Draft for the private pilot — placeholders in brackets must be completed before launch.
Privacy notice
Last updated 19 September 2026.
This notice explains what personal data DadMode collects, why, who it is shared with, how long it is kept and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018). DadMode is for adults aged 18 or over.
1. Who we are
DadMode is provided by [TRADING NAME] ([COMPANY NUMBER IF ANY]), [REGISTERED ADDRESS]. We are the controller of the personal data described here. We are registered with the Information Commissioner’s Office under registration number [ICO REGISTRATION NUMBER].
Contact us about privacy at [CONTACT EMAIL]. You can also send /bug or /feedback to the coach in Telegram, but please use email for formal requests.
2. What we collect
When you use the coach in Telegram
- Telegram identity: your Telegram chat ID and the first name (or username, if there is no first name) that Telegram shares with the bot.
- Onboarding answers: what you want to be called, age, goals and why they matter, starting point (for example height, weight and training level), training history, weekly availability, equipment, eating pattern, dietary preferences and constraints (which can include allergies or religious requirements), how much tracking you want, schedule constraints, sleep, stress and energy, coaching style, things the coach should never do, and biological sex.
- Health and medical information you choose to share: injuries, pain, medical conditions, medications, eating-disorder history and advice from clinicians. This is special category data.
- Your messages: text messages and the coach’s replies. We keep the most recent 1,000 entries per person.
- Voice notes: we send the audio to our AI provider to transcribe and store the transcript. We do not store the audio file.
- Photos and images: we send the image to our AI provider for analysis. We store a “[photo]” marker, your caption and the coach’s reply, not the image. With each voice note or image we also keep Telegram’s file reference (a
file_id) and basic details such as file type, size, dimensions or duration. Telegram itself may still hold the file under its own terms. - Your data log: logged meals, workouts, body measurements and notes extracted from your messages are stored encrypted to power totals and trends. After the coach replies to a message that looks like a meal, a session, a weigh-in or how you feel, an AI model turns it into short structured records (for example “porridge with banana, about 350 kcal” or “run, 5 km, 28 minutes”) with the date, where it came from (chat, photo or import) and whether the numbers are your own or an estimate. Totals such as daily calories and protein are added up by our code from these records.
/todayand/logshow them, and/undoand/log deleteremove them. - Feedback and support: what you send with
/feedbackor/bug. - Coach memory: the coach remembers short notes about your preferences and circumstances from your conversations (for example your schedule, kit, an injury to work around or what works for you), plus notes you add with
/rememberor/feedbackand if-then plans you agree to. It never keeps health numbers or other people’s names. These notes are encrypted, used only for your own coaching, and you can see them with/memoryand remove them with/forget. - Safety screening records: when an automated check spots a safety concern (see section 8), we store the category and an excerpt of up to 400 characters of the message.
- Eating-disorder safety marker: if the safety check finds signs of an eating disorder in your own messages, we keep an encrypted marker on your profile (the date and whether the signs were strong or mild). One mild screen pauses calorie targets, deficits and weight-trend advice for 30 days; a hard referral or a repeated mild screen keeps that advice off until a person reviews it. Check-ins stay quieter while the marker applies (see section 8).
- Learning signals: short excerpts of up to 200 characters, automatically redacted to remove things like names, emails, phone numbers, addresses and postcodes, and stored against a pseudonymous code (a keyed hash of your chat ID) rather than your chat ID.
- Check-in preferences: whether you have muted check-in messages or turned on the morning readiness note (
/mornings), which kinds of check-in we sent and when, whether you replied within a day, and (encrypted) the number a check-in was about and how it changed a week later, so we send fewer of the kinds you ignore. - Usage records: for each AI request, the model used, the number of tokens and the time. We also keep daily usage and message-rate counters.
When you use the dashboard
- Sign-in: the dashboard uses Netlify Identity with Google sign-in. Netlify Identity holds your account email address and the basic profile details Google shares. Our coaching data store keeps only an opaque account ID that links your login to your Telegram coaching account.
- Opening the dashboard from Telegram: if you open the dashboard with the Dashboard button in Telegram, you are signed in with the Telegram account details Telegram shares with the dashboard (your Telegram user ID and name). No Google sign-in is needed, and we use these details only to check it is you, not to store anything new.
