Draft for the private pilot — placeholders in brackets must be completed before launch.
US privacy notice
Last updated September 29, 2026. This notice is for members and visitors in the United States. If you live in the United Kingdom, read our UK privacy notice.
This notice explains what personal information DadMode collects, why, who we disclose it to, how long we keep it, and the choices and rights you have. It is also our notice at collection under the California Consumer Privacy Act (CCPA) and our consumer health data privacy policy under Washington’s My Health My Data Act and similar state laws (see section 7). DadMode is only for adults aged 18 or over.
The short version. We use what you tell the coach to coach you. Most of it is encrypted before we store it. An AI provider (OpenAI) reads your messages so the coach can reply. We do not sell your personal information or your health data, we do not share it for targeted advertising, and we do not use advertising or analytics cookies. You can see, download and delete your data yourself, and deleting your account also cancels your subscription.
1. Who we are
DadMode is provided by [TRADING NAME] ([COMPANY NUMBER IF ANY]), [REGISTERED ADDRESS]. We decide how and why your information is used (we are the “business” or “controller” under state privacy laws, and the “regulated entity” under consumer health data laws).
Contact us about privacy at [CONTACT EMAIL]. You can also send /bug or /feedback to the coach in Telegram, but please use email for formal requests.
2. What we collect
When you use the coach in Telegram
- Telegram identity: your Telegram chat ID and the first name (or username, if there is no first name) that Telegram shares with the bot.
- Onboarding answers: what you want to be called, age, goals and why they matter, starting point (for example height, weight and training level), training history, weekly availability, equipment, eating pattern, dietary preferences and restrictions (which can include allergies or religious requirements), how much tracking you want, schedule constraints, sleep, stress and energy, coaching style, things the coach should never do, your time zone and biological sex.
- Health information you choose to share: injuries, pain, medical conditions, medications, eating-disorder history and advice from clinicians.
- Your messages: text messages and the coach’s replies. We keep the most recent 1,000 entries per person.
- Voice notes: we send the audio to our AI provider to transcribe and store the transcript. We do not store the audio file.
- Photos and images: we send the image to our AI provider for analysis. We store a “[photo]” marker, your caption and the coach’s reply, not the image. With each voice note or image we also keep Telegram’s file reference (a
file_id) and basic details such as file type, size, dimensions or duration. Telegram itself may still hold the file under its own terms. - Documents: if you send a PDF or a text file (Markdown, TXT, CSV, JSON or XML), our service reads the text and sends up to 20,000 characters of it to our AI provider with your message. We store a “[document]” marker, the file name, basic file details and your caption, not the document or its text.
- Health screenshots: if you have agreed to us using your health information and send a screenshot that looks like a health or wearable app, our AI provider may read numbers such as resting heart rate, sleep or weight from it, and nothing is added to your health readings until you confirm the numbers. If you have said no, or not answered yet, no numbers are read from it: the coach replies to the picture, and nothing it read or said about it is kept.
- Your data log: meals, workouts, body measurements and notes the coach picks out of your messages, stored encrypted to power totals and trends. After the coach replies to a message that looks like a meal, a workout, a weigh-in or how you feel, an AI model turns it into short structured records (for example “oatmeal with banana, about 350 calories” or “run, 3 miles, 28 minutes”) with the date, where it came from and whether the numbers are your own or an estimate. Totals such as daily calories and protein are added up by our code.
/todayand/logshow them, and/undoand/log deleteremove them. - Challenges and goal tracking: if you start a challenge (for example “1,000 push-ups by the end of October”) we keep an encrypted ledger of the challenge, its target, due date and each amount you log. When our own code cannot read a progress report (“did another 25 before school drop-off”), a small AI model sees only that message and your own list of challenges, and suggests which challenge and amount it means. Our code checks the suggestion before anything is counted.
- Your plan, saved meals and coaching preferences: the current plan the coach is working to and the changes it has made, meals you ask it to remember, and how you like coaching presented. All are encrypted.
