Privacy at Phaze
最后更新及生效日期:2026 年 9 月 2 日
Phaze is operated by Zeit Capital Ltda.
Ask only for what's necessary
We collect what we need to run the app. We do not sell your data and we do not share it with advertisers or data brokers.
Your health data stays on your device
你的记录保存在手机上应用自己的存储中。Phaze 不运行任何保存这些记录的服务器。在 Android 上,你可以开启加密备份到你自己的 Google 云端硬盘。
No medical data in advertising
We never use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.
目录
- 1. Who we are
- 2. Quick summary
- 3. Information we collect
- 4. How we use your information
- 5. Local storage and Cloud Backup
- 6. AI features, analytics, and other third-party processors
- 7. Apple HealthKit and Google Health Connect
- 8. Sharing
- 9. Retention
- 10. Security
- 11. Children
- 12. Your choices and rights
- 13. Jurisdiction-specific notices
- 14. Cookies and similar technologies (phaze.fit)
- 15. Changes to this Policy
- 16. Contact
1. Who we are
Phaze is operated by Zeit Capital Ltda, a limited liability company organized under the laws of Brazil ("Phaze," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Phaze mobile application, the Apple Watch companion, our website at phaze.fit, and related services (together, the "Service").
Contact
- Email (Privacy and Data Subject Rights): privacy@phaze.fit
- Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
- LGPD Encarregado de Dados (DPO for Brazil): Vinicius, privacy@phaze.fit
- EU Representative (Art 27 GDPR): a representative will be appointed if and when our EU user base reaches the threshold that requires one. Until then, contact us directly at privacy@phaze.fit and we will respond within statutory timeframes.
- UK Representative (UK GDPR Art 27): same status as the EU Representative above.
If you are in the European Economic Area, the United Kingdom, Brazil, or another jurisdiction with data-protection laws, additional rights and disclosures appear in Section 13.
2. Quick summary
This summary is informational only. The full text below governs.
- We do not sell your personal information.
- We do not share your personal information with advertisers or data brokers.
- 健康数据保存在你的设备上。Phaze 不在自有服务器上保留副本。在 Android 上,你可以启用云备份,它会把加密存档写入你自己的 Google 云端硬盘。见第 5 节。
- We do not use Apple HealthKit or Google Health Connect data for advertising, marketing, or sale.
- AI 功能(Ember 聊天、食物扫描、每日洞察)会通过我们运营的边缘服务把你的数据发送给 Google Gemini。在你单独授予许可之前,这些功能保持关闭,且你随时可以撤回许可。我们不会用你的数据训练 AI 模型。
- You must be 18 or older to use Phaze.
3. Information we collect
3.1 Information you provide
- Account information: Phaze 没有登录。没有用户名,也没有密码。你在引导流程中填写姓名和出生日期,两者都留在你的设备上。只有当你选择发送反馈,或在“设置、隐私”中开启资料共享时,才会提供电子邮件地址。
- Health and body data: weight, height, body composition entries, progress photos, goals, dietary preferences.
- Medication data: GLP-1 (or other) medication name, dose, schedule, side effects, injection-site notes. Provided voluntarily.
- Nutrition data: food logs, barcode scans, meal photos, voice-described meals, dietary preferences.
- Activity data: exercise logs, hydration entries, fasting windows, sleep summaries.
- Subscription information: purchase confirmations from Apple App Store or Google Play. We do not receive your full payment card number.
- Communications: support emails, in-app feedback.
3.2 Information collected automatically
- Device information: device model, operating system version, app version, language, time zone, country (derived from store region), and a device-generated pseudonymous identifier used to link your usage events.
- Diagnostics and product analytics: 崩溃报告、性能追踪、错误日志和产品分析事件。我们不会把你的电子邮件地址、姓名,或任何药物名称、剂量、副作用、注射部位发送给分析或崩溃服务商。分析事件记录你打开了哪些页面、执行了哪些操作,以及每日打卡中的情绪与精力评分,和你添加的化验指标名称,绝不包含其数值。我们的分析服务商还会录制约 10% 会话的屏幕,所有文本、图片和输入框在上传前都会被遮蔽。这些都关联到一个设备生成的标识符,因此属于假名化而非匿名。“设置、隐私”中的一个开关即可全部关闭。见第 6.2 节。
- Approximate location: city-level only, derived from IP. We do not collect precise GPS location.
3.3 Information from third parties
- Apple HealthKit (iOS): if you connect HealthKit, we read the data types you authorize. See Section 7.
