---
title: "Privacy Policy | Agents4"
description: "Agents4 Fitness Privacy Policy — how we collect, use, and protect your data on the AI coaching platform."
source: https://agents4fitness.com/privacy.html
site: Agents4 (agents4fitness.com)
---

# Privacy Policy

Last updated: August 13, 2026

**Agents4 Fitness**

**Last Updated: August 13, 2026**

**Effective Date: March 18, 2026**

## Introduction

Agents4 Fitness LLC ("Agents4 Fitness," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and protect your personal information when you use the Agents4 Fitness mobile application, website, APIs, and related services (collectively, the "Platform").

This Privacy Policy is incorporated into and subject to our [Terms of Service](https://agents4fitness.com/terms.html). By creating an account or using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Platform.

## Table of Contents

1. [Information We Collect](#section-1)
2. [How We Collect Information](#section-2)
3. [How We Use Your Information](#section-3)
4. [Sensitive Health Information](#section-4)
5. [How We Share Your Information](#section-5)
6. [Third-Party Service Providers](#section-6)
7. [AI Processing and Automated Decision-Making](#section-7)
8. [Data Storage and Security](#section-8)
9. [Data Retention](#section-9)
10. [Your Rights and Choices](#section-10)
11. [State-Specific Privacy Rights (US)](#section-11)
12. [International Users and Data Transfers](#section-12)
13. [Children's Privacy](#section-13)
14. [Device Permissions](#section-14)
15. [Cookies and Tracking Technologies](#section-15)
16. [Do Not Track Signals](#section-16)
17. [Third-Party Links and Services](#section-17)
18. [Changes to This Privacy Policy](#section-18)
19. [Contact Us](#section-19)

## 1. Information We Collect

We collect several categories of personal information to provide and improve the Platform. The specific information we collect depends on your account type (Client or Trainer/Creator) and how you use the Platform.

### 1.1 Account and Identity Information

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Registration data | Name, email address, username, password (stored as bcrypt hash — we never store plaintext passwords) | You, at signup |
| Profile information | Display name, bio, profile photo, contact preferences | You, in settings |
| Account type | Client or Trainer role designation | You, at signup |
| Professional credentials | Certifications, qualifications, specializations (Trainers only) | Trainers, in profile |
| Optional trainer invitation data | Invitation codes or referral-style trainer linkage information you voluntarily enter during signup so we can connect your account to a coach when applicable | You, during signup |

### 1.2 Health and Fitness Data

**This is the most sensitive category of data we collect. Please review this section carefully.**

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Body metrics | Weight, height, body fat percentage, body measurements (chest, waist, hip, arm, thigh), body composition data (lean mass, DEXA results) | You, via check-ins and profile |
| Exercise data | Workout logs, sets, reps, weights, exercise history, personal records, workout compliance, training days per week | You and AI-generated plans |
| Nutrition data | Calorie targets, macronutrient intake (protein, carbs, fat), meal plans, food items consumed, dietary restrictions, supplement intake and preferences, calorie cycling preferences | You and AI-generated plans |
| Daily check-in data | Date, day type (training/rest/cardio), weight, sleep hours, energy level (1–10), stress level (1–10), fatigue level (1–10), mood (1–10), hunger level, water intake, recovery feeling, strength feeling, cardio completion, notes | You, via daily check-ins |
| Weekly assessment data | Aggregate weekly metrics, summary mood, energy, adherence scores | You, via weekly check-ins |
| Progress photos | Date-stamped body progress photographs | You, via check-in uploads |
| Exercise form videos | Video recordings of exercise performance for AI form analysis | You, via video upload |
| Biometric wearable data | Heart rate variability (HRV), resting heart rate (RHR), sleep duration and efficiency, sleep stages, recovery scores, strain scores, activity levels, step counts, workout detection, device sync timestamps, and data staleness indicators (hours since last sync) | Third-party wearable devices and health platforms (WHOOP, Oura Ring, Garmin, Apple Watch, Fitbit, Google Fit, Apple Health / HealthKit, Polar) via OAuth or platform permissions |
| Readiness assessments | Daily readiness state (green/yellow/orange/red), session adjustment recommendations, volume and intensity modifiers, RPE caps, signal confidence scores, predicted next-day readiness | Calculated by Platform from your data |
| Menstrual cycle data | Last period start date, cycle length, current cycle phase (menstrual, follicular, ovulatory, luteal), hormonal contraceptive use | You, via profile or check-in |
| Medication status | GLP-1 receptor agonist use (e.g., semaglutide, tirzepatide), medication type, dose, side effects, other medications relevant to exercise | You, via profile or agent interaction |
| Medical history | Known medical conditions, injuries, contraindications (including prenatal contraindication flags such as cervical insufficiency, placenta previa, preeclampsia, preterm labor risk, persistent bleeding, severe anemia, and uncontrolled hypertension), surgical history (e.g., bariatric surgery, cesarean section), pregnancy status, trimester, postpartum phase, post-cesarean section recovery status, medical clearance flags | You, via intake forms and profile |
| Mental wellness data | Mood scores (1–10), stress scores, energy levels, sleep quality ratings, mood trends over time. Mood data may be used to automatically suggest workout types tailored to your current emotional state (e.g., high-stress moods may trigger lower-intensity workout suggestions) | You, via check-ins and mood tracking |
| Sport-specific data | Primary sport, competition dates, weight class, current level, recovery priority | You, via intake forms |
| Neurodivergent profile | Neurodivergent type (if disclosed), sensory preferences, medication status related to ADHD/autism/dyspraxia | You, voluntarily via intake forms |
| Longevity metrics | Grip strength, VO2max estimates, Zone 2 cardio minutes, dead hang duration, sit-to-stand times | You, via agent interaction |
| Dietary medical conditions | Celiac disease, Crohn's disease, IBS, food allergies, FODMAP requirements, eating disorder history | You, via intake forms |