- Reminders and nudges: reminders you set (label, time, time zone and how often), a record of the ones we sent, and, if you say yes to them, challenge nudges on days you have not logged. These are encrypted, and you can see, pause and delete them in the dashboard or with
/reminders. - Feedback and support: what you send with
/feedbackor/bug. A bug report also keeps up to the last 8 messages of your conversation, so we can see what went wrong. - Coach memory: short, encrypted notes about your preferences and circumstances (for example your schedule, gear or an injury to work around), notes you add with
/remember, and if-then plans you agree to. It never keeps health numbers or other people’s names./memoryshows them and/forgetremoves them. - Safety screening records: when an automated check spots a safety concern (see section 9), we store the category and an encrypted excerpt of up to 400 characters of the message. If the concern is about suicide or self-harm, or comes from a private onboarding answer, we store the category only, never your words.
- Eating-disorder safety marker: if the safety check finds signs of an eating disorder in your own messages, we keep an encrypted marker (the date and whether the signs were strong or mild) that pauses calorie targets, deficits and weight-trend advice (see section 9).
- Learning signals: short excerpts of up to 200 characters, automatically redacted to remove things like names, emails, phone numbers and addresses, stored against a pseudonymous code (a keyed hash of your chat ID) rather than your chat ID. If you have agreed to us using your health information and send a health screenshot, a short summary of the numbers read from it can be kept as a learning signal in the same way. Without that agreement nothing read from a screenshot is kept.
- Check-in and message preferences: whether you have muted check-ins and update messages or turned on the morning readiness note, which kinds of check-in, tip or update we sent and when, whether you replied, and (encrypted) the number a check-in was about and how it changed a week later.
- Usage records: for each AI request, the model used, the number of tokens and the time, plus daily usage and message-rate counters.
- Your own API key (founding members only): a few original pilot members use their own OpenAI API key. We store it encrypted and use it only for that member’s coaching.
Before you share health information. Straight after it checks that you are 18 or over, and before it asks about your body, food, sleep, injuries, conditions, medication or eating history, the coach asks whether we may collect and use the health information you share to coach you. The question says what we collect (your training, food, weight, sleep and health readings), why (to coach you), and who processes it (our hosting provider stores it and our AI provider processes it to write replies), and links both our UK and US privacy notices. It is a separate yes-or-no question, not part of accepting our terms. We keep a record of your answer, when you gave it and which version of the question you saw. Members who joined before this question existed are asked it at their next message. If you say no, you still get general coaching: we do not keep health readings, weight or meal details, and the coach does not use any we already hold; onboarding skips the health questions; the coach keeps no notes about injuries, conditions or medication; what the coach says about a photo you send is not kept; learning signals keep only their category, not your words; and automatic health imports are switched off. Challenge counts you ask the coach to track (such as reps or distances) are kept either way. Until you answer, the message you sent is held, checked by our safety screen (a voice note is transcribed for that check only) and answered once you reply. Our chat history itself is still kept, as described in section 8. You can change your answer at any time with /consent in Telegram or in the dashboard.
When you use the dashboard
- Sign-in: the dashboard uses Netlify Identity with Google sign-in. Netlify Identity holds your account email address and the basic profile details Google shares. Our coaching data store keeps only an account ID that links your login to your Telegram coaching account.
- Opening the dashboard from Telegram: Telegram shares your Telegram user ID and name with the dashboard so we can check it is you. We do not store anything new from this.
- Diary entries: notes you write in the dashboard, encrypted before we store them.
- Health readings (optional, with your consent): if you connect Health Auto Export on iPhone (which reads from Apple Health) or a compatible Health Connect export app on Android, send readings to the coach, or confirm numbers from a screenshot, we keep only these daily values: resting heart rate, heart-rate variability, sleep time, deep sleep time, time in bed, steps, body weight, body-fat percentage, lean mass, active energy, resting energy, a readiness score and a short note of up to 280 characters, plus where each reading came from, when it arrived, and a record of your consent. Everything else in an export is thrown away. Health readings are encrypted before we store them.
- Health import key: a private key that lets your export app send readings to your account. We store only a one-way hash of it.
Connected tools (optional)
- If you create a personal access token with
/connect, the apps you give it to can read your DadMode data and add notes. We keep a one-way hash of each token (never the token), its label and dates, and the last 30 notes your apps add. You can revoke tokens any time with/disconnect.
