Privacy Policy

ServiceAi HQ LLC · serviceaihq.com · last updated 22 August 2026

ServiceAi HQ LLC ("ServiceAi", "we", "us") develops and licenses business software, operates that software for clients, and provides related consulting. This policy explains what information we handle, why, who we share it with, how long we keep it, and the rights you have.

1. Scope, and the two different roles we play

This policy covers three things, and the distinction matters because our responsibilities differ.

(a) Our own website and marketing. serviceaihq.com and our own enquiries, email and phone lines. Here we decide why and how information is used — we are the business or controller, and this policy governs directly.

(b) Systems we operate for clients. Where a client licenses a system from us, that client's customer, patient and member records belong to the client. The client decides what is collected and why; we process it on the client's instructions as a service provider or processor. If you are a customer, patient or member of one of our clients, that client's own privacy policy governs your information, and requests about it should go to them. We will assist them in responding.

(c) Applications operated by us or by companies under our control, including the Body Ops fitness application. Where we operate an application directly for its users, we act as the business or controller for that application, and sections 4 and 5 apply in full.

2. Information you give us

Enquiries. Name, email address, and optionally a phone number, company name and a message, when you submit a form or email us.

Account information. Where you hold an account with us or with a system we operate, an email address, name, role and authentication credentials.

Booking information. When you book a call, the details you enter in the scheduler, and the appointment record.

Billing information. Company details, billing address and invoice records. Card details are handled by our payment processor and are not stored by us.

Communications. Emails, messages and call records exchanged with us.

3. Information collected automatically

Device and usage data. IP address, browser and device type, operating system, referring page, pages viewed, time on page, and interactions such as clicks and scroll depth.

Cookies and similar technologies. Used for essential site function and for the measurement described in section 8.

Logs. Server, application and security logs generated when systems are accessed.

4. Health, fitness and wellness information

Some applications we operate — in particular the Body Ops fitness application — handle information about a person's body, training and health. This is treated as sensitive personal information and is subject to the additional protections in this section.

What it can include. Training and workout records; sessions logged; recovery, sleep and readiness indicators; nutrition entries; body measurements and related metrics; coaching notes; and messages exchanged with a coach.

Where it comes from. Information you enter directly; information generated by your use of the application; and — only where you explicitly connect it — information from Apple Health, Garmin, Whoop or another device or health service you authorise. Connected sources can include steps, active and basal energy, resting heart rate, heart-rate variability, sleep and body weight. Any such connection is optional, is made by you, and can be disconnected by you at any time.

How it is used. Solely to provide the service to you: to deliver and adapt your programme, to compute readiness, to show your own history, to allow your coach to support you, and to operate, secure and support the application.

Automated coaching and third-party processing — what leaves the app. Some features are produced by an artificial-intelligence service operated by Google. Where you use them, the following is transmitted to that service in order to generate a response:

· Coach conversations — your messages together with assembled training context, which can include a derived readiness summary. Replies are stored so your history persists.
· Meal photographs — sent to identify foods and estimate macronutrients. These are processed transiently and are not retained by us in that flow.
· Voice meal notes — the audio is sent to identify foods. It is transient and is not retained by us.

Speech used to talk to the coach is transcribed on your device; only the resulting text leaves it. Progress photographs you upload are stored in a private bucket and served only through short-lived signed links.

What we do not do with it. We do not sell health or wellness information. We do not share it for cross-context behavioural advertising. We do not use it for advertising or marketing of any kind. We do not provide it to any third party for that party's own purposes, including the training of their models. We do not disclose it to data brokers. Our applications contain no advertising identifier and no advertising software development kit, and do not track you across other companies' apps or websites.

Advertising and analytics tools are not deployed on signed-in application screens. The measurement tools described in section 8 run on public marketing pages only.

Not medical advice. Fitness and wellness applications we operate are not medical devices and do not provide diagnosis, treatment or medical advice. Information and recommendations they generate are for general wellness purposes and should not replace advice from a qualified healthcare professional.

Health information held for clients. Where a client uses a system we operate to hold patient or medical information, that client is responsible for it, and any processing of information subject to specific health regulation is governed by a separate written agreement between us and that client.

5. How we use information

To provide, operate, secure, maintain and support our website, applications and the systems we run for clients; to respond to enquiries and provide quotations; to schedule and conduct meetings; to invoice and collect payment; to communicate about services, changes and incidents; to understand how our public marketing pages are used and improve them; to detect, investigate and prevent fraud, abuse and security incidents; and to comply with legal obligations and enforce our terms.

We do not use information about a client's customers, patients or members for our own marketing.

6. SMS and text messaging

Consent. We send text messages only to people who have opted in — by submitting a form carrying explicit SMS consent language, or by messaging one of our numbers first.

No third-party marketing, ever. Phone numbers and SMS opt-in consent are not shared with, sold to, or disclosed to any third party or affiliate for their marketing purposes.

Opting out. Reply STOP to any message to unsubscribe, or HELP for help. Message frequency varies. Message and data rates may apply. Full terms: SMS Terms & Conditions.

7. Phone calls

Calls to our business numbers may be answered by an automated assistant when a person is unavailable. Voicemails may be transcribed and delivered to us in writing. Where a call is recorded or transcribed, notice is given at the start of the call, and recordings and transcripts are handled as described in this policy.

