Privacy Policy

Effective Date: May 21, 2026

Please read the following carefully to understand our views and practices regarding your (“your”) Personal Data.

Polychart is a product of 1 AND 1 Life, Inc., a Delaware corporation (“Polychart”, “we”, “us”). We value your privacy and are committed to keeping your Personal Data confidential. We use your data solely in the context of providing the Polychart mobile application and web services (together, the “Services”) to service providers (such as coaches, trainers, consultants, and therapists) and the clients they invite to collaborate with them. “Personal Data” includes any information that can be used on its own or in combination with other information to identify or contact one of our users.

Polychart is for non-HIPAA service providers and is not a HIPAA-covered entity. The Services are not designed or authorized to store Protected Health Information (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Providers using the Services should not enter PHI on a chart or in messages.

By using the Services, you acknowledge that you have read and agree to the terms of this Privacy Policy. If you do not agree, please do not submit any Personal Data to us and immediately cease use of the Services.

Responsible Entity

1 AND 1 Life, Inc., with its principal place of business at 40 Harrison Street, Apt 36L, New York, NY 10013, operates the Polychart product and Services and is the controller of your Personal Data and may process this data in accordance with this Privacy Policy. If we are processing Personal Data on behalf of a third party under that third party’s own privacy policy, that policy applies to that processing. Your mobile phone number, SMS opt-in, and messaging consent data are always governed by this Privacy Policy, including the non-sharing commitment in the Mobile Number and SMS Communications section below. You can contact us with any questions about our Privacy Policy at hello@getpolychart.com.

Links to Other Sites

The Services may contain links to websites and services that are owned or operated by third parties (each, a “Third-party Service”). Any information you provide on or to a Third-party Service, or that is collected by a Third-party Service, is provided directly to the owner or operator of the Third-party Service and is subject to its privacy policy. We are not responsible for the content, privacy, or security practices of any Third-party Service. To protect your information, we recommend that you carefully review the privacy policies of all Third-party Services that you access.

What Personal Data do We collect?

The types of Personal Data we collect are described below.

Demographic Data

We may collect demographic information, such as your name, email address, profile photo, and optional bio and social links. Primarily, the collection of your Personal Data assists us in creating your account so you can use the Services.

Account & Authentication Data

When you sign in, we collect your authentication provider (Apple, Google, or email/password), a unique user identifier issued by our authentication system (Firebase Authentication), and timestamps for account creation and last sign-in.

Service Content You Create

The Services let you author content on a “chart” for each client or person you work with - including notes, targets, tasks, workouts, assessments, updates, and messages. This may include content the in-app AI agent helps you draft, which you explicitly review and approve before it is saved to a chart. You are responsible for what you choose to record. As noted in the introduction, Polychart is for non-HIPAA service providers; do not enter Protected Health Information.

Payment Data

If you pay a provider through the Services, your card details are entered in a payment form hosted and secured by our payment processor, Stripe, and are transmitted from your browser directly to Stripe. Polychart does not receive or store your full card number, expiration date, or security code. From Stripe we receive the status, amount, and currency of the payment and the identifiers Stripe assigns to it.

When a payment is started, we send Stripe the amount to charge, the identifier of the provider’s connected Stripe account, a short descriptor based on the provider’s username that appears on your card statement, and internal identifiers for the provider and for the session or payment request being paid. We also share your email address with Stripe so that Stripe can send you a receipt. Because the payment form loads in your browser from Stripe, Stripe also receives your IP address and information about your device and browser, which it uses to process the payment and to detect fraud.

If you are a provider and you enable payments, Stripe collects the identity, business, and bank account information required to operate your connected account directly from you, through a form Stripe hosts. Of that information we store only the identifier of your Stripe account and whether it is enabled to accept charges and to receive payouts.

Device, Telephone, and ISP Data

We use common information-gathering tools, such as log files, cookies, and similar technologies, to automatically collect information from your device as you use the Services. The information we collect may include your IP address, device and application identification numbers, operating system, app version, browser type, internet service provider, push notification token, and product-analytics events about how you interact with the app. This information is used to analyze overall trends, to help us provide and improve the Services, and to maintain their security.

Support Data

If you contact us for support or to lodge a complaint, we may collect technical or other information from you through support communications. Such information will be used for troubleshooting, customer support, software updates, and improvement of the Services in accordance with this Privacy Policy.

