← Back to coacha.fit
Privacy

Privacy Policy

Last updated: June 19, 2026
The short version. Coacha collects the account details you provide, the fitness and health data you connect or enter, and the messages you send your AI coach. We send the necessary context to Anthropic's Claude to generate coaching — Anthropic does not train on that data and deletes it within 30 days. We treat your health data as sensitive: we don't sell it and we never use it for advertising. You can delete your account and all associated data from inside the app at any time.

1. Who we are

Coacha is operated by Coacha LLC, a California limited liability company ("Coacha", "we", "us", "our"). Coacha is an AI-powered running, cycling, and strength-training coaching app. This Privacy Policy explains what personal information we collect through the Coacha iOS app and the website at coacha.fit (together, the "Service"), how we use and share it, and the choices and rights you have.

The data controller is:

Coacha LLC
c/o Northwest Registered Agent, Inc.
2108 N St, Ste N, Sacramento, CA 95816, USA
Email: hello@coacha.fit

Coacha is intended for users in the United States. See International users for our position on users outside the U.S.

Health and fitness data is sensitive. Coacha is built around your workout and health data. We treat that data as sensitive personal information, we do not sell it, and we do not use it for advertising or marketing.

2. Information we collect

Information you provide

Health & fitness data you connect or enter

With your permission, we collect activity and health data, including:

This data may come from your manual entry or from a service you connect: Apple Health (HealthKit), Strava, Hevy, and (where offered) Garmin. See Connected services.

Information collected automatically

Subscription & billing

Paid subscriptions are offered through Apple's App Store and managed via RevenueCat. We receive your subscription status and entitlements. We do not receive or store your full payment card details — payment is handled by Apple.

Push notifications

If you enable notifications, we store a device push token to deliver them. You can disable notifications in your device settings.

3. How we use information & California "Notice at Collection"

We use personal information for the business and commercial purposes below. This table is also our CCPA/CPRA Notice at Collection: the categories collected, their sources, the purposes, and the categories of third parties to whom they are disclosed for a business purpose.

CategorySourcePurposeDisclosed to
Identifiers / account (name, email, time zone, account id, Apple/Google sign-in id)You; authentication providerCreate and secure your account; personalize coachingAuthentication provider; analytics (account id only); AI provider
Onboarding & coaching context (goals, injuries, preferences, body stats)YouPersonalize coaching and training plansAI provider
Health & fitness data (workouts, heart rate, power, cadence, distance, streams, segments, training load, routes) — sensitiveYou; Apple Health; Strava; Hevy; Garmin (where offered)Generate coaching, plans, reviews, and trends; show your training historyAI provider
Strength / workout logs (exercises, sets, weights, reps, RPE) — sensitiveYou; HevyCoaching and training historyAI provider
Coach conversations (text, voice, images) — may be sensitiveYouProvide the AI coaching chatAI provider; voice-transcription provider (audio, transiently)
Training plans & trendsGenerated by the coach; computedWeekly programming; trends; calendar export (if enabled)AI provider; calendar provider (only if you enable it)
Connected-service credentials (OAuth tokens; your BYO keys)OAuth flows; youSync data from / push plans to services you connectThe respective connected service
Subscription & billing statusRevenueCat via AppleGrant access to paid features; enforce limitsSubscription provider
Usage / product analytics (account id, platform, app version, event names)AutomaticallyUnderstand and improve the productAnalytics provider
Device, crash & technical data (app version, OS, identifiers, stack traces, numeric user id, latency)AutomaticallyOperate, debug, and secure the ServiceCrash / error-reporting provider; hosting provider
Feedback (free text, app version, platform)YouImprove the product; respond to youInternal (operational)

We also use personal information to comply with legal obligations; enforce our terms; detect, prevent, and respond to fraud, abuse, and security incidents; and, where you have given any required consent, to send you communications about the Service. We do not use your health or fitness data for advertising, marketing, or use-based data mining, and we do not sell it.

4. How we share information

We share personal information only as described here. We use service providers ("sub-processors") that process data on our behalf, under contract, for the limited purpose of operating the Service. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Sub-processorWhat they doData they process
Anthropic (Claude API)Powers the AI coachYour coaching context, activities / health metrics, workout logs, plans, and coach messages (text, image, and transcribed voice)
Fly.ioCloud hosting / compute for our backendAll data, processed by our application servers in the U.S.
Fly Managed PostgresPrimary production databaseAll stored account, health / fitness, coaching, and operational data
ClerkAuthentication and account managementName, email, account identifiers, sign-in metadata
RevenueCatSubscription managementSubscription status, account identifier (no card data)
PostHogProduct analyticsAccount identifier, event names, platform / app version, non-health event properties
SentryCrash and error reportingDiagnostic / error data and your numeric user id (configured to exclude message content, request bodies, and credentials)
GroqVoice-to-text transcriptionAudio you record for the coach, processed transiently and not retained by us as audio
Apple (HealthKit / App Store)Source of Apple Health data; App Store paymentsHealth / fitness data you authorize; subscription payment
StravaSource of activities you sync (optional)Activities, streams, and the tokens needed to sync
HevySource of strength data you sync (optional)Strength workouts / sets
GoogleCalendar export (optional); Google Sign-In (optional)Calendar events (plans you push); sign-in identifier / email
Garmin (where offered)Source of Garmin device activities (optional)Activities, laps, power, heart rate, and per-second data you authorize — see Garmin
ExpoMobile delivery / push-notification transportPush device token

We may also disclose information: (a) for legal & safety reasons, if required by law or legal process, or to protect the rights, property, or safety of Coacha, our users, or the public; (b) in a business transfer (merger, acquisition, or sale of assets), subject to this Policy; and (c) with your direction, when you connect a third-party service or push your plan to your calendar.

