Privacy Policy
Effective date: 17 June 2026
Last updated: 3 July 2026
This Privacy Policy explains how Alpha Stream Marketing ("Yoni", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Yoni coaching platform, our website at https://coaching.alphastreammarketing.com, and related services (collectively, the "Service").
Yoni is a coach–client fitness coaching platform. Coaches use Yoni to manage clients, assign training programs and nutrition (macro targets and meal plans), message clients 1:1, and track progress. Because the Service handles health and fitness information, we take particular care with that data and treat it as a special category of personal data under the EU General Data Protection Regulation ("GDPR").
We are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a coach (see Section 12). If you have questions, contact us at vas@alphastreammarketing.com.
1. Who this policy applies to
- Coaches — professionals who hold an account to manage their clients.
- Clients — individuals invited by a coach to use the Service to follow programs, log workouts, track nutrition, and communicate with their coach.
- Visitors — anyone who browses https://coaching.alphastreammarketing.com.
2. What data we collect and why
2.1 Account information
- What: Name, email address, password (managed by our authentication provider), account role (coach or client), and basic profile details.
- Why: To create and secure your account, authenticate you, and provide the Service.
2.2 Client health and fitness data (sensitive)
- What: Body weight, body measurements, progress photos (body photos), workout logs (exercises, sets, reps, loads), check-in notes (such as energy, sleep, and adherence), and food diary entries (meals, descriptions, and photos of food).
- Why: To let coaches design and adjust programs and nutrition, to track client progress over time, and to power optional features. This data reveals information about your health and physical condition and is treated as a special category of personal data under GDPR Article 9 (see Section 4).
2.3 Messaging content
- What: Messages exchanged between a coach and a client through the Service.
- Why: To enable 1:1 communication that is core to coaching.
2.4 Payment information
- What: Subscription tier, billing status, and transaction metadata. Card details are collected and stored by our payment processor (Stripe), not by us.
- Why: To process coach subscriptions and manage billing.
2.5 Technical and usage data
- What: Device and browser information, IP address, log data, and, if you consent, error-diagnostic and crash data.
- Why: To operate, secure, debug, and improve the Service.
We do not buy personal data from third parties, and we do not sell your personal data.
3. Legal bases for processing (GDPR Article 6)
We rely on the following legal bases:
| Processing activity | Legal basis (Art. 6) |
|---|---|
| Providing accounts and core Service features | Contract — performance of our terms with you (Art. 6(1)(b)) |
| Processing coach payments and subscriptions | Contract (Art. 6(1)(b)) |
| Securing the Service, preventing abuse, debugging | Legitimate interests (Art. 6(1)(f)) |
| Optional analytics, crash reporting, push notifications | Consent (Art. 6(1)(a)) |
| Complying with legal and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Processing health/fitness data and progress photos | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) — see Section 4 |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object at any time (see Section 9).
4. Sensitive health data (GDPR Article 9)
Health and fitness data — including body weight, measurements, progress photos, food diaries, and check-in notes — is a special category of personal data. We process it only on the basis of your explicit consent (Art. 9(2)(a)).
- How consent is given. Before the health-data features (Progress, Nutrition, Check-ins) process this data, you are asked to give a separate, affirmative explicit consent — a distinct step, not bundled into acceptance of the Terms. The features stay locked until you consent, and we record that you consented and when.
- You are never required to upload progress photos or detailed health data to use core features.
- You may withdraw consent at any time from within the Service. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
- If you withdraw consent or delete this data, related features (such as progress charts) may no longer function.
Important: Yoni is not a medical device and does not provide medical advice. See our Terms of Service.
5. AI features
Some features use artificial intelligence. To provide them, the relevant content is sent to our AI sub-processor (OpenRouter and the model providers it routes to) for processing. The AI features and the data each one sends are:
- Food photo / label analysis — a meal or product image, or a text description, to estimate macros.
- Restaurant menu scan — a photo of a menu, to suggest dishes that fit your targets.
- AI nutrition coach — to generate personalized feedback we send your nutrition context: your macro targets, recent food-log intake, and most recent body weight.
- AI message drafting (coaches) — the prompt and purpose a coach provides, to draft a client message the coach reviews before sending.
Notes:
- AI output is provided for informational and convenience purposes only and may be inaccurate. It is not nutritional or medical advice.
- The nutrition coach feature processes health/fitness data (targets, intake, weight), which is special-category data — see Section 4. It runs only on features you choose to use.
- We do not use your health/fitness data, photos, or messages to train our own AI models, for advertising, or for cross-user analytics or benchmarking. We use AI providers to return your result only.
- We configure our AI provider (OpenRouter) with data collection disabled, so your content is used only to return your result and is not used to train AI models and is not retained beyond providing the response. You should still avoid submitting content to AI features that you would not want processed by a third party.
- OpenRouter routes requests to underlying model providers; the specific providers used for a given feature may change. Where a model provider would act as an independent recipient of your content, we limit routing accordingly for the health-data path.
6. Sub-processors
We share personal data with the following service providers ("sub-processors") strictly to operate the Service. Each is bound by a data processing agreement and may process data only on our instructions.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Convex | Database, backend, and realtime infrastructure | Account, health/fitness, messaging, usage data |
| Clerk | Authentication and identity | Name, email, login credentials |
| Cloudflare R2 | Storage of photos and files | Progress photos, food photos, uploaded files |
| Vercel | Application hosting and delivery | Technical/log data, data in transit |
| OpenRouter | AI features (food/menu photo analysis, AI nutrition coach, coach message drafting) | Food/menu images and descriptions; nutrition context (targets, recent intake, latest weight) for the coach feature; coach-supplied prompts |
| Stripe | Payment processing | Billing details, payment metadata |
| OneSignal *(optional)* | Push notifications | Device tokens, notification metadata |
| Sentry *(optional)* | Error monitoring and crash reporting | Technical/diagnostic data |
Some of these providers act as independent controllers for parts of the data rather than as our processors — in particular Stripe for payment and fraud-prevention data, which it handles under its own privacy policy. Where we add or replace a sub-processor, we will give notice here (and, where we act as a coach's processor, advance notice to the coach so they may object) before the new sub-processor starts processing.
