DRAFT 2.0 (beta), written 10 October 2026. Not yet reviewed by a lawyer. Do not publish until a qualified lawyer has approved it.
Builds on draft 1.2 (8 Oct 2026). Square-bracket notes are for Niranjan and the lawyer:[DECISION]= a product choice,[VERIFY]= a fact to check,[PLACEHOLDER]= missing detail,[LEGAL REVIEW]= a question for the lawyer. Remove every note, and this box, only after approval. Legal sources and open questions:legal/LAW-CHECK.md.
Effective date: [PLACEHOLDER: date of publication]
Version: 2.0 (beta)
Web address: /app-privacy
This policy has two parts:
- Part A applies to everyone, in every country. It is written to the standard of the United Arab Emirates Personal Data Protection Law, our home law, and we apply the stricter rules of other countries' laws to everyone where we can (for example, we treat health information as sensitive and ask for your consent everywhere).
- Part B adds what the law in your country or region requires on top of Part A. If Part B and Part A differ, Part B wins for people in that place.
Part A: for everyone
A1. Who we are
MiPhy ("Mind & Physique") is a fitness, food, habits and mindfulness app. It is run by Mind and Physique Lifestyle Coaching, a company registered in Dubai, United Arab Emirates ("MiPhy", "we", "us").
- Address: [PLACEHOLDER: registered address]
- Trade licence: [PLACEHOLDER: licence number and issuing authority, e.g. Dubai Department of Economy and Tourism]
- Email for privacy questions and requests: support@miphyfitness.com
We decide why and how your personal data is used, so we are the controller of your data (called the "data fiduciary" in India). Where a law asks for a named privacy contact, data protection officer or grievance officer, that is our founder, Niranjan [VERIFY: full legal name], at the same email address (Part B lists any local representatives).
[LEGAL REVIEW: confirm the company is licensed on the Dubai mainland and not in DIFC or ADGM (those free zones have their own data protection laws that would replace the UAE PDPL as home law). Confirm whether a formal Data Protection Officer must be appointed under PDPL Article 10 because we process health data.]
A2. What MiPhy is, and is not
MiPhy gives general fitness, nutrition and wellbeing guidance. It is not a medical device and is not a healthcare provider. It does not diagnose, treat, cure or prevent any illness. The AI coach is an AI, not a doctor, therapist or person. Talk to a doctor before making medical decisions. Full details are in our Terms of Use.
A3. The short version
- MiPhy is for adults aged 18 or over.
- During the beta, MiPhy is free, it is invite-only (you need a beta code), and every feature is on for everyone.
- We collect what you type, log, photograph, film or say to the app, so the app can work for you. Much of it is health information, and we treat it as sensitive in every country.
- The AI coach, AI plan builder and check-in suggestions send some of your information to an AI service provider. They only run if you turn on AI help, and you can turn it off at any time. The AI never changes your plan by itself.
- Posture photos and form videos are private. They are not sent to the AI, not analysed, and not shown to anyone else.
- There is no human coach in the beta. During the beta, authorised members of the MiPhy team can look at your account in a private, view-only admin screen (your setup answers, logs, progress, measurements, stats and AI chats, but never your photos or videos) to check how the app and the AI are working for you and to improve them. Every look is recorded (section A9).
- We do not sell your data, do not share it for advertising, show no ads, use no analytics or advertising trackers, and do not use your data to train AI models.
- Your data is stored in Mumbai, India. Some service providers are in the USA (section A11).
- You can see, correct, download and delete your data. You can delete your account inside the app at any time.
A4. What we collect
A4.1 Account and sign-in
| What | Details |
|---|---|
| Email address | Used to create your account, sign in and reset your password. When you create an account we email you a 6-digit code once to confirm the address. |
| Password | If you sign in with email. It is stored only as a one-way scrambled value (a "hash") by our sign-in provider. Nobody at MiPhy can see it. |
| Google sign-in | If you choose "Continue with Google", Google tells us your email address, your name and your Google profile picture link, and that Google confirmed your email. We never see your Google password. |
| Account ID | An internal number created when you sign up. |
| Name and profile photo | Your first name (required), last name (optional), and a profile photo if you add one. |
| Settings | Language (English or Hindi), appearance, units, time zone (read from your phone so "today" starts at your local midnight). |
| Beta access | The beta code you entered, when you used it, and whether your access is active or stopped. |
| Plan | During the beta every account has every feature. We keep the plan field (Free or Progress) for after the beta. The app never receives payment details. |
| Consent records | Each consent choice you make (section A8), with the date and the version of the wording you saw. We keep the history, not just your latest answer. |
| Safety note | The date you ticked "I've read this and I'm ready to start", and the version you saw. |
| Sign-in records | Date of sign-up and of your last sign-in. |
| Approximate location | The city and country we work out from your internet connection's IP address when you sign in. We keep only the city and country, never the IP address itself and never your precise (GPS) location. The app never asks for location permission. [VERIFY: which service does the IP-to-city lookup, and whether it keeps the IP; added 10 Oct for the admin Users list.] |
A4.2 Setup questions
After you agree to the health-information consent, setup asks short questions. Answers are saved step by step so you can stop and continue later.
