Zome Privacy Policy
Last updated: 4 September 2026
Who we are: Phi Labs Technology Ltd, a company registered in Nigeria (RC 9063518), of Lagos, Nigeria ("Zome", "we"). We are the data controller for everything described here. Contact, including any data protection enquiry: privacy@myzome.app
The short version
- Your health data is held in the European Union, in Frankfurt, and it does not leave for the UK or EEA.
- We never sell it, and we do not advertise. There is no arrangement under which anybody pays us for access to it, and no advertiser, insurer or employer ever sees it.
- We never store your phone number, even when Zomy is texting you.
- A language model writes the wording of your plan and measures nothing. It never sees your name, your email, your phone number or your raw measurements.
- You can take everything with you, or delete all of it, from inside the app, in two taps. Deletion is immediate.
- You must be 18.
The rest of this document is the detail behind those six lines.
1. Definitions
These words carry these meanings wherever they appear in this policy with a capital letter. They are the same words the Terms of Service defines, so the two documents cannot drift apart on what they mean.
| Term | Meaning |
|---|---|
| Apple Health Data | The categories of health data listed in §3.2, read from Apple Health on your device only after you permit each category. |
| Health Data | Data concerning your physical or mental health. Under the NDPA this is sensitive personal data; under the UK and EU GDPR it is a special category of personal data. It includes Apple Health Data, your assessment answers and your Profile. |
| Personal Data | Any information relating to you as an identified or identifiable person. |
| Plan | The Proactive Path generated for you: a sequence of daily goals over a defined period. |
| Process | Anything done with Personal Data, including collecting, storing, using, sharing and deleting it. |
| Processor | A service provider that Processes Personal Data on our written instructions and for no purpose of its own. |
| Profile | Your age band, sex, height, weight, name and nickname. |
| we, us, our | Phi Labs Technology Ltd (RC 9063518), of Lagos, Nigeria, the controller of your Personal Data. |
| you, your | The person whose Personal Data this policy describes. |
2. In one paragraph
Zome reads what your body is already telling you — how much you move, how you sleep, what you eat, how you are feeling — and turns it into a plan for the next 28 days. Doing that means holding data about your health, which is the most strongly protected category of personal data there is. We hold as little of it as the product needs, we never sell it, no advertiser or insurer ever sees it, and you can delete all of it from inside the app in one action.
Zome is not a medical device and does not diagnose anything. See the Terms of Service.
Zome is not a doctor's surgery, and HIPAA does not apply to it. That law covers health plans, clearinghouses and providers who bill electronically; we are none of those. It is said here rather than only in the US section because people assume otherwise about anything holding health data, and the assumption should be corrected before it is relied on. What protects your data here is this policy, the Nigerian NDPA, and — because your data is held in the EU — the GDPR.
3. What we hold
3.1 What you give us
| What | Why we need it | Where it is |
|---|---|---|
| Email address | It is your account, and where your sign-in code goes | Our database |
| Password (optional) | So you can sign in without waiting for mail | Our database, in a form we cannot read back — never as you typed it |
| Age band, sex, height, weight | They change what a reasonable next step looks like. They never change a target. | Our database |
| Your name and nickname | To greet you | Our database |
| Assessment answers | Your plan is built from them | Our database |
| Food you log | To work out what you are eating | Our database |
| Phone number (only if you turn on messaging) | To send your daily goal by iMessage | Our database |
| Messages you send us by iMessage | To record whether you kept the day's goal | Our database |
3.2 What your phone gives us, once you allow it
Health data read from Apple Health. All of it is health data, which is the most strongly protected category there is, so here is the whole list rather than a summary of it:
| Category | What we read |
|---|---|
| Movement | Steps, distance walked or run, active energy burned |
| Exercise | Exercise minutes, workouts, and muscle-strengthening activity |
| Heart | Heart rate, resting heart rate, heart rate variability |
| Cardio fitness | VO₂max, where your phone or watch estimates it |
| Sleep | How long you slept and when |
| Body measurements | Height and weight |
You choose exactly which of these in Apple's own permission screen, and you can change your mind at any time in the Health app. We never receive anything you did not tick.
We do not receive your medical records. Nothing about diagnoses, medications, treatments, test results, reproductive or sexual health, or anything a clinician has written about you ever reaches us — Zome does not ask Apple Health for those categories at all.
