Evidence Review uses disclosure and consent version 6. It sends only reduced, metadata-stripped photos from the selected comparison pair, check-in, upload and pair identifiers, and match quality. It sends no weight.
A later Review question requires both reviewText and healthContext before it may share an expressly selected user-entered weight from the selected pair. It sends no photos or Apple Health sample.
Privacy policy
PhysiqueProof is designed so your original progress photos stay on your iPhone and online processing happens only when you request it.
Who operates PhysiqueProof
PhysiqueProof is operated by Josh Waller trading as Kovus in Western Australia. Privacy questions can be sent to josh@kovus.dev.
Information we handle
- Account identifiers supplied through Sign in with Apple, including a stable user ID and an email or private relay email. If you used email-and-password sign-in in an earlier version, Supabase handles those credentials. Kovus does not receive or store your plaintext password or your Apple Account password.
- Apple purchase history, original transaction lineage and entitlement status needed to provide PhysiqueProof Pro and prevent one subscription receiving duplicate paid allowances after restore, transfer or account deletion.
- An Apple App Attest key identifier, public key, attestation receipt and request counter linked to the signed-in account while it exists. These cryptographic records help confirm that paid server requests come from a genuine installation of PhysiqueProof.
- Reduced copies of matched progress photos you choose may enter Evidence Review with check-in, upload and pair identifiers and match quality. No weight is included. Original photos stay on your iPhone.
- Ask and Review questions and the bounded recent conversation context needed to answer a question. Full conversations and reference links supplied with successful Ask answers are stored locally on your iPhone.
- Feedback categories and messages you choose to send from Settings.
- Apple Health samples you explicitly authorise — body mass, body fat percentage, lean body mass, waist circumference and workouts over a rolling 180-day Trends-only window — as described below.
-
A Hevy Pro API key you choose to connect, encrypted connection metadata, and workout data
fetched to create bounded workout-count, cardio and muscle-group summaries. The server
discards the fetched Hevy data after responding and stores no Hevy rows in hosted
Postgres. The summaries and the raw workouts and sets are stored in the app's local
database (
hevy_workouts,hevy_exercise_sets). Disconnecting Hevy clears those local tables. - Account-linked feature usage and rate-limit counts. Legacy allowance records created during earlier testing can retain a one-way hash derived from a stable sign-in identifier without your account ID or email so deleting or recreating an account cannot reset an already consumed allowance. Paid-subscription quota totals, conservative provider-cost reservations, model and token totals are also used to operate online features, prevent allowance resets and control costs. These records do not contain your photos, prompts, Review responses or Health values.
Online AI consent and age requirement
Online AI features are available only to users aged 18 or older. Before your first online AI request, PhysiqueProof names Google Gemini, explains the categories of information that can be shared, asks you to confirm that you are at least 18, and offers Allow or Not now. Choosing Not now keeps online AI processing off.
If you choose Allow, disclosure version 6 stores only the exact scopes you accepted:
photoEvidence for reduced paired-review photos, reviewText for an
Ask, Review, Training or Journal question, journalContext for selected Journal
dates, check-in cadence and pose-coverage counts in an Ask question (never photos, file
paths or record identifiers), healthContext for user-entered weight shared with
one of those questions, workoutContext for an expressly selected Hevy summary,
compareHistory for the captions of your own Compare results (dates, area,
outcome and limitations) in an Ask question (never the photos), and
goalVisual for a labelled AI goal visual from one selected check-in photo. The
goal-visual feature is not available in this build, so no photo is sent for it. Each scope
is off by default and one scope never authorises another.
Version 6 still states that the same reduced, temporary photo copies made for an evidence
review may be read for a visual body-composition indication shown beside that check-in. That
indication is not available in this build, so those copies are not read for it. Where it is
available it describes how the photos look rather than what your body is. It is not a
percentage, a measurement or a health conclusion, and PhysiqueProof does not use photos to
provide body measurements or appearance grades. It is covered by
photoEvidence and by nothing else.
Version 4 and version 5 permission no longer authorises any online AI feature. Version 3 permission is legacy-only: it still covers a request sent in the earlier v1 or r1 format by an app version you have not updated yet, and can never authorise the post-1.0 v2/r2 contract. Build 36 uses version 6 even though its generic request remains v1/r1. When the disclosure changes, you are asked again before anything is shared.
The server checks every required current-version scope before Google access. Permission applies only when you deliberately request an online AI feature. You can withdraw every scope at any time in Settings. Withdrawal blocks future information sharing on the device and server; it cannot undo a request that has already been processed or remove a result already saved on your device.
What is shared with Google Gemini
Depending on the feature you request, PhysiqueProof shares:
- For Evidence Review: only reduced, metadata-stripped photo copies from the selected comparison pair, check-in, upload and pair identifiers and match quality. It sends no weight.
