← Back to Agents4

Privacy Policy

Last updated: June 23, 2026

Agents4 Fitness

Last Updated: June 23, 2026

Effective Date: March 18, 2026

Introduction

Agents4 Fitness LLC ("Agents4 Fitness," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and protect your personal information when you use the Agents4 Fitness mobile application, website, APIs, and related services (collectively, the "Platform").

This Privacy Policy is incorporated into and subject to our Terms of Service. By creating an account or using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Platform.

Table of Contents

  1. Information We Collect
  2. How We Collect Information
  3. How We Use Your Information
  4. Sensitive Health Information
  5. How We Share Your Information
  6. Third-Party Service Providers
  7. AI Processing and Automated Decision-Making
  8. Data Storage and Security
  9. Data Retention
  10. Your Rights and Choices
  11. State-Specific Privacy Rights (US)
  12. International Users and Data Transfers
  13. Children's Privacy
  14. Device Permissions
  15. Cookies and Tracking Technologies
  16. Do Not Track Signals
  17. Third-Party Links and Services
  18. Changes to This Privacy Policy
  19. Contact Us

1. Information We Collect

We collect several categories of personal information to provide and improve the Platform. The specific information we collect depends on your account type (Client or Trainer/Creator) and how you use the Platform.

1.1 Account and Identity Information

Data TypeExamplesCollected From
Registration dataName, email address, username, password (stored as bcrypt hash — we never store plaintext passwords)You, at signup
Profile informationDisplay name, bio, profile photo, contact preferencesYou, in settings
Account typeClient or Trainer role designationYou, at signup
Professional credentialsCertifications, qualifications, specializations (Trainers only)Trainers, in profile
Optional trainer invitation dataInvitation codes or referral-style trainer linkage information you voluntarily enter during signup so we can connect your account to a coach when applicableYou, during signup

1.2 Health and Fitness Data

This is the most sensitive category of data we collect. Please review this section carefully.

Data TypeExamplesCollected From
Body metricsWeight, height, body fat percentage, body measurements (chest, waist, hip, arm, thigh), body composition data (lean mass, DEXA results)You, via check-ins and profile
Exercise dataWorkout logs, sets, reps, weights, exercise history, personal records, workout compliance, training days per weekYou and AI-generated plans
Nutrition dataCalorie targets, macronutrient intake (protein, carbs, fat), meal plans, food items consumed, dietary restrictions, supplement intake and preferences, calorie cycling preferencesYou and AI-generated plans
Daily check-in dataDate, day type (training/rest/cardio), weight, sleep hours, energy level (1–10), stress level (1–10), fatigue level (1–10), mood (1–10), hunger level, water intake, recovery feeling, strength feeling, cardio completion, notesYou, via daily check-ins
Weekly assessment dataAggregate weekly metrics, summary mood, energy, adherence scoresYou, via weekly check-ins
Progress photosDate-stamped body progress photographsYou, via check-in uploads
Exercise form videosVideo recordings of exercise performance for AI form analysisYou, via video upload
Biometric wearable dataHeart rate variability (HRV), resting heart rate (RHR), sleep duration and efficiency, sleep stages, recovery scores, strain scores, activity levels, step counts, workout detection, device sync timestamps, and data staleness indicators (hours since last sync)Third-party wearable devices and health platforms (WHOOP, Oura Ring, Garmin, Apple Watch, Fitbit, Google Fit, Apple Health / HealthKit, Polar) via OAuth or platform permissions
Readiness assessmentsDaily readiness state (green/yellow/orange/red), session adjustment recommendations, volume and intensity modifiers, RPE caps, signal confidence scores, predicted next-day readinessCalculated by Platform from your data
Menstrual cycle dataLast period start date, cycle length, current cycle phase (menstrual, follicular, ovulatory, luteal), hormonal contraceptive useYou, via profile or check-in
Medication statusGLP-1 receptor agonist use (e.g., semaglutide, tirzepatide), medication type, dose, side effects, other medications relevant to exerciseYou, via profile or agent interaction
Medical historyKnown medical conditions, injuries, contraindications (including prenatal contraindication flags such as cervical insufficiency, placenta previa, preeclampsia, preterm labor risk, persistent bleeding, severe anemia, and uncontrolled hypertension), surgical history (e.g., bariatric surgery, cesarean section), pregnancy status, trimester, postpartum phase, post-cesarean section recovery status, medical clearance flagsYou, via intake forms and profile
Mental wellness dataMood scores (1–10), stress scores, energy levels, sleep quality ratings, mood trends over time. Mood data may be used to automatically suggest workout types tailored to your current emotional state (e.g., high-stress moods may trigger lower-intensity workout suggestions)You, via check-ins and mood tracking
Sport-specific dataPrimary sport, competition dates, weight class, current level, recovery priorityYou, via intake forms
Neurodivergent profileNeurodivergent type (if disclosed), sensory preferences, medication status related to ADHD/autism/dyspraxiaYou, voluntarily via intake forms
Longevity metricsGrip strength, VO2max estimates, Zone 2 cardio minutes, dead hang duration, sit-to-stand timesYou, via agent interaction
Dietary medical conditionsCeliac disease, Crohn's disease, IBS, food allergies, FODMAP requirements, eating disorder historyYou, via intake forms

