This policy explains what Shape collects, why we collect it, who we share it with, and the choices you have. It applies to theshapecommunity.com and any connected apps or services operated by Shape ("Shape," "we," "our"). By using Shape you accept this policy; if you do not agree, please don't use the service.
Information we collect
Account & profile. Name, email, password hash, role (client, trainer, nutritionist), bio, profile photo, and—if you're a coach—credentials, specialties, and business details submitted during application.
Fitness & health information you choose to share. Goals, workout logs, session notes, meal plans, macro targets, weight, measurements, performance metrics, and progress photos. We treat this as sensitive data and apply stricter protections below.
Payment information. Shape uses Stripe for all payments. Card details are entered directly into Stripe; Shape receives only the last four digits, card brand, and transaction status. We never see, store, or transmit full card numbers.
Communications. Messages you send through our in-app chat with coaches, consultation notes, and support requests.
Usage & device. IP address, browser type, device identifiers, pages visited, referring pages, session timestamps, and basic analytics. Collected automatically for security and product improvement.
Third-party fitness, health, and audio connections (optional). Shape only pulls the specific data types you authorize during each provider's OAuth or HealthKit consent flow — nothing more. The services you can currently connect are:
- Apple Health / Apple Watch / Apple Fitness (HealthKit). Workouts, heart rate, activity, sleep, and other metrics you enable in the iOS Health permissions sheet. Available only through the Shape iOS app; HealthKit is not exposed on the web.
- Strava. Activities, routes, and basic profile, via Strava OAuth. See Strava's privacy policy.
- Garmin Connect. Workouts, heart rate, calories, sleep, and similar metrics from your Garmin device, via Garmin's Health API consent flow. See Garmin's privacy policy.
- Whoop. Recovery, strain, sleep, and workout data, via Whoop OAuth. See Whoop's privacy policy.
- Spotify. Basic profile and the playlists you choose to share with Shape (used for in-workout audio). See Spotify's privacy policy.
You can disconnect any of these services from your account settings at any time. Disconnecting stops new data from syncing; previously synced data remains in your Shape account until you delete it (see Section 06).
Health & medical data
Coaching involves sensitive health information. Beyond the fitness data above, Shape may collect, at your choice: a health-and-readiness screening (PAR-Q answers, prescription medications, allergies, pregnancy or postpartum status, ongoing medical conditions, injuries, and an emergency contact), body measurements and girths, weigh-ins and body-fat readings, progress photos, training and nutrition logs, weekly check-ins (sleep, energy, stress, hunger, adherence), and recovery metrics from connected wearables (heart rate, HRV, sleep). We treat all of this as sensitive personal information and apply the safeguards in Section 05 (Data security) — including per-user row-level access controls and private, signed-URL storage for photos and voice notes. We ask for your consent before collecting health data. Because several US laws regulate this specifically, we maintain a separate Consumer Health Data Privacy Policy that governs it in detail.
Who can see it. Your health and training data is visible to you and to the specific coach(es) you are linked to — no one else. Most data is share-gated: you choose what your coach sees. Your safety screening (PAR-Q answers, injuries, medications, emergency contact) is made available to a linked coach so they can work with you safely. Cancelling a coaching relationship ends that coach's ongoing access.
HIPAA. Shape is a consumer fitness and coaching platform — not a healthcare provider, health plan, or clearinghouse — and the trainers and nutritionists on Shape act as independent fitness professionals, not as your medical providers. Health information you enter here is therefore consumer health data, not "Protected Health Information (PHI)" under HIPAA, and HIPAA generally does not apply. We nonetheless treat this information as sensitive and protect it as described in this policy. Shape is not a substitute for professional medical care — see the medical disclaimer in our Terms.
Your control. You can edit your health data and adjust what each coach can see from Settings, export a copy or delete your account and data yourself from Settings, or make a request at any time by emailing privacy@theshapecommunity.com.
How we use your information
- Provide core service: account creation, authentication, billing, and matching clients with coaches.
- Personalize your experience: showing relevant trainers/nutritionists, calculating Shape Score, and recommending programs.
- Facilitate coaching: sharing relevant client data with the specific coach(es) a client has subscribed to or booked — never more broadly.
- Handle payments: processing the $5/month membership, coach subscriptions, and one-off purchases through Stripe.
- Operate the platform: fraud detection, debugging, security monitoring, and platform improvements.
- Communicate: transactional email (receipts, booking confirmations, password resets), product updates, and—only if you opt in—marketing.
- Comply with legal obligations, including tax reporting for coaches earning revenue on the platform.
We do not use your fitness or health data to train machine-learning models or sell targeted advertising.