| What | Required or optional |
|---|---|
| Name | First name required |
| Gender (male / female / other) | Required. It also decides which body measurements the app suggests. |
| Main goal, age (18+), height, weight, activity level | Required. BMI is shown on screen, not saved. |
| Body type and estimated body-fat range (your own description) | Optional |
| Areas of pain or discomfort, or "no pain" | Optional |
| Health conditions you choose to tell us about, with an optional note | Optional |
| When you last had a blood test | Optional. We never ask for the report itself. |
| Diet type, halal preference, food allergies | Optional [DECISION: the halal question can reveal religious belief, which is sensitive data in most laws. Keep and treat as sensitive, reword as a plain food preference, or remove.] |
| Where and how often you train, experience, equipment | Required |
| What you want help with (e.g. sleep, stress, focus, nerves before training) | Optional |
| Starter habits | Optional |
[VERIFY: match this table to the final setup questions; Niranjan plans to redesign them.]
A4.3 What you log
- Food: meals with date, time, meal slot, foods, amounts, estimated calories, protein, carbohydrate and fat, notes, foods you add yourself, and meals you save to My meal library.
- Water, steps and activity, and your own daily water and steps goals.
- Habits and each day's status (done, tiny version, paused).
- Workouts: sessions, sets, weights, reps, time, exercises added or swapped, an optional "discomfort" flag, effort rating (RPE), notes, and your saved routines. The app works out personal bests and volume from these.
- Targets: your calorie and protein targets and the numbers the estimate used.
- Body stats: weight, and if you choose, body-fat % and muscle mass with the method used.
- Body measurements you enter.
- Mindfulness sessions: technique, length, whether you finished, how you felt before and after, and what prompted it.
- "Make today fit your day": your mood, sleep, available time, energy and main barrier for that day, and the change you applied.
- Weekly check-ins: how the week went; energy, sleep, hunger and plan difficulty; optionally a win and a barrier in your words, your weight, and your menstrual-cycle status (period this week / expected soon / not relevant).
- "Coming to MiPhy" votes: which future features you said you want.
A4.4 AI features (only when AI help is on)
- AI coach chat: the messages you type or dictate, and the AI's replies. During the beta each person can send up to 100 messages a month.
- AI plan builder: a workout plan made from your setup answers and our training rules, with a short "Why this plan?". You accept or decline it.
- Check-in suggestions: after a check-in the AI may propose plan changes. Nothing changes unless you tap Accept.
- Safety flags: if our safety rules or the AI flag a chat message (for example sharp pain, chest pain, pregnancy, very low eating, a medical question, or thoughts of self-harm), we store the flag type and time with the message.
- AI usage record: for each AI request, the feature, AI model, amount of text processed, cost and whether it worked. It never contains your messages. If you delete a chat, we keep only the time of each AI reply for up to about 2 months so the monthly message limit still works. [VERIFY: exact period in the server functions]
A4.5 Photos and videos
- Posture photos: up to 4 photos per set (front, side, side with arms lifted, back), with the date and view. The camera opens only after you tap Start.
- Form videos: short exercise clips you record or upload, with the exercise and linked workout. Clips are compressed before upload. A clip you choose from your gallery is uploaded as it is, so it may still contain sound or other details your phone stored in it. [VERIFY: whether in-app recordings include sound; whether gallery uploads keep location data.]
- Profile photo, if you add one.
- All are kept in private storage, shown to you only through links that expire, not sent to the AI, not analysed, and not shown to anyone else. We do not create face or body templates from them. If we ever add AI video analysis, we will ask for your separate consent first.
- If you choose "save to my phone", a copy goes to your phone's gallery, which you control.
A4.6 Voice
"Talk to log", "Describe a meal" and the microphone in the AI chat use your phone's or browser's built-in speech recognition (Apple on iPhone; usually Google on Android; your browser on the web). Depending on your device, your voice may be sent to Apple or Google under their own privacy terms. MiPhy never receives or stores your voice. The microphone runs only after you tap it. You see and can edit the text before anything is saved or sent. Turning text into log entries happens inside the app, not with AI. Spoken breathing guides and "read aloud" use your phone's own text-to-speech.
A4.7 Stored only on your phone
Language, theme, reminder choices, voice-guide settings, camera timer, the state of a workout in progress, and your sign-in session. Reminders are scheduled on your phone; nothing about them is sent to us. [VERIFY: the beta build registers no push tokens.]
A4.8 Technical information
Our database host and web host keep standard server logs (for example IP address, time, device or browser type) for security and troubleshooting, for a short time (section A12). We do not use them to track you. The only location we keep is the approximate city and country from sign-in (section A4.1).
A4.9 Support and website enquiries
If you email us, we keep the email and our reply. If you contact us through our website, we may keep your name, email or phone number, your goal, how you heard of us, and our notes, so we can reply. Website enquiries are not linked to what you log in the app.