### 1.3 Financial and Transaction Data

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Subscription information | Plan tier (Launchpad/Pro Coach/Empire), billing cycle, subscription status, trial status | Your subscription choices |
| Transaction history | AI credit purchases, top-ups, auto-refill transactions, marketplace subscriptions | Payment processing |
| Marketplace earnings | Revenue earned, payout amounts, payout status (Creators/Trainers only) | Platform calculations |
| Stripe identifiers | Stripe Customer ID, Stripe Connect Account ID, subscription IDs | Stripe |

**Important: We do NOT store your complete credit card number, CVV, or banking details on our servers.** All payment processing is handled by Stripe, Inc., which is PCI-DSS Level 1 certified. We only store Stripe-generated identifiers and transaction metadata.

### 1.4 Communication Data

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Trainer-client messages | Direct messages, group messages, scheduled messages, message read status, delivery status | You and your Trainer |
| AI agent conversations | Chat messages with AI coaching agents, tool invocations, AI-generated responses, session history | You and AI systems |
| Messaging channel data | Linked WhatsApp phone numbers, Discord user IDs, message content and metadata, account-linking tokens, delivery events, and one-time passcodes used to verify ownership of a messaging account | You and supported messaging providers |
| Notification preferences | Push notification settings, email preferences, quiet hours | You, in settings |
| Reviews and feedback | Marketplace agent reviews, trainer reviews, star ratings, review titles and body text, "helpful" votes | You, when submitting reviews |

### 1.5 Device and Technical Information

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Device information | Device type (iOS/Android), device model, operating system version, app version | Automatically collected |
| Push notification tokens | Firebase Cloud Messaging (FCM) device tokens for delivering push notifications | Automatically upon notification opt-in |
| Pseudonymous analytics identifier | Firebase-generated app instance identifier used to distinguish app installations; not your Agents4 username and not GAID/advertising ID | Automatically collected by Firebase Analytics |
| Timezone | Inferred from device settings for scheduling and display purposes | Automatically collected |
| Error and crash data | App crash reports, error stack traces, performance metrics (collected via Sentry and Firebase Crashlytics with PII filtering — see Section 1.7) | Automatically collected |

### 1.6 Usage and Analytics Data

| Data Type | Examples | Collected From |
| --- | --- | --- |
| Feature usage | Screens viewed, features accessed, AI credit consumption, check-in submission events, chat message events, streaming fallback events. Event telemetry excludes message contents, raw error text, URLs, and direct account/client/recipient identifiers. | Automatically collected via Firebase Analytics and internal server analytics |
| Marketplace activity | Agent searches, agent views, subscription events, recommendation interactions | Automatically collected |
| Automation analytics | Automation rule executions, trigger events, action outcomes, impact metrics | Automatically collected |
| Engagement metrics | Login frequency, session duration, feature adoption patterns | Automatically collected |

### 1.7 Error Tracking Data (Sentry and Firebase Crashlytics)

We use Sentry and Firebase Crashlytics for error tracking and performance monitoring. These services are configured with privacy protections:

- **PII transmission is disabled** (`send_default_pii` is set to `false` in our Sentry configuration).
- **Sensitive data is stripped** before transmission: Authorization headers, cookies, query string parameters, passwords, and authentication tokens are removed from error reports.
- **Performance monitoring** samples approximately 10% of transactions in production.
- **Breadcrumbs** (contextual events leading to an error) are limited to 50 per transaction and do not contain personal health data.

### 1.8 Information We Do NOT Collect

- **Precise geolocation** (GPS coordinates) — we do not track your physical location
- **Advertising identifiers** — we do not collect IDFA, GAID, or similar ad tracking identifiers
- **Contacts or address book** — we do not access your phone's contact list
- **Browsing history** — we do not track your activity outside the Platform
- **Biometric authentication data** — Face ID/fingerprint data is processed entirely on your device by the operating system and is never transmitted to our servers

## 2. How We Collect Information

### 2.1 Information You Provide Directly

Most information is collected when you actively provide it: creating an account, optionally entering a trainer invitation code during signup, completing intake forms, submitting check-ins, uploading photos or videos, sending messages, writing reviews, or configuring your profile and preferences.

### 2.2 Information Collected Automatically

Device information, usage analytics, error reports, and performance data are collected automatically when you use the Platform.

### 2.3 Information from Third-Party Sources

When you connect a wearable device or health platform (WHOOP, Oura, Garmin, Apple Watch, Fitbit, Google Fit, Apple Health / HealthKit, or Polar), we retrieve health and fitness data from that provider's API or permission framework on your behalf. When you link a supported messaging channel such as WhatsApp or Discord, we receive the identifiers, verification events, and messages necessary to authenticate your account and deliver coaching interactions through that channel. These connections are initiated by you and can be revoked at any time.

### 2.4 Information Generated by the Platform

The Platform generates derived data from your inputs, including readiness scores, adherence percentages, trend analyses, predicted readiness, progress analytics, and AI-generated coaching content.

### 2.5 Information from Your Trainer

If you are a Client, your assigned Trainer may input or modify information about you, such as training plans, nutrition plans, check-in feedback, notes, and persona configurations.

## 3. How We Use Your Information

We use your personal information for the following purposes:

### 3.1 Providing the Platform Services

- Creating and managing your account
- Processing optional trainer invitation codes and linking your account to a coach when you provide one
- Generating AI-powered workout plans, nutrition plans, and coaching responses
- Calculating readiness scores, trend analyses, and predictive assessments
- Performing AI exercise form analysis on uploaded videos
- Processing daily and weekly check-ins
- Syncing and displaying wearable device data
- Linking and authenticating WhatsApp and Discord accounts using one-time passcodes or similar verification steps
- Matching you with appropriate Marketplace Agents based on your goals, preferences, and health profile
- Facilitating Trainer-Client communication
- Delivering coaching interactions across supported channels, including the native app, WhatsApp, and Discord
- Executing Trainer-configured Automations (sending messages, notifications, and plan adjustments based on triggers)
- Processing payments, subscriptions, and Creator payouts
- Delivering push notifications, email notifications, and in-app alerts

### 3.2 Personalization

- Tailoring AI Agent responses to your fitness level, goals, health conditions, and preferences
- Customizing Marketplace Agent recommendations
- Adapting training intensity based on readiness scores and wearable data
- Providing cycle-synced, medication-aware, or condition-specific guidance when applicable
- Mapping mood and mental wellness check-in data to workout type suggestions (e.g., high-anxiety states may trigger strength-focused suggestions, low-energy states may trigger lighter movement suggestions)

### 3.3 Platform Improvement

- Analyzing aggregate usage patterns to improve features and user experience
- Identifying and fixing bugs, errors, and performance issues
- Developing new features and services
- Conducting internal analytics and research using aggregated or anonymized data

### 3.4 Safety and Security

- Detecting and preventing fraud, abuse, and unauthorized access
- Enforcing our Terms of Service and Acceptable Use Policy
- Investigating reports of harmful content or behavior
- Rate-limiting API requests to prevent abuse

### 3.5 Communications

- Sending transactional communications (account verification, password resets, billing confirmations, subscription updates, trial expiration notices, and messaging-channel account-linking codes)
- Sending Trainer-initiated communications (check-in reminders, workout notifications, coaching messages)
- Delivering coaching and support communications through the native app and, if you link them, through supported channels such as WhatsApp and Discord
- Sending optional promotional or product-update communications only where you have requested them or consented to receive them
- Sending system notifications (Platform updates, policy changes, security alerts)

### 3.6 Legal Compliance

- Complying with applicable laws, regulations, and legal processes
- Responding to lawful requests from government authorities
- Generating tax reporting documents (e.g., IRS Form 1099 for Creators)

## 4. Sensitive Health Information

### 4.1 Special Treatment of Health Data

We recognize that much of the data collected by the Platform constitutes sensitive health information. We treat Health Data (as defined in our Terms of Service) with heightened care:

- **Purpose limitation**: Health Data is used solely for providing fitness coaching services, generating personalized recommendations, and operating the Platform. We do not sell Health Data.
- **Access controls**: Health Data is accessible only to you, your assigned Trainer (if applicable), and authorized Platform systems. Agents4 Fitness employees access Health Data only when necessary for technical support, safety investigations, or legal compliance.
- **Encryption in transit**: All Health Data is transmitted over HTTPS/TLS encrypted connections.
- **Wearable token encryption**: OAuth tokens for wearable device connections are encrypted using Google Cloud Key Management Service (KMS).

### 4.2 HIPAA Disclaimer

Agents4 Fitness is NOT a "covered entity" or "business associate" as defined under the Health Insurance Portability and Accountability Act (HIPAA). The Platform is a fitness and wellness technology service — not a healthcare provider, health plan, or healthcare clearinghouse. Health Data stored on the Platform is not subject to HIPAA protections. If you require HIPAA-compliant health data management, the Platform is not appropriate for that purpose.

### 4.3 Voluntary Disclosure

All Health Data you provide to the Platform is provided voluntarily. You are not required to disclose medication status, menstrual cycle data, medical history, pregnancy status, neurodivergent status, or any other sensitive health information to use the Platform. However, withholding relevant health information may result in less accurate or less safe AI-generated recommendations.

### 4.4 Health Data and AI Processing

Your Health Data is processed by AI systems to generate personalized coaching content. This means your health information — including medical conditions, medications, cycle data, mood assessments, and body metrics — is used as input to large language models and machine learning algorithms. While we implement safeguards, AI processing of health data involves inherent risks described in our Terms of Service, Section 5 (AI-Generated Content Disclaimer).

## 5. How We Share Your Information

### 5.1 We Do NOT Sell Your Personal Information

Agents4 Fitness does not sell your personal information, including Health Data, to third parties for monetary or other valuable consideration.

### 5.2 Sharing with Your Trainer

If you are a Client with an assigned Trainer, your Trainer has access to:

- Your profile information, intake form responses, and preferences
- Daily and weekly check-in data, including progress photos
- Wearable device metrics and readiness scores
- Workout and nutrition plan compliance data
- AI agent conversation summaries (as visible in trainer dashboards)
- Mood, stress, energy, and sleep trends
- Medication status and medical history you have provided
- Menstrual cycle data (if provided)

**Your Trainer is an independent service provider, not an employee or agent of Agents4 Fitness.** We require Trainers to agree to our Terms of Service, which include obligations regarding data handling, but we cannot fully control how Trainers use information they access through the Platform. If you terminate your relationship with a Trainer, their direct access through the Platform is restricted, but we cannot retrieve information the Trainer may have previously viewed, downloaded, or recorded outside the Platform.