Payments
- Your Stripe customer ID, subscription ID and status, the date the current period ends and whether you have used a free trial. Card details go straight to Stripe and we never see them. Stripe also collects the email address and billing details you enter at checkout. We share your Telegram chat ID with Stripe as a reference so we can match payments to your account.
The pilot waitlist
- If you join the waitlist on the pilot page without an invite, we keep your email address, the sport or activity you picked and the date you joined. It is encrypted and is not linked to a DadMode account.
Security records, cookies and browser storage
- To stop people guessing invite codes, admin passwords or import keys, we count attempts using a one-way hash of your IP address (or of the import key). We do not store the IP address itself. Our hosting provider also processes IP addresses in its own request logs. Our application logs use shortened one-way hashes instead of Telegram chat IDs.
dadmode_pilot_inviteis a 30-day cookie set on the pilot page when you enter a valid invite; it holds a keyed hash, not the code.dadmode-dashboard-linkanddadmode-telegram-launchare held in your browser’s session storage only while you use the dashboard. Netlify Identity uses its own cookies and browser storage to keep you signed in.- All of these are strictly necessary. We do not use advertising or analytics cookies, and our pages load no third-party fonts, scripts, pixels or trackers.
3. Notice at collection
This table sums up the categories of personal information we collect (using the CCPA’s category names), where it comes from, why we use it and who receives it. We collect it from you, from your device and apps you connect, from Telegram, Google and Stripe, and by inference from what you tell us.
| Category | Examples | Why we use it | Disclosed to (for a business purpose) | Sold or shared? |
|---|---|---|---|---|
| Identifiers | Telegram chat ID and name, dashboard email address, Stripe customer ID, hashed IP address | Providing the service, sign-in, billing, security | Netlify, Telegram, Google, Stripe; OpenAI receives only the name you ask the coach to use, never your chat ID or email | No |
| Customer records | Billing details you give Stripe | Billing | Stripe | No |
| Characteristics of protected classifications | Age, biological sex, religious dietary requirements | Tailoring coaching; the under-18 block | Netlify, OpenAI | No |
| Commercial information | Subscription status, trial use, checkout sessions | Billing | Stripe, Netlify | No |
| Internet or other electronic activity | Usage records, rate counters, message processing records | Running and securing the service, cost limits | Netlify | No |
| Audio and visual information | Voice notes and photos (not stored; transcripts and captions are) | Transcription and image reading for coaching | OpenAI, Telegram | No |
| Consumer health data and other sensitive personal information | Health information you share, health readings, data log, safety records, eating-disorder marker | Coaching you, keeping you safe (see section 7) | Netlify, OpenAI | No |
| Inferences | Readiness call, trends, drifts, calorie suggestion, coach memory | Personalizing coaching and check-ins | Netlify, OpenAI | No |
| Other content you send | Messages, documents, diary, challenges, reminders, feedback, bug reports | Providing and improving the service | Netlify, OpenAI, Telegram | No |
Our nightly encrypted backups of all of the above are stored with Dropbox (see section 8). How long we keep each category is in section 8.
4. How we use your information
- To coach you in Telegram and the dashboard: replies, transcription, reading photos and documents, food lookups, your plan, data log, challenges, reminders and nudges you ask for.
- To keep you safe: the automated safety screen, the eating-disorder safety marker and the under-18 block (see section 9).
- To personalize coaching and check-ins from your data log, health readings, coach memory and check-in history (see section 9).
- To send short service messages in Telegram about new features and useful commands, at most one a day. Reply “mute” to stop them.
- To improve the service from redacted learning signals, feedback and support notes. An AI model suggests general coaching lessons, and a person reviews and approves each one before it is used for all members. Approved lessons contain no personal information and are not linked to you.
- To bill you and manage your membership.
- To secure and run the service, prevent abuse, and keep encrypted backups so we can recover from a failure.
- To tell you when a place opens, if you join the pilot waitlist.
- To meet legal obligations and respond to lawful requests.
We do not use your information for advertising, and we do not use your sensitive personal information to infer characteristics about you beyond what coaching needs.
5. Who we disclose it to
We use these service providers (also called processors) to run DadMode. They may use your information only to provide their services to us.
- Netlify, Inc. (United States): hosts the website and dashboard, runs parts of our service, stores DadMode’s data (Netlify Blobs) and provides dashboard sign-in (Netlify Identity).
