PRIVACY POLICY

PRIVACY POLICY.

EFFECTIVE MAY 6, 2026

Eumorphic (“Eumorphic,” “we,” “us”) is a software service operated by Inexcelsis, LLC (d/b/a NanoScript), a Florida limited liability company. This policy explains what data we collect, why, and how we protect it. It applies to two distinct sets of people: trainers who sign up for Eumorphic, and prospects + clients who interact with those trainers through Eumorphic-powered features.

1. Data we collect

From trainers (Eumorphic account holders): name, email, password hash, phone number, business name and address, billing details (processed by Stripe), and any content you upload — workout plans, meal plans, client records, photos, message templates, and your tenant configuration.

From your social media accounts (when you connect them): if you connect an Instagram Business or Facebook Page through our OAuth flow, we receive a Page-scoped access token and basic metadata about that Page or Instagram account (Page id, Page name, Instagram username, Instagram business account id). We never receive your Meta password.

From prospects who message your connected accounts: when a prospect sends a direct message to your Page or Instagram, Meta delivers the message to our webhook. We store the message text, the sender's Meta user id (an opaque identifier scoped to your Page), and timestamps. We do not receive the prospect's personal Meta profile.

From your clients (when you onboard them): name, email, phone, fitness goals, training history, injuries, progress measurements + photos, workout/meal-plan adherence, and any messages they exchange with you in the client portal.

Automatically: log data (IP, user agent, request paths) for security and abuse prevention; cookies for session management.

2. How we use it

To deliver the service you signed up for: route DMs to your inbox, run the AI assistant on inbound messages, generate workout/meal plans, process payments via Stripe, send transactional emails + push notifications, and produce the analytics shown in your admin dashboard. We do not sell data. We do not use your data or your prospects' data to train any AI model — including our own.

3. Third-party processors

We rely on a small set of vendors. Each receives only what they need to perform their function:

  • Anthropic, PBC — generates AI replies, workout plans, and meal plans. Receives the conversation history or client profile relevant to the request. Anthropic's zero-retention policy applies. Tenants on the “Bring Your Own Key” option send requests to Anthropic with their own API key, in which case Anthropic is processing on their behalf, not ours.
  • Stripe, Inc. — payment processing. Receives card details directly; we never store full card numbers.
  • MinIO — encrypted object storage for uploaded files (logos, progress photos, plan PDFs). Hosted on infrastructure under our control.
  • SendGrid — transactional email delivery.
  • Twilio — SMS / WhatsApp notifications, when enabled by the tenant.
  • Cloudflare — DNS, CDN, Turnstile bot protection.
  • Meta Platforms, Inc. — for the Messenger and Instagram Graph APIs. We act as a Tech Provider on the connected Page, sending and receiving on the trainer's behalf within the scope they authorized.

4. Meta + Instagram data, specifically

Meta Page access tokens are encrypted at rest using AES-256-GCM and used only to send and receive messages within the scopes you authorized: pages_messaging, instagram_manage_messages, pages_show_list, pages_read_engagement, pages_manage_metadata, instagram_basic, business_management. Webhook payloads are verified with HMAC-SHA256 against your app secret before we accept them. You can disconnect any Page at any time from Settings → Social; on disconnect we delete the access token and stop receiving webhooks for that Page. You can also revoke our access from your Meta Business Settings, which triggers our data deletion flow.

5. Retention

We keep tenant + client data for as long as the tenant maintains an active Eumorphic account, plus 30 days after deletion request to allow recovery. After 30 days the data is purged from primary databases; encrypted backups roll off at 90 days. Conversation + message data tied to a Meta user who revokes app access is deleted within 24 hours of the revocation callback (see § 7).

6. Your rights

You can request a copy of your data, correction, or deletion at any time by emailing [email protected]. EU/UK residents have additional rights under GDPR (access, rectification, erasure, restriction, portability, objection); California residents under CCPA. Trainers can also delete their account directly from Settings → Account.

7. Meta data deletion callback

When a Meta user revokes Eumorphic from their Meta settings, Meta sends our app a signed deletion request. We verify the signature with HMAC-SHA256 against our app secret, then delete every Conversation and Message tied to that user's id from our database. We return a confirmation code; you can check the deletion status at eumorphic.app/data-deletion-status. We do not retain a backup copy of the deleted records.

8. Security

Data in transit is TLS-encrypted. Tokens, BYO API keys, and other secrets are AES-256-GCM encrypted at rest. Access to production systems is role-restricted with MFA. We log security-relevant events for incident response.

9. Children

Eumorphic is not directed to children under 13 (or under 16 in jurisdictions requiring it). We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account.

10. Changes

If we change this policy materially, we'll notify active tenants by email at least 14 days before the change takes effect.

11. Contact

Inexcelsis, LLC (d/b/a NanoScript)
[email protected]
Florida, United States.