- Google Health Connect (Android): if you connect Health Connect, we read the categories you authorize. Phaze currently requests: Steps (read), Weight (read and write), Active calories burned (read), Exercise session (read).
- Google 云端硬盘(仅 Android): 如果你在 Android 上开启云备份,你会授予 Phaze 云端硬盘 AppData 权限,以便把备份文件写入你自己的云端硬盘。我们不会收到任何其他云端硬盘内容。Phaze 没有账户,因此不使用“通过 Apple 登录”,也不使用 Google 登录。
We do not buy data from data brokers and do not enrich your profile from external sources.
3.4 What we do NOT extract
- No biometric identifiers. Phaze does not extract or store face geometry, facial landmarks, fingerprints, iris scans, voiceprints, speaker embeddings, gait analysis, or any other biometric identifier as defined by the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI statute, or similar laws. Food scans and progress photos are not processed for facial recognition. Voice transcription uses the platform speech APIs and does not create or retain a voiceprint on the Phaze side.
- No precise location. We do not collect GPS coordinates or use geofencing. We do not geofence around health care facilities.
- No third-party advertising IDs we use ourselves. The IDFA or advertising ID on your device is governed by the platform's privacy controls.
4. How we use your information
We process your information for the following purposes and on the following lawful bases (the lawful basis matters most under GDPR, UK GDPR, and LGPD; United States users may disregard the "Lawful basis" column).
| Purpose | What we do | Lawful basis (GDPR / LGPD) |
|---|---|---|
| Provide the Service | Render your dashboards, store your logs, sync to your watch, calculate trends | Performance of contract (Art 6(1)(b) GDPR) / Art 7(V) LGPD |
| Process health data | Store and display weights, photos, medications, food, activity | Explicit consent (Art 9(2)(a) GDPR) / Art 11(I) LGPD specific consent |
| AI features (Ember chat, food scan, recommendations) | Send your input to AI providers named in Section 6 to generate responses | Explicit consent for special-category processing (Art 9(2)(a) / Art 11) |
| Cloud Backup (optional) | Store an encrypted archive in your personal cloud storage if you enable it | Consent (Art 6(1)(a)) / Art 7(I) LGPD |
| Subscription billing | Process purchases through Apple App Store and Google Play | Performance of contract |
| Diagnostics and abuse prevention | Crash reports, performance monitoring, security | Legitimate interest (Art 6(1)(f)) / Art 7(IX) LGPD; you may object |
| Communicate updates | Service notices, policy changes | Legitimate interest / Art 7(IX) |
| Comply with law | Respond to legal process; protect rights | Legal obligation (Art 6(1)(c)) / Art 7(II) |
We do not use your information to: sell to third parties for monetary or other valuable consideration; serve targeted advertising; profile you to predict future behavior outside the Service; share with insurers, employers, or data brokers.
You may withdraw consent at any time by deleting the relevant data in-app, disabling the feature, or contacting privacy@phaze.fit. Withdrawal does not affect prior lawful processing.
5. Local storage and Cloud Backup
5.1 Default: on device
Your health, medication, and progress photo data is stored on your device:
- iOS: SwiftData persistent store with iOS Data Protection (NSFileProtectionCompleteUntilFirstUserAuthentication class). Sensitive medical fields (medication identifiers, doses, side-effect entries, injection-site notes, your medical profile, and your dose schedule) are additionally encrypted with AES-256-GCM using a key stored in the iOS Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly).
- Android: Room database. Sensitive medical fields are encrypted with AES-256-GCM (cipher mode AES/GCM/NoPadding, 256-bit key, 12-byte IV, 128-bit tag) using a key generated and stored in the Android Keystore (hardware-backed where the device supports it). General preferences use Android Jetpack Security's EncryptedSharedPreferences (AES256_SIV for keys, AES256_GCM for values) with a Keystore-bound master key.
