are stripped. The user identifier is a device-scoped ID. Administration type is attached as a context field. The same analytics switch in Settings, Privacy turns crash reporting off.United States
RevenueCatSubscription stateSubscription identifiers, purchase confirmations, RevenueCat customer ID (mapped to your Mixpanel distinct ID). No health values.United States
Meta (Facebook) Aggregated Event Measurement SDKInstall and conversion attributionApp install, app launch, and conversion events, for example a subscription. Each event carries an identifier the SDK creates and stores on your device, plus basic device information such as model and OS version. No medication, dose, weight, or food values. The advertising ID (IDFA on iOS, GAID on Android) is not collected; that is switched off in our configuration. On iOS, Phaze shows Apple's App Tracking Transparency prompt for this attribution. Declining it moves the SDK to its aggregate measurement path, and events are still sent.United States
TikTok Business SDK (Android only)Install and conversion attributionApp install, app launch, two-day retention, and purchase events, all tracked automatically by the SDK. No medication, dose, weight, or food values. This SDK is not present in the iOS app.United States
Cloud Backup targetUser-controlled storageEncrypted archive (see Section 5). Android only.Your own Google Drive AppData folder
App distributionApple App Store, Google PlayStandard store telemetryUnited States, Ireland (EU)
Phaze edge serviceCloudflare Workers and D1Proxies the AI requests in Section 6.1 and holds the records in Section 5.4. Logs the IP address, route, and size of each request. Does not log message text or health values.United States, Cloudflare global edge
Food dataUSDA FoodData Central, Open Food FactsNutrient lookups. USDA searches go through our edge service, so USDA sees our server and not you. Open Food Facts barcode lookups go straight from your device, so it sees your IP address. We send a food name or a barcode, never your weight or your medication.United States, Europe
Recipes (Android)SpoonacularRecipe queriesUnited States
Health platformsApple HealthKit, Google Health Connect (only if you authorize)Read and write of the categories you authorizeOn your device

We do not engage providers other than those listed above for the processing of your personal information. We require each provider to (i) act only on our instructions, (ii) implement appropriate security, (iii) not use your data for their own purposes other than aggregate statistics necessary for the service, and (iv) honor your deletion requests passed through us.

6.3 What about advertising trackers?

In the Phaze mobile app we use the Meta Aggregated Event Measurement SDK on both platforms, and the TikTok Business SDK on Android, for install attribution. They tell us which campaign brought a new user to Phaze. They are not used to serve advertising inside Phaze, and no health value is sent to either. On iOS, Phaze shows Apple's App Tracking Transparency prompt for Meta attribution. We do not embed Meta Pixel, TikTok web pixel, Snap Pixel, Google Ads conversion tags, Pinterest tag, or LinkedIn Insight tag on phaze.fit. We do not sell your personal information.

7. Apple HealthKit and Google Health Connect

Phaze integrates with Apple HealthKit (iOS, watchOS) and Google Health Connect (Android) only if you authorize it. You choose which categories to share. You can revoke this access at any time from your device system settings.

In accordance with Apple's HealthKit terms (Apple Developer Program License Agreement section 5.1.4) and Google's Health Connect terms:

  • We do not use HealthKit or Health Connect data for advertising or other use-based data mining purposes other than improving health, medical, and fitness management, or for the purpose of medical research.
  • We do not sell HealthKit or Health Connect data to advertising platforms, data brokers, or information resellers.
  • We do not share HealthKit or Health Connect data with third parties for advertising or marketing purposes.
  • We do not use HealthKit or Health Connect data to identify users beyond what is necessary for personalization within Phaze.
  • We will not access an end user's HealthKit or Health Connect data without their authorization.

HealthKit and Health Connect data is stored on your device. If you enable Cloud Backup, summaries you have created within Phaze (not raw HealthKit or Health Connect records) may be included in the encrypted backup archive.

