What we collect, why, who touches it, and how you stay in control. Written to be read, not skimmed.
Effective September 22, 2026
1. Who we are and what this covers
Program Delta Performance Group, LLC ("PDPG," "we," "us") is a Missouri limited liability company based in Kirkwood, Missouri. We run a private performance practice for executives and high-performing professionals.
This policy covers:
program-delta.com — our public website and lead-magnet pages (the 4-Pillar Audit, the ebook).
Delta OS at os.program-delta.com — our client application, intake, and the Delta Terminal used by the Principal to review client signal.
Email we send you after you opt in.
Integrations you authorize inside Delta OS, including the Oura Ring connection.
Some things we link to are run by other companies under their own policies: our store at edgepd.store (Shopify), the CORE community on Skool, scheduling on Calendly, video calls on Zoom, and any clinical services delivered by our licensed clinical partners. When you use those, their privacy policies apply to what you give them.
2. What we collect
Information you give us
Opt-in forms. Your email address and, optionally, first name when you request the 4-Pillar Audit, the ebook, or otherwise join our list. We also record which page you signed up from and the site that referred you, so we know what is working.
Applications and intake. When you apply to work with us through Delta OS, the answers you give — where you are, what is falling apart, what you are after, your role and industry, and similar context.
Account information. The email address you use to sign in to Delta OS. Sign-in uses a one-time code sent to that address; we do not store a password.
Client records. If you become a client: your daily "pulse" check-ins (a score, a word, and any note you add), the coaching plan, session notes, messages, and the Principal's working notes about your program.
Correspondence. Anything you send us by email, on a call, or in a session.
Information collected automatically
Server logs. Our hosting providers record standard technical data such as IP address, browser type, pages requested, and timestamps in order to serve and secure the sites.
Referrer attribution. The public site stores the referring URL in your browser's session storage (cleared when you close the tab) so a form submission can record where you came from. This is not an advertising tracker.
3. Wearable and health-related data
Performance coaching is built on measurement, so some of what we handle is sensitive. We treat it that way.
Oura Ring
If you are a client and you choose Connect with Oura inside Delta OS, you are asked by Oura to authorize our application ("Delta OS Terminal") to read specific categories of your Oura data. Depending on what you approve, this can include:
Sleep, readiness, and activity summaries (scores, sleep duration and stages, steps).
Heart rate data, including resting heart rate and heart rate variability (HRV), and respiratory rate.
Temperature deviation from your personal baseline.
Workout sessions and tags you log in the Oura app.
Personal information held by Oura — email address, age, sex, height, and weight.
We pull this data on a schedule (currently once a day) and on demand when the Principal reviews your feed. We store daily summaries, not raw second-by-second sensor streams. We store the access tokens Oura issues so the connection keeps working without asking you to sign in again; those tokens are stored server-side, encrypted at rest, and are never shown in the browser.
You can disconnect at any time — inside Delta OS, or by revoking "Delta OS Terminal" in your Oura account settings. When you disconnect, we delete the stored tokens and stop syncing. Data already synced is handled under Section 8.
What we are not
PDPG is a coaching and education practice. We are not a healthcare provider, and Bryan Sauder does not diagnose, treat, or prescribe. Where a program includes clinical services — labs, prescriptions, or medical oversight — those are delivered by independent licensed clinicians and clinical partners under their own agreements and privacy practices, which may include HIPAA. Information you give a clinical partner is governed by their policy; information the Principal receives back from them, with your consent, is handled under this one.
Signal only. The Delta Terminal and The Read exist to inform training and recovery decisions. Nothing in them is a medical diagnosis. If something in your data looks like it warrants a physician's attention, we will tell you to see one.
4. How we use information
To send you what you asked for (the Audit, the ebook, our emails) and to follow up.
To evaluate applications and decide whether we are a fit for each other.
To deliver coaching: build and adjust your program, read your recovery and readiness signal, prepare for sessions, and coordinate handoffs between the specialists working with you.
To write The Read — a periodic interpretation of your signal (see Section 5).
To run, secure, debug, and improve our sites and Delta OS.
We do not sell your personal information, and we do not use your health or wearable data for advertising.
5. Automated analysis
Delta OS uses an AI language model (currently provided by Anthropic) to draft The Read from your recent wearable summaries, your pulse check-ins, and the Principal's notes. The model receives only the signal described in Section 3 and 2 — no labs, no clinical records — and is instructed not to diagnose or recommend medications, supplements, hormones, or peptides.
Every Read is a draft until the Principal reviews and approves it. No decision about your program is made solely by an automated system. The AI provider processes the data to generate the response and, under our agreement with them, does not use it to train their models.
6. Who we share information with
We share information only as needed to run the practice:
Service providers that host and operate our systems: Netlify (website hosting), Supabase and Vercel (Delta OS database, authentication, and application hosting), Kit (email list and delivery), Google Workspace (email and documents), Calendly and Zoom (scheduling and calls), Anthropic (AI drafting, Section 5), and Oura (the API we read your ring data from).
Your coaching team. Specialists and partners working on your program — for example nutrition, performance therapy, or a clinical partner — receive the parts of your information they need to do their part, and only with your knowledge.
Legal and safety. If required by law, subpoena, or to protect someone's safety or our legal rights.
Business transfer. If PDPG is sold or merged, your information may transfer to the successor under this policy.
We do not share, sell, or rent your list data or client data to third parties for their own marketing.
7. Cookies, storage, and tracking
program-delta.com does not run advertising pixels or third-party analytics trackers. It uses your browser's session storage for referrer attribution (Section 2) and nothing else. Delta OS sets the cookies or local storage needed to keep you signed in. Third-party services we link to (Kit forms, Calendly, Skool, Shopify) may set their own cookies when you use them.
8. How long we keep information
Email list: until you unsubscribe or ask us to delete you. Every email has an unsubscribe link.
Applications: up to 24 months after submission if we do not work together, so we can reconnect if timing changes; deleted sooner on request.
Client records and wearable summaries: for the duration of the engagement and up to 7 years after, because long baselines are part of the value of the work and because we have record-keeping obligations. You can ask us to delete wearable data earlier (Section 10).
Oura tokens: deleted when you disconnect or when the engagement ends.
Server logs: per our hosting providers' short default retention windows.
9. Security
Delta OS runs on providers with encryption in transit and at rest, row-level access controls, and one-time-code sign-in. Wearable tokens and API keys are stored as server-side secrets. Access to client data is limited to the Principal and the people working on your program. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you as the law requires.
10. Your choices and rights
Unsubscribe from email at any time using the link in any message.
Disconnect Oura at any time in Delta OS or in your Oura account.
Access, correct, export, or delete your information by emailing us (Section 14). We will verify it is you and respond within 30 days. Some records may be kept where the law requires or where we need them to resolve disputes.
Depending on where you live you may have additional rights under state or national privacy laws. We honor them regardless of residency where practical.
11. Children
Our services are for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
12. Where data is processed
We are based in the United States and our providers process data primarily in the United States. If you access our services from elsewhere, your information will be transferred to and processed in the U.S.
13. Changes to this policy
When we change this policy we will update the effective date at the top. For material changes affecting client or wearable data, we will notify active clients by email.