Privacy Policy
Last updated: 31 March 2026
1. Who We Are
S+C.ai is operated by Sanara Ltd, a company registered in England and Wales. We are the data controller for the personal data described in this policy. You can contact us at privacy@sandc.ai or by post at the registered office of Sanara Ltd.
2. What Data We Collect
We collect the following categories of personal data:
- Account information: name, email address, and password (stored securely via Firebase Authentication).
- Profile data: age, sex at birth, training experience, goals, available equipment, training schedule, and any health limitations or injuries you disclose during onboarding.
- Training data: workout logs, exercise performance (sets, reps, weight, RPE), programme history, and completion records.
- Usage data: how you interact with the app, feature usage, and session duration. We do not use third-party analytics or tracking pixels.
- Voice data: if you use voice logging, audio is processed in real-time to extract workout data. We do not store audio recordings — only the parsed text result.
3. How We Use Your Data
- To generate personalised training programmes using AI models. Your profile and training history are sent to our AI provider (Anthropic/Google) as context for programme generation.
- To provide coaching features including weekly reviews, workout modifications, and progress tracking.
- To authenticate your account and maintain your session.
- To send transactional emails (password reset, account notifications). We will never send marketing emails without your explicit opt-in consent.
- To improve the quality and safety of our AI-generated programmes through aggregated, anonymised analysis. This includes using anonymised training data to evaluate and improve our AI models, algorithms, and programme generation quality. Anonymised data cannot be used to identify you.
4. Legal Basis for Processing (GDPR)
- Contract: processing your data is necessary to provide the service you signed up for (Article 6(1)(b)).
- Legitimate interest: improving service quality, security, and AI model performance using anonymised and aggregated data (Article 6(1)(f)).
- Consent: for optional processing such as marketing communications (Article 6(1)(a)).
- Health data: your training data and any health information you provide may constitute special category data under GDPR. We process this on the basis of your explicit consent given at registration (Article 9(2)(a)).
5. Third-Party Data Processors
We use the following third-party services to operate S+C.ai:
- Google Cloud Platform (Cloud Run, Cloud SQL) — hosting and database. Data stored in europe-west2 (London). Google acts as a data processor under standard contractual clauses.
- Firebase Authentication (Google) — account management and authentication.
- Anthropic — AI model provider for programme generation. Training context is sent per request; Anthropic does not store or train on this data under their API terms.
- Google AI (Gemini) — AI model provider for chat, voice parsing, and coaching features. Same data handling as above.
- Resend — transactional email delivery.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data and training history is permanently deleted within 30 days. Anonymised, aggregated data (which cannot identify you) may be retained indefinitely for service improvement, AI model training, and research purposes.
7. Your Rights
Under GDPR, you have the following rights:
- Access: request a copy of all personal data we hold about you.
- Rectification: correct inaccurate data via your Settings page or by contacting us.
- Erasure: delete your account and all associated data from Settings, or contact us.
- Portability: request your data in a machine-readable format.
- Restriction: request we limit processing of your data.
- Objection: object to processing based on legitimate interest.
- Withdraw consent: where processing is based on consent, you may withdraw at any time.
To exercise any of these rights, email privacy@sandc.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Cookies and Local Storage
S+C.ai uses essential cookies and local storage for authentication and session management only. We do not use advertising cookies, tracking pixels, or third-party analytics. No cookie consent banner is required as we only use strictly necessary cookies under the Privacy and Electronic Communications Regulations (PECR).
9. International Transfers
Your data is primarily stored in the UK/EU (Google Cloud europe-west2, London). When data is sent to AI providers for programme generation, it may be processed in the United States. These transfers are covered by the providers' standard contractual clauses and the UK-US Data Bridge adequacy regulations.
10. Children
S+C.ai is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors. If you believe someone under 18 has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you via email or an in-app notification. Continued use of S+C.ai after changes are posted constitutes acceptance of the revised policy.
12. Contact
For privacy-related enquiries, contact us at privacy@sandc.ai.
© Sanara Ltd. All rights reserved.