Legal
Privacy Policy
Last updated: July 14, 2026
This Privacy Policy explains how Tandem DNA Marketing LLC (“we,” “us,” or “our”) collects, uses, stores, and shares information when you use TrainerDNA (the “Service”).
1. Information We Collect
We collect information you provide directly, information generated through your use of the Service, and information from third-party platforms you choose to connect. We do not collect data from social, calendar, payment, or video platforms unless you authorize that connection.
2. Account, Profile, and Workspace Data
When you create an account, we collect account information such as email address, authentication metadata, display name, workspace name, and profile details you enter. Workspace data may include business name, niche, target audience, offer details, pricing inputs, content preferences, schedules, growth notes, attribution data, AI prompts, and generated recommendations.
3. Client and Prospect Data
TrainerDNA lets you record client and prospect information such as names, contact details, goals, check-in notes, progress updates, testimonial text, proof notes, progress photos or media, and engagement status. You are responsible for having a lawful basis and any required consent before entering that information into TrainerDNA. We process it to provide the Service to you.
4. Connected Platform Data
If you connect Google Calendar, we may access calendar event information you authorize, such as event titles, times, descriptions, locations, attendees, and calendar metadata needed to show your schedule inside TrainerDNA. The initial connection requests read-only calendar access. If you separately enable scheduling, TrainerDNA also requests permission to create, update, and delete coaching-session events on calendars you own, add a Google Meet conference, and invite the client you select. TrainerDNA does not modify unrelated calendar events. Google push notifications tell TrainerDNA that a selected calendar changed; they do not contain the calendar event itself.
If you separately enable Google Meet Session Insights, TrainerDNA may read conference-record metadata for coaching calls associated with your connected account. This can include meeting start and end times, participant display names and join/leave times, and metadata or Google-provided open links for recordings and transcripts generated by Google. TrainerDNA does not download or store call audio, video, recording files, or transcript text through this feature.
If you connect Zoom, we may receive your Zoom user identifier, account label or email, OAuth scope information, and the meeting details needed to create and maintain coaching sessions. This can include the meeting identifier, topic, start time, duration, and secure participant and host URLs. Signed Zoom webhooks let us reconcile reschedules, completed meetings, cancellations, and app deauthorization. TrainerDNA does not record call audio or video through this connection.
If you connect TikTok, Instagram, Facebook, or YouTube, we may access the account identity, profile details, public content or media metadata, and performance metrics you authorize. Depending on the provider and permissions approved, this may include handles, avatars, follower or subscriber counts, video or post counts, views, likes, comments, shares, links, verification status, and recent public video or upload metrics.
If you connect Stripe, we may receive connected account identifiers, onboarding status, transaction or subscription metadata, customer identifiers, amounts, and limited card metadata such as last four digits. Stripe processes payment data under its own terms and privacy policy. We do not store full payment card numbers on our own servers.
If you are a TrainerDNA client and choose to connect Fitbit, TrainerDNA uses Google Health to read only the categories you authorize: steps, active minutes, active energy, sleep duration, resting heart rate, heart-rate variability, weight, and body-fat percentage. TrainerDNA does not request Google Health profile, email, location, nutrition, or write access. We synchronize after consent, when you select Sync now, and approximately daily; the initial and manual sync window is fourteen days and daily syncs recheck three overlapping days. Missing values remain empty. Imported Fitbit information and its source/update labels are visible to you and to the coach authorized for your TrainerDNA client relationship for progress coaching, not diagnosis or treatment.
TrainerDNA does not sell Google Health information or use it for advertising. TrainerDNA's use and transfer of information received from Google Health APIs will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
If you use the TrainerDNA mobile app and choose to connect Apple Health, TrainerDNA requests read-only access to the categories you select: steps, active energy, exercise time, sleep duration, resting heart rate, heart-rate variability, weight, and body-fat percentage. TrainerDNA does not write to Apple Health. If you connect Android Health Connect, TrainerDNA requests the matching read-only fitness, sleep, recovery, body-measurement, hydration, and nutrition categories shown in Android's permission screen. Access is requested only when you choose to connect or sync a source, not for advertising, marketing, diagnosis, or treatment.
Apple Health and Health Connect summaries remain attributed to their source and are visible only to you and the coach authorized for your TrainerDNA client relationship. Manual connected-app entries are labeled as manual and are not presented as wearable sensor readings. Disconnecting stops future sync; imported history remains available until you use the separate delete-imported-data action or request account deletion.
If you connect Oura, TrainerDNA requests Oura's daily access scope to read the activity, sleep, readiness, and related recovery summaries you authorize. TrainerDNA does not request your Oura email or personal-information scope and does not write data to Oura. Imported Oura summaries remain source-attributed and are visible only to you and the coach authorized for your TrainerDNA client relationship; they are used for coaching trends, not advertising, diagnosis, or treatment. Official Oura sandbox data may be used only in a protected Preview environment for testing and is visibly labeled as synthetic rather than as ring-sensor evidence.
5. OAuth Tokens and Connected Account Security
When you authorize a third-party connection, we may receive access tokens, refresh tokens, provider account identifiers, and granted scope information. Tokens are stored encrypted at rest where the Service persists them, used only to provide authorized sync and connection features, and removed from TrainerDNA when you disconnect the integration or request deletion. Previously imported health history may remain after disconnect so existing progress records stay understandable. The client can separately choose Delete imported data for that source. Where a provider supports token revocation, we attempt to revoke access as part of disconnect or deletion workflows.