5. AI coaching (automated processing)

Your coach is AI, not a human. Coacha's coaching, plans, reviews, and in-chat responses are generated by a large language model (Anthropic's Claude). When you interact with the coach, your relevant data — your profile and goals, activities and health metrics, workout logs, plans, and your messages (including transcribed voice and any images) — is transmitted to Anthropic to generate a response.

Not medical advice. Coacha provides general fitness and training guidance. It is not medical advice, diagnosis, or treatment, and its coaching is AI-generated and may be wrong or incomplete. Always talk to a qualified health professional before acting on any injury, pain, or medical concern. If you are experiencing a medical emergency, call your local emergency number.

6. Health & fitness data

We take special care with health and fitness data, which we treat as sensitive personal information.

Apple HealthKit. Coacha reads workout and health data from Apple Health only with your permission, on a read-only basis (we never write to Apple Health). Consistent with Apple's requirements, we do not use HealthKit data for advertising or other use-based data mining, we do not sell it, we do not share it with third parties except as needed to provide the Service to you, and we do not store HealthKit data in iCloud. You can revoke Coacha's access at any time in iOS Settings → Privacy & Security → Health.

7. Connected services & integrations

Coacha can connect to third-party services with your authorization. Each integration is optional and can be disconnected at any time in the app. When you connect a service, you authorize Coacha to access the data described, and that service's own privacy policy governs its handling of your data on its side.

Apple Health (HealthKit)

See above. Read-only; revoke via iOS Settings.

Strava

With your authorization, we sync your Strava activities and associated data and store the access credentials needed to keep them in sync. Disconnecting Strava in Coacha revokes our access. Strava's privacy policy: strava.com/legal/privacy.

Hevy

With your authorization (via a Hevy API key you provide), we sync your strength-training data. Hevy's privacy policy: hevyapp.com/privacy.

Garmin

(Applies if and when you connect a Garmin account.) If you connect Garmin Connect, you expressly consent to Coacha accessing and transferring your Garmin device data (such as activities, laps, power, heart rate, and per-second metrics) to provide your coaching, including processing that data with our AI provider to generate coaching. Insights derived in part from Garmin device-sourced data are identified as such, and Garmin data is labeled as originating from your Garmin device.

Google (Calendar & Sign-In)

If you enable calendar export, we use Google Calendar to write your training plan as calendar events; we do not read your other calendar data. If you use Google Sign-In, we receive your sign-in identifier and email. Google's privacy policy: policies.google.com/privacy. Coacha's use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your privacy rights

You can exercise the following rights regardless of where you live. We will not discriminate against you for exercising them.

How to exercise your rights

California residents (CCPA / CPRA)

The categories of personal information we collect, their sources, the purposes, and the categories of third parties to whom we disclose them are described in sections 2–4 above. In the preceding 12 months we have not sold or shared personal information for cross-context behavioral advertising, and we have not sold or shared consumers' personal information. We collect and use sensitive personal information (health / fitness data and coach conversations) only to provide the Service.

Washington residents (My Health My Data Act)

If you are a Washington resident, the health and fitness data you provide may be "consumer health data" under the Washington My Health My Data Act. We maintain a separate Consumer Health Data Privacy Policy describing how we collect, use, share, and let you control that data, including your right to withdraw consent and to have consumer health data deleted. Residents of other states with similar consumer-health-data or comprehensive privacy laws (e.g. Nevada, Connecticut) have comparable rights.

9. Analytics & crash reporting

10. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter as required for legitimate business or legal purposes.

11. Security

We use technical and organizational measures to protect personal information, including encryption in transit (HTTPS / TLS) and encryption at rest, access controls, credential rotation, and provider-managed infrastructure. Connected-service credentials and your bring-your-own API keys are stored encrypted. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and the authorities as required by law.

12. International users

Coacha is intended for and directed to users in the United States. We do not target users in the European Economic Area, the United Kingdom, or Switzerland, and we do not monitor the behavior of individuals in those regions. If you access the Service from outside the United States, your information will be processed in the United States.

13. Children's privacy

The Service is not directed to children. You must be at least 16 years old to use Coacha. We do not knowingly collect personal information from anyone under that age. If you believe a child has provided us personal information, contact hello@coacha.fit and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes (for example, a new third-party data flow), provide additional notice in-app or by email before the change takes effect. We review this Policy at least every 12 months.

15. Contact us

Questions, requests, or complaints about this Policy or your data:

Coacha LLC
Email: hello@coacha.fit
Mail: Coacha LLC, c/o Northwest Registered Agent, Inc., 2108 N St, Ste N, Sacramento, CA 95816, USA

If you are a California resident with an unresolved privacy concern we have not addressed, you may contact the California Attorney General's office. If you are a Washington resident, you may contact the Washington Attorney General's office.