How we handle your data.
Plain language. Real commitments. Last reviewed 2026-08-18.
Who this policy applies to
This policy covers everyone who uses Marrow. Coaches and instructors who run their practice on the platform, athletes and clients who train with those coaches, gym owners and studio admins, and visitors to marrowfitness.com. We wrote it in plain language so a non-technical person can read it without a dictionary. If you have a question, ask it on our contact page and a real person will answer.
What we collect
Depending on how you use Marrow, we collect some or all of the following.
- Application and form submissions. Name, email, professional details, and anything you wrote in the open text fields.
- Account data. Email for magic-link authentication, profile information, role (coach, athlete, gym admin), and the connection between coach and athlete accounts.
- Training data. Programs, sessions, logged workouts, form videos you upload, notes between coach and athlete, nutrition ranges, and wearable-derived signals if you choose to connect a device.
- Billing data. Name, billing address, and payment method tokens, handled by Stripe. Marrow never sees full card numbers.
- Operational data. IP addresses, browser type, device type. Used for abuse prevention and to keep the service running. Not used to track you across the web.
What we don't collect
We use Plausible Analytics, which is privacy-first and cookie-free. We don't run Facebook Pixel, Google Analytics, or any retargeting cookies. There's no fingerprinting and no cross-site tracking. We don't sell, license, or share your data with third parties for marketing purposes.
How we use your data
We use the data you submit to:
- Run the platform, including coaching tools, athlete dashboards, and admin surfaces.
- Authenticate you and keep your account secure.
- Process payments for coach subscriptions and athlete billing.
- Respond to applications, demo requests, and support questions as soon as we can.
- Send platform onboarding details, transactional notifications, and the receipts you would expect.
- Deliver messages your coach chooses to send you through Marrow, on the channels you agreed to. The Messages from your coach section below explains how that works and what protects you.
- Maintain a private record of your interaction with us.
Your phone number and text messages
We treat your phone number with the same care as the rest of your data. We do not sell your personal data or your phone number. We do not share it with third parties for their own marketing, and we do not let anyone else use it to market to you. The only companies Marrow lets touch your number are the named service providers that help us run the platform, such as our messaging and payment providers, and only so they can deliver the messages and services you asked for. No mobile information is shared with third parties or affiliates for marketing or promotional purposes.
One thing that sentence does not cover, so we are naming it here rather than leaving it implied. Your coach can connect their own AI assistant to their own Marrow account, and the owner of the gym you train at can connect one to their own gym console. Neither connection receives your phone number, your name, your email, or any other contact detail. What each one can and cannot receive is written out in full under Connected AI assistants below.
Text messaging (SMS). If you text or call Marrow's published business number, you consent to receive conversational text replies from us at the number you contacted us from. These messages are how we answer your question, return a missed call, and help you with your account. We do not send marketing or promotional text blasts. Messages are sent in reply to you, and message frequency varies based on how the conversation goes. Message and data rates may apply, depending on your carrier and plan.
You are always in control. Reply STOP to any message to opt out and we will not text you again. Reply HELP for help, or reach us on our contact page. Opting out of texts does not close your account or stop transactional notices you need, such as receipts and security alerts.
Texts from your coach do not exist today. Coach messaging through Marrow, described in Messages from your coach below, does not use text messages. There is no path in the product that lets a coach text you. If that ever changes, we rewrite this section and collect your written permission first, before any coach text is sent, not after.
Messages from your coach
Your coach can send you messages through Marrow. Three kinds exist. A message in your Marrow inbox, which you read inside the product. A push notification on your phone that tells you an inbox message arrived. And an email. Text messages are not one of them. Coach messaging through Marrow cannot send a text, and the section above says what happens before that could ever change.
Your coach decides to message you. Marrow never does. Every message needs a recorded human authority behind it: your coach pressing send inside Marrow, or a standing approval your coach set in advance under their own login. Marrow runs the delivery and keeps the record. The decision to contact you belongs to your coach, and no message goes out on Marrow's own initiative.
An AI assistant can draft, and it cannot send. If your coach uses a connected assistant, described under Connected AI assistants below, that assistant can write a draft. It has no way to send one. Sending lives on a separate Marrow screen, behind your coach's own login, on a surface no assistant can reach.
Permission is separate for each channel. Saying yes to email is not saying yes to anything else. Before a message can go out on a channel, a consent record has to exist for you, on that channel, for that kind of message. That record is created only when you yourself act on a Marrow surface, such as ticking a box or changing a setting, or when your coach imports permission you already gave them in writing and puts their name to that claim. It is never created by an AI and never created by an unattended job.
The record is permanent evidence. When you say yes, we record when you said it, where you said it, and the exact words you were shown. When you say no, we record that too. Consent records are never edited and never deleted, because they are the proof of what you agreed to. A no is final. If you opt out and later change your mind, saying yes again takes a fresh action from you.