1.3 Financial and Transaction Data

Data TypeExamplesCollected From
Subscription informationPlan tier (Launchpad/Pro Coach/Empire), billing cycle, subscription status, trial statusYour subscription choices
Transaction historyAI credit purchases, top-ups, auto-refill transactions, marketplace subscriptionsPayment processing
Marketplace earningsRevenue earned, payout amounts, payout status (Creators/Trainers only)Platform calculations
Stripe identifiersStripe Customer ID, Stripe Connect Account ID, subscription IDsStripe

Important: We do NOT store your complete credit card number, CVV, or banking details on our servers. All payment processing is handled by Stripe, Inc., which is PCI-DSS Level 1 certified. We only store Stripe-generated identifiers and transaction metadata.

1.4 Communication Data

Data TypeExamplesCollected From
Trainer-client messagesDirect messages, group messages, scheduled messages, message read status, delivery statusYou and your Trainer
AI agent conversationsChat messages with AI coaching agents, tool invocations, AI-generated responses, session historyYou and AI systems
Messaging channel dataLinked WhatsApp phone numbers, Discord user IDs, message content and metadata, account-linking tokens, delivery events, and one-time passcodes used to verify ownership of a messaging accountYou and supported messaging providers
Notification preferencesPush notification settings, email preferences, quiet hoursYou, in settings
Reviews and feedbackMarketplace agent reviews, trainer reviews, star ratings, review titles and body text, "helpful" votesYou, when submitting reviews

1.5 Device and Technical Information

Data TypeExamplesCollected From
Device informationDevice type (iOS/Android), device model, operating system version, app versionAutomatically collected
Push notification tokensFirebase Cloud Messaging (FCM) device tokens for delivering push notificationsAutomatically upon notification opt-in
TimezoneInferred from device settings for scheduling and display purposesAutomatically collected
Error and crash dataApp crash reports, error stack traces, performance metrics (collected via Sentry and Firebase Crashlytics with PII filtering — see Section 1.7)Automatically collected

1.6 Usage and Analytics Data

Data TypeExamplesCollected From
Feature usageScreens viewed, features accessed, AI credit consumption, check-in submission events, chat message events, streaming fallback eventsAutomatically collected via internal analytics
Marketplace activityAgent searches, agent views, subscription events, recommendation interactionsAutomatically collected
Automation analyticsAutomation rule executions, trigger events, action outcomes, impact metricsAutomatically collected
Engagement metricsLogin frequency, session duration, feature adoption patternsAutomatically collected

1.7 Error Tracking Data (Sentry and Firebase Crashlytics)

We use Sentry and Firebase Crashlytics for error tracking and performance monitoring. These services are configured with privacy protections:

1.8 Information We Do NOT Collect

2. How We Collect Information

2.1 Information You Provide Directly

Most information is collected when you actively provide it: creating an account, optionally entering a trainer invitation code during signup, completing intake forms, submitting check-ins, uploading photos or videos, sending messages, writing reviews, or configuring your profile and preferences.