A4.10 What we do not collect
No precise (GPS) location and no location permission (only the approximate city and country in section A4.1), no contacts, calendar, advertising ID, payment card details, heart rate, or Apple Health / Google Health Connect data. No analytics, advertising or crash-reporting tools in the app. No cookies for tracking or advertising; the web version stores only what it needs to work (section A4.7).
A4.11 The MiPhy food database
The food list is the same for everyone and holds no personal data. Values come from published food tables (Indian Food Composition Tables 2017, USDA FoodData Central, UK CoFID 2021, Indian Nutrient Databank 2024) and MiPhy recipe estimates; estimated foods are marked Estimate. Your searches are not stored. [VERIFY: list only sources in the live database; IFCT 2017 reuse terms.]
A5. Health information and other sensitive data
Most of what you give MiPhy is health information or can reveal it: pain areas, health conditions, blood-test date, body stats and measurements, posture photos, food and allergies, menstrual status, mood, sleep, and anything you tell the AI coach. Many laws treat this as sensitive (for example "sensitive personal data" in the UAE and Saudi Arabia, "special category data" in the EU and UK, "consumer health data" in some US states).
So, everywhere, we:
- collect it only after you give the health-information consent (section A8), and ask for extra consent before it is sent to the AI provider;
- use it only to run the app for you, never for ads, never sold, never used to train AI;
- keep it in private, access-controlled storage, encrypted in transit and at rest;
- show it to no one at MiPhy except authorised team members, only for the beta review and other tasks described in section A9;
- delete it when you delete your account.
We do not want official medical records. Please do not upload lab reports or medical documents or type ID numbers into the chat.
A6. How the AI features use your data
What we send (only when AI help is on, and only what each request needs):
- AI chat: your message, earlier messages in the chat, and a short summary of your profile, plan and recent logs (for example goal, experience, equipment, pain areas, health conditions you told us about, recent workouts, food and step totals, recent check-ins), so the reply fits you.
- Plan builder: your setup answers and our training rules.
- Check-in suggestions: your check-in answers, current plan and recent workout logs.
What we never send: your email address, password, last name, profile photo, posture photos, videos or voice. [DECISION: send your first name so the coach can greet you, or no name at all. Recommended: first name only.]
How: requests go from our server (never from your phone) to [DECISION: AI provider, chosen in task 7], which works for us as a service provider under a written contract. We use settings under which the provider does not use your data to train its models. The provider may keep requests for a short time for abuse and security checks: [VERIFY: provider retention period, region and zero-retention option].
Our own checks: our code, not the AI, decides safety. If your answers or a message suggest you should see a professional first, the app shows a rules-based safety card. AI output is checked against our rules before you see it.
Limits: AI answers are labelled AI, can be wrong, and are not medical advice. The AI cannot change your plan, targets or logs by itself.
If you turn AI help off: nothing new goes to the AI provider, and the AI chat, plan builder and check-in suggestions stop. [DECISION: what a user gets instead, e.g. a rules-based plan.] Your earlier chat stays until you delete it.
No automated decisions with legal effects. MiPhy does not make decisions about you that have legal or similarly important effects (such as credit, insurance, employment or access to healthcare). The AI only suggests; you decide.
A7. Why we use your data, and our legal grounds
| Why | Data | Legal ground |
|---|---|---|
| Create your account, sign you in, keep it secure, check your beta code, and see roughly where beta testers are | Account and sign-in data, approximate city and country, beta code, technical logs | Needed to provide the app you asked for (contract); our legitimate interest in security |
| Run the app: store and show your logs, targets, stats, plans and progress | Setup answers, logs, photos, videos, check-ins | Your explicit consent (health information), and the contract |
| AI chat, plan builder, check-in suggestions | Section A6 | Your separate explicit consent (AI help) |
| Beta review: authorised MiPhy team members look at individual accounts to check that plans, targets, safety cards and AI replies are right, and to improve the app and the AI | Setup answers, logs, progress, measurements, stats, check-ins, AI chats (not photos or videos) | Your explicit consent (health information, which names this purpose) |
| Safety cards and checking safety-flagged chats | Flag type, time, the flagged message | Your consent; our legitimate interest and, where it applies, protecting your vital interests |
| Control AI costs and the monthly message limit | AI usage record | Legitimate interest; contract |
| Reply to support and website enquiries | Your messages and contact details | Legitimate interest; contract; consent where required |
| Keep consent and deletion records, meet legal duties, handle legal claims | Consent history, request records | Legal obligation; legitimate interest |
| Tell you about important changes to the app or this policy | Email, in-app notices | Contract; legal obligation |
We do not use your data for advertising, profiling for marketing, selling, or training AI. We will not send you marketing emails unless you separately agree. [LEGAL REVIEW: Part B notes where a law does not recognise "legitimate interest" (e.g. India, where consent or a listed "legitimate use" is needed).]