-
For a Review question: your current question, up to eight recent messages from the local
thread, the selected check-in dates, and the saved evidence summary, observations,
limitations, match checks and source identity for that pair. Both
reviewTextandhealthContextare required before an expressly selected user-entered weight from that pair may be shared. Separately selected Hevy summaries requireworkoutContext. Review receives no progress photos or Apple Health samples. -
For a Training question: your current question, up to eight recent messages from the local
Training thread, the connected Hevy summary, check-in days and stated training goal. When
you expressly select your own entered weight, it also sends the weight recorded on those
days, your stored weight series and your weight goal. It never sends progress photos or an
Evidence Review.
reviewTextandworkoutContextare required;healthContextis required only when you expressly select your own entered weight. Training shares the daily Review-question allowance. -
For a Journal question: your current question, up to eight recent messages from the local
Journal thread, your recorded check-in days, the weight you entered on them, your stored
weight series and goal, and your weekly check-in target. It never sends progress photos or
an Evidence Review.
reviewTextis required;healthContextis required whenever user-entered weight is part of that recorded journal, andworkoutContextonly when you expressly include your Hevy summary. Journal questions share the daily Review-question allowance. -
For an Ask question: your current question and bounded recent Ask conversation turns.
Personal sources are off by default, so a general question attaches no personal records.
You may separately enable selected Journal dates and pose-coverage counts with
journalContext, manual or check-in weight readings from the last 180 days withhealthContext, a recorded Hevy workout summary and exercise names withworkoutContext, or saved Compare-result captions withcompareHistory. A stated goal is included only with selected Journal or Weight context. Every Ask question requiresreviewText. Ask does not share Apple Health samples, photo imagery, file paths, photo-library identifiers, free-text Journal notes or raw workout sets. -
Version 6 names a
goalVisualscope for one reduced, metadata-stripped copy of a check-in photo you select, sent to Google Gemini to draw a labelled AI goal visual. That feature is not available in this build, so no photo is sent for it.
When you change Ask sources, earlier turns using a different selection are excluded from the next request. Earlier conversations remain readable on your device but are not supplied to the new Ask conversation. Photo analysis remains a separate Compare action using the reduced, metadata-stripped temporary copies described below.
Ask may also receive selected general reference summaries from public health and research documentation. These contain no personal records. Successful answers can show links to the references supplied to the AI; those links and reference versions are saved with the answer on your device. This does not train a model on your records, upload DXA reports or estimate body-fat percentages from photographs.
PhysiqueProof does not intentionally include your email address or account user ID in the Gemini prompt. Google processes the submitted inputs and generated outputs to provide the requested feature under the Gemini API terms. Google is a separate service provider, so its handling is not covered by PhysiqueProof's temporary Supabase storage deletion described below.
An Ask or Review-question allowance is reserved before Google Gemini is contacted. A failure proven to occur before provider contact can release that reservation. Once Google Gemini has been contacted, the attempt remains consumed even if its output is rejected or delivery fails.
Hevy
Connecting Hevy is optional and requires a Hevy Pro API key. PhysiqueProof sends the key to its authenticated Supabase function, validates it with Hevy and stores only an AES-GCM encrypted copy plus connection and sync times. The key is not shown again and is never sent to Google Gemini.
During a sync, the backend fetches relevant workouts and exercise templates from Hevy,
creates bounded summaries of workout count, cardio minutes, sets and weight volume by muscle
group, returns those summaries plus the raw workouts and sets, then discards the fetched
Hevy data. The server stores no Hevy rows in hosted Postgres. The summary and the raw
workouts and sets (hevy_workouts, hevy_exercise_sets) are stored
on your device. Disconnecting Hevy clears those local tables. If you enable Hevy as a
Ask, Review, Training or Journal input, the bounded summary can be shared with Google Gemini
after the versioned disclosure.
Photos and temporary storage
Original progress photos stay on your iPhone. For a paired evidence review, the app creates reduced, metadata-stripped JPEG copies. One exact App Attest request creates the private, account-scoped earlier and later upload paths together; a partial pair is not issued. The processing service accepts only the matching unexpired pair and removes both upload prefixes after a completed or failed request. The app also requests owner-scoped cleanup when the flow is interrupted or a ticket response is lost. If cleanup cannot be verified, the review is withheld.
An upload that is not processed becomes eligible for scheduled cleanup 15 minutes after it is created. The storage object is removed by cleanup, while limited upload metadata may be retained until the signed upload token expires approximately 125 minutes after creation so a second cleanup can close the upload safely. To stop a delayed signed upload from restoring an aborted pair, a separate tombstone containing only the account owner identifier, pair identifier, abort time and expiry may remain for up to 135 minutes. Scheduled cleanup then prunes it. These tombstones contain no photo, prompt, weight value or generated response.
A paid review claim is finalised only after a strict source-bound result and verified cleanup are ready for delivery. If provider processing, response validation, cleanup or delivery finalisation prevents delivery, that feature claim is refunded exactly once. A minimal provider-attempt and cost record remains without photo content for operations and abuse prevention.