8. Analytics, measurement and advertising

Our public marketing pages run measurement tools. None of them is used on a client portal, on a signed-in application screen, or on any page behind authentication.

Google Analytics — which pages are read and how visitors arrived.

Meta Pixel — whether our own social posts and advertisements lead to enquiries.

Microsoft Clarity — how pages are used: mouse movement, clicks, scrolling and where in a form people stop. This produces a replay of the visit. Input fields are masked.

When an enquiry form is submitted we may report that conversion to Meta from our server. Any email address is hashed with SHA-256 before transmission, so the address itself is not sent in readable form.

Opting out. Browser "Do Not Track" signals and content blockers prevent these tools from loading, and we do not attempt to work around them. We honour Global Privacy Control signals where they are presented. You may also opt out through Google's and Meta's own controls.

9. Who we share information with

We do not sell personal information. We share it only as follows.

Service providers. Infrastructure and tooling used solely to operate the service, under contracts limiting their use of the information. These currently include: hosting, content delivery and application hosting; database and file storage; authentication; communications carriage for calls and text messages; automated voice assistance; artificial intelligence services used for coaching, transcription and food identification as described in section 4; food and nutrition reference databases, which receive search terms and barcodes transiently for lookup; subscription and entitlement management; payment processing, which is handled by the app store and its processor so that we never receive card numbers; email delivery; error and performance monitoring, retained for a limited period; and the measurement tools described in section 8.

Our clients. Where information is held in a system we operate for a client, that client has access to it.

Professional advisers. Lawyers, accountants and insurers, where necessary.

Legal and safety. Where required by law, legal process or governmental request, or where necessary to protect rights, safety or property, or to investigate fraud or a security incident.

Corporate transactions. In connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.

10. How long we keep information

Enquiries and correspondence — kept while the enquiry is active and for a reasonable period afterwards for context and record-keeping.

Client and account records — kept for the duration of the engagement and thereafter as required for legal, tax and accounting purposes.

Application data, including health and wellness information — kept while the account is active. On account deletion it is removed from live systems and from backups in the ordinary course of backup rotation.

Client-held records — retention is determined by the client, whose data it is. On termination the client may export in full, after which we may delete.

Logs and security records — kept for a limited period for security and diagnostic purposes.

We delete or de-identify information when it is no longer needed for the purpose it was collected for, unless a longer period is required by law.

11. Security

We maintain administrative, technical and physical safeguards designed to protect information against unauthorised access, loss, alteration and disclosure, appropriate to the nature of the information. These include encryption in transit, access control on a need-to-know basis, authentication requirements for administrative access, logging, and regular backups. No system is completely secure, and we do not warrant that our safeguards will be impenetrable. Where a security incident affects personal information we hold, we will notify affected parties and, where applicable, our clients without undue delay.

12. Your rights

Depending on where you live, you may have the right to: know what personal information we hold and how it is used; obtain a copy of it in a portable format; correct inaccurate information; delete it; limit the use and disclosure of sensitive personal information; opt out of any sale or sharing (we do neither); and not be discriminated against for exercising a right.

How to exercise them. Email [email protected] or call (323) 863-6989. We will verify your identity before acting, respond within the period required by applicable law, and will not charge for a reasonable request. An authorised agent may act for you with written permission and verification.

If we decline. You may ask us to reconsider by replying to our response, and we will review the decision.

If the information is held for a client, we will refer you to that client, who is responsible for deciding on the request, and we will assist them in giving effect to it.

13. California

Under the California Consumer Privacy Act as amended, we disclose the following. In the past twelve months we have collected the categories of information described in sections 2, 3 and 4, for the purposes described in section 5, from the sources described in those sections, and have disclosed them for business purposes to the categories of recipient described in section 9.

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We do not knowingly sell or share the personal information of anyone under 16.

Sensitive personal information. Health and wellness information is treated as sensitive personal information. We use and disclose it only for the purposes permitted without a right to limit — namely to provide the service you requested, to secure it, and to comply with law. We do not use it to infer characteristics about you.

Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.

14. Consumer health data

Where consumer health data legislation applies to you — including the Washington My Health My Data Act and comparable state laws — we collect consumer health data only to provide the service you have asked for, with your consent where consent is required; we do not sell it; we do not use it for advertising; and we do not share it except with the service providers described in section 9, under contract, for the purpose of operating the service. You may withdraw consent and request deletion using the contact details in section 12.

15. Children

Our website and services are not directed to children under 13, and we do not knowingly collect their personal information. Applications we operate are intended for adults. If you believe a child has provided us with information, contact us and we will delete it.

16. International visitors

We are based in the United States and information we handle is processed there. If you access our services from outside the United States, you understand that information will be transferred to and processed in a country whose data protection laws may differ from those of your own.

17. Third-party sites and platforms

Our site and systems may link to or connect with services operated by others. Those services are governed by their own privacy policies, and we are not responsible for their practices. Where a client instructs us to connect an account on a third-party platform, that platform's terms and policies govern the information held there.

18. Changes to this policy

We may update this policy. Material changes will be posted on this page with a new date and, where we hold your contact details, notified to you. The date at the top shows when this version took effect.

19. Contact

ServiceAi HQ LLC · 4040 Piedmont Dr #276, Highland, CA 92346 · [email protected] · (323) 863-6989

See also Data Deletion for how to request removal of information, including information connected through a third-party platform.