Privacy Policy
Last updated: 1 July 2026
This policy explains what personal data backpain.ai (operated by Jules Thine, Georgia — the "data controller") collects and how we use it. Contact: support@backpain.ai.
What we collect
- Your check-in answers — the back-pain details you provide (where it hurts, duration, triggers, goals). This is health-related information you choose to share so we can generate your plan.
- Email address — to send your plan, sign-in links, and account emails.
- Usage & technical data — basic logs, IP (for rate-limiting/abuse prevention), and cookies.
- Anonymous usage statistics — which steps of the check-in are viewed and completed, with no name, email, or answer content attached. Collected cookieless (nothing stored on your device) and hosted in the EU (PostHog). We use this only to improve the Service.
- Payment data — handled entirely by Paddle. We never see or store your card details.
Health-related data. Your check-in answers relate to your health. We process them only to create and adapt your plan, based on your consent, and you can withdraw consent and delete your data at any time.
How we use it
To provide the Service (generate and adapt your plan and sessions), to sign you in, to process your subscription, to prevent abuse, and to communicate with you. We do not sell your data or use it for third-party advertising.
Service providers (sub-processors)
We share the minimum necessary with providers that help run the Service:
- Anthropic — AI generation of your plan/session content.
- Railway — hosting and database.
- Resend — sending sign-in and account emails.
- Paddle — payments and subscription management (Merchant of Record).
- Cloudflare — bot protection (Turnstile), when enabled.
- PostHog (EU) — anonymous, cookieless usage statistics.
Cookies
We use a small number of essential cookies: a signed session cookie (to keep you logged in), a state cookie for the free flow, and bot-protection cookies. No third-party advertising cookies.
Retention
We keep your data while your account is active. Ask us to delete it and we will, except where we must keep limited records (e.g. for tax/payment purposes via Paddle).
Your rights
Depending on where you live (including the EU/UK under GDPR), you may have rights to access, correct, delete, or export your data, and to object to or restrict processing. Email support@backpain.ai and we'll help.
International transfers
Our providers may process data outside your country. We rely on their safeguards for such transfers.
Children
The Service is not intended for anyone under 18.
Changes
We may update this policy; material changes will be posted here with a new date.