Legal
Privacy Policy
Last updated: 23 August 2026 · Effective on the date Phasly is made publicly available.
Plain-English summary: Phasly is a health app, so we handle some of the most sensitive data there is. We collect only what we need to personalise your training, we keep your intimate data in a separate private space, we encrypt your data in transit, and we never sell it. You can export or delete your data at any time. The full detail is below.
Important. Not a medical device. Phasly is a wellbeing tool, not a regulated medical device. We do not provide medical advice or diagnosis, and we do not use cycle data for contraception decision-making. If something feels off, like heavy bleeding, severe pain or missed periods, please consult a clinician (ACOG Committee Opinion 651).
1. Who we are
Phasly ("Phasly", "we", "us" or "our") provides a cycle-aware fitness and wellbeing application that personalises training to your menstrual cycle and to how you feel each day. This Privacy Policy explains what personal information we collect, how we use and protect it, and the choices you have. It applies to our website, our mobile apps and any related services (together, the "Service").
For the purposes of data protection law, Phasly is the data controller of the personal information described here.
2. What we collect
Information you give us
- Account details: your name and email address, and authentication data when you sign in (including via Google or Apple sign-in, if you choose them).
- Health & cycle data (sensitive): period and bleed dates, cycle and phase information, ovulation-test results, contraception type, relevant health conditions, pregnancy/postpartum status, and your daily check-ins. energy, sleep, readiness, mood and symptoms.
- Intimate activity data (sensitive): if you choose to log it, sexual-activity entries and protection used. This is stored in a separate, access-controlled space and is never shown on your main calendar.
- Fitness data: workouts, exercises, goals and training history you create in the app.
- Communications: messages you send us (e.g. support emails) and your waitlist / early-access sign-up.
Information we collect automatically
- Device & usage data: app version, device type and operating system, and basic interaction and diagnostic events, used to keep the app working and improve it.
- Crash & error reports: technical logs that help us fix bugs.
We do not use your health or intimate data for advertising, and we do not allow advertisers to target you based on it.
3. How we use your data
- To create and run your account and authenticate you securely.
- To generate your personalised, phase-aware and check-in-aware training plans and coaching.
- To sync your data across your devices so you don't lose it.
- To provide customer support and respond to your requests.
- To maintain, secure, debug and improve the Service.
- To send you service-related and (where you've opted in) launch and product emails. You can unsubscribe at any time.
- To comply with legal obligations and enforce our Terms.
4. Legal bases & consent
Where the GDPR or similar laws apply, we rely on the following legal bases: your consent (especially for health and intimate data, which are special-category data), performance of a contract (to provide the Service you sign up for), legitimate interests (to secure and improve the Service, balanced against your rights), and legal obligation where required.
You can withdraw your consent at any time by editing or deleting the relevant data or your account. Withdrawing consent doesn't affect processing that already happened.
5. Who we share data with
We do not sell your personal information. We share it only with service providers ("processors") who help us run the app, under contracts that require them to protect it and use it only on our instructions. These currently include:
- Cloud database & authentication (e.g. Supabase), to store your account and app data securely.
- AI processing (Anthropic, PBC). Phasly's coach, Phoebe, is powered by Anthropic's Claude models. When you chat with Phoebe or use AI-generated features (workout suggestions, weekly digests, PDF import), the content of your messages together with relevant profile and cycle context is sent to Anthropic's API to generate the response. Anthropic acts as our data processor under contract: this data is not used to train Anthropic's models, and API inputs and outputs are retained by Anthropic only for limited-time safety and abuse monitoring under their commercial terms.
- Email delivery (Resend), to send account, support and launch emails.
- Error & crash monitoring (Sentry), to detect and fix technical problems. Crash reports contain device and diagnostic data, not your health entries.
- Subscription management (RevenueCat), to manage subscription status and entitlements across devices. RevenueCat receives purchase and subscription-status information, never your health data.
- App stores & payment processors (e.g. Apple App Store, Google Play), to handle subscriptions and billing. We do not receive or store your full card details.
- Website analytics & advertising measurement (Google Analytics, Microsoft Clarity, Meta, TikTok), on phasly.app only, with cookie consent, and never connected to your in-app health data.
We may also disclose data if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (in which case we'll notify you).
5a. Health data, the special rules we hold ourselves to
Your cycle, symptom, pregnancy, contraception and intimate data are special-category health data. On top of everything above, these rules apply specifically to them:
- Where it lives. In our cloud database (Supabase), protected by row-level security so only your authenticated account can read your rows, and encrypted in transit (HTTPS/TLS).
- Who ever sees it. Only two processors can touch health entries: Supabase (storage) and Anthropic (generating your coach's replies, as described above). No analytics tool, no advertiser, no crash reporter receives it.
- Apple Health. If you connect Apple Health, HealthKit data is read on your device with your permission, used only for the app's features, and is never used for advertising or shared with third parties, in line with Apple's HealthKit rules.
- Never for ads. Never sold. We do not use health data for advertising, do not sell it, and do not "share" it for cross-context behavioural advertising as defined by the CCPA/CPRA.
- Not for contraception. Phasly's predictions and fertile-window estimates are informational. We do not offer or market them as a contraceptive method.
- How to delete it. Delete individual entries in the app anytime, or delete everything at once in Profile Settings → Delete account. Deletion removes your cycle history, day logs, workouts and coach memory from our database. No longer have the app? Use the account deletion request form, no install and no login needed.
6. How we protect your data
We use industry-standard safeguards, including encryption in transit (HTTPS/TLS), access controls and database row-level security so each user can only reach their own data, and secure storage of authentication tokens on your device. No system is perfectly secure, but we work hard to protect your information and to limit who can access it internally.
7. How long we keep it
We keep your personal data for as long as your account is active or as needed to provide the Service. If you delete specific entries, they are removed from your account. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep limited records to meet legal obligations.
8. Your rights & choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and get a copy (data portability / export).
- Correct inaccurate data.
- Delete your data and your account.
- Restrict or object to certain processing, and withdraw consent.
- Lodge a complaint with your local data-protection authority.
You can exercise most of these rights directly in the app (Profile Settings → Delete account removes everything), through the deletion request form if you no longer have the app installed, or by emailing us at privacy@phasly.app. We won't discriminate against you for exercising your rights.
California (CCPA/CPRA). California residents have the right to know what personal information we collect and how it's used, to access and correct it, to delete it, and to opt out of "sale" or "sharing" of personal information. Phasly does not sell your personal information and does not share it for cross-context behavioural advertising. To exercise these rights, use the in-app controls or email privacy@phasly.app. we will verify and respond within the statutory window.
EU/EEA and UK (GDPR). The rights above (access, rectification, erasure, restriction, objection, portability, withdrawal of consent) apply in full, and you may lodge a complaint with your supervisory authority. Health and intimate data are processed on the basis of your explicit consent.
9. Children
Phasly is not directed to children. You must be at least 16 years old (or the age of digital consent in your country, whichever is higher) to use the Service. We do not knowingly collect data from children below that age; if you believe a child has provided us data, contact us and we will delete it.
10. International transfers
Your data may be processed in countries other than your own, including where our service providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) to protect your data when it is transferred internationally.
11. Changes to this policy
We may update this Privacy Policy as the Service evolves. If we make material changes, we'll update the "Last updated" date and, where appropriate, notify you in the app or by email. Continued use of the Service after changes take effect means you accept the updated policy.
Questions, requests or concerns about your privacy? Email us at privacy@phasly.app. We read every message.