Phaze 不运行任何存储你健康记录的服务器。确实有少量其他信息会到达我们运营的一项服务,第 5.4 节把它们全部列出。离开设备的数据流在第 6 节:AI 功能、分析、可选的云备份,以及可选的健康平台同步。
5.2 备份
备份的运作方式取决于你的平台,两者并不相同。
- iOS: Phaze 不再上传自己的备份。你的数据由 Apple 的 iPhone 备份承载,你在 iOS 设置中控制它,并在设备初始设置时恢复。“设置、数据与隐私、设备备份”会说明这一点,除此之外不提供任何操作,因为应用没有别的可控制。使用过旧版本的设备可能仍在 Phaze 的 iCloud 容器(iCloud.com.zeit.phaze)中保留一份存档。该页面允许你恢复一次或删除它,“删除全部数据”也会一并清除。
- Android: 云备份需主动开启,默认关闭。开启后,一份加密存档会写入你自己 Google 云端硬盘的 AppData 文件夹。该文件夹为 Phaze 专用、限于应用范围,在你常规的云端硬盘视图中不可见。频率由你选择:关闭、每天或每周。
两种情况下,存档内容在写入前都以 AES-256-GCM 加密。
About the encryption key. 为了让备份能在新设备上无需另设口令即可恢复,加密密钥在本地生成,并与加密内容一起保存在备份文件内。这意味着备份的安全性取决于你的 iCloud 或 Google 账户,而不是由你自己保管的口令。我们不支持用户自设口令,也不会把这份备份描述为“只有你能读取”,因为那会暗示存在我们无法触及的密钥。若你需要真正的零知识加密,请不要启用云备份。
Phaze 不保留任何备份的副本。存档只存在于你自己的 iCloud 或 Google 云端硬盘中。
在 Android 上,云备份启用后, 它会按你选择的频率运行。你可以随时在“设置、云备份”中更改频率或关闭它。
要删除备份文件: 应用内的“删除全部数据”会在同一操作中移除 Phaze 备份文件,两个平台均如此。你也可以在设置中关闭云备份,并通过 Apple 或 Google 的数据管理工具自行删除该文件。
5.3 What this means in plain language
- Default: on device.
- 在 iOS 上,应用本身不上传任何内容。在 Android 上,云备份默认关闭,开启后会有一份加密文件保存在你自己的 Google 云端硬盘中。
- AI features and analytics described in Section 6 do transmit specific fields off your device.
- 卸载应用会移除设备上的数据。Android 的云备份文件会一直留在你的 Google 云端硬盘中,直到被删除。
5.4 Phaze 在自有服务器上保存什么
我们在 Cloudflare 上运行一项自有服务。它代理第 6.1 节所述的 AI 请求,并在 Cloudflare D1 数据库中保存少量记录。以下就是全部。药物、剂量、用药安排、副作用、注射部位、体重、身高或 BMI 从不会写入这些记录。
- 资料共享(需主动开启,默认关闭): 如果你在“设置、隐私”中开启资料共享,我们会为你的设备保存一行记录:设备生成的标识符、出生年份与年龄段、生理性别、活动水平、转变目标、阶段、应用平台、版本与语言,以及你的同意标记。电子邮件地址保存在单独的表中,且仅在你提供时。Cloudflare 会附加它从请求本身解析出的国家、地区和城市。应用没有位置权限,也不会请求。关闭开关会删除该行,“删除全部数据”同样会删除。
- 反馈与功能路线图: 当你在应用内发送反馈或在公开路线图上投票时,我们会保存你的评分、你写下的留言(若有)、你提供的电子邮件地址(若有)、你的设备标识符,以及应用平台、版本和语言。若反馈留言提到药物、剂量或副作用,过滤器会在保存前将其拒绝。如需删除某条反馈或路线图条目,请发送邮件至 privacy@phaze.fit。
- 社区排名(需主动加入): 如果你加入排名,我们会保存你的设备标识符、生活方式评分和连续天数,以便计算名次。退出排名会删除该条目。
- 请求日志与缓存: 为了可靠性与限流,我们的服务会记录每次请求的 IP 地址、路由和大小。它不会记录 Ember 消息的文本、洞察内容、照片或任何健康数值。食物扫描结果会按图片哈希缓存 24 小时;图片本身不会保存。每日洞察从不缓存,也不记录。
6. AI features, analytics, and other third-party processors
6.1 AI features
