Privacy Policy
Brave Systems Pty. Ltd., trading as Yates Total Health and operating the Coached platform ("we", "our", "us"). This Privacy Policy explains how we collect, use, store, and protect your Personal Information when you use the Coached web application and mobile applications (collectively, the "Service"). By using the Service, you agree to this policy.
If you have questions about this policy or want to exercise any of the rights described below, contact us at the address in Section 12.
1. Who we are
Coached is a coaching platform connecting personal trainers and health coaches ("Coaches") with their clients ("Clients"). The Service is operated by Brave Systems Pty. Ltd. (trading as Yates Total Health) (ABN 80 164 223 116), based in Queensland, Australia.
Coaches subscribe to Coached and use it to deliver coaching services to their own Clients. Clients access Coached through invitation by their Coach. Throughout this policy, "you" means whichever of these you are.
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. Information we collect
We collect information when you create an account and use the Service. Different categories of information are collected from Coaches and Clients depending on which features you use.
2.1 From all Users
- Account information — full name, email address, password (stored hashed via Supabase Auth, never accessible to us in plain form), and an optional profile photo you upload.
- Identifiers — a Supabase user ID assigned automatically.
- Direct messages — communications between Coaches and their assigned Clients sent through the in-platform messaging feature.
- Shared media — videos you share in chat, including form-check videos, stored in a private storage bucket accessible only to you and your assigned Coach.
- Push notification tokens — if you grant permission, your device push token is held by OneSignal so we can deliver notifications.
- Technical information — IP address, browser type, device type, and timestamps of your interactions with the Service, collected automatically by our hosting provider as part of standard server logs and used for security and diagnostic purposes only.
2.2 From Clients (additional)
When you, as a Client, complete the one-time health intake on first use of the companion app, you provide:
- Personal details — date of birth, phone number, home address, sex, and an emergency contact (name and phone).
- Health information — current medications, previous surgeries, answers to a health screening questionnaire (including yes/no flags for a range of medical conditions and risk factors, with free-text detail where you opt to provide it), exercise contraindications, and movements you wish to avoid.
- Food allergy and intolerance information — to enable allergen warnings in the food logging feature.
- Training history and goals — years training, current frequency, primary goal, sport background, previous programs.
- Nutrition history — current diet approach, meal frequency, supplements, previous nutrition coaching.
- Health goals and priorities — multi-select preferences relevant to your sex.
- Measurement tools you have access to — smart scales, calipers, tape measure.
- Consent signature — your typed full name and the timestamp at which you accepted the consent declaration.
Throughout your use of the Service, you may also provide:
- Training data — the programs your Coach assigns to you, your one-rep maxes and strength anchors, per-set training records (weight, reps, RPE), session history, and any exercise swaps or modifications.
- Body composition data — bodyweight, body fat percentage (including values derived from skinfolds), girth measurements, skinfold measurements (up to a 12-site protocol), clothing size where you record it, and progress photos (front, side, and back views) if you choose to upload them.
- Wellbeing check-ins — your self-reported sleep quality, energy, stress, and soreness scores, plus any free-text notes and any custom metrics your Coach configures.
- Daily activity — self-reported steps and water intake.
- Nutrition data — your food logs (items, quantities, times), nutrition plan targets your Coach sets, and any custom foods you create.
- Wearable and device health data — if you connect a wearable or grant access to your device's health platform, we read and store the metrics you authorise. Sources can include Apple Health on iOS, Google Health Connect on Android (where available), and WHOOP (connected via the Open Wearables bridge). Depending on your device and what you allow, this may include heart rate variability (HRV), resting heart rate, sleep duration and sleep stages, sleep efficiency, blood oxygen (SpO2), respiratory rate, skin temperature, step count, and workout data (training strain, energy expenditure, and distance). We also compute a recovery score from these inputs. You can revoke this access at any time in your device's health settings (for example, on iOS: Settings → Health → Data Access & Devices) or by disconnecting the wearable.
2.3 From Coaches (additional)
- Notes you record about your Clients' programs, exercises, and check-ins.
- Acknowledgements of programmatic suggestions (e.g. calorie adjustment proposals).
- Internal notifications about your Clients' activity (e.g. new check-ins, invitation tokens for pending Client invitations).
2.4 What we do not collect
We do not collect this information passively or without your direct input, with the exception of the technical server-log information described in Section 2.1. We do not use advertising trackers or third-party analytics SDKs. We do not buy or sell Personal Information.
3. How we use your information
We use the information we collect solely to operate, deliver, and improve the Service.
3.1 To deliver the coaching service
- To provide your Coach with visibility of your training, nutrition, body composition, wellbeing, and (where you grant permission) wearable and device health data so they can deliver coaching to you.
- To display your own data back to you in your app.
- To enable Coach-to-Client messaging within the Service.