2.2 Information Collected Automatically

Device information, usage analytics, error reports, and performance data are collected automatically when you use the Platform.

2.3 Information from Third-Party Sources

When you connect a wearable device or health platform (WHOOP, Oura, Garmin, Apple Watch, Fitbit, Google Fit, Apple Health / HealthKit, or Polar), we retrieve health and fitness data from that provider's API or permission framework on your behalf. When you link a supported messaging channel such as WhatsApp or Discord, we receive the identifiers, verification events, and messages necessary to authenticate your account and deliver coaching interactions through that channel. These connections are initiated by you and can be revoked at any time.

2.4 Information Generated by the Platform

The Platform generates derived data from your inputs, including readiness scores, adherence percentages, trend analyses, predicted readiness, progress analytics, and AI-generated coaching content.

2.5 Information from Your Trainer

If you are a Client, your assigned Trainer may input or modify information about you, such as training plans, nutrition plans, check-in feedback, notes, and persona configurations.

3. How We Use Your Information

We use your personal information for the following purposes:

3.1 Providing the Platform Services

3.2 Personalization

3.3 Platform Improvement

3.4 Safety and Security

3.5 Communications

3.6 Legal Compliance

4. Sensitive Health Information

4.1 Special Treatment of Health Data

We recognize that much of the data collected by the Platform constitutes sensitive health information. We treat Health Data (as defined in our Terms of Service) with heightened care:

4.2 HIPAA Disclaimer

Agents4 Fitness is NOT a "covered entity" or "business associate" as defined under the Health Insurance Portability and Accountability Act (HIPAA). The Platform is a fitness and wellness technology service — not a healthcare provider, health plan, or healthcare clearinghouse. Health Data stored on the Platform is not subject to HIPAA protections. If you require HIPAA-compliant health data management, the Platform is not appropriate for that purpose.

4.3 Voluntary Disclosure

All Health Data you provide to the Platform is provided voluntarily. You are not required to disclose medication status, menstrual cycle data, medical history, pregnancy status, neurodivergent status, or any other sensitive health information to use the Platform. However, withholding relevant health information may result in less accurate or less safe AI-generated recommendations.

4.4 Health Data and AI Processing

Your Health Data is processed by AI systems to generate personalized coaching content. This means your health information — including medical conditions, medications, cycle data, mood assessments, and body metrics — is used as input to large language models and machine learning algorithms. While we implement safeguards, AI processing of health data involves inherent risks described in our Terms of Service, Section 5 (AI-Generated Content Disclaimer).

5. How We Share Your Information

5.1 We Do NOT Sell Your Personal Information

Agents4 Fitness does not sell your personal information, including Health Data, to third parties for monetary or other valuable consideration.

5.2 Sharing with Your Trainer

If you are a Client with an assigned Trainer, your Trainer has access to:

Your Trainer is an independent service provider, not an employee or agent of Agents4 Fitness. We require Trainers to agree to our Terms of Service, which include obligations regarding data handling, but we cannot fully control how Trainers use information they access through the Platform. If you terminate your relationship with a Trainer, their direct access through the Platform is restricted, but we cannot retrieve information the Trainer may have previously viewed, downloaded, or recorded outside the Platform.

5.3 Sharing with Marketplace Creators

If you subscribe to a Marketplace Agent, the Creator of that Agent may have access to aggregate subscriber analytics (subscriber count, retention rates, engagement metrics). Creators do NOT have access to your individual Health Data, personal information, or conversation history with their Agent unless they are also your assigned Trainer.

5.4 Sharing with Service Providers

We share information with third-party service providers who process data on our behalf to operate the Platform. These providers are contractually obligated to use your information only for the services they provide to us. See Section 6 for details.

5.5 Sharing for Legal Reasons

We may disclose your information if required to do so by law or in response to valid legal process, including:

5.6 Business Transfers

If Agents4 Fitness is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and any choices you may have regarding your information.

