PhysioOS

The Operating System for Your Body

PhysioOS

Privacy Policy

Last updated September 4, 2026

Who this policy covers

This draft describes how PhysioOS / PhysioX processes information when you create an account, use the dashboard, or connect PhysioOS through ChatGPT or another MCP client such as Claude.

Categories of personal data

Account identity: email address, display name, password hash or passkey credentials, session cookies, and timezone or unit preferences.

Training data: programs, workout templates, sessions, sets, personal records, progression, substitutions, and session or training notes.

Body composition: consumer scan values you enter (for example weight, skeletal muscle mass, body-fat percentage, and water metrics). Estimated SMM is a derived estimate, not a clinical measurement, and can move with hydration and glycogen.

Nutrition: foods, meals, daily totals, targets, and optional USDA FoodData Central lookups you request.

Photos and files: metadata in PhysioX. File bytes, when archived, stay in your connected private Google Drive folder. PhysioX does not create public file links.

Connected fitness data: if you authorize Google Health or Fitbit, PhysioOS may read exercise sessions and sleep records covered by the permissions you approve. The current connector requests read-only access and does not write to or delete data in your Google or Fitbit account.

Product feedback you submit. OAuth tokens issued to a connected assistant for your account. Encrypted refresh tokens if you connect Google Drive, Google Health, or Fitbit.

What we ask you not to submit

PhysioOS is fitness and wellness tracking, not a medical-record system. Do not submit medical records, diagnoses, prescriptions, government identifiers, payment-card numbers, or authentication secrets (API keys, passwords, one-time codes) through tools or notes.

If you mention a training limitation, we treat it as a workout constraint, not as a clinical chart. We do not claim HIPAA compliance and we do not claim that users never enter sensitive information.

Purposes of use

Operate your account, show your dashboard, and return your own training, nutrition, and body-composition history to you or to a connected assistant when you authorize PhysioOS.

Calculate progression, personal records, workout scoring, and coaching context. When you connect Google Health or Fitbit, synchronize authorized exercise and sleep data into your PhysioOS history. Send transactional email such as password reset when that feature is configured.

Store product feedback. We do not sell personal data.

Google Health and Fitbit data

PhysioOS accesses Google Health or Fitbit data only after you choose to connect the service and approve the requested permissions. Current access is limited to read-only exercise and sleep information used to populate your personal fitness history and coaching context.

PhysioOS does not sell Google user data, use it for advertising, or allow humans to read it except when necessary for security, support you request, legal compliance, or operating the service through the processors identified below.

PhysioOS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect the integration in PhysioOS and revoke access through your Google Account. Disconnecting stops future synchronization. You may delete imported records by deleting your PhysioOS account or contacting support.

Connected assistants

If you connect PhysioOS inside ChatGPT, Claude, or another MCP client, that provider receives the tool arguments and tool results needed to fulfill your prompts. We do not receive your full chat log except for the snippets and tool calls the client sends to PhysioX.

Disconnect PhysioOS in the client settings to stop new OAuth access. Access tokens expire after one hour. Refresh tokens last up to 30 days.

Processors and infrastructure

Hosting and application runtime: Vercel. Database: Neon Postgres. Optional email: Resend. Optional food lookup: USDA FoodData Central. Optional file archive: Google Drive in your account. Optional fitness and sleep synchronization: Google Health and Fitbit. Authentication uses OAuth on the application host.

These processors may handle the categories above when you use those features. Hosting is commonly located in the United States.

Retention

We keep account and training data until you delete the account or we delete it when processing a valid deletion request.

Abandoned empty sign-up accounts with no password or passkey may be removed automatically after a short period.

Password-reset tokens are short-lived. Dashboard sessions can be signed out. OAuth access tokens expire after one hour.

Deletion and your controls

You can sign out; disconnect Google Drive, Google Health, or Fitbit from Account or Settings; revoke Google access from your Google Account; and disconnect PhysioOS in the assistant you connected.

Non-owner users can delete their own account from Account → Delete account. That removes the PhysioX user row and cascaded training, nutrition, and related records for that user.

The reserved production owner account cannot be self-deleted from the product. Request owner-account deletion through support.

Deleting PhysioX metadata does not automatically empty your Google Drive. Disconnect Drive and remove files there if you want Drive copies gone.

Security

Passwords are stored as hashes. Dashboard sessions are signed cookies. Google Drive refresh tokens are encrypted at rest. Tool callers cannot supply a trusted userId; the authenticated account is the only identity.

No security measure is perfect. Report problems on the support page or by emailing the support address listed there.

Minors

PhysioOS is not directed at children under 18. Do not create an account for a minor.

Region and international users

PhysioOS is initially offered in the United States only. The service is operated from Texas, United States using infrastructure commonly located in the United States.

If you use PhysioOS from another country, your information may be processed in the United States.

Contact

Public support contact: support@physioos.com. Also see https://physiox-c1c364.vercel.app/support. Do not send passwords or API keys.

The support mailbox is the intended public contact. Confirm it is receiving mail before treating this page as final.