phaze

Consumer Health Data Privacy Policy

最后更新及生效日期:2026 年 9 月 2 日。由 Zeit Capital Ltda 运营。

This Consumer Health Data Privacy Policy explains how Zeit Capital Ltda ("Phaze," "we," "us," or "our") collects, uses, shares, and protects "consumer health data" of users of the Phaze mobile application, the Apple Watch companion, and the phaze.fit website (the "Service").

This Policy is provided in addition to our Privacy Policy and Terms of Service, and is intended to satisfy the requirements of the Washington My Health My Data Act (RCW 19.373), the Nevada Consumer Health Data Privacy Law (SB 370), the Connecticut Data Privacy Act as amended for consumer health data, the California Confidentiality of Medical Information Act (CMIA) where applicable, and similar state consumer health data laws.

If you are a resident of one of these states, you have specific rights summarized in Section 8.

Important: Phaze is not a HIPAA "covered entity" or "business associate," and the Health Insurance Portability and Accountability Act (HIPAA) does not directly regulate our processing of your data. We do not claim to be HIPAA-compliant. Instead, we describe below the specific practices we apply to your consumer health data.

1. What is "Consumer Health Data"

For the purposes of this Policy, "Consumer Health Data" means personal information that identifies your past, present, or future physical or mental health status, including data that is derived or inferred from non-health information, such as:

  • Body measurements (weight, height, body composition entries)
  • Progress photos showing your body
  • Medication information you log (including GLP-1 medications such as Wegovy, Ozempic, Mounjaro, Zepbound, or Saxenda)
  • Dose schedule and side-effect entries you record
  • Food, hydration, and nutrient logs
  • Exercise, activity, and sleep entries
  • Fasting and meal-timing windows
  • Goals and progress narratives
  • Data shared with Phaze via Apple HealthKit or Google Health Connect (if you authorize)

2. Categories of Consumer Health Data we collect

CategorySourceExamples
Body measurementsYou; HealthKit / Health ConnectWeight, body fat %, lean mass, waist
Progress photosYouFront, side, back photos you save
Medication entriesYouDrug name, dose, schedule, side effects, injection site
NutritionYou; food databasesFood logs, meal photos, voice descriptions, water
ActivityYou; HealthKit / Health ConnectWorkouts, steps, active minutes
Sleep and fastingYou; HealthKit / Health ConnectSleep summaries, fasting windows
Inferred informationPhaze processingTrend lines, goal progress, recommendation triggers
Conversational health dataYou (AI chat)你发送给 Ember 的消息,以及随之发送的取自你自身历史的上下文记录(第 5 节)

3. Purposes for collection and processing

We process Consumer Health Data only to:

  • Provide the Service to you (display dashboards, log entries, sync, charts)
  • Generate insights, summaries, and personalized recommendations for your use
  • Power AI features (Ember chat, food scan) that you choose to use
  • Allow you to export your data (PDF reports, sharing)
  • Sync data across your devices (with your authorization)
  • Back up your data to your personal cloud storage if you enable Cloud Backup
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not process Consumer Health Data to: serve advertising, build advertising profiles, sell to third parties, share with data brokers, share with insurers or employers, or train AI models on your data.

4. Where your data is stored

4.1 On-device default

Consumer Health Data is stored on your device by default.

  • iOS: SwiftData persistent store with iOS Data Protection. Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, medical profile, dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain.
  • Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (256-bit key, 12-byte IV, 128-bit tag) using a key stored in the Android Keystore. Preferences use Jetpack Security EncryptedSharedPreferences.

我们不运行任何存储你消费者健康数据的服务器。我们确实在 Cloudflare 上运行一项自有服务。它代理第 6 节的 AI 请求,并保存少量记录:一条需主动开启的资料记录(年龄段、出生年份、生理性别、活动水平、转变目标、阶段、同意标记,以及 Cloudflare 从请求中解析出的国家、地区和城市)、若你提供则保存在单独表中的电子邮件地址、应用内反馈、公开路线图投票,以及包含生活方式评分与连续天数的自愿加入的排名条目。药物、剂量、用药安排、副作用、注射部位、体重、身高或 BMI 从不会写入这些记录。我们隐私政策第 5.4 节对此有完整说明。

4.2 备份

备份的运作方式取决于你的平台:

  • iOS: Phaze 不再上传自己的备份。你的数据由 Apple 的 iPhone 备份承载,你在 iOS 设置中控制它。使用过旧版本的设备可能仍在 Phaze 的 iCloud 容器(iCloud.com.zeit.phaze)中保留一份存档;在“设置、数据与隐私、设备备份”中可恢复一次或删除。
  • Android: 云备份需主动开启,默认关闭。开启后,一份加密存档会写入你自己 Google 云端硬盘的 AppData 文件夹,该文件夹为 Phaze 专用、限于应用范围,在你常规的云端硬盘视图中不可见。

The archive is encrypted with AES-256-GCM before upload.

About the encryption key. So that you can restore the backup on a new device without managing a separate passphrase, the encryption key is generated locally and stored alongside the encrypted payload in the same backup file. This means the security of the backup file is bound to the security of your iCloud or Google account, not to a separate passphrase you hold. We do not market Cloud Backup as protected only for you or as having no key access by us. If you require true zero-knowledge encryption, do not enable Cloud Backup. We may add a user-passphrase option in a future release.

We do not retain a server-side Phaze copy of the backup outside your own iCloud or Google account.

4.3 What does leave your device

  1. 若你在 Android 上启用云备份:写入你自己 Google 云端硬盘的 AppData 文件夹。在 iOS 上,应用不上传自己的备份。
  2. AI 功能:见第 6 节。Ember 会连同一份取自你自身历史的广泛上下文记录一起发送你的消息;食物扫描与身体成分估算会发送照片;每日洞察会发送 90 天的记录;文档导入会发送你所选的化验或 DEXA 图像。
  3. Health platforms, if you authorize them: Apple HealthKit (iOS) or Google Health Connect (Android) read and write through the system framework.
  4. 分析与崩溃上报:见第 5 节。产品分析不含体重数值、饮水量、餐食宏量营养素、食物名称、药物名称或剂量数值。会话录制会上传抽样部分会话的已遮蔽屏幕录像。
  5. PDF report export, milestone share, or screenshot share: if you initiate them.

4.4 HealthKit and Health Connect

Phaze reads these platforms only with your authorization. We do not store a separate server-side copy of HealthKit or Health Connect data. We do not use this data for advertising, marketing, sale, data mining, or user identification outside Phaze.

5. Categories of third parties with whom we share Consumer Health Data

We share Consumer Health Data only with the following categories of recipients, and only as needed to operate the Service:

RecipientPurposeWhat is sentWhere
Google (Gemini, via Cloudflare Workers edge service)Ember chat, food image recognition, body-composition estimate from photo你的消息,以及一份取自你自身历史的广泛上下文记录:个人资料与目标、含情绪、精力、饥饿感、食欲噪音、睡眠及副作用与其严重程度的 30 天每日记录、含精确数值的 90 天体重记录、运动记录、身体围度与成分、含数值的化验结果、里程碑、进度照片的日期与备注,以及你的药物名称、当前剂量、用药安排、用药日期、周期阶段和估算药物水平。单次剂量数值、注射部位和用药备注不会发送,进度照片的图像也不经 Ember 发送。食物扫描与身体成分估算会发送照片本身。每日洞察会发送 90 天的记录,包括用药日期、副作用,以及餐食名称与宏量营养素。文档导入会发送你所选的化验或 DEXA 图像。United States, Cloudflare global edge
Apple (iOS) / Google (Android) system speech APIsVoice meal description transcriptionAudio routed by SFSpeechRecognizer (iOS) or SpeechRecognizer (Android); may transit to Apple or Google services depending on device and languagePer platform
Google 云端硬盘(仅 Android,且已启用云备份时)User-controlled backup of your dataEncrypted archive of your data (Section 4)你自己 Google 云端硬盘的 AppData 文件夹
Apple HealthKit (iOS) / Google Health Connect (Android), only if authorizedSync of authorized data categoriesReads and writes performed locally through the system frameworkOn your device
MixpanelProduct analytics关联到设备生成标识符的假名化事件,不含电子邮件,也不含姓名。事件记录你打开了哪个页面、执行了哪个操作,以及每日打卡中的情绪与精力评分,和你添加的化验指标名称。体重数值、饮水量、餐食宏量营养素、食物名称、药物名称和剂量数值都不会发送。用户属性包括给药方式。这属于假名化而非匿名化:同一设备的所有事件都关联同一个标识符。United States
Mixpanel Session Replay抽样会话的屏幕录制对随机抽取的约 10% 会话进行屏幕录制,并关联到与你的事件相同的设备标识符。所有文本、图片、网页视图、地图和输入框都会在上传任一帧之前在你的设备上被遮蔽,因此药物名称、剂量、副作用或注射部位在离开手机前就已被涂除。“设置、隐私”中的分析开关可停止录制。美国
SentryCrash and error monitoring崩溃报告、堆栈追踪、导航轨迹,以及崩溃时刻屏幕上视图层级的快照。药物标识、剂量、副作用记录、注射部位备注和医疗档案会在传输前从事件负载中被匹配并移除,命中的轨迹会被整条丢弃。姓名和电子邮件会被剥除。标识是设备范围的 ID;给药方式作为上下文附加。“设置、隐私”中的分析开关同样会关闭崩溃上报。United States
RevenueCatSubscription managementSubscription identifiers, purchase events. No health values.United States
Meta Aggregated Event Measurement SDKApp install and conversion attribution安装与转化事件。不含健康数值。我们的配置中已关闭广告 ID 采集。在 iOS 上,Phaze 会为该归因展示 Apple 的“App 跟踪透明度”提示。United States
TikTok Business SDK(仅 Android)App install and conversion attribution安装与转化事件。不含健康数值。iOS 应用中不包含该 SDK。United States
Apple App Store, Google PlayDistribution and IAPStandard store telemetry, purchase confirmationsUnited States, Ireland
USDA FoodData Central, Open Food Facts, Spoonacular (Android)Food and recipe lookups你查询的食物名称或条形码。USDA 检索经由我们的边缘服务,因此 USDA 看到的是我们的服务器而不是你;Open Food Facts 的条码查询直接从你的设备发出,因此它会看到你的 IP 地址。我们不会把你的健康数值发送给这些数据库。United States, Europe
Cloudflare(Phaze 边缘服务与 D1)AI 代理,以及第 4.1 节所述记录每次请求的 IP 地址、路由和大小。不记录消息文本,也不记录健康数值。以及第 4.1 节所述的自愿加入的资料、联系人、反馈、路线图与排名记录。美国,Cloudflare 全球边缘节点
Legal and regulatoryComply with valid legal processAs legally requiredAs applicable

我们不“出售”消费者健康数据,也不会向任何广告平台发送药物、剂量、体重、副作用或其他健康数值。但我们确实会告诉 Meta,以及在 Android 上告诉 TikTok,Phaze 何时被安装、打开和订阅,以便了解是哪条广告把人带到了这里。这些事件带有一个由归因 SDK 生成并保存在你设备上的标识符。由于 Phaze 是一款 GLP-1 追踪应用,你安装了它这件事本身就可能透露与健康有关的信息,因此我们不主张这不属于面向跨情境行为广告的“共享”。我们不会在任何医疗机构 600 米范围内进行地理围栏。

我们要求每一位接收方:(i) 仅按我们的指示行事;(ii) 实施适当的安全措施;(iii) 除其服务所必需的汇总统计外,不得将你的消费者健康数据用于自身目的;(iv) 履行经我们转达的删除请求。Meta 归因 SDK 的配置已关闭广告 ID 采集。两个归因 SDK 均不会收到任何健康数值。

6. AI features: additional disclosures

Phaze includes AI-driven features:

  • Ember (AI chat companion), routed through a Phaze edge service (Cloudflare Workers) to Google Gemini
  • Food scan (image recognition for meal logging), routed through the edge service to Google Gemini Vision
  • Body composition estimate from photo, routed through the edge service to Gemini Vision
  • Voice meal description, transcribed by the platform speech API, then sent to Gemini for parsing
  • 每日洞察 (付费方案),会通过边缘服务把你自己 90 天的记录发送给 Gemini,并返回一段简短总结。它从不在我们的服务器上缓存或记录,其中每个数字都会在你的设备上重新核对。
  • 化验与 DEXA 文档导入, 会在确认页之后,把你所选的文档图像经边缘服务发送给 Gemini,并让你在保存前复核每个提取出的数值。数据导入以同样方式发送粘贴的文本。

Important about AI features:

  • AI responses can be inaccurate or out of date. Treat them as informational only.
  • 我们不会用你的数据训练任何模型。我们使用 Google 的付费 Gemini API,Google 针对该档位的条款说明,发送至该 API 的提示词与回复不会用于训练 Google 的模型。我们的边缘服务还会在转发前筛查每条聊天消息,遇到剂量、药物相互作用或症状分诊类问题时,会直接建议你联系医生,而完全不调用 Gemini。对于每日洞察,该服务会丢弃任何读起来像医疗断言的生成结果,你的设备还会把剩下内容中的每个数字与你自己的数据重新核对,只要有一个数字对不上就丢弃该洞察。
  • Ember will not knowingly provide dosing advice, contraindication guidance, side-effect triage, or any clinical recommendation. For any medical question, contact your prescribing healthcare provider.
  • 在你同意之前,AI 功能始终保持关闭。当某项功能首次需要向 Gemini 发送数据时,Phaze 会展示将要发送的内容并请求许可,并记录你同意的是哪个版本的说明以及同意时间。“设置、隐私”中提供 AI 功能开关和“撤回 AI 许可”按钮。撤回会一次性停止所有 AI 功能,并清除已生成的洞察。

In accordance with the EU AI Act Article 50 transparency requirements, AI-generated outputs are labeled as AI in the interface, and you are informed when you interact with an AI system. Ember responses carry a per-output "AI-generated" label, and AI food-scan estimates are marked with an AI badge.

7. Retention

CategoryRetention
Consumer Health Data on your deviceUntil you delete it, or you uninstall the app
Consumer Health Data in your Cloud Backup仅 Android。保留至该备份文件从你 Google 云端硬盘的 AppData 文件夹中删除,“删除全部数据”会为你完成这一步。
Phaze 边缘服务上的记录那里不存储任何消费者健康数据。第 4.1 节所述自愿加入的资料、联系人、反馈、路线图与排名记录会保留至你关闭相应选项、使用“删除全部数据”或要求我们删除为止。请求日志遵循 Cloudflare 的保留窗口;食物扫描结果缓存 24 小时后过期。
AI provider transient retentionPer provider policy; we contractually require deletion within their normal log windows; we do not retain a copy ourselves
Aggregated, irreversibly anonymized statisticsIndefinite (no longer Consumer Health Data)
Legal holdAs required by law

8. Your rights

8.1 Washington (My Health My Data Act)

You have the right to:

  • Confirm whether Phaze is processing your Consumer Health Data
  • Access your Consumer Health Data
  • Request deletion of your Consumer Health Data: Phaze will delete the data within 30 days and direct any service provider or processor to do the same
  • Withdraw consent: you may withdraw consent to processing or sharing at any time; withdrawal does not affect prior lawful processing
  • Appeal a denial of any of the above

Submit requests by email to privacy@phaze.fit。你也可以在应用中使用“设置、隐私、全部删除、删除全部数据”。这一次操作即可移除设备上的数据、删除你 iCloud 或 Google 云端硬盘中的任何 Phaze 备份文件、取消已排定的提醒、将你的设备从分析与崩溃上报中退出,并删除第 4.1 节所述的资料与联系人记录。由于 Phaze 没有账户,我们会将你提供的信息与我们保存的记录(例如设备标识符,或资料、反馈记录中的电子邮件地址)进行比对以核验请求。我们会在法律要求的期限内答复,通常为 45 天,可延长一次。

If we deny a request, we will explain why and how to appeal within 45 days. If your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/file-complaint.

Geofencing. Phaze does not use geofences within 2,000 feet of any in-person health care service or facility.

8.2 Nevada (SB 370)

Nevada residents have the right to confirmation, access, deletion, opt-out of sale, and opt-out of sharing for targeted advertising. Phaze does not sell Consumer Health Data and does not engage in targeted advertising. Submit requests to privacy@phaze.fit.

8.3 Connecticut, Colorado, Virginia, Texas, Oregon, and other state laws

Residents of these states have rights including access, correction, deletion, portability, opt-out of sale, opt-out of targeted advertising, and the right to limit the use of sensitive data including consumer health data. Phaze does not sell or engage in targeted advertising and processes sensitive data only with your opt-in consent. Submit requests to privacy@phaze.fit. Universal opt-out signals (GPC) are honored where required.

8.4 California (CCPA / CPRA / CMIA)

California residents have all rights described in Section 13.3 of our Privacy Policy, including the right to limit use of sensitive personal information (which includes Consumer Health Data). We process your Consumer Health Data only as needed to provide the Service you requested.

For purposes of the California Confidentiality of Medical Information Act (CMIA, Cal. Civ. Code sections 56 et seq.), to the extent Phaze qualifies as a "provider of health care" as defined in the statute, the medical information you provide is processed under the safeguards described in this Policy and disclosed only as permitted by law or with your authorization.

8.5 Brazil (LGPD)

Brazilian residents may exercise rights under LGPD Article 18 (confirmation, access, correction, anonymization or deletion, portability, sharing information, consent revocation). Submit to privacy@phaze.fit or the Encarregado (Vinicius) at privacy@phaze.fit. ANPD: gov.br/anpd.

8.6 EU / UK / EEA

EU and UK residents may exercise rights under GDPR Articles 15 to 22, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects.

9. Security

We apply the following safeguards to Consumer Health Data:

  • Encryption at rest: AES-256-GCM for sensitive medical fields on device and for Cloud Backup archives
  • Encryption in transit: TLS 1.3
  • Platform key storage: Apple Keychain on iOS (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly); Android Keystore on Android (hardware-backed where available)
  • Crash-report scrubbing: Sentry breadcrumbs and event payloads are scrubbed to remove medication identifiers, doses, side-effect entries, injection-site notes, and medical profile before transmission
  • Vendor diligence: processors are reviewed before engagement and subject to data-processing terms
  • Access controls: role-based access to internal tools
  • Code review and testing: code review and automated test coverage prior to releases that affect data handling
  • We do not currently hold an independent security certification or audit attestation (for example, ISO 27001). We do not claim certifications we do not hold.
  • 如第 5 节所披露,产品分析事件与会话录制关联到设备范围的假名标识符。这属于假名化而非匿名化,并仍受本政策及我们隐私政策所述权利与义务的约束。

No method of transmission or storage is perfectly secure. If we discover a security incident that compromises the confidentiality of your Consumer Health Data, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318) within 60 days of discovery, the EU GDPR Article 33 and 34 (within 72 hours for the supervisory authority), the LGPD Article 48, and applicable US state breach-notification laws.

10. Consent

Phaze 没有账户。当某项功能首次需要在你的设备之外处理消费者健康数据时,我们会在应用内请求同意、展示将要发送的内容,并记录你同意的是哪个版本的说明以及同意时间。你可以随时通过以下方式撤回同意:

  • 在“设置、隐私”中关闭相应功能:AI 功能开关、“撤回 AI 许可”按钮、分析开关,或资料共享开关
  • Deleting the relevant data
  • 使用“设置、隐私、全部删除、删除全部数据”
  • Emailing privacy@phaze.fit to withdraw consent for any specific processing

Withdrawal does not affect prior lawful processing.

For sale or sharing of Consumer Health Data, we obtain separate, signed valid authorization prior to any such activity. We do not currently sell or share Consumer Health Data, so no such authorization is requested.

11. Children

The Service is intended for adults aged 18 and over. We do not knowingly collect Consumer Health Data from anyone under 18. If we learn we have collected data from a person under 18, we delete it promptly.

12. Changes to this Policy

We will post material changes here with a new "Last updated" date and notify you in-app or by email at least 30 days before they take effect, unless a shorter timeframe is required by law.

13. Contact

  • Email: privacy@phaze.fit
  • In-app: Settings, Privacy, Consumer Health Data Requests
  • Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
  • Brazilian Encarregado: Vinicius (privacy@phaze.fit)
  • EU / UK Representative: not currently appointed; will be appointed if and when our EU or UK user base reaches the threshold that requires one. Until then, contact privacy@phaze.fit.

If we deny your request, you may appeal at privacy@phaze.fit; if the appeal is denied, you may contact your state attorney general (in the United States), the Information Commissioner's Office (UK), your EU member-state supervisory authority, or the ANPD (Brazil).

返回首页