Last updated: May 12, 2026
This Policy describes what we collect, how we use it, and the choices you have. We designed Physiq to minimize data collection and to keep your physique data under your control.
Photos are encrypted in transit (TLS) and at rest (AES-256). By default, raw photos are retained for the duration of your account; derived numerical measurements are retained for your progress history. You can delete all scans at any time from your scan history.
We do not sell your data. We share data only with:
You can:
EU/UK users additionally have rights under GDPR; California users under CCPA. Contact stimtroop@gmail.com to exercise them.
Physiq is not intended for users under 16. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact stimtroop@gmail.com for prompt deletion.
Body photos and physique measurements may be considered sensitive personal information in some jurisdictions. We treat all scan data with elevated protections: encrypted storage, restricted internal access, and no use for advertising — ever.
Data may be processed in the United States and other countries where our service providers operate. We rely on Standard Contractual Clauses for transfers from the EEA/UK.
We use industry-standard safeguards including encryption, access controls, and regular security reviews. No system is 100% secure; in the event of a breach affecting your data we will notify you within 72 hours where required by law.
Account data: until you delete your account. Scan photos: until you delete them or your account. Derived measurements: until account deletion. Crash logs: 90 days.
Physiq does not use third-party advertising cookies or trackers.
We will notify you in-app of material changes to this Policy at least 14 days before they take effect.
For privacy questions, data requests, or any concerns about this Policy:
✉ stimtroop@gmail.com