Privacy policy

This policy explains what personal data Stack processes, why and on what legal basis, who receives it, how long it is kept, and the rights you may exercise at any time.

The short version

The full policy

Tap a section to open it.

1. Controller

Stack is operated by Dad with Style OÜ (Estonia), which is the controller of your personal data. For any question or request concerning your data, contact [email protected]. Requests are answered within one month, as required by the General Data Protection Regulation (the GDPR).

Stack is a service for adults. It is not directed at anyone under eighteen, and no data is knowingly processed about anyone under that age.

2. Data processed

Apple Health data is never sold and never used for advertising or marketing, is not used for anything but your coaching, and is never stored in iCloud by the application. It is stored with the rest of your data, in Ireland, where only you and your coach can read it. It is shared with no one else, with one exception you choose yourself: your daily step count reaches the AI assistant that drafts your coach's notes before a call (section 7) only if you say yes to that in the iPhone app. You are asked before Apple Health's own permission screen, saying no still connects Apple Health, and you can change your answer in Settings at any time. A weight from a smart scale is only ever offered to you on the weigh-in row; it becomes a weigh-in only when you tap to log it. The weigh-ins the app saves to Apple Health are never read back as a scale's weight. You can stop any of it at any time in the Health app (Settings → Apps → Health → Stack), and the lines already stored are deleted with your account or on request.

Health information—including how you slept, the days you mark yourself sick and the Apple Health figures above—is a special category of personal data under the GDPR. It is processed only because safe coaching requires it and only with your explicit consent, which you may withdraw at any time.

Your name and email address are required to provide the service: without them an account cannot be created. All other data is provided at your discretion.

3. Purposes and legal bases

Your data is processed for one purpose: the provision of your coaching. It is not used for advertising, is not sold, and is not disclosed except as described in this policy. The legal bases are:

4. Recipients and where data is held

Your account, your history and your photographs are stored in Ireland. Your coach has access to your data. Beyond him, it is disclosed only to the following providers and, only if you choose to connect one, to your own AI assistant (section 8).

Each provider that processes your data on the application's behalf acts as a processor on documented instructions, under a data processing agreement. The push services and the public food databases are sent nothing about you and are not processors. The arrangements that stand outside such an agreement are the coach's own AI assistant and his iCloud storage, described in section 7. Anthropic, Apple, Cloudflare, GitHub, Google, PostHog, Resend and Supabase are United States companies, whatever the region their servers stand in; where data is transferred to, or may be accessed from, the United States, the transfer is covered by the European Commission's standard contractual clauses or by that company's certification under the EU–US Data Privacy Framework. A copy of the clauses is available on request from the address in section 1.

5. Backups and automated jobs

Automated daily backups protect your history against technical failure. They are made by an automated job run on GitHub and stored with Cloudflare in the European Union; the twelve most recent copies are kept and older ones are deleted automatically. Your data, photographs included, passes through that job's temporary storage for the minutes it takes to make the copy and is destroyed with the machine that made it; nothing is retained by GitHub. Once a month the newest copy is rebuilt into a throwaway database, by the same kind of job, to prove that it can be restored; that database is deleted at the end of the test. The coach's own computer may also hold a working copy of the database, taken before a manual change is made to it.

Each morning a job of the same kind runs the application's own summary of your progress (the same summary shown on your Progress page) and stores what it says in the application's database, where only your coach can read it, so that he prepares for your call from the figures your own app shows you. Your records pass through that job's temporary storage for the minute it takes and are destroyed with the machine; nothing is retained by GitHub. The stored summaries are deleted with your account.

The logs of these jobs are kept by GitHub for ninety days and contain no name, weight or other personal value.

6. AI-assisted features

The application sends material to a language model operated by Anthropic (United States) in the cases described in this section: recording a meal from a photograph or from a description, and producing call notes. Recording a meal this way is optional, and nothing is sent unless you choose to.