3.2 To send communications
- Transactional emails — account creation, welcome to the Service, password reset, and Client invitation links — delivered via Resend.
- Push notifications — check-in reminders, calorie-target updates from your Coach, and other service-related notifications — delivered via OneSignal. You can withdraw consent for push notifications at any time in your device's notification settings.
- Billing communications — if you are a Coach, Stripe sends payment-related emails (such as receipts and card-expiry notices) in connection with your subscription.
We do not send marketing emails. All communications relate directly to your use of the Service.
3.3 To power AI-assisted features
The Service uses Anthropic's Claude API for several features. The following information is sent to Anthropic when these features are used:
- Food barcode reading — the image of a barcode you photograph using the in-app scanner.
- Food identification from photo — the image of a food item you photograph for nutritional analysis.
- Nutrition estimation for unknown foods — the name and serving size of a food you ask the AI to estimate, when the food is not found in our existing food database or Open Food Facts.
- Recovery recommendations — your age, sex, listed health context tags, your estimated weekly training tonnage, and your position in your current training block (week N of M). Your name, email, or any other directly identifying information is not included in this request.
Anthropic does not retain the content of API requests for training under their commercial terms of service. AI-generated outputs are estimates and suggestions intended only as coaching context; they are not authoritative and should not be relied on for nutritional, training, or medical decisions.
3.4 To diagnose and improve the Service
- To diagnose technical issues from the hosting provider's server logs.
- To understand patterns of feature usage in aggregate so we can improve the Service. We do not produce User-level analytics from this data.
3.5 To comply with legal obligations
- To respond to lawful requests from authorities or court orders.
- To enforce our Terms of Service.
- To protect against fraud, abuse, or threats to safety.
3.6 Automated adjustments and decision-making
One feature changes your plan automatically: calorie and macronutrient target auto-adjustment. In response to your logged progress, it may adjust your targets by up to about 5% per step, always protecting a minimum protein floor. Every adjustment is recorded in an audit log and can be reviewed and reversed by your Coach within 48 hours. This is the only feature that adjusts your plan automatically.
All other computed outputs are advisory and require a person to act on them: your recovery score is shown for context; a recovery deload is suggested and applied only when you or your Coach taps to apply it; AI nutrition estimates are reviewed by a person before being saved.
You can ask your Coach to disable automatic adjustments, and you can ask for human review of any automated adjustment — your supervising Coach is the human reviewer.
4. Data storage and security
Your data is stored in Supabase, a cloud database platform. Supabase enforces row-level security so that each User can only access their own data (Clients can only see their own records; Coaches can only see records for Clients assigned to them).
Progress photos, profile photos, and chat/form-check videos are stored in private Supabase Storage buckets. Access is enforced by row-level security and served via short-lived signed URLs: each object is retrievable only by the User who uploaded it and that User's assigned Coach. There is no public or anonymous access to these buckets.
We use industry-standard encryption in transit (HTTPS/TLS) and at rest. Passwords are stored hashed by Supabase Auth and are never visible to us in plain form.
Supabase infrastructure is hosted on AWS. Your data is stored on AWS infrastructure in Sydney, Australia (the ap-southeast-2 region).
5. Who we share your data with — and where it's processed
We do not sell or rent your Personal Information. We share data only with the sub-processors listed below, strictly to operate the Service:
- Supabase, Inc. — database, authentication, and file storage. Privacy policy.
- Vercel Inc. — web hosting and serverless functions. Privacy policy.
- Resend, Inc. — transactional email delivery. Privacy policy.
- Anthropic, PBC — AI features (see Section 3.3). Privacy policy.
- OneSignal, Inc. — push notification delivery. Privacy policy.
- Google LLC — web font delivery (Google Fonts). Loading a web font discloses your IP address to Google; no Coached data is transmitted to Google. Privacy policy.
- Stripe — Coach subscription billing. Card details are entered into and held by Stripe; we never receive or store your card number. Privacy policy.
- Open Wearables (The Momentum) and WHOOP — optional wearable data integration; only active if you connect a wearable. WHOOP privacy policy.
- Svix — verifies the cryptographic signatures of incoming webhooks (payments and wearables). Handles message-authentication metadata only; no Personal Information. Privacy policy.
We also embed exercise demonstration videos from Vimeo and YouTube within the Service. When you view an embedded video, your browser interacts directly with these services and they may set their own cookies and receive your IP address. See our Cookie Policy for more.
We send food barcode digits to Open Food Facts (a public open-source food database) to look up product information. This request contains the barcode only and no User identifier.
Your assigned Coach has access to the training, nutrition, body composition, wellbeing, and (where granted) wearable and device health data that you generate through the Service, as part of the coaching relationship. No other User can access your data.
If you are re-assigned from one Coach to another — an administrative operation performed by Coached staff with your consent — your new Coach gains the same data access. Your previous Coach retains access only to historical content they personally authored (programs they wrote, nutrition plans they created, and prior message history). The re-assignment itself is recorded in an internal audit log retained by Coached.