- Ember (AI chat): 当你向 Ember 发送消息时,消息和一份上下文记录会经由我们在 Cloudflare 上运营的边缘服务发送到 Google Gemini。这份上下文记录就是你自己的历史数据,范围很广。视你记录的内容而定,它可能包括你的姓名、身高、生理性别、活动水平和目标;最近 30 天的每日记录,含营养、活动、情绪、精力、饥饿感、食欲噪音、睡眠,以及你记录的副作用及其严重程度;90 天的体重记录及其精确数值;你的运动记录;你的身体围度与身体成分;你的化验结果及其数值;你的里程碑;进度照片的日期和备注;以及你的药物名称、当前剂量、用药安排、用药日期、周期阶段和估算药物水平。单次剂量数值、注射部位和用药备注不会发送。进度照片的图像不经 Ember 发送,只发送其日期和备注。
- Food scan: 当你扫描一餐时,照片会经由同一边缘服务发送到 Google Gemini 进行营养估算。为避免同一张照片被分析两次,我们的服务会按图片哈希把返回的估算缓存 24 小时。照片本身不会保存,也不会从中提取任何生物识别标识。
- Voice meal description: 语音记录的餐食由 Apple 语音识别(iOS)或 Android SpeechRecognizer 转写。两者都是由 Apple 和 Google 控制路由的系统 API,Phaze 不强制设备端识别,因此在许多设备和语言上,音频确实会到达它们的语音服务。所得转写文本随后发送给 Gemini,解析为食物条目。
- Body composition estimate from photo: 如果你使用该功能,照片会经边缘服务发送给 Gemini,并返回一个数值估算。在照片离开手机之前,会先出现确认页告知你。不会派生或保存任何生物识别标识。
- 每日洞察(付费方案): 如果你拥有付费方案并已授予 AI 许可,Phaze 会通过边缘服务把你自己 90 天的记录发送给 Gemini,并取回一段简短的模式文字总结。该数据包含你的用药日期、带严重程度的副作用、餐食名称与宏量营养素、每日合计、睡眠、情绪、精力、体重、你的药物名称和当前剂量。它不包含单次剂量数值、注射部位、用药备注、进度照片、化验数值或身体成分。它从不在我们的服务器上缓存或记录。结果中的每个数字都会在你的设备上与你自己的数据重新核对,只要有一个数字对不上,该洞察就会被丢弃。
- 化验与 DEXA 文档导入: 如果你选择自动提取,你所选的化验单或 DEXA 扫描图像会经边缘服务发送给 Gemini。在文档离开手机之前,会先出现确认页告知你。保存前你会逐项复核提取出的每个数值。
- 数据导入: 你粘贴的文本,或从其他应用中选取的文件,会经边缘服务发送给 Gemini,以便 Phaze 识别出记录供你复核。该文本可能包含药物名称和剂量数值。
- 推荐、里程碑、连续记录与剂量周期估算: run on-device. No external service is called.
Important about AI features:
- AI 回答可能不准确、不完整或已过时。Ember 不提供医疗建议、剂量建议、禁忌指导或症状分诊。我们的边缘服务会先筛查每条消息,遇到剂量、药物相互作用或症状分诊类问题时,会直接建议你联系医生,而完全不调用 Gemini。有关剂量决定、副作用顾虑或任何临床问题,请联系为你开处方的医疗专业人员。
- 我们不会用你的数据训练任何模型。我们使用 Google 的付费 Gemini API,Google 针对该档位的条款说明,发送至该 API 的提示词与回复不会用于训练 Google 的模型。
- 在你同意之前,AI 功能始终保持关闭。当某项功能首次需要向 Gemini 发送数据时,Phaze 会展示将要发送的内容并请求许可,并记录你同意的是哪个版本的说明以及同意时间。“设置、隐私”中提供 AI 功能开关和“撤回 AI 许可”按钮。撤回会一次性停止所有 AI 功能,并清除已生成的洞察。
- AI-generated outputs are labeled as such in the interface per the EU AI Act Article 50. Ember responses carry a per-output "AI-generated" label, and AI food-scan estimates are marked with an AI badge.
6.2 Analytics, crash reporting, and attribution
We use the following third-party tools. Each one receives the categories described.