The same terms apply to all of them. Anthropic processes the material solely on documented instructions, under a data processing agreement incorporating the European Commission's standard contractual clauses governing transfers to the United States. It is not used to train their models. Anthropic retains it for abuse monitoring, typically deleting it within about thirty days; material flagged by their safety systems can be kept longer.

Food photographs

A meal can be recorded from a photograph of a product's nutrition label, of a screen displaying nutritional information, or of the food itself. The model identifies what the photograph shows and either transcribes the printed nutritional values or names the foods present and estimates their portions. Where the photograph shows food rather than a printed label, the nutritional values are not produced by the model: they are retrieved from the public food databases described below, using only the foods the model identified.

The photograph is not stored by us. It is transmitted, processed and discarded: never written to our storage, never attached to your record, and never visible to your coach. What is retained is only the resulting diary entry (the food's name, the portion and its nutritional values), which you review and confirm before it is saved. Photographs are reduced in size on your own device before transmission, which also removes hidden camera metadata, including location.

A photograph you choose to save for later waits on your own phone, in the application's storage on that device, until you read it or discard it. Up to thirty may wait at a time. It is not uploaded, is not visible to your coach, and is removed when you sign out. Reading it is what sends it for processing, on the terms above.

Meals described in words

A meal may also be recorded by describing it, typed or dictated. The model separates the description into individual foods and estimates the amount of each; the nutritional values are again retrieved from the public food databases. Nothing is recorded in your diary until you have reviewed the result and saved it.

A short summary of your recent meals is transmitted with every description, whether or not it refers back to one, so that a reference to something you have already recorded (the same breakfast as yesterday, for example) can be resolved. This is the only place in the application where records you have already stored are sent for processing rather than the thing you have just written. That summary contains the names of the foods you recorded, their portions, and the day and meal each belonged to, nothing else: no nutritional values, no brands, no identifiers, and nothing older than the preceding seven days. Your name is not transmitted.

Dictation, by the microphone shown in the application where your browser provides one or by your keyboard's own microphone key, is performed by the device or the browser you are using, never by the application. On an iPhone or iPad, speech is normally converted to text on the device itself. Chrome and the browsers built on it send the audio to the speech service run by the maker of that browser, where it is handled under that company's own policy. Either way, the application receives only the resulting text; no audio recording is transmitted to it or retained by it.

The food databases

Nutritional information comes from two public food databases: Open Food Facts, whose data is made available under the Open Database License, and FoodData Central, published by the United States Department of Agriculture. A product scanned by its barcode is looked up with Open Food Facts first and, where that database does not hold it, with FoodData Central. A food from a photograph or a description is looked up with FoodData Central first; where it has no record of the food at all (a product sold outside the United States, or a brand newer than its catalog), that one food is then looked up with Open Food Facts as well.

The barcode lookup is made by your own phone, directly with Open Food Facts. Like any website your phone visits, Open Food Facts sees the network address it is using and the language it is set to; it receives no name, no account and nothing about your diary. Every other lookup (a food you search for by typing its name, and every food from a photograph or a description) is made by our own server rather than by your phone. Neither database learns anything about you: the request carries a barcode or a food's name and nothing else.

Choosing the right database entry is done by the application's own rules, without a language model. An entry that had to be recorded from an estimate, because no database answered at the time, is re-checked against the databases the next time the app opens, using only the food's name. Overnight, the foods recorded most often across all clients are looked up ahead of time so that searches are fast; only the food words travel, never who recorded them.

The application also remembers which database entry people choose for the words they search for or say. When you save a food, the words it was found for and the entry you kept are added to a shared count, so that the same words open on that entry for everyone who uses the application. The count holds words and a catalog reference only: not your name, not your diary, not the day. Each such vote is also kept as a dated line (the words, the entry, whether it was a correction) so your coach can see which foods the application keeps getting wrong; that line carries no name either.

