Privacy Policy
Last updated: March 2026
Ascend ("we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights as a user of www.myascendhq.com. By using Ascend, you agree to the practices described in this policy.
1. Data We Collect
We collect the following categories of personal data:
- Account data — your email address, display name, and age, provided when you create an account.
- Profile data — optional information you provide during onboarding (fitness goals, experience level, preferences).
- Usage data — pages visited, features used, AI plan interactions, and session duration. Collected automatically via server logs and analytics.
- Payment data — billing information is processed by Stripe. We do not store your full card number; we only receive a tokenised reference and subscription status from Stripe.
- Newsletter email — if you subscribe to our newsletter, we store your email address for that purpose only.
- Technical data — IP address, browser type, device type, and operating system, collected automatically for security and service improvement.
2. How We Use Your Data
We use your personal data only for the following purposes:
- To create and manage your account and authenticate you securely.
- To provide and personalise the Ascend service, including generating AI plans tailored to your profile.
- To process subscription payments and manage your billing status via Stripe.
- To send transactional emails (account confirmation, password reset, subscription receipts).
- To send our newsletter if you have opted in — you can unsubscribe at any time.
- To improve the platform by understanding how users engage with features.
- To detect and prevent fraud, abuse, or violations of our Terms of Service.
- To comply with our legal obligations.
We do not use your data for automated decision-making that produces legal or similarly significant effects without your explicit consent.
3. Third-Party Services
Ascend relies on the following third-party providers. Each has its own privacy policy and security practices:
Supabase
Our database and authentication provider. Your account data, profile, and content is stored on Supabase's infrastructure (hosted on AWS). Supabase is SOC 2 compliant.
Stripe
Our payment processor. Stripe handles all card data and is PCI DSS Level 1 certified. We never store raw payment details on our servers.
Anthropic (Claude API)
We use Anthropic's Claude API to power AI-generated plans and the AI coach feature. Content you submit in AI interactions may be processed by Anthropic's servers. Anthropic's usage policies prohibit them from training on your data by default.
We do not share your personal data with any third parties for their own marketing purposes.
4. No Selling of Personal Data
We do not sell, rent, trade, or otherwise transfer your personal data to third parties for commercial purposes. Your data is used solely to operate and improve the Ascend service.
5. Data Retention
We retain your personal data for as long as your account is active. Specifically:
- Account and profile data is retained until you request deletion of your account.
- Payment records and transaction history may be retained for up to 7 years for tax and legal compliance.
- Usage logs and analytics data are aggregated and anonymised after 12 months.
- Newsletter subscriber data is retained until you unsubscribe.
- AI conversation data is not stored beyond the current session.
6. Your Rights
You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@myascendhq.com:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct any inaccurate or incomplete data.
- Erasure — request deletion of your account and associated personal data.
- Data portability — receive a machine-readable export of your data.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — withdraw consent for newsletter communications at any time.
You may also delete your account directly from your account settings page, which will initiate deletion of your personal data.
7. Cookie Policy
Ascend uses cookies and similar technologies to operate the service. We use the following types:
- Essential cookies — required for authentication and to keep you logged in. Cannot be disabled without breaking core functionality.
- Preference cookies — remember your settings and onboarding state.
- Analytics cookies — help us understand aggregate usage patterns. Data is anonymised and not tied to individual users.
You can control cookies through your browser settings. Disabling non-essential cookies will not affect your ability to use Ascend's core features.
8. GDPR Compliance
We serve users in the European Union and comply with the General Data Protection Regulation (GDPR). Our legal bases for processing your data are:
- Contract performance — processing necessary to provide the service you signed up for.
- Legitimate interests — improving the service, security monitoring, and fraud prevention.
- Consent — newsletter communications and non-essential cookies.
- Legal obligation — retaining financial records as required by law.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement industry-standard security measures including HTTPS encryption for all data in transit, row-level security on our database, and access controls limiting who can view user data. However, no system is 100% secure — please use a strong, unique password for your Ascend account.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a notice in the app. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Ascend after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
For any privacy-related questions, data requests, or concerns, contact our privacy team at:
We aim to respond to all privacy requests within 30 days.