### 5.3 Sharing with Marketplace Creators

If you subscribe to a Marketplace Agent, the Creator of that Agent may have access to aggregate subscriber analytics (subscriber count, retention rates, engagement metrics). **Creators do NOT have access to your individual Health Data, personal information, or conversation history with their Agent** unless they are also your assigned Trainer.

### 5.4 Sharing with Service Providers

We share information with third-party service providers who process data on our behalf to operate the Platform. These providers are contractually obligated to use your information only for the services they provide to us. See Section 6 for details.

### 5.5 Sharing for Legal Reasons

We may disclose your information if required to do so by law or in response to valid legal process, including:

- Court orders, subpoenas, or warrants
- Requests from law enforcement or government agencies
- To protect the rights, property, or safety of Agents4 Fitness, our Users, or the public
- To enforce our Terms of Service
- In connection with an investigation of fraud, intellectual property infringement, or other illegal activity

### 5.6 Business Transfers

If Agents4 Fitness is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and any choices you may have regarding your information.

### 5.7 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. For example, we may publish statistics about Platform usage, aggregate fitness trends, or Marketplace analytics. This data is not considered personal information.

### 5.8 Advertising and Conversion Measurement Partners

When you interact with our advertising or sign up or subscribe after clicking an ad, we share a limited set of event and conversion data with our advertising partner, **Meta Platforms, Inc.**, to measure and optimize our campaigns, as described in Section 15.4. Identifiers such as your email address and phone number are **cryptographically hashed (SHA‑256)** before transmission, and we never share your Health Data for advertising. Under certain U.S. state privacy laws this activity may be considered "sharing" for "targeted advertising" or "cross-context behavioral advertising"; you may opt out as described in Section 15.4 and Section 11. This is not a "sale" of your personal information for monetary consideration (see Section 5.1).

## 6. Third-Party Service Providers

We use the following categories of third-party service providers to operate the Platform:

### 6.1 Cloud Infrastructure and Database

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Google Cloud Platform (GCP)** | Primary cloud infrastructure, compute, and networking | All Platform data |
| **Google Cloud Firestore** | Primary database for user accounts, health data, plans, messages, marketplace data, and all structured data | All structured personal data |
| **Google Cloud Storage (GCS)** | Storage for progress photos, profile photos, gallery images, exercise videos, knowledge base files | Photos, videos, documents |
| **Google Cloud Key Management Service (KMS)** | Encryption of sensitive credentials (wearable OAuth tokens) | OAuth tokens |

### 6.2 AI and Machine Learning

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Google Vertex AI (Gemini)** | AI model powering coaching agents, form analysis, plan generation, and conversational AI | Health data, fitness data, conversation messages, exercise videos (for form analysis) |
| **Weaviate** | Vector database for retrieval-augmented generation (RAG) knowledge search | Trainer knowledge base documents (PDFs, transcripts), embeddings |

### 6.3 Payment Processing

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Stripe, Inc.** | Payment processing, subscription billing, Creator payouts (via Stripe Connect), customer portal, webhook event processing | Payment method details, billing addresses, transaction amounts, subscription status, payout information |

Stripe is PCI-DSS Level 1 certified. Your payment card information is collected and processed directly by Stripe and is never stored on Agents4 Fitness servers. Please review [Stripe's Privacy Policy](https://stripe.com/privacy) for details on their data practices.

### 6.4 Communication Services

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Firebase Cloud Messaging (FCM)** | Push notification delivery to iOS and Android devices | Device push tokens, notification content |
| **Resend** | Transactional email delivery (billing notifications, progress reports, check-in reminders, password resets) | Email addresses, email content, attachment data (up to 25 MB) |
| **Slack** (Trainer-configured) | Trainer webhook notifications for readiness alerts, automation events, check-in submissions | Notification content (configured by Trainer) |
| **Twilio** | WhatsApp messaging delivery, verification workflows, and webhook processing where Twilio is the configured WhatsApp provider | Phone numbers, message content, delivery metadata, verification events |
| **Meta WhatsApp Business Platform / Cloud API** | WhatsApp message delivery and receipt, webhook processing, and account linking where Meta is the configured WhatsApp provider | Phone numbers, message content, delivery metadata, verification events |
| **Discord** | Discord message delivery and receipt, account linking, and bot interactions | Discord user IDs, message content, delivery metadata |
| **Meta Platforms, Inc.** (Advertising & measurement) | Ad performance measurement, optimization, and remarketing via the Meta Pixel (marketing pages) and the Meta Conversions API (server-side conversion events). See Sections 5.8 and 15.4. | SHA‑256 hashed email/phone/user ID, browser & click identifiers (`_fbp`/`_fbc`), IP address, user agent, event name/value/source URL. No Health Data; no plaintext contact details. |

### 6.5 Error Tracking and Monitoring

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Sentry** | Backend error tracking and performance monitoring | Error reports, stack traces, performance metrics (PII stripped before transmission — authorization headers, cookies, passwords, and tokens are removed) |
| **Firebase Crashlytics** | Mobile app crash reporting | Crash reports, device information, app state at time of crash |

### 6.6 Product Analytics

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Firebase Analytics** | Aggregate mobile feature-usage and reliability measurement | Screen names, feature events, app/device metadata, and a pseudonymous app instance identifier. Agents4 account IDs, message contents, raw error text, URLs, and advertising identifiers are excluded from event telemetry. |