3.3 What you tell us that is also health data
Your assessment answers include a validated well-being scale (WHO-5) and questions about how you have been feeling, sleeping, eating and moving. Your food logs record what you ate. Your profile records your age band, sex, height and weight.
These are health data too, and they get the same protection as anything read from your phone.
3.4 What we work out
Your Zome scores, your 28-day Proactive Path, and the reasoning behind them — including a measure of how confident we are in each score, given how much evidence it rests on.
These are inferences about your health, which makes them health data in their own right. They are held with everything else and deleted with it.
3.5 What we never collect
- Advertising identifiers. There is no advertising in Zome and no ad network.
- Your location. Zome never asks for it.
- Your contacts, photos, microphone or camera roll. The camera is used only to scan a barcode; that image is never stored and never leaves your phone.
- Third-party trackers. There are none in the app.
3.6 Apple Health data, specifically
Because Apple requires us to say so plainly, and because we mean it:
- We never use Apple Health data for advertising, marketing or any similar purpose.
- We never sell Apple Health data, or disclose it to data brokers or information resellers.
- We never share Apple Health data with a third party except the service providers in §6 that are necessary to run Zome for you.
- We use Apple Health data only to provide the health and fitness features you came for.
4. Which law applies, and why we are allowed to hold it
We are a Nigerian company, so the Nigeria Data Protection Act 2023 (NDPA) governs what we do, and the Nigeria Data Protection Commission (NDPC) is our supervisory authority. Health data is sensitive personal data under the NDPA and carries its strictest requirements.
Zome is offered worldwide, so other laws apply on top of the NDPA depending on where you are:
- United Kingdom and European Economic Area — the UK GDPR and EU GDPR apply to us because we offer the service to people there (Article 3(2)).
- United States — there is no single federal privacy law. State laws apply instead, and several treat health data as its own protected category. See §10.
Where these differ, we apply whichever is strictest, so you get the stronger protection wherever you are.
Under all of them we need a lawful basis, and for health data a further condition on top of it.
| What | Lawful basis | Condition for sensitive/health data |
|---|---|---|
| Email, password, sessions | Performance of our contract with you | Not health data |
| Health data from Apple Health | Contract, and your explicit consent | Explicit consent — NDPA s.30(1)(b); GDPR Art. 9(2)(a) |
| Assessment answers | Contract, and your explicit consent | Explicit consent |
| Profile (age band, sex, height, weight) | Contract, and your explicit consent | Explicit consent |
| iMessage reminders and your replies | Your explicit consent, given separately when you turn messaging on | Explicit consent |
| Rate limiting and abuse prevention | Legitimate interests — stopping people breaking into accounts | Not health data |
| Fault reporting | Legitimate interests — knowing when the product is broken | Not health data; see §6 |
| Usage analytics | Legitimate interests — knowing which parts of Zome are used | Not health data; see §6. You can turn it off in Settings → Privacy. |
Consent is recorded per purpose, and you can withdraw it. The database physically refuses to record health data without a live consent grant — it is enforced by the storage layer, not by a checkbox. Withdrawing consent stops new data being recorded. It does not by itself delete what is already there; for that, see §9.
4.1 Decisions made by a machine
Your Plan is generated automatically. An engine reads your scores and your Profile and selects the actions in it, and a language model writes the wording; neither is a person deciding something about you.
It is not a decision with legal or similarly significant effects. It suggests small daily actions. It does not price anything, refuse you anything, diagnose anything or report anything about you to anybody. Nothing in Zome grades your health or forms a view about you that follows you anywhere. So Article 22 of the UK and EU GDPR, which restricts decisions taken solely by automated means where they significantly affect somebody, does not apply to it.
We are telling you anyway, because a health app that quietly generates advice about your body from your measurements should say out loud that a machine is doing it. If you would rather a person looked at how your Plan was produced, write to privacy@myzome.app and one of us will.
5. Where it is, and when it leaves the country
Your data is stored in the European Union.
| Component | Location |
|---|---|
| Database (everything about you) | AWS eu-central-1, Frankfurt, Germany |
| Application servers | Frankfurt, Germany |
| Sign-in email delivery | eu-west-1, Ireland |
| Rate-limiting cache | Frankfurt, Germany |
| Fault reporting | See below |
| Usage analytics | Frankfurt, Germany |
| iMessage delivery | United States |
If you are in the UK or the EEA, your health data does not leave it. We chose Frankfurt over a cheaper US region for exactly this reason.
