Privacy

Your data, your device.

Trophos stores the minimum needed to sync your health log across devices. No ads. No selling data. No trackers following you around the web.

What we collect

Every data class below is declared in the app itself, module by module, and you can read the same list inside Trophos under More, Privacy and data. Nothing is collected for a part of the product that has not shipped.

Account. Your email and name, held by the sign-in provider. Your profile: sex, birthday, height, pregnancy status, allergies, and any free text you write in your bio or notes. Your consent record and your API keys.

Food diary. What you log to eat and drink, the nutrition revisions behind each entry, water, fasts, favorite ingredients, saved meals, and your nutrition plan and targets.

Recipes. The recipes you build, their ingredient lists, and their images.

Gym. Sessions, exercises, sets, personal records, templates, programs, rest days, favorites, exercise notes, group sessions, and your bar, plate and equipment setup. Also the training questionnaire: injuries, restrictions and history you choose to answer. Trophos holds that questionnaire at its medical sensitivity tier.

Body metrics. Weigh-ins, body measurements, the custom measurement types you define, and your trend milestones.

Progress photos. The photos you take of your body and the notes attached to them.

Health sync. On Android, the Health Connect record types you allow, which can include sleep, activity, vitals and reproductive records. From WHOOP, sleep, recovery, body measurement and cycle records.

AI jobs. The photo and text extraction jobs run to read a label or a sentence into a food entry.

How sensitive data is ranked

Trophos sorts every table it stores into a sensitivity tier, and the tier decides how the data is handled rather than a per-feature judgment call. Tier 1 is reproductive, medical and body data: reproductive and intimacy records, the gym health questionnaire, your profile, weigh-ins, measurements, progress photos, and everything arriving through health sync. Tier 2 is behavioral: what you logged and when. Tier 3 is account plumbing: keys, links, sessions.

Reproductive and intimacy records

Menstruation, flow, cervical mucus, ovulation tests, intermenstrual bleeding, sexual activity and basal body temperature are treated as a class apart. When these records arrive through health sync, no server surface decrypts them: the check runs before the query, so the exclusion holds even for an account that has turned AI access on. They are also left out of an export unless you explicitly ask for sensitive data.

Encryption

All traffic runs over TLS. Server-side storage is encrypted at rest.

Health data synced from your phone goes further. It is sealed on the device in an encrypted envelope, bound to your account, the key generation, the record type and its timestamps, and only the ciphertext is uploaded. Trophos cannot read it unless you turn on AI access for it, which hands the server a copy of the key and is reversible. Disconnecting erases the server-side ciphertext and the key material with it.

Data you create inside Trophos is a different case, and we will not blur them. It is encrypted in transit and at rest, minimized, and kept under access control, but we hold the key. We do not claim we cannot read it, because that would be false.

Consent

Consent is recorded per purpose, and where a purpose covers more than one thing it is recorded per scope: per health provider, and per module of the app. There is no single accept-everything switch.

Grants and revokes are both entries in an append-only ledger. Nothing is overwritten, every entry carries a timestamp and the policy version in force at the time, and the app shows you that history. Terms and privacy acceptance is recorded once at signup. AI features, AI data retention and crash reports are asked during onboarding, with AI off until you turn it on.

In the app, under More, Privacy and data, each module has its own page carrying its summary, its consent switches, its export and its delete control. Each page states exactly what its switch does today rather than implying an enforcement it does not have.

What revoking does

Revoking a purpose stops the flows it gates. It does not delete data on its own, because erasure is a separate action you take deliberately. Turning off crash reports stops the reporter sending anything at all. Turning off AI access for synced health data makes it unreadable to the server again. Disconnecting a health provider erases what was synced.

Third parties

Apple and Google handle sign-in. The app stores handle billing through RevenueCat, so your payment details never reach Trophos. Resend sends transactional and waitlist email. Sentry receives crash and error reports, with personal identifiers stripped, only while crash reporting is on. Google's Gemini receives the food photos and text you send for extraction. WHOOP receives an access token to read the health data you connected.

There are no ad, attribution or retargeting SDKs in the app: no ad pixels, no cross-site trackers following you around the web. That is an architectural rule, not a setting. No product analytics tool is installed in the app at all. Your data is never sold and never shared for advertising.

This website

This marketing site is separate from the app and does not sign you in or read your health log. It loads Google Analytics to measure page traffic, and web fonts served by Google, both of which see your IP address. Joining the waitlist sends your email address to Resend. The in-page emulator is a simulation running entirely in your browser on fixed sample data; it has no account, no server and no connection to anyone's real history.

Controls

Export everything as JSON from the settings menu, section by section. Sensitive data is left out by default and included only when you ask for it. Beyond deleting your whole account, you can delete a single area on its own: gym data, diary history, body metrics, progress photos, recipes, or AI job history.

Deleting your account cascades through every table, the stored images behind your photos and recipes, and the raw records from every health provider. Purchase records held by RevenueCat as the processor of record are outside that cascade. Your history is kept until you delete it.

HIPAA

HIPAA does not apply to Trophos, and we say so plainly rather than letting the word health imply it. Trophos is not a covered entity and your log is not a medical record.

Contact

Questions or requests: privacy@trophos.ai