When you correct a food the app read from a photo or a description, we keep a short record: the food's name, the entry the app offered and the one you kept, with their weights and calories, and when you corrected it. It carries no name, no account and no diary date, and shows us where the app reads food wrong. To notice a correction made after saving, your phone keeps a two-day note of which foods came from a photo or a description; it stays on your phone and is removed when you sign out.

The same applies to a restaurant menu you photograph: when you save a dish the menu printed no calorie for, the dish’s name, the restaurant’s name as printed on the menu and the figures you saved are added to a shared average, so the same dish at the same place opens on those figures for everyone after you. Nothing about you is stored with it.

Two shared catalogs are built from these features, and neither is linked to you. Where a scanned packet states its serving without a weight, the product's own printed details are sent to Anthropic once to ask what one piece weighs, and the answer is kept for everyone who scans that packet. Where you correct what a restaurant dish contains before recording it, the dish's name, the menu's printed title and your corrected weights are kept so that the next person reading that menu gets the corrected figures; your name and your diary are not part of it.

Call notes

Coaching calls are recorded and transcribed automatically by Google within the Google Workspace account from which the call is scheduled, and Google's own assistant writes a first set of notes into the same document. Those recordings, transcripts and first notes are the coach's own records (section 7).

Call notes in the application are produced only if you have switched them on; until you do, no transcript of yours is read or transmitted by the application. Where you have, the transcript is transmitted to Anthropic, whose model extracts the coaching content: training and nutrition guidance, targets, decisions made about your program, and actions agreed before the next call. Only that content is retained, and it is stored in Ireland with the rest of your data. Personal conversation, matters concerning your work or business, and references to third parties are excluded and are not stored in the application. Where a figure in the transcript is unclear, it is flagged for confirmation by your coach rather than recorded as stated.

You may have call notes switched off, or object to them, at any time, by telling your coach or writing to the address in section 1. From that point no transcript of yours is read or transmitted by the application, any AI assistant you connected (section 8) is cut off, and notes already produced are deleted on request.

7. How your coach prepares for a call

Before each coaching call your coach reads a short brief about you, drafted for him by an AI assistant: Claude, made by Anthropic (United States), running on his own computer and in Anthropic's cloud under a subscription held by Dad with Style OÜ. To draft it, the assistant reads your records in the application (the figures your own Progress page shows, your weight, food, sleep and workout entries, anything you flagged, and your call notes) together with the coach's working files about you: his notes and the transcripts of your earlier calls. Those working files are held on his computer and in his Apple iCloud account. The same assistant helps him with other coaching work that draws on those records, such as a summary of your week or a letter to you.

Your daily step count from Apple Health is part of what the assistant reads only if you said yes to that in the iPhone app; without that yes it is left out of everything the assistant sees, and you can withdraw it in Settings at any time.

This does not depend on whether you have switched call notes on. That switch governs what the application reads, stores and shows you; the transcripts are the coach's own records of calls he took part in.

The brief is sent to your coach alone and kept in his working files. It sets no target and changes nothing in your program; what he does with it on the call is his decision.

The same assistant also checks the application once a week, and on the same day when a client's card breaks one of its rules. It reads what your Brief, Today and Food screens said each day, the figures behind them and your call notes, without your name, to find mistakes in what the application tells you. It changes nothing in your program. We also see which buttons you tap in the app and whether they respond, without your name, so we can fix the ones that don't work. It also reads the problems you report, without your name or your screenshot. We also see the day the app last received your Apple Health figures, without your name, so we can fix it when it stops. We also see whether what you save reaches our servers (which kind of entry and how long it waited, never what it says), and an automatic check reads each day's workouts and entries, without your name, to find any that saved only in part.

The assistant is provided under Anthropic's terms for that subscription, not under the data processing agreement that covers the application's own use of Anthropic (section 6). The setting that would allow Anthropic to use these conversations to improve its models is switched off. Anthropic keeps the conversations until your coach deletes them and removes deleted ones from its systems within thirty days; material flagged by its safety systems can be kept longer. The transfer to the United States rests on Anthropic's certification under the EU–US Data Privacy Framework.