5.7 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. For example, we may publish statistics about Platform usage, aggregate fitness trends, or Marketplace analytics. This data is not considered personal information.

5.8 Advertising and Conversion Measurement Partners

When you interact with our advertising or sign up or subscribe after clicking an ad, we share a limited set of event and conversion data with our advertising partner, Meta Platforms, Inc., to measure and optimize our campaigns, as described in Section 15.4. Identifiers such as your email address and phone number are cryptographically hashed (SHA‑256) before transmission, and we never share your Health Data for advertising. Under certain U.S. state privacy laws this activity may be considered "sharing" for "targeted advertising" or "cross-context behavioral advertising"; you may opt out as described in Section 15.4 and Section 11. This is not a "sale" of your personal information for monetary consideration (see Section 5.1).

6. Third-Party Service Providers

We use the following categories of third-party service providers to operate the Platform:

6.1 Cloud Infrastructure and Database

ProviderPurposeData Processed
Google Cloud Platform (GCP)Primary cloud infrastructure, compute, and networkingAll Platform data
Google Cloud FirestorePrimary database for user accounts, health data, plans, messages, marketplace data, and all structured dataAll structured personal data
Google Cloud Storage (GCS)Storage for progress photos, profile photos, gallery images, exercise videos, knowledge base filesPhotos, videos, documents
Google Cloud Key Management Service (KMS)Encryption of sensitive credentials (wearable OAuth tokens)OAuth tokens

6.2 AI and Machine Learning

ProviderPurposeData Processed
Google Vertex AI (Gemini)AI model powering coaching agents, form analysis, plan generation, and conversational AIHealth data, fitness data, conversation messages, exercise videos (for form analysis)
WeaviateVector database for retrieval-augmented generation (RAG) knowledge searchTrainer knowledge base documents (PDFs, transcripts), embeddings

6.3 Payment Processing

ProviderPurposeData Processed
Stripe, Inc.Payment processing, subscription billing, Creator payouts (via Stripe Connect), customer portal, webhook event processingPayment method details, billing addresses, transaction amounts, subscription status, payout information

Stripe is PCI-DSS Level 1 certified. Your payment card information is collected and processed directly by Stripe and is never stored on Agents4 Fitness servers. Please review Stripe's Privacy Policy for details on their data practices.

6.4 Communication Services

ProviderPurposeData Processed
Firebase Cloud Messaging (FCM)Push notification delivery to iOS and Android devicesDevice push tokens, notification content
ResendTransactional email delivery (billing notifications, progress reports, check-in reminders, password resets)Email addresses, email content, attachment data (up to 25 MB)
Slack (Trainer-configured)Trainer webhook notifications for readiness alerts, automation events, check-in submissionsNotification content (configured by Trainer)
TwilioWhatsApp messaging delivery, verification workflows, and webhook processing where Twilio is the configured WhatsApp providerPhone numbers, message content, delivery metadata, verification events
Meta WhatsApp Business Platform / Cloud APIWhatsApp message delivery and receipt, webhook processing, and account linking where Meta is the configured WhatsApp providerPhone numbers, message content, delivery metadata, verification events
DiscordDiscord message delivery and receipt, account linking, and bot interactionsDiscord user IDs, message content, delivery metadata
Meta Platforms, Inc. (Advertising & measurement)Ad performance measurement, optimization, and remarketing via the Meta Pixel (marketing pages) and the Meta Conversions API (server-side conversion events). See Sections 5.8 and 15.4.SHA‑256 hashed email/phone/user ID, browser & click identifiers (_fbp/_fbc), IP address, user agent, event name/value/source URL. No Health Data; no plaintext contact details.