A8. Your consents
| Consent | What it allows | Required? |
|---|---|---|
| Health information | Storing your answers about health, body and food, your logs, body stats, measurements, check-ins and mindfulness sessions so the app can work, in our database in India (section A11), and letting authorised MiPhy team members review them and your AI chats during the beta to check and improve the app and the AI (section A9). | Required to use the app, because the app cannot work without it. |
| AI help | Sending the information in section A6 to our AI provider, which may be in another country. | Optional. On or off any time in Profile → Privacy. |
| Photos and videos | Taking and storing posture photos and form videos in private storage. | Optional. On or off any time in Profile → Privacy. |
Withdrawing consent: switch AI help or Photos and videos off in Profile → Privacy, or email us. Nothing new is sent or stored from then on. To remove what was already saved, delete the chat, the photos or videos, or your account. Withdrawing the health-information consent means we can no longer provide the app, so we will delete your account if you ask. Withdrawal does not make earlier processing unlawful.
[LEGAL REVIEW: whether making the health-information consent a condition of use is valid in every region (GDPR Art. 7(4) "freely given"; India DPDP s.6 "necessary for the specified purpose"). The argument: the data is the service itself.]
A9. Who can see your data
- You. Other MiPhy users cannot see anything you log. Nothing is posted publicly.
- No human coach in the beta.
- The MiPhy admin dashboard (authorised MiPhy team members only, protected by a second sign-in step) shows: beta codes; a user list with name, email, approximate city and country, beta access, sign-up and last sign-in dates, and how many AI messages you sent this month; AI cost totals; and safety flags (flag type, rules or AI, time, person).
- Beta review of your account. During the beta, authorised members of the MiPhy team can open a view-only page for any account. It shows your setup answers, food and other logs, workouts, progress, body stats, measurements, statistics, check-ins and AI coach chats, so we can see how the app and the AI responded to you and make them better. It never shows posture photos, form videos or your profile photo [VERIFY with the admin build], and nothing can be changed from it. Every time an account is opened, we record who opened it, which account and when. Access is limited to the few people who need it to run the beta, and what we see is never shared, sold or used for advertising. You can ask us for the list of times your account was viewed. This review is part of the health-information consent you give at sign-up (section A8). [DECISION: keep this after the beta, or switch it off when the beta ends.]
- Database administration: our database administrator can technically reach the database and private storage. We do so only for the beta review above, support you ask for, security, fixing faults, or a legal duty, and never look at your photos or videos unless you ask us to. Every such access is limited to what the task needs.
- Service providers (section A10), only to run MiPhy for us.
- Authorities, only when the law requires it, for example a valid court order. Where allowed, we will tell you first.
- A buyer or successor, if MiPhy is ever sold or merged; they must keep this policy's promises, and we will tell you first.
We do not share your data with advertisers, data brokers, insurers or employers.
A10. Service providers
| Provider | What they do | Data they handle | Where |
|---|---|---|---|
| Supabase Inc. | Database, sign-in, private file storage, server functions | Everything stored in your account | Mumbai, India (AWS ap-south-1) |
| [DECISION: AI provider] | AI replies, plans and check-in suggestions, only when AI help is on | Section A6 only | [VERIFY: region; likely USA] |
| Resend Inc. | Sends sign-in and password-reset codes | Your email address and the code email | USA |
| Google LLC (Google sign-in) | Lets you sign in with Google, if you choose | Your Google email, name and profile picture link | USA / global |
| Cloudflare Inc. (Cloudflare Pages) | Serves the web version of the app | Standard request logs (IP address, time) | Global network |
| Google LLC (Google Workspace) | Our support email | Emails you send us | [VERIFY: data region] |
| Apple or Google speech services (only if you use voice) | Speech to text on your device | Your voice while the mic is on | Under their own terms; not controlled by MiPhy |
Each provider handles data only on our instructions, under a data processing agreement, and must protect it at least as well as this policy does. [LEGAL REVIEW: sign or accept the DPAs of Supabase, Resend, Cloudflare and the AI provider, including standard contractual clauses for transfers.]
A11. Where your data goes (international transfers)
- Main storage: Mumbai, India. Account data, logs, photos and videos.
- USA: sign-in emails (Resend), Google sign-in, and very likely the AI provider.
- Worldwide: the web host's network serves the web app from the location nearest you.
- UAE: our own encrypted weekly backup copies, kept by MiPhy. [DECISION: confirm FileVault is on and how many weeks are kept.]
So your data will usually be processed outside the country where you live. Where the law of your country requires it, we protect these transfers with the safeguards it recognises, such as standard contractual clauses, your explicit consent, or an adequacy decision (Part B lists them by region). You can ask us for a copy of the safeguards we use.
