1. Who we are
Phyziq is made by Foggo Apps, the independent studio of developer Charles Chiejina ("we", "us"). This policy explains what the Phyziq app does with your information on iPhone and Apple Watch. You can reach us at support@foggoapps.com.
2. What stays on your device
Your workout logs, routines, programs, body measurements, progress photos, character and settings are saved locally. Your account is not a cloud backup of that information, and signing in on a new phone does not download it.
Progress photos are not uploaded by Phyziq to Foggo Apps, Supabase, RevenueCat or an AI service. Taking or choosing a progress photo saves it in the app on your iPhone. A workout-plan image you deliberately choose for AI import is a separate feature, described in AI features.
If you make a device backup or export a Phyziq backup file, the data included in that backup can leave the phone under your control. You choose where to save or share an exported file; it is not a backup hosted by Foggo Apps. Keep copies you need before deleting the app.
3. Apple Health
Phyziq uses Apple Health (HealthKit) only with your permission. You choose which data types it can access. These are the permissions requested by the app, across setup, workouts, cardio and the separate body-measurement import.
What the iPhone app reads
| Health data | Why |
|---|---|
| Steps | Your step totals, goal and history |
| Workouts | Workout access requested during setup |
| Heart rate and active energy | Live workout information and calories |
| Body weight (body mass), date of birth and biological sex | Your fitness profile and calorie calculations |
| Body weight, body fat percentage, height and lean body mass | Importing body measurements when you ask for it |
What the iPhone app writes
With your permission, Phyziq saves workouts, heart rate and active energy. For cardio and interval sessions it also requests permission to write walking/running distance, cycling distance, rowing distance and workout routes. Outdoor walks and runs can include the route recorded by your phone. It does not request permission to write steps, body measurements, date of birth or biological sex.
Apple Watch permissions
The Watch app requests permission to read workouts, heart rate and active energy, and to write workouts and walking/running, cycling and rowing distances. The phone and watch coordinate which device saves a session to Apple Health.
How health data is used
Health data is used for Phyziq's fitness features on your devices. It is not sent to our account or purchase services, sold, used for advertising or marketing, or used to build advertising profiles. Phyziq does not send HealthKit samples to AI services.
You can change access in the Health app under your profile → Apps → Phyziq. Removing access stops future reading or writing; data already saved in Apple Health stays there until you delete it in Health. Your own Apple Health storage and sync settings are controlled by Apple.
4. Motion and location
During a walk or run, Phyziq can use your iPhone's motion sensor to count steps and measure pace. For outdoor walks and runs, it asks for "While Using the App" location permission to measure distance and pace, draw your route, and add the route to the workout in Apple Health if allowed. Routes are saved locally. They are not sent to Foggo Apps, Supabase, RevenueCat or Gemini.
You can remove Motion & Fitness or Location Services access in iPhone Settings → Privacy & Security. These permissions are not used for advertising.
5. Apple Watch
Your iPhone and Apple Watch exchange the live workout through Apple's WatchConnectivity: exercises, sets, reps, weights, timers, session state and workout controls, along with live activity information such as heart rate and calories. This communication is between your devices through Apple's system, not through a Foggo Apps server.
6. Accounts and sign-in (optional)
You do not need a Foggo Apps account to log workouts or buy a Gym Pass. In Settings → Account & Gym Pass, you can sign in with Apple or Google when available. Email sign-in uses a one-time code when enabled; it is not currently offered in the configured release.
Our account provider is Supabase. Account records include an account ID, linked Apple or Google identifiers, an email address if supplied, sign-in/provider information and the record that you use Phyziq. Provider sign-in can include basic profile information; Apple asks for a name and email, and Google sign-in requests basic profile and email access. With Apple, you can choose a private relay email address. We never receive your Apple or Google password. Sign-in sessions are kept in your iPhone's Keychain.
For Sign in with Apple, an authorization code is sent to our account service and exchanged for a token used to request revocation when you delete your account. That token is stored on the server with your Phyziq account.
Phyziq and Step Tomo use the same Foggo Apps account system. They share a sign-in identity, but keep their app data and purchases separate. Signing in to Phyziq does not upload your workouts, measurements, photos or character.
Delete account in Settings → Account & Gym Pass removes your Phyziq account membership and its stored Apple token, and clears the sign-in from this iPhone. The app also requests revocation of the Phyziq Apple token; account deletion can still complete if Apple revocation fails. If you also use Step Tomo with that identity, its account and the shared sign-in record remain. Otherwise the underlying account, linked sign-in identities and email are deleted. See Delete your account for the full steps and the email option.
Where the GDPR or UK GDPR applies, our basis for handling your account information is providing the service you asked for. Optional device permissions are under your control and can be withdrawn at any time.
7. Purchases
Gym Pass subscriptions and Lifetime are sold by Apple through the App Store. Apple processes payment; we never receive your card details or Apple Account password. Apple's Privacy Policy covers its handling of your purchase.
RevenueCat records purchases and restored purchase history so we can maintain purchase records. When signed in, the identifier sent to RevenueCat is your account ID, never your email address. Without a linked account, RevenueCat uses an anonymous identifier. Phyziq does not set your name or email as RevenueCat customer attributes. This purchase processing is separate from usage analytics or advertising. See RevenueCat's Privacy Policy.
