Last updated: August 26, 2026
This Privacy Policy explains how Jawad Hossain, an individual operating Phalanx from Canada ("Phalanx," "we," "us," or "our"), collects, uses, shares, and protects information when you use the Phalanx mobile application for iOS (the "App"). Phalanx is available to users worldwide; this Policy is written to address obligations that may apply under Canadian law (PIPEDA and applicable provincial legislation), the EU/UK GDPR, and the US CCPA/CPRA, in addition to general privacy practices. By using the App, you agree to the collection and use of information as described here.
When you sign up, we collect information through our authentication provider, Clerk, including your email address and, if you use Sign in with Google or Sign in with Apple, the basic profile information those providers share with us (typically name and email).
During onboarding, you provide: name, age, gender, height, weight, activity level, and fitness goal. From this, we calculate and store your BMI, BMR, TDEE, and macronutrient targets. This information is stored in our database (Supabase) tied to your account.
If you choose to fill in Health Conditions (Profile → Nutrition → Health Conditions), we also store whether you have indicated diabetes or a kidney condition. These answers are optional, are not collected during onboarding, and are used only to adjust your macronutrient split. We treat them as sensitive health information (see Section 9).
We also store logging-streak data — the date your current streak began, the date it was last extended, and your longest streak — so the App can display your streak.
When you log food, we store the food name, serving/quantity, calories, and macronutrients (protein, carbs, fat), the date logged, and whether the entry was generated by AI photo analysis or entered manually. Food search and barcode lookups are powered by the FatSecret nutrition database (see Section 4).
You can also save a food to a personal shortlist for quick re-logging. A saved food stores the food name, the serving you confirmed, and its nutrition values. Saved foods persist until you remove them or delete your account — they are not subject to the automatic diary deletion described in Section 8.
If you use the photo food-logging feature, the photo you take or select is sent to a third-party AI vision service (Google, via the Gemini API) to identify foods and estimate nutrition. You review and can edit the AI's output before it is saved. Photos you choose to save with a diary entry are stored in our private cloud storage (Supabase Storage), are not publicly accessible, and are served back to you only via access-controlled, signed links.
The App can also generate a shareable image card of a logged meal. The card is created entirely on your device. If you choose to share or save it, the image is handed to your device's own share sheet or photo library — we do not receive a copy of it, and we have no knowledge of where you send it.
If you choose to connect Apple Health, we read your step count only. We do not request or have the ability to write any data back to Apple Health (write access is explicitly disabled in our app configuration). You can revoke this access at any time in your device's Health app settings.
Your subscription/entitlement status is managed through RevenueCat. Purchases themselves are processed directly by the Apple App Store — we do not receive or store your payment card details.
We use Sentry for crash and error reporting. Sentry receives crash reports and error logs. It is configured not to attach your IP address, device identity, or account identity to these events, and error messages are filtered to strip email addresses before they are sent. Console output from the App is not forwarded off your device.
If you use the in-app "Report a Bug or Send Feedback" feature, the name, email, message, and optional screenshot you choose to submit are sent directly to Sentry. That submission is the only route by which Sentry receives information identifying you, and it contains only what you chose to enter.
To prevent abuse of AI photo analysis and food-search features, we temporarily process your account identifier through Upstash Redis to enforce usage limits. These features require a signed-in account; we do not use IP addresses for rate limiting, and unauthenticated requests are rejected rather than recorded. This data is used only for abuse prevention.
We do not collect your precise or approximate location. We do not use advertising identifiers (e.g., IDFA) and do not show an App Tracking Transparency prompt, because we do not integrate any advertising or cross-app tracking SDK. We do not use any analytics or behavioral-tracking SDK beyond the crash reporting described above.
We use the information above to:
Food photo analysis is performed by a third-party AI vision service (Google, via the Gemini API). Photos you submit for analysis are transmitted to this provider to generate food identification and nutrition estimates. These estimates are approximations, may be inaccurate, and are not medical or dietary advice — you should review and confirm them before relying on them. Our AI provider does not use photos submitted through the App to train or improve its models.