8. Sharing

We share personal information only in these limited cases:

  • With your direction: when you choose to export a PDF report, share a milestone card, send a screenshot, or grant a feature access to your data.
  • With processors: the third-party providers listed in Section 6, bound by data-processing terms.
  • For legal reasons: to comply with valid legal process (subpoena, court order), respond to government requests where required by law, or protect the safety and rights of Phaze, our users, or the public. We narrow disclosures to what is legally required.
  • Business transfer: if Phaze is acquired, merged, or assets transferred, your information may be transferred to the successor entity subject to this Policy. You will be notified of any material change in handling.

We do not "sell" your personal information as that term is defined under the California Consumer Privacy Act, Washington My Health My Data Act, Connecticut Data Privacy Act, Texas Data Privacy and Security Act, or any other applicable law. We do share app install, app launch, and subscription events with Meta on both platforms, and with TikTok on Android, so we can tell which ad brought someone to Phaze. Each event carries an identifier the attribution SDK creates and stores on your device, plus basic device information such as model and OS version. No medication, dose, weight, food, or other health value is included. Meta and TikTok can use these events to measure and target advertising on their own platforms, which some state laws count as "sharing" for "cross-context behavioral advertising." We do not show ads inside Phaze.

9. Retention

CategoryRetention
Records on our own servers (Section 5.4)Profile and contact rows until you switch profile sharing off or use Delete All Data. Rankings until you leave. Feedback and roadmap entries until you ask us to remove them.
Health, medication, body, nutrition, activity dataOn your device until you delete it. In an Android Cloud Backup until the backup is deleted. Not stored on our servers.
Subscription records7 years (tax and accounting obligations)
Diagnostic and crash logs90 days, sanitized
Support correspondence24 months from last message
Aggregated, irreversibly anonymized statisticsRetained indefinitely (no longer personal data)
Legal holdAs required by law
Edge request logs, rate-limit counters, and the food-scan cacheCloudflare's log retention window. Food-scan results are cached for 24 hours.

When you use Delete All Data in the app, one action removes the data on your device, deletes any Phaze backup file from your iCloud or Google Drive, cancels every scheduled reminder, opts your device out of analytics, session replay, and crash reporting, and deletes your profile and contact rows from our servers. To have a feedback message or a roadmap entry removed, email privacy@phaze.fit. Subscription and tax records are kept where the law requires.

10. Security

We implement reasonable administrative, technical, and physical safeguards:

  • AES-256-GCM at rest on device and for Cloud Backup archives
  • TLS 1.3 in transit
  • Apple Keychain and iOS Data Protection (iOS)
  • Android Keystore plus EncryptedSharedPreferences (Android)
  • Role-based access control on internal tools
  • Code review and automated tests before a release that changes how data is handled
  • Vendor diligence on processors

No method of transmission or storage is perfectly secure. We do not claim to be HIPAA-compliant, and Phaze is not a HIPAA-covered entity.

Breach notification. If we discover a security incident that compromises the confidentiality of your personal information, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318), GDPR Article 33 and 34, LGPD Article 48, and applicable state breach-notification laws. Where required, we will notify affected individuals within 60 days of discovery (HBNR) and applicable regulators within 72 hours (GDPR).

11. Children

Phaze is intended for users 18 years of age or older. Onboarding asks for a date of birth and will not let you continue if it puts you under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, contact privacy@phaze.fit and we will delete it.

If we discover that we have collected personal information from a person under 18, we will delete that information promptly.