Mobile Number and SMS Communications

We collect your mobile number to verify your identity by text. That verification code is part of signing in. We use the same number for session messaging, such as confirmations, reminders, cancellation or reschedule follow-ups, and payment requests, only if you separately opt in to it when you book. Session messaging is optional, you can book without it, and you can withdraw consent at any time by replying STOP, or reply HELP to any message for help. Message frequency varies based on your account activity and the sessions you book. Message and data rates may apply.

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties, affiliates, or lead generators for marketing or promotional purposes. See our Terms of Service for the full SMS messaging program terms, including how to opt out.

How will We use Your Personal Data?

We process your Personal Data based on legitimate business interests, the fulfillment of our Services to you, compliance with our legal obligations, and/or your consent. We only use or disclose your Personal Data when it is legally mandated or where it is necessary to fulfill the purposes described herein. Where required by law, we will ask for your prior consent before doing so.

Specifically, we process your Personal Data for the following legitimate business purposes:

  • To fulfill our obligations to you under our terms of use;
  • To communicate with you about and manage your account;
  • To properly store and track your data within our system;
  • To respond to lawful requests from public and government authorities, and to comply with applicable state and federal law, including cooperation with judicial proceedings or court orders;
  • To protect our rights, privacy, safety, or property, and/or that of you or others, by providing proper notices, pursuing available legal remedies, and acting to limit our damages;
  • To handle technical support and other requests from you;
  • To enforce and ensure your compliance with our terms of use or the terms of any other applicable services agreement we have with you;
  • To manage and improve our operations and the Services, including the development of additional functionality;
  • To evaluate the quality of service you receive, identify usage trends, and improve your user experience;
  • To keep the Services safe and secure for you and for us;
  • To send you information about changes to our terms, conditions, and policies; and
  • To allow us to pursue available remedies or limit the damages that we may sustain.

Where is Your Personal Data processed?

Personal Data we collect through the Services will be stored on secure servers operated by Firebase (Google Cloud), primarily in United States regions. Our marketing website is hosted by Vercel. Payment Data is processed and stored by Stripe on Stripe’s own servers, primarily in the United States. Your mobile number is transmitted to Twilio to deliver session messages and to Firebase Authentication to deliver the code that verifies it. Personal Data may be transmitted to these providers, which may store or maintain the data on their secure servers.

Will We share Your Personal Data with anyone else?

With other Polychart users

Content you place on a chart that is shared with a client (or other invited participants) is visible to those participants. If you connect to a chart as a client, content authored on that chart by the provider may be visible to you. You can control sharing by adjusting the participants on a chart or by not sharing the chart at all.

With third parties that help us power the Services (Business Partners)

We use a limited number of service providers (“Business Partners”) that help us operate the Services. These Business Partners are contractually bound to protect your Personal Data and use it only for the limited purposes for which it is shared. Our current Business Partners include:

  • Firebase (Google) - authentication, database (Firestore), file storage, push notifications, crash reporting, and serverless backend functions. Firebase Authentication also receives your mobile number to send the one-time code that verifies it.
  • Amplitude - product analytics on how the app and website are used.
  • Attio - customer relationship management for waitlist and application records submitted via the marketing site.
  • Vercel - hosting for the Polychart marketing website at getpolychart.com.
  • Stripe - payment processing: card collection, receipts, fraud detection, and payouts to providers.
  • Twilio - SMS delivery: receives your mobile phone number solely to deliver the session messages described above, never for marketing.

With third parties and the government when legal or enforcement issues arise

We may share your Personal Data, if reasonable and necessary, to (i) comply with legal processes or enforceable governmental requests, or as otherwise required by law; (ii) cooperate with third parties in investigating acts or omissions that violate this Privacy Policy or our terms of use; or (iii) bring legal action against someone who may be violating our terms of use or who may be causing intentional or unintentional injury or interference to the rights or property of Polychart or any third party, including other users of the Services.

With third parties that provide advisory services

We may share your Personal Data with third parties that provide advisory services to us - including, but not limited to, our lawyers, auditors, accountants, or banks - when we have a legitimate business interest in doing so.

In the event of a corporate transaction

We may share your Personal Data with third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of Polychart’s business, assets, or stock (including in connection with any bankruptcy or similar proceedings). This does not permit any use of your mobile phone number or messaging consent data for marketing or promotional purposes, which remains governed by the non-sharing commitment above.

If we share your Personal Data with a third party other than as provided above, you will be notified at the time of data collection or transfer, and you will have the option of not permitting the transfer.

How long do We retain Personal Data?

