Privacy Policy

Last updated: 28 July 2026  ·  Effective: 28 July 2026

Philoi is a social accountability app for students. You set goals, run focused sessions, and share your progress with a small group of friends (a “campfire”). This policy explains exactly what data that involves, who can see it, and how to get rid of it.

It is written to be read, not to be survived. If anything here is unclear, email nb@philoi.app and we will answer.

1. Who we are

Philoi (“Philoi”, “we”, “us”) provides the Philoi mobile app and this website. For the purposes of the UK GDPR and EU GDPR, Philoi is the data controller for the personal data described below.

Contact for all privacy matters, including data protection requests: nb@philoi.app.

2. What we collect

Account information

Activity within the app

Technical and diagnostic data

Optional connected sources

If — and only if — you choose to connect a fitness source such as Apple Health, Garmin or Strava, we receive activity metrics from it. This is covered in detail in the next section.

3. Fitness & health integrations

The short version: connecting a fitness source is entirely optional, read-only, and scoped to a single metric for a single challenge. Your health data is displayed only to you. Nothing is sold, and disconnecting deletes what we pulled.

Philoi lets you run friendly challenges — most steps this week, most workouts this month, furthest distance. So that nobody has to take anyone's word for it, a fitness challenge can verify itself from your own device data. The rules we hold ourselves to:

Data received from a fitness provider is stored in the same protected database as the rest of your account data, is accessible only to you and to the small number of Philoi personnel who need it to operate the service, and is never disclosed to third parties except the infrastructure providers listed in section 6.

4. Who can see what

This is the part people actually care about, so it is worth being precise.

5. How we use your data

We use the data above to:

Where the UK/EU GDPR applies, our legal bases are: performance of a contract (running the service you signed up for), consent (fitness integrations, push notifications, and any marketing email — each of which you can withdraw at any time), legitimate interests (security, abuse prevention, and basic product improvement), and legal obligation where applicable.

6. Sharing & service providers

We share personal data only with the infrastructure providers that let Philoi run, and only to the extent needed:

These providers act as processors on our instructions and are bound by contract to protect your data. We may also disclose data if we are legally required to, or where necessary to protect the rights or safety of our users. If Philoi is ever acquired or merged, your data may transfer as part of that transaction, and we will notify you before it becomes subject to a different privacy policy.

7. We do not sell your data

We do not sell, rent, or trade your personal data. We do not share it with data brokers, advertisers or ad networks. We do not use your data — and specifically not any health or fitness data — to build advertising profiles or to target ads, on Philoi or anywhere else.

8. Retention & deletion

9. Your rights

Depending on where you live, you have some or all of the following rights over your personal data: access a copy of it, correct it, delete it, export it in a portable format, object to or restrict certain processing, and withdraw consent at any time — including by disconnecting a fitness source or turning off notifications.

To exercise any of these, email nb@philoi.app from the address on your account. We will respond within 30 days. Exercising your rights costs nothing and we will never restrict your use of Philoi for doing so. If you are in the UK or EEA and you believe we have mishandled your data, you also have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

10. Security

Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the people who need it, protected by row-level security rules in the database so that one user cannot read another user's data. We keep dependencies patched and review access regularly. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant regulator as required by law.

11. Children

Philoi is intended for university and college students and is not directed at children. You must be at least 13 years old to use Philoi (or 16 where your country's law sets a higher age for consent to online services). We do not knowingly collect personal data from anyone below that age. If you believe a child has given us their data, email nb@philoi.app and we will delete the account.

12. International transfers

Philoi is operated from the United Kingdom and our infrastructure providers may process data in the United States and the European Union. Where data leaves the UK or EEA, it is transferred under an approved safeguard — typically the European Commission's Standard Contractual Clauses together with the UK Addendum — so that your data keeps an equivalent level of protection.

13. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your data — particularly anything to do with health or fitness data — we will notify you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

14. Contact us

Questions, requests, or complaints about privacy: nb@philoi.app. A real person reads that inbox.