Limits that hold on every message. Messages that interrupt you, such as a push notification or an email, are held to daytime hours where you are, 8am to 9pm in your own local time. A message due outside that window waits and goes out when the window opens. It is deferred, never dropped, so nothing your coach sends you silently disappears. There are also caps: by default one message per person per day, plus a daily cap on each account, so a runaway loop cannot become a flood. And the consent check runs again inside the same database step that records the send, so an opt out that lands moments before a send still wins.
You can take permission back at any time. Tell us on our contact page and we will switch that channel off for you, or use the opt out in the message itself where the channel carries one. Your withdrawal is recorded the same way your yes was, and it stops future sends to you on that channel.
If you asked a coach a question and have not joined. When you contact a coach through a form on their Marrow page, that coach can answer you by email through Marrow. The basis for that reply is your own enquiry: you asked, they answered. The only thing that path can send is a reply, not a mailing list, and it can never send you a marketing text.
Where your data lives
Marrow application data is stored in the United States. The primary database is Supabase, hosted in the US, with row-level security enforced at the database layer. Static assets are delivered via Cloudflare's global edge for performance, while application reads and writes route to US origins. Plausible Analytics, hosted in the European Union, receives only anonymized, aggregated page-view counts and never individual identifiers.
Application form submissions arrive through Formsubmit and land in our email inbox at hello@marrowfitness.com. From there, they may be added to your coach or athlete account record if you sign up.
Sub-processors
Marrow uses a small number of third-party services to operate the platform. Each of them is named, with the data they touch and where they're located, on our canonical sub-processor page. We update that page before any new sub-processor goes live and we notify coaches in advance of material changes.
The current list covers Stripe (payments and coach payouts), Cloudflare (DNS, edge, compute, storage), Supabase (database, authentication, video storage), Kit (email sequences), Postmark (transactional email), Plausible Analytics (privacy-friendly analytics), Sentry (error monitoring), Upstash (background job queue), and Daily.co (virtual session video, activating with v1.1 in August 2026).
The canonical, always-current list lives at marrowfitness.com/legal/subprocessors. If the page below ever conflicts with that page, the sub-processor page is the source of truth.
Open item, under legal review. An AI assistant that a coach connects through Marrow Lamella is chosen and paid for by that coach, not engaged by Marrow, so it is not a Marrow sub-processor in the way Stripe or Supabase is. Whether it must still be named on the sub-processor page, or covered there by explicit carve-out language, is with our counsel and is not settled yet. That counsel review is ongoing. Our current position is the one stated above, that an assistant a coach chooses and pays for is not a Marrow sub-processor in the way Stripe or Supabase is. If counsel rules that those vendors belong on the sub-processor list, they go on the list and we notify coaches.
Connected AI assistants
Marrow Lamella lets someone connect an AI assistant they already pay for to their own Marrow account. There are two kinds of connection and they reach different things, so both are written out below. A coach connection is your coach connecting an assistant to their own coaching account. A gym owner connection is the owner of a gym connecting one to their own gym console. In both cases the person connecting chooses that vendor and pays it directly. Marrow does not choose it, does not resell it, and has no agreement with it. Today the only client Marrow has run end to end is Claude, made by Anthropic. Any other client that speaks the same open protocol can be connected.
Because that assistant runs on their own vendor account, anything it is sent leaves Marrow's systems and lands with that vendor under that vendor's terms. So the honest question is not whether we trust them. It is exactly what can reach them. Here is the whole list, for each kind of connection.
A coach connection
Your coach connects an assistant to their own account, so it can help them write their page, fill their tiers and packages, read a summary of how their business is doing, see how full their own schedule is, and keep up with the people who have enquired. Whether it also receives money amounts depends on the agreement your coach has accepted, which is set out below.
What a coach connected assistant can receive about members.
- Counts, not people. How many memberships are active, cancelled, or past due, and how many members sit on each tier. Numbers only.
- Session pack usage in aggregate. How many credits across a coach's packs have been used and how many are left.
- Opaque per member pointers. A one-way code standing in for one member, for example so an assistant can say a client is close to running out of sessions. The code carries no name, no email, no phone number, and nothing derived from any of them. It cannot be reversed by the AI vendor. Marrow retains the means to match a pointer back to a member, and Marrow alone.
- Timestamps. When something last happened, such as the date of the last community post.
What a coach connected assistant can receive about people who enquired. If you contacted a coach through Marrow and have not signed up yet, your enquiry sits in that coach's own pipeline. Their assistant can read that pipeline and draft a follow up for one entry in it. What reaches their AI vendor is the shape of the pipeline, never the person.
