Template — legal review required
This document is an accurate technical description of the platform’s data handling, provided as a starting point. It is not legal advice. The operator must have it reviewed by a qualified lawyer and must replace every [BRACKETED] placeholder before publishing or submitting to an app store.
Privacy Policy
Last updated: 2026-08-07
This policy explains what [COMPANY LEGAL NAME](“we”, “us”, the “Platform”) collects when you use this coaching platform, why we collect it, who we share it with, how long we keep it, and how you can get it back or delete it.
The Platform is white-label software used by independent fitness and nutrition coaches. If you are a client, your coach is the person who decides what to ask you for and how to use it — in data protection terms your coach is generally the controller and we act as a processoron their behalf. For coaches’ own account data, we are the controller. [Confirm this characterisation with counsel for your [JURISDICTION].]
1. Who we are and how to contact us
- Operator: [COMPANY LEGAL NAME], [COMPANY ADDRESS].
- Privacy contact: [CONTACT EMAIL] (also our contact for data subject requests, deletion requests and complaints).
- Data protection contact / representative, where one is required: [DPO / PRIVACY CONTACT].
- Governing law and venue: [JURISDICTION].
2. What we collect
We only collect what the Platform actually needs to work. The list below reflects the real data model, not a generic template.
Account and identity
- Email address and a hashed password (authentication is handled by Supabase Auth; we never store your password in plain text).
- Name, profile photo, time zone and locale, where you provide them.
- For coaches: business name, brand colours, logo, public landing-page content and subdomain slug.
- Membership status, tier, team/seat role and referral codes.
Health and fitness data
Much of this is special-category / sensitive health data. We process it only to deliver the coaching service you signed up for, and only on the lawful basis of your explicit consent and the contract between you and your coach. [Confirm lawful bases with counsel.]
- Body weight logs and weight-trend history.
- Body measurements and biometrics (circumferences, body-fat estimates and similar).
- Progress photos you upload, stored in private storage buckets.
- Weekly check-ins — free-text answers about training, nutrition, sleep, stress, energy, adherence and anything else your coach asks.
- Food and nutrition logs, macro targets, meal plans, saved meals, dietary likes, dislikes and allergies.
- Blood panel results you or your coach enter, including flagged out-of-range markers.
- Menstrual cycle logs, including cycle phase and symptoms.
- PAR-Q health screening and waiver answers, including cardiac and other medical risk questions, and whether your answers flagged a need for medical clearance.
- Wearable / Apple Health metrics you choose to sync: steps, resting heart rate, heart-rate variability, sleep minutes, active energy, workout minutes and body weight.
- Supplement protocols (products, dosages, timing) and adherence.
- Habits you tick off and your daily completion history.
- Workout logs — exercises, sets, reps, loads, RPE and personal records.
- Goals, assessments, client notes and tasks recorded by you or your coach.
Communications and community
- 1:1 and group messages between you and your coach, and posts, comments and reactions in community spaces.
- Voice notes you record, stored as audio files.
- Group video call participation (calls are hosted by a third-party video provider — see section 5).
- Notification preferences and web-push subscription endpoints for your browser or device.
Contracts, payments and records
- E-signature data for coaching agreements: the typed legal name you signed with, the signature timestamp, and — as required to make an electronic signature evidentially useful — your IP address and browser user-agent string at the moment of signing.
- Payment records: subscription and package status, amounts, currency, invoice/charge identifiers and payment state. Card numbers are handled entirely by Stripe and never touch our servers.
Technical data
- Session cookies needed to keep you logged in, and a cookie storing your light/dark theme choice.
- Server logs generated by our hosting providers (IP address, timestamp, request path) used for security, abuse prevention and debugging.
- Rate-limiting counters tied to your account or IP, used to stop abuse.
We do not run advertising SDKs, third-party analytics trackers, session recording, fingerprinting or cross-site tracking of any kind. There are none in this application.
3. How we use your data
- To provide the coaching service: build and deliver meal plans, training programs, habits, check-ins and progress tracking.
- To let your coach — and only your coach and any team members they have explicitly granted a seat — review your progress and respond to you.
- To send transactional email and push notifications you have opted into (check-in reminders, new message alerts, macro updates, appointment reminders).
- To take payment for coaching packages and subscriptions.
- To keep the service secure: authentication, rate limiting, abuse and fraud prevention.
- To meet legal, tax and accounting obligations.
We never use your health or fitness data for advertising, ad targeting, or audience building, and we never sell or rent your personal data to anyone. We do not share it with data brokers. This is a hard product commitment, not just a policy statement — the application contains no advertising or analytics integrations.
