Security & Data
Coaching happens in the most private room there is. Real client words, real breakthroughs, real vulnerability. Before you paste a single session into CoachAlly, you deserve to know exactly what happens to it, including the parts most tools would rather you didn’t ask about. Here it is, in plain language, no legal fog.
A note from the person behind this
CoachAlly is founder-run. My name is on it, not a boardroom of shareholders. That matters for one simple reason: a company owned by investors has a duty to make them money, and the easiest way software companies do that is by mining the data they hold. My business is the opposite. I make money only when this tool is good enough that you choose to keep paying for it. Your clients’ words are worth nothing to me as data and everything to me as the thing that makes your work sing.
So this is a personal commitment, with a real person accountable for keeping it, not a policy that quietly changes the day a bigger company buys the mailing list. And it is not just my word: the commitments on this page bind whoever runs CoachAlly after me, and this is written into our Terms, not only promised here. If the company is ever sold, wound down, or passes to someone else, these promises travel with your data, or your data is returned to you and deleted. Your clients’ sessions are never an asset to be sold. If any of this ever stops being true, you will hear it from me first.
— Daniel, founder
You have probably already crossed this bridge
If you have a transcript to paste, your session has already been recorded and already been turned into text by a tool like Zoom, Fathom, Fireflies, Otter, or Read.ai. Your client already agreed to be recorded. Those words already exist as data, sitting on someone’s servers.
We say this because the honest question is not “should this private conversation become data at all.” That already happened, the moment you hit record. The real question is a smaller one: who holds it now, and what do they do with it. Some of the consumer transcription tools reserve the right to use your recordings to improve their own services. We do the opposite, and the rest of this page is how.
More private than pasting it into a chatbot
Many coaches already paste client notes straight into ChatGPT or Claude to get help. It is worth knowing what that actually does. In the consumer versions of those apps, your conversations can be used to train the company’s models by default. Your client’s words become part of a system that answers other people.
CoachAlly does not work that way. We run on the business tiers of our AI providers, where the provider is contractually barred from using anything we send to train or improve their models. The AI reads your session to do the work, produces your report or your client intelligence, and then it is done with it. The provider may hold the request briefly to guard against abuse of their systems, under contract, and never uses it for training. Think of it as the AI working with the session and then handing it straight back, while we hold the result for you, encrypted. That is the part a raw chatbot cannot promise you.
Analysis is not training
There is an important difference worth naming, because it is where most of the worry lives.
Training means feeding data into an AI model so it becomes part of that model and can resurface for other people. We will never do this with your sessions. Full stop.
Analysis means an AI reads a session and hands back an insight, a report, or a pattern under the contractual controls above, while the model itself is unchanged. That is the entire product. It is closer to a calculator running over your numbers than to teaching a machine your clients.
Separately, and only if you choose to switch it on, we would love to learn from de-identified, aggregated patterns across many coaches, the kind of insight no solo coach could ever assemble alone, and hand it back to you to make you better. Aggregated means counts and patterns, never anyone’s actual words. It is off by default. It is designed so that it cannot identify you or your clients, it is never shared with another coach, and it is never used to train a model. It is your choice, not a condition of using CoachAlly.
Who can see your client's name, honestly
This is the question that matters most for a sensitive client, so we will answer it straight rather than talk around it.
Your client’s real name is held in an encrypted Vault, secured with a key you hold, not the platform. In plain terms: our own systems cannot join a name back to a record without your key, so a member of staff with full system access, or a party executing a lawful court order, cannot recover a client’s real name from us without you. We have never voluntarily sold or shared client data and never would. If we were ever served with a lawful legal demand, we would resist it to the fullest extent the law allows and tell you about it wherever we are permitted to. We would rather you know the true shape of it than believe a softer version.
That protection comes from three layers, and we publish the real status of each one on our Nameless Architecture page rather than describe an ideal:
- 1Scrubbed at the door (live). Other people named in a session, a partner, a boss, a co-founder, are replaced with neutral placeholders before the transcript is written to storage. If the system cannot guarantee a clean result for a transcript, it refuses to store that transcript at all.
- 2Blind in the middle (live). Stable internal client tokens carry the AI and database paths. A client’s real name is not the thing flowing through the pipes in the middle of the system.
- 3Locked at the core (live). The encrypted name Vault protects client names under a key you hold, not the platform. CoachAlly cannot recover a client’s real name from the Vault without your own key.