8. AI features
Currently, Phyziq uses Apple Intelligence on your iPhone where available. Workout-plan image reading, dictated-text interpretation, plan generation and exercise suggestions run on device. If on-device AI is unavailable, those AI features may be unavailable. The Gemini cloud fallback is currently disabled.
If a version offers the cloud fallback, requests go by HTTPS to Foggo Apps' own server proxy, hosted on Vercel, which forwards them to Google Gemini. Depending on the feature, the request contains:
- Workout-plan import: text read from the image you select and exercise-library names. If no text can be read, the selected workout-plan image is sent as a JPEG instead. This is not access to your progress-photo library.
- Dictated exercises: the dictated text and exercise-library names, not an audio recording.
- Plan generation: goal, experience level, training place or equipment, session length, number of days and exercises, the first day's exercise names, allowed library names and any supplied notes. Program generation can also include training frequency, preferred days, body focus areas, your main training constraint and sensitive areas you selected.
- Exercise suggestions: old saved exercise names and current library names for matching; exercise names, equipment, exercise type and current primary/secondary muscle labels for classification.
These requests do not automatically include your account ID, email, progress photos, body measurements, workout history, routes or raw Apple Health records. Anything you put in the selected image, dictated text or notes forms part of that request, so avoid including personal information you do not want processed.
We do not promise that cloud requests are excluded from model training. Google's handling depends on the applicable service terms and account configuration; see the Gemini API terms. The current on-device AI path does not send requests to Gemini.
9. Notifications
With permission, Phyziq schedules local training, walking and trial reminders on your iPhone. You can change them in the app or turn off notifications in iPhone Settings.
10. What we don't do
There are no ads, no advertising tracking, and no sale of your data in Phyziq. The app has no separate usage-analytics or crash-reporting SDK. RevenueCat's purchase records are described above. Fitness charts and progress calculations run locally; they are not usage reports sent to us.
11. Service providers and international transfers
- Apple: HealthKit and device services, Apple Intelligence, the App Store, payments and Sign in with Apple.
- Google: Sign in with Google; Gemini only if the cloud AI fallback is offered and used.
- Supabase: the shared Foggo Apps account system and Apple sign-in token storage.
- RevenueCat: purchase records and purchase identifiers.
- Vercel: hosting for our website and the Gemini proxy.
Our Supabase account service is configured in the United States. Providers may process information outside your country under their applicable data-processing and privacy terms. Account information travels over HTTPS. HealthKit samples and progress photos are not uploaded to those account or purchase services by Phyziq.
12. Data that can leave your device
| Data | Purpose and recipient |
|---|---|
| Account ID, provider identifiers, email if supplied, sign-in/profile information and Phyziq membership | Optional sign-in and account management through Supabase and your sign-in provider |
| Apple authorization code and token | Account linking and token revocation through our account service and Apple |
| Purchase records and an account or anonymous identifier | Apple payment processing and RevenueCat purchase records |
| Selected AI inputs listed above, only if cloud fallback is enabled | Responding to that request through our Vercel proxy and Google Gemini; currently disabled |
| Email address and anything you send in a support request | Answering your request |
Network services necessarily receive connection information, such as an IP address, when you connect. The live workout also moves between your own phone and watch, and files you export go wherever you choose to save or share them.
13. Your choices and rights
- Permissions: change Health, Motion & Fitness, Location, Camera, Photos and Notifications access in your device settings.
- Your account: use Delete account in Phyziq or ask by email. Account deletion does not cancel an Apple subscription or erase your local workout data.
- Your local data: manage it in the app, export a backup where available, or delete the app to remove its local files. Apple Health records and copies in your own backups are managed separately.
- Information we hold: email support@foggoapps.com to request access, correction or deletion. We reply within 30 days.
Depending on where you live, you may have rights to access, correct, delete or port personal data, object to or restrict processing, withdraw consent, and complain to your local data protection authority. We honour these requests for everyone, wherever you live. We do not sell or "share" personal information as those terms are defined under California law.
14. Children
Phyziq is a general-audience fitness app. We don't knowingly collect personal information from children under 13 (or the minimum age in your country). If you are under that age, please don't link an account or send personal information. If you believe a child has given us personal information, contact us and we will delete it.
15. Security and retention
Information on your devices is protected by iOS and watchOS, including their device security and HealthKit protections. Sign-in credentials are kept in the Keychain, and account requests use HTTPS. No system can guarantee absolute security.
We keep your Phyziq account information until you delete the account. Successful in-app deletion removes its account records immediately; email requests are handled within 30 days after we can verify the account. A shared identity stays while it is still used by Step Tomo. Apple and RevenueCat purchase records are separate and may remain for billing, refunds and legal records.
Your local files remain until you remove them or delete the app. Keychain records, including sign-in information and purchase-offer or reward flags, can survive reinstalling; signing out or deleting your account clears the app's sign-in. Your own device backups, exported files and Apple Health data are not erased by account deletion. Contact us about deletion of information you sent to support.
16. Changes and contact
If we change how Phyziq handles data, we will update this page and the date above, and for significant changes we will tell you in the app before the change applies.
Foggo Apps (Charles Chiejina)
Email: support@foggoapps.com
Help: Phyziq Support · Terms of Use