1. Scope and responsible party
This policy explains how Phoenix-Fitness (“PF”, “we”, “us”) handles personal information when you use the PF iPhone app, its supporting services, and this website. PF is operated under the Prestige Worldwide brand. For South African privacy law, PF acts as the responsible party for the processing described here.
PF is intended only for adults aged 18 or older. It is a fitness and nutrition planning tool, not a healthcare provider or medical-record service.
2. Information we process
Account and identity
- Email address, internal user identifier, authentication state, and account-security events.
- Subscription entitlement, credit balance, and Apple transaction identifiers. PF does not receive your payment-card details.
Fitness and nutrition profile
- Age, date of birth, sex-related physiological input used for calorie estimation, height, current weight, target weight, units, goal, and timeframe.
- Sport, experience, confidence, available days, session duration, training location, equipment and resistance limits, movement preferences, and recovery days.
- Injuries, symptoms, restrictions, clinician instructions, baseline activity, occupation, sleep, and steps.
- Dietary pattern, allergies, intolerances, disliked foods, meal frequency, cooking ability, budget, and regional food availability.
Activity and content
- Workout plans, exercise selections, set and session logs, notes, adherence, and personal records.
- Nutrition plans, recipes, food and meal logs, portions, calorie and protein totals, and shopping lists.
- Weight, measurements, progress entries, trends, and optional progress photos.
- AI planning requests, the profile fields approved for a request, validated proposals, warnings, approvals, and credit-ledger events.
Optional device information
If you grant permission, PF may read selected HealthKit data such as body mass, steps, and workouts, and may write a completed workout. Camera or photo-library access is used only when you choose to scan a barcode or add a progress photo. You can use manual entry without granting these permissions.
We do not ordinarily request race or ethnicity because those factors are not required for PF plan generation.
3. How information is collected
- Directly from you during sign-up, onboarding, profile editing, logging, support, and account-management actions.
- From your device only after the relevant iOS permission and PF consent control are enabled.
- From Apple for subscription and purchase status.
- Automatically from PF services when a sync command, security event, AI proposal, export, or deletion action is processed.
4. Why we use information
We process personal information only for defined product and operational purposes:
- Creating and securing your account, restoring sessions, and sending transactional or security messages.
- Saving your profile so plans reflect your goals, equipment, restrictions, preferences, and measured progress.
- Providing templates, workout execution, nutrition logging, progress tracking, offline synchronization, and data export.
- Calculating conservative calorie and protein starting ranges.
- Generating an AI proposal only when the feature is available, you are eligible, and you request it.
- Processing subscription entitlement and AI credit transactions.
- Preventing fraud, protecting users, resolving support issues, and meeting legal obligations.
No advertising use. PF does not sell personal information and does not use HealthKit, fitness, nutrition, injury, or progress information for advertising or cross-app tracking.
5. AI-assisted planning
AI is designed primarily to propose workouts and nutrition plans from the profile and requirements you provide. Free accounts do not send profile data to AI; they use editable approved seven-day templates. AI remains locked unless the relevant paid entitlement and service flag are active.
When you request an AI plan, PF minimizes the context sent to the configured provider, applies deterministic safety limits, validates the response against a structured schema, and presents assumptions, missing inputs, warnings, and a plan difference for your approval. Raw model output is never activated automatically.
HealthKit data is excluded from AI requests unless PF asks for and you give explicit consent for that planning use. Provider failures do not consume settled credits. Provider-specific retention and processing will be disclosed in-app before a live AI provider is enabled.
6. Service providers and disclosures
PF uses processors only to operate the product:
- Supabase for authentication, database, private file storage, and server functions.
- Resend for confirmation, recovery, email-change, security, and support email delivery.
- Apple for app distribution, StoreKit transactions, subscriptions, and device permission frameworks including HealthKit.
- AI providers such as OpenAI, Anthropic, or Google only when the relevant AI route is enabled and you request a proposal.
- Open Food Facts for optional barcode lookup; PF sends the barcode, not your account identity.
Providers must process data under contractual and technical controls appropriate to their role. We may disclose information if required by law, to protect rights or safety, or as part of a business reorganisation with equivalent privacy obligations. We do not permit processors to use PF health or fitness data for their own advertising.
7. Storage and international transfers
PF and its processors may store or process information outside South Africa. Where personal information crosses borders, we use contractual, organisational, and technical safeguards intended to provide protection consistent with applicable law. The live service region and provider details may change as PF scales, but the purposes and protections in this policy continue to apply.
8. Retention and deletion
Account content is kept while your account is active so PF can provide history, progress, offline sync, and plan continuity. You can edit or delete individual content in the app where available, export your account data, or delete the entire account.
Account deletion removes the Auth user, owned database rows, private progress-photo objects, AI credentials held for the account, and other user content not legally required to be retained. Limited records may be retained where required for tax, purchase, fraud-prevention, dispute, or legal compliance. Encrypted provider backups may age out on their normal restricted schedule and are not used to restore a deleted account.
Transactional email and infrastructure providers keep operational logs under their own documented retention controls. Deleting PF does not automatically cancel an Apple subscription; manage it through Apple before or after deletion.
9. Security
PF uses authenticated requests, row-level database security, private storage policies, least-privilege client keys, encrypted transport, protected device storage, account-scoped synchronization, idempotency controls, and server-held provider secrets. Optional services fail closed when their configuration is unavailable.
No system can guarantee absolute security. Use a unique password, protect your device, keep iOS current, and contact PF promptly if you suspect unauthorised access. PF will never ask you to email a password, recovery code, or AI-provider key.
10. Your choices and rights
Subject to applicable law, including South Africa’s Protection of Personal Information Act, you may ask to:
- Access information PF holds about you or export it in a portable format.
- Correct inaccurate or incomplete profile information.
- Delete information or your full account.
- Object to or restrict certain processing.
- Withdraw optional consent for HealthKit, photos, or AI profile use without affecting earlier lawful processing.
- Complain to the South African Information Regulator or another competent supervisory authority.
Device permissions can be changed in iOS Settings. PF consent controls are available in the app. Use the in-app export and account-deletion controls first for the fastest result, or contact privacy support.
11. Contact and policy changes
Privacy and information-officer contact: privacy@pf.prestige-worldwide.co.za. General support: support@pf.prestige-worldwide.co.za.
We may update this policy as PF functionality, providers, or law changes. Material changes will be dated here and, where appropriate, communicated in the app before they take effect.