12. Your choices and rights

You have the following choices regardless of where you live:

  • Access and export: view your data in-app. Settings, Privacy, Export Data gives a JSON file of your logs; that file leaves medical fields out for security, so use Settings, My Report for a PDF that includes your medication, your recent doses, and your side effects.
  • Correct: edit any entry in-app.
  • Delete: delete individual entries, or use Settings, Privacy, Delete Everything, Delete All Data. That one action removes the data on your device, deletes any Phaze backup file from your iCloud or Google Drive, cancels scheduled reminders, opts your device out of analytics and crash reporting, and deletes your profile and contact rows from our servers.
  • Disable AI features: Settings, Privacy has an AI features switch and a Withdraw AI permission button. Withdrawing stops every AI feature at once and clears the insights already generated.
  • Disconnect HealthKit or Health Connect: revoke from device system settings.
  • Disable Cloud Backup (Android): toggle off in Settings, Cloud Backup. On iOS there is nothing to switch off, because the app uploads no backup of its own.
  • Opt out of analytics: Settings, Privacy has one switch that turns off product analytics, session replay, and crash reporting together. That switch does not cover the install-attribution SDKs. For those, use your platform's controls: App Tracking Transparency on iOS, and the advertising ID controls in Android settings. Declining App Tracking Transparency moves Meta to its aggregate measurement path. It does not stop install and launch events from being sent.
  • Push notifications: disable in device system settings.

To exercise any right not available in-app, email privacy@phaze.fit. We will verify your identity (typically by matching to the email of record) and respond within the timeframe required by your local law (generally 30 days under GDPR, 15 days under LGPD, 45 days under CCPA). If we cannot complete the request in that time, we will tell you why and what timeframe applies. You may appoint an authorized agent under CCPA and CPRA.

13. Jurisdiction-specific notices

13.1 European Economic Area and United Kingdom (GDPR / UK GDPR)

Controller and representatives: Zeit Capital Ltda. EU Representative: not currently appointed; see Section 1 for status and contact route. UK Representative: not currently appointed; see Section 1.

Lawful basis: see Section 4 table. We rely on explicit consent for special category health data (Art 9(2)(a) GDPR).

Your rights: access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), portability (Art 20), object (Art 21), withdraw consent (Art 7(3)), and not be subject to solely automated decisions with legal or similarly significant effects (Art 22). Automated decision-making: AI-generated suggestions in Ember and food scan are decision-support, not solely automated decisions with legal effects. You can disable them and continue using Phaze.

International transfers: We are based in Brazil. Your data may be transferred to the United States or other jurisdictions where our processors operate. We rely on EU Standard Contractual Clauses with our processors and, where a processor is certified, on the EU-U.S. Data Privacy Framework. Contact privacy@phaze.fit for details of the safeguards in place for a specific transfer.

Complaints: you may lodge a complaint with the supervisory authority of your habitual residence. For UK users: the Information Commissioner's Office (ico.org.uk). Cookies and similar technologies on phaze.fit are covered in Section 14.

13.2 Brazil (LGPD)

Controller: Zeit Capital Ltda, registered in Brazil. Encarregado de Dados: Vinicius, privacy@phaze.fit.

Legal bases: Article 7 (general) and Article 11 (sensitive data: health, biometric where applicable). We rely on specific consent (Art 11(I)) for health data.

Your rights (Art 18): confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; deletion of data processed with consent; information about public and private entities with whom we share; information about the possibility of not providing consent; revocation of consent.

International transfers: we use standard contractual clauses approved by ANPD (Resolucao CD/ANPD no 19/2024) for cross-border transfers where applicable.

ANPD: you may submit a complaint to the Autoridade Nacional de Protecao de Dados (gov.br/anpd).

13.3 California (CCPA / CPRA)

We collect the following CCPA categories of personal information:

CategoryExamples
Identifiersname, email, device ID
Customer recordsaccount profile
Internet/network activityapp usage, crash logs
Geolocation (approximate)city-level from IP
Audiovoice meal descriptions (transient)
Sensoryprogress photos
Sensitive Personal Information (SPI)health information, progress photos

Sale and share: we do not sell personal information (including SPI) for money or other valuable consideration. We do disclose app install, app launch, and subscription events to Meta, and on Android to TikTok, for advertising attribution. Each event carries an identifier the attribution SDK creates and stores on your device, plus basic device information. No SPI and no health value is included. Because Meta and TikTok can use these events for their own ad measurement and targeting, we treat this as a "share" for cross-context behavioral advertising rather than claim it falls outside the definition. Sources are: directly from you, from your device, from Apple HealthKit or Google Health Connect if you authorize. Business purposes are as listed in Section 4. Disclosure to other third parties is limited to the processors listed in Section 6, in their service-provider capacity.