We will retain your Personal Data for as long as you maintain an account and up to six (6) years after the account is closed. The exact period of retention will depend on the type of Personal Data, our contractual obligation to you, and applicable law. We keep your Personal Data for as long as necessary to fulfill the purpose for which it was collected, unless otherwise required or necessary pursuant to a legitimate business purpose outlined in this Privacy Policy. At the end of the applicable retention period, we will remove your Personal Data from our databases and will request that our Business Partners do the same. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing of such data. We retain anonymized data indefinitely.

How do We protect Your Personal Data?

We use a combination of reasonable physical, technical, and administrative security controls to maintain the security and integrity of your Personal Data, to protect against any anticipated threats or hazards to the security or integrity of such information, and to protect against unauthorized access to or use of such information in our possession or control. This includes encryption in transit and at rest provided by Firebase by default, authentication, and access controls. However, internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, we cannot ensure the security of information you transmit to us. By using the Services, you assume this risk.

How can You Protect Your Personal Data?

We will never send you an email requesting confidential information such as account numbers, usernames, passwords, or social security numbers, and you should never respond to any email requesting such information. If you receive such an email that looks like it is from us, do not respond, do not click any links, and do not open any attachments - notify us at hello@getpolychart.com.

You are responsible for taking reasonable precautions to protect your account credentials from disclosure to third parties. You should immediately notify us at hello@getpolychart.com if you know of or suspect any unauthorized use or disclosure of your credentials, or any other security concern.

Your Rights

You have certain rights relating to your Personal Data, subject to applicable data protection laws. These rights may include:

  • To access your Personal Data held by us;
  • To erasure or deletion of your Personal Data, to the extent permitted by applicable data protection laws;
  • To receive communications related to the processing of your Personal Data that are concise, transparent, intelligible, and easily accessible;
  • To restrict the processing of your Personal Data, to the extent permitted by law;
  • To object to the further processing of your Personal Data, including the right to object to marketing;
  • To request that your Personal Data be transferred to a third party, where technically feasible;
  • To receive your Personal Data in a structured, commonly used, and machine-readable format;
  • To lodge a complaint with a supervisory authority;
  • To rectify inaccurate Personal Data and, taking into account the purpose of processing, ensure it is complete; and
  • Not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects.

Where the processing of your Personal Data by us is based on consent, you have the right to withdraw that consent without detriment at any time, or to exercise any of the rights listed above, by emailing us at hello@getpolychart.com.

How can You update, correct, or delete Personal Data?

You can change your profile information in the app at any time. For full deletion of your account and associated Personal Data, email hello@getpolychart.com with the subject line REQUEST FOR PERSONAL DATA DELETION.

Although we will use reasonable efforts to delete your Personal Data, you understand that it may not be technologically possible to remove every record from our systems - including backups designed to protect data from inadvertent loss. Where we cannot delete a record, we will put in place appropriate measures to prevent any further processing of such data.

Can You opt out of receiving communications from Us?

We only send emails or other messages related to your account unless we have your express consent to do otherwise. We do not sell your information to third parties, and we do not share your contact information with third parties or affiliates for marketing or promotional purposes.

Information submission by minors

We do not knowingly collect Personal Data from individuals under the age of 18. Our Services are not directed to individuals under the age of 18, and we request that these individuals not provide Personal Data to us. If we learn that Personal Data from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you are aware of a user under the age of 18 using the Services, please contact us at hello@getpolychart.com.

California Residents

California residents may request and obtain from us, once a year and free of charge, a list of the third parties (if any) to which we disclosed their Personal Data for direct marketing purposes during the preceding calendar year, and the categories of Personal Data shared with those third parties. We do not disclose Personal Data to third parties for their direct marketing purposes. If you are a California resident and wish to obtain that information, please submit your request by emailing us at hello@getpolychart.com with California Privacy Rights in the subject line.

Changes to this Privacy Policy

We occasionally update this Privacy Policy. If we modify this Privacy Policy, we will post the modified terms on our website and/or notify you via the email address you have provided to us. You can store this policy and any amended version digitally, print it, or save it in any other way. Any changes to this Privacy Policy will be effective immediately upon providing notice, and shall apply to all Personal Data we maintain, use, and disclose. If you continue to use the Services following such notice, you are agreeing to those changes.

Contact Us

If you have any questions about this Privacy Policy, please contact us by email at hello@getpolychart.com. You can also reach us by mail at: 1 AND 1 Life, Inc. (Polychart), 40 Harrison Street, Apt 36L, New York, NY 10013. Please note that email communications are not always secure, so please do not include sensitive information in your emails to us.