- OpenAI (United States): writes coaching replies, transcribes voice notes, reads images, documents and health screenshots, builds your data log, reads challenge progress reports the goal tracker cannot settle on its own, picks out coach-memory notes and helps suggest general lessons from redacted signals. To write a reply, the coach sends OpenAI your message with your recent conversation and a summary of your recent record. When your message needs it (for example “what did I log for that protein bar in June?”), the coach can also look up older parts of your own saved record — your food and training log, a past day, your health readings, saved meals, plan, challenges, coach memory, notes from your connected tools and earlier messages — and what it finds is sent to OpenAI with that request only. These look-ups read only your own record and never change it. If you have said no to us using your health information, or have not answered yet, they do not reach your food, training, weight or health records. We use OpenAI’s API under its API terms, which do not use API data to train models by default, and we ask OpenAI not to store our requests as saved responses. OpenAI may keep API data for a limited time, for example to monitor abuse. If you use
/meal, the meal description you type is sent to OpenAI’s image model to draw the picture. Founding members on their own API key send their coaching requests to OpenAI under their own OpenAI account. - Dropbox, Inc. (United States): stores our nightly backup files. They are encrypted before they leave our computer, and Dropbox cannot read them.
- Nutrition databases (Open Food Facts, USDA FoodData Central, FatSecret, Nutritionix and Edamam): when you describe food, we may send a short food search phrase taken from your message (up to 120 characters), or a product barcode you send, to look up nutrition values. Open Food Facts is always used; the others only when we have an account with them. We do not send your name, chat ID or account details, and the request comes from our server, not your device.
- Uptime monitoring: our message-processing service sends a regular “still running” signal to a monitoring service. It contains no personal information.
These companies also receive information when you use their services, under their own terms and privacy policies:
- Telegram carries your messages to and from the coach and delivers voice notes, photos and documents to us. Chats with bots are not end-to-end encrypted by Telegram.
- Google signs you in to the dashboard through Netlify Identity, and receives the fact that you signed in to DadMode.
- Stripe processes payments and runs the billing portal. It is our service provider for payments and makes its own decisions about fraud prevention and its legal duties.
- Apps you connect yourself with a personal access token can read your DadMode data and add notes, because you told us to let them. Health Auto Export and other export apps you install send data from your phone to us; we do not send data to them.
Our message-processing service runs on a computer we control in the United Kingdom, so your information is processed in both the United States and the United Kingdom. Admin alerts (for example that a crisis referral was sent) go to our own admin Telegram chat and name you only by a pseudonymous code, never your words.
We may also disclose information if the law requires it, to protect someone’s safety, or as part of a sale or reorganization of the business (in which case this notice would still apply).
6. We do not sell or share your information
We do not sell personal information, we do not “share” it for cross-context behavioral advertising, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing information of anyone under 16. We do not sell consumer health data. Because we use sensitive personal information only to provide the service you ask for, keep it secure and meet legal duties, we do not offer a separate “limit the use of my sensitive personal information” choice; there is nothing further to limit.
If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of sale and sharing. Since we do neither, nothing changes. We do not disclose personal information to third parties for their own direct marketing (California’s “Shine the Light” law).
7. Consumer health data privacy policy
Washington’s My Health My Data Act, Nevada’s consumer health data law, and similar laws in other states give extra protection to information linked to you that identifies your past, present or future physical or mental health. At DadMode that includes health information you share in chat or onboarding, health readings, numbers from health screenshots, your data log (meals, workouts, body measurements), safety records and the eating-disorder marker, coach memory about injuries or conditions, and inferences such as readiness.
- What we collect and where it comes from: the health-related items in section 2, from you, your phone’s export app, and our AI provider’s reading of what you send.
- Why: only to provide the coaching you ask for, to keep you safe while using it, and to keep the service secure. We ask for your consent before collecting it, as described in section 2, and you can withdraw consent at any time with
/consent noin Telegram or in the dashboard. Withdrawing stops us collecting it;/consent deletedeletes what we hold. - Who receives it: our processors Netlify, OpenAI and Dropbox (encrypted backups only), which act on our instructions. Apps you connect with a personal access token receive it only because you direct us to. We do not share consumer health data with anyone else, and if that ever changes we will ask for your separate consent first. We never sell it.
