Effective Date: August 2026
1. Introduction
Solo AI Coach ("we," "us," "Company") values your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
2. Information We Collect
Information You Provide Directly
- Account information: Email, name, payment details (via Stripe)
- Coaching session transcripts: Conversations you upload for analysis
- Audio files: Voice recordings you upload for transcription
- Account settings: Subscription tier, billing preferences, contact preferences
Information Collected Automatically
- Usage data: Which features you use, analysis frequency, session length
- Device information: IP address, browser type, operating system
- Cookies: Session tokens, authentication, preferences (no tracking pixels)
Information from Third Parties
- Stripe: Payment processing, billing information
- Deepgram: Audio transcription (we do not retain raw audio; Deepgram does not retain it longer than processing)
- Anthropic: Claude API usage (we do not share session content with Anthropic beyond processing)
3. How We Use Your Information
For Service Delivery
- Process and analyze your coaching transcripts
- Generate insights and suggestions
- Manage your subscription and billing
- Provide customer support
For Product Improvement
- Identify common coaching patterns
- Train and improve our analysis algorithms
- Debug and fix errors
- Measure feature usage
For Research (Anonymized Only)
- Create aggregate insights about coaching practices
- Develop online courses based on patterns
- Publish industry reports and findings
- Share findings with the coaching community
Important: We only use anonymized data for research (see Data Retention below).
For Legal Compliance
- Comply with laws and regulations
- Respond to lawful requests from authorities
- Enforce these terms and other agreements
- Protect our legal rights
4. How We Share Your Information
What We DON'T Share
- ❌ We never sell your personal data to third parties
- ❌ We never share your raw coaching transcripts with advertisers, analytics companies, or brokers
- ❌ We never sell client names or identifying information
- ❌ We never share payment details (Stripe handles this)
What We DO Share
- Service providers: Stripe (payments), Deepgram (transcription), Supabase (hosting), Anthropic (analysis)
- Anonymized research data: With coaches, researchers, and the coaching community (no identifying info)
- Legal requests: We comply with lawful court orders and law enforcement requests
Data Processing Agreements
Our service providers have committed to data protection:
- Stripe: Stripe Privacy
- Deepgram: Deepgram Privacy
- Supabase: Supabase Privacy
- Anthropic: Anthropic Privacy
5. Data Retention & Deletion
Active Sessions
- Retained for as long as your account and the session exist
- You can access, export, or request deletion of a session anytime by contacting us
Deleted Sessions
- Kept for 30 days after deletion, in case you need it restored
- After 30 days, the session is anonymized and archived (see below), regardless of subscription tier
Anonymization Process
When a deleted session reaches the 30-day mark, we:
- Remove its link to your coach account
- Remove its link to the client record
- Remove the session title (which often names the client)
- Retain the transcript, notes, and analysis content as written
This removes the direct, structured links back to you and your client. It does not edit the conversation content itself, which may still reference names or identifying details mentioned during the session.
Archived (Anonymized) Data
Retention:
- Kept indefinitely for research and product improvement
- Cannot be linked back to your account or client record through our system
- Used for the purposes described in Section 3 ("For Research")
Automated Process:
- Daily job identifies sessions deleted more than 30 days ago
- Anonymizes and moves them into an internal archive
- Removes the original from the active session list
- Process logged for audit trail
Example:
- Jan 1: A session is deleted
- Jan 1–31: Still recoverable on request
- Feb 1: Job anonymizes and archives the session
- Feb 1 onward: Archived data retained indefinitely
Deletion Requests
You can request deletion of an active session anytime by emailing: privacy@soloaicoