Fysiqal

Privacy Policy

Effective July 24, 2026

Draft, not yet reviewed by counsel. This describes what Fysiqal actually does today, as accurately as we can state it — but it has not yet been reviewed by a lawyer, and Fysiqal is still pre-launch. Don't treat this as a final, binding legal document; it will be replaced with a reviewed version before general availability.

This Privacy Policy explains what information Fysiqal collects, how we use it, and who we share it with. It's written to describe what the product actually does, not generic boilerplate — if a section below doesn't match what you see in the app, tell us at support@fysiqal.com.

1. Information you provide

  • Account info: name and email, used for sign-in and communication. Passwords are handled by our authentication provider (Supabase Auth) — we never see or store your password in plain text.
  • Training profile: your primary goal, training days per week, session duration, equipment access, experience level, and (optional) age, weight, height, sex, and activity level — used to generate your program and nutrition targets. Sex and activity level are optional specifically because they're only used to sharpen calorie/macro estimates (Mifflin-St-Jeor); Fysiqal works without them.
  • Injury restrictions: anything you note is used to steer program generation away from contraindicated movements. This is self-reported information, not a medical record, and is treated as sensitive — it's never shared with anyone besides a coach you've actively subscribed to.
  • Workout logs: exercises, sets, reps, weight, and RPE you log, plus recovery check-ins (sleep, soreness, energy).
  • Progress photos: if you choose to upload them, they're stored in a private Supabase Storage bucket, readable only by your account, and only ever served back to you via short-lived signed URLs — there is no public URL for any progress photo, ever.
  • Form-check video frames: when you use Form Analysis, frames are extracted from your video in your browser and sent to our AI vision provider for one-time analysis. The frames themselves are not stored by Fysiqal after analysis — only the resulting technique feedback is saved to your account.
  • Meal photos: similarly processed by our AI vision provider to recognize food items and estimate portions; the photo itself isn't stored — only the nutrition log entry you confirm.
  • Payment information: handled entirely by Stripe. Fysiqal never receives or stores your full card number — only a Stripe customer/subscription reference.
  • Coach messages: if you subscribe to a coach, messages between you are stored so both sides can see the conversation history; they're visible only to the two of you.

2. Information we collect automatically

If Fysiqal has a Google Analytics 4 property configured (it may not, depending on the deployment), we collect standard, aggregated site-usage analytics — pages visited and button clicks on our public marketing pages — to understand what's working. This is never tied to your training data, and is disabled entirely (no script loads at all) if no GA4 property is configured.

3. How we use your information

  • To generate and adapt your training program, nutrition targets, and recovery guidance.
  • To power Form Analysis, the AI Coach, and meal-photo recognition via our AI provider.
  • To connect you with a coach you've chosen, and give that coach visibility into your real training history once you've subscribed to them (not before).
  • To process payments and manage your subscription.
  • To respond to support requests and, if you've opted in, send product updates.

We do not sell your personal or health data to third parties, ever.

4. Who we share information with

Fysiqal is built on top of a small number of infrastructure providers, each with a specific, limited role:

  • Supabase — our database, authentication, and file-storage provider. Your account, training data, and any uploaded photos are stored in Supabase's infrastructure, protected by row-level security policies that scope every table to your own user ID.
  • Google (Gemini API) — processes form-check video frames and meal photos to generate the AI feedback described above. Frames/photos are sent for processing and are not retained by Fysiqal afterward.
  • Stripe — processes all payments and manages coach payouts. Stripe's own privacy policy governs the payment data it holds directly.
  • Google Analytics (only if configured) — aggregated, anonymized marketing-site analytics, never authenticated user data.
  • Your coach — only if you've actively subscribed to them, and only the training data relevant to coaching you (sessions, programs, check-ins) — never your payment details.

We don't share your data with advertisers or data brokers.

5. Data retention and deletion

We retain your data for as long as your account is active, so your program and progress history stay intact. Settings → Trust & Privacy has a real self-serve "Download my data" export (a JSON file covering every table we store your data in) and a real "Request account deletion" flow — requesting deletion starts a 14-day grace period (cancellable at any time from that same page) before your account and all associated data are permanently deleted. You can also reach support@fysiqal.com for either request, or with any questions about what a specific export contains.

6. Security

Data is encrypted in transit (HTTPS) and at rest (Supabase's infrastructure defaults). Every database table has row-level security enabled — most scope access to your own account; a few (like coach and product reviews, or your public Community activity if you've opted into it) are visible by design, the same way they'd be visible in the app itself. Uploaded files (progress photos) live in a private storage bucket with no public path — access is only ever granted via short-lived signed URLs generated for you, the owner.

7. Children's privacy

Fysiqal is not directed at, and we don't knowingly collect data from, anyone under 16.

8. Changes to this policy

We'll update the effective date above whenever this policy changes, and we'll aim to describe real product behavior at the time — not a generic template.

9. Contact

Questions, data-export requests, or deletion requests: support@fysiqal.com.