- Your rights: you can confirm whether we collect, share or sell your consumer health data; get a copy of it and a list of every third party and processor that received it (the list in this section); withdraw your consent; and have it deleted, including from our backups, which are overwritten within 30 days. See section 10 for how to ask and how to appeal.
8. How long we keep information
| Information | How long |
|---|---|
| Profile, onboarding answers, subscription status, check-in preferences, feedback and support messages | Until you delete your account or ask us to delete them |
| Conversation history, including transcripts | The most recent 1,000 entries; older entries are overwritten automatically. All deleted when you delete your account |
| Diary entries | Until you delete your account. We keep the most recent 1,000 |
| Personal access tokens and notes from your connected tools | Tokens until you revoke them or delete your account; the most recent 30 notes until you delete them or your account |
| Health readings and consent record | Until you delete them, or delete your account |
| Data log | Until you remove items with /undo or /log delete, or delete your account |
| Challenges and their ledger | Until you archive or correct them, or delete your account |
| Reminders and the record of the ones we sent | Until you delete them or your account. At most 24 reminders and the most recent 120 deliveries |
| Your plan, saved meals and coaching preferences | Until you delete your account |
| Coach memory | Until you remove it with /forget or delete your account. At most 60 notes and 20 plans |
| Check-in state and outcomes | Until you delete your account. Only the most recent 30 of each are kept |
| Your own OpenAI API key (founding members only) | Until you delete it with /delete_key or delete your account |
| Learning signals and safety screening records | 180 days, or sooner if you delete your account |
| Records of automatic lesson suggestions | 90 days. Their suggested text is removed sooner if anyone deletes their account |
| Eating-disorder safety marker | One mild screen expires after 30 days. A hard referral or repeated mild screen stays until a person removes it after a review, or you delete your account |
| AI usage records | Until you delete your account |
| Daily usage and message-rate counters | 35 days |
| Message processing records used to avoid duplicate replies | 7 days |
| One-time dashboard links | 15 minutes |
| Hashed security records | Up to 24 hours of counting, deleted after two days without use; never linked to your account |
| Pilot invite cookie | 30 days |
| Pilot waitlist entry | 12 months, then deleted automatically. Email [CONTACT EMAIL] to have it deleted sooner |
| Payment records held by Stripe | As long as Stripe and tax law require |
| Prepaid credit ledger and checkout sessions | Paid ones until you delete your account; an unpaid checkout is deleted after 30 days |
| Free-trial marker (a one-way keyed hash of your chat ID and the date) | Kept after you delete your account so a free trial cannot be started again. It holds no chat ID, name or other details |
| Encrypted nightly backups | 30 days, then deleted automatically |
| Approved general coaching lessons | Kept while useful. They contain no personal information |
When you delete your account, we first cancel any subscription and delete your customer record at Stripe (if Stripe cannot be reached, nothing is deleted and you can try again). We then delete the information above, including redacted learning signals linked to your pseudonymous code, and we try to delete your dashboard login; if that fails, we tell you and finish the job manually. For 7 days afterward we keep a marker holding only your chat ID, so a message still being processed cannot re-create your data. Your data can stay in an encrypted backup for up to 30 days. To make sure a restore can never bring it back, we keep a deletion record for one year that holds no chat ID, name or content. Deletion does not remove copies held by Telegram, your phone or your export app, or data a provider keeps for a limited time under its own terms.
9. Automated processing, profiling and safety
Every message, transcript and document goes through an automated safety check before the coach replies. If a message suggests a situation that needs a clinician or specialist support (for example thoughts of suicide or self-harm, signs of an eating disorder, pregnancy, some medical conditions or medications, performance-enhancing drugs, dangerous weight cutting, or that you are under 18), the coach may decline to give a plan and point you to appropriate help instead. If the check finds signs of an eating disorder in your own messages, we keep the safety marker described in section 2, and the coach stops giving calorie and weight advice. After a safety concern, reminders, nudges and check-ins pause for a while.
