Privacy Policy
What we collect, why we collect it, who we share it with, and the rights you can exercise at any time.
Effective September 2, 2026 · Last updated September 2, 2026
1. Introduction and Scope
This Privacy Policy explains how Coach Manuals ("Coach Manuals", "we", "us" or "our") collects, uses, discloses and protects personal information when you visit our website, create an account, or use the Coach Manuals platform (the "Service").
It applies to coaches and other professionals who hold accounts with us, to visitors to our website, and to people who receive a manual or check-in link that a coach has shared with them.
It does not apply to how an individual coach handles the information of their own clients outside our Service. Coaches decide what client information to enter and are responsible for their own privacy practices.
2. Our Role: Controller and Processor
For your account data, we are the controller. We decide how and why we process the information you give us as an account holder, such as your name, email address, billing details and how you use the Service.
For your clients data, we are the processor. When you enter information about the people you coach, you are the controller (or "business") and we process that information only on your instructions, as set out in the Data Processing Addendum. Requests from your clients about their information should be directed to you; if we receive one, we will refer the person to you unless the law requires otherwise.
3. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account and profile | Name, email address, hashed password, business or brand name, plan, credit balance, onboarding preferences. | You |
| Client records you enter | Client name and contact details, goals, fitness level, dietary preferences, injuries, health notes, progress logs, session notes, check-in responses. | You |
| Generated content | Manuals, guides, habit trackers and related materials produced for you, and the prompts used to produce them. | You and our AI subprocessor |
| Billing | Subscription status, plan, billing period, invoices, partial card details and payment identifiers held by our payment processor. | You and Stripe |
| Uploads | Cover images and other files you upload, and their metadata. | You |
| Usage | Pages viewed, features used, generations performed, credits consumed, timestamps. | Automatically |
| Device and log | IP address, browser and device type, operating system, referring page, and error diagnostics. | Automatically |
| Security | Authentication events, session identifiers, bot-protection challenge results, administrative audit records. | Automatically |
| Communications | Messages you send us, support requests and their contents. | You |
We do not collect precise geolocation, and we do not knowingly collect biometric identifiers or government identification numbers. Please do not enter them into free-text fields.
4. How and Why We Use Information
| Purpose | Categories used | Legal basis (where GDPR applies) |
|---|---|---|
| Provide the Service, generate content and store your work | Account, client records, generated content, uploads | Performance of a contract |
| Authenticate you and keep accounts secure | Account, security, device and log | Contract; legitimate interests in security |
| Process payments, manage subscriptions and credits | Account, billing, usage | Contract; legal obligation |
| Send transactional email such as receipts, credit and check-in notices | Account, billing, usage | Contract |
| Provide support and respond to enquiries | Account, communications | Contract; legitimate interests |
| Monitor, debug and improve reliability and performance | Usage, device and log, security | Legitimate interests |
| Prevent fraud, abuse and misuse, and enforce our terms | All categories | Legitimate interests; legal obligation |
| Comply with law and respond to lawful requests | All categories | Legal obligation |
| Send product or marketing email, where you have opted in | Account, usage | Consent (withdrawable at any time) |
We do not use automated decision-making that produces legal or similarly significant effects about you, and we do not engage in profiling for advertising purposes.
5. Artificial Intelligence Processing
When you generate a manual, guide or habit tracker, the prompt and the client attributes you have selected are transmitted to our AI subprocessor, currently the Google Gemini API, which returns generated text to us. The output is stored in your account.
We do not use the content you submit, or the output generated for you, to train publicly available foundation models. Our AI subprocessor processes the data under its own enterprise terms for the purpose of returning your result.
Because AI output is generated automatically and may be inaccurate, you remain responsible for reviewing it before use, as described in our Terms of Service and Disclaimer.
To limit exposure, enter only the client information that is genuinely needed for the material you are producing, and prefer initials or first names where full identity is not required.
9. Data Retention
We keep personal information only as long as needed for the purposes described above, then delete or anonymise it.
| Data | Retention |
|---|---|
| Account and profile | For the life of the account, then up to 90 days after closure. |
| Client records and generated content | Until you delete them, or up to 90 days after account closure. |
| Billing and tax records | Up to 7 years, as required by tax and accounting law. |
| Security, authentication and audit logs | Up to 24 months. |
| Error diagnostics | Up to 90 days. |
| Support correspondence | Up to 24 months after the matter is closed. |
| Backups | Rolling backups are overwritten within 35 days. |
We may retain information for longer where necessary to comply with a legal obligation, resolve a dispute or enforce our agreements.
10. How We Protect Information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold, including encryption in transit, encrypted storage at rest, salted password hashing, server-side session revocation, role-based access control, bot protection and rate limiting on sensitive endpoints, HTML sanitisation with a restrictive content security policy on public pages, and an append-only audit log of administrative actions. A fuller description is in Annex II of our Data Processing Addendum.
Share and check-in links are unguessable capability tokens that you can revoke. They are deliberately excluded from our error-monitoring telemetry so that a link is never captured in a diagnostic report.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the service at your own risk.