6.5 Error Tracking and Monitoring

ProviderPurposeData Processed
SentryBackend error tracking and performance monitoringError reports, stack traces, performance metrics (PII stripped before transmission — authorization headers, cookies, passwords, and tokens are removed)
Firebase CrashlyticsMobile app crash reportingCrash reports, device information, app state at time of crash

6.6 Wearable Device Providers

ProviderPurposeData Processed
WHOOPWearable data sync (recovery, strain, sleep)OAuth tokens (KMS-encrypted), health metrics
OuraWearable data sync (readiness, HRV, sleep)OAuth tokens (KMS-encrypted), health metrics
GarminWearable data sync (activity, sleep, health)OAuth tokens (KMS-encrypted), health metrics
Apple Health / HealthKitHealth data sync (heart rate, steps, workouts, weight)Health metrics (processed on-device and synced with your permission)
FitbitWearable data sync (activity, heart rate, sleep)OAuth tokens (KMS-encrypted), health metrics
Google FitWearable and health platform data sync (activity, heart rate, sleep, workouts)OAuth tokens (KMS-encrypted), health metrics
PolarWearable data syncOAuth tokens (KMS-encrypted), health metrics

When you connect a wearable device, you authorize that provider to share your data with Agents4 Fitness through their API. Each provider has their own privacy policy governing their collection and use of your data.

6.7 App Distribution

ProviderPurposeData Processed
Expo (expo.dev)Over-the-air (OTA) app updates, build infrastructureApp version, device platform, update metadata
Apple App Store / Google Play StoreApp distributionAs governed by Apple/Google privacy policies

6.8 Video Content (Trainer-Initiated)

ProviderPurposeData Processed
YouTube (Trainer OAuth)Knowledge base video ingestion — Trainers connect YouTube channels to import exercise videos and transcripts for their Agent's knowledge baseYouTube channel metadata, video transcripts (PII-scrubbed during ingestion: emails and phone numbers are removed from transcripts before indexing)

7. AI Processing and Automated Decision-Making

7.1 How AI Processes Your Data

The Platform uses artificial intelligence extensively to deliver its core services. Your personal information, including Health Data, is processed by AI systems in the following ways:

  1. Conversational AI Coaching: When you chat with an AI Agent, your messages, health profile, check-in history, workout data, nutrition data, wearable metrics, and other relevant information may be included as context for the AI model to generate personalized responses.
  2. Plan Generation: AI systems use your body metrics, goals, experience level, medical history, dietary restrictions, and preferences to generate workout and nutrition plans.
  3. Readiness Scoring: The Platform combines wearable data, check-in data, and historical patterns to calculate daily readiness scores and predict future readiness using algorithmic and AI-based methods.
  4. Form Analysis: Exercise form videos you upload are processed by AI vision models to evaluate movement quality and provide feedback.
  5. Agent Matching: The recommendation engine uses your goals, medical conditions, dietary needs, experience level, gender, age range, and other profile data to score and rank Marketplace Agents for you.
  6. Automation Triggers: Trainer-configured Automations may use your data (readiness state, check-in status, wearable sync status, compliance metrics) to trigger automated actions.

7.2 Automated Decision-Making

The Platform uses automated decision-making in the following areas:

These automated decisions do not have legal or similarly significant effects on you. They affect fitness recommendations only, which you are free to accept or disregard. You always retain the ability to contact your Trainer for human-reviewed guidance.

7.3 AI Data Processing by Third Parties

AI-generated content is produced using Google Vertex AI (Gemini models). When your data is processed by these models:

8. Data Storage and Security

8.1 Where Your Data Is Stored

Your data is stored on:

All primary data storage is on Google Cloud Platform infrastructure located in the United States.

8.2 Security Measures

We implement the following security measures to protect your data:

  1. Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS.
  2. Credential Encryption: Wearable device OAuth tokens are encrypted at rest using Google Cloud Key Management Service (KMS). Passwords are hashed using bcrypt (industry-standard one-way hashing — we cannot read your password).
  3. Authentication and Access Control: API access requires Bearer token authentication. Rate limiting is applied to prevent abuse (e.g., photo uploads limited to 50 per hour). Trainer concurrent request limits are enforced.
  4. PII Filtering in Logs: Our logging infrastructure masks sensitive fields (email, phone, password, access tokens, refresh tokens) before writing log entries. Error tracking (Sentry) is configured to strip authorization headers, cookies, and tokens before transmission.
  5. Knowledge Base PII Scrubbing: When Trainers upload content to the knowledge base (including YouTube transcripts), email addresses and phone numbers are automatically detected and removed during the ingestion pipeline before indexing.
  6. Photo Access Controls: Client progress photos are stored in private cloud storage buckets with time-limited signed URLs (60-minute expiration). Trainer profile and gallery photos designated as public are stored separately.
  7. Image Processing Limits: Uploaded images are validated for format (JPEG, PNG, WebP only), size (maximum 12 MB), and dimensions (maximum 1920px width) to prevent abuse.

