Phalanx

Phalanx Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how Jawad Hossain, an individual operating Phalanx from Canada ("Phalanx," "we," "us," or "our"), collects, uses, shares, and protects information when you use the Phalanx mobile application for iOS (the "App"). Phalanx is available to users worldwide; this Policy is written to address obligations that may apply under Canadian law (PIPEDA and applicable provincial legislation), the EU/UK GDPR, and the US CCPA/CPRA, in addition to general privacy practices. By using the App, you agree to the collection and use of information as described here.


1. Information We Collect

a. Account Information

When you sign up, we collect information through our authentication provider, Clerk, including your email address and, if you use Sign in with Google or Sign in with Apple, the basic profile information those providers share with us (typically name and email).

b. Profile and Onboarding Information

During onboarding, you provide: name, age, gender, height, weight, activity level, and fitness goal. From this, we calculate and store your BMI, BMR, TDEE, and macronutrient targets. This information is stored in our database (Supabase) tied to your account.

c. Food and Nutrition Data

When you log food, we store the food name, serving/quantity, calories, and macronutrients (protein, carbs, fat), the date logged, and whether the entry was generated by AI photo analysis or entered manually. Food search and barcode lookups are powered by the FatSecret nutrition database (see Section 4).

d. Food Photos and AI Analysis

If you use the photo food-logging feature, the photo you take or select is sent to a third-party AI vision service (OpenRouter, using a Google Gemma vision model) to identify foods and estimate nutrition. You review and can edit the AI's output before it is saved. Photos you choose to save with a diary entry are stored in our private cloud storage (Supabase Storage), are not publicly accessible, and are served back to you only via access-controlled, signed links.

e. Health and Fitness Data

If you choose to connect Apple Health, we read your step count only. We do not request or have the ability to write any data back to Apple Health (write access is explicitly disabled in our app configuration). You can revoke this access at any time in your device's Health app settings.

f. Subscription and Payment Status

Your subscription/entitlement status is managed through RevenueCat. Purchases themselves are processed directly by the Apple App Store — we do not receive or store your payment card details.

g. Device, Diagnostic, and Crash Data

We use Sentry for crash and error reporting. Sentry receives crash reports, error logs, and — because of our current configuration — your IP address with each event. If you use the in-app "Report a Bug or Send Feedback" feature, the name, email, message, and optional screenshot you choose to submit are sent directly to Sentry.

h. Rate-Limiting Data

To prevent abuse of AI photo analysis and food-search features, we temporarily process an identifier (your account ID, or your IP address if not signed in) through Upstash Redis to enforce usage limits. This data is used only for abuse prevention.

i. What We Do Not Collect

We do not collect your precise or approximate location. We do not use advertising identifiers (e.g., IDFA) and do not show an App Tracking Transparency prompt, because we do not integrate any advertising or cross-app tracking SDK. We do not use any analytics or behavioral-tracking SDK beyond the crash reporting described above.

2. How We Use Your Information

We use the information above to:

  • Create and maintain your account and profile
  • Calculate your nutrition and fitness targets (BMI, BMR, TDEE, macros)
  • Provide food logging, food search, barcode lookup, and AI-based photo food recognition
  • Verify and manage your subscription status
  • Maintain app stability through crash and error monitoring
  • Prevent abuse of rate-limited features
  • Respond to support requests and feedback you submit

3. AI-Generated Content

Food photo analysis is performed by a third-party AI vision service (OpenRouter). Photos you submit for analysis are transmitted to this provider to generate food identification and nutrition estimates. These estimates are approximations, may be inaccurate, and are not medical or dietary advice — you should review and confirm them before relying on them.