Information sharing & processors
We do not sell your personal information. We share it only in these specific situations:
With the coach(es) you subscribe to or book. A trainer you've subscribed to sees the workout data, goals, and messages relevant to coaching you. A nutritionist you hire sees your meal log and targets. You control the relationship: cancel any time and that coach's ongoing access ends.
Publicly visible information. Some profile information is visible to other Shape members by design: your name or handle, profile photo, role, Shape Score and tier, and anything you post publicly or set to "Profile" visibility. This information may appear on your public profile, in community feeds, in search, and on leaderboards. You control it in Settings — set your profile to Public, Friends, or Private. Your health, training, and nutrition data is never made public; it is limited to you and the coach(es) you link with.
The coaches you link with are independent professionals and third-party recipients of the data you choose to share with them — not our processors. They agree by contract to keep it confidential, use it only to coach you, and meet their own legal obligations.
With subprocessors who help us run Shape. Each is bound by contract to protect your data and use it only to deliver their service to us. The complete, versioned list — with the data each receives, its region, and the transfer safeguard — is on our Subprocessors page. In summary:
- Supabase — database, authentication, and file storage (holds the bulk of your data, including health data).
- Stripe — payments, subscriptions, Connect payouts to coaches. See Stripe's privacy policy.
- Vercel — web hosting, edge delivery, and product analytics. See Vercel's privacy policy.
- Cloudflare — DNS, network security, and the Turnstile bot check.
- OpenAI — the "Nora" assistant, voice transcription, and text-to-speech. Depending on the feature, the text sent can include health and fitness context; it is processed only to generate your response.
- Google Firebase Cloud Messaging — push notifications.
- Resend — transactional (and, where you opt in, marketing) email.
- Instacart — only when you choose to send it a grocery list.
- Wearable & audio services you connect — Apple Health, Strava, Garmin, Whoop, Oura, Spotify.
We do not sell your personal information and do not share it for cross-context behavioral advertising, and we do not use your fitness or health data to train artificial-intelligence models.
With law enforcement or legal counterparties when required by subpoena, court order, or applicable law, or to protect the rights, safety, and property of Shape or others.
In connection with a business transfer (merger, acquisition, financing) — recipients are bound by this policy.
Data security
Shape uses industry-standard safeguards:
- TLS 1.2+ for all traffic in transit.
- Encryption at rest for database tables and storage.
- Role-based access controls; engineering staff access logged and minimized.
- Short-lived session tokens with automatic rotation.
- Payment data handled only by Stripe (PCI-DSS Level 1).
- Regular dependency audits and vulnerability patching.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any regulator required by law (typically within 72 hours of discovery).
Your rights
Depending on where you live, you may have the right to:
- Know / access: request a copy of the personal information we hold about you, and the categories of recipients we've shared it with.
- Correct: update inaccurate or incomplete data.
- Delete: request we erase your account and associated data (subject to limited legal-retention needs such as tax records).
- Port: receive your data in a portable, machine-readable format.
- Opt out of any "sale" or "sharing" of personal information, of targeted advertising, and of profiling — although Shape does none of these.
- Limit the use of sensitive personal information to what's needed to provide the service.
- Withdraw consent (including for health data), object to or restrict processing, and opt out of marketing (unsubscribe links in every marketing email; transactional email cannot be disabled).
- Appeal a decision we make on your request, and be free from discrimination for exercising any right.
How to exercise them. Use our privacy request form, export or delete your data directly in Settings, or email privacy@theshapecommunity.com. You may use an authorized agent. We verify your identity proportionately. We acknowledge California requests within 10 business days and respond within 45 days; GDPR and other state requests within one month (extendable where the law allows). If we deny a request you may appeal by replying to our response; if an appeal is denied you may contact your state attorney general or, in the EEA/UK, lodge a complaint with your data protection authority.
EEA/UK lawful bases (GDPR). We rely on: contract for your account, core coaching, and payments; explicit consent for health/special-category data and for optional analytics and marketing; legitimate interests for security, fraud prevention, and product improvement; and legal obligation for tax and compliance records.
Your privacy choices
Do Not Sell or Share My Personal Information. Shape does not sell your personal information and does not share it for cross-context behavioral advertising, so there is nothing to opt out of — but if that ever changes we will provide a working opt-out here first.
Limit the Use of My Sensitive Personal Information. We use sensitive information (including health data) only to provide the coaching and features you ask for, to keep the platform secure, and as this policy describes — never to infer characteristics for advertising. To ask us to limit it further, email privacy@theshapecommunity.com.
