Privacy Policy

DNAi Systems
Version 2.0 · Effective March 1, 2026 · Last Updated February 28, 2026
Applies to all DNAi products including Asha and Harley AI.

Our Core Principles: We collect only what we need. We never sell your data. We never share your health or fitness information with advertisers or insurance companies. You control your data and can delete it at any time.

1. Information We Collect

1.1 Information You Provide

Data TypeExamplesRetention
Account InformationName, email, role (trainer/client)Until account deletion
Profile InformationAge, gender, countryUntil account deletion
Health Context (Asha)Medications, conditions, allergiesUntil account deletion
Fitness Data (Harley)Workouts, sets, reps, weight, body measurementsUntil account deletion
Nutrition Data (Harley)Food logs, macro targetsUntil account deletion
ConversationsChat messages, AI responsesUntil you delete them (Asha*); 1 year then anonymized (Harley*)
Trainer Business DataClient lists, schedules, exercise librariesUntil account deletion
Progress PhotosPhotos uploaded by clientsUntil deleted by user

*Conversation retention note: Asha conversations are retained until you manually delete them because users often reference prior health discussions over long periods. Harley conversations are automatically anonymized after 1 year because fitness coaching interactions have a shorter useful lifespan and anonymization reduces the data protection burden on trainers acting as data controllers. In both cases, you may delete your conversations at any time.

1.2 Information Collected Automatically

Data TypePurposeRetention
Device InformationService optimization90 days
Usage DataProduct improvement (anonymized)90 days
IP AddressSecurity, regional content30 days
Server LogsSecurity, debugging30 days

1.3 Wearable Device Data (Optional)

If you connect a wearable device (e.g., Whoop), we may collect recovery scores, heart rate variability (HRV), resting heart rate, sleep metrics, strain scores, skin temperature, and SpO2.

Wearable data is biometric data. It is never sold, never shared with advertisers or insurance companies, never used for underwriting, and is used only to personalize your fitness recommendations. You may disconnect your device at any time to stop collection and request deletion.

1.4 Information We Do NOT Collect

2. How We Use Your Information

2.1 Service Provision

2.2 Service Improvement

2.3 Communication

2.4 What We Will NEVER Do

3. AI Processing

3.1 How Your Data Is Processed

When you interact with any DNAi product: your message is encrypted and sent to our servers; we retrieve relevant context from your profile; your query is processed by our AI system; a response is generated and returned to you.

3.2 AI Service Providers

We use the following AI providers to process queries. This list is updated as providers change; your data may be processed by any provider listed below:

ProviderUseData Handling
Google Vertex AI (Gemini)Primary LLM for query processingEnterprise data protection, Zero Data Retention (ZDR)
Anthropic (Claude)LLM for query processing and analysisEnterprise data protection, Zero Data Retention (ZDR)
Local ModelsPrivacy-sensitive operations, knowledge synthesisProcessed on DNAi-controlled infrastructure

All third-party AI providers process data under strict contractual obligations with zero data retention (ZDR) — your queries are processed and immediately discarded. No third-party provider uses your data to train their models. We may add or change AI providers over time; this policy will be updated to reflect any changes, and material changes will be notified per Section 13.

3.3 Knowledge Synthesis and Improvement

Our AI systems may generate structured knowledge units (such as synthesized medical or fitness insights) derived from your interactions. These knowledge units:

Example: If you ask about a rare condition, our system may generate a synthesized knowledge summary about that condition from medical literature. This summary is stored to improve future responses for anyone asking about the same topic. Your name, account, health profile, and the fact that you asked the question are never included in or linked to the knowledge unit.

We will never use your identifiable health or fitness information to train AI models without your explicit, informed consent. Anonymized, aggregated interaction patterns (such as which topics are most frequently asked about) may be used to prioritize product improvements.

4. Trainer-Client Data Flow (Harley AI)

4.1 What Trainers Can See

Trainers can view their own clients' workout logs, nutrition logs (if used), wearable data summaries (if connected), and progress metrics.

4.2 What Trainers Cannot See

Other trainers' client data, client conversations with Harley AI (unless shared by the client), or client data from other platforms.

4.3 Client Privacy Controls

Clients can view only their own data, disconnect wearable devices at any time, request deletion, and opt out of data sharing with their trainer.