We share information with the following third parties as necessary to operate the App. Each is governed by its own privacy policy and terms:
| Provider | What it receives | Purpose |
|---|---|---|
| Clerk | Email, authentication credentials, session data | Account authentication and sign-in (including Google and Apple sign-in) |
| Supabase | Profile data, diary entries, food photos | Database and cloud storage |
| RevenueCat | Account identifier, entitlement/subscription status | Subscription management |
| Apple App Store | Payment information (handled by Apple, not us) | Payment processing and billing |
| FatSecret | Food search queries, barcode data | Nutrition database lookups |
| Google (Gemini API) | Food photos you submit for AI analysis | AI-based food recognition and nutrition estimation |
| Sentry | Crash logs and error messages (no IP address, no account identity); if submitted, feedback name/email/message/screenshot | Crash reporting and bug/feedback collection |
| Upstash (Redis) | Account identifier | Rate limiting / abuse prevention |
| Apple HealthKit | Step count (read-only) | Displaying your activity data in-app |
| YouTube | Standard video-embed interaction data | Displaying exercise demonstration videos |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use any advertising network.
Meal-reminder notifications are scheduled locally on your device. We do not collect or transmit a push-notification token to any server, and we do not send remote push notifications.
The App may request the following device permissions:
Each permission is requested only when you first use the feature that needs it, and the App remains usable if you decline. The App does not request microphone, location, contacts, or biometric permissions.
Your data is stored using Supabase (database and file storage) and Clerk (authentication), with row-level security restricting each user's data to that user's own authenticated account. Local session tokens are cached on your device using the iOS Keychain. All network communication uses HTTPS/TLS. We do not perform any additional application-level encryption beyond what these providers supply by default. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Deleting your account. You can delete your account, and all of the data described above, at any time from within the App: Profile → Account → Delete Account. The flow asks you to confirm twice, and warns you first if you have an active subscription. Deletion is immediate and permanent — Section 8 describes exactly what is erased.
Deleting your account does not cancel an App Store subscription. Subscriptions are billed by Apple, not by us, and must be cancelled separately in your Apple ID subscription settings. Deleting your Phalanx account while a subscription is active will not stop future charges.
Data export. We do not yet offer an automated data export within the App. To request a copy of your personal information, contact us using the details in Section 13 and we will respond within a reasonable time.
Depending on where you live, you may also have rights to access, correct, or restrict your personal information, and to withdraw previously granted permissions (for example, Health access, revocable in your device settings).
If you are in the European Economic Area or United Kingdom: we process your information based on your consent (for health/nutrition data, which may be considered a special category of data) and our legitimate interest in operating the App. You have the right to access, rectify, erase, restrict, or object to processing of your data, to data portability, and to lodge a complaint with your local data protection authority. Because our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, Google, FatSecret) may process data outside the EEA/UK, including in the United States, such transfers rely on the safeguards those providers offer (e.g., Standard Contractual Clauses). You may withdraw your consent to our processing of health and nutrition data at any time by deleting your account in the App, which erases that data.
If you are a California resident: you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell or share personal information as defined by the CCPA/CPRA, so no opt-out mechanism is required. We will not discriminate against you for exercising your privacy rights.
If you are in Canada: we handle your personal information in accordance with applicable federal and provincial privacy legislation (e.g., PIPEDA), including your right to access your personal information and challenge its accuracy.
Our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, Google, FatSecret) may store or process data on servers located outside your country of residence, including in the United States. By using the App, you understand that your information may be transferred to and processed in such locations.
Phalanx is not intended for children under the age of 13, and we do not knowingly collect personal information from anyone under 13. Where local law sets a higher minimum age for consent to online services — for example, 16 in some EU member states — the App is not intended for users below that age either. Our onboarding flow includes an age check (13–120) before a profile can be created, enforced within the app; it is not a verified, tamper-proof age-verification system. If we learn that we have collected personal information from a child below the applicable age without appropriate consent, we will delete it.
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where appropriate, we will provide notice within the App.
If you have questions about this Privacy Policy, or wish to exercise your privacy rights (including data access, correction, deletion, or export requests), contact us at:
contact@phlnx.org
Jawad Hossain