1. Overview
Aeon Kairos ("we," "us," or "our") is a business operations platform for boutique fitness businesses, operated by MNBK LLC. This Privacy Policy explains how we collect, use, store, and share information when you use the Aeon Kairos platform, including our web dashboard, APIs, and any associated services (collectively, the "Platform").
Aeon Kairos operates as both a data controller (for information we collect directly, such as account information from business owners and staff) and a data processor (for information that fitness businesses — our customers — collect from their members and process through our Platform).
By using the Platform, you agree to the practices described in this policy.
2. Who This Policy Covers
This policy applies to:
- business Owners and Staff — businesses and individuals who create an Aeon Kairos account and use the Platform to manage their operations
- business Members and Leads — individuals whose information is entered into the Platform by a fitness business using Aeon Kairos
If you are a business member or lead and have questions about how your specific business handles your data, please contact that business directly. They are the data controller for your personal information within their account.
3. Information We Collect
3A — Information from business Owners and Staff
When a fitness business creates an account, we collect:
- Business name, address, and contact information
- Owner and staff names, email addresses, and phone numbers
- Billing information (processed by Stripe — we do not store payment card details)
- Account credentials and authentication data
- Platform usage data, including feature interactions and session activity
3B — Information Processed on Behalf of business Customers
Fitness businesses using Aeon Kairos may enter or import data about their members and leads. This may include:
- Member names, email addresses, and phone numbers
- Membership plan and billing status
- Class attendance, booking history, and check-in records
- Health and fitness data, including body composition scans (InBody), physical assessments, and nutrition logs
- Coaching notes, program phases, and call history
- SMS and in-app message history
- Gamification data including experience points, badges, and skill progression
- Lead source and advertising attribution data
- Consult and appointment history
We process this data on behalf of and under the instruction of the fitness business. We do not use member data for our own marketing or sell it to third parties.
3C — Information from Meta (Facebook/Instagram)
For fitness businesses using our advertising intelligence features (Intelligence tier and above), we receive data from Meta platforms including:
- Ad performance metrics (impressions, reach, frequency, click-through rate, hook rate)
- Lead form submissions from Meta Lead Ads, including name, email, and phone number of prospective members
- Ad account and campaign identifiers
This data is received via the Meta Leads API and Meta Marketing API and is processed solely to provide advertising intelligence features to the fitness business that connected their Meta account.
3D — Automatically Collected Information
When you use the Platform, we automatically collect:
- IP address and device information
- Browser type and operating system
- Pages visited and features used
- Session timestamps and duration
- Error logs and performance data
4. How We Use Information
For business Owners and Staff:
- To create and manage your account
- To provide, operate, and improve the Platform
- To process billing through Stripe
- To send transactional communications (account alerts, billing notices, platform updates)
- To provide customer support
- To monitor platform security and prevent fraud
For business Member and Lead Data:
- To provide the features and functionality requested by the fitness business
- To power AI-assisted analysis, recommendations, and message drafting on behalf of the fitness business
- To generate action center signals, member health scores, and lifecycle metrics for the fitness business
- To facilitate SMS and in-app communication initiated and approved by the fitness business and its staff
- To display gamification progress (XP, badges, levels) within the Platform
We do not use business member data to train AI models, sell to advertisers, or contact members independently.
5. Artificial Intelligence and Automated Processing
Aeon Kairos uses the Anthropic Claude API to power features including action center analysis, message draft generation, call brief generation, and ad performance verdicts.
When AI features are used:
- Member and lead data relevant to the specific analysis is sent to Anthropic's API for processing
- AI outputs are recommendations only — a human staff member reviews and approves all actions before execution
- No autonomous messages are sent to members or leads without staff approval
- All AI-assisted actions are logged in an audit trail tied to the staff member who approved them
Anthropic's data processing practices are governed by Anthropic's privacy policy and our data processing agreement with them.
6. SMS Communications
Aeon Kairos facilitates SMS communications between fitness business staff and their members and leads via Twilio.
- Outbound SMS messages are only sent to individuals who have provided explicit SMS consent
- Consent records are maintained per member per fitness business location
- Members may opt out at any time by replying STOP to any SMS message
- SMS opt-out requests are processed immediately and recorded in the Platform
- Fitness businesses are responsible for obtaining and documenting member SMS consent
7. How We Share Information
We do not sell personal information. We share information only in the following circumstances:
Service Providers
We share data with third-party vendors who help us operate the Platform, including:
- Supabase — database hosting and authentication
- Vercel — platform hosting and deployment
- Stripe — payment processing
- Twilio — SMS and voice communications
- Anthropic — AI analysis and content generation
- Meta — advertising data integration (for connected accounts only)
All service providers are contractually obligated to process data only as directed and to maintain appropriate security standards.
Fitness Businesses
Data entered by a fitness business is accessible to that business's authorized staff only. We do not share one business's data with another business or any third party.
Legal Requirements
We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of Aeon Kairos, our customers, or others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will notify affected users prior to any such transfer.
8. Data Retention
- business owner and staff account data is retained for the duration of the account and for 90 days following account termination, after which it is deleted
- business member and lead data is retained as long as the fitness business account is active. Upon account termination, the fitness business may request export of their data within 30 days, after which data is deleted
- Billing records are retained for 7 years as required by financial regulations
- Audit logs are retained for 2 years
- SMS opt-in and consent records are retained for 5 years following the last recorded interaction
9. Data Security
We implement industry-standard security measures to protect your information, including:
- Row-level security ensuring each fitness business can only access their own data
- Encryption of sensitive integration credentials at rest
- HTTPS encryption for all data in transit
- Webhook signature validation for all inbound data from third-party services
- Access controls limiting platform staff access to tenant data, with a full audit trail of any access
No method of transmission or storage is 100% secure. In the event of a data breach affecting your information, we will notify affected parties as required by applicable law.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your personal information, subject to legal retention requirements
- Portability — request your data in a portable format
- Objection — object to certain types of processing
business members and leads: To exercise these rights, please contact the fitness business that manages your membership. You may also contact us at privacy@aeonkairos.com and we will direct your request appropriately.
business owners and staff: Contact us at privacy@aeonkairos.com.
We will respond to all verified requests within 30 days.
11. Children's Privacy
The Aeon Kairos Platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor's information has been submitted to the Platform, please contact us at privacy@aeonkairos.com and we will take steps to delete it.
12. Third-Party Links
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify business owners via email. Your continued use of the Platform after any update constitutes acceptance of the revised policy.
14. Contact
For privacy-related questions, requests, or concerns:
Email: privacy@aeonkairos.com
Mail: MNBK LLC, DBA Aeon Kairos, Euless, Texas