| Tool | Purpose | What is sent | Where |
|---|---|---|---|
| Mixpanel | Product analytics | 关联到设备生成标识符的假名化事件。不含电子邮件地址,也不含姓名。事件记录你打开了哪个页面、执行了哪个操作,以及每日打卡中的情绪与精力评分,和你添加的化验指标名称。体重数值、饮水量、餐食宏量营养素、食物名称、药物名称和剂量数值都不会发送。用户属性包括你的给药方式(“注射”“口服”或“无”)、开始至今天数、订阅状态和应用版本。由于同一设备的所有事件都关联同一个标识符,这一组合属于假名化而非匿名。 | United States |
| Mixpanel Session Replay | 抽样会话的屏幕录制 | 对随机抽取的约 10% 会话录制应用屏幕回放,上传后关联到与你的事件相同的设备标识符。所有文本、图片、网页视图、地图和输入框都会在上传任一帧之前在你的设备上被遮蔽,因此药物名称、剂量、副作用或注射部位在离开手机前就已被涂除。在“设置、隐私”中关闭分析即可停止录制。 | 美国 |
| Sentry | Crash and error monitoring | 崩溃报告、错误堆栈、导航与点击轨迹,以及崩溃时刻屏幕上视图层级的快照。药物标识、剂量、副作用记录、注射部位备注和你的医疗档案会在传输前从轨迹和事件负载中被匹配并移除,命中的轨迹会被整条丢弃。你的姓名和电子邮件会被剥除。用户标识是设备范围的 ID。给药方式作为上下文字段附加。“设置、隐私”中同一个分析开关也会关闭崩溃上报。 | United States |
| RevenueCat | Subscription state | Subscription identifiers, purchase confirmations, RevenueCat customer ID (mapped to your Mixpanel distinct ID). No health values. | United States |
| Meta (Facebook) Aggregated Event Measurement SDK | Install and conversion attribution | 安装、应用启动和转化事件,例如订阅。每个事件都带有一个由 SDK 生成并保存在你设备上的标识符,以及型号、系统版本等基本设备信息。不含任何药物、剂量、体重或饮食数值。广告标识符(iOS 上的 IDFA、Android 上的 GAID)不会被收集,我们已在配置中关闭。在 iOS 上,Phaze 会为此归因显示 Apple 的“应用跟踪透明度”提示。拒绝后,SDK 会转入聚合测量方式,事件仍会发送。 | United States |
| TikTok Business SDK(仅 Android) | Install and conversion attribution | 安装、应用启动、次两日留存和购买事件,均由 SDK 自动记录。不含任何药物、剂量、体重或饮食数值。iOS 版应用中没有这个 SDK。 | United States |
| Cloud Backup target | User-controlled storage | 加密存档(见第 5 节)。仅 Android。 | 你自己 Google 云端硬盘的 AppData 文件夹 |
| App distribution | Apple App Store, Google Play | Standard store telemetry | United States, Ireland (EU) |
| Phaze 边缘服务 | Cloudflare Workers 与 D1 | 代理第 6.1 节的 AI 请求,并保存第 5.4 节的记录。记录每次请求的 IP 地址、路由和大小。不记录消息文本或健康数值。 | 美国,Cloudflare 全球边缘节点 |
| Food data | USDA FoodData Central, Open Food Facts | 营养数据查询。USDA 检索经由我们的边缘服务,因此 USDA 看到的是我们的服务器而不是你。Open Food Facts 的条码查询直接从你的设备发出,因此它会看到你的 IP 地址。我们只发送食物名称或条形码,绝不发送你的体重或药物。 | United States, Europe |
| Recipes (Android) | Spoonacular | Recipe queries | United States |
| Health platforms | Apple HealthKit, Google Health Connect (only if you authorize) | Read and write of the categories you authorize | On your device |
We do not engage providers other than those listed above for the processing of your personal information. We require each provider to (i) act only on our instructions, (ii) implement appropriate security, (iii) not use your data for their own purposes other than aggregate statistics necessary for the service, and (iv) honor your deletion requests passed through us.
6.3 What about advertising trackers?
在 Phaze 移动应用中,我们在两个平台上使用 Meta 聚合事件衡量 SDK,并在 Android 上使用 TikTok Business SDK,用于安装归因。它们告诉我们是哪个广告系列把新用户带到了 Phaze。它们不用于在 Phaze 内投放广告,也不会向其中任何一方发送健康数值。在 iOS 上,Phaze 会为 Meta 归因展示 Apple 的“App 跟踪透明度”提示。我们没有在 phaze.fit 上嵌入 Meta Pixel、TikTok 网页像素、Snap Pixel、Google Ads 转化代码、Pinterest 代码或 LinkedIn Insight 代码。我们不出售你的个人信息。
7. Apple HealthKit and Google Health Connect
Phaze integrates with Apple HealthKit (iOS, watchOS) and Google Health Connect (Android) only if you authorize it. You choose which categories to share. You can revoke this access at any time from your device system settings.
In accordance with Apple's HealthKit terms (Apple Developer Program License Agreement section 5.1.4) and Google's Health Connect terms:
- We do not use HealthKit or Health Connect data for advertising or other use-based data mining purposes other than improving health, medical, and fitness management, or for the purpose of medical research.
- We do not sell HealthKit or Health Connect data to advertising platforms, data brokers, or information resellers.
- We do not share HealthKit or Health Connect data with third parties for advertising or marketing purposes.
