Last updated: August 5, 2026
This Privacy Policy explains how Jawad Hossain, an individual operating Phalanx from Canada ("Phalanx," "we," "us," or "our"), collects, uses, shares, and protects information when you use the Phalanx mobile application for iOS (the "App"). Phalanx is available to users worldwide; this Policy is written to address obligations that may apply under Canadian law (PIPEDA and applicable provincial legislation), the EU/UK GDPR, and the US CCPA/CPRA, in addition to general privacy practices. By using the App, you agree to the collection and use of information as described here.
When you sign up, we collect information through our authentication provider, Clerk, including your email address and, if you use Sign in with Google or Sign in with Apple, the basic profile information those providers share with us (typically name and email).
During onboarding, you provide: name, age, gender, height, weight, activity level, and fitness goal. From this, we calculate and store your BMI, BMR, TDEE, and macronutrient targets. This information is stored in our database (Supabase) tied to your account.
When you log food, we store the food name, serving/quantity, calories, and macronutrients (protein, carbs, fat), the date logged, and whether the entry was generated by AI photo analysis or entered manually. Food search and barcode lookups are powered by the FatSecret nutrition database (see Section 4).
If you use the photo food-logging feature, the photo you take or select is sent to a third-party AI vision service (OpenRouter, using a Google Gemma vision model) to identify foods and estimate nutrition. You review and can edit the AI's output before it is saved. Photos you choose to save with a diary entry are stored in our private cloud storage (Supabase Storage), are not publicly accessible, and are served back to you only via access-controlled, signed links.
If you choose to connect Apple Health, we read your step count only. We do not request or have the ability to write any data back to Apple Health (write access is explicitly disabled in our app configuration). You can revoke this access at any time in your device's Health app settings.
Your subscription/entitlement status is managed through RevenueCat. Purchases themselves are processed directly by the Apple App Store — we do not receive or store your payment card details.
We use Sentry for crash and error reporting. Sentry receives crash reports, error logs, and — because of our current configuration — your IP address with each event. If you use the in-app "Report a Bug or Send Feedback" feature, the name, email, message, and optional screenshot you choose to submit are sent directly to Sentry.
To prevent abuse of AI photo analysis and food-search features, we temporarily process an identifier (your account ID, or your IP address if not signed in) through Upstash Redis to enforce usage limits. This data is used only for abuse prevention.
We do not collect your precise or approximate location. We do not use advertising identifiers (e.g., IDFA) and do not show an App Tracking Transparency prompt, because we do not integrate any advertising or cross-app tracking SDK. We do not use any analytics or behavioral-tracking SDK beyond the crash reporting described above.
We use the information above to:
Food photo analysis is performed by a third-party AI vision service (OpenRouter). Photos you submit for analysis are transmitted to this provider to generate food identification and nutrition estimates. These estimates are approximations, may be inaccurate, and are not medical or dietary advice — you should review and confirm them before relying on them.
We share information with the following third parties as necessary to operate the App. Each is governed by its own privacy policy and terms:
| Provider | What it receives | Purpose |
|---|---|---|
| Clerk | Email, authentication credentials, session data | Account authentication and sign-in (including Google and Apple sign-in) |
| Supabase | Profile data, diary entries, food photos | Database and cloud storage |
| RevenueCat | Account identifier, entitlement/subscription status | Subscription management |
| Apple App Store | Payment information (handled by Apple, not us) | Payment processing and billing |
| FatSecret | Food search queries, barcode data | Nutrition database lookups |
| OpenRouter | Food photos you submit for AI analysis | AI-based food recognition and nutrition estimation |
| Sentry | Crash logs, IP address, and (if submitted) feedback name/email/message/screenshot | Crash reporting and bug/feedback collection |
| Upstash (Redis) | Account identifier or IP address | Rate limiting / abuse prevention |
| Apple HealthKit | Step count (read-only) | Displaying your activity data in-app |
| YouTube | Standard video-embed interaction data | Displaying exercise demonstration videos |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use any advertising network.
Meal-reminder notifications are scheduled locally on your device. We do not collect or transmit a push-notification token to any server, and we do not send remote push notifications.
The App may request the following device permissions:
Our app configuration also currently requests Microphone and Face ID/biometric permissions on iOS. Neither is used by any feature in the App today — these are default entries introduced by underlying components and have not yet been removed. No microphone audio or biometric data is captured or processed.
Your data is stored using Supabase (database and file storage) and Clerk (authentication), with row-level security restricting each user's data to that user's own authenticated account. Local session tokens are cached on your device using the iOS Keychain. All network communication uses HTTPS/TLS. We do not perform any additional application-level encryption beyond what these providers supply by default. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Depending on where you live, you may have rights to access, correct, delete, or request a copy of your personal information, and to withdraw previously granted permissions (e.g., Health access, revocable in your device settings). Account deletion and data-export requests are currently handled manually — contact us using the details in Section 13, and we will respond within a reasonable time. We do not currently offer an automated, self-service data export or account-deletion tool within the App.
If you are in the European Economic Area or United Kingdom: we process your information based on your consent (for health/nutrition data, which may be considered a special category of data) and our legitimate interest in operating the App. You have the right to access, rectify, erase, restrict, or object to processing of your data, to data portability, and to lodge a complaint with your local data protection authority. Because our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, OpenRouter, FatSecret) may process data outside the EEA/UK, including in the United States, such transfers rely on the safeguards those providers offer (e.g., Standard Contractual Clauses); we have not independently verified each provider's specific transfer mechanism for purposes of this draft — see Reviewer Notes.
If you are a California resident: you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell or share personal information as defined by the CCPA/CPRA, so no opt-out mechanism is required. We will not discriminate against you for exercising your privacy rights.
If you are in Canada: we handle your personal information in accordance with applicable federal and provincial privacy legislation (e.g., PIPEDA), including your right to access your personal information and challenge its accuracy.
Our service providers (Clerk, Supabase, RevenueCat, Sentry, Upstash, OpenRouter, FatSecret) may store or process data on servers located outside your country of residence, including in the United States. By using the App, you understand that your information may be transferred to and processed in such locations.
Phalanx is not intended for children under the age of 13, and we do not knowingly collect personal information from anyone under 13. Our onboarding flow includes an age check (13–120) before a profile can be created, enforced within the app; it is not a verified, tamper-proof age-verification system. If we learn that we have collected personal information from a child under 13 without appropriate consent, we will delete it.
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where appropriate, we will provide notice within the App.
If you have questions about this Privacy Policy, or wish to exercise your privacy rights (including data access, correction, deletion, or export requests), contact us at:
[email protected]
Jawad Hossain