5. Data Security

5.1 Technical Safeguards

MeasureDescription
Encryption in TransitTLS 1.3 for all data transmission between clients, servers, and third-party APIs
Encryption at RestDatabase-level encryption for PostgreSQL and Redis datastores. Application data files (e.g., exported trainer data) are stored on access-controlled infrastructure but are not individually encrypted at the application layer. We are actively working toward full application-level encryption at rest.
Password Hashingbcrypt with salting
Access ControlsRole-based access with JWT-based authentication; multi-factor authentication via Auth0
Tenant IsolationUser-scoped data access at both application and storage layers, preventing cross-tenant data leakage

5.2 Organizational Safeguards

5.3 Data Breach Notification

5.4 Limitations

While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of your data.

6. Information Sharing

6.1 Service Providers

Provider CategoryPurposeSafeguards
Cloud InfrastructureHosting, storageData processing agreements
AI Providers (Google Vertex AI)Query processingZero Data Retention, contractual protection
Payment Processor (Stripe)Subscription billingPCI-DSS compliant
Cloudflare (CDN, Pages, DNS)Content delivery, static site hosting, DDoS protection, DNSIP addresses, request metadata, and static page requests. Cloudflare Pages hosts the frontend applications for Asha and Harley.
Wearable APIs (Whoop)Device syncUser-initiated OAuth, revocable
Food Databases (Open Food Facts, USDA)Nutrition lookupSearch queries only, no personal data
Authentication (Auth0)Identity managementEnterprise data protection agreement

All providers are bound by data processing agreements and are prohibited from using your data for their own purposes.

6.2 Legal Requirements

We may share information if required by valid legal process (subpoena, court order), to protect rights, property, or safety, or to investigate fraud or security issues.

6.3 We Will NEVER Share With

7. Cookies and Tracking

8. Your Rights

8.1 All Users

8.2 EU Users (GDPR)

8.3 California Users (CCPA/CPRA)

8.4 India Users (DPDP Act 2023)

8.5 US HIPAA Considerations

DNAi products are wellness tools and not "Covered Entities" under HIPAA. However, we maintain technical safeguards informed by HIPAA standards (TLS 1.3 in transit, database-level encryption at rest, access controls, audit logging, Business Associate Agreements with applicable providers) as part of our Privacy by Design commitment.

8.6 How to Exercise Your Rights

Email privacy@dnai.systems with subject "Data Request — [Your Request Type]". We will respond within 30 days.

9. International Data Transfers

Your data may be processed in the United States and the European Union (via compliant providers). When transferring data internationally, we use Standard Contractual Clauses (EU), Data Processing Agreements, and compliance with local data protection laws.

10. Children's Privacy

Asha is not intended for users under 18. Harley AI is not intended for users under 16. We do not knowingly collect personal information from children below these age thresholds. Users between 16 and 18 (Harley) require parental consent. If you believe we have collected information from a child, contact us immediately at privacy@dnai.systems.

11. De-Anonymization Safeguards

We use industry-standard k-anonymization and differential privacy techniques to ensure that retained analytics cannot be re-linked to an individual. Our anonymization processes are designed to prevent re-identification even when combined with external data sources.

12. Data Retention Summary

Data TypeRetention Period
Account informationUntil account deletion
Health profile / Fitness dataUntil account deletion
Wearable dataUntil device disconnected or account deletion
Conversations (Asha)Until you delete them
Conversations (Harley)1 year, then anonymized
Usage analytics90 days, then anonymized
Server logs30 days
Payment recordsAs required by tax law (typically 7 years)
Anonymized dataIndefinitely (cannot be linked to you)

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email, in-app notification, and banner on the website at least 30 days before taking effect. The "Last Updated" date at the top indicates the most recent revision. Continued use constitutes acceptance.

14. Contact Information

PurposeContact
Privacy inquiries / Data requestsprivacy@dnai.systems
General supportsupport@dnai.systems
Harley supportharley@dnai.systems
Data Protection Officer (EU)dpo@dnai.systems
Grievance Officer (India)grievance@dnai.systems

Quick Reference

Do we sell your data?No, never.
Do we share with advertisers?No, never.
Can you delete your data?Yes, at any time.
Is your data encrypted?Yes, in transit (TLS 1.3) and at rest (AES-256).
Who can see your health information?Only you and our systems.
Do we use your data for ads?No, never.