- Where an enquiry sits, and how long it has waited. The stage it is at, where it came from, for example a referral, an event, or a form on the coach's page, and three counts of days: how long it has sat at that stage, how long since the coach last logged contact, and how long since it first arrived.
- Not your name, and no way to write to you. Your first name, last name, email address, phone number, any tags on you, and the note about what you were interested in are not read at all. They are not removed from an answer after the fact. Those columns are never asked for, so there is no answer the assistant could get them from.
- An opaque per enquiry pointer. The same kind of code as the member pointer above, so the assistant can point at one particular enquiry and have a follow up drafted for it. It carries no name, no email address and no phone number, it cannot be reversed by the AI vendor, and the same person sitting in two different coaches' pipelines produces two unrelated codes.
- Counts across the pipeline. How many enquiries sit at each stage, how many arrived from each source, how many have never been contacted, and how many arrived in each month. Numbers only.
- The follow up is a draft, and the assistant cannot send it. The text the assistant writes is filed in the coach's Marrow account for the coach to read. There is no tool on this connection that mails, texts, messages or calls anyone, and the draft is addressed to the pointer rather than to you. Sending is a separate act on a separate Marrow screen, behind the coach's own login, on a surface no assistant can reach, and it works only where a consent record covers you on that channel. So the coach is the one who decides to reach out. What protects a message once a coach does send it is set out under Messages from your coach above.
What a coach connected assistant can receive about your coach's schedule. Your coach can ask how full they are, which hours of their week are quiet, and where the gaps sit. This is the one category on the connection that carries no pointer at all, because it reads no identity column to make one from.
- Counts, clock times and durations. Nothing else. How many sessions are scheduled or cancelled in a forward window of up to 90 days, how many seats those sessions hold and how many are taken, how many booking slots are open, and how many bookings are active or waiting. Then which weekday and hour each of those sits in.
- Not you, and not a code standing in for you either. No member id, no booking id, no slot id, and no code derived from any of them. Unlike the member and enquiry categories above, there is no opaque pointer here at all. Those columns are never asked for, so a session reaches the assistant as a time and a number and never as an attendee.
- Not what the session was. Neither the note your coach wrote about a session nor any note attached to you is read.
- Only forward. These reads look at what is scheduled ahead. They do not look back over your attendance history.
- A schedule change is a proposal, not a change. Your coach's assistant can propose opening a slot, holding a window, or moving something. Each one writes a pending row into a separate table and can reach nothing else. It has no route to the real sessions, slots or bookings, so nothing on your coach's calendar moves until your coach presses it in Marrow.
What a coach connected assistant can receive about money. It depends on the agreement your coach accepted. Five tools inside Marrow reach money. Two read revenue, one reads a ceiling on what can be staged, and two propose a refund or a price change. They reach a connection only when the coach on it has accepted the version of the connection agreement that describes them in plain words, and Marrow holds a switch over that surface as well. Where either one does not hold, no dollar amount reaches the assistant at all, and a request that names one of the five is answered that the capability is unavailable.
What those five send on a connection where they do reach. Written out so you can judge it rather than discover it. Everything below is about your coach's business, and the last two lines hold on every connection whether the five reach it or not.
- Your coach's own business totals, never a bill of yours. What that coach took over a named window, what they refunded, what is left after Marrow's fee, their refund rate, how many transactions there were, the same figures split across the things they sell, and the same totals month by month.
- Never the payer. None of the five reads who paid, and there is no tool on the coach surface that returns the member behind a payment. So no amount resolves to you, on any connection, in any state of that gate. A single payment comes back behind an opaque one-way pointer of the same kind as the pointers above, aimed at a payment and never at a person.
- No money moved. A refund and a price change are recorded as proposals and wait. Nothing is charged, nothing is returned, and no live price changes until your coach presses it in Marrow.
What moves, and what does not. We will not describe this as a permanent absence, because it is not one. A coach who has not accepted the current agreement sends no amounts. A coach who has can send the totals above, on their own account and by their own decision, and we rewrite this section before that changes rather than after. What none of it moves is anything about you. The payer guarantee in the list below holds either way, and so does every other line in it.
What a coach connected assistant can never receive. These are not settings. There is no tool on the coach surface that returns them.
- Your name, email address, phone number, or mailing address.
- Health data of any kind. No injuries, no body metrics, no nutrition detail, no wearable readings.
- Your workouts, programs, logged sessions, or form videos.
- Messages between you and your coach, and the text of anything you posted in a community.
- Your card details or your billing address.
- What you personally paid, or that you were the one who paid. No tool on the coach surface reads the payer behind a payment, so no dollar figure on this connection is ever attached to a person. That holds whether or not the five money tools reach the connection, and it is the one line here that no agreement version and no switch can move.
A gym owner connection
If you train at a gym rather than with a solo coach, that gym's owner can connect an assistant to their gym console. It works one level up from a coach connection. It looks at the gym: who is on the roster, which trainers are ready to sell, and how busy the schedule is. It does not look down into any one member.