8.3 Security Limitations

No system is 100% secure. While we implement reasonable security measures, we cannot guarantee that your data will never be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. You provide personal information, including Health Data, at your own risk.

If we become aware of a security breach that affects your personal information, we will notify you in accordance with applicable law.

9. Data Retention

9.1 General Retention Principles

We retain your personal information for as long as necessary to:

9.2 Retention Periods by Data Type

Data CategoryRetention Period
Account informationRetained while your account is active, plus 90 days after account deletion to allow for account recovery
Health and fitness data (check-ins, body metrics, plans, readiness scores)Retained while your account is active. Deleted upon account deletion request, subject to legal retention requirements
Progress photos and videosRetained while your account is active. Deleted from cloud storage upon account deletion request
Wearable dataRetained while your account is active. Default sync range is 30 days of historical data per sync. Deletable via data deletion request (see Section 10)
AI conversation historyRetained while your account is active for continuity of coaching experience
Financial recordsRetained for seven (7) years after the transaction date, as required by tax and financial regulations
Communication data (messages)Retained while your account is active and both parties' accounts exist
ReviewsRetained while the reviewed entity (Trainer or Agent) exists on the Platform, even if the reviewer's account is deleted (reviews may be anonymized)
Error and crash reportsRetained by Sentry and Firebase Crashlytics per their respective retention policies (typically 90 days for event data)
Usage analyticsRetained in aggregate/anonymized form indefinitely. Individual-level analytics retained while your account is active
Audit logs (MCP, automation execution)Retained for one (1) year

9.3 Post-Deletion Retention

After you request account deletion:

10. Your Rights and Choices

10.1 Access Your Data

You may request a copy of the personal information we hold about you. For wearable data specifically, you can use the in-app data export feature (Export My Wearable Data), which provides a JSON export of your wearable connections, synced health data, and sync logs (excluding sensitive OAuth tokens).

10.2 Correct Your Data

You may update or correct your personal information at any time through the Platform's settings and profile screens. If you believe data is inaccurate and cannot correct it yourself, contact us.

10.3 Delete Your Data

You may request deletion of your account and personal data by:

Upon receiving a deletion request, we will delete or anonymize your data within thirty (30) days, subject to the retention exceptions described in Section 9.3.

10.4 Data Portability

You may request a portable copy of your data in a structured, machine-readable format (JSON). This includes health data, check-in history, and wearable data. Contact us to initiate a data export request.

10.5 Disconnect Wearable Devices

You may disconnect any wearable device at any time through the Platform's wearable settings. Disconnecting stops future data retrieval from that device but does not automatically delete previously synced data. To delete synced wearable data, use the deletion feature described in Section 10.3.

10.6 Notification Preferences

You may control notifications through:

10.7 Opt Out of AI Processing

If you wish to opt out of AI-driven features (such as AI coaching, readiness predictions, or automated recommendations), please contact us. Note that opting out of AI processing will substantially limit the Platform's functionality, as AI-powered coaching is a core service.

10.8 Close Your Account

You may close your account at any time. See Section 19 of our Terms of Service for details on the effect of account termination.

11. State-Specific Privacy Rights (US)

11.1 California Residents — CCPA / CPRA

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  1. Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
  2. Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, fraud prevention, exercising legal rights).
  3. Right to Correct: You have the right to request correction of inaccurate personal information.
  4. Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
  5. Right to Limit Use of Sensitive Personal Information: Much of the data collected by the Platform (health data, biometric data) constitutes "sensitive personal information" under CPRA. We use sensitive personal information only as necessary to provide the services you request (fitness coaching and related features). You have the right to limit our use of sensitive personal information to purposes that are necessary and expected.
  6. Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise your CCPA/CPRA rights, contact us at admin@agents4.com or use the in-app Data Privacy controls. We will verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf.

