Privacy Policy

Last updated 2 August 2026

Pending legal review

Everything below describes how Foviq actually works today and is written to be accurate, but it has not yet been reviewed by a licensed attorney. Foviq is in pre-launch development and is not yet open to the general public.

Foviq is a consumer wellness app that adapts training and nutrition to your menstrual cycle and how you report feeling. Doing that requires health data, including reproductive health data. This page explains exactly what we collect, why, who else can see it, and what control you have. It is written to be read, not to be skimmed past.

1. Who this applies to

This policy covers the Foviq website and web application at foviq.com. Foviq currently operates in the United States only and stores data in a United States region. If you use Foviq from outside the U.S., your data will be processed in the U.S.

Foviq is not a covered entity or business associate under HIPAA, and the data you give us is generally not protected by HIPAA. It is, however, consumer health data, and several U.S. state laws treat reproductive health data as especially sensitive. We have tried to build accordingly.

2. What we collect

Account data. Your email address and authentication credentials, which are handled by our authentication provider. If you sign in with Google, we receive your email address and basic profile identifier from Google — never your Google password.

Profile and goals. Display name, date of birth, height, weight, timezone, units preference, activity level, fitness level, primary goal, where you train, preferred session length, and how many days a week you want to train.

Reproductive and cycle data. Your cycle profile type (for example natural, hormonal contraception, irregular, perimenopause, postmenopause), your contraceptive method if you tell us, typical cycle and period length, and the dates and flow level of periods you log.

Daily wellbeing logs. Energy, mood, pain level, sleep hours and quality, stress, water intake, steps, flow, any symptoms you select from our list, and an optional free-text note about your day.

Body measurements. Weight, waist, hip, thigh and arm measurements, and body fat percentage, where you choose to record them.

Health context. Medical flags you select (for example PCOS, endometriosis, thyroid conditions, injuries), dietary restrictions, and food allergies including severity. We also record the outcome of a brief, optional wellbeing screen used to make our default recommendations more conservative.

Activity data. Workouts generated for you, sessions you start, complete or skip, sets and weights you log, meals you mark as eaten, and hydration you record.

Consent records. Which consents you granted or withdrew, when, and against which version of our policies. Consent history is kept as an immutable record.

Technical data. Standard server logs and error reports. Our logging deliberately redacts email addresses, tokens, free-text notes and dates of birth before they are written.

3. Consent, asked separately

During onboarding we ask for consent to process your health data, and separately for consent to have that data processed by an AI model. These are distinct checkboxes recorded as distinct entries. We do not bundle health data consent into acceptance of our terms, and we do not treat continued use of the app as consent.

Marketing consent is asked separately again, and is optional. Declining it does not limit your use of the product.

4. How we use your data

  • Estimating where you are in your cycle and how recovered you appear to be, in order to set each day's training intensity and nutrition targets.
  • Selecting exercises and recipes from our own libraries that fit your equipment, restrictions, allergies and medical flags.
  • Excluding foods containing allergens you have told us about — this filtering happens in our database before any recommendation is produced.
  • Showing you your own history and trends over time.
  • Detecting patterns that warrant suggesting you speak to a clinician.
  • Operating, securing, debugging and improving the service.

We do not sell your personal information. We do not share your health data with advertisers, data brokers, or social platforms, and we do not use it to target advertising to you.

5. AI processing, specifically

When Foviq generates your daily plan, it sends a structured summary of your current context to a third-party AI model provider. That summary includes your estimated cycle phase, readiness score, recent logged metrics, goals, equipment, dietary restrictions and medical flags, and — if you wrote one — the free-text note from your daily log.

Your name, email address and date of birth are not sent. The model is only ever asked to choose from exercise and recipe options we supply it; it does not invent movements, and it never authors a calorie or macro figure. Those numbers are calculated by our own servers from ingredient data.

If AI generation fails or is unavailable, Foviq falls back to building your plan deterministically from our own libraries, with no model call at all.

If you would rather your data were not processed this way, you should not grant AI processing consent at onboarding. Note that some personalisation will be limited as a result.

6. Who else processes your data

We use the following categories of service provider. Each acts on our instructions.

  • Cloud database and authentication (United States region) — stores essentially all data described above and handles sign-in.
  • Application hosting — runs the application and produces server logs.
  • AI model provider — receives the plan-generation context described in section 5.
  • Transactional email — sends verification, password reset and account emails.
  • Bot protection — screens sign-up attempts. Receives your IP address.
  • Media delivery — serves exercise and recipe images. These contain no personal data.
  • Error monitoring — receives redacted diagnostic reports when something breaks.
  • Rate limiting — receives derived keys such as a hashed identifier to stop abuse.
  • Payments — when paid plans launch, a hosted checkout provider will process payment details. Foviq never receives or stores your card number.
  • Product analytics — marketing pages only, and only if you accept the cookie banner. Never on signed-in screens.

We may also disclose data where we are legally required to, or to protect the rights and safety of our users or ourselves. Given the sensitivity of reproductive health data, our position is to require valid legal process, to narrow any request as far as we reasonably can, and to notify you unless we are legally prohibited from doing so.

7. No tracking inside the app

There are no third-party analytics scripts, advertising pixels, or social media trackers on any signed-in screen of Foviq. This is enforced in our code, not merely as a policy commitment. Analytics exist only on our public marketing pages, only after you accept the cookie banner, and are not linked to your account or your health data.

8. How long we keep data

We keep your data for as long as your account exists. Consent records are retained as an immutable history even after a consent is withdrawn, because we need to be able to show what you agreed to and when.

We do not currently operate automated time-based deletion of older records such as historical plan generation logs. Implementing defined retention windows is planned work, and this section will be updated with specific periods when it ships.

9. Your choices and how to exercise them

You can view and edit your profile, goals, equipment, dietary restrictions and medical flags at any time in Settings. You can edit or delete individual daily logs and period entries directly.

Settings also contains controls to request a full export of your data and to request permanent deletion of your account. To be accurate about how these currently work: submitting either one records your request, and fulfilment is presently carried out manually by us rather than automatically. Automated fulfilment is in active development. If you have submitted a request and have not heard back, or you want either action carried out immediately, contact us at the address in section 12 and we will action it directly.

Deletion is permanent. Your profile, logs, cycle history, plans and sessions are removed. Consent records and any records we are required to retain for legal or accounting reasons may be kept.

Depending on where you live, you may have additional rights over your personal information, including the right to know what we hold, to correct it, to delete it, and to opt out of its sale or sharing. We do not sell or share personal information for cross-context behavioural advertising. To make any request, contact us at the address in section 12. We will not discriminate against you for exercising these rights.

10. Security

Data is encrypted in transit and at rest by our infrastructure providers. Access to your records is enforced at the database level: our access rules are written so that a signed-in user can read and write only their own rows, and this is covered by automated tests that specifically attempt cross-account access and assert that it fails.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by applicable law.

11. Children

Foviq is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.

12. Changes and contact

If we make a material change to how we handle your data, we will update the date at the top of this page and, where the change is significant, notify you in the app or by email. Where a change requires your consent, we will ask for it rather than assume it.

Questions, requests, or concerns about this policy or your data: privacy@foviq.com.

Privacy Policy — Foviq