A12. How long we keep your data
| Data | How long |
|---|---|
| Account, setup answers, logs, routines, targets, body stats, measurements, mindfulness, check-ins, AI plans | While your account exists. Deleted when you delete your account. You can delete most single entries yourself. |
| AI chat messages | Until you delete the chat or your account. Only reply times are kept for up to about 2 months after a chat is deleted, for the monthly limit. |
| Posture photos, form videos, profile photo | Until you delete them or your account. |
| Copies held by the AI provider | Up to [VERIFY] days under its terms. |
| Consent history | While your account exists, then [DECISION: e.g. kept without the content for up to 3 years as proof of consent, where the law needs it]. |
| AI usage record | Kept for cost records, unlinked from you when you delete your account. Never contains your messages. |
| Beta codes | The code and date stay in our records, unlinked from you when you delete your account. |
| Inactive accounts | [DECISION: e.g. we email you after 2 years without sign-in and delete the account 30 days later if you don't reply. Some laws, such as India's rules for large platforms, expect a limit.] |
| Approximate city and country | Updated at each sign-in; deleted with your account. |
| Server logs | Up to 7 days [VERIFY: Supabase plan]. |
| Database provider backups | Up to 7 days, then overwritten [VERIFY]. |
| Our own weekly backups | [DECISION: e.g. last 12 weeks]. |
| Sign-in emails at Resend | Up to 30 days. |
| Support emails and website enquiries | [DECISION: e.g. 12 months after the last message]. |
| Record of beta-review views (who opened which account, when) | [DECISION: e.g. 2 years]; deleted or unlinked when you delete your account. |
| Records of privacy requests (what was asked and when we answered) | [DECISION: e.g. 3 years], to show we met the law. |
A13. Deleting your account
In the app: tap your photo (top right) → Profile → Delete account → type DELETE → confirm. If you have not finished setup, use Delete my account at the bottom of the setup screens. Your photos and videos are deleted first, then your account and everything in it, straight away. This cannot be undone. Copies you saved to your phone's gallery stay on your phone.
Without the app: email support@miphyfitness.com from your sign-in address with the subject "Delete my MiPhy account", or follow Delete your MiPhy account. We may send a code to confirm it is you, and we delete the account within [PLACEHOLDER: 7] days.
Some copies remain for a short time in backups and with providers, as listed in section A12, and are then overwritten.
A14. Security
- All traffic is encrypted (HTTPS/TLS). Stored data is encrypted at rest by our providers.
- Database rules let each person reach only their own data.
- Photos and videos are in private storage, shown only through links that expire.
- Secret keys, including the AI provider key, live only on our server, never in the app.
- The admin dashboard needs a second sign-in step.
- AI spending has a daily cap.
No system is perfectly secure. If a breach is likely to put you at risk, we will tell you and the authorities without undue delay, and within the deadline each law sets (Part B). [LEGAL REVIEW: incident response steps.]
A15. Your rights
Wherever you live, you can ask us to:
- Know what data we hold about you, how we use it, who we share it with, and where it goes;
- Get a copy of it, in a common machine-readable format (portability);
- Correct or complete it (you can edit most of it yourself);
- Delete it (you can do this yourself, section A13);
- Withdraw consent at any time (section A8);
- Restrict or stop processing, or object to it;
- Not be subject to decisions made only by automated means that seriously affect you (we make none);
- Name someone to act for you, including after your death or if you cannot act;
- Complain to us, and to the data protection authority where you live (Part B lists them).
How: email support@miphyfitness.com with "Privacy request" in the subject, from your sign-in address. We may send a code to that address to confirm it is you. We reply within 30 days, or sooner where your law requires. If a request is complex we may extend this where the law allows, and we will tell you why. Requests are free, unless clearly unfounded or excessive. We will never treat you worse for using your rights.
[DECISION: add a "Download my data" button in Profile → Privacy (DECISIONS lists it), or handle copies by email for now.]
A16. Adults only
MiPhy is for adults aged 18 and over in every country, even where the local age of digital consent is lower. Setup does not accept ages under 18. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account. If you think a child has signed up, email us. [LEGAL REVIEW: the account exists from the first code email, before the age question; consider an age check on the sign-up screen.]
A17. No selling, no ads, no tracking
We do not sell or rent personal data, do not "share" it for cross-context behavioural advertising, do not use advertising or analytics trackers, and do not track you across other apps or websites. Because we do none of this, there is nothing to opt out of; we also honour browser "Global Privacy Control" and "Do Not Track" signals by default.
A18. Changes to this policy
We will update the date and version at the top, and tell you in the app (and by email for important changes) before a change takes effect. If a change needs your consent, for example a new use of health data, a new AI feature, AI video analysis, or a new country for storage, we will ask first. Earlier versions are available on request.
A19. Contact and complaints
Mind and Physique Lifestyle Coaching
[PLACEHOLDER: registered address], Dubai, United Arab Emirates
Email: support@miphyfitness.com (privacy contact and grievance officer: Niranjan [VERIFY: full legal name], founder)
Please contact us first so we can try to fix the problem. You can also complain to the data protection authority in your country (Part B).
Part B: extra rules for your country or region
Part A applies everywhere. The sections below add what each law requires. We follow the law that gives you more protection.
B1. United Arab Emirates (home law)
Law: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). It applies to people in the UAE and to our processing as a UAE company.
