← Back to PlanFlow

Privacy Policy

PlanFlow Trainer, operated by PlanFlow Trainer LLC (a PlanFlow AI product) · Version 2.1 · Effective June 19, 2026

PlanFlow Trainer is software for personal trainers. Trainers enter information about their clients — including goals and injury notes, which can reveal health conditions. When a trainer asks our AI assistant a client-specific question, our servers remove direct identifiers (names, phone numbers, emails, exact dates) and replace names with placeholders before sending the question to a third-party, U.S.-based AI provider, and only if that client has given consent through a two-step flow. Below we describe exactly what is sent, what is removed, the known gaps, and your rights.

1. Scope and our roles

This Privacy Policy explains how we handle personal information in the PlanFlow Trainer service ("Service"). It covers two different relationships, and our legal role differs in each:

If you are a Client and have questions about your information in the Service, please contact the Trainer who manages your record; we will support Trainers in responding to such requests as required by law.

2. Information we collect

From and about Trainers (we are the controller):

Client Data entered by Trainers (we act as processor):

Voice data: see Section 7. In production, we do not receive, store, or transmit raw audio.

3. How we use information

4. Sensitive / health information and our lawful basis

A Client's goals and injury notes can describe a physical or mental health condition. When a Trainer asks the AI Advisor a question about a Client who has granted consent, the content of that Client's goals, injury notes, and training history is sent to the third-party AI provider in de-identified form (direct identifiers removed; names replaced with placeholders; exact dates replaced with relative labels). The clinical/training substance of the notes is retained because the AI needs it to respond.

We treat this category as sensitive information. The lawful basis for processing it through the AI Advisor is the Client's opt-in consent, captured through the two-step consent flow described in Section 6. If consent has not been granted, the Client's name and data are not sent to the AI provider; the Client is represented to the AI by a neutral placeholder label only. Removing direct identifiers reduces what the provider receives, but is not the same as full anonymization — information a Trainer types may still describe a Client indirectly.

We are not a HIPAA-covered entity by virtue of this Service, and using the Service does not make a Trainer's records exempt from generally applicable privacy laws. Trainers must not enter information they are not permitted to process through a third-party AI service, and must keep HIPAA-protected information out of the Service unless and until an appropriate agreement is in place.

5. The AI Advisor — what is shared with the AI provider

When a Trainer uses the AI Advisor, the request passes through a fixed, server-side sequence before anything reaches the AI provider:

  1. Authentication — the Trainer's identity is verified.
  2. Consent check (fail-closed) — if the relevant Client has not granted consent, or the Client cannot be verified, identifiable context is blocked from being sent.
  3. PII scrubbing — on our servers, before the request leaves our infrastructure, the system replaces:
    • email addresses with placeholder tokens;
    • U.S.-format phone numbers with placeholder tokens;
    • the names of the Trainer's Clients (the full client roster, not just the selected Client) with placeholder tokens such as [[C1]];
    • ISO/YYYY-MM-DD dates with relative labels (for example, "3 days ago," "last week"). Date conversion is one-way and is not reversed.
  4. Verification gate — the system re-scans the scrubbed request for any remaining raw identifiers. If any are detected, the request is blocked and not sent to the provider. Blocked requests are recorded as category counts only (not the underlying text).
  5. AI provider — only the de-identified request is sent.
  6. Restoration for the Trainer — when the response returns, name placeholders are restored to real names for the Trainer's view only, using a map that exists only in memory for that single request and is then discarded. It is not persisted, logged, or written to any database.

What is sent to the AI provider: the static system instructions, the (de-identified) prior conversation turns, the current (de-identified) question, and de-identified Client context (name as a placeholder, dates as relative labels, training numbers such as weights and reps intact).

What is designed not to be sent: real names, phone numbers, email addresses, and exact dates. The system is designed so that the AI provider does not receive these direct identifiers.

Audit records: AI questions and responses are stored in their de-identified, tokenized form. The map needed to restore the placeholders is destroyed at the end of each request, so identifiers in stored AI records are not reversible. Each Trainer can read only their own records.