To personalize coaching, our code analyzes your data log, health readings (if connected), coach memory and check-in history to work out a daily readiness call, trends and baselines, drifts worth mentioning, where safe a calorie suggestion, and which check-in to send, if any. This only shapes the coach’s messages. It is not used to make decisions that produce legal or similarly significant effects about you, such as your price or your access to the service. You can turn it down or off: reply “mute” or send /mute, send /mornings off, /disconnecthealth or /deletehealth, remove items with /undo, /log delete or /forget, or delete everything with /delete_me confirm.
If you think a check got it wrong, including the eating-disorder marker or the under-18 block, email [CONTACT EMAIL] and a person will look at it.
If you are in crisis. The coach is not a crisis service. In an emergency, call 911. If you are thinking about suicide or are in emotional distress, call or text 988 (the 988 Suicide & Crisis Lifeline), any time.
10. Your privacy rights
Depending on the state you live in (including California, Colorado, Connecticut, Virginia, Texas, Oregon, Washington, Nevada and a growing number of others), you may have the right to:
- know and access the personal information and consumer health data we hold about you, including the categories, sources, purposes and recipients, and get a copy in a portable format;
- have inaccurate information corrected;
- have your information deleted;
- withdraw consent to our use of sensitive or health information;
- opt out of sale, sharing, targeted advertising and profiling that produces legal or similarly significant effects (we do none of these); and
- not be discriminated against for using any of these rights. We will not charge you more or give you a worse service for using them.
How to use them:
- Dashboard: download a full JSON copy of your data, stop or delete health imports, manage reminders, or delete your account.
- Telegram:
/exportshows a summary of what is stored;/today,/log,/undoand/log deletemanage your data log;/memoryand/forgetmanage coach memory;/challengeand/remindersmanage challenges and reminders;/restart_onboardingredoes your answers;/deletehealthdeletes health readings;/disconnectrevokes connected apps;/delete_me confirmdeletes your account. - Email: [CONTACT EMAIL] for anything else.
We will confirm we received your request within 10 business days and respond within 45 days. If we need more time, we will tell you why, and we can extend by up to another 45 days. We may need to verify who you are, usually by asking you to make the request from your Telegram account or signed-in dashboard. You can use an authorized agent; we may ask for proof of their authority and to confirm your identity directly.
Appeals. If we decline your request, you can appeal by emailing [CONTACT EMAIL] with “Privacy appeal” in the subject. We will answer within the time your state’s law allows (usually 45 or 60 days) and explain our decision. If you are not satisfied, you can contact your state attorney general.
11. Children
DadMode is only for people aged 18 or over and is not directed to children. We do not knowingly collect personal information from anyone under 18. If someone tells the coach they are under 18, their account is blocked from coaching right away. They, or a parent or guardian, can delete everything with /delete_me in Telegram or by contacting us, and we will delete any account we confirm belongs to someone under 18 and refund any subscription.
12. How we protect your information
- Your chat history, profile answers, coaching brief and notes, coach memory, health readings, data log, challenges, reminders, plan, saved meals, coaching preferences, diary, your own API key if you have one, redacted learning excerpts, and the text of feedback, support messages and safety records are encrypted at rest with AES-256-GCM by our own service, on top of our hosting provider’s storage security. Each kind of data has its own key, and each record is bound to its own account.
- Data travels over encrypted connections (TLS). Dashboard access needs a sign-in plus a one-time link from your Telegram chat, or opening it from Telegram, which we verify.
- Logs use hashed identifiers. Only authorized people can open the admin tools, which need a separate sign-in and show records against pseudonymous codes.
- Backups are encrypted with a key pair: the computer that makes them holds only the half that locks them, and the half that opens them is protected by a separate passphrase.
DadMode is not end-to-end encrypted. Our service holds the keys: messages, transcripts, documents and image analyses are decrypted and processed in readable form by our service and our AI provider so the coach can reply. No system is completely secure. If a breach affects your information, we will notify you as the law requires.
13. Changes to this notice
We will update this notice when our practices change and change the date at the top. If a change materially affects how we use your information, we will tell you in Telegram or the dashboard before it takes effect, and we will ask for your consent again where the law requires it.
14. Contact
[TRADING NAME], [REGISTERED ADDRESS]. Email [CONTACT EMAIL].
See also our US terms of use. Members in the United Kingdom: UK terms · UK privacy notice.