Privacy Policy
Last updated: June 2026
We take the protection of your personal data seriously. This Privacy Policy informs you in accordance with Art. 13 GDPR about what data we process, for what purpose, and on what legal basis.
Controller
Neese Consulting LLC1914 Thomes Ave, Ste 2 #5296
Cheyenne, WY 82001, USA
Represented by: Neese Consulting LLC
Email: support@neese-consulting.com
1. Overview & Principles
This policy applies to the app Managed., available at managed-os.neese-consulting.com and start-managed-os.neese-consulting.com. User data is primarily stored on servers in the EU (AWS Frankfurt — eu-central-1).
Important: We do not use analytics cookies or tracking tools. Only technically necessary cookies are used.
2. What Data We Process
2.1 Account Data (required)
- Email address → authentication via one-time login code (OTP)
- Session token (JWT) → login status
- One-time login code (valid for a limited time)
These are mandatory for login and account management. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
2.2 Profile Data (voluntary)
You may provide: first name (pseudonym allowed), role, athlete type, business description, target audience, inspiration, goals, preferred color. All of this is entered by you and can be changed or deleted at any time in the app settings. Legal basis: Art. 6(1)(b) GDPR.
2.3 Tracking Data (health data — Art. 9 GDPR)
If you use optional tracking features (workout logs, strength benchmarks, resting heart rate, protein tracking, energy levels), these may qualify as health data under Art. 9 GDPR, as they allow conclusions about your physical condition. We process this data only based on your explicit consent (Art. 9(2)(a) GDPR), granted during onboarding. You may revoke this consent at any time by deleting your account.
2.4 Payment Data
Payments are processed exclusively by Stripe. We do not store payment details (credit card, SEPA, etc.). We only store the Stripe Customer ID, Subscription ID, and subscription status. Legal basis: Art. 6(1)(b) GDPR.
2.5 Technical Data (automatic)
IP address (hashed, max. 30 days), user agent, referrer — collected via our hosting infrastructure (Vercel). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operation and security).
2.6 AI Audit Logs
When using AI personalization, we log: user ID, timestamp, token usage, latency, and success/error status (retention: 90 days). The content of your inputs (prompts) is not stored permanently. Legal basis: Art. 6(1)(b) GDPR (contract performance for the Pro feature) / Art. 6(1)(a) GDPR (consent via optional use).
3. AI Personalization (OpenAI GPT-4.1)
No model training: We use the OpenAI API with training opt-out enabled. OpenAI does not use API inputs to train models. Your prompts are not used for model improvement.
Data transmitted to OpenAI (only when you activate AI personalization): first name (pseudonym possible), business description, target audience, inspiration, tone preference, role, athlete type, 12-month goal — all information you have stored in the app yourself.
Purpose: generation of personalized persona text, story ideas, reel hooks, and day blueprints. Legal basis: Art. 6(1)(a) GDPR (your consent through active use of the optional feature). The AI feature is entirely optional and can be disabled in Settings → AI at any time; all other app features work independently of it.
Provider: OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA. Transfer basis: EU-US Data Privacy Framework + SCCs. DPA: openai.com/policies/data-processing-addendum.
Recommendation: do not input sensitive personal data into AI prompts.
4. AI Chat Assistant (OpenAI GPT-4.1-mini)
What it is: Pro users can chat with an in-app assistant ("Coach"). It is clearly labeled as an AI system in the interface, consistent with Art. 50 of the EU AI Act.
Data transmitted to OpenAI (only when you send a message): your message text, a short context summary generated from your own app data (first name, role, athlete type, 12-month vision, current weekly focus, target numbers you have set, today's top-3 tasks, ritual/energy/protein/recovery status, current streak, your KPIs, and your year-tree progress), and up to 8 prior messages of the same conversation for context.
Purpose: generating a personalized, context-aware reply. Legal basis: Art. 6(1)(a) GDPR (consent through active use of this optional Pro feature).
What we store: the conversation itself lives only in your browser (local app storage) and is never saved on our servers. Server-side we log only a usage record per message — user ID, token counts, response time, and success/error status (retention: 90 days) — never the message content or the reply.
Limits: up to 20 messages per user per day, reset daily.
Provider: OpenAI, L.L.C. (see Section 3 for full provider details, training opt-out, and transfer basis — identical for this feature).
Recommendation: do not share sensitive personal data in chat messages.
5. Cookies, Local Storage & Web Fonts
Cookies (technically necessary — no banner required): Managed. only uses technically necessary cookies (session cookie for login; planned: Cloudflare bot protection). No cookie consent banner is required under § 25 TTDSG.
Local browser storage (not a cookie): We use your browser's LocalStorage for app data caching (offline function), PIN status, and your consent choice. This data does not leave your browser and can be removed at any time via your browser settings or the “Delete Account” button in the app.
Web fonts (Google Fonts): On our website, the web font is loaded only after your explicit consent; when you consent, your IP address is transmitted to Google. Without consent, a system font is used and no request is sent to Google. Your choice is stored locally and can be reset at any time.
6. Data Retention
We store personal data only as long as necessary: account data until deletion; logs for a maximum of 30–90 days. Legal obligations may require longer storage.
7. Data Processors (Sub-processors)
We use the following processors and have concluded Data Processing Agreements (DPAs) under Art. 28 GDPR with all of them, or are in the process of doing so:
- Supabase — database, authentication · Server location: EU (AWS Frankfurt)
- Vercel — hosting, CDN, logs · Server location: EU + USA
- Stripe — payment processing · Server location: USA (DPF-certified)
- OpenAI, L.L.C. — AI personalization & chat assistant (GPT-4.1 / GPT-4.1-mini) · Server location: USA (DPF + SCCs)
8. Third-Country Data Transfers
Since some of our service providers are based in the USA, data is transferred to a third country. The transfer takes place on the basis of the EU-US Data Privacy Framework (DPF) for DPF-certified providers and additionally on the basis of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Primary data storage (Supabase database) takes place in the EU (AWS Frankfurt). Third-country transfers only occur for specific processing operations (AI personalization via OpenAI, hosting logs via Vercel).
9. Your Rights (GDPR)
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR). We have made these rights accessible as far as possible directly within the app (e.g., view and delete your data).
You also have the right to lodge a complaint with the competent data protection supervisory authority. If you reside in Germany, this is the data protection authority of your federal state. Data protection contact: support@neese-consulting.com.
10. Security Measures
We implement technical and organizational measures in accordance with the current state of the art:
- HTTPS / TLS 1.3 everywhere
- HSTS (HTTP Strict Transport Security)
- Row-Level Security in the database (only your own data is accessible)
- Encryption at rest and in transit
- Rate limiting
- Passwordless login (no password storage)
- Automatic session timeouts
11. Updates / Changes to This Policy
This Privacy Policy will be updated in the event of significant changes to data processing or applicable law. Registered users will be notified by email. The current version is always available at start-managed-os.neese-consulting.com/datenschutz.