Model training. We operate no AI models of our own and do not train any model on Client Data. Data sent to the third-party AI provider is processed on its infrastructure under its own terms and data processing agreement. We do not represent how that provider retains or uses submitted data beyond those terms; we state only that we ourselves neither retain it in identifiable form nor use it to train models.

Known limits of the de-identification (please read)

The de-identification is strong for the cases it covers, but it is not absolute. In particular:

6. Client consent system

Before a Client's identifiable information or training data is used with the AI Advisor, the Trainer must record that Client's consent through a two-step flow: the Trainer reads a scripted disclosure to the Client, then confirms the Client's answer.

7. Voice features

8. Third parties and sub-processors

We use the following service providers. They process data to provide infrastructure and features to us, under their own terms and our agreements with them:

ProviderRoleNotes
Supabase Database, authentication, and server (Edge Function) hosting Managed PostgreSQL on AWS, U.S. region; provider reports SOC 2 Type II compliance and AES-256 encryption at rest
Third-party, U.S.-hosted AI provider Powers the AI Advisor Receives de-identified questions/context via an OpenAI-compatible API; processes under its own terms and data processing agreement
DeepSeek (demo/sandbox only) Powers the AI Advisor's free lane in the demo environment Not used in production; a non-U.S. provider, so it is confined to the demo/sandbox environment and receives only de-identified questions under its own terms; synthetic data only
Cloudflare Frontend hosting / content delivery and TLS Serves the static application; no personal data is logged by this layer
Groq (demo/sandbox only) Voice-to-text transcription in the demo environment Not used in production; synthetic data only

In addition, when you use voice dictation in production, your browser vendor (for example, Google) may receive the audio you speak in order to transcribe it (Section 7). That vendor is not engaged by us; its processing is governed by its own terms.

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising.

9. Data retention

10. Security

We use technical and organizational measures including:

No method of storage or transmission is completely secure, and we cannot promise absolute security.

11. Data breach notification

If we become aware of a breach of security that leads to the unauthorized access, disclosure, or loss of personal information we process, we will:

in each case as, and within the timeframes, required by applicable law.

12. Your privacy rights

Depending on where you live, you may have rights to:

How to exercise them. Trainers may exercise rights regarding their own account data by contacting us at support@planflowai.com. Because we act as a service provider/processor for Client Data, Clients should contact the Trainer who manages their record; we will assist the Trainer as required by law. We will verify requests as the law requires and respond within the timeframes applicable to your jurisdiction. You may also have the right to appeal a decision and to contact your state attorney general.

13. State privacy laws

This Policy is intended to provide the disclosures required by U.S. state privacy laws, including the California Consumer Privacy Act (as amended) and the Virginia/Colorado-model state laws, among others. Several of these laws treat health-related information and other categories as sensitive data requiring opt-in consent to process; we rely on the Client consent flow (Section 6) for that basis. Note that some states (for example, Texas, Nebraska, and Colorado) do not apply a minimum revenue or volume threshold in the same way, so the Service may be in scope regardless of size. We apply our protections to all users on a single standard rather than varying them by state.

14. Children's information

The Service is intended for adult Trainers and is not directed to children. We do not knowingly collect personal information directly from children. However, a Trainer may enter information about a Client who is a minor (for example, a youth athlete). Where a Client is under 13, additional protections under the Children's Online Privacy Protection Act (COPPA) may apply, and several states require opt-in consent to process the data of consumers aged 13–17. Trainers are responsible for obtaining any parental/guardian consent the law requires before entering a minor Client's information and before enabling AI processing of that data. If we learn that a child's information was provided in violation of applicable law, we may delete it.

15. Where data is processed

The Service and its providers are hosted in the United States. If you access the Service from outside the United States, your information will be processed in the United States.

16. Changes to this Policy

We may update this Policy. If we make material changes, we will provide reasonable notice (for example, in-app or by email) before they take effect, and we will update the effective date above.

17. Contact

Privacy questions or requests: support@planflowai.com

Operator: PlanFlow Trainer LLC, a PlanFlow AI product.

The privacy protections described here — de-identification before AI calls, consent-gated identity, append-only consent records, server-side enforcement, and full data export — are implemented in the product today, not just promised on this page. Where this page and the application code ever differ, the code governs and this page will be corrected.