4. Automated processing and AI
Two features send a limited slice of your data to Anthropic (the provider of the Claude AI models) so the model can generate text. Anthropic processes it as our sub-processor to return a result to us.
- Check-in summaries. When your coach generates a summary of your weekly check-in, we send your first name together with your full check-in answers for that week.
- Meal-plan generation. When a plan is generated, we send your macro targets and your dietary likes, dislikes and allergies.
We do not send progress photos, blood panels, PAR-Q answers, messages, cycle logs or payment data to any AI provider. These features produce suggestions for a human coach to review; they do not make decisions with legal or similarly significant effects about you. [If you enable further AI features, this section must be updated before launch.]
5. Who we share data with
These are our service providers (sub-processors). We share only what each one needs.
- Supabase — application database, authentication and file storage (progress photos, voice notes, uploads). Effectively all data described above is stored here.
- Stripe — payment processing for coaching packages, subscriptions and coach payouts. Stripe receives your email, name and payment details directly; we receive back only charge/subscription identifiers and status.
- Resend — transactional email delivery (invites, check-in reminders, password resets, notifications). Receives your email address and the message content.
- Anthropic — AI text generation, limited to the data listed in section 4.
- Jitsi / 8x8 — hosting of group video calls. Receives your display name and the call room identifier while you are in a call.
- Web push services operated by Apple, Google and Mozilla — delivery of browser/device push notifications to the endpoint your browser registered. These services receive the notification payload we send.
- Your coach (and any team members they have granted a seat) — they see the data you submit to them. Other clients never see your health data; they only see what you voluntarily post in a shared community space.
- Hosting infrastructure — [HOSTING PROVIDER, e.g. Vercel] serves the application and generates request logs.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect someone’s vital interests.
6. International transfers
Our providers may process data outside your country, including in the United States. Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. [Confirm your regions and safeguards with counsel and record the actual data-residency regions you configure in Supabase and Stripe.]
7. How long we keep it
- Account, coaching, health and messaging data: kept for as long as your account is active, then deleted when you delete your account (see section 9).
- Financial and tax records: retained for the period required by law in [JURISDICTION], typically several years, even after account deletion.
- Signed contracts and their e-signature audit data: retained for the limitation period applicable to the agreement, so the signature stays verifiable.
- Server and security logs: short retention, per our providers’ defaults.
8. How we protect it
- All traffic is encrypted in transit (TLS); data at rest is encrypted by our hosting providers.
- Every table enforces row-level security in the database, so a coach can only read their own clients’ rows and a client can only read their own.
- Progress photos, voice notes and uploaded files are held in private storage and served only via short-lived signed URLs.
- Payment card data never reaches our servers.
- Passwords must be at least 8 characters, and email confirmation is required before an account can be used — so nobody can claim an account by guessing your email address.
9. Your rights — including deletion and export
Depending on where you live you have some or all of the following rights. We honour these requests for everyone, regardless of location.
- Access and export. You can request a machine-readable copy of your data. Coaches can export their roster and account data from the dashboard; clients can download their own data from Account → Settingsinside their coach’s app, or request it by emailing [CONTACT EMAIL]. We respond within 30 days.
- Deletion. You can delete your account and the personal data associated with it at any time, yourself, from your account settings — clients at /account/settings in their coach’s app, coaches at /dashboard/settings/account. Deletion removes your profile, health logs, check-ins, photos, voice notes and messages, subject only to records we are legally required to keep (section 7). You can also email [CONTACT EMAIL] and we will action it for you.
- Correction. You can edit most of your data in the app directly.
- Withdraw consent. You can stop syncing wearable data, turn off push notifications, or stop submitting health information at any time — this does not affect processing already carried out.
- Object / restrict. You can ask us to stop or limit certain processing.
- Complain. You can complain to your data protection authority ([SUPERVISORY AUTHORITY]). We would appreciate the chance to resolve it first at [CONTACT EMAIL].
If you are a client, your coach also holds a copy of the coaching relationship data. Where your coach is the controller, we will forward your request to them and assist them in fulfilling it.
10. Children
The Platform is not intended for anyone under 16 (or the minimum age in your country, if higher), and we do not knowingly collect data from them. If you believe a child has created an account, contact [CONTACT EMAIL] and we will delete it.
11. Cookies
We use only strictly necessary cookies: an authentication session cookie, a short-lived cookie used during password recovery, and a cookie that remembers your light/dark theme. There are no advertising, analytics or tracking cookies, so there is nothing to opt out of.
12. Changes to this policy
If we make a material change we will update the date at the top of this page and notify account holders by email or in-app before the change takes effect.
13. Contact
Questions, requests or complaints: [CONTACT EMAIL] — [COMPANY LEGAL NAME], [COMPANY ADDRESS].