- We do not use HealthKit or Health Connect data to identify users beyond what is necessary for personalization within Phaze.
- We will not access an end user's HealthKit or Health Connect data without their authorization.
HealthKit and Health Connect data is stored on your device. If you enable Cloud Backup, summaries you have created within Phaze (not raw HealthKit or Health Connect records) may be included in the encrypted backup archive.
8. Sharing
We share personal information only in these limited cases:
- With your direction: when you choose to export a PDF report, share a milestone card, send a screenshot, or grant a feature access to your data.
- With processors: the third-party providers listed in Section 6, bound by data-processing terms.
- For legal reasons: to comply with valid legal process (subpoena, court order), respond to government requests where required by law, or protect the safety and rights of Phaze, our users, or the public. We narrow disclosures to what is legally required.
- Business transfer: if Phaze is acquired, merged, or assets transferred, your information may be transferred to the successor entity subject to this Policy. You will be notified of any material change in handling.
我们不会按《加州消费者隐私法》《华盛顿州 My Health My Data 法》《康涅狄格州数据隐私法》《得克萨斯州数据隐私与安全法》或任何其他适用法律所定义的含义“出售”你的个人信息。但我们确实会在两个平台上向 Meta,以及在 Android 上向 TikTok,共享安装、应用启动和订阅事件,以便了解是哪条广告把人带到了 Phaze。每个事件都带有一个由归因 SDK 生成并保存在你设备上的标识符,以及型号、系统版本等基本设备信息。其中不包含任何药物、剂量、体重、饮食或其他健康数值。Meta 和 TikTok 可以将这些事件用于其自有平台上的广告衡量与投放,某些州法将此视为面向“跨情境行为广告”的“共享”。我们不在 Phaze 内展示广告。
9. Retention
| Category | Retention |
|---|---|
| 我们自有服务器上的记录(第 5.4 节) | 资料与联系人记录保留至你关闭资料共享或使用“删除全部数据”。排名保留至你退出。反馈与路线图条目保留至你要求删除。 |
| Health, medication, body, nutrition, activity data | 保存在你的设备上直至你删除。在 Android 云备份中保留至该备份被删除。不存储在我们的服务器上。 |
| Subscription records | 7 years (tax and accounting obligations) |
| Diagnostic and crash logs | 90 days, sanitized |
| Support correspondence | 24 months from last message |
| Aggregated, irreversibly anonymized statistics | Retained indefinitely (no longer personal data) |
| Legal hold | As required by law |
| 边缘请求日志、限流计数器与食物扫描缓存 | Cloudflare 的日志保留窗口。食物扫描结果缓存 24 小时。 |
当你在应用中使用“删除全部数据”时,一次操作即可移除设备上的数据、删除你 iCloud 或 Google 云端硬盘中的任何 Phaze 备份文件、取消所有已排定的提醒、将你的设备从分析、会话录制与崩溃上报中退出,并删除我们服务器上你的资料与联系人记录。如需删除某条反馈或路线图条目,请发送邮件至 privacy@phaze.fit。订阅与税务记录会在法律要求的范围内保留。
10. Security
We implement reasonable administrative, technical, and physical safeguards:
- AES-256-GCM at rest on device and for Cloud Backup archives
- TLS 1.3 in transit
- Apple Keychain and iOS Data Protection (iOS)
- Android Keystore plus EncryptedSharedPreferences (Android)
- Role-based access control on internal tools
- 在改变数据处理方式的版本发布前进行代码评审和自动化测试
- Vendor diligence on processors
No method of transmission or storage is perfectly secure. We do not claim to be HIPAA-compliant, and Phaze is not a HIPAA-covered entity.
Breach notification. If we discover a security incident that compromises the confidentiality of your personal information, we will notify you and applicable regulators in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318), GDPR Article 33 and 34, LGPD Article 48, and applicable state breach-notification laws. Where required, we will notify affected individuals within 60 days of discovery (HBNR) and applicable regulators within 72 hours (GDPR).
11. Children
Phaze 面向 18 周岁及以上的用户。引导流程会询问出生日期,若显示未满 18 周岁则无法继续。我们不会有意收集未满 18 周岁者的个人信息。若你认为未满 18 周岁的人向我们提供了个人信息,请联系 privacy@phaze.fit,我们会予以删除。
If we discover that we have collected personal information from a person under 18, we will delete that information promptly.
