DRAFT — this document has not been reviewed by legal counsel and is not yet in effect.

Cornerman

Privacy Policy

Last updated: [DATE]

Who we are

Cornerman is operated by [COMPANY NAME], [COMPANY ADDRESS]. We provide software that fitness coaches and studios use to record and review their clients' training and recovery. This policy explains what we collect, why, and who can see it. It applies to both coaches and the clients they work with.

For data you enter as a client, [COMPANY NAME] acts as the data controller for your account, and your coach or studio is separately responsible for how they use what they can see. Questions about either can go to [PRIVACY EMAIL].

What we collect

Account information. Your email address, a display name, your password (stored only as a salted hash), your unit preference, and the workspace or coach you are connected to.

Training and recovery data. The sessions logged in your account — strength work, conditioning, cold exposure, sauna and heat, hyperbaric sessions, sleep records, mobility, and the other session types the app supports — including their date, duration, intensity or exertion rating, and any typed values recorded for that kind of session.

Health and wellness data. If you choose to connect Apple Health or Health Connect, we read the specific data types listed below. This connection is optional, requires your permission on the device, and can be revoked at any time in your device settings.

  • Heart rate variability (HRV)
  • Resting heart rate
  • Sleep duration
  • Respiratory rate
  • Blood oxygen saturation
  • Body weight and body composition
  • Steps
  • Active energy
  • Nutrition totals

Body measurements and photos. Measurements such as body mass, girths and skinfolds, and any progress photos you or your coach choose to upload. Photos are never required.

Messages. Messages exchanged between you and your coach inside the app.

Technical data. IP address, browser and device type, timestamps, and error diagnostics, used to keep the service running and secure.

What we do NOT do with your health data

Our commitments

  • We do not use your health data for advertising or marketing of any kind.
  • We do not sell your data to anyone, and we never will.
  • We do not use your health data to train machine learning or AI models without your separate, explicit consent.
  • We do not share your health data with any third party other than the named service providers listed under “Who can see your data” below, who process it only on our instructions.
  • We do not disclose health data to data brokers, insurers or employers.

These commitments reflect Apple's HealthKit requirements for apps that read health data, and they apply equally to data read from Health Connect on Android and to health data you enter by hand.

Why we collect it

We collect this data to run the service you asked for: to show your training and recovery history, to summarise load and readiness, to let your coach review your logs and message you, to keep your account secure, and to fix problems when something breaks. We also use aggregated, non-identifying usage counts to understand which parts of the product are used.

Where the law requires a legal basis, we rely on performance of our contract with you for running the service, your consent for optional health data connections and progress photos, and our legitimate interest in security and abuse prevention.

Who can see your data

Your coach and the staff of their workspace. They can see the training and recovery data in your account, your measurements, and your messages with them. That is the purpose of the product.

Other clients. Never. Clients cannot see each other's data.

Our staff. Only where necessary to operate the service, investigate a fault you reported, or comply with a legal obligation.

Named service providers. We use a small number of processors:

  • [HOSTING PROVIDER] — application hosting and content delivery
  • Supabase — database and authentication
  • Resend — transactional email, such as invitations and account notices

Each is bound by contract to process data only on our instructions. We will disclose data if legally compelled, and will tell you unless prohibited from doing so.

Your rights

You can access and correct your data at any time in the app, and you can ask us for anything not visible there at [PRIVACY EMAIL].

Export. A full machine-readable export of your data is available in Settings, on every plan, at no charge, at any time. It is not a paid feature and it is never withheld — including from an account that has been moved to read-only.

Deletion. You can request deletion of your account from Settings. Deletion starts a 30-day grace period, which you can cancel at any point during those 30 days by signing in and choosing to keep your account. If you would rather not wait, an immediate deletion option is available in the same place. Once immediate deletion runs, or once the grace period ends, your data is erased and cannot be recovered.

Depending on where you live, you may also have the right to restrict or object to certain processing, to data portability, and to complain to your local data protection authority.

What happens when your coach leaves

Your account is never deleted because a business stopped paying, closed, or moved to another product. If a coach or studio's account ends, the client accounts connected to it move to permanent read-only: the history stays intact and you can keep signing in to read and export it.

A business cannot delete your data. Only you can delete your own account and data, using the deletion flow described above.

Retention

We keep your data for as long as your account exists. Read-only accounts are retained indefinitely so that the history remains available to you. When you delete your account, personal and health data is erased; backups containing it are cycled out within [BACKUP RETENTION PERIOD]. We may keep a minimal record of the deletion itself, and any data we are legally required to retain, such as billing records.

Security

Data is encrypted in transit with TLS and encrypted at rest by our hosting and database providers. Access between accounts is enforced at the database level, so one workspace's data is not reachable from another. Internal access is limited to staff who need it. No system is perfect; if a breach affects your data we will notify you and the relevant authority as required by law.

Children

The service is not intended for children under 16. We do not knowingly collect data from them. Where a coach works with a minor, the account must be created and managed by a parent or legal guardian who accepts the Terms of Service on the minor's behalf. If you believe a child has an account without that consent, contact [PRIVACY EMAIL] and we will remove it.

Changes

If we change this policy in a way that materially affects how we handle your data, we will notify you in the app or by email before it takes effect. The date at the top shows when it was last updated.

Contact

[COMPANY NAME], [COMPANY ADDRESS]. Privacy enquiries: [PRIVACY EMAIL]. Data protection contact: [DPO NAME OR CONTACT].