Effective: September 15, 2026 · Version: 2026-09-15
This policy applies to the Phill app, required Phill account, and optional Community. The person or organization identified as Phill’s seller on the App Store is responsible for this service.
Your goals, plan, capability estimates, schedule, equipment, injuries, readiness answers, workout logs, settings, and coach context are stored in the app’s protected container on your device. Phill does not upload this record to Community. If you enable the cloud coach, the app sends a limited factual summary and recent coach conversation for each question to the hosted coach as described below. Apple may include app data in an operating-system backup according to your Apple backup settings.
When you create an account, Supabase processes your email address, unique account identifier, salted password verifier, session tokens, and legal-consent dates and versions. The password you type is sent to Supabase over HTTPS and is never written to Phill’s local files.
If you join Community, Supabase stores a generated public display name, messages, blocks, reports, moderation status, and Community-rules acceptance. Your email address is not included in the public feed. Do not include health details or personal contact information in a post.
Supabase may process an IP address, request time, response status, and basic device or user-agent information to deliver requests, enforce rate limits, investigate abuse, and maintain security logs.
Apple processes subscription purchases and payment details. Phill receives signed StoreKit product and entitlement information needed to unlock membership, restore access, and show subscription status. Phill does not receive your payment-card details.
If you grant permission, Phill schedules workout and goal reminders through Apple’s notification system. Preferences are managed on your device, and notifications are not used for third-party advertising.
Settings lets you choose the smarter cloud coach. When enabled, Phill sends your question, a limited factual training summary, and up to six recent coach messages through an authenticated Supabase function to Cloudflare Workers AI. Transport is encrypted. Phill does not store those prompts or replies on its servers, and Cloudflare states that Workers AI customer content is not used to train models or improve services without explicit consent. You can turn the cloud coach off at any time and use an on-device or built-in coach.
Data is used only to authenticate you, provide paid features, answer cloud-coach questions you submit, operate and moderate Community, protect the service, respond to support requests, comply with law, and preserve your choices. Supabase provides authentication, database hosting, Community storage, and the authenticated cloud-coach gateway. Cloudflare processes cloud-coach prompts and replies when you enable that option. Apple provides App Store billing, entitlement verification, operating-system notifications, and optional on-device model capabilities. Coach model files are downloaded from Hugging Face when you choose the local model; that download requests the model itself and carries none of your training data. Each provider’s policy governs information it processes independently.
Phill does not sell personal information, show third-party ads, or track you across other companies’ apps and websites.
Local training data remains until you use Settings → Data → Erase everything or remove the app. Deleting your Phill account does not automatically erase local training data from your device.
You can request deletion by using Settings → Account → Delete account or, if you cannot access the app, by using the private privacy-request form linked below. We may take reasonable steps to verify that you control the account before acting on a request. Deleting the account permanently removes the active Supabase authentication account and associated profile, Community messages, blocks, and reports. Phill processes deletion requests within the period required by applicable law and will not discriminate against you for exercising a privacy right.
Limited information may be retained when reasonably necessary to comply with law, prevent fraud or abuse, protect users and the service, resolve disputes, enforce agreements, or establish or defend legal claims. Residual copies may remain temporarily in provider backups and security logs until they expire under normal retention schedules; they are not returned to the active service except for disaster recovery or security purposes.
Phill does not retain cloud-coach prompts or replies on its servers. Recent coach conversation stored on your device is removed when you erase local training data or remove the app. Apple independently retains subscription and transaction records under its policies. Deleting your Phill account does not cancel an Apple subscription; cancel it separately in your Apple Account subscription settings.
Session tokens use the iOS Keychain with device-only protection. Local training files use iOS complete file protection. Network requests require HTTPS, database access is restricted by row-level and column-level permissions, and Community posting has server-side filtering and rate limits. No system can be guaranteed completely secure.
Phill accounts are not intended for children under 13. Community is limited to people 18 and older. Contact Support if you believe a child supplied account data so it can be reviewed and deleted.
You can decline notifications, avoid Community, block users, report content, erase local training history, sign out, and delete your account in the app. You may contact Support to ask about access, correction, portability, objection, restriction, or deletion rights available where you live. See Privacy Choices for instructions.
Supabase may process account and Community data outside your region under its contractual and security safeguards. Cloudflare may process cloud-coach requests outside your region when you enable that feature.
Material policy changes may require renewed acknowledgement in Phill. For non-sensitive questions, use Phill Support. For a sensitive privacy or security concern, use the private report form. Do not include passwords, payment details, authentication tokens, or medical records.