Privacy Policy
Last updated: July 15, 2026
1. Who We Are
The CoachRight platform (the "Service") is provided by CoachRight ("we", "us"), established in Ireland. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Irish data-protection law. This Policy explains what personal data is processed in the Service, for what purposes, how it is protected, and what rights you have. Questions about this Policy: hello@coachright.io.
2. Roles: the Coach as Controller, CoachRight as Processor
The Service has two kinds of users — Coaches (our customers) and their Clients (trainees who use the companion app via an access code issued by their Coach).
- For a Coach's own account data (username, contact details, billing records) we are the data controller.
- For Client data that a Coach enters into the Service, or that a Client enters themselves (names, contact info, body measurements, nutrition and workout logs), the Coach is the data controller: the Coach decides whose data is processed and why. CoachRight acts as the processor and platform operator — we process this data only to provide the Service and per the instructions implied by its functionality.
Coaches are responsible for obtaining their Clients' consent to the processing of their data in the Service, including health-related data.
3. Data We Process
3.1. Coach data
- registration data: username, display name, email address;
- credentials: password (stored only as a bcrypt hash — never in plaintext), last-login timestamp;
- subscription and payment data: plan, validity period, records of received payments;
- content created in the Service: programs, exercises, notes, finance records, schedule entries.
3.2. Client data
- identification and contact data entered by the Coach or the Client: name, phone/contact details, access code;
- health-related data: body measurements (weight, girths, body-fat percentage), workout logs (exercises, weights, reps), food diary entries (meals, calories, macronutrients), and photos of nutrition labels or meals uploaded for scanning;
- in-app activity data (completed workouts, streaks, achievements).
4. Purposes and Legal Bases
- providing the Service — performance of the contract with the Coach (GDPR Art. 6(1)(b)): maintaining accounts, storing and displaying data, syncing between the trainer and client apps;
- processing Client data — based on the Client's consent obtained by their Coach (GDPR Art. 6(1)(a) and, for health-related data, Art. 9(2)(a)), within the Service's functionality;
- payment records — performance of the contract and compliance with legal obligations, including tax and accounting law (Art. 6(1)(c));
- security — our legitimate interest in protecting the Service from abuse (Art. 6(1)(f));
- communication — service notices and responses to your requests.
We do not use personal data for advertising and we do not sell it.
5. Isolated-Database Architecture
Every Coach receives their own, fully isolated database. All of that Coach's Client data — programs, workouts, nutrition, finance — lives only in that database. Different coaches' data is physically separated: one coach's requests cannot read another coach's data. Routing to the correct database is enforced server-side through the authenticated session token.
6. AI Processing (Nutrition Scanning)
When a Client photographs a nutrition label or a meal to log it in the food diary, the image is transmitted to Anthropic's Claude API (servers located in the United States) solely to extract nutrition data (calories, protein, carbohydrates, fat). Under Anthropic's API terms, submitted images are not used to train models. The extracted result is stored in the Coach's isolated database. Using this feature is optional — nutrition data can always be entered manually instead. See Section 13 on international transfers.
7. Storage and Security
- passwords are stored only as bcrypt hashes; plaintext passwords are never stored and cannot be viewed even by an administrator;
- sessions use signed JWT tokens with limited validity;
- SQLite databases run in WAL mode; each coach's database is isolated at the filesystem level;
- administrative functions are access-restricted and separately authenticated;
- backups are retained for a limited period (see Section 8).
No system can guarantee absolute security, but we apply reasonable organisational and technical measures appropriate to the nature of the data processed.
8. Retention and Deletion
Data is kept for as long as the Coach's account is active. A Coach may request full account deletion — in that case the master account record and the Coach's entire isolated database, including all Client data in it, are hard-deleted. Backups containing the deleted data are purged within 30 days. Payment records required for tax and accounting compliance are retained in anonymised form for the statutory period (generally six years in Ireland). Details are in the Data Deletion Policy.
9. Data Sharing
We do not sell personal data and do not share it for advertising. Data is shared only with the following categories of processors, to the extent needed to run the Service:
- hosting provider — running the servers and storing the databases;
- Anthropic (US) — image processing for nutrition scanning (Section 6);
- payment provider — if you pay by card once card payments are available, your payment details are collected and processed directly by the payment provider; full card numbers never reach our servers.
Data may be disclosed to public authorities only where we are legally required to do so under EU or Irish law.
10. Your Rights
Under the GDPR you have the right to access your data, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format (data portability).
- Coaches contact us directly at hello@coachright.io;
- Clients should first contact their Coach — the Coach controls their records and can correct or delete them in the app. If the issue is not resolved, a Client may also contact our support and we will assist within our role as processor.
You may also withdraw consent to processing (which may make further use of the Service impossible) and lodge a complaint with a supervisory authority — in Ireland, the Data Protection Commission, or the data-protection authority of your own EU member state.
11. Cookies and Local Storage
We use only functional browser storage (session token, theme, language). There are no advertising or third-party analytics cookies. See the Cookie & Storage Policy.
12. Children
The Service is directed at professional coaches. Client accounts are created by a Coach, not by the child; the Service is not intended for independent use by children under 16. If a Coach works with a minor Client, the Coach must ensure a parent or legal guardian has consented to the processing of that Client's data.
13. International Transfers
Primary data storage happens on the Service's servers. The only routine transfer outside the European Economic Area is the transmission of nutrition-label/meal photos to Anthropic's Claude API in the United States, as described in Section 6. Such transfers are protected by appropriate safeguards under Chapter V of the GDPR (such as the European Commission's Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as applicable to the provider). The scanning feature is optional; manual entry involves no such transfer.
14. Changes to This Policy
We may update this Policy. We will announce material changes through the Service or by email. The date of the latest revision is shown at the top of this page.
15. Contact
CoachRight, email hello@coachright.io. See also our Terms of Service and Data Deletion Policy.