Two things still involve a transfer, and we would rather name them than imply otherwise:
- iMessage delivery is handled in the United States. It receives your phone number and the text of the reminders and your replies — never your health measurements, your scores or your plan. This only applies if you turn messaging on, and you can turn it off at any moment.
- Fault reporting carries stack traces. It is configured to exclude personal data and never receives health data.
As a Nigerian company we transfer your data out of Nigeria to hold it in the EU. We do so relying on the protection the EU regime provides and on the contractual terms each provider gives us, as the NDPA permits.
5.1 The safeguard we rely on
Where Personal Data of someone in the UK or the EEA reaches a Processor outside it, that transfer is made under the standard contractual clauses adopted by the European Commission, and under the UK International Data Transfer Addendum where the UK GDPR applies. Each such Processor is bound by them in its contract with us, in addition to the terms described in §6.
The two transfers this applies to are named in the list above. You may ask for a copy of the clauses that cover a particular transfer by writing to privacy@myzome.app, and we will provide them, with commercial terms removed.
We name locations rather than companies. If you need to know which provider handles a particular component, ask us at privacy@myzome.app.
6. Who else sees it
Only the services that run Zome, each acting as our processor under a contract that binds them to our instructions. We describe them by what they do rather than by name:
| What they do | What they get | Why |
|---|---|---|
| Our database and application hosting | Everything, because the product runs on it | Zome cannot run without it |
| Rate limiting | No personal data, only counters that stand for an account or a device | To stop somebody guessing their way into accounts |
| Email delivery | Your email address and a six-digit code | To send you the code |
| iMessage delivery | Your phone number and the text of the reminders and replies | To deliver iMessage, only if you turn it on |
| Food barcode lookup | The barcode you scanned, and nothing else | To look up the food |
| Fault reporting (United States) | Fault reports, configured to exclude personal data | To know when Zome is broken |
| Usage analytics (European Union) | Which screens are used and how far people get, with no identifier attached | To know which parts of Zome are worth building on |
| Language model (see below) | Your scores, the shape of your plan and your stated barriers | To word your plan |
The barcode lookup receives a barcode and nothing about you — no account, no identifier, no history.
Fault reporting is configured not to collect personal data, and it never receives health data.
Usage analytics never receives health data, and is not about you. It is a fixed list of things that can happen in the app — a screen opened, a goal ticked, an assessment finished — and the list is written into the app's source in one file. It carries no name, no email, no phone number, no measurement and no words from your plan. It is not linked to your account: events are counted and never gathered into a person, so nobody at Zome can look up what you in particular did. It is held in Frankfurt with everything else. You can turn it off at any time in Settings → Privacy, and turning it off stops it on your phone immediately rather than asking us to stop later.
We may occasionally ask you a question in the app, such as how you are finding something. Answering is optional, answers go to the same place in Frankfurt, and they are not linked to your account. We do not ask about your health there: the assessment is where health questions belong, because that is what you gave explicit consent for. If a question ever has a free-text box, please do not put anything about your health in it. Turning off usage data in Settings → Privacy turns these off too.
If you need the identity of a specific processor, ask us at privacy@myzome.app and we will tell you.
Artificial intelligence
Zome uses a language model to write the wording of your plan. It never measures anything: it cannot compute a score, invent an observation, override a confidence figure, or produce a plan that did not pass validation. Every number in Zome is produced by deterministic rules, and the model only chooses words for what those rules already decided.
The model receives your Zome scores, the shape of your plan and your stated barriers. It never receives your email, your name, your phone number or your raw health measurements.
We do not sell your data. We do not share it with advertisers, insurers, employers or data brokers. There is no arrangement under which anybody pays us for access to it.
7. How long we keep it
| What | How long |
|---|---|
| Your account and everything in it | Until you delete it |
| Sign-in codes | 10 minutes, then deleted; single use |
| Sessions | 30 days, or until you sign out |
| iMessage events and check-ins | 12 months, then deleted |
| Webhook delivery records | 30 days — long enough to stop a duplicate, no longer |
| Database change history (for restore) | 6 hours |
| Fault reports | 90 days |
| Record that an account was deleted | Kept, with nothing in it that identifies you |
8. How it is protected
Your data is encrypted in transit and encrypted at rest. Passwords and session tokens are stored in a form we cannot read back, so neither we nor anybody who obtained a copy of the database could recover them. Sign-in is rate limited to make guessing impractical, and an account locks after repeated wrong attempts.