5.1 Cross-border data transfers
Your primary application data — profile, training history, nutrition logs, body composition, wellbeing, photos, wearable and device health data — is stored on AWS infrastructure in Sydney, Australia through Supabase.
Some of our other sub-processors process data on infrastructure located outside Australia. Vercel, Resend, Anthropic, OneSignal, and Google are headquartered in the United States and may process data on US-located infrastructure when you interact with the relevant feature (web hosting and serverless functions, transactional email, AI features, push notification delivery, web font delivery respectively).
When your Personal Information is processed outside Australia, we rely on the contractual data processing terms of each sub-processor and, where applicable, on the protections of Australian Privacy Principle 8.2. We take reasonable steps to ensure that overseas sub-processors handle your information consistently with the APPs.
5.2 Future sub-processors
We have no additional sub-processors pending at this time. If we add one, we will update this Privacy Policy before any of your data is sent to it.
6. Your rights
Under the Australian Privacy Act and the APPs, you have the right to:
- Access the Personal Information we hold about you.
- Correct inaccurate or incomplete information. Most fields are directly editable in the app; for anything else, contact us.
- Delete your account and all associated data. Clients can self-delete directly within the app via Profile (top-right avatar) → Delete account. Coaches can request deletion by contacting us. Once a deletion is initiated, we permanently delete your data within 30 days, except where retention is required by law.
- Withdraw consent for push notifications at any time via your device settings.
- Withdraw consent for wearable and device health data sharing at any time in your device's health settings (for example, on iOS: Settings → Health → Data Access & Devices) or by disconnecting the wearable.
- Request a copy of your data in a portable format. Contact us and we will provide it within 30 days.
- Lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au) if you believe we have mishandled your Personal Information.
To exercise any of these rights other than the self-service deletion or the device-level controls, contact us at the address in Section 12. We will respond within 30 days.
7. Sensitive Information
Some of the data we collect is Sensitive Information under the Privacy Act, including:
- All health information you provide at intake (medications, surgeries, health screening, allergies, contraindications).
- Body composition data (bodyweight, body fat, photos, measurements).
- Wearable and device health data (for example HRV, resting heart rate, sleep stages, blood oxygen, respiratory rate, skin temperature, steps, and recovery score).
- Free-text health context tags and emergency contact information.
We collect Sensitive Information only with your explicit consent, given at the intake step. You cannot use the Service to receive coaching without completing the intake and accepting the consent declaration. Your consent and the timestamp at which it was given are recorded.
We use Sensitive Information only for the purposes described in Section 3 (delivering coaching, AI features that explicitly use health-related context as described, and complying with legal obligations).
8. Data retention
We retain your data for as long as your account is active. Specifically:
- Active accounts — retained indefinitely.
- Account deletion (self-service or by request) — your account and associated data are permanently deleted within 30 days.
- Coach-initiated removal of a Client — when a Coach removes a Client from their roster, the Client's training, nutrition, body composition, wellbeing, messaging, and wearable data associated with that Coach are deleted in the same operation.
- Backups — our hosting provider retains platform-level backups for short periods as standard backup hygiene. Personal Information may persist in backups for a short time after deletion but is not retained for the purpose of restoring deleted accounts. Backups roll off according to the hosting provider's schedule.
- Legal hold — where retention is required by law (e.g. financial records for tax purposes, response to a subpoena), we retain only the specific information required and for the period required.
9. Children's privacy
The Service is intended for use by professional fitness and health coaches and their adult Clients. The Service is not directed at children under 16, and we do not knowingly collect Personal Information directly from anyone under 16.
Coaches using the Service are responsible for determining the appropriateness of the Service for their own Clients, and for obtaining any required parental or guardian consent where their Client is a minor. Coaches accept this responsibility under our Terms of Service.
If you believe a minor has provided us with Personal Information without appropriate consent, contact us and we will delete it promptly.
10. Push notifications
If you grant permission, we will send push notifications for:
- Daily check-in reminders from your Coach.
- Updates from your Coach (e.g. when your calorie targets change).
- New program assignments.
- Direct messages from your Coach (Clients) or your Clients (Coaches).
Push notifications are delivered through OneSignal, which holds your device push token keyed to your Supabase user ID. You can withdraw consent at any time via your device's notification settings or by contacting us.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy at this URL and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
When we add new sub-processors or significantly change the data we collect, we will update Sections 2 and 5 and announce the change in-app.
12. Governing law and contact us
This policy is governed by the laws of Queensland, Australia. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Contact Us
For privacy enquiries, data requests, or account deletion:
Brave Systems Pty. Ltd. (trading as Yates Total Health)
Email: hello@coached.au
Website: coached.au
ABN: 80 164 223 116
See also: Terms of Service · Disclaimer · Cookie Policy