- Diary entries: notes you write in the dashboard. These are encrypted before we store them.
- Health readings (optional, with your consent): if you connect Health Auto Export on iPhone (or a compatible Health Connect export app on Android), or send readings to the coach, we keep only these daily values: resting heart rate, heart-rate variability, sleep time, deep sleep time, time in bed, steps, body weight, body-fat percentage, lean mass, active energy, resting energy, a readiness score and a short note of up to 280 characters. We also keep where each reading came from and when it arrived, plus a record of your consent. Everything else in an export is thrown away and the raw export is not stored. Health readings are encrypted before we store them.
- Health import key: a private key that lets your export app send readings to your account. We store only a one-way hash of it, and connecting again replaces it. It is deleted when you stop imports or delete your health data.
Connected tools (optional)
- If you create a personal access token with /connect, the apps you give it to can read your DadMode data and add notes; you can revoke tokens any time with /disconnect.
- What we keep: for each token, a one-way hash of it (never the token itself), the label you chose, and when it was created and last used. We also keep the last 30 notes your apps add, with their source and type. Notes that match a safety topic are marked with its category, and the coach sees your notes from the last 7 days.
- Your coaching brief and profile answers can also be updated by tools you connect; the coach follows your brief unless it conflicts with its safety rules.
Payments (paid membership)
- Your Stripe customer ID, subscription ID, subscription status, the date the current billing period ends and whether you have used a free trial. Card details go straight to Stripe and we never see them. We share your Telegram chat ID with Stripe as a reference so we can match payments to your account.
- If you use a tester discount code, Stripe records which code was applied to your subscription.
Security records
- To stop people guessing pilot invite codes, admin passwords or import keys, we count attempts using a one-way hash of your IP address (or of the import key), with a counter and a timestamp. We do not store the IP address itself. Our hosting provider also processes IP addresses in its own request logs.
- Our application logs use shortened one-way hashes instead of Telegram chat IDs.
Cookies and browser storage
dadmode_pilot_invite: set on the private pilot page when you enter a valid invite. It lasts 30 days and contains a keyed hash (HMAC), not the invite code.dadmode-dashboard-link: stored in your browser’s session storage for the dashboard. It holds the one-time link from Telegram until your account is linked, is then removed, and is cleared when you close the tab.dadmode-telegram-launch: stored in your browser’s session storage when you open the dashboard from Telegram. It holds only the value “1”, so that after a reload the dashboard asks you to reopen it from Telegram. Your Telegram sign-in details are never stored in the browser. It is cleared when you close the dashboard.- Netlify Identity keeps you signed in to the dashboard using its own cookies and browser storage.
All of these are strictly necessary for the service to work, so we do not ask for cookie consent. We do not use advertising or analytics cookies.
3. Why we use your data and our lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing coaching in Telegram and the dashboard, including transcription, photo analysis, food lookups and check-in messages | Telegram identity, onboarding answers, messages, transcripts, diary, usage records | Contract (Article 6(1)(b)): we need this to provide the service you asked for |
| Using health and medical information, including onboarding answers about conditions, imported health readings and your data log (meals, workouts, body measurements and notes) | Special category health data | Contract (Article 6(1)(b)), plus your explicit consent (Article 9(2)(a)) |
| Safety screening, which stops the coach answering where a topic needs a clinician or specialist support, and the eating-disorder safety marker that keeps calorie and weight advice off | Messages, safety screening records, safety marker | Legitimate interests in keeping users safe (Article 6(1)(f)); for health information, your explicit consent (Article 9(2)(a)) |
| Profiling to personalise coaching and check-ins: working out your readiness call, trends, drifts and (where safe) a calorie suggestion, and choosing which check-in to send and when (see section 8) | Data log, health readings, coach memory, messages, check-in history and outcomes | Contract (Article 6(1)(b)); for health information, your explicit consent (Article 9(2)(a)) |
| Improving the service using redacted learning signals, feedback and support notes. An AI model suggests general coaching lessons, and a person reviews and approves each one before it is used for all users | Redacted learning excerpts, feedback, support notes | Legitimate interests in improving coaching quality and safety (Article 6(1)(f)) |
| Billing and managing subscriptions | Stripe IDs, subscription status | Contract (Article 6(1)(b)); legal obligation to keep financial records (Article 6(1)(c)) |
| Security, abuse prevention and keeping the service running | Hashed IP records, rate-limit counters, pseudonymous logs | Legitimate interests in protecting users and the service (Article 6(1)(f)) |
| Telling you when a place opens, if you join the pilot waitlist on the pilot page without an invite code | Email address, the sport or activity you picked, and the date you joined | Your consent (Article 6(1)(a)): you can withdraw it at any time by emailing [CONTACT EMAIL], and we will delete the entry |
Explicit consent and how to withdraw it. Before health readings are imported, we ask for your consent and keep a record of it. By choosing to give the coach health or medical information during onboarding or in chat, you agree to us using it to tailor your coaching. You can withdraw consent at any time:
- send
/disconnecthealth, or use “Stop health imports” in the dashboard, to stop new imports (existing readings stay until you delete them); - send
/deletehealth, or use “Delete health readings” in the dashboard, to delete stored health readings and your import key; - send
/delete_me confirm, or delete your account in the dashboard, to delete everything, including onboarding answers; or - email [CONTACT EMAIL] to ask us to remove particular information.
