How we handle your data.
Last updated August 21, 2026
This policy explains what personal data Phorme collects, why we use it, who can receive it, how we protect it, and how you can control or delete it. For any question or request, email support@phor.me.
Phorme is operated by Elite Locker LLC.
What we collect.
- Account and profile details, such as your name, phone number, email, age, and training preferences.
- Workouts, programs, check-ins, messages, nutrition entries, and other content or activity you choose to create.
- Purchase, subscription, device, log, and basic analytics data needed to operate, secure, and improve the service.
- When you connect a professional social account, the account identifier, username, access token, comments, messages, automation activity, and delivery status needed to run the features you enable.
Health and wearable data.
Phorme accesses health and fitness data only after you turn on Apple Health or affirmatively connect a provider account such as Google Health/Fitbit, Oura, Garmin, Whoop, or Strava. Depending on what you connect and permit, this may include sleep duration and efficiency, heart-rate variability, resting heart rate, steps, active calories, workouts, and provider recovery or readiness scores. We also store the provider account identifier, permissions, encrypted OAuth credentials, and synchronization status needed to maintain that connection.
We normalize those readings into daily recovery summaries to show your trends, prefill check-ins, and personalize training and recovery guidance. Phorme is a fitness and coaching product, not a medical device, and this information is not used to diagnose or treat a condition.
Journey analytics and social profiles.
Phorme records first-party journey events such as pages made visible, links selected, forms completed, app installation and use, purchases, onboarding, programs, workouts, renewals, cancellations, and delivery of service messages. We connect those events only when we have a reliable identifier, such as your signed-in account, a verified contact, an app installation identifier, a payment-customer identifier, or a social messaging contact. An Instagram referrer by itself does not tell us which account visited a page.
When you interact with a connected creator account, apply, or give us a social handle, approved providers may supply permitted public profile facts and non-sensitive signals such as training interests, movement goals, content themes, language, creator affinity, or broad regional context. Inferred fields are labeled with their source and confidence. We do not infer sensitive individual traits such as age, gender, income, race or ethnicity, religion, politics, sexuality, disability, medical conditions, biometric identity, or precise location. Creator-facing demographic reporting is aggregated and small cohorts are suppressed.
You can review this use or turn off profile enrichment from the social profile privacy control. You may also ask us to correct an attribute or remove a profile by emailing support@phor.me.
How we use personal data.
- To provide your account, workouts, programs, coaching, recovery insights, and connected-device synchronization.
- To personalize recommendations and improve features you use.
- To process purchases, provide support, and answer your requests.
- To deliver, route, and measure social messaging automations you configure.
- To keep the service secure and prevent abuse.
Who receives data.
- Service providers acting for Phorme may process only the data necessary to host the product, store data, operate authentication, process payments, deliver messages, monitor reliability, or generate the coaching experience.
- If you choose a coach, trainer, or gym relationship in Phorme, the people you authorize may see relevant workout and daily recovery summaries to provide that coaching. They do not receive your wearable account password or OAuth token.
- We may disclose data when required by law or necessary to protect users, Phorme, or the public.
We do not sell health data, provide it to data brokers, or use it for advertising, credit, lending, or human-subject research. Our use of information received from Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements.
Storage, security, and retention.
Data is transmitted over HTTPS. Wearable credentials receive application-level authenticated encryption at rest and are unavailable to the client app. Access is restricted to systems and personnel that need it to operate or secure the service. Operational wearable webhook receipts are automatically deleted after 30 days. We retain account and training data while your account is active, and for only as long afterward as needed for the purposes above, legal obligations, dispute resolution, and security.
Your choices and deletion.
You can turn off a wearable connection from Your devices at any time. That stops future collection and deletes Phorme's stored connection credentials; previously synchronized daily summaries remain part of your training history until you delete your account or ask us to erase them. Deleting your Phorme account revokes connected provider access where the provider supports it and deletes your wearable connections, daily metrics, and other user-owned data from our active systems.
Use the in-app Delete account control or visit phor.me/delete-account. For access, correction, portability, objection, or deletion requests, email support@phor.me. You can also reach every inbox from the contact page. Disconnecting a social account stops access and removes its token. A verified platform deletion request removes the associated social automation data.
Children and changes.
Phorme is not directed to children under 13. We may update this policy as the product or applicable rules change. Material changes will be identified here by a new effective date and, when appropriate, an in-product notice.