Legal
Privacy Policy
Last Updated: February 11, 2026
Woodworth Group LLC, doing business as two ("we," "us," or "our"), operates the website mytwo.app and the two mobile application (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you visit our website or use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Waitlist & Account Information: Email address when you join our waitlist or create an account.
- Payment Information: When you purchase a founding member spot or subscription, payment is processed by Stripe. We do not store your credit card number, bank account number, or other financial account details on our servers. Stripe's handling of your payment information is governed by Stripe's Privacy Policy.
- Profile Information: When you use the two app, you may provide information including your name, age, sex, height, weight, fitness goals, training experience, dietary preferences, food allergies, injury history, and other health and fitness data you choose to share with the AI coach.
- Workout & Nutrition Data: Exercise logs, personal records, workout feedback, meal logs, pantry items, weight tracking entries, and related fitness and nutrition data you enter into the app.
- Injury & Rehabilitation Data: Information about current or past injuries, rehabilitation phases, pain levels, range of motion progress, and related recovery data you provide.
- Communications: Messages you send through the in-app AI chat, feedback you submit, and any correspondence with us.
1.2 Information Collected Automatically
- Log Data: When you access the Service, we may automatically collect information such as your IP address, browser type, operating system, referring URLs, pages viewed, and the dates and times of your visits.
- Device Information: We may collect information about the device you use to access the Service, including device type, operating system version, and unique device identifiers.
- Usage Data: We collect information about how you interact with the Service, including features used, actions taken, and time spent on various screens.
- Cookies & Similar Technologies: We use essential cookies to operate the Service. We do not use advertising or tracking cookies. You can control cookies through your browser settings.
1.3 Information We Do Not Collect
- We do not collect data from your device's health apps (Apple Health, Google Fit) unless you explicitly enable such integration in the future and grant permission.
- We do not access your contacts, photos, microphone, or camera unless a specific feature requires it and you grant explicit permission.
- We do not purchase data about you from third-party data brokers.
2. How We Use Your Information
We use the information we collect to:
- Provide and operate the Service, including delivering AI-generated workout, nutrition, and rehabilitation coaching tailored to your profile and history.
- Process transactions, and send related information, including purchase confirmations and invoices.
- Send administrative communications, such as waitlist updates, product announcements, and changes to our terms or policies.
- Improve the Service, including analyzing usage patterns, diagnosing technical issues, and developing new features.
- Personalize your experience, by using your fitness data, preferences, and history to generate relevant AI coaching suggestions.
- Ensure safety and security, including detecting fraud, abuse, and violations of our Terms of Service.
- Comply with legal obligations, and respond to lawful requests from public authorities.
3. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We share your information only in the following limited circumstances:
3.1 Service Providers
We share information with third-party service providers who perform services on our behalf:
Stripe
Payment processing
Neon
Database hosting
Resend
Email delivery
Vercel
App hosting
OpenAI
AI coaching
These providers are contractually obligated to use your information only to provide services to us and are prohibited from using it for their own purposes.
3.2 AI Processing
When you interact with the AI coach, your profile data, fitness history, and conversation context are sent to our AI model provider (currently OpenAI) to generate coaching responses. This data is used solely to generate your coaching response and is subject to our data processing agreement with the provider. We do not permit our AI provider to use your data to train their models.
3.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency).
3.4 Business Transfers
If two is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our Service before your information is transferred and becomes subject to a different privacy policy.
3.5 With Your Consent
We may share your information for any other purpose with your explicit consent.
4. Data Retention
- Waitlist data: We retain your email address and signup information for as long as the waitlist is active or until you request removal.
- Account and fitness data: We retain your data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes.
- Payment records: We retain transaction records as required by applicable tax and accounting laws (typically 7 years).
- Aggregated data: We may retain aggregated, de-identified data that cannot be used to identify you for analytical and product improvement purposes indefinitely.
5. Data Security
We implement commercially reasonable technical and organizational measures to protect your personal information, including:
- •Encryption of data in transit (TLS/SSL) and at rest
- •Secure database hosting with access controls
- •Regular security reviews of our infrastructure
- •Limited employee access to personal data on a need-to-know basis
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
6. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information, subject to certain exceptions.
- Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
- Opt-out: Unsubscribe from marketing emails at any time using the link in any email we send.
- Withdraw consent: Where we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@mytwo.app. We will respond within 30 days.
6.1 California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale of personal information. We do not sell personal information.
6.2 European Residents (GDPR)
If you are located in the European Economic Area, our legal basis for processing your information is typically your consent (which you may withdraw at any time), performance of a contract with you, or our legitimate business interests. You have the right to lodge a complaint with your local data protection authority.
7. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@mytwo.app.
8. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you by email. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Woodworth Group LLC
Email: privacy@mytwo.app
Website: mytwo.app
two is not a medical provider. The Service provides AI-generated fitness coaching, nutritional suggestions, and rehabilitation guidance for informational purposes only. It does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional before beginning any exercise, nutrition, or rehabilitation program.