Withdrawing consent does not affect anything we did before. Without health information the coach can only give more general advice.
Objecting to service improvement. You can object to your redacted signals being used by emailing [CONTACT EMAIL] or by deleting your data with /delete_me confirm. Approved lessons are general coaching rules. They are checked so they do not contain names, contact details or information about any one person, and they are not linked to you.
We do not sell your data or use it for advertising.
4. Who we share data with
We use these providers to run DadMode. Where they act as our processors, they may only use the data on our instructions.
- Netlify, Inc. (United States): hosts the website and dashboard, stores DadMode’s data and provides dashboard sign-in (Netlify Identity).
- Telegram: carries your messages to and from the coach. Telegram handles your messages as its own controller under its privacy policy.
- OpenAI (United States): writes coaching replies, transcribes voice notes, analyses images, turns messages about meals, training, weigh-ins and how you feel into your data log, picks out coach-memory notes from your recent messages and helps suggest general lessons from redacted signals. We use OpenAI’s API under its API terms, which do not use API data to train models by default. OpenAI may keep API data for a limited time, for example to monitor abuse. If you use
/meal, the meal description you type is sent to OpenAI’s image model to draw the picture; charts and session cards are drawn on our own servers and are not sent to any third party other than Telegram, which delivers them to you. - Google (United States): sign-in for the dashboard. The private pilot page also loads fonts from Google Fonts, which means Google receives your IP address when you view that page.
- Stripe: processes membership payments and runs the billing portal.
- Apps you connect yourself: if you give a personal access token to another app or bot, that app can read your DadMode data and add notes. It is your choice and runs under that app’s own terms; we do not send data to it unless it asks with your token.
- USDA FoodData Central and FatSecret: when you describe food, we may send a short food search phrase taken from your message (for example “porridge with banana”, up to 120 characters) to look up nutrition values. We do not send your name or account details.
- Uptime monitoring: our message-processing service sends a regular “still running” signal to a monitoring service. It contains no personal data.
- Health Auto Export and other export apps that you install are provided by other companies under their own terms. They send data from your phone to us; we do not share data with them.
Our message-processing service runs on a computer we control [CONFIRM LOCATION AND ANY HOSTING PROVIDER]. We may also disclose data if the law requires it, to protect someone’s safety, or as part of selling or reorganising the business (in which case this notice would still apply).
5. International transfers
Some of these providers process data in the United States or other countries outside the UK. Where that happens, we rely on appropriate safeguards such as UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework, where the provider is certified), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Contact us for more information about these safeguards.