On top of those three layers, the strongest protection available to you is nickname mode, below, because it keeps a real name off our servers entirely rather than relying on encryption alone.
Nickname mode: the strongest protection available today
You can store any client under a nickname instead of their real name, per client, at any time. In that mode the real name never reaches our servers at all: the swap happens in your browser before anything is sent, and only the nickname is stored. For a genuinely high-stakes client, this is the setting we recommend today, because it is the one place where a name simply is not on our systems to be reached.
Two honest caveats so you can rely on it properly. First, the swap matches the name you enter, so if a transcript spells it differently or uses a nickname you did not list, that variant can slip through; it is a strong safeguard, not a magic filter. Second, nickname mode hides the name, not the fact that a client exists: see “What we keep even when the name is protected” below.
Real names are not the reckless choice and nicknames the safe one. Both are legitimate. Real names simply let CoachAlly thread a client’s story across every session and give you the fullest picture. A nickname trades a little of that continuity for the certainty that the name is never on our servers. Choose per client, and change your mind whenever you like.
Whichever mode you choose, CoachAlly automatically de-identifies anyone else named in a session, such as a partner, a boss, or another client, before the transcript is processed. This runs on every import and re-checks for any third-party name that survives the first pass. It is an automated safeguard, not a guarantee that every reference is removed, and if it cannot get a clean result it refuses the transcript rather than store a messy one.
What we keep even when the name is protected
Even in nickname mode, or with the Vault protecting a real name, some information is still ours to hold so the product can work: which client record a session belongs to, when sessions happened and how often, the coded placeholders and insights we derive from the conversation, and basic technical data like your IP address and approximate location for security and login. None of this includes your client’s real name in nickname mode, but a determined person with outside context could sometimes infer identity from pattern alone. We keep this category as small as the product allows and do not sell it. Contracted processors and lawful disclosure remain the boundaries described on this page.
The Vault, and how key custody works
The third layer, “Locked at the core,” is live. Client names are held in an encrypted Vault under a recovery key you hold, not the platform, so CoachAlly cannot recover a client’s real name from the Vault without you.
How custody works in practice:
- •You prove locally that you can retrieve your recovery key from the place you chose to keep it. CoachAlly records only the successful custody check, never the key or anything derived from it.
- •Every client name lives inside an encrypted envelope, and your browser restores it to plaintext on your own screen when you need it.
- •Provable deletion, tamper-evident logs, and publishing the code of the one component that ever sees a name are the receipts we are still building, so you can read the proof instead of believing us.
The production custody check belongs to you, the account holder, in your own browser. Support and CoachAlly staff should never ask for, receive, or store your private recovery key.
What happens to a session transcript
- 1The transcript is stored encrypted in our database under your coach account.
- 2It is sent to our AI provider for analysis as a single, isolated request.
- 3The provider returns the result and does not use it for training; any brief operational retention is under contract and never feeds their models.
- 4CoachAlly stores the resulting intelligence, signals, and reports under your account.
- 5No other coach can reach your data. Each coach’s data is separated by an account identity that is checked on every single request.
Client voice-note check-ins
If you enable voice-note check-ins, here is the path a client’s voice note takes. The client records it in a messaging app (Telegram) and sends it. Our system receives the audio, transcribes it to text using a speech-to-text provider that is contractually barred from training on it, keeps only the text, and discards the audio; we do not store the recording. The audio does pass through the messaging app’s servers and the transcription provider on its way, which is why both are named in our sub-processor list below. We are telling you the full path rather than implying the audio never leaves the client’s phone.
Your data belongs to you
Every transcript you upload, every report CoachAlly generates, every piece of client intelligence, it is yours. It always has been and always will be, including if you cancel your subscription. Under data protection law you are the controller of your clients’ data and CoachAlly, operated by Phoenix Rising International LLC, is your processor, acting only on your instructions.
We never share your data with another coach, never sell it, and never use your session content to train or fine-tune an AI model, ourselves or through any provider.
Client agreement, deletion, and how long we keep things
Before recording or uploading a session, tell the client how their session may be recorded, transcribed, and analysed, then make sure you have the right legal basis to use it. CoachAlly gives you two ways to record a client’s agreement to session recording and analysis. That record can support a consent-based approach, but does not choose or document your lawful basis for you.