Categories of Personal Information Collected (per CCPA categories):

Shine the Light: California Civil Code § 1798.83 permits California residents to request information about personal information disclosed to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.

11.2 Virginia, Colorado, Connecticut, and Other State Privacy Laws

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or another state with comprehensive privacy legislation, you may have similar rights including:

To exercise any of these rights, contact us at admin@agents4.com.

11.3 Health Data Privacy Laws

Certain states have enacted health data privacy laws that may apply to the Platform:

  1. Washington My Health My Data Act: If you are a Washington State resident, we collect and use consumer health data only with your consent (provided when you create an account and use health-related features). You have the right to withdraw consent and request deletion of your health data. This Privacy Policy is also intended to function as our consumer health data privacy policy. The categories of consumer health data we collect are described in Sections 1.2 and 4, the categories of sources are described in Section 2, the purposes of collection and use are described in Sections 3 and 7, and the categories of third parties and service providers with whom consumer health data may be shared are described in Sections 5 and 6, including cloud infrastructure providers, AI providers, messaging providers you choose to link, and wearable or health platform providers you choose to connect.
  2. Other State Health Privacy Laws: We comply with applicable state-level health data privacy requirements. If your state has enacted health data privacy legislation, your rights under that legislation apply in addition to the rights described in this Privacy Policy.

12. International Users and Data Transfers

12.1 Data Transfer to the United States

If you access the Platform from outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States, where our servers and service providers are located. Data protection laws in the United States may differ from those in your country of residence.

12.2 European Economic Area (EEA), United Kingdom, and Switzerland

If you are located in the EEA, UK, or Switzerland, the following applies:

  1. Legal Basis for Processing: We process your personal data based on:
  2. Data Subject Rights under GDPR: You have the right to:
  3. Data Transfers: Data is transferred to the United States pursuant to appropriate safeguards, which may include Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognized transfer mechanisms.
  4. Data Protection Officer: If required by GDPR based on the nature and scale of our processing activities, we will appoint a Data Protection Officer. Contact us at admin@agents4.com for DPO inquiries.

12.3 Other International Jurisdictions

We endeavor to comply with applicable data protection laws in all jurisdictions where the Platform is available. If you believe your local data protection rights are not adequately addressed in this Privacy Policy, please contact us.

13. Children's Privacy

13.1 Age Restriction

The Platform is not directed to and is not intended for use by individuals under eighteen (18) years of age (or the age of majority in your jurisdiction, whichever is greater). We do not knowingly collect personal information from children.

13.2 Parental Notification

If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at admin@agents4.com.

13.3 COPPA Compliance

In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. The Platform's collection of health data, body measurements, photos, and biometrics makes it particularly unsuitable for use by minors.

14. Device Permissions

The Platform may request the following device permissions:

14.1 iOS Permissions

PermissionPurposeRequired?
CameraTake progress photos for fitness check-insOptional — only needed for photo check-ins
Photo LibraryUpload progress photos from your libraryOptional — only needed for photo uploads
Apple Health (Read)Sync health data (heart rate, steps, workouts, weight) for personalized coachingOptional — only needed for Apple Health integration
Apple Health (Write)Save workout and weight data back to Apple HealthOptional
MicrophoneRecord voice messages for hands-free workout loggingOptional — only needed for voice features
Face ID / Touch IDBiometric app unlock for quick accessOptional — biometric data stays on-device
Push NotificationsReceive coaching alerts, check-in reminders, readiness notificationsOptional but recommended

14.2 Android Permissions

PermissionPurposeRequired?
CameraTake progress photos for fitness check-insOptional
Storage (Read/Write)Access and save photos and documentsOptional
Activity RecognitionDetect physical activity for wearable integrationOptional — only needed for wearable features
VibrateHaptic feedback for notificationsAutomatic
BiometricFingerprint/face unlock for quick accessOptional — biometric data stays on-device
MicrophoneRecord voice messages for hands-free workout loggingOptional
Receive Boot CompletedResume scheduled notifications after device restartAutomatic
Push NotificationsReceive coaching alerts and remindersOptional but recommended

14.3 Permission Control

All optional permissions are requested only when you attempt to use the corresponding feature. You can revoke any permission at any time through your device's system settings. Revoking a permission will disable the feature that depends on it but will not affect other Platform functionality.