What a gym owner connected assistant can receive. Nineteen tools, and this is everything they touch.
- The gym's own record. Display name, city, onboarding state, whether payouts are set up, the brand colours on file, and how many trainers, gym plans, fee templates, events and saved reports exist.
- The trainer roster. Each trainer's display name, role, status, location identifier, and invite and join dates. This is staff information, not member information.
- Readiness per trainer. Whether an active trainer has a published page, a live price, programs, and payments enabled. Whether the thing exists, never the trainer's own content and never a price figure.
- Roll ups across the roster. Counts for a forward window of up to 90 days, per trainer and in total: class sessions, class attendees, open booking slots, bookings, pending requests, slot utilisation, and how many active athletes each trainer has. Numbers only, never a named person.
- The gym's commercial setup. Gym owned membership plans, the fee templates that decide what a trainer is paid, and the gym's events, each with the fields the console already shows.
- The owner's own reports and change log. Reports Lamella saved for that owner, and the record of changes Lamella made with the before and after value of each field it touched.
- Where your branded app is up to. Which step of the build it is on, whether that step is moving, and whether anything is waiting on you. It never claims Apple has approved anything, and it says plainly when it could not check rather than reporting that nothing has started.
- The shape of the month. Counts bucketed over a window so an owner can see whether the gym is growing, never a money figure and never a named person.
- What it can stage on the commercial side. A trainer fee template and a gym event, both written switched off. A fee template arrives not in force and an event arrives as a draft no member can see, and only the owner turns either one on from the console.
- The words on the gym's own public page. The headline, the description, the list of what the gym offers, and the wording of its enquiry form. The gym's own copy. Never a trainer's page, and an edit it drafts changes nothing the public sees until the owner publishes it.
What a gym owner connected assistant can never receive. These are not settings either. There is no tool on the gym surface that returns them.
- Any individual member's identity or contact details. No member name, email address, phone number or mailing address, and no member id. You appear only inside a count.
- Any member's health, body or nutrition record. Attendance and totals yes. One named person's body data never.
- A trainer's own content or prices. Not their page copy, not their programs, not their price figures, not their client records. A gym owner's assistant cannot write to any of it either.
A gym owner connection also cannot change your membership, publish anything, or move money. A plan it writes lands switched off until a person turns it on, and it cannot invite, remove or suspend a trainer. The full text an owner accepts is the Lamella gym connection agreement.
Small rosters, said plainly. A count can still point at a person when the number is small. If a coach has one member past due, a count of one past due member is about that member, even though no name was sent. The same holds on the gym side. If one trainer has one active athlete, a count of one is about that athlete. That is a limit of counts, not a loophole, and your coach and your gym already know who their members are. We are naming it so the guarantees above are not read wider than they are.
What they type is on them. A connected assistant is that person's own chat window. If your coach, or your gym's owner, types something about you into it, or saves it into a Lamella report, that is content they wrote, not data Marrow handed over. Everyone who connects an assistant must first accept an agreement that makes them responsible for their vendor choice, for that vendor's data handling settings, and for keeping member personal and health details out of their AI chats and their saved reports. A coach accepts the Lamella connection agreement. A gym owner accepts the Lamella gym connection agreement.
Control and questions. A coach connects, and revokes, from their own dashboard. A gym owner connects, and revokes, from their gym console. Either way it loses access immediately, and Marrow can disable the whole Lamella surface at once. If you want to know whether the coach you train with, or the gym you train at, has an assistant connected, ask them, or reach us through our contact page and we will tell you.
Athletes
If you are an athlete, your data is processed by Marrow on behalf of the coach you train with. Marrow does not market to athletes for anything other than transactional platform notifications. For solo coach accounts, coaches own the relationship with their athletes and may export athlete data at any time. For studio and gym accounts, the gym owns the member relationship at the platform level, and coaches keep a copy of their own programming work, matching the terms of service. On termination of a coach's account, athletes are given 30 days to migrate their training history before deletion.
Your rights
You can export a full copy of your data or close your account at any time from your account settings. You can also reach us through our contact page to ask what we have on you, request deletion, or correct errors. We respond inside 30 days. If you're in the EU, UK, or California, you have specific rights under GDPR or CCPA. We honor all of them.
How long we keep it
Application data: 12 months unless you become a customer. After that, we retain it as part of your customer record. Customer training data is retained for the life of your account, plus a short post-termination window so you can export it. If you ask us to delete sooner, we delete within 30 days.
Updates to this policy
We'll update this page when our practices change. The "last reviewed" date at the top tracks every revision. If a change is material, we'll email you.
Contact
Marrow Fitness
Miami Beach, FL
Privacy questions go through our contact page.