- Health and other sensitive data: the PDPL treats data about your physical, psychological or mental condition, biometric data and religious beliefs as sensitive personal data. We process it only with your specific, clear and unambiguous consent (section A8), given separately for AI help.
- Not a health service: MiPhy is a general fitness and wellbeing app, not a licensed health facility, and does not provide health services. [LEGAL REVIEW: confirm that Federal Law No. 2 of 2019 on ICT in Health Fields, including its data-localisation rule, does not apply, so that health-type data stays under the PDPL.]
- Transfers outside the UAE: the UAE has not yet published a list of countries with adequate protection. We transfer data to India (main storage) and the USA (section A11) under binding contracts with each provider that require PDPL-level protection, together with your express consent given in the app (PDPL Article 23).
- Your rights (PDPL Articles 13 to 18): information about the processing; data portability; correction and erasure; restriction; stopping processing; and objecting to decisions based only on automated processing, with the right to ask for human review. We do not make such decisions.
- Data protection officer: Niranjan [VERIFY: full legal name], support@miphyfitness.com. [LEGAL REVIEW: whether a formal DPO appointment under Article 10 is needed.]
- Breaches: we will notify the UAE Data Office and affected people as the PDPL and its Executive Regulations require.
- Complaints: contact us first. You can then complain to the UAE Data Office. [VERIFY: the Data Office's complaint channel; as of October 2026 its Executive Regulations have not been published and the Telecommunications and Digital Government Regulatory Authority (TDRA) acts as interim contact.]
B2. India
Law: the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025. It applies because we offer MiPhy to people in India and store data in India. [LEGAL REVIEW: most duties start around 13 May 2027 (18 months after the Rules were notified on 13 November 2025), or earlier if the Government shortens the period; this section is written to comply now.]
Notice in brief (Rule 3). We, Mind and Physique Lifestyle Coaching, are the data fiduciary.
| Personal data | Purpose (service it is needed for) |
|---|---|
| Email, password or Google sign-in, name, account ID | Creating your account and signing you in |
| Setup answers (age, gender, height, weight, goals, pain, conditions, diet, allergies, training) | Personalising your plan, targets and safety notices |
| Logs: food, water, steps, workouts, habits, body stats, measurements, mindfulness, mood and sleep, check-ins | Showing your progress and adjusting your plan |
| Posture photos and form videos | Letting you compare your posture and form over time |
| AI chat messages and the profile summary in section A6 | AI coach replies, plans and check-in suggestions (only with AI help on) |
| Technical logs | Security and fixing problems |
- Consent: we rely on your consent for each purpose, given in the app. Where we rely on a "legitimate use" under section 7 of the Act (for example, complying with a law or responding to a medical emergency), we say so.
- Withdraw consent: Profile → Privacy, or email support@miphyfitness.com. Withdrawing is as easy as giving consent. When you withdraw, we stop and delete the data unless a law requires us to keep it.
- Your rights: information about your data and who it was shared with; correction, completion, updating and erasure; grievance redressal; and to nominate another person to exercise your rights if you die or become unable to act (email us with their name and contact).
- Grievance officer: Niranjan [VERIFY: full legal name], founder, support@miphyfitness.com, [PLACEHOLDER: address]. We respond within 30 days, and in any case within the 90 days the Rules allow.
- Complaints to the Board: if you are not satisfied, you can complain to the Data Protection Board of India through the online channel the Board publishes [VERIFY: the Board's website once its members are appointed; MeitY: https://www.meity.gov.in].
- Transfers: your data is stored in Mumbai, India. Some is processed in the USA (section A11). The Act allows this unless the Government restricts a country; we will follow any such restriction.
- Breaches: we will tell you and the Board without delay, with a detailed report to the Board within 72 hours, as the Rules require, and report cyber incidents to CERT-In where required.
- Children: MiPhy is for adults only (section A16), so we do not process children's data.
- Languages: this notice is in English and Hindi. [DECISION: offer it in other Indian languages listed in the Eighth Schedule of the Constitution on request.]
B3. European Union, EEA and Switzerland
Applies if you live in the EU, Iceland, Liechtenstein, Norway or Switzerland. Laws: the General Data Protection Regulation (EU) 2016/679 (GDPR) and Switzerland's Federal Act on Data Protection (nFADP).
- Controller: Mind and Physique Lifestyle Coaching (section A1). We have no office in the EU.
- EU representative (GDPR Art. 27): [PLACEHOLDER: name and address of the EU representative]. You can contact them instead of us about any privacy question.
- Legal grounds: health information and other special-category data: your explicit consent (Art. 9(2)(a)). Sending it to our AI provider: a separate explicit consent. Account, security and running the app: performance of our contract with you (Art. 6(1)(b)). Security, cost control and handling claims: our legitimate interests (Art. 6(1)(f)), which you can object to. Keeping records the law requires: legal obligation (Art. 6(1)(c)).
- Do you have to give the data? Account data and the health-information consent are needed to use the app; without them we cannot provide it. AI help, photos and videos, and every optional setup question are your choice.