6. How long we keep data
| Data | How long |
|---|---|
| Profile, onboarding answers, subscription status, check-in preferences, feedback and support messages | Until you delete your account or ask us to delete them |
| Conversation history, including transcripts | The most recent 1,000 entries; older entries are overwritten automatically. All deleted when you delete your account |
| Diary entries | Until you delete your account |
| Personal access tokens (hash, label and dates) and notes from your connected tools | Tokens until you revoke them with /disconnect or delete your account; the most recent 30 notes until you delete them or your account |
| Health readings and consent record | Until you delete them, or delete your account |
| Data log (logged meals, workouts, body measurements and notes) | Until you remove items with /undo or /log delete, or delete your account. There is no automatic expiry, because the log exists to show longer-term totals and trends |
| Learning signals (redacted excerpts) | 180 days, or sooner if you delete your account |
| Safety screening records | 180 days, or sooner if you delete your account |
| AI usage records (model, token counts, time) | Until you delete your account |
| Daily usage counters and per-account message-rate counters | 35 days |
| Message processing records used to avoid duplicate replies | 7 days |
| One-time dashboard links | 15 minutes, then removed by a daily clean-up |
| Hashed security records (invite, admin sign-in and import attempts) | The count resets after 15 minutes (invite and admin sign-in attempts) or 24 hours (import requests). The record holds only the hash, a count and a time, and is not linked to your account |
| Pilot invite cookie | 30 days |
| Pilot waitlist entry (email address, chosen sport and the date you joined) | 12 months, then deleted automatically by a daily clean-up. Email [CONTACT EMAIL] to have it deleted sooner. It is encrypted at rest and is not linked to a DadMode account |
| Payment records held by Stripe | As long as Stripe and UK tax law require (usually six years) |
| Coach memory (notes about your preferences and circumstances, and if-then plans you agreed to) | Until you remove them with /forget or delete your account. We keep at most 60 notes and 20 plans; when there are more, the least certain and oldest notes are dropped first |
| Check-in state and outcomes (which kinds of check-in we sent and when, whether you replied within a day, this week’s focus, and, encrypted, the number a check-in was about and how it changed a week later) | Until you delete your account. Only the most recent 30 check-ins and 30 outcomes are kept; older ones are overwritten automatically |
| Eating-disorder safety marker | One mild screen expires after 30 days. A hard referral or repeated mild screen stays until a person removes it after a review, or you delete your account |
| Free-trial marker (a one-way keyed hash of your chat ID and the date the trial was used) | Kept after you delete your account, with no fixed end date, so that a free trial cannot be started again by deleting and re-joining. It holds no chat ID, name or other details |
| Approved general coaching lessons | Kept while useful. They contain no personal data |
When you delete your account, we first cancel any subscription and delete your customer record at Stripe (if Stripe cannot be reached, nothing is deleted and you can try again). We then delete the data listed above from DadMode’s store, including redacted learning signals linked to your pseudonymous code, and we try to delete your dashboard login. If deleting the login fails, we tell you and finish the job manually. For 7 days afterwards we keep a marker holding only your chat ID, so that a message still being processed when you deleted cannot re-create your data. Records of automatic lesson suggestions have their suggested text removed when anyone deletes their account, and are deleted after 90 days. Deletion does not remove copies held by Telegram, your phone or your export app, or data a provider keeps for a limited time under its own terms. We keep a one-way marker that a free trial was used, to prevent repeat trials. It cannot be turned back into your chat ID.
Our encrypted backups are kept for a limited time and may still hold your data for a while after you delete your account. To make sure a restore from backup can never bring it back, we keep a deletion record for one year: a one-way code derived from your chat ID with a secret key, the date of deletion and the pseudonymous code of your learning signals. It holds no chat ID, name or content, and it is used only to skip your data when a backup is restored. It is then deleted.
7. Your rights
You have the right to:
- access your data;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use your data;
- receive your data in a portable format (portability);
- object to uses based on legitimate interests; and
- withdraw consent at any time.
How to use them:
- Dashboard: download a JSON copy (your profile, stored health readings, your full data log, up to 1,000 recent conversation entries, up to 100 diary entries, notes from your connected tools, your personal access tokens (label and dates only), redacted learning excerpts, feedback, support messages, safety records and a usage summary), stop or delete health imports, or delete your account.
- Telegram:
/exportshows a summary of what is stored;/todayand/logshow your data log, and/undoand/log deleteremove items from it;/restart_onboardinglets you redo your answers;/deletehealthdeletes health readings;/connectionslists your personal access tokens and/disconnectrevokes them;/delete_me confirmdeletes your coaching data; reply “mute” to stop check-in messages. - Email: [CONTACT EMAIL] for anything else, including a full copy of your data or a correction.
We will reply within one month. For complex requests we can extend this by up to two more months, and if so we will tell you why. We may need to confirm who you are first.
8. Automated decisions and profiling
Every message goes through an automated safety check before the coach replies. If a message suggests a situation that needs a clinician or specialist support (for example signs of an eating disorder, pregnancy, some medical conditions or medications, performance-enhancing drugs, dangerous weight cutting, or that you are under 18), the coach may decline to give a plan and point you to appropriate help instead. The coach may also reply more cautiously. If the check finds signs of an eating disorder in your own messages, we also keep the safety marker described in section 2, so the coach stops giving calorie and weight advice from then on.
Profiling. To personalise your coaching, our code automatically analyses your data log (meals, workouts, body measurements and notes), your health readings if you have connected them, your coach memory and your check-in history. From these it works out:
- a daily readiness call (Go, Caution or Back off) from your sleep, heart-rate variability, resting heart rate and training load;
- trends and personal baselines, such as your usual sleep, training volume, protein and weight trend;
- drifts, which are patterns worth mentioning, such as shorter sleep or fewer sessions than usual;
- where it is safe to do so, a calorie suggestion based on your logged food and weight trend. It is never given if the safety check, your answers or your preferences rule calorie advice out; and
- which check-in to send, if any, and when. This includes sending fewer of the kinds of check-in you tend to ignore.
This analysis only shapes the coach’s messages. It has no legal or similarly significant effect on you: it does not decide your price, your access to the service or anything outside coaching, and how you feel always counts for more than the numbers. You can turn it down or off at any time: reply “mute” or send /mute to stop all check-ins; send /mornings off to stop the morning readiness note; send /disconnecthealth or /deletehealth to stop using or delete health readings; remove items from your data log with /undo or /log delete; remove memory notes with /forget; or delete everything with /delete_me confirm. You can also object by emailing [CONTACT EMAIL].
None of these checks has legal or similarly significant effects on you. The under-18 check blocks coaching; if you have a subscription, contact us and we will cancel and refund it. If you think a check got it wrong, including the eating-disorder safety marker, email [CONTACT EMAIL] and a person will look at it.
9. Age
DadMode is only for people aged 18 or over. If someone tells the coach they are under 18, their account is blocked from coaching straight away. They, or a parent or guardian, can delete everything at once with /delete_me in Telegram, or by contacting us, and we will delete any account we confirm belongs to someone under 18.
10. How we protect your data
- Your chat history (including voice-note transcripts and photo captions), your profile answers, coaching brief and notes, coach memory, health readings, data log, diary entries, and the text of feedback, support messages and safety records are encrypted at rest with AES-256-GCM by our own service, on top of our hosting provider’s storage security. Each kind of data has its own key derived from our master secret, and each record is bound to its own account, so an encrypted record cannot be read as someone else’s. The few fields our systems need to route messages and billing without decrypting anything stay readable to them: account and chat IDs, whether onboarding is finished, subscription and funding status, opt-outs and blocks, and dates.
- Data is sent over encrypted connections (TLS) between your device, our services and our providers.
- Dashboard access needs both a sign-in and a one-time link sent in your Telegram chat, or opening it from Telegram, which confirms your Telegram account with a signature we check. Each login can see only its own linked account.
- Logs use hashed identifiers, and security records store hashed IP addresses.
- Only authorised people can open the admin tools, which need a separate admin sign-in. Learning excerpts, feedback, support messages and safety records are shown there against pseudonymous codes, not chat IDs.
DadMode is not end-to-end encrypted. Our service holds the keys: Telegram messages, transcripts and image analyses are decrypted and processed in readable form by our service and our AI provider so the coach can reply, and authorised admins see feedback, support and safety records in readable form. Short, redacted learning excerpts and usage and billing records are protected by our hosting provider’s storage security rather than our own extra encryption. No system is completely secure.
11. Complaints
Please contact us first at [CONTACT EMAIL]. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.
12. Changes to this notice
We will update this notice when our practices change and change the date at the top. If a change materially affects how we use your data, we will tell you in Telegram or the dashboard before it takes effect.
See also our terms of use.