Your CCPA rights: know, access, delete, correct, opt-out of sale or share (we do not sell; to opt out of the attribution sharing described above, decline App Tracking Transparency on iOS or use the advertising ID controls in Android settings), limit use of Sensitive Personal Information, no retaliation, authorized agent. Submit requests via privacy@phaze.fit or Settings, Privacy, Your Privacy Choices. Premium subscription tiers ("Phaze Pro") are payment for additional features, not a "financial incentive" tied to data collection. Shine the Light: you may request information about disclosures of personal information to third parties for direct marketing. We make none.

Universal opt-out signals (GPC): we honor Global Privacy Control signals on phaze.fit.

13.4 Washington (My Health My Data Act)

See the Consumer Health Data Privacy Policy for the disclosures required by the Washington My Health My Data Act, including categories of consumer health data, purposes, third parties, your right to withdraw consent, delete, and appeal.

13.5 Other US states (CO, CT, VA, UT, TX, OR, MT, IA, DE, NJ, MD, MN, NH, RI, TN, NV)

Residents of these states have rights including access, correction, deletion, portability, and opt-out of targeted advertising or sale (we do not engage in either). Health information is treated as sensitive data and we obtain opt-in consent before processing. Universal opt-out signals are honored where required. Submit requests to privacy@phaze.fit.

13.6 Japan (APPI)

Health data is treated as special care-required personal information and processed only with your opt-in consent. International transfer recipients and their data-protection frameworks are disclosed in Section 6.

13.7 China (PIPL)

Phaze does not actively offer the Service in mainland China. The Simplified Chinese localization is provided for users in other regions. Users in mainland China should not use the Service.

14. Cookies and similar technologies (phaze.fit)

The phaze.fit website uses:

  • Strictly necessary cookies: a country cookie set from your IP-derived country header, used for locale and pricing routing; a sidebar_state cookie that remembers whether the documentation sidebar is open; a cookie_consent cookie that records your answer to the notice below; and a gpc cookie set when your browser sends a Global Privacy Control signal.
  • First-party performance and analytics: Vercel Analytics and Vercel Speed Insights, which use first-party storage and do not load third-party tracking pixels.

We do not embed Meta Pixel, TikTok Pixel, Snap Pixel, Google Ads conversion tag, Pinterest tag, or LinkedIn Insight tag on phaze.fit. We do not engage in cross-context behavioral advertising.

phaze.fit sets no optional cookies, so the banner is a notice with a single acknowledgement rather than an accept-or-reject choice. A Global Privacy Control signal is treated as a rejection without prompting you. Your Privacy Choices in the footer reopens the notice, and you can clear cookies from your browser settings at any time.

The Phaze mobile application uses the Meta Aggregated Event Measurement and TikTok Business SDKs for install attribution. On iOS, TikTok requests App Tracking Transparency authorization. We do not use these SDKs to serve personalized advertising within Phaze, and we do not embed advertising tags on phaze.fit.

15. Changes to this Policy

We will post material changes here and notify you in-app or by email at least 30 days before they take effect, except where a shorter timeframe is required by law. We will not apply material new uses to data we already hold without obtaining your consent where required.

16. Contact

Questions, requests, complaints:

  • Email: privacy@phaze.fit
  • Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
  • Brazilian Encarregado: Vinicius (privacy@phaze.fit)
  • EU Representative: not currently appointed (see Section 1)
  • UK Representative: not currently appointed (see Section 1)

We aim to respond to all requests within 30 days, or sooner where required by law.

Phaze is not a medical device. The Service does not provide medical advice, diagnosis, or treatment. Always consult your healthcare provider regarding medications, dosing, or symptoms.

Back to Home