If you lose a device you can end every session at once from inside the app, without waiting for anything to expire.
We keep the specifics of how this is implemented out of this document on purpose. Naming a particular algorithm here would turn a security decision into a published commitment we would have to keep accurate as the product changes, and would tell an attacker more than it tells you.
9. What you can make us do
You have the right to see what we hold about you, correct it, have it deleted, restrict or object to how it is used, take it elsewhere, and withdraw consent.
Deletion is in the app. Settings → Account → Delete account. It removes your observations, derived metrics, cycles, plans, food logs, assessment answers, messaging records, consents and every session, in one database transaction. It cannot be undone, there is no grace period, and there is no archived copy.
What survives is a single line recording that an account was deleted at a particular time, with nothing in it that connects to you. That is what lets us evidence the deletion without keeping you.
To withdraw consent for messaging, reply STOP to any message, or turn it off in the app. We stop immediately and permanently, and we do not treat a later reply as permission to start again.
For anything else, write to privacy@myzome.app. We answer within one month, as GDPR requires.
You can also complain to a regulator: in Nigeria, the Nigeria Data Protection Commission (ndpc.gov.ng); in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, your national authority.
When you delete your account, one thing is outside our reach. Everything we hold goes immediately. The service that delivers iMessage holds the same conversation, and your phone number, which we have never stored. We record a request to erase it and pass it on; until they act, their own retention applies. And data your phone has already saved into Apple Health belongs to your phone, not to us. Remove it in the Health app.
10. If you are in the United States
HIPAA does not apply to Zome. HIPAA covers health plans, clearinghouses and health-care providers who bill electronically, and their contractors. We are none of those, so your data is not "protected health information" under HIPAA. That does not leave it unprotected — it means a different set of rules applies, set out below.
10.1 Consumer health data
Several states now regulate consumer health data specifically, most notably Washington's My Health My Data Act, Nevada SB 370, and Connecticut's health-data amendments. Wherever you live in the US, we apply their standard to everyone:
- We collect your health data only with your consent, given separately from everything else, and only for the purposes you consented to.
- We do not sell your health data. Not for money, not for anything else of value. We would need your signed authorisation to do so, and we do not ask for one because we do not do it.
- We do not share your health data except with the service providers in §6 who are contractually bound to process it only on our instructions.
- You can withdraw consent and have your health data deleted, from inside the app.
- We do not use geofencing around any health facility, for any purpose.
10.2 Your rights under state privacy laws
If you live in California, Colorado, Connecticut, Delaware, Montana, Oregon, Texas, Utah, Virginia or another state with a comprehensive privacy law, you have the right to know what we hold, get a copy, correct it, delete it, and opt out of its sale or of targeted advertising.
We make the last one easy: there is nothing to opt out of. We do not sell personal information, we do not share it for cross-context behavioural advertising, and there is no advertising in Zome at all.
Under the California Consumer Privacy Act, health data and precise identifiers are sensitive personal information. We use yours only to provide the service you asked for — never to infer characteristics about you, and never for advertising. We do not offer financial incentives for data, and we will not discriminate against you for exercising any right.
To exercise any of these, write to privacy@myzome.app. We will verify it is you before we act, and we will answer within the time your state's law allows.
10.3 If there is ever a breach
As a health app outside HIPAA, we are covered by the FTC Health Breach Notification Rule. If your health data is ever acquired without your authorisation, we will notify you, the Federal Trade Commission, and — where the Rule requires it — the media, within the deadlines it sets.
11. Children
Zome is for adults. You must be 18 or over to use it, and we do not knowingly hold data about anyone younger. If we discover we have, we delete it.
Eighteen rather than thirteen, deliberately. Nigeria's NDPA treats anyone under 18 as a child and requires verifiable parental consent before processing their data — and "verifiable" means a real mechanism, not a checkbox. In the EEA the threshold moves between 13 and 16 depending on the country, so a single lower number would be lawful in Ireland and not in Germany. Setting the bar at 18 means one rule everywhere, no parental-consent machinery to build, and no country where we are quietly non-compliant.
We ask you to confirm it when you set the account up, and we record that you confirmed it — not your date of birth. The question is a yes or no, so the answer is stored as one. A birthday would be the strongest identifier in your account, collected to answer something a single yes already answers.
12. Changes
If we change this policy in a way that affects what we do with your data, we will tell you in the app before it takes effect, and you will be asked to agree again where the law requires it.