Apple Health
Apple Health access is optional and controlled in iPhone Settings. With your authorisation, PhysiqueProof can read body mass, body fat percentage, lean body mass, waist circumference and workouts for a rolling 180-day Trends-only window on this device. Those samples are never included in Ask or any online AI payload. Connecting Health does not automatically write later check-ins. The app writes body mass only when you make the separate Also save to Apple Health choice for that entry. Photos are never written to Apple Health. Withdrawal stops future reads and keeps stored rows on the device.
Authorised samples are shown with their source and date over the 180-day window and remain on device. They are not inferred from a photo. Apple Health samples never enter Review, Ask or Google Gemini. Health and fitness data is never used for advertising, marketing, ad profiling or sale to data brokers.
Service providers
PhysiqueProof uses Supabase for authentication, private temporary storage and server functions; Google Gemini for user-requested AI processing after consent; RevenueCat and Apple for purchase management; Apple's App Attest service for app-integrity checks; Hevy for user-requested workout-data access; Expo services for signed application builds; and, when configured, Slack for operational notifications, including feedback you submit. A Slack feedback notification contains the category, message and submission identifier but not your account identifier. Each provider processes only the information needed for its role under its own security and privacy terms. PhysiqueProof does not track you across other companies' apps or websites.
Retention and deletion
Local photos, check-ins, notes, user-entered external body-fat readings, evidence reviews, Recaps, full Ask and Review history, and reference links saved with Ask answers remain until you delete the account and local data, remove the app or otherwise delete the relevant local record. The online Ask and Review function does not store your prompt, recent messages or response in the PhysiqueProof server database. PhysiqueProof 1.0 has no personas, response-depth modes, free provider preview, generated future imagery or long-form report feature.
External body-fat readings are values you enter from an external method. PhysiqueProof keeps the measured calendar date, percentage, method, source/device/provider label and optional note on your device. It records rather than validates the value, does not infer it from a photo, does not import it from Apple Health, and does not send it to Review, Google Gemini or a server.
Server account, entitlement, App Attest, rate-limit, consent, feedback, encrypted Hevy credential and account-linked operational metadata remain while your account is active or as required for security, fraud prevention, legal compliance and purchase records. AI usage records contain the feature, model, token totals, estimated cost and time, not the prompt or output.
Account deletion removes the link between your account and its subscription. The free allowance key, consumed free feature and period claims and related provider-attempt reservations described above remain without your account ID or email. For paid features, a one-way hash derived from the original Apple transaction lineage, hashed transaction mappings, paid feature quota totals and conservative provider-attempt reservations also remain without your account ID or email. These minimal records are retained for security and fraud prevention so deleting an account, reinstalling, restoring, transferring or changing devices cannot reset or duplicate a free or paid allowance. They are not used for advertising, marketing or tracking.
Settings includes data export and Delete account and local data. Account
deletion attempts to revoke Sign in with Apple access when it is attached, erases email-only
or Apple Supabase accounts and related account-scoped rows, including consent, App Attest
keys, stored feedback, encrypted Hevy credentials and current subscription aliases. Local
deletion resets the app database and attempts to remove stored and draft photos,
setup/check-in drafts, cached export ZIPs and staging directories, Hevy summaries, on-device
Hevy workouts and sets (hevy_workouts, hevy_exercise_sets), Apple
Health window rows (health_body_samples, health_workouts) and the
local App Attest key pointer. If a local cleanup category cannot be removed after the
account and database are deleted, the app names it and directs you to support rather than
claiming it was cleared. Disconnecting Hevy removes the encrypted key, local summaries and
those Hevy tables without deleting the PhysiqueProof account. If Slack notifications are
enabled, a feedback message already delivered there follows the Slack workspace retention
settings; contact us to request its removal.
For an Apple-linked account, PhysiqueProof attempts revocation when its secure credential is available. Verified completion is recorded before later cleanup, so retrying a later failure does not repeat the provider call. A missing credential or temporary Apple outage does not block deletion of your PhysiqueProof account and local data; the app instead tells you to remove PhysiqueProof manually in your Apple Account settings. It does not represent that follow-up as completed revocation. Email-only accounts do not require Apple revocation. Account deletion does not cancel Apple billing and does not remove existing Apple Health weight records; manage those separately through Apple.
Your choices
You can decline Apple Health and notifications, leave Hevy disconnected or disconnect it later, choose Not now for Google Gemini processing, withdraw future AI sharing in Settings, change photo privacy controls, export your records, or delete your account and local data in Settings. Apple Health permission can also be withdrawn in iPhone Settings. For access, correction or deletion questions, email josh@kovus.dev.
Children and online AI
Online AI features are restricted to users aged 18 or older. Evidence-review observations and Review responses are general fitness information, not diagnosis, treatment or medical advice.
Changes
Material policy changes will be posted on this page with a new effective date. Contact josh@kovus.dev if you need an earlier version.