Legal
Last updated: July 2026
Section 5 (agent access) is a material change: it is published here for review and takes effect 14 days after we email account holders, as section 9 requires.
Coach Anvil is operated from the European Union. We are the data controller for personal data processed through the service. Our servers are hosted in Frankfurt, Germany (EU) via Supabase.
We process your data on the following legal bases:
We share data with the following sub-processors solely to operate the service:
You can connect an AI agent — an agent running in your browser on an open Coach Anvil page, or an external agent such as ChatGPT — to your account. This is off unless you turn it on. Turning it on requires a separate, explicit consent in Coach Anvil in which you choose the access to grant, confirm you are 18 or older, and agree to share the selected fitness data. That consent is the legal basis, and you can withdraw it at any time by unlinking.
What reaches an agent. Only the structured fitness fields the connected tools are defined to return: plan, day, session, exercise, inventory and job identifiers; exercise and equipment names from our own catalogue; sets, repetitions, durations, distances, loads with their unit, rest, RPE and RIR; adherence counts, personal records and progression points; your equipment entries, your training preferences and schedule constraints; and your timezone. Plans and equipment inventories are labelled by number, not by any name you wrote.
What never reaches an agent. Genetic data, lab results, medical intake, injury and pain reports, body composition and other measurements, connected health and wearable data, coaching chat and voice transcripts, plan rationales, your free-text notes, your email address and your billing details. There is no agent tool for any of them; a request for one returns a link to Coach Anvil.
Grant duration. A connection lasts 90 days, after which the client must ask again. Within that period an agent's access credential is short-lived (minutes) and its renewal credential lasts at most 30 days.
Operation records we keep. Every agent-initiated change is recorded as an operation so that a repeated request replays its original result instead of acting twice. A change awaiting your confirmation expires within minutes if you do not confirm it. A completed operation keeps its result for 30 days so a reconnecting agent can recover it; after that the arguments, summary and result are erased and only a tombstone remains. Argument and summary data are erased as soon as the operation completes. We also log which capability ran, on which connection and with what outcome code — never the contents.
Unlinking. Unlinking a connection, or disabling browser access, stops all further access immediately, invalidates credentials already issued to that client, and cancels anything still waiting for your confirmation.
What we cannot undo. Data an agent already received is held by whoever operates that agent, under their own privacy policy and retention rules, as an independent recipient. Unlinking does not delete copies that were already shared with them, and we have no ability to reach into an external service and remove one. To have such a copy deleted, contact that agent's operator. Read the terms of any agent you connect before you connect it.
We retain your Coach data for as long as your account is active. A successful self-service account deletion immediately cancels an owner's active subscription and removes the account, personal uploads, and Coach-held personal data. Stripe may retain payment and transaction records where tax, accounting, or fraud-prevention law requires it (typically up to 7 years).
You have the right to access, rectify, erase, restrict processing of, or port your personal data. Signed-in users can download a portable JSON copy of their data or permanently delete their account from Settings. Account deletion requires a fresh Google authentication and explicit confirmation; owners of a shared tenant must transfer ownership or remove other members first. You also have the right to lodge a complaint with your local data protection authority. For rights that cannot be completed in-product, email privacy@coach.app. We will respond within 30 days.
All data is encrypted at rest and in transit. Database rows are access-controlled with row-level security (Supabase RLS). Health and genetic data require authenticated access and cannot be accessed across accounts.
We will notify you by email at least 14 days before material changes take effect.
For privacy questions, email privacy@coach.app.