Privacy, data and security
What support can say about how Straton handles data. The full documents are public:
| Document | Address |
|---|---|
| Terms of Service | straton.fit/legal/terms |
| Privacy Policy | straton.fit/legal/privacy |
| Cookie Policy | straton.fit/legal/cookies |
| Subprocessors | straton.fit/legal/subprocessors |
When a question needs a precise legal answer, point to these documents or pass
it to privacy@straton.fit rather than paraphrasing.
Who is responsible for what
- Straton is operated by Straton Suite LLC.
- For a coach’s own account data, Straton is the data controller.
- For client data inside a coach’s workspace, the coach is the controller and Straton processes it on the coach’s behalf. Clients with a request about that data should contact their coach first.
- For individuals using Straton on their own, Straton is the controller.
What Straton collects
- Account details: name, email, sign-in details, profile, team membership.
- Applications: contact details and answers given on a coach’s onboarding page, the chosen package and consent records.
- Coaching data: profile, programs and workout logs, nutrition, check-ins, intake forms, habits, progress photos, body measurements, notes and messages.
- Health data shared from Apple Health, when connected: sleep, resting heart rate, heart rate variability, steps, active energy and workouts from other apps.
- Billing details: what was bought and when. Full card numbers are held by the payment provider, never by Straton.
- Technical data: device, browser, IP address, usage and error reports.
- Support conversations.
Health and body data
- Body measurements, photos, nutrition logs and injury notes are sensitive data. Straton asks for explicit consent before processing them.
- Clients give consent in the app, and can withdraw it in Profile > Privacy and data.
- Applicants give consent on the coach’s onboarding page before answering health questions.
- Progress photos have their own separate, optional consent.
- Straton is not a HIPAA-compliant service and must not be used to store protected health information or medical records.
AI
- Straton does not use coach or client content to train AI models.
- Only the content needed for a task is sent to AI providers, under terms that prohibit training on it.
- The Agent never contacts clients on its own. Nothing is assigned or sent to a client until the coach approves it.
- AI output can be incomplete or wrong. Coaches should review it before using it with a client.
Security
- Data is encrypted in transit and at rest.
- Access requires sign-in, and workspace roles control who sees what.
- Regular encrypted backups.
- Card payments are handled by payment providers. Straton does not store full card numbers.
- Straton does not sell personal information, and a coach’s client list is never shared or sold.
Do not claim certifications. Straton has not completed SOC 2 or ISO 27001 and is
not HIPAA-compliant. Security reports go to security@straton.fit.
Service providers
Straton uses a small number of providers to run the service, including hosting
and storage, email delivery, push notifications, real-time messaging, payments
(Polar for coach plans, Stripe for coaching payments, Apple for App Store
subscriptions), support chat, product analytics and AI providers. The current
list is at straton.fit/legal/subprocessors.
For questions about where data is hosted, refer to that page or to
privacy@straton.fit.
Cookies
- The website and web app use cookies. The iOS app does not.
- Necessary cookies keep you signed in and protect the site.
- Analytics cookies are used to understand product usage. Where the law requires consent, they stay off until allowed.
- There are no advertising cookies.
- Change your choice with Cookie preferences in the website footer, or Settings > Privacy > Manage in the web app.
Your choices and rights
Getting a copy of your data
| Who | How |
|---|---|
| Applicant (before paying) | Download my data at the bottom of the application page |
| Coach client or individual | Email privacy@straton.fit from the account’s email address |
| Coach, for a client | Workspace Owners and Admins can export a client’s data. Contact support for help |
A view-only workspace can still export data.
Deleting data
| Who | How | Timing |
|---|---|---|
| Applicant (before paying) | Cancel & delete application on the application page | Immediate |
| App user | Profile > Privacy and data > Delete account | Signed out at once. Deleted after 30 days. Signing in again within 30 days cancels it |
| Coach, a whole workspace | Settings > General > Danger zone > Delete workspace (Owner only) | Deleted after 30 days. Keep workspace cancels it before then |
| Coach, one client’s data | Owners and Admins can request erasure of a client’s data. Contact support | |
| Coach, their own account | Email privacy@straton.fit |
Things to know:
- Archiving a client does not delete their data.
- Deleting an account does not cancel a subscription. Cancel it first.
- Backups may hold deleted data for up to 30 further days.
- Some billing, tax and legal records are kept longer where the law requires.
- After an account is closed or a deletion is requested, data is kept for up to 30 days, then deleted.
Unfinished applications
- Drafts abandoned for 30 days are deleted.
- Declined applications are deleted after 90 days.
- Applications waiting for review or payment expire after 90 days without activity, and their sensitive answers are deleted.
Age
- 18 or older to use Straton on your own.
- 16 or older to be coached. Clients aged 16 or 17 need a parent or guardian’s agreement, which the coach is responsible for obtaining.
- Straton is not for anyone under 16. The app asks for a date of birth and does not let anyone under these ages continue.
- If someone reports an under-16 account, pass it to
privacy@straton.fit.
Data processing agreement
Coaches who need a data processing agreement can request one from
privacy@straton.fit.
What to escalate
Send these to the support team or privacy@straton.fit. Do not answer them
from this article:
- a request to access, correct, export or erase personal data;
- a report of a data breach, account takeover or security weakness;
- a request from a lawyer, regulator or law enforcement;
- questions about hosting location, certifications or contract terms;
- anything involving a person under 16.