4. Third-Party Service Providers

We share information with the following third parties as necessary to operate the App. Each is governed by its own privacy policy and terms:

ProviderWhat it receivesPurpose
ClerkEmail, authentication credentials, session dataAccount authentication and sign-in (including Google and Apple sign-in)
SupabaseProfile data, diary entries, food photosDatabase and cloud storage
RevenueCatAccount identifier, entitlement/subscription statusSubscription management
Apple App StorePayment information (handled by Apple, not us)Payment processing and billing
FatSecretFood search queries, barcode dataNutrition database lookups
OpenRouterFood photos you submit for AI analysisAI-based food recognition and nutrition estimation
SentryCrash logs, IP address, and (if submitted) feedback name/email/message/screenshotCrash reporting and bug/feedback collection
Upstash (Redis)Account identifier or IP addressRate limiting / abuse prevention
Apple HealthKitStep count (read-only)Displaying your activity data in-app
YouTubeStandard video-embed interaction dataDisplaying exercise demonstration videos

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use any advertising network.

5. Push and Local Notifications

Meal-reminder notifications are scheduled locally on your device. We do not collect or transmit a push-notification token to any server, and we do not send remote push notifications.

6. Device Permissions

The App may request the following device permissions:

  • Camera — to photograph meals and scan barcodes
  • Photo Library — to select existing photos for AI food analysis
  • Health (read-only) — to display your step count, if you choose to connect it
  • Notifications — to schedule local meal reminders

Our app configuration also currently requests Microphone and Face ID/biometric permissions on iOS. Neither is used by any feature in the App today — these are default entries introduced by underlying components and have not yet been removed. No microphone audio or biometric data is captured or processed.

7. Data Storage and Security

Your data is stored using Supabase (database and file storage) and Clerk (authentication), with row-level security restricting each user's data to that user's own authenticated account. Local session tokens are cached on your device using the iOS Keychain. All network communication uses HTTPS/TLS. We do not perform any additional application-level encryption beyond what these providers supply by default. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

8. Data Retention

  • Food diary entries are automatically and permanently deleted on a rolling basis, generally within about five weeks of creation, regardless of whether your account remains active.
  • Food photos are deleted together with the diary entries they belong to. Because a single photo can be attached to several entries from the same meal, a photo is removed once the last entry referencing it is deleted. Removal is normally immediate; any photo that cannot be removed straight away is queued and cleared by an automated daily process, so photos do not outlive their entries by more than about a day.
  • Profile and account information is retained for as long as your account remains active, or until you request deletion.
  • Crash/diagnostic data and feedback submissions are retained according to Sentry's own retention settings.

9. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or request a copy of your personal information, and to withdraw previously granted permissions (e.g., Health access, revocable in your device settings). Account deletion and data-export requests are currently handled manually — contact us using the details in Section 13, and we will respond within a reasonable time. We do not currently offer an automated, self-service data export or account-deletion tool within the App.

If you are in the European Economic Area or United Kingdom: we process your information based on your consent (for health/nutrition data, which may be considered a special category of data) and our legitimate interest in operating the App. You have the right to access, rectify, erase, restrict, or object to processing of your data, to data portability, and to lodge a complaint with your local data protection authority. Because our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, OpenRouter, FatSecret) may process data outside the EEA/UK, including in the United States, such transfers rely on the safeguards those providers offer (e.g., Standard Contractual Clauses); we have not independently verified each provider's specific transfer mechanism for purposes of this draft — see Reviewer Notes.

If you are a California resident: you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell or share personal information as defined by the CCPA/CPRA, so no opt-out mechanism is required. We will not discriminate against you for exercising your privacy rights.

If you are in Canada: we handle your personal information in accordance with applicable federal and provincial privacy legislation (e.g., PIPEDA), including your right to access your personal information and challenge its accuracy.

10. International Data Transfers

Our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, OpenRouter, FatSecret) may store or process data on servers located outside your country of residence, including in the United States. By using the App, you understand that your information may be transferred to and processed in such locations.

11. Children's Privacy

Phalanx is not intended for children under the age of 13, and we do not knowingly collect personal information from anyone under 13. Our onboarding flow includes an age check (13–120) before a profile can be created, enforced within the app; it is not a verified, tamper-proof age-verification system. If we learn that we have collected personal information from a child under 13 without appropriate consent, we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where appropriate, we will provide notice within the App.

13. Contact Us

If you have questions about this Privacy Policy, or wish to exercise your privacy rights (including data access, correction, deletion, or export requests), contact us at:

[email protected]
Jawad Hossain