PRIVACY POLICY

Phoenix Protocol Pte. Ltd.

Effective Date: 11 March 2026

TL;DR — The Short Version

  • We never sell your data. Your health information is never shared with advertisers or third parties for commercial gain.
  • Your data is encrypted. All health data is protected with industry-standard encryption.
  • You're in control. You can delete everything anytime — just email us.
  • No surprise sharing. We only share data with service providers who need it to run the platform (like Stripe for payments).

Full legal details below.

1. Introduction

Phoenix Protocol Pte. Ltd. (“Phoenix,” “we,” “us,” or “our”) operates the Phoenix mobile application and web platform (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Information You Provide

We collect information you voluntarily provide when using our Service, including:

  • Account information: name, email address, age, and genetic status (such as APOE genotype)
  • Payment information: processed through our third-party payment processor (Stripe). We do not store your full credit card number.

2.2 Health Data We Collect

Our Service collects the following categories of health data that you voluntarily provide or authorize:

  • Blood test and biomarker data: When you upload blood test PDFs, Phoenix AI extracts biomarker values (such as ApoB, HbA1c, lipid panels, and other lab markers). These are stored to track trends over time.
  • Supplement and medication data: Names, dosages, and schedules of supplements and medications you log in the app.
  • Daily check-in responses: Self-reported health information including mood, energy levels, sleep quality, cognitive function, and other wellness metrics you choose to report.
  • Experiment and protocol data: Information about structured health experiments you participate in, including intervention type, duration, and self-reported outcomes.

2.3 Health Data from Connected Third-Party Services

With your explicit consent, we collect health and fitness data from connected third-party services. You control which services are connected and can disconnect them at any time.

From Apple Health (iOS): activity data (steps, distance, calories burned), sleep analysis (duration, stages), heart rate data, workout data, and other health metrics you authorize through the Apple Health permissions screen.

From Google Health Connect (Android): activity data (steps, distance, calories burned), sleep data (duration, stages), heart rate data, exercise sessions, and other health metrics you authorize through the Health Connect permissions screen.

We only access the specific data categories you grant permission for. We do not read health data beyond what you have explicitly authorized.

2.4 Information We Do Not Collect

We do not collect device identifiers, IP addresses, or precise location data through the Phoenix application.

3. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Display your health data, generate trend analyses, and personalize your experience based on your genetic profile and tracked metrics
  • Generate health insights: Analyze your biomarker data, check-in responses, and connected device data to provide personalized health insights and recommendations specific to your APOE status
  • Support structured experiments: Track your progress through health experiments, compare outcomes, and help you refine your personal protocol
  • Facilitate community features: Match you with accountability pod members based on shared goals, genetics, and interests
  • Process transactions: Handle subscription payments and send related information
  • Communicate with you: Send administrative information, updates, security alerts, and relevant content
  • Improve the Service: Analyze aggregated, anonymized usage patterns to improve features and user experience
  • Provide customer support: Respond to your inquiries and troubleshoot issues

4. Disclosure of Your Information

4.1 General Policy

We do not sell, rent, or share your personal data with third parties for their marketing purposes. We will never share your individual health data without your explicit, specific consent.

4.2 Research and Clinical Trials

From time to time, we may offer opportunities to participate in research studies or clinical trials conducted by Phoenix or our partners. Participation is entirely voluntary. If you choose to participate, you will be required to provide separate, explicit opt-in consent for each study. Your data will only be shared with research partners after you have reviewed and agreed to the specific terms of that study.

4.3 Service Providers

We share your information with the following third-party service providers who perform services on our behalf:

  • Supabase (database hosting and backend services, Asia East region)
  • Stripe (payment processing)
  • Google Analytics (anonymized usage analytics only)
  • Circle (community platform)
  • Beehiiv (email communications)
  • Typeform (forms and surveys)

These service providers are contractually obligated to protect your information and may only use it for the purposes for which it was disclosed.

4.4 Legal Requirements

We may disclose your information where required by law, regulation, legal process, or governmental request.

5. Data Retention

We retain your personal data and health data for as long as your account is active and you maintain an active subscription to our Service.

Active accounts: All data (including health data, biomarker records, check-in history, supplement logs, and experiment data) is retained for the duration of your account’s existence to provide continuous trend analysis and historical insights.

After account deletion: When you delete your account, all personal data and health data is permanently deleted from our production systems within 30 days. Backups containing your data are purged within 90 days of account deletion.

Payment records: Transaction records may be retained for up to 7 years after your last transaction as required by applicable tax and financial regulations.

Anonymized data: Aggregated, anonymized data that cannot be used to identify you may be retained indefinitely for research and Service improvement purposes.

6. Data Deletion

6.1 How to Delete Your Data

You may delete your account and all associated data at any time using either of the following methods:

  • In-app: Navigate to My Profile > Delete Data in the web application
  • By email: Send a deletion request to kevin@thephoenix.community

6.2 What Happens When You Delete

Upon receiving your deletion request:

  1. Your account is immediately deactivated and you will no longer be able to access the Service
  2. All personal data, health data, biomarker records, check-in responses, supplement logs, experiment data, and community contributions are permanently deleted from our production database within 30 days
  3. Your data is purged from all backup systems within 90 days
  4. Any data shared with third-party services (Apple Health, Google Health Connect) remains on those platforms and is governed by their respective privacy policies. You can manage that data directly through those services.
  5. Payment transaction records processed by Stripe may be retained by Stripe in accordance with their data retention policies and applicable financial regulations

6.3 Disconnecting Third-Party Services

You can disconnect Apple Health or Google Health Connect at any time through the app settings. Disconnecting stops all future data collection from that service. Previously synced data remains in your Phoenix account unless you separately request its deletion or delete your account.

7. Community Confidentiality

The Phoenix Community (hosted on Circle) is a private, members-only space. All content shared within the community is considered confidential. Members are strongly discouraged from sharing any information, discussions, or personal details of other members outside the community.

Important: While we enforce community guidelines and take reasonable measures to maintain confidentiality, we cannot guarantee that other members will not share information outside the community. If you have concerns about privacy, you may use a pseudonym within the community.

8. Data Storage and Security

Your data is stored on secure servers provided by Supabase, located in the Asia East region. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Row-level security on all database tables
  • Encryption of data in transit (TLS/SSL)
  • Encryption of data at rest
  • Access controls limiting employee access to personal data

No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights and Choices

You have the right to:

  • Access the personal data and health data we hold about you
  • Correct inaccurate data by updating your profile or contacting us
  • Delete your data at any time (see Section 6 above)
  • Withdraw consent for data processing where consent is the basis for processing
  • Disconnect third-party integrations (Apple Health, Google Health Connect) at any time through app settings
  • Export your data by contacting us at kevin@thephoenix.community

To exercise any of these rights, contact us at kevin@thephoenix.community. We will respond to your request within 30 days.

10. Age Restrictions

The Service is intended for users who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If we learn that we have collected personal data from a person under 18, we will delete that information promptly. If you believe we may have collected information from a person under 18, please contact us.

11. International Data Transfers

Your information may be transferred to, and maintained on, servers located outside your country of residence. By using the Service, you consent to such transfer. We will take reasonable steps to ensure your data is treated securely and in accordance with this Privacy Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top. We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Phoenix Protocol Pte. Ltd.
16 Spottiswoode Park Road
#36-03, Spottiswoode Suites
Singapore 088661
kevin@thephoenix.community

We use cookies to enhance your experience.