15. Cookies and Tracking Technologies

15.1 Mobile App

The Agents4 Fitness mobile application is a native mobile app and does not use browser cookies. Authentication is managed through encrypted tokens stored in secure device storage (SecureStore for sensitive data, MMKV for general preferences).

15.2 Web Interfaces

If you access Platform web interfaces (such as the Stripe billing portal or password reset pages), those pages may use:

15.3 Analytics

We use internal analytics events (not third-party analytics cookies) to understand feature usage within the mobile app. These analytics are processed server-side and do not involve browser-based tracking.

15.4 Advertising, Marketing Pixels, and Conversion Measurement

To promote the Platform and measure the effectiveness of our advertising, our marketing website and paid-acquisition landing pages use the Meta (Facebook) Pixel, and our servers send conversion events to Meta Platforms, Inc. through the Meta Conversions API. This advertising activity is used only for measurement, optimization, and remarketing — it is not used to deliver the coaching service itself.

The information shared with Meta may include: events you trigger (such as viewing a landing page or starting a subscription), the event value and source URL, browser/click identifiers (_fbp and _fbc/fbclid), your IP address and user agent, and a one-way SHA‑256 hashed version of identifiers such as your email address, phone number, and a pseudonymous user ID. We do not send Meta your name, your plaintext email or phone number, or any Health Data. Hashing is applied before transmission, so Meta receives only irreversible representations of these identifiers for ad-matching purposes.

Your choices: You can limit or opt out of this advertising activity by adjusting your Meta ad preferences, using the industry opt-out tools at DAA WebChoices and NAI, enabling your browser's tracking-prevention or cookie controls, or using your device's "Limit Ad Tracking" / "Opt out of Ads Personalization" setting. Opting out does not affect your ability to use the Platform. (We do not currently run TikTok or Google advertising tags; if we add other advertising partners, we will update this section and the providers list in Section 6.)

16. Do Not Track Signals

The Platform does not currently respond to "Do Not Track" (DNT) browser signals, as there is no industry-standard protocol for DNT compliance. Aside from the advertising-measurement activity on our marketing and landing pages described in Section 15.4 — which you can opt out of, and which we treat opt-out preference and Global Privacy Control (GPC) signals as a request to limit — we do not track your activity across unaffiliated third-party websites.

17. Third-Party Links and Services

The Platform may contain links to or integrations with third-party websites, services, or applications (including wearable device platforms, Stripe billing portal, YouTube, and Slack). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Platform.

18. Changes to This Privacy Policy

18.1 Notification of Changes

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:

18.2 Material Changes

Material changes include but are not limited to: new categories of data collection, new purposes for data processing, new third-party data sharing, changes to your privacy rights, or changes to data retention practices.

18.3 Continued Use

Your continued use of the Platform after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated Privacy Policy, you must stop using the Platform and request account deletion.

19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Agents4 Fitness LLC

General Privacy Inquiries:
Email: admin@agents4.com

Data Access, Correction, or Deletion Requests:
Email: admin@agents4.com
Subject line: "Data Request — [Access/Correction/Deletion]"

Security Concerns or Data Breach Reports:
Email: admin@agents4.com

Legal Inquiries:
Email: admin@agents4.com

Mailing Address:
5511 Parkcrest Dr. Suite 103, Austin, TX 78731

Response Time: We will acknowledge your request within five (5) business days and aim to fulfill verified requests within thirty (30) days, or within the time frame required by applicable law.

This Privacy Policy was last updated on March 18, 2026.