Coached

Privacy Policy

Last updated: June 2026

Brave Systems Pty. Ltd., trading as Yates Total Health and operating the Coached platform ("we", "our", "us"). This Privacy Policy explains how we collect, use, store, and protect your Personal Information when you use the Coached web application and mobile applications (collectively, the "Service"). By using the Service, you agree to this policy.

If you have questions about this policy or want to exercise any of the rights described below, contact us at the address in Section 12.

1. Who we are

Coached is a coaching platform connecting personal trainers and health coaches ("Coaches") with their clients ("Clients"). The Service is operated by Brave Systems Pty. Ltd. (trading as Yates Total Health) (ABN 80 164 223 116), based in Queensland, Australia.

Coaches subscribe to Coached and use it to deliver coaching services to their own Clients. Clients access Coached through invitation by their Coach. Throughout this policy, "you" means whichever of these you are.

We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Information we collect

We collect information when you create an account and use the Service. Different categories of information are collected from Coaches and Clients depending on which features you use.

2.1 From all Users

2.2 From Clients (additional)

When you, as a Client, complete the one-time health intake on first use of the companion app, you provide:

Throughout your use of the Service, you may also provide:

2.3 From Coaches (additional)

2.4 What we do not collect

We do not collect this information passively or without your direct input, with the exception of the technical server-log information described in Section 2.1. We do not use advertising trackers or third-party analytics SDKs. We do not buy or sell Personal Information.

3. How we use your information

We use the information we collect solely to operate, deliver, and improve the Service.

3.1 To deliver the coaching service

3.2 To send communications

We do not send marketing emails. All communications relate directly to your use of the Service.

3.3 To power AI-assisted features

The Service uses Anthropic's Claude API for several features. The following information is sent to Anthropic when these features are used:

Anthropic does not retain the content of API requests for training under their commercial terms of service. AI-generated outputs are estimates and suggestions intended only as coaching context; they are not authoritative and should not be relied on for nutritional, training, or medical decisions.

3.4 To diagnose and improve the Service

3.5 To comply with legal obligations

3.6 Automated adjustments and decision-making

One feature changes your plan automatically: calorie and macronutrient target auto-adjustment. In response to your logged progress, it may adjust your targets by up to about 5% per step, always protecting a minimum protein floor. Every adjustment is recorded in an audit log and can be reviewed and reversed by your Coach within 48 hours. This is the only feature that adjusts your plan automatically.

All other computed outputs are advisory and require a person to act on them: your recovery score is shown for context; a recovery deload is suggested and applied only when you or your Coach taps to apply it; AI nutrition estimates are reviewed by a person before being saved.

You can ask your Coach to disable automatic adjustments, and you can ask for human review of any automated adjustment — your supervising Coach is the human reviewer.

4. Data storage and security

Your data is stored in Supabase, a cloud database platform. Supabase enforces row-level security so that each User can only access their own data (Clients can only see their own records; Coaches can only see records for Clients assigned to them).

Progress photos, profile photos, and chat/form-check videos are stored in private Supabase Storage buckets. Access is enforced by row-level security and served via short-lived signed URLs: each object is retrievable only by the User who uploaded it and that User's assigned Coach. There is no public or anonymous access to these buckets.

We use industry-standard encryption in transit (HTTPS/TLS) and at rest. Passwords are stored hashed by Supabase Auth and are never visible to us in plain form.

Supabase infrastructure is hosted on AWS. Your data is stored on AWS infrastructure in Sydney, Australia (the ap-southeast-2 region).

5. Who we share your data with — and where it's processed

We do not sell or rent your Personal Information. We share data only with the sub-processors listed below, strictly to operate the Service:

We also embed exercise demonstration videos from Vimeo and YouTube within the Service. When you view an embedded video, your browser interacts directly with these services and they may set their own cookies and receive your IP address. See our Cookie Policy for more.

We send food barcode digits to Open Food Facts (a public open-source food database) to look up product information. This request contains the barcode only and no User identifier.

Your assigned Coach has access to the training, nutrition, body composition, wellbeing, and (where granted) wearable and device health data that you generate through the Service, as part of the coaching relationship. No other User can access your data.

If you are re-assigned from one Coach to another — an administrative operation performed by Coached staff with your consent — your new Coach gains the same data access. Your previous Coach retains access only to historical content they personally authored (programs they wrote, nutrition plans they created, and prior message history). The re-assignment itself is recorded in an internal audit log retained by Coached.

5.1 Cross-border data transfers

Your primary application data — profile, training history, nutrition logs, body composition, wellbeing, photos, wearable and device health data — is stored on AWS infrastructure in Sydney, Australia through Supabase.

Some of our other sub-processors process data on infrastructure located outside Australia. Vercel, Resend, Anthropic, OneSignal, and Google are headquartered in the United States and may process data on US-located infrastructure when you interact with the relevant feature (web hosting and serverless functions, transactional email, AI features, push notification delivery, web font delivery respectively).

When your Personal Information is processed outside Australia, we rely on the contractual data processing terms of each sub-processor and, where applicable, on the protections of Australian Privacy Principle 8.2. We take reasonable steps to ensure that overseas sub-processors handle your information consistently with the APPs.

5.2 Future sub-processors

We have no additional sub-processors pending at this time. If we add one, we will update this Privacy Policy before any of your data is sent to it.

6. Your rights

Under the Australian Privacy Act and the APPs, you have the right to:

To exercise any of these rights other than the self-service deletion or the device-level controls, contact us at the address in Section 12. We will respond within 30 days.

7. Sensitive Information

Some of the data we collect is Sensitive Information under the Privacy Act, including:

We collect Sensitive Information only with your explicit consent, given at the intake step. You cannot use the Service to receive coaching without completing the intake and accepting the consent declaration. Your consent and the timestamp at which it was given are recorded.

We use Sensitive Information only for the purposes described in Section 3 (delivering coaching, AI features that explicitly use health-related context as described, and complying with legal obligations).

8. Data retention

We retain your data for as long as your account is active. Specifically:

9. Children's privacy

The Service is intended for use by professional fitness and health coaches and their adult Clients. The Service is not directed at children under 16, and we do not knowingly collect Personal Information directly from anyone under 16.

Coaches using the Service are responsible for determining the appropriateness of the Service for their own Clients, and for obtaining any required parental or guardian consent where their Client is a minor. Coaches accept this responsibility under our Terms of Service.

If you believe a minor has provided us with Personal Information without appropriate consent, contact us and we will delete it promptly.

10. Push notifications

If you grant permission, we will send push notifications for:

Push notifications are delivered through OneSignal, which holds your device push token keyed to your Supabase user ID. You can withdraw consent at any time via your device's notification settings or by contacting us.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy at this URL and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

When we add new sub-processors or significantly change the data we collect, we will update Sections 2 and 5 and announce the change in-app.

12. Governing law and contact us

This policy is governed by the laws of Queensland, Australia. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Contact Us

For privacy enquiries, data requests, or account deletion:

Brave Systems Pty. Ltd. (trading as Yates Total Health)
Email: hello@coached.au
Website: coached.au
ABN: 80 164 223 116

See also: Terms of Service · Disclaimer · Cookie Policy