### 6.7 Wearable Device Providers

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **WHOOP** | Wearable data sync (recovery, strain, sleep) | OAuth tokens (KMS-encrypted), health metrics |
| **Oura** | Wearable data sync (readiness, HRV, sleep) | OAuth tokens (KMS-encrypted), health metrics |
| **Garmin** | Wearable data sync (activity, sleep, health) | OAuth tokens (KMS-encrypted), health metrics |
| **Apple Health / HealthKit** | Health data sync (heart rate, steps, workouts, weight) | Health metrics (processed on-device and synced with your permission) |
| **Fitbit** | Wearable data sync (activity, heart rate, sleep) | OAuth tokens (KMS-encrypted), health metrics |
| **Google Fit** | Wearable and health platform data sync (activity, heart rate, sleep, workouts) | OAuth tokens (KMS-encrypted), health metrics |
| **Polar** | Wearable data sync | OAuth tokens (KMS-encrypted), health metrics |

When you connect a wearable device, you authorize that provider to share your data with Agents4 Fitness through their API. Each provider has their own privacy policy governing their collection and use of your data.

### 6.8 App Distribution

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **Expo (expo.dev)** | Over-the-air (OTA) app updates, build infrastructure | App version, device platform, update metadata |
| **Apple App Store / Google Play Store** | App distribution | As governed by Apple/Google privacy policies |

### 6.9 Video Content (Trainer-Initiated)

| Provider | Purpose | Data Processed |
| --- | --- | --- |
| **YouTube** (Trainer OAuth) | Knowledge base video ingestion — Trainers connect YouTube channels to import exercise videos and transcripts for their Agent's knowledge base | YouTube channel metadata, video transcripts (PII-scrubbed during ingestion: emails and phone numbers are removed from transcripts before indexing) |

## 7. AI Processing and Automated Decision-Making

### 7.1 How AI Processes Your Data

The Platform uses artificial intelligence extensively to deliver its core services. Your personal information, including Health Data, is processed by AI systems in the following ways:

1. **Conversational AI Coaching**: When you chat with an AI Agent, your messages, health profile, check-in history, workout data, nutrition data, wearable metrics, and other relevant information may be included as context for the AI model to generate personalized responses.
2. **Plan Generation**: AI systems use your body metrics, goals, experience level, medical history, dietary restrictions, and preferences to generate workout and nutrition plans.
3. **Readiness Scoring**: The Platform combines wearable data, check-in data, and historical patterns to calculate daily readiness scores and predict future readiness using algorithmic and AI-based methods.
4. **Form Analysis**: Exercise form videos you upload are processed by AI vision models to evaluate movement quality and provide feedback.
5. **Agent Matching**: The recommendation engine uses your goals, medical conditions, dietary needs, experience level, gender, age range, and other profile data to score and rank Marketplace Agents for you.
6. **Automation Triggers**: Trainer-configured Automations may use your data (readiness state, check-in status, wearable sync status, compliance metrics) to trigger automated actions.

### 7.2 Automated Decision-Making

The Platform uses automated decision-making in the following areas:

- **Readiness assessments**: Your daily readiness state (green/yellow/orange/red) is calculated automatically based on check-in and wearable data. This may result in modified training recommendations (e.g., reduced volume or intensity).
- **Automation execution**: Trainer-configured rules may automatically send you messages, notifications, or plan adjustments based on data-driven triggers without per-action human review.
- **Agent recommendations**: Marketplace Agent matching is algorithmically generated based on your profile.

These automated decisions do not have legal or similarly significant effects on you. They affect fitness recommendations only, which you are free to accept or disregard. You always retain the ability to contact your Trainer for human-reviewed guidance.

### 7.3 AI Data Processing by Third Parties

AI-generated content is produced using Google Vertex AI (Gemini models). When your data is processed by these models:

- Your data is transmitted to Google Cloud servers for processing
- Google's AI data usage policies apply (Google does not use customer data submitted through Vertex AI to train its foundation models)
- Processing occurs within the Google Cloud infrastructure region configured for our project

## 8. Data Storage and Security

### 8.1 Where Your Data Is Stored

Your data is stored on:

- **Google Cloud Firestore** (structured data — account info, health data, plans, messages, marketplace data)
- **Google Cloud Storage** (unstructured data — photos, videos, documents)
- **Weaviate** (vector embeddings for knowledge search)
- **Stripe** (payment data — processed and stored by Stripe on their infrastructure)

All primary data storage is on Google Cloud Platform infrastructure located in the United States.

### 8.2 Security Measures

We implement the following security measures to protect your data:

1. **Encryption in Transit**: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
2. **Credential Encryption**: Wearable device OAuth tokens are encrypted at rest using Google Cloud Key Management Service (KMS). Passwords are hashed using bcrypt (industry-standard one-way hashing — we cannot read your password).
3. **Authentication and Access Control**: API access requires Bearer token authentication. Rate limiting is applied to prevent abuse (e.g., photo uploads limited to 50 per hour). Trainer concurrent request limits are enforced.
4. **PII Filtering in Logs**: Our logging infrastructure masks sensitive fields (email, phone, password, access tokens, refresh tokens) before writing log entries. Error tracking (Sentry) is configured to strip authorization headers, cookies, and tokens before transmission.
5. **Knowledge Base PII Scrubbing**: When Trainers upload content to the knowledge base (including YouTube transcripts), email addresses and phone numbers are automatically detected and removed during the ingestion pipeline before indexing.
6. **Photo Access Controls**: Client progress photos are stored in private cloud storage buckets with time-limited signed URLs (60-minute expiration). Trainer profile and gallery photos designated as public are stored separately.
7. **Image Processing Limits**: Uploaded images are validated for format (JPEG, PNG, WebP only), size (maximum 12 MB), and dimensions (maximum 1920px width) to prevent abuse.

