Privacy policy
PhysiqueProof is designed so your original progress photos stay on your iPhone and online processing happens only when you request it.
Who operates PhysiqueProof
PhysiqueProof is operated by Josh Waller trading as Kovus in Western Australia. Privacy questions can be sent to josh@kovus.dev.
Information we handle
- Account identifiers supplied through Sign in with Apple or email-and-password sign-in, including a stable user ID and an email or private relay email. Supabase handles password verification; Kovus does not receive or store your plaintext password.
- Apple purchase history, original transaction lineage and entitlement status needed to provide PhysiqueProof Pro and prevent one subscription receiving duplicate paid allowances after restore, transfer or account deletion.
- An Apple App Attest key identifier, public key, attestation receipt and request counter linked to the signed-in account while it exists. These cryptographic records help confirm that paid server requests come from a genuine installation of PhysiqueProof.
- Progress photos you choose for an online analysis or illustrative AI projection, along with pose labels and related profile, check-in, body, weight, measurement and goal values.
- Coach questions and the recent conversation context needed to answer a question. Full Coach threads are stored locally on your iPhone.
- Feedback categories and messages you choose to send from Settings.
- Apple Health and fitness types you explicitly authorise, as described below.
- A Hevy Pro API key you choose to connect, encrypted connection metadata, and workout data fetched transiently to create bounded workout-count, cardio and muscle-group summaries. The summaries are stored in the app's local database, not the PhysiqueProof server database.
- Account-linked feature usage and rate-limit counts, plus paid-subscription quota totals, conservative provider-cost reservations, model and token totals needed to operate online features, prevent allowance resets and control costs. These records do not contain your photos, prompts, Coach responses or Health values.
Online AI consent and age requirement
Online AI features are available only to users aged 18 or older. Before your first online AI request, PhysiqueProof names Google Gemini, explains the categories of information that can be shared, asks you to confirm that you are at least 18, and offers Allow or Not now. Choosing Not now keeps online AI processing off.
If you choose Allow, the current disclosure version is stored for your account and checked again by the server before Google access. The permission applies only when you deliberately request an online AI feature. You can withdraw it at any time in Settings. Withdrawal blocks future information sharing on the device and server; it cannot undo a request that has already been processed or remove a result already saved on your device.
What is shared with Google Gemini
Depending on the feature you request, PhysiqueProof shares:
- For check-in analysis: reduced, metadata-stripped photo copies, pose labels, height, weight and relevant previous photo-derived estimates.
- For Coach: your current question, up to eight recent messages from the local thread, selected check-in estimates, weight entries and goals, and only the Health-derived values or bounded connected-fitness summaries you enable as Coach sources.
- For Progress Report: numeric before-and-after estimates, dates, weight, selected goal, muscle scores and an optional Hevy summary for the same date window. Progress Report does not send progress photos, raw workouts or your Hevy API key.
- For Goal Preview: a reduced copy of your selected photo, goal, timeframe, intensity, selected emphasis areas and projected body values. The generated image and source are also checked for age eligibility, clothing coverage, a single person and output consistency.
PhysiqueProof does not intentionally include your email address or account user ID in the Gemini prompt. Google processes the submitted inputs and generated outputs to provide the requested feature under the Gemini API terms. Google is a separate service provider, so its handling is not covered by PhysiqueProof's temporary Supabase storage deletion described below.
Hevy
Connecting Hevy is optional and requires a Hevy Pro API key. PhysiqueProof sends the key to its authenticated Supabase function, validates it with Hevy and stores only an AES-GCM encrypted copy plus connection and sync times. The key is not shown again and is never sent to Google Gemini.
During a sync, the backend fetches relevant workouts and exercise templates from Hevy, creates bounded summaries of workout count, cardio minutes, sets and weight volume by muscle group, then discards the fetched workout data. The summary is returned to and stored on your device. If you enable Hevy as a Coach source or generate a Progress Report for that date window, the bounded summary can be shared with Google Gemini after the versioned disclosure.
Photos and temporary storage
Original progress photos stay on your iPhone. For check-in analysis and Goal Preview, the app creates a reduced, metadata-stripped copy and uploads it to private, account-scoped Supabase storage. The processing service removes that copy after a completed or failed request. If photo cleanup cannot be verified, the AI result is withheld.
An upload that is not processed becomes eligible for scheduled cleanup 15 minutes after it is created. The storage object is removed by cleanup, while limited upload metadata may be retained until the signed upload token expires approximately 125 minutes after creation so a second cleanup can close the upload safely. Generated Goal Preview images are returned to and stored on your device, not in the PhysiqueProof account database.
Apple Health
Apple Health access is optional and controlled in iPhone Settings. With your authorisation, PhysiqueProof can read body mass, sleep analysis, heart-rate variability, resting heart rate, respiratory rate, sleeping wrist temperature, steps, workouts, active energy, activity summaries, dietary energy and dietary protein. PhysiqueProof writes body mass only after you explicitly save a weight entry while Health is connected. Photos are never written to Apple Health.
Authorised Health data is used to show your own recovery, activity, nutrition and progress context. It remains on device unless you separately enable Health as a Coach source and request a Coach answer after accepting the Google Gemini disclosure. The shared Coach context can include active energy, dietary energy, heart-rate variability, protein, respiratory rate, resting heart rate, sleep, steps, workout count, wrist temperature and a derived recovery score and label. Health and fitness data is never used for advertising, marketing, ad profiling or sale to data brokers.
Service providers
PhysiqueProof uses Supabase for authentication, private temporary storage and server functions; Google Gemini for user-requested AI processing after consent; RevenueCat and Apple for purchase management; Apple's App Attest service for app-integrity checks; Hevy for user-requested workout-data access; Expo services for signed application builds; and, when configured, Slack for operational notifications, including feedback you submit. A Slack feedback notification contains the category, message and submission identifier but not your account identifier. Each provider processes only the information needed for its role under its own security and privacy terms. PhysiqueProof does not track you across other companies' apps or websites.
Retention and deletion
Local photos, check-ins, generated images, reports and full Coach history remain until you delete the account and local data, remove the app or otherwise delete the relevant local record. The online Coach function does not store your prompt, recent messages or response in the PhysiqueProof server database.
Server account, entitlement, App Attest, rate-limit, consent, feedback, encrypted Hevy credential and account-linked operational metadata remain while your account is active or as required for security, fraud prevention, legal compliance and purchase records. AI usage records contain the feature, model, token totals, estimated cost and time, not the prompt or output.
Account deletion removes the link between your account and its subscription. A one-way hash derived from the original Apple transaction lineage, hashed transaction mappings, paid feature quota totals and conservative provider-attempt reservations remain without your account ID or email. This minimal record is retained for security and fraud prevention so deleting an account, reinstalling, restoring, transferring or changing devices cannot reset or duplicate the paid allowance. It is not used for advertising, marketing or tracking.
Settings includes data export and Delete account and local data. Account deletion revokes Sign in with Apple access when it is attached, erases email-only or Apple Supabase accounts and related account-scoped rows, including consent, App Attest keys, stored feedback and current subscription aliases, and clears local app data, including Hevy summaries and the encrypted Hevy credential. Disconnecting Hevy removes both without deleting the PhysiqueProof account. If Slack notifications are enabled, a feedback message already delivered there follows the Slack workspace retention settings; contact us to request its removal. Deletion still completes if Apple is temporarily unavailable.
Your choices
You can use core local tracking without an account, decline Apple Health and notifications, leave Hevy disconnected or disconnect it later, choose Not now for Google Gemini processing, withdraw future AI sharing in Settings, change photo privacy controls, export your records, or delete your account and local data in Settings. Apple Health permission can also be withdrawn in iPhone Settings. For access, correction or deletion questions, email josh@kovus.dev.
Children and wellness estimates
Online AI features are restricted to users aged 18 or older. Goal Preview also requires the user's own single-person photo. Photo-derived body values are wellness estimates, not diagnosis, treatment or medical advice.
Changes
Material policy changes will be posted on this page with a new effective date. Contact josh@kovus.dev if you need an earlier version.