Philoi is a social accountability app for students. You set goals and run focused “lock in” sessions, close each one with a check-in, and keep at it alongside a small group of friends (a “campfire”). On top of that sit challenges, streaks, XP and ranks, campus leaderboards, milestones you can share, an optional AI coach, and a cosmetic economy you earn or buy your way through. This policy explains exactly what data all of that involves, who can see it, and how to get rid of it.
It is written to be read, not to be survived. If anything here is unclear, email nb@philoi.app and we will answer.
1. Who we are
Philoi (“Philoi”, “we”, “us”) provides the Philoi mobile app and this website. For the purposes of the UK GDPR and EU GDPR, Philoi is the data controller for the personal data described below.
Contact for all privacy matters, including data protection requests: nb@philoi.app.
2. What we collect
Account information
- Email address — used to create and secure your account, to sign you in, and to send essential service messages.
- Display name and handle — chosen by you, shown to other members of your campfires.
- Profile details you choose to add, such as an avatar or your university. Your university is optional and is used only to place you on that university's leaderboard.
- University verification — if you verify a campus email, we send a six-digit code to that address and record the verified result against your existing account.
- Sign-in method — if you sign in with Google, we receive the basic account identifiers that provider returns so we can authenticate you.
- Purchase records — if you buy embers or a Forge Pass, we receive confirmation of the purchase and the entitlement it granted. Your card details are handled by Apple or Google and are never seen by Philoi.
Activity within the app
- Goals and sessions — the goals you create, the “lock in” sessions you start, their duration, and whether you completed them.
- Check-ins — the record that closes a session, including the photo you take at the end of it. That photo is captured with the camera in the moment; Philoi does not upload from your photo library.
- Campfire membership — which campfires you belong to, how you joined, and your role in them.
- Messages and reactions you send inside a campfire chat.
- Challenges — which challenges you create or join, your progress and final standing, and the cheers and notes you send on them.
- Progress data — XP, ranks, streaks, season placements and leaderboard standing, derived from the above.
- Milestones — an achievement you choose to post, its note, and the audience you chose for it.
- Journal notes and profile bio — your journal notes are private to you.
- Gym sessions — the sets you log and, if you record them, short per-set video clips.
- Embers and inventory — your ember balance and transaction history, the cosmetic items you own or equip, and Forge Pass progress.
- Reports and moderation records if you report content, a user or a campfire.
Technical and diagnostic data
- Device and app information — device model, operating system version, app version, and language. Used to fix crashes and support the right devices.
- Push notification token, if you allow notifications, so we can deliver reminders and campfire activity alerts. You can turn notifications off at any time in your device settings.
- Basic error and usage logs — for example that a screen failed to load. We do not use advertising identifiers and we do not run third-party ad trackers.
- Product analytics and crash reports — in-app events (such as “started a lock in” or “joined a campfire”) recorded against your user ID, and crash diagnostics. These are used to understand how the app is used and to fix what breaks. The providers are listed in section 7.
Optional connected sources
If — and only if — you choose to connect a fitness source such as Apple Health, Garmin or Strava, we receive activity metrics from it. This is covered in detail in the next section.
If you connect Google Calendar, we receive read-only event times and titles (not their contents) — covered in the Calendar integration section below.
3. Fitness & health integrations
The short version: connecting a fitness source is entirely optional, read-only, and scoped to a single metric for a single challenge. Your health data is displayed only to you. Nothing is sold, and disconnecting deletes what we pulled.
Philoi lets you run friendly challenges — most steps this week, most workouts this month, furthest distance. So that nobody has to take anyone's word for it, a fitness challenge can verify itself from your own device data. The rules we hold ourselves to:
- Opt-in, per source. No fitness source is connected by default. You explicitly connect Apple Health, Garmin or Strava, and you grant permission through that provider's own authorisation screen.
- Read-only. We only ever read. Philoi never writes, edits or deletes anything in your Apple Health, Garmin or Strava account.
- Only the metric the challenge needs. If you join a step-count challenge, we request step counts — not your heart rate, sleep, weight, body composition, blood oxygen, menstrual data, GPS routes, or anything else. We request the narrowest permission scope the challenge requires.
- Only for the window the challenge covers. We request that metric for the days the challenge runs, not your entire history.
- Disconnect any time. You can disconnect a source from within Philoi (Settings → Connected apps), and you can also revoke access from the provider's own settings — for example in Apple Health, in your Garmin Connect account, or in Strava's connected-apps page. When you disconnect, we immediately stop requesting data and delete the metric values we pulled from that source, other than the final score of any challenge that has already finished.
- Never used for advertising, profiling or resale. Data received from a fitness provider is used solely to show you your own progress and to score challenges you chose to enter.
Data received from a fitness provider is stored in the same protected database as the rest of your account data, is accessible only to you and to the small number of Philoi personnel who need it to operate the service, and is never disclosed to third parties except the infrastructure providers listed in section 7.
4. Calendar integration (Google Calendar)
The short version: connecting your Google Calendar is optional and read-only. Philoi reads only your upcoming event times and titles — never their contents — so your in-app coach can steer you around real deadlines and your free time. It is never shown to other users, never sold, and deleted when you disconnect.
If — and only if — you choose to connect Google Calendar, Philoi requests read-only access so your coach can be useful about your actual schedule. The rules we hold ourselves to:
- Opt-in. Google Calendar is never connected by default. You connect it explicitly and grant permission through Google's own authorisation screen. The scope we request is
calendar.readonly. - Read-only. We only ever read. Philoi never creates, edits, moves or deletes anything in your calendar.
- Only what the coach needs — titles and times, for a short window ahead. We read the start/end times and titles of your upcoming events, and your free/busy blocks, for a rolling window of the next few weeks. We deliberately do not fetch event descriptions, locations, attendees, or event IDs — the request is masked to exclude them.
- Used only to personalise your coaching. Those titles and times are passed to our AI coach (see section 7) so it can nudge you around a real exam or deadline, suggest a free window to lock in, and stay quiet while you're in class. That is the only use.
- Not stored beyond a short cache. We don't keep a copy of your calendar. The forward window is held in an encrypted, short-lived cache (minutes) only to avoid re-requesting it on every coaching message, and your Google refresh token is stored encrypted.
- Never shared, never sold, never used for ads. Calendar data is never shown to other users, never disclosed to third parties except the AI provider in section 7 that generates your coaching, and never used for advertising or profiling.
- Disconnect any time. You can disconnect from within Philoi (Settings → Connected apps) or revoke access from your Google account. When you disconnect, we revoke the token with Google and delete what we cached.
Philoi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Who can see what
This is the part people actually care about, so it is worth being precise.
- Your health data is shown only to you. The values we read from a connected fitness source — your daily step counts, your workouts, your distances — appear in your own app, on your own screens. Other users never see your underlying health data.
- Challenge standings are shared only with the people in that challenge. If you join a step challenge with four friends, those four friends see your total for that challenge and your position on its leaderboard. That is the single number the challenge is about, and joining is what shares it. Nothing else from the connected source is shared — not your route maps, not your heart rate, not your history before or after the challenge window.
- Your campfire sees your app activity — your sessions, check-ins, streaks, XP and messages — because that is the purpose of a campfire.
- Your check-in photos default to your campfires. In Settings you can widen this to everyone. It is your choice, and you can change it back at any time.
- Milestones carry the audience you pick, per post. The default is friends. You can widen a milestone to campus (other verified users at your university) or to public (any signed-in Philoi user). Grades and similar sensitive achievements start at friends-only for that reason.
- University leaderboards show your handle and score only, and only if you have set a university.
- Campfires are not all invite-only. Some are private and reachable only with a join code; others are listed so students can find and join them, either openly or by requesting approval. The campfire's creator chooses which, and you can see which kind you are joining before you join.
- Some things are never shown to anyone else — your journal notes, your calendar data, your conversations with the AI coach, and the raw health data behind a challenge score.
- You can block another user, which hides their content from you and yours from them in both directions.
6. How we use your data
We use the data above to:
- create and secure your account and sign you in;
- run the core product — lock-in sessions and check-ins, campfires, streaks, XP, ranks, challenges, leaderboards, milestones, and the ember economy and its cosmetics;
- send notifications you have asked for, such as reminders and campfire activity;
- score challenges you have entered, including from a connected fitness source;
- keep Philoi safe — investigating reports, preventing abuse and enforcing our terms;
- diagnose crashes and improve the app;
- meet our legal obligations.
Where the UK/EU GDPR applies, our legal bases are: performance of a contract (running the service you signed up for), consent (fitness integrations, push notifications, and any marketing email — each of which you can withdraw at any time), legitimate interests (security, abuse prevention, and basic product improvement), and legal obligation where applicable.
7. Sharing & service providers
We share personal data only with the infrastructure providers that let Philoi run, and only to the extent needed:
- Supabase — database, authentication and file storage.
- Expo / Apple Push Notification service / Firebase Cloud Messaging — delivery of push notifications you have opted into.
- App Store and Google Play — app distribution, and any purchases, handled under their own policies.
- Our email provider (Resend) — sign-in links, university verification codes and essential service messages.
- RevenueCat — processes and validates in-app purchases of embers and the Forge Pass, and tells us which entitlement to grant.
- Cloudflare R2 — object storage for the per-set gym video clips you choose to record.
- PostHog — product analytics. Receives in-app event names and properties against your user ID so we can see how the app is actually used. Hosted in the United States.
- Sentry — crash and error reporting, configured not to send personal information along with a crash.
- The fitness provider you connect (Apple Health, Garmin, Strava or Whoop) and Google (if you connect Calendar) — these send data to us at your instruction, under sections 3 and 4.
- Anthropic (Claude) — powers the in-app AI coach. When you use the coach, the relevant context (your recent activity, goals, streak, and — if you've connected it — your upcoming calendar titles/times and free/busy) is sent to Anthropic's API to generate a coaching message. It is processed to answer you and is not used to train Anthropic's models.
- ElevenLabs — text-to-speech. If you use voice, the text of the coach's reply is sent to ElevenLabs to synthesise the spoken audio. ElevenLabs receives only that reply text, not your account data.
These providers act as processors on our instructions and are bound by contract to protect your data. We may also disclose data if we are legally required to, or where necessary to protect the rights or safety of our users. If Philoi is ever acquired or merged, your data may transfer as part of that transaction, and we will notify you before it becomes subject to a different privacy policy.
8. We do not sell your data
We do not sell, rent, or trade your personal data. We do not share it with data brokers, advertisers or ad networks. We do not use your data — and specifically not any health or fitness data — to build advertising profiles or to target ads, on Philoi or anywhere else.
9. Retention & deletion
- We keep your account data for as long as your account exists.
- Metric values pulled from a connected fitness source are deleted when you disconnect that source, other than the final score of an already-completed challenge.
- If you connected Google Calendar, the short-lived window we cache is deleted and your access token is revoked when you disconnect; we keep no copy of your calendar.
- You can delete your account from inside the app (Settings → Delete account), or by emailing nb@philoi.app from your account address.
- When you delete your account, your profile, goals, sessions, health metrics, messages and progress are deleted from our production systems within 30 days, and from encrypted backups within 90 days. Anonymised, non-identifying aggregates (for example “sessions started this week”) may remain.
- Gym video clips you recorded are deleted from object storage when you remove them or delete your account.
- We may retain a minimal record of a moderation action or a legal request where we are required to.
10. Your rights
Depending on where you live, you have some or all of the following rights over your personal data: access a copy of it, correct it, delete it, export it in a portable format, object to or restrict certain processing, and withdraw consent at any time — including by disconnecting a fitness source or turning off notifications.
To exercise any of these, email nb@philoi.app from the address on your account. We will respond within 30 days. Exercising your rights costs nothing and we will never restrict your use of Philoi for doing so. If you are in the UK or EEA and you believe we have mishandled your data, you also have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
11. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the people who need it, protected by row-level security rules in the database so that one user cannot read another user's data. We keep dependencies patched and review access regularly. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant regulator as required by law.
12. Children
Philoi is intended for university and college students and is not directed at children. You must be 18 years of age or older to use Philoi, matching our Terms of Service. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us their data, email nb@philoi.app and we will delete the account.
13. International transfers
Philoi is operated from the United Kingdom and our infrastructure providers may process data in the United States and the European Union. Where data leaves the UK or EEA, it is transferred under an approved safeguard — typically the European Commission's Standard Contractual Clauses together with the UK Addendum — so that your data keeps an equivalent level of protection.
14. Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your data — particularly anything to do with health or fitness data — we will notify you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
15. Contact us
Questions, requests, or complaints about privacy: nb@philoi.app. A real person reads that inbox.