12. Your choices and rights
You have the following choices regardless of where you live:
- Access and export: 在应用内查看你的数据。“设置、隐私、导出数据”会生成记录的 JSON 文件;出于安全考虑,该文件不含医疗字段,因此如需包含药物、近期用药和副作用的 PDF,请使用“设置、我的报告”。
- Correct: edit any entry in-app.
- Delete: 删除单条记录,或使用“设置、隐私、全部删除、删除全部数据”。这一次操作即可移除设备上的数据、删除你 iCloud 或 Google 云端硬盘中的任何 Phaze 备份文件、取消已排定的提醒、将你的设备从分析与崩溃上报中退出,并删除我们服务器上你的资料与联系人记录。
- Disable AI features: “设置、隐私”中提供 AI 功能开关和“撤回 AI 许可”按钮。撤回会一次性停止所有 AI 功能,并清除已生成的洞察。
- Disconnect HealthKit or Health Connect: revoke from device system settings.
- 关闭云备份(Android): 在“设置、云备份”中关闭。在 iOS 上没有可关闭的项目,因为应用不上传自己的备份。
- Opt out of analytics: 在“设置”的“隐私”中,有一个开关可同时关闭产品分析、会话回放和崩溃报告。该开关不涵盖安装归因 SDK。对于这些 SDK,请使用你所在平台的控制项:iOS 上的“应用跟踪透明度”,以及 Android 设置中的广告 ID 控制项。拒绝“应用跟踪透明度”会让 Meta 转入聚合测量方式,但不会阻止安装和启动事件的发送。
- Push notifications: disable in device system settings.
To exercise any right not available in-app, email privacy@phaze.fit. We will verify your identity (typically by matching to the email of record) and respond within the timeframe required by your local law (generally 30 days under GDPR, 15 days under LGPD, 45 days under CCPA). If we cannot complete the request in that time, we will tell you why and what timeframe applies. You may appoint an authorized agent under CCPA and CPRA.
13. Jurisdiction-specific notices
13.1 European Economic Area and United Kingdom (GDPR / UK GDPR)
Controller and representatives: Zeit Capital Ltda. EU Representative: not currently appointed; see Section 1 for status and contact route. UK Representative: not currently appointed; see Section 1.
Lawful basis: see Section 4 table. We rely on explicit consent for special category health data (Art 9(2)(a) GDPR).
Your rights: access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), portability (Art 20), object (Art 21), withdraw consent (Art 7(3)), and not be subject to solely automated decisions with legal or similarly significant effects (Art 22). Automated decision-making: AI-generated suggestions in Ember and food scan are decision-support, not solely automated decisions with legal effects. You can disable them and continue using Phaze.
International transfers: 我们的主体位于巴西。你的数据可能被传输至美国或我们的处理方所在的其他司法辖区。我们与处理方依据欧盟标准合同条款,并在处理方已获认证时依据欧盟与美国数据隐私框架。如需了解某项具体传输所适用的保障措施,请联系 privacy@phaze.fit。
Complaints: you may lodge a complaint with the supervisory authority of your habitual residence. For UK users: the Information Commissioner's Office (ico.org.uk). Cookies and similar technologies on phaze.fit are covered in Section 14.
13.2 Brazil (LGPD)
Controller: Zeit Capital Ltda, registered in Brazil. Encarregado de Dados: Vinicius, privacy@phaze.fit.
Legal bases: Article 7 (general) and Article 11 (sensitive data: health, biometric where applicable). We rely on specific consent (Art 11(I)) for health data.
Your rights (Art 18): confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; deletion of data processed with consent; information about public and private entities with whom we share; information about the possibility of not providing consent; revocation of consent.
International transfers: we use standard contractual clauses approved by ANPD (Resolucao CD/ANPD no 19/2024) for cross-border transfers where applicable.
ANPD: you may submit a complaint to the Autoridade Nacional de Protecao de Dados (gov.br/anpd).
