PhysiqueProof

Evidence Review uses disclosure and consent version 6. It sends only reduced, metadata-stripped photos from the selected comparison pair, check-in, upload and pair identifiers, and match quality. It sends no weight.

A later Review question requires both reviewText and healthContext before it may share an expressly selected user-entered weight from the selected pair. It sends no photos or Apple Health sample.

Effective 6 September 2026

Privacy policy

PhysiqueProof is designed so your original progress photos stay on your iPhone and online processing happens only when you request it.

Who operates PhysiqueProof

PhysiqueProof is operated by Josh Waller trading as Kovus in Western Australia. Privacy questions can be sent to josh@kovus.dev.

Information we handle

Online AI consent and age requirement

Online AI features are available only to users aged 18 or older. Before your first online AI request, PhysiqueProof names Google Gemini, explains the categories of information that can be shared, asks you to confirm that you are at least 18, and offers Allow or Not now. Choosing Not now keeps online AI processing off.

If you choose Allow, disclosure version 6 stores only the exact scopes you accepted: photoEvidence for reduced paired-review photos, reviewText for an Ask, Review, Training or Journal question, journalContext for selected Journal dates, check-in cadence and pose-coverage counts in an Ask question (never photos, file paths or record identifiers), healthContext for user-entered weight shared with one of those questions, workoutContext for an expressly selected Hevy summary, compareHistory for the captions of your own Compare results (dates, area, outcome and limitations) in an Ask question (never the photos), and goalVisual for a labelled AI goal visual from one selected check-in photo. The goal-visual feature is not available in this build, so no photo is sent for it. Each scope is off by default and one scope never authorises another.

Version 6 still states that the same reduced, temporary photo copies made for an evidence review may be read for a visual body-composition indication shown beside that check-in. That indication is not available in this build, so those copies are not read for it. Where it is available it describes how the photos look rather than what your body is. It is not a percentage, a measurement or a health conclusion, and PhysiqueProof does not use photos to provide body measurements or appearance grades. It is covered by photoEvidence and by nothing else.

Version 4 and version 5 permission no longer authorises any online AI feature. Version 3 permission is legacy-only: it still covers a request sent in the earlier v1 or r1 format by an app version you have not updated yet, and can never authorise the post-1.0 v2/r2 contract. Build 36 uses version 6 even though its generic request remains v1/r1. When the disclosure changes, you are asked again before anything is shared.

The server checks every required current-version scope before Google access. Permission applies only when you deliberately request an online AI feature. You can withdraw every scope at any time in Settings. Withdrawal blocks future information sharing on the device and server; it cannot undo a request that has already been processed or remove a result already saved on your device.

What is shared with Google Gemini

Depending on the feature you request, PhysiqueProof shares:

When you change Ask sources, earlier turns using a different selection are excluded from the next request. Earlier conversations remain readable on your device but are not supplied to the new Ask conversation. Photo analysis remains a separate Compare action using the reduced, metadata-stripped temporary copies described below.

Ask may also receive selected general reference summaries from public health and research documentation. These contain no personal records. Successful answers can show links to the references supplied to the AI; those links and reference versions are saved with the answer on your device. This does not train a model on your records, upload DXA reports or estimate body-fat percentages from photographs.

PhysiqueProof does not intentionally include your email address or account user ID in the Gemini prompt. Google processes the submitted inputs and generated outputs to provide the requested feature under the Gemini API terms. Google is a separate service provider, so its handling is not covered by PhysiqueProof's temporary Supabase storage deletion described below.

An Ask or Review-question allowance is reserved before Google Gemini is contacted. A failure proven to occur before provider contact can release that reservation. Once Google Gemini has been contacted, the attempt remains consumed even if its output is rejected or delivery fails.

Hevy

Connecting Hevy is optional and requires a Hevy Pro API key. PhysiqueProof sends the key to its authenticated Supabase function, validates it with Hevy and stores only an AES-GCM encrypted copy plus connection and sync times. The key is not shown again and is never sent to Google Gemini.

During a sync, the backend fetches relevant workouts and exercise templates from Hevy, creates bounded summaries of workout count, cardio minutes, sets and weight volume by muscle group, returns those summaries plus the raw workouts and sets, then discards the fetched Hevy data. The server stores no Hevy rows in hosted Postgres. The summary and the raw workouts and sets (hevy_workouts, hevy_exercise_sets) are stored on your device. Disconnecting Hevy clears those local tables. If you enable Hevy as a Ask, Review, Training or Journal input, the bounded summary can be shared with Google Gemini after the versioned disclosure.

Photos and temporary storage

Original progress photos stay on your iPhone. For a paired evidence review, the app creates reduced, metadata-stripped JPEG copies. One exact App Attest request creates the private, account-scoped earlier and later upload paths together; a partial pair is not issued. The processing service accepts only the matching unexpired pair and removes both upload prefixes after a completed or failed request. The app also requests owner-scoped cleanup when the flow is interrupted or a ticket response is lost. If cleanup cannot be verified, the review is withheld.

An upload that is not processed becomes eligible for scheduled cleanup 15 minutes after it is created. The storage object is removed by cleanup, while limited upload metadata may be retained until the signed upload token expires approximately 125 minutes after creation so a second cleanup can close the upload safely. To stop a delayed signed upload from restoring an aborted pair, a separate tombstone containing only the account owner identifier, pair identifier, abort time and expiry may remain for up to 135 minutes. Scheduled cleanup then prunes it. These tombstones contain no photo, prompt, weight value or generated response.

A paid review claim is finalised only after a strict source-bound result and verified cleanup are ready for delivery. If provider processing, response validation, cleanup or delivery finalisation prevents delivery, that feature claim is refunded exactly once. A minimal provider-attempt and cost record remains without photo content for operations and abuse prevention.

Apple Health

Apple Health access is optional and controlled in iPhone Settings. With your authorisation, PhysiqueProof can read body mass, body fat percentage, lean body mass, waist circumference and workouts for a rolling 180-day Trends-only window on this device. Those samples are never included in Ask or any online AI payload. Connecting Health does not automatically write later check-ins. The app writes body mass only when you make the separate Also save to Apple Health choice for that entry. Photos are never written to Apple Health. Withdrawal stops future reads and keeps stored rows on the device.

Authorised samples are shown with their source and date over the 180-day window and remain on device. They are not inferred from a photo. Apple Health samples never enter Review, Ask or Google Gemini. Health and fitness data is never used for advertising, marketing, ad profiling or sale to data brokers.

Service providers

PhysiqueProof uses Supabase for authentication, private temporary storage and server functions; Google Gemini for user-requested AI processing after consent; RevenueCat and Apple for purchase management; Apple's App Attest service for app-integrity checks; Hevy for user-requested workout-data access; Expo services for signed application builds; and, when configured, Slack for operational notifications, including feedback you submit. A Slack feedback notification contains the category, message and submission identifier but not your account identifier. Each provider processes only the information needed for its role under its own security and privacy terms. PhysiqueProof does not track you across other companies' apps or websites.

Retention and deletion

Local photos, check-ins, notes, user-entered external body-fat readings, evidence reviews, Recaps, full Ask and Review history, and reference links saved with Ask answers remain until you delete the account and local data, remove the app or otherwise delete the relevant local record. The online Ask and Review function does not store your prompt, recent messages or response in the PhysiqueProof server database. PhysiqueProof 1.0 has no personas, response-depth modes, free provider preview, generated future imagery or long-form report feature.

External body-fat readings are values you enter from an external method. PhysiqueProof keeps the measured calendar date, percentage, method, source/device/provider label and optional note on your device. It records rather than validates the value, does not infer it from a photo, does not import it from Apple Health, and does not send it to Review, Google Gemini or a server.

Server account, entitlement, App Attest, rate-limit, consent, feedback, encrypted Hevy credential and account-linked operational metadata remain while your account is active or as required for security, fraud prevention, legal compliance and purchase records. AI usage records contain the feature, model, token totals, estimated cost and time, not the prompt or output.

Account deletion removes the link between your account and its subscription. The free allowance key, consumed free feature and period claims and related provider-attempt reservations described above remain without your account ID or email. For paid features, a one-way hash derived from the original Apple transaction lineage, hashed transaction mappings, paid feature quota totals and conservative provider-attempt reservations also remain without your account ID or email. These minimal records are retained for security and fraud prevention so deleting an account, reinstalling, restoring, transferring or changing devices cannot reset or duplicate a free or paid allowance. They are not used for advertising, marketing or tracking.

Settings includes data export and Delete account and local data. Account deletion attempts to revoke Sign in with Apple access when it is attached, erases email-only or Apple Supabase accounts and related account-scoped rows, including consent, App Attest keys, stored feedback, encrypted Hevy credentials and current subscription aliases. Local deletion resets the app database and attempts to remove stored and draft photos, setup/check-in drafts, cached export ZIPs and staging directories, Hevy summaries, on-device Hevy workouts and sets (hevy_workouts, hevy_exercise_sets), Apple Health window rows (health_body_samples, health_workouts) and the local App Attest key pointer. If a local cleanup category cannot be removed after the account and database are deleted, the app names it and directs you to support rather than claiming it was cleared. Disconnecting Hevy removes the encrypted key, local summaries and those Hevy tables without deleting the PhysiqueProof account. If Slack notifications are enabled, a feedback message already delivered there follows the Slack workspace retention settings; contact us to request its removal.

For an Apple-linked account, PhysiqueProof attempts revocation when its secure credential is available. Verified completion is recorded before later cleanup, so retrying a later failure does not repeat the provider call. A missing credential or temporary Apple outage does not block deletion of your PhysiqueProof account and local data; the app instead tells you to remove PhysiqueProof manually in your Apple Account settings. It does not represent that follow-up as completed revocation. Email-only accounts do not require Apple revocation. Account deletion does not cancel Apple billing and does not remove existing Apple Health weight records; manage those separately through Apple.

Your choices

You can decline Apple Health and notifications, leave Hevy disconnected or disconnect it later, choose Not now for Google Gemini processing, withdraw future AI sharing in Settings, change photo privacy controls, export your records, or delete your account and local data in Settings. Apple Health permission can also be withdrawn in iPhone Settings. For access, correction or deletion questions, email josh@kovus.dev.

Children and online AI

Online AI features are restricted to users aged 18 or older. Evidence-review observations and Review responses are general fitness information, not diagnosis, treatment or medical advice.

Changes

Material policy changes will be posted on this page with a new effective date. Contact josh@kovus.dev if you need an earlier version.