Privacy Policy
Last Updated: November 1, 2025
Your Privacy Matters
PhaseTwin ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your information.
IMPORTANT: PhaseTwin is a wellness app and is NOT covered by HIPAA (Health Insurance Portability and Accountability Act). We are not a healthcare provider, health plan, or healthcare clearinghouse.
1. Information We Collect
Account Information
- Name, email address, phone number
- Team affiliation (coach, sport)
- School/institution
- Account credentials (hashed passwords)
Wellness & Performance Data
- Daily check-in responses (balance tests, reaction time, sit-to-stand performance)
- Biometric data you choose to share (heart rate, HRV, respiratory rate, temperature, sleep duration)
- Menstrual cycle data (last menstrual period, cycle phase estimates)
- Self-reported soreness and readiness levels
- Training calls (Push/Steady/Recover recommendations)
Usage Data
- Login times, pages visited, features used
- Device information (browser type, operating system)
- IP address and general location data
- AI chatbot conversations (with Luna and Dr. Audri)
Communications
- Feedback, bug reports, and support requests
- Pilot application information
2. How We Use Your Information
We use your data to:
- Provide the Service: Generate daily training recommendations, track readiness, display coach dashboards
- Improve the Service: Analyze usage patterns, fix bugs, develop new features
- AI Assistance: Power Luna and Dr. Audri chatbots (your conversations are sent to OpenAI's API)
- Communicate: Send updates about the pilot program, respond to inquiries
- Research: Analyze anonymized data to improve cycle-aware training algorithms (only with your explicit consent)
- Legal Compliance: Comply with applicable laws and legal requests
3. How We Share Your Information
With Your Coach
If you are an athlete, your coach has access to:
- Your daily training calls (Push/Steady/Recover)
- General readiness trends and patterns
- Aggregated team data
Coaches do NOT have access to: Your raw biometric data, specific menstrual cycle dates, or private AI chat conversations.
With Third-Party Services
- OpenAI: Your AI chat messages are sent to OpenAI's API to generate responses. OpenAI's privacy policy applies: openai.com/privacy
- Hosting Services: Data is stored on Replit's secure infrastructure
We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Legal Disclosures
We may disclose information if required by law, court order, or to protect rights and safety.
4. AI & OpenAI Data Processing
PhaseTwin uses OpenAI's GPT-4 to power Luna and Dr. Audri chatbots.
What this means:
- Your chat messages are sent to OpenAI's servers to generate AI responses
- OpenAI may temporarily process your messages but does not use them to train public models (per their data usage policy as of 2025)
- Do not share sensitive personal health information in AI chats
- AI responses are not stored permanently but may be logged for debugging during the pilot
Learn more: OpenAI Enterprise Privacy
5. Data Security
We implement security measures to protect your data:
- Encryption: Data is encrypted in transit (HTTPS/TLS)
- Password Protection: Passwords are hashed using industry-standard methods
- Access Controls: Limited team access to production data
- Secure Hosting: Data stored on Replit's secure infrastructure
However, no system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
6. Data Retention
- Active Accounts: Data retained as long as your account is active
- Pilot Program: Data collected during the 4-week pilot may be retained for analysis with your consent
- Deletion Requests: You may request data deletion at any time (see Your Rights below)
- Backups: Backup copies may persist for up to 90 days after deletion
7. Your Privacy Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Data Portability: Receive your data in a machine-readable format
- Opt-Out: Decline participation in research or data analysis
- Withdraw Consent: Withdraw consent for data processing at any time
To exercise these rights, contact: tavar24a@mtholyoke.edu
8. Children's Privacy
PhaseTwin is intended for users 18 years and older. We do not knowingly collect data from children under 13. If you are 13-17, you may use the Service only with parental consent.
9. Cookies & Tracking
We use session cookies to:
- Keep you logged in
- Remember your preferences
- Protect against CSRF attacks
We do not use third-party advertising cookies or trackers during the pilot phase.
10. Changes to This Policy
We may update this Privacy Policy. Continued use of the Service after changes constitutes acceptance. We will notify you of material changes via email or in-app notice.
11. Contact Us
Questions about privacy? Contact:
Adriana N. Tavarez
Mount Holyoke College
Email: tavar24a@mtholyoke.edu
Phone: +1 (914) 648-5926
By using PhaseTwin, you consent to the collection and use of information as described in this Privacy Policy.