- •Send the client agreement link. A single-use link your client clicks to record their agreement to session recording and analysis. The timestamp and method are stored on their record.
- •Record existing permission. If the client agreed verbally or in writing outside the platform, you can record that directly. You remain responsible for holding the underlying record and documenting your legal basis.
Clients can request deletion at any time through a separate deletion link. When they do, CoachAlly deletes the client record and the sessions, transcripts, intelligence, and reports directly tied to it from live systems, then purges that data from encrypted backups within 30 days. Three residuals sit outside that cascade: a mention inside another client’s stored prose, a name already captured in another client’s group roster snapshot, and a message already delivered through email or Telegram. We also retain what the law requires us to keep (for example, minimal billing records), plus aggregate counts that no longer identify anyone. If you cancel your account, data tied to your account follows the same deletion process and the same disclosed limits. We do not keep your content as leverage to win you back.
The other companies that help run CoachAlly (sub-processors)
These are the third-party services CoachAlly relies on to deliver the platform. This is the authoritative and complete list. All are bound by data processing agreements, and none uses your data or your clients’ data to train AI models. We will give advance notice before adding a new sub-processor that would process your content, and you may object.
| Provider | What it does | Location |
|---|---|---|
| Anthropic | AI analysis of session transcripts and check-in summaries | United States |
| OpenAI | Speech-to-text transcription of voice-note check-ins | United States |
| Convex | Database and encrypted file storage | United States |
| Clerk | Login and identity management | United States |
| Vercel | Hosting and delivery of the app | United States |
| Stripe | Payment processing | United States |
| Resend | Transactional email (receipts, links, reports) | United States |
| PostHog | Product analytics, so we can see how the app is used | United States |
| Sentry | Error monitoring, so we can catch and fix crashes | United States |
| Telegram | Delivery channel for client voice-note check-ins, where enabled (audio is transient and discarded after transcription) | Multiple regions |
If something ever goes wrong (breach notification)
No system is perfectly secure, and we will not pretend otherwise. What we commit to is this: if we ever become aware of a security breach affecting your data, we will notify you without undue delay and within 72 hours of becoming aware, tell you what we know, what we are doing, and what you may need to do for your clients. As the data controller, you decide what your clients are told; our job is to get you the facts fast.
Your rights and a signable agreement
CoachAlly complies with GDPR (EU) and UK GDPR.
- •You are the data controller for your clients’ personal data. CoachAlly (Phoenix Rising International LLC) is your data processor, acting only on your instructions.
- •A signable Data Processing Agreement is available, naming Phoenix Rising International LLC as processor and incorporating this sub-processor list. Request it at support@coachally.co, or if you have a corporate sponsor’s own DPA we are happy to review it.
- •International transfers to US-based sub-processors are covered by Standard Contractual Clauses (EU) and the UK International Data Transfer Addendum.
- •Your clients’ rights (access, rectification, erasure, portability, restriction, objection) can be exercised through the client portal deletion link or by contacting support@coachally.co.
For the technically minded
The plain-language promises above rest on concrete controls. If you or your client’s IT team want the detail, here it is; if not, you can skip it without missing anything.
Show the technical detail
- •Data separation. Every database read and write verifies that the requesting coach owns the record. This is enforced in code on each request; cross-coach access is designed and enforced against, not merely discouraged.
- •Client portal links. Each client’s private link carries a cryptographically signed token scoped to that one client, so it cannot be guessed or altered to reach anyone else.
- •Internal functions. System-level functions are not reachable from the public interface; they run only via the internal scheduler.
- •Payment and integration endpoints verify a cryptographic signature before processing any incoming message.
- •Encryption. Data is encrypted in transit with TLS (HTTPS), enforced by HTTP Strict Transport Security, and encrypted at rest.
- •Authentication is handled by Clerk; we support email/password and Google sign-in and do not store passwords ourselves.
- •Hardening. The platform enforces strict transport security, clickjacking protection, content-type sniffing prevention, and a strict referrer policy.
Responsible disclosure
If you discover a security vulnerability, please report it to support@coachally.co. We will acknowledge within 48 hours and aim to resolve confirmed issues promptly. We ask that you give us reasonable time to investigate before disclosing publicly.
Questions
If you have any questions about how CoachAlly handles data, or would like a copy of our Data Processing Agreement, contact us at support@coachally.co. Every hard question makes this page better.