You may object to this at any time by writing to the address in section 1. From then on your coach prepares for your calls without the assistant, and nothing else about your coaching changes.

8. Connecting your own AI assistant

You may connect an AI assistant of your choice (Claude, ChatGPT or another) to your own coaching data, so that it can answer questions about your program, your history and your calls. This is entirely optional, and it is your act: the application never connects one for you.

Your assistant can read your profile (name, age, height, goal, what gets in your way, how often and where you train, whether you are traveling), your weight and measurement history, your workouts and program, your food diary and nutrition targets, your activity and sleep records, and your call notes. It cannot see your progress photographs, and it can only read: it cannot write, change or delete anything.

Your assistant is run by the company you chose, under that company's own privacy policy, not this one. What it reads may be retained or used by that company on the terms you have with it. Choose with that in mind, in particular for your call notes.

The connection is a private link, and whoever holds the link holds the access; it appears in the address of every request your assistant makes, so treat it as you would a password. One link is live at a time: making a new one in the app retires the old at once, and your coach revokes it altogether at your word, which cuts the assistant off immediately. The application records the fact of each request your assistant makes (which kind, and when) and never the question or the answer.

9. Service analytics

To keep the application reliable, technical usage events are recorded with PostHog (EU): for example, the fact that a weigh-in was logged or a workout completed, and errors the application itself reports. On the iPhone, the same record includes the reports that Apple's own diagnostics on the phone hand the application after it has crashed, frozen or been slow to open: the kind of failure, the place in the application's code where it happened, how long the application took to open, and the phone's model and iOS version. These reports contain nothing entered into the application. They are recorded against an internal account identifier, your first name and your role (client or coach); like any web service, PostHog also sees the network address the request came from. These events contain no substantive values: weights, measurements, notes, food and photos are never transmitted to analytics. Session recording is disabled. The analytics record is deleted when your data is erased (section 13).

10. Notifications

Notifications are optional and switched off unless you turn them on yourself. If you do, your phone's operating system issues an address for delivering them, which is stored with your account together with the encryption keys it requires, your phone's time zone (so that a reminder set for the morning arrives in your morning, wherever you are), an identifier for the device (so that one phone is registered once, however many times the address changes), your browser's description of itself, and the time the app last checked in from that device.

Notifications are delivered through the push service operated by the maker of your phone's operating system: Apple for an iPhone or iPad, Google for an Android device. The content of each notification is encrypted before it leaves our systems and can be read only by your own device. Notifications are limited to your check-in reminders, your training timers (the end of a rest interval or a timed hold), and an evening reminder when meal photographs are waiting unread on your phone; that last one names the meal the photograph was saved under (breakfast, lunch, dinner or a snack) and never a food. No health information, body weight, measurement, food or note is ever placed in a notification.

You may switch notifications off at any time, in the app or in your phone's settings. Switching them off in the app deletes the stored address.

11. Cookies and storage on your device

The application sets no advertising cookies and uses no third-party trackers. It stores your session and a copy of your own data on your device so that it opens quickly and functions offline. Signing out removes them, once any changes still waiting to be saved have been sent.

12. Retention

Your data is retained for the duration of the coaching relationship, and afterwards so that your history can be restored should you return. It is permanently deleted on request at any time; no reason is required. Technical records are kept for the life of the account and deleted with it.

13. Your rights
14. Automated decision-making

The application selects coaching messages and suggestions automatically from your own entries (which sentence to show under a chart, or that a lift is ready to go up), every one of them written in advance by your coach. It sets no target, changes no program and decides nothing about you: those are your coach's acts, made in his console. No decision taken by the application has a legal or similarly significant effect on you.

Last updated 6 October 2026. The date above changes whenever this policy does.