Privacy Policy
Effective Date: August 1, 2026 Last Updated: August 1, 2026
This Privacy Policy describes how Momentum Body Work LLC, a California limited liability company, collects, uses, stores, shares, and protects information through the MomentumWellness4you website and services. That website and platform are referred to in this policy as the "Service."
Who processes your information. Momentum Body Work LLC is the organization that collects and processes personal information through MomentumWellness4you, and is the data controller for the information described in this policy. Throughout this policy, "MomentumWellness4you," "Momentum," "we," "us," and "our" refer to Momentum Body Work LLC. MomentumWellness4you is a brand name and is not a separate legal entity.
We have written this policy to be read, not skimmed. If anything here is unclear, contact us at founder@momentumwellness4you.com.
1. Introduction
MomentumWellness4you is an educational anatomy platform operated by Momentum Body Work LLC. We provide interactive 3D anatomy, medical illustrations, educational articles, anatomy search, and premium educational content, along with user accounts and paid subscriptions.
Momentum is not a healthcare provider. We do not provide medical advice, diagnosis, treatment, physical therapy, telehealth, or emergency services. Because of this, we deliberately collect a small amount of information — essentially what is needed to give you an account and take payment for a subscription. We do not want, and do not knowingly collect, medical records or clinical health information about you.
This policy applies to the Service and to information we collect through it. It does not apply to third-party websites or services that we link to but do not control (for example, an external research article).
By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically when you use the Service, and information we receive from the service providers that operate parts of our platform.
2.1 Information You Provide
- Account information. When you create an account, you provide your email address and a password. Your password is handled by our authentication provider (Supabase) and is stored only in a securely hashed form — we never see or store your plain-text password.
- Communications. If you email us or contact support, we receive the contents of your message and your contact details so we can respond.
A note on anatomy search. Anatomy search runs in your browser. The words you type into search are used on your device to find relevant educational content and are not transmitted to or stored by us. Even so, please do not enter information you consider medically sensitive.
2.2 Automatically Collected Information
When you use the Service, we and our providers automatically collect limited technical information, including:
- Device and connection data such as IP address, browser type, operating system, and general device characteristics.
- Usage data from standard server logs, such as the pages you request, referring pages, and timestamps.
- Diagnostic and log data used to keep the Service secure, detect abuse, and fix errors.
We use this information to operate, secure, and improve the Service. We do not use it to build advertising profiles about you.
2.3 Cookies and Similar Technologies
We use a minimal, privacy-conscious approach to cookies:
- Essential cookies. We use cookies that are strictly necessary to run the Service — primarily to keep you securely signed in (your authentication session) and to protect against fraud and abuse. The Service cannot function without these, so they are not subject to opt-in consent under applicable law.
- Payment cookies. When you go through checkout, our payment processor (Stripe) may set cookies on its own checkout pages to process your payment securely and prevent fraud.
We do not currently use analytics, advertising, cross-site tracking, or third-party marketing cookies. You can control or delete cookies through your browser settings, but disabling essential cookies will prevent you from signing in.
2.4 Authentication Data
Accounts and sign-in are provided through Supabase Authentication. This involves:
- Your email address and a securely hashed password.
- Email verification status and related timestamps.
- Session tokens (stored in cookies) that keep you signed in across pages and devices.
- Security metadata such as sign-in timestamps used to protect your account.
We use authentication data to create and secure your account, verify your email, keep you signed in, and let you reset your password.
2.5 Payment Information
Paid subscriptions are processed by Stripe, our third-party payment processor. We do not collect or store your full payment card number, card security code, or bank details. That information is provided by you directly to Stripe and handled under Stripe's own security standards (Stripe is a PCI-DSS Level 1 certified provider).
From Stripe, we receive and store limited billing metadata needed to manage your subscription, such as:
- A Stripe customer identifier and subscription identifier.
- Your subscription status (for example, active, past due, or canceled), plan, and the current billing period end date.
- Whether a cancellation is scheduled.
We use this to grant or remove access to premium content, show your membership status, and provide support. Depending on your payment method and location, Stripe may also process billing details such as your name, billing address, and country.
2.6 Analytics
Momentum does not currently use third-party analytics, advertising, or cross-site tracking services. To understand how the Service performs, we rely only on the essential operational and security logs described in Section 2.2. If we introduce privacy-respecting analytics in the future, we will update this policy first, list the provider in Section 6, and configure any such analytics so that they do not result in a "sale" or "share" of personal information as those terms are defined under the CCPA (Section 11).
3. How We Use Information
We use personal information to:
- Provide the Service — create and maintain your account, authenticate you, and deliver the educational content and features you request.
- Process subscriptions — take payment through Stripe, manage renewals and cancellations, and grant or remove premium access based on your current entitlement.
- Communicate with you — send account and transactional messages such as email verification, password resets, subscription confirmations, receipts, and cancellation notices, and respond to your support requests.
- Secure the Service — detect, prevent, and investigate fraud, abuse, unauthorized access, and technical problems.
- Improve the Service — understand aggregate usage and diagnose issues to make the platform better.
- Comply with law — meet our legal, tax, accounting, and regulatory obligations, and enforce our Terms of Service.
We do not sell your personal information, and we do not use it for third-party advertising.
4. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal information only where we have a legal basis to do so. Our bases are:
- Performance of a contract — to provide the Service and your membership under our Terms of Service (for example, creating your account and processing your subscription).
- Legitimate interests — to secure the Service, prevent fraud and abuse, and improve our platform, provided these interests are not overridden by your rights. Where we rely on legitimate interests, you may object as described in Section 12.
- Legal obligation — to comply with laws that apply to us, such as tax and accounting requirements for billing records.
- Consent — where we ask for it (for example, any optional analytics that require consent). You may withdraw consent at any time without affecting processing already carried out.
5. How We Share Information
We share personal information only in the limited circumstances described below. We do not sell your personal information, and we do not share it with third parties for their own marketing.
- Service providers (processors). We share information with the vendors that operate parts of our platform on our behalf — payment, authentication, database, and hosting providers (see Section 6). They may process your information only to provide services to us and are bound by contractual confidentiality and data-protection obligations.
- Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Momentum, our users, or the public, or to investigate fraud or security incidents.
- Business transfers. If Momentum is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy or notify you of any material change.
- With your direction. We share information at your request or with your consent.
6. Third-Party Services
The Service relies on the following key third-party providers. Each processes personal information under its own privacy policy and security program.
6.1 Stripe (Payments)
Stripe processes subscription payments and manages billing. Your payment card details are provided directly to Stripe; we receive only billing metadata (Section 2.5). Stripe's handling of your information is governed by the Stripe Privacy Policy (https://stripe.com/privacy).
6.2 Supabase (Authentication and Database)
Supabase provides our authentication and our database. It stores your account credentials (in hashed form) and your profile and subscription status. Supabase's handling of your information is governed by the Supabase Privacy Policy (https://supabase.com/privacy).
6.3 Hosting and Infrastructure
Our website is served by Vercel, our cloud hosting and content-delivery provider, which processes technical data (such as IP address and request logs) to deliver the site and keep it secure. Its handling of information is governed by its own privacy policy.
We may update this list as our providers change. Material changes will be reflected in this policy.
7. Data Retention
We keep personal information only for as long as we need it for the purposes described in this policy:
- Account information is retained while your account is active.
- Subscription and billing records are retained for as long as needed to manage your membership and to meet legal, tax, and accounting obligations, which may require us (or Stripe) to keep transaction records for a period set by law (commonly up to seven years).
- Logs and diagnostic data are retained for a limited period for security and troubleshooting, then deleted or aggregated.
- Support communications are retained for as long as needed to resolve your request and keep a reasonable service record.
When you delete your account (Section 13), we delete or de-identify your personal information within a reasonable period, except where we are required or permitted by law to retain it (for example, billing records for tax purposes) and except for information already contained in secure backups, which is deleted on our normal backup rotation.
8. Security
We take reasonable and appropriate technical and organizational measures to protect personal information, including:
- Passwords stored only in hashed form by our authentication provider.
- Encryption of data in transit (HTTPS/TLS) across the Service.
- Access controls that limit who can access personal data, and database-level rules that prevent one user from accessing another user's records.
- Reliance on established, security-certified providers for payments (Stripe) and infrastructure (Supabase and our hosting provider).
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential and for notifying us if you believe your account has been compromised.
9. International Data Transfers
Momentum is operated from the United States, and our providers may process and store information in the United States and other countries. If you access the Service from outside the United States, your information will be transferred to and processed in countries that may have different data-protection laws than your own.
Where we transfer personal information out of the EEA or the United Kingdom, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), or another lawful transfer mechanism offered by our providers.
10. Children's Privacy
The Service is intended only for adults and is not directed to children. Consistent with the eligibility requirement in our Terms of Service, we do not knowingly collect personal information from anyone under 18. We do not target children, and we do not knowingly permit anyone under 18 to create an account or purchase a subscription.
If you believe someone under 18 has provided us with personal information, contact us at founder@momentumwellness4you.com and we will delete it.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), gives you the following rights regarding your personal information:
- Right to know / access — to request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete — to request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct — to request correction of inaccurate personal information.
- Right to opt out of sale or sharing — Momentum does not sell your personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. There is nothing to opt out of.
- Right to limit use of sensitive personal information — the account log-in credentials we collect (your email together with your password) are "sensitive personal information" under the CPRA, but we use them only to authenticate you and secure your account, and we do not use sensitive personal information to infer characteristics about you. This use does not trigger the right to limit, so there is nothing to limit.
- Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service because you exercised your privacy rights.
Categories of personal information we collect (as defined by the CCPA) include: identifiers (such as email address and IP address); account and commercial information (such as subscription and billing metadata); internet or network activity (such as usage and log data); and a limited category of sensitive personal information — account log-in credentials (your email combined with your password) — used only to authenticate you and secure your account.
To exercise these rights, contact us at founder@momentumwellness4you.com. We will verify your request using your account information and respond within the time required by law. You may use an authorized agent to submit a request on your behalf, subject to verification.
12. Your GDPR Rights (EEA and United Kingdom)
If you are in the EEA or the United Kingdom, you have the following rights regarding your personal information, subject to applicable law:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted ("right to be forgotten") in certain circumstances.
- Restriction — restrict our processing in certain circumstances.
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at founder@momentumwellness4you.com. You also have the right to lodge a complaint with your local data protection supervisory authority, though we encourage you to contact us first so we can help.
The data controller for your personal information is Momentum Body Work LLC, reachable at the contact details in Section 14.
13. How to Delete Your Account
You can request deletion of your account and associated personal information at any time by emailing us at founder@momentumwellness4you.com from the email address associated with your account. We will verify the request against your account and process it.
Before requesting deletion, you should cancel any active subscription (see the Terms of Service and Refund Policy) so that it does not renew. When we delete your account, we remove or de-identify your personal information as described in Section 7, subject to legal retention requirements (such as billing records) and to routine deletion of secure backups. Deletion is permanent and cannot be undone.
14. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or your personal information, contact us at:
Momentum Body Work LLC MomentumWellness4you Attn: Privacy 755 Sunrise Ave, Roseville, CA 95661 Email: founder@momentumwellness4you.com
We will respond within a reasonable time and within any period required by applicable law.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, our providers, or the law. When we make material changes, we will update the "Last Updated" date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after an update takes effect means you accept the revised policy.