- Transfers outside the EEA/Switzerland: to India (Supabase, main storage) under the European Commission's standard contractual clauses (2021), with a transfer assessment; to the USA (Resend, Google, likely the AI provider) under the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise the standard contractual clauses; Swiss transfers use the Swiss-U.S. framework or the clauses adapted for Swiss law. You can ask us for a copy.
- Rights: access, rectification, erasure, restriction, portability, objection, withdrawing consent at any time, and not being subject to solely automated decisions with legal or similarly significant effects (we make none).
- AI: the AI coach is clearly labelled as AI, as the EU AI Act's transparency rules expect.
- Complaints: you can complain to the data protection authority in the EU country where you live or work, or where you think the problem happened (list: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC).
- Breaches: we notify the competent authority within 72 hours where required, and you without undue delay if you are at high risk.
B4. United Kingdom
Laws: UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
- UK representative (UK GDPR Art. 27): [PLACEHOLDER: name and address of the UK representative].
- Legal grounds, rights and "do you have to give the data": the same as B3 (explicit consent for health data; separate explicit consent for AI help).
- Transfers: to India under the UK International Data Transfer Agreement or the UK Addendum to the EU clauses, with a transfer risk assessment; to the USA under the UK-U.S. data bridge where the provider is certified, otherwise the IDTA or Addendum.
- Complaints to us: email support@miphyfitness.com with "Privacy complaint" in the subject [DECISION: or a web form]. We acknowledge your complaint within 30 days and reply without undue delay.
- Complaints to the regulator: the Information Commissioner's Office (ICO), https://ico.org.uk/make-a-complaint/.
B5. United States
We do not sell personal data, do not share it for targeted advertising, and do not profile you in ways that produce legal or similarly significant effects. We do not use your personal data to train large language models or any AI model.
B5.1 Consumer health data (Washington, Nevada, Connecticut and similar laws)
Much of what you log in MiPhy is "consumer health data" under Washington's My Health My Data Act, Nevada's SB 370 (NRS 603A), and Connecticut's consumer health data rules. Our separate Consumer Health Data Privacy Policy explains exactly what we collect, why, who we share it with, and how to use your rights. In short:
- we collect consumer health data only with your consent, and only for the features you use;
- we share it only with the service providers in section A10 that process it for us, and with the AI provider only after your separate consent (AI help);
- we never sell it;
- we do not use geofencing;
- you can access it (including a list of every third party we shared it with), delete it (including from our providers), and withdraw consent at any time.
B5.2 Your rights in states with privacy laws
Depending on your state (for example California, Colorado, Connecticut, Texas, Virginia and others), you may have the right to: know and access your data; correct it; delete it; get a portable copy; opt out of sale, targeted advertising and significant profiling (we do none of these); and limit the use of sensitive data (we use it only to provide the service you asked for, with your consent). Use them by emailing support@miphyfitness.com. You can use an authorised agent; we may ask them for proof. We do not discriminate against you for using your rights.
Appeals: if we decline your request, you can appeal by replying to our decision with "Appeal" in the subject. We answer appeals within 45 days [VERIFY: shortest state deadline]. If you are not satisfied, you can contact your state Attorney General.
B5.3 California
The categories of personal information we collected in the last 12 months are listed in section A4: identifiers (email, account ID), approximate geolocation (city and country from your IP address), personal records (name), characteristics (age, gender), sensitive personal information (health information, account sign-in), audio, electronic, visual or similar information (photos, videos; voice only on your device's speech service), and internet activity limited to server logs. Sources: you, and Google if you use Google sign-in. Purposes: section A7. Disclosed for a business purpose to: the service providers in section A10. Sold or shared: none. Retention: section A12. Do Not Track and Global Privacy Control: we do not track you across other sites or apps, and no third party tracks you through MiPhy, so these signals have nothing to change; we treat them as a request to opt out anyway.
[LEGAL REVIEW: CCPA likely does not apply yet (below thresholds), but CalOPPA does. Keep this short California section either way.]
B5.4 Health breach notices
If a breach of your unsecured health information happens, we will notify you, and the U.S. Federal Trade Commission where its Health Breach Notification Rule applies. [LEGAL REVIEW: the rule covers apps that can draw health data from more than one source; it may apply once wearables or Health Connect are added.]
B6. Saudi Arabia
Law: the Personal Data Protection Law (Royal Decree M/19 of 1443H, amended by Royal Decree M/148 of 1444H) and its Implementing Regulations and Transfer Regulation. It applies to the personal data of people living in the Kingdom, even when processed abroad.
- Health data is sensitive data. We process it only with your explicit consent, never on the basis of legitimate interest.
- Transfers outside the Kingdom (to India and the USA): under standard contractual clauses approved by SDAIA, with a transfer risk assessment, as the Transfer Regulation requires.
- Your rights: to be informed; to access and get a copy of your data in a readable format; to correct it; to have it destroyed when no longer needed; to have it transferred (portability); and to withdraw consent. We answer within 30 days (extendable by 30 days where the law allows, and we will tell you).
- Breaches: we notify SDAIA within 72 hours where the breach may harm you, and tell you without undue delay.
- Data protection officer: Niranjan [VERIFY], support@miphyfitness.com. Representative in the Kingdom: [PLACEHOLDER: required before serving Saudi users; see LAW-CHECK.md].
- Complaints: contact us first, then the Saudi Data and AI Authority (SDAIA) (https://dgp.sdaia.gov.sa).
[LEGAL REVIEW: registration on SDAIA's National Register of Controllers (opened to overseas controllers in October 2026) and appointment of a local representative are likely required because we process health data. Do not make MiPhy available in Saudi Arabia until done.]
B7. Other Gulf countries, and UAE free zones
- Qatar (Law No. 13 of 2016): health data is "personal data of a special nature". We process it only with your explicit consent. You can complain to the National Cyber Security Agency (National Cyber Governance and Assurance Affairs). [LEGAL REVIEW: whether a special-nature processing permit is needed before offering MiPhy in Qatar.]
- Bahrain (Law No. 30 of 2018): health data is sensitive and is processed with your consent. Transfers abroad rely on your consent and contractual safeguards. Complaints: the Personal Data Protection Authority.
- Oman (Royal Decree 6/2022 and its Executive Regulation, amended by Royal Decree 68/2026): health data is sensitive and is processed with your explicit consent. Transfers abroad rely on your explicit consent and contractual safeguards. You can object to decisions made only by automated means (we make none). Complaints: the Ministry of Transport, Communications and Information Technology. [LEGAL REVIEW: the sensitive-data permit from the Ministry is likely needed before offering MiPhy in Oman.]
- Kuwait: there is no general data protection law that applies to us; Part A applies in full. [VERIFY before launch.]
- DIFC and ADGM: their data protection laws apply only to businesses licensed or processing data in those free zones. We are not, so the federal PDPL (B1) applies to people there.
B8. Other countries
Brazil (LGPD). Health data is sensitive and is processed with your specific, highlighted consent (Art. 11). Transfers to India and the USA use the ANPD's standard contractual clauses. Our data protection officer (encarregado) is Niranjan [VERIFY: full legal name], support@miphyfitness.com, and can be contacted in Portuguese [DECISION: or name a Brazilian encarregado service]. You can complain to the ANPD (https://www.gov.br/anpd).
Canada (PIPEDA; Quebec Law 25). We get your express consent for health information. The person in charge of protecting personal information is our founder, Niranjan [VERIFY], support@miphyfitness.com. Your data is stored in India and processed in the USA, where it may be accessed by local authorities under local law; we assessed these transfers before making them. We use no technology that profiles, identifies or locates you. Complaints: the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca), or in Quebec the Commission d'accès à l'information (https://www.cai.gouv.qc.ca).
Australia (Privacy Act 1988). We treat MiPhy as handling health information under the Australian Privacy Principles. Your data is disclosed to recipients in India and the USA (section A10). We do not use computer programs to make decisions that significantly affect your rights or interests; AI features only suggest, and you decide. You can access and correct your information and complain to us, then to the Office of the Australian Information Commissioner (https://www.oaic.gov.au). We follow the Notifiable Data Breaches scheme.
Singapore (PDPA). Our data protection officer is Niranjan [VERIFY], support@miphyfitness.com. Transfers abroad are protected by contract to a comparable standard. Complaints: the Personal Data Protection Commission (https://www.pdpc.gov.sg).
Japan (APPI). We obtain your consent before acquiring special care-required information (such as medical history). Your data is transferred to India and the USA; information on their privacy laws is available from Japan's Personal Information Protection Commission, and we protect the data by contract. Our security measures are described in section A14. Regulator: PPC (https://www.ppc.go.jp/en/).
South Korea (PIPA). Health information is processed with your separate consent. Data is stored in India and processed in the USA by the providers in section A10, for the purposes and periods in sections A7 and A12. You can refuse; optional features then stop. Regulator: PIPC (https://www.pipc.go.kr).
South Africa (POPIA). Health information is special personal information, processed with your consent. Our information officer is Niranjan [VERIFY], support@miphyfitness.com. Regulator: the Information Regulator (https://inforegulator.org.za).
Nigeria (NDPA 2023), Kenya (DPA 2019), Türkiye (KVKK) and others with similar laws. Health data is processed with your explicit consent, and transfers abroad use contractual safeguards. You can complain to your national authority (Nigeria: NDPC; Kenya: ODPC; Türkiye: KVKK). [LEGAL REVIEW: registration duties (Nigeria NDPC, Türkiye VERBIS, Kenya ODPC) once there are users in these countries.]
Mainland China. MiPhy is not offered in mainland China. [DECISION: exclude mainland China from App Store and Google Play availability.]
B9. Everywhere else
If you live in a country not named above, Part A applies to you in full: you have every right in section A15, health information is collected only with your consent, it is never sold, and we follow any stricter rule in your local law. If your local law gives you a right this policy does not mention, email us and we will honour it.