To report a security concern, please follow our Security and Responsible Disclosure policy.
11. Data Breach Notification
If we determine that a breach of security has compromised personal information, we will notify affected individuals and any regulator as required by applicable law, including the Florida Information Protection Act (Fla. Stat. § 501.171), which generally requires notice within 30 days of determination, and comparable laws in other states and countries.
Where we act as your processor, we will notify you without undue delay after becoming aware of a personal data breach affecting client information, so that you can meet your own notification duties.
12. International Transfers
We and our subprocessors are located in the United States, and information you provide will be processed there. Privacy laws in the United States may differ from those in your country.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we apply supplementary technical measures such as encryption in transit and at rest.
13. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights in relation to personal information we hold about you as a controller:
- Access a copy of the personal information we hold about you, and information about how we process it.
- Correct inaccurate or incomplete personal information.
- Delete personal information, subject to legal exceptions.
- Portability — receive a copy in a portable, machine-readable format.
- Opt out of sale, sharing for cross-context behavioural advertising, or profiling with legal effects. We do none of these.
- Withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Object to or restrict certain processing based on legitimate interests.
- Non-discrimination — we will not deny service, charge a different price, or provide a different quality of service because you exercised a privacy right.
How to exercise your rights
Email contact@coachmanuals.com from the address associated with your account, or write to us using the contact details in the final section. We will verify your identity by confirming control of the account email, and may ask for additional information where a request is sensitive or the identity is unclear.
We respond within 45 days, and may extend once by a further 45 days where reasonably necessary, telling you why. An authorised agent may submit a request on your behalf with written permission that we can verify.
Appeals. If we decline your request, you may appeal by replying to our decision with the word "Appeal" in the subject line. We will respond in writing within 45 days with our decision and the reasons for it. If your appeal is denied, you may contact the Florida Attorney General or the regulator in your state.
Florida residents. The Florida Digital Bill of Rights (Fla. Stat. § 501.701 et seq.) applies to businesses above statutory revenue thresholds that we do not currently meet. We nonetheless honour the access, correction, deletion, portability and opt-out requests described above for Florida residents as a matter of policy.
Other United States residents. Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws may exercise the rights those laws provide using the same contact route.
14. Additional Information for California Residents
Under the California Consumer Privacy Act as amended, we disclose the following about the preceding twelve months. The categories of personal information we collected are listed in Section 3, together with their sources. The business and commercial purposes for collection are listed in Section 4. The categories of third parties to whom we disclosed personal information for a business purpose are listed in Section 6.
We collected the following statutory categories: identifiers; customer records; commercial information; internet or other electronic network activity; and, where you choose to enter it about your clients, health-related information that may constitute sensitive personal information.
We use sensitive personal information only to provide the Service you requested, and not to infer characteristics about anyone. That use falls within the exceptions in the CCPA, so no right to limit its use applies; even so, you may ask us to delete it at any time.
We did not sell or share personal information, and we did not disclose sensitive personal information for any purpose other than those permitted.
California residents may also request the information described in California Civil Code § 1798.83 (the "Shine the Light" law). We do not disclose personal information to third parties for their own direct-marketing purposes.
15. Information for Users in Europe and the United Kingdom
Where the EU or UK GDPR applies to our processing as a controller, our legal bases are set out in the table in Section 4.
You have the rights described in Section 12, and you may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner Office. We would appreciate the chance to address your concern first.
We do not have an establishment in the EU or UK. Where an Article 27 representative is required for our processing, we will appoint one and publish the details here.
16. Health Information and HIPAA
Coach Manuals is not a covered entity or a business associate under the health insurance portability and accountability act, and the service must not be used to create, receive, maintain or transmit protected health information subject to HIPAA. We do not enter into business associate agreements.
Fitness and wellness details that a coach records — such as goals, injuries, dietary preferences and body measurements — may still be consumer health data under laws such as the Washington My Health My Data Act and similar state statutes. We collect that information only because a coach enters it, use it only to provide the Service, never sell it, and never use it for advertising.
If you are a coach, obtain your client consent before entering health-related details, and enter only what is necessary.
17. Children and Minors
The Service is intended for professional users aged 18 or over. We do not knowingly collect personal information directly from children.
A coach must not enter information about a client under 18 without the verifiable consent of a parent or legal guardian, and must comply with the Children Online Privacy Protection Act and any other law that applies to that information.
If you believe a child has provided personal information to us, contact contact@coachmanuals.com and we will delete it promptly.
18. Third-Party Links and Services
The Service may link to third-party websites and may display images sourced from third-party libraries. We do not control those sites and are not responsible for their privacy practices. Review their policies before providing personal information.
19. Changes to This Policy
We may update this Privacy Policy. When we do, we revise the "Last updated" date above. If a change is material, we will give notice by email or an in-product notice before it takes effect.
Continued use of the Service after an update takes effect constitutes acceptance of the revised policy, except where consent is required by law.
20. Contact Us
Questions, requests or complaints about privacy may be sent to contact@coachmanuals.com.
Coach Manuals is located in the State of Florida, United States. A postal address for formal notices is available on request.