6. Usage, Device, Cookies, and Logs
We may collect usage and technical information such as pages or features used, request timestamps, IP address, browser, device, operating system, errors, diagnostics, and security logs. We use necessary cookies and similar storage for authentication, security, preferences, and basic product functionality. We do not currently use advertising or retargeting pixels in the Service; if that changes, we will update this policy before using them.
7. Authentication and Communications
Authentication is handled by Supabase. Passwords are never stored by us in plaintext. Supabase may process session, IP, user agent, and login metadata to operate authentication and security. We may send transactional emails such as confirmations, password resets, security notices, deletion confirmations, and service updates through an email provider such as Resend. We do not send marketing emails unless you opt in.
8. How We Use Information
We use information to:
- Provide, operate, secure, and maintain TrainerDNA.
- Authenticate users and protect accounts and workspaces.
- Display connected calendar, social, video, payment, and workspace data.
- Generate AI-powered recommendations, content ideas, and business insights.
- Sync authorized third-party data and keep connection status current.
- Provide customer support and respond to deletion or privacy requests.
- Diagnose issues, prevent abuse, improve reliability, and comply with law.
9. AI Providers
TrainerDNA uses AI providers, such as Anthropic and any future AI provider we configure, to generate recommendations, content drafts, scoring, and summaries. We send only the information needed to provide the feature you use. AI outputs may be incomplete or inaccurate, and you should review them before acting on them or sharing them.
10. How We Share Information
We do not sell personal information, client data, Google user data, or social platform data. We share information only as described here:
- With service providers that host, store, secure, email, process payments, run AI inference, or otherwise help operate the Service.
- With third-party platforms you connect, only to exchange the information needed for the connection you authorized.
- When required by law, legal process, governmental request, platform policy, or to protect rights, safety, and security.
- In connection with a merger, acquisition, financing, restructuring, or sale of assets, with notice where required by law.
11. Third-Party Services
TrainerDNA relies on third-party services including Supabase (authentication, database, storage), Vercel (hosting), Stripe (payments), Anthropic (AI inference), Resend (email), Google Calendar, Google Health, Apple Health, Health Connect, Fitbit, Zoom, Oura, YouTube, TikTok, Instagram, Facebook, and Meta products you choose to connect. Each provider has its own terms and privacy policy. TrainerDNA is not affiliated with, endorsed by, or sponsored by these platforms unless explicitly stated.
12. International Transfers
Tandem DNA Marketing LLC is based in the United States. If you access TrainerDNA from outside the United States, your information may be processed and stored in the United States and other countries where we or our service providers operate. Those countries may have data protection laws different from your own. Where required, we rely on appropriate legal mechanisms and service-provider safeguards for international transfers.
13. Data Retention
We retain information for as long as your account is active or as needed to provide the Service. Account, workspace, client, proof, content, and business data are generally retained until you delete them, disconnect an integration, close your account, or request deletion. Social snapshots, calendar events, coaching session records, meeting-provider identifiers, encrypted join URLs, encrypted webhook payloads, sync logs, connection metadata, and diagnostics may be retained for a reasonable period for product functionality, security, support, and audit purposes.
Google Meet Session Insights metadata has a 90-day retention boundary and is removed when expired records are next processed. The separate Delete Meet history action removes imported conference, attendance, recording, and transcript metadata from TrainerDNA while leaving the coach's Google files unchanged. Disconnecting Google removes TrainerDNA's OAuth tokens and stops future Calendar and Meet access.
Disconnecting Fitbit attempts Google token revocation, deletes TrainerDNA's stored encrypted Fitbit OAuth tokens and provider identifier, marks the connection revoked, and stops future sync. Previously imported, source-attributed Fitbit summaries and samples remain available to the client and their authorized coach until the client separately selects Delete imported data or requests account deletion. A remote revocation failure does not prevent TrainerDNA from removing its local access tokens; the client can also remove TrainerDNA from Google Account permissions. We retain a minimal non-health audit event recording that disconnection occurred.
We may retain certain information after account closure where required by law, to resolve disputes, enforce agreements, prevent fraud or abuse, maintain security, or preserve anonymized or aggregated records that no longer identify you. Some data may also exist in browser localStorage; clearing browser storage removes that local copy.
14. Your Choices and Rights
You can update many profile and workspace details inside the Service. You can disconnect third-party integrations from TrainerDNA and revoke access from the connected provider's own account settings. To request account deletion, connected account deletion, access, correction, portability, restriction, objection, or withdrawal of consent, email support@trainerdna.app from the email address associated with your account.
Depending on where you live, you may have additional rights under privacy laws such as GDPR/UK GDPR, state privacy laws, or other local rules. We will process rights requests within a reasonable time and as required by applicable law. You can also review our data deletion instructions for provider-specific removal steps.
15. Security
We use safeguards designed to protect information, including encryption in transit, encrypted storage for persisted OAuth tokens, scoped OAuth permissions, access controls, and authentication protections. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials safe.
16. Children's Privacy
TrainerDNA is intended for adults and is not directed to children under 13 or the equivalent minimum age in your jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us so we can take appropriate action.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date and, where appropriate, notify you in the Service or by email. Continued use of TrainerDNA after changes take effect constitutes acceptance of the updated policy.
18. Contact
Questions or privacy requests can be sent to support@trainerdna.app. TrainerDNA is operated by Tandem DNA Marketing LLC.