← Back to Coach Anvil

Legal

Privacy Policy

Last updated: July 2026

1. Who we are

Coach Anvil is operated from the European Union. We are the data controller for personal data processed through the service. Our servers are hosted in Frankfurt, Germany (EU) via Supabase.

2. Data we collect

  • Account data: your Google account email address and name, provided when you sign in via Google OAuth.
  • Health & fitness data: workout logs, training plans, body composition metrics (if connected), and activity data imported from Strava, Withings, or Apple Health.
  • Genetic data (optional): raw genotype files from 23andMe or Ancestry, if you choose to upload them. This is special category data under GDPR; it is processed only to generate fitness insights and is never sold or shared with third parties.
  • Voice data: audio from coaching sessions is processed by ElevenLabs in real time; we store the transcript for session continuity.
  • Usage data: API call counts and timing for rate-limiting and billing purposes (no behavioural profiling).

3. Legal bases (GDPR)

We process your data on the following legal bases:

  • Contract: account data, billing, and service delivery.
  • Legitimate interests: service improvement, fraud prevention, and security.
  • Explicit consent: genetic data and any other special category health data. You may withdraw consent at any time by deleting the data or your account.

4. Sub-processors

We share data with the following sub-processors solely to operate the service:

  • Supabase — database and authentication (EU, Frankfurt)
  • Anthropic — AI coaching (US; Standard Contractual Clauses apply)
  • ElevenLabs — voice synthesis and transcription (US; SCCs apply)
  • Stripe — payment processing (US/EU; SCCs apply)

5. Retention

We retain your Coach data for as long as your account is active. A successful self-service account deletion immediately cancels an owner's active subscription and removes the account, personal uploads, and Coach-held personal data. Stripe may retain payment and transaction records where tax, accounting, or fraud-prevention law requires it (typically up to 7 years).

6. Your rights (GDPR)

You have the right to access, rectify, erase, restrict processing of, or port your personal data. Signed-in users can download a portable JSON copy of their data or permanently delete their account from Settings. Account deletion requires a fresh Google authentication and explicit confirmation; owners of a shared tenant must transfer ownership or remove other members first. You also have the right to lodge a complaint with your local data protection authority. For rights that cannot be completed in-product, email privacy@coach.app. We will respond within 30 days.

7. Security

All data is encrypted at rest and in transit. Database rows are access-controlled with row-level security (Supabase RLS). Health and genetic data require authenticated access and cannot be accessed across accounts.

8. Changes to this policy

We will notify you by email at least 14 days before material changes take effect.

9. Contact

For privacy questions, email privacy@coach.app.

Terms of Service · Coach Anvil