7. Data retention
- Account and health/fitness data (incl. photos, logs, messages, check-ins): Retained while your account is active and for as long as needed to provide the Service.
- After account deletion: When you erase your account we delete your personal data from our live systems promptly, typically within 30 days, except where we must retain limited records to meet legal, tax, accounting, or fraud-prevention obligations.
- Backups: Residual copies in encrypted backups are purged on our backup-rotation cycle (no later than 90 days) and are not restored to active use in the meantime.
- Consent records: We keep a record that you gave (or withdrew) consent for as long as needed to demonstrate compliance.
- Payment and tax records: Retained as required by law — under Dutch law, administrative/tax records must be kept for 7 years.
Where we act as a coach's processor, we return or delete client data on the coach's instruction and on termination of the coaching relationship, subject to the legal-retention exceptions above.
You can erase your account and data at any time from within the Service (see Section 9).
8. International data transfers
We are based in the Netherlands. Some of our sub-processors may process data outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision, to ensure your data receives an equivalent level of protection. You may request information about these safeguards via vas@alphastreammarketing.com.
9. Your rights
Subject to applicable law, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten").
- Portability / Export — receive your data in a structured, machine-readable format.
- Restriction — ask us to limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests, and to direct marketing.
- Withdraw consent — where processing is based on consent, including for health data and AI features. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Automated decision-making (Art. 22 GDPR) — we do not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI features (e.g. food-photo macro estimates) produce suggestions you and your coach review; they are not automated decisions.
- Lodge a complaint — with your data protection authority. If you are in the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); EU residents may also contact the supervisory authority where they live.
Already built into Yoni: You can export your data as JSON and perform full account and data erasure directly from within the Service. For any request you cannot complete in-product, contact vas@alphastreammarketing.com. We respond within the timeframes required by law (generally one month under GDPR).
10. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information. We will not discriminate against you for exercising your privacy rights.
Under the CPRA, health and fitness information (body metrics, progress photos, nutrition/workout logs) is "sensitive personal information." We use it only to provide and secure the Service and do not use it for any other purpose; you may request that we limit the use of your sensitive personal information. To exercise any of these rights, contact vas@alphastreammarketing.com. We respond to verifiable requests within 45 days (extendable by a further 45 days with notice).
US health-privacy note. Yoni is not a HIPAA-covered entity or business associate, and the Service is not intended to create "protected health information" under US health law; we do not enter Business Associate Agreements. If you are a US resident, state consumer-health-privacy laws — such as Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's data-privacy act — may give you additional rights over your health data; contact us at the address above to exercise them.
11. Cookies and local storage
We use cookies and similar technologies (including browser local storage and IndexedDB) to:
- Keep you signed in and secure your session (strictly necessary).
- Enable offline workout logging and reconnect sync (functional).
- Optionally measure performance and diagnose errors (only with consent).
| Technology | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
| Session / auth cookies | Clerk (our auth provider) | Keep you signed in, secure the session | Strictly necessary | Session / short-lived |
| Browser local storage + IndexedDB (Dexie) | Yoni | Offline workout logging + reconnect sync, UI preferences | Functional | Until you clear it |
| Error/performance diagnostics | Sentry *(if enabled)* | Diagnose errors, measure performance | Optional (consent) | Per provider |
Strictly necessary cookies do not require consent. For non-essential cookies, we request your consent and you can change your choices at any time. You can also control cookies through your browser settings.
12. When we act as a processor for coaches
When a client uses Yoni at the invitation of a coach, the coach is the data controller for the client data the coach directs us to process within their coaching relationship (programs, nutrition, progress, messages), and we act as the coach's processor for that data under our Data Processing Agreement with the coach. Clients should also review their coach's own privacy practices and may exercise their data-subject rights against the coach as controller; we will assist the coach in responding. We remain the controller for account, authentication, billing, security, and Service-operation data, and for any data we determine the purposes of (such as this website and aggregate Service analytics).
13. Children
The Service is not intended for children under 16. We do not knowingly collect personal data from children below this age. Coaches must not invite or add anyone under 16 as a client, and are responsible for the ages of the clients they onboard. If you believe a child has provided us personal data, contact vas@alphastreammarketing.com and we will delete it.
14. Security measures
We implement technical and organizational measures appropriate to the sensitivity of the data, including:
- Encryption of data in transit (TLS) and at rest where supported by our providers.
- Access controls that scope each user's data to their account and coaching relationship.
- Authentication managed by a dedicated identity provider.
- Restricted, signed access to stored photos and files.
- Logging, monitoring, and regular review of our security practices.
No system is perfectly secure. If we become aware of a personal data breach that poses a risk to you, we will notify the relevant authority and affected users as required by law. Where we act as a coach's processor, we will notify the coach (as controller) without undue delay so they can meet their own breach-notification obligations.
15. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes affecting health data or your rights, provide additional notice where required.
16. Contact
Alpha Stream Marketing *(controller)*
KvK (Chamber of Commerce) no.: [KvK number — to add]
Registered address: [registered address — to add], the Netherlands
Privacy contact: vas@alphastreammarketing.com
We have not appointed a Data Protection Officer; whether one is legally required (GDPR Art. 37, given large-scale special-category processing) is under assessment. For any privacy question or to exercise your rights, use the privacy contact above.
If you are in the EEA and believe we have not addressed your concern, you may lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).