← Back to home
Legal
Privacy Policy
Effective June 2026 · Last updated June 2026 · Version 1.0
Stoic SaaS is a nutrition planning platform operated by Stoic Physique LLC, a Pennsylvania limited liability company ("Stoic SaaS," "we," "us").
This Privacy Policy explains how we collect, use, and share information when a coaching business or its team ("you," "your") uses our nutrition planning software and this website at stoicsaas.com.
We built this software on real coaching operations, and we treat coach and client data accordingly. The short version: you own what you put in, we process it to run the service, and we do not sell it or advertise against it.
01Information we collect
Information you give us. Account and contact details (name, business name, email, phone) that you provide when you request a call, create an account, or contact support. This includes the content of support conversations.
Data you enter into the software. Meal plans, foods, recipes, targets, notes, and the client records you create, including information about your own clients ("end-user data"). Some of this is health-related, such as body measurements, dietary restrictions, allergies, and nutrition targets. You control this data. We process it on your behalf to run the service. Section 04 explains how we handle it.
Usage and device data. Standard technical information such as IP address, browser type, pages viewed, and actions taken in the app, collected to operate, secure, and improve the service.
Cookies. We use essential cookies to keep you signed in and remember preferences such as your light or dark theme. We use limited analytics to understand how the product is used. Our public marketing pages may also use advertising and attribution cookies to measure which pages produce enquiries. These advertising and attribution tools do not run inside the authenticated application, and no end-user data is transmitted to them. You can control cookies through your browser settings.
02How we use information
- To provide, maintain, and secure the software and website
- To respond to your requests and schedule calls you book with us
- To send service and administrative messages about your account, billing, and material changes to the product
- To improve features, performance, and reliability
- To detect, prevent, and address fraud, abuse, or technical issues
- To send marketing about our software to business contacts, with an unsubscribe link in every message
- To comply with legal obligations
We do not sell your data or your clients' data. We do not use end-user data, meal plans, or health-related client information for advertising, and we do not use it to train third-party artificial intelligence models. Where we use data to improve the product, we use aggregated or de-identified data that cannot reasonably be linked back to an individual.
03How we share information
We share information only as needed to run the service:
- Service providers (subprocessors). Hosting, database, infrastructure, email, and payment vendors that process data under our written instructions and confidentiality and security obligations. We maintain a current list of subprocessors and will provide it on request.
- Legal requirements. When required by law, subpoena, or valid legal process, or to protect rights, safety, and security. Where we are legally permitted, we will notify the affected account holder before disclosing.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy. We will notify account holders before their information becomes subject to a different privacy policy.
We do not share end-user data with advertising platforms, data brokers, or analytics vendors.
04Your clients' data
This is the section that matters most if you are evaluating us for your coaching business.
Roles. When you enter information about your clients, you are the controller of that data and we act as your processor (or, under California law, your service provider). You decide what to collect and why. We handle it only to provide the service to you and only on your documented instructions.
Your responsibilities. You are responsible for having a lawful basis and any necessary consent, notice, or authorization to enter and process your clients' information in the software, and for maintaining your own privacy policy with your clients. Several states, including Washington and Nevada, treat nutrition, body measurement, and health information as consumer health data subject to specific consent requirements. Confirm your obligations before you enter that data.
Our commitments as your processor. We will:
- Process end-user data only to provide the service and only on your instructions
- Keep it confidential and limit access to personnel who need it to do their jobs
- Apply the safeguards described in Section 06
- Bind our subprocessors to obligations no less protective than these
- Notify you without undue delay after becoming aware of a security incident affecting your end-user data, with the information you need to meet your own notification obligations
- Assist you in responding to access, correction, deletion, and portability requests from your clients
- Delete or return end-user data on termination, as described in Section 05
Data processing agreement. If your obligations require a signed data processing agreement, including GDPR Article 28 terms or standard contractual clauses, contact us and we will put one in place.
End-user requests. If one of your clients contacts us directly about their data, we will refer them to you and notify you of the request. We will not act on it without your instruction.
05Data retention
We retain information for as long as your account is active or as needed to provide the service.
End-user data is tied to the record you control. When you delete a client profile, the associated data is deleted with it, including meal plans, notes, measurements, and any health-related information in that record. Deleted data may persist in encrypted backups for a limited period before being overwritten in the normal backup cycle.
On account termination, we will delete or anonymize your account data and remaining end-user data within a reasonable period, unless a longer retention is required by law. We retain billing and transaction records for seven years for tax and accounting purposes.
You may request an export or deletion of your data at any time by contacting us.
06Security
We use administrative, technical, and organizational safeguards designed to protect information, including:
- Encryption in transit and at rest
- Access controls that restrict each account to its own data
- Multi-factor authentication available on accounts
- Least-privilege access for our personnel, with access to customer data limited to what is needed for support and operations
- Regular backups
No method of transmission or storage is perfectly secure. We work to protect your data and will notify you of material incidents as described in Section 04 and as required by law.
07Your rights
Legal bases. Where GDPR or UK GDPR applies to our processing of your business contact information, we rely on contractual necessity to deliver the service, legitimate interests to operate and secure our business and to market to business contacts, and consent where required. For end-user data, the legal basis is determined by you as controller.
Your rights. Depending on where you are located, including under GDPR, UK GDPR, and the CCPA as amended, you may have rights to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent. We will not discriminate against you for exercising these rights.
How to exercise them. Contact us at the address in Section 11. We will verify your identity and respond within 45 days, or within one month where GDPR applies. We may extend once where the request is complex and will tell you if we do.
Your clients' rights. If you are an end user of a coaching business that uses our software, please direct your request to that coaching business. They control your data and we act on their instructions.
Complaints. If you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with your local supervisory authority.
08International transfers
We process and store information in the United States. If you access the service from outside the United States, you are transferring your information to the United States, which may have different data protection laws than your country. Where required for transfers out of the European Economic Area or the United Kingdom, we use standard contractual clauses and additional safeguards as appropriate.
09Children
The service is intended for coaching businesses and their staff. We do not knowingly collect personal information directly from children, and accounts may not be created by anyone under 18.
If you enter information about a minor client into the software, you are responsible for obtaining verifiable parental or guardian consent and for meeting any additional legal requirements that apply to minors in your jurisdiction.
10Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above. Where a change materially affects how we handle end-user data, we will notify account holders by email at least 14 days before it takes effect.
11Contact
Questions about this policy or your data, requests for our subprocessor list, or requests for a data processing agreement:
georgiy@stoicphysique.com
Stoic Physique LLC · Pennsylvania, United States · stoicsaas.com
For our registered mailing address, email us and we will provide it.