Global Privacy Control (GPC). We recognize the GPC browser/extension signal as a valid opt-out of sale/sharing for the browser that sends it. (GPC honoring is being wired in; until it is fully automated, send opt-outs to the address above.)
Categories & retention
For California and other US state laws, the categories of personal information we collect, why, who we disclose them to, and how long we keep them:
- Identifiers & account (name, email, username, profile) — to run your account; disclosed to Supabase, Stripe, Vercel; kept while your account is active.
- Sensitive / health data (screening, medications, allergies, pregnancy, measurements, photos, wearable metrics, check-ins) — to deliver coaching, with your consent; disclosed to your chosen coach(es), Supabase, and (for AI features) OpenAI; kept while active, deleted on request.
- Commercial & financial (membership, purchases, payout records) — to process payments and meet tax law; disclosed to Stripe; financial records kept 7 years.
- Internet / device & usage (IP, device identifiers, analytics) — for security and product improvement; disclosed to Vercel and Cloudflare; kept on a rolling short-term basis.
- Communications & content (messages, posts, support requests) — to operate coaching and community; disclosed to Supabase (and Resend for email); support kept 2 years.
We do not sell or share any of these categories. Deleted-account data is removed within 30 days except records we must keep by law; backups expire within 90 days.
Notice of financial incentive
Our Shape Score rewards program lets you earn points through qualifying activity and redeem them in the Shape Store. Because points can be earned partly in connection with logging activity, this may be treated as a "financial incentive" under California law, so: participation is voluntary, you may withdraw at any time, and declining is not a condition of using the paid service and does not degrade it. The program runs to reward engagement, not to purchase your data; any reasonable estimate of the value of data to Shape relates only to the cost of operating the program. To opt out, email privacy@theshapecommunity.com.
Cookies & tracking
We use cookies and similar technologies for these purposes:
- Strictly necessary: session cookies that keep you logged in and protect against CSRF, and the Cloudflare Turnstile bot-protection challenge on login/signup forms (which processes your IP to tell humans from bots). Cannot be disabled without breaking the site.
- Functional: remember your preferences (e.g., dashboard view, active role) across sessions.
- Analytics: Vercel Analytics collects aggregate, privacy-friendly usage data (page views, referrers) to help us improve the product — no advertising pixels and no cross-site tracking.
- Fraud prevention: on pages with payments, our processor Stripe sets its own cookies (e.g.,
__stripe_mid,__stripe_sid) to detect and prevent fraud.
We do not use advertising or cross-site tracking cookies. For visitors in the EEA and the UK we present a consent banner to control non-essential storage, and we honor the Global Privacy Control signal. You can also block or delete cookies in your browser settings; doing so may sign you out or disable certain features.
Data retention
We keep personal data only as long as we need it:
- Active accounts: kept for as long as the account is active.
- Deleted accounts: removed within 30 days of your deletion request, except for records we must keep by law (e.g., tax records are retained for 7 years).
- Financial records: retained for 7 years to comply with U.S. tax law.
- Backups: may contain deleted data for up to 90 days before they expire.
- Support correspondence: retained for 2 years.
Children's privacy
Shape is for adults 18 and older. We are not directed to children and do not knowingly collect personal information from anyone under 18; we verify age with a neutral date-of-birth check at sign-up (being rolled out), and we delete any account we learn belongs to a minor. If you believe a minor has created an account, email privacy@theshapecommunity.com and we will delete it promptly.
International transfers & representatives
Shape is operated from the United States, so if you access it from outside the U.S. your personal data is transferred to, stored in, and processed in the U.S. For people in the EEA and the UK, we rely on the safeguard appropriate to each recipient — the EU-US Data Privacy Framework where the recipient is certified, or European Commission Standard Contractual Clauses (with the UK International Data Transfer Addendum) and a transfer impact assessment where it is not. The per-recipient safeguard is listed on our Subprocessors page.
EU & UK representatives. Where required by Article 27 of the GDPR / UK GDPR, we will appoint and publish here an EU representative and a separate UK representative who can be contacted about this policy. (Appointment in progress.) Until then, reach us at privacy@theshapecommunity.com.
Changes to this policy
We may update this privacy policy. Material changes will be announced via email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top of this page always reflects the current version. Continued use after the effective date means you accept the updated terms.
Contact us
General questions about this policy: info@theshapecommunity.com or the contact page. To exercise a privacy right or report a security issue, email privacy@theshapecommunity.com. See also our Consumer Health Data Privacy Policy, Subprocessors list, and Data & compliance page.
Questions about your data?
We'll walk you through what we hold, how it's used, and how to export or delete it. One business day turnaround.
Contact privacy team →