### 8.3 Security Limitations

No system is 100% secure. While we implement reasonable security measures, we cannot guarantee that your data will never be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. You provide personal information, including Health Data, at your own risk.

If we become aware of a security breach that affects your personal information, we will notify you in accordance with applicable law.

## 9. Data Retention

### 9.1 General Retention Principles

We retain your personal information for as long as necessary to:

- Provide the Platform services to you
- Maintain your account and its associated data
- Comply with our legal and regulatory obligations
- Resolve disputes and enforce our agreements
- Maintain business records as required by law

### 9.2 Retention Periods by Data Type

| Data Category | Retention Period |
| --- | --- |
| **Account information** | Retained while your account is active, plus 90 days after account deletion to allow for account recovery |
| **Health and fitness data** (check-ins, body metrics, plans, readiness scores) | Retained while your account is active. Deleted upon account deletion request, subject to legal retention requirements |
| **Progress photos and videos** | Retained while your account is active. Deleted from cloud storage upon account deletion request |
| **Wearable data** | Retained while your account is active. Default sync range is 30 days of historical data per sync. Deletable via data deletion request (see Section 10) |
| **AI conversation history** | Retained while your account is active for continuity of coaching experience |
| **Financial records** | Retained for seven (7) years after the transaction date, as required by tax and financial regulations |
| **Communication data** (messages) | Retained while your account is active and both parties' accounts exist |
| **Reviews** | Retained while the reviewed entity (Trainer or Agent) exists on the Platform, even if the reviewer's account is deleted (reviews may be anonymized) |
| **Error and crash reports** | Retained by Sentry and Firebase Crashlytics per their respective retention policies (typically 90 days for event data) |
| **Usage analytics** | Retained in aggregate/anonymized form indefinitely. Individual-level analytics retained while your account is active |
| **Audit logs** (MCP, automation execution) | Retained for one (1) year |

### 9.3 Post-Deletion Retention

After you request account deletion:

- We will delete or anonymize your personal information within thirty (30) days, except where retention is required by law or for legitimate business purposes (e.g., financial records, fraud prevention, ongoing legal proceedings).
- Aggregated and anonymized data that cannot be used to identify you may be retained indefinitely.
- Data that has been included in backups may persist in backup systems until those backups are rotated, but will not be actively used.
- Content you shared with others (messages to Trainers, reviews) may persist in anonymized form.

## 10. Your Rights and Choices

### 10.1 Access Your Data

You may request a copy of the personal information we hold about you. For wearable data specifically, you can use the in-app data export feature (`Export My Wearable Data`), which provides a JSON export of your wearable connections, synced health data, and sync logs (excluding sensitive OAuth tokens).

### 10.2 Correct Your Data

You may update or correct your personal information at any time through the Platform's settings and profile screens. If you believe data is inaccurate and cannot correct it yourself, contact us.

### 10.3 Delete Your Data

You may request deletion of your account and personal data by:

- Using the account deletion feature in the Platform's settings
- Using the in-app `Delete All My Wearable Data` feature for wearable-specific data (which permanently removes all wearable connections, synced data, and sync logs)
- Contacting us at [admin@agents4.com](mailto:admin@agents4.com)

Upon receiving a deletion request, we will delete or anonymize your data within thirty (30) days, subject to the retention exceptions described in Section 9.3.

### 10.4 Data Portability

You may request a portable copy of your data in a structured, machine-readable format (JSON). This includes health data, check-in history, and wearable data. Contact us to initiate a data export request.

### 10.5 Disconnect Wearable Devices

You may disconnect any wearable device at any time through the Platform's wearable settings. Disconnecting stops future data retrieval from that device but does not automatically delete previously synced data. To delete synced wearable data, use the deletion feature described in Section 10.3.

### 10.6 Notification Preferences

You may control notifications through:

- **Push notifications**: Enable or disable via device settings or in-app notification preferences
- **Email notifications**: Manage preferences in your account settings
- **Automation notifications**: Discuss with your Trainer to adjust automation rules, or contact support

### 10.7 Opt Out of AI Processing

If you wish to opt out of AI-driven features (such as AI coaching, readiness predictions, or automated recommendations), please contact us. Note that opting out of AI processing will substantially limit the Platform's functionality, as AI-powered coaching is a core service.

### 10.8 Close Your Account

You may close your account at any time. See Section 19 of our Terms of Service for details on the effect of account termination.

## 11. State-Specific Privacy Rights (US)

### 11.1 California Residents — CCPA / CPRA

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

1. **Right to Know**: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
2. **Right to Delete**: You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, fraud prevention, exercising legal rights).
3. **Right to Correct**: You have the right to request correction of inaccurate personal information.
4. **Right to Opt Out of Sale/Sharing**: **We do not sell your personal information.** We do not share your personal information for cross-context behavioral advertising.
5. **Right to Limit Use of Sensitive Personal Information**: Much of the data collected by the Platform (health data, biometric data) constitutes "sensitive personal information" under CPRA. We use sensitive personal information only as necessary to provide the services you request (fitness coaching and related features). You have the right to limit our use of sensitive personal information to purposes that are necessary and expected.
6. **Right to Non-Discrimination**: We will not discriminate against you for exercising your privacy rights.

**To exercise your CCPA/CPRA rights**, contact us at [admin@agents4.com](mailto:admin@agents4.com) or use the in-app Data Privacy controls. We will verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf.

**Categories of Personal Information Collected** (per CCPA categories):

- A: Identifiers (name, email, username)
- B: Personal information in Cal. Civ. Code &sect; 1798.80 (name, address, phone)
- D: Commercial information (transaction history, subscriptions)
- F: Internet or other electronic network activity (usage data, feature interactions)
- G: Geolocation data (timezone only — not precise location)
- H: Sensory data (photos, videos, audio)
- I: Professional or employment information (Trainer credentials)
- K: Inferences drawn from above (readiness scores, trend analyses, recommendations)
- Sensitive: Health data, biometric data (wearable metrics)

**Shine the Light**: California Civil Code &sect; 1798.83 permits California residents to request information about personal information disclosed to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.

### 11.2 Virginia, Colorado, Connecticut, and Other State Privacy Laws

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or another state with comprehensive privacy legislation, you may have similar rights including:

- Right to access and obtain a copy of your personal data
- Right to correct inaccuracies
- Right to delete your personal data
- Right to data portability
- Right to opt out of targeted advertising (we do not engage in targeted advertising)
- Right to opt out of the sale of personal data (we do not sell personal data)
- Right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (our automated decisions affect fitness recommendations only, not legal or financial outcomes)
- Right to appeal a denial of a privacy request

To exercise any of these rights, contact us at [admin@agents4.com](mailto:admin@agents4.com).

### 11.3 Health Data Privacy Laws

Certain states have enacted health data privacy laws that may apply to the Platform:

1. **Washington My Health My Data Act**: If you are a Washington State resident, we collect and use consumer health data only with your consent (provided when you create an account and use health-related features). You have the right to withdraw consent and request deletion of your health data. This Privacy Policy is also intended to function as our consumer health data privacy policy. The categories of consumer health data we collect are described in Sections 1.2 and 4, the categories of sources are described in Section 2, the purposes of collection and use are described in Sections 3 and 7, and the categories of third parties and service providers with whom consumer health data may be shared are described in Sections 5 and 6, including cloud infrastructure providers, AI providers, messaging providers you choose to link, and wearable or health platform providers you choose to connect.
2. **Other State Health Privacy Laws**: We comply with applicable state-level health data privacy requirements. If your state has enacted health data privacy legislation, your rights under that legislation apply in addition to the rights described in this Privacy Policy.

## 12. International Users and Data Transfers

### 12.1 Data Transfer to the United States

If you access the Platform from outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States, where our servers and service providers are located. Data protection laws in the United States may differ from those in your country of residence.

### 12.2 European Economic Area (EEA), United Kingdom, and Switzerland

If you are located in the EEA, UK, or Switzerland, the following applies:

1. **Legal Basis for Processing**: We process your personal data based on: **Consent**: For processing Health Data, connecting wearable devices, linking third-party messaging channels, and sending optional promotional or product-update communications where you opt in. You may withdraw consent at any time.
2. **Contractual necessity**: For processing necessary to provide the Platform services you requested (account management, plan generation, billing).
3. **Legitimate interests**: For analytics, security, fraud prevention, and Platform improvement, where our interests are not overridden by your rights.
4. **Legal obligation**: For tax reporting, law enforcement requests, and compliance.
5. **Data Subject Rights under GDPR**: You have the right to: Access your personal data
6. Rectify inaccurate data
7. Erase your data ("right to be forgotten")
8. Restrict processing
9. Data portability
10. Object to processing based on legitimate interests
11. Withdraw consent at any time
12. Lodge a complaint with your local supervisory authority
13. **Data Transfers**: Data is transferred to the United States pursuant to appropriate safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognized transfer mechanisms.
14. **Data Protection Officer**: If required by GDPR based on the nature and scale of our processing activities, we will appoint a Data Protection Officer. Contact us at [admin@agents4.com](mailto:admin@agents4.com) for DPO inquiries.

### 12.3 Other International Jurisdictions

We endeavor to comply with applicable data protection laws in all jurisdictions where the Platform is available. If you believe your local data protection rights are not adequately addressed in this Privacy Policy, please contact us.

## 13. Children's Privacy

### 13.1 Age Restriction

The Platform is not directed to and is not intended for use by individuals under eighteen (18) years of age (or the age of majority in your jurisdiction, whichever is greater). We do not knowingly collect personal information from children.

### 13.2 Parental Notification

If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [admin@agents4.com](mailto:admin@agents4.com).

### 13.3 COPPA Compliance

In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. The Platform's collection of health data, body measurements, photos, and biometrics makes it particularly unsuitable for use by minors.

## 14. Device Permissions

The Platform may request the following device permissions:

### 14.1 iOS Permissions

| Permission | Purpose | Required? |
| --- | --- | --- |
| **Camera** | Take progress photos for fitness check-ins | Optional — only needed for photo check-ins |
| **Photo Library** | Upload progress photos from your library | Optional — only needed for photo uploads |
| **Apple Health (Read)** | Sync health data (heart rate, steps, workouts, weight) for personalized coaching | Optional — only needed for Apple Health integration |
| **Apple Health (Write)** | Save workout and weight data back to Apple Health | Optional |
| **Microphone** | Record voice messages for hands-free workout logging | Optional — only needed for voice features |
| **Face ID / Touch ID** | Biometric app unlock for quick access | Optional — biometric data stays on-device |
| **Push Notifications** | Receive coaching alerts, check-in reminders, readiness notifications | Optional but recommended |

### 14.2 Android Permissions

| Permission | Purpose | Required? |
| --- | --- | --- |
| **Camera** | Take progress photos for fitness check-ins | Optional |
| **Storage (Read/Write)** | Access and save photos and documents | Optional |
| **Activity Recognition** | Detect physical activity for wearable integration | Optional — only needed for wearable features |
| **Vibrate** | Haptic feedback for notifications | Automatic |
| **Biometric** | Fingerprint/face unlock for quick access | Optional — biometric data stays on-device |
| **Microphone** | Record voice messages for hands-free workout logging | Optional |
| **Receive Boot Completed** | Resume scheduled notifications after device restart | Automatic |
| **Push Notifications** | Receive coaching alerts and reminders | Optional but recommended |

### 14.3 Permission Control

All optional permissions are requested only when you attempt to use the corresponding feature. You can revoke any permission at any time through your device's system settings. Revoking a permission will disable the feature that depends on it but will not affect other Platform functionality.

## 15. Cookies and Tracking Technologies

### 15.1 Mobile App

The Agents4 Fitness mobile application is a native mobile app and does **not** use browser cookies. Authentication is managed through encrypted tokens stored in secure device storage (SecureStore for sensitive data, MMKV for general preferences).

### 15.2 Web Interfaces

If you access Platform web interfaces (such as the Stripe billing portal or password reset pages), those pages may use:

- **Strictly necessary cookies**: For authentication, session management, and security (e.g., Stripe's payment session cookies)
- **Advertising and measurement cookies (marketing pages only)**: Our marketing and paid-acquisition landing pages (for example, agents4fitness.com and `/c/` campaign pages) use the Meta (Facebook) Pixel, which sets first-party advertising identifiers (such as `_fbp`) and reads click identifiers (such as `fbclid`/`_fbc`) to measure ad performance. See Section 15.4 for details and your opt-out choices. The Agents4 Fitness application itself does not use advertising cookies.

### 15.3 Analytics

We use Firebase Analytics in the native mobile app and internal server analytics to understand aggregate feature usage and reliability. Mobile events use a pseudonymous app instance identifier and exclude Agents4 account IDs, message contents, raw error text, URLs, and advertising identifiers. These analytics do not use browser cookies, cross-site tracking, or targeted advertising.

### 15.4 Advertising, Marketing Pixels, and Conversion Measurement

To promote the Platform and measure the effectiveness of our advertising, our marketing website and paid-acquisition landing pages use the **Meta (Facebook) Pixel**, and our servers send conversion events to **Meta Platforms, Inc.** through the **Meta Conversions API**. This advertising activity is used only for measurement, optimization, and remarketing — it is not used to deliver the coaching service itself.

The information shared with Meta may include: events you trigger (such as viewing a landing page or starting a subscription), the event value and source URL, browser/click identifiers (`_fbp` and `_fbc`/`fbclid`), your IP address and user agent, and a one-way **SHA‑256 hashed** version of identifiers such as your email address, phone number, and a pseudonymous user ID. We do **not** send Meta your name, your plaintext email or phone number, or any Health Data. Hashing is applied before transmission, so Meta receives only irreversible representations of these identifiers for ad-matching purposes.

**Your choices:** You can limit or opt out of this advertising activity by adjusting your [Meta ad preferences](https://www.facebook.com/adpreferences), using the industry opt-out tools at [DAA WebChoices](https://optout.aboutads.info/) and [NAI](https://optout.networkadvertising.org/), enabling your browser's tracking-prevention or cookie controls, or using your device's "Limit Ad Tracking" / "Opt out of Ads Personalization" setting. Opting out does not affect your ability to use the Platform. (We do not currently run TikTok or Google advertising tags; if we add other advertising partners, we will update this section and the providers list in Section 6.)

## 16. Do Not Track Signals

The Platform does not currently respond to "Do Not Track" (DNT) browser signals, as there is no industry-standard protocol for DNT compliance. Aside from the advertising-measurement activity on our marketing and landing pages described in Section 15.4 — which you can opt out of, and which we treat opt-out preference and Global Privacy Control (GPC) signals as a request to limit — we do not track your activity across unaffiliated third-party websites.

## 17. Third-Party Links and Services

The Platform may contain links to or integrations with third-party websites, services, or applications (including wearable device platforms, Stripe billing portal, YouTube, and Slack). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Platform.

## 18. Changes to This Privacy Policy

### 18.1 Notification of Changes

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:

- Posting the updated Privacy Policy on the Platform with a new "Last Updated" date
- Sending you an email notification to the address associated with your account
- Displaying an in-app notice

### 18.2 Material Changes

Material changes include but are not limited to: new categories of data collection, new purposes for data processing, new third-party data sharing, changes to your privacy rights, or changes to data retention practices.

### 18.3 Continued Use

Your continued use of the Platform after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated Privacy Policy, you must stop using the Platform and request account deletion.

## 19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

**Agents4 Fitness LLC**

**General Privacy Inquiries:** Email: [admin@agents4.com](mailto:admin@agents4.com)

**Data Access, Correction, or Deletion Requests:** Email: [admin@agents4.com](mailto:admin@agents4.com) Subject line: "Data Request — [Access/Correction/Deletion]"

**Security Concerns or Data Breach Reports:** Email: [admin@agents4.com](mailto:admin@agents4.com)

**Legal Inquiries:** Email: [admin@agents4.com](mailto:admin@agents4.com)

**Mailing Address:** 5511 Parkcrest Dr. Suite 103, Austin, TX 78731

**Response Time**: We will acknowledge your request within five (5) business days and aim to fulfill verified requests within thirty (30) days, or within the time frame required by applicable law.

*This Privacy Policy was last updated on March 18, 2026.*