13.3 California (CCPA / CPRA)
We collect the following CCPA categories of personal information:
| Category | Examples |
|---|---|
| Identifiers | name, email, device ID |
| Customer records | account profile |
| Internet/network activity | app usage, crash logs |
| Geolocation (approximate) | city-level from IP |
| Audio | voice meal descriptions (transient) |
| Sensory | progress photos |
| Sensitive Personal Information (SPI) | 健康信息、进度照片 |
出售与共享:我们不会为金钱或其他有价对价而出售个人信息(包括敏感个人信息)。但我们确实会出于广告归因目的,向 Meta,以及在 Android 上向 TikTok,披露安装、应用启动和订阅事件。每个事件都带有一个由归因 SDK 生成并保存在你设备上的标识符,以及基本设备信息。其中不包含任何敏感个人信息和健康数值。由于 Meta 和 TikTok 可将这些事件用于其自有的广告衡量与定向,我们将其按面向跨情境行为广告的“共享”处理,而不主张其不属于该定义。来源为:你本人直接提供、你的设备,以及经你授权的 Apple 健康或 Google Health Connect。商业目的见第 4 节。向其他第三方的披露仅限于第 6 节所列的处理方,且以其服务提供者身份进行。
Your CCPA rights: 知情、访问、删除、更正、拒绝出售或共享(我们不出售;如需拒绝上述归因共享,请在 iOS 上拒绝“应用跟踪透明度”,或使用 Android 设置中的广告 ID 控制项)、限制敏感个人信息的使用、不受报复、授权代理人。请通过 privacy@phaze.fit,或在“设置”“隐私”“你的隐私选择”中提交请求。高级订阅(“Phaze Pro”)是对附加功能的付费,而非与数据收集挂钩的“财务激励”。Shine the Light:你可以查询我们为直接营销目的向第三方披露个人信息的情况。我们没有任何此类披露。
Universal opt-out signals (GPC): we honor Global Privacy Control signals on phaze.fit.
13.4 Washington (My Health My Data Act)
See the Consumer Health Data Privacy Policy for the disclosures required by the Washington My Health My Data Act, including categories of consumer health data, purposes, third parties, your right to withdraw consent, delete, and appeal.
13.5 Other US states (CO, CT, VA, UT, TX, OR, MT, IA, DE, NJ, MD, MN, NH, RI, TN, NV)
Residents of these states have rights including access, correction, deletion, portability, and opt-out of targeted advertising or sale (we do not engage in either). Health information is treated as sensitive data and we obtain opt-in consent before processing. Universal opt-out signals are honored where required. Submit requests to privacy@phaze.fit.
13.6 Japan (APPI)
Health data is treated as special care-required personal information and processed only with your opt-in consent. International transfer recipients and their data-protection frameworks are disclosed in Section 6.
13.7 China (PIPL)
Phaze does not actively offer the Service in mainland China. The Simplified Chinese localization is provided for users in other regions. Users in mainland China should not use the Service.
14. Cookies and similar technologies (phaze.fit)
The phaze.fit website uses:
- Strictly necessary cookies: 由你的 IP 推导出的国家标头设置的 country cookie,用于语言与定价路由;记住文档侧栏是否展开的 sidebar_state cookie;记录你对下方通知所作回应的 cookie_consent cookie;以及当你的浏览器发送全球隐私控制信号时设置的 gpc cookie。
- First-party performance and analytics: Vercel Analytics and Vercel Speed Insights, which use first-party storage and do not load third-party tracking pixels.
We do not embed Meta Pixel, TikTok Pixel, Snap Pixel, Google Ads conversion tag, Pinterest tag, or LinkedIn Insight tag on phaze.fit. We do not engage in cross-context behavioral advertising.
phaze.fit 不设置任何可选 cookie,因此横幅是带单个确认按钮的通知,而非接受或拒绝的选择。全球隐私控制信号会被直接视为拒绝,不再询问你。页脚的“你的隐私选择”可重新打开该通知,你也可以随时在浏览器设置中清除 cookie。
The Phaze mobile application uses the Meta Aggregated Event Measurement and TikTok Business SDKs for install attribution. On iOS, TikTok requests App Tracking Transparency authorization. We do not use these SDKs to serve personalized advertising within Phaze, and we do not embed advertising tags on phaze.fit.
15. Changes to this Policy
We will post material changes here and notify you in-app or by email at least 30 days before they take effect, except where a shorter timeframe is required by law. We will not apply material new uses to data we already hold without obtaining your consent where required.
16. Contact
Questions, requests, complaints:
- Email: privacy@phaze.fit
- Postal: Zeit Capital Ltda, SRTVS Conjunto L, Lote 38, Centro Empresarial Assis Chateaubriand, No 30, Sala 417 Parte J 07, Brasilia, DF, CEP 70340-906, Brazil
- Brazilian Encarregado: Vinicius (privacy@phaze.fit)
- EU Representative: not currently appointed (see Section 1)
- UK Representative: not currently appointed (see Section 1)
We aim to respond to all requests within 30 days, or sooner where required by law.
Phaze is not a medical device. The Service does not provide medical advice, diagnosis, or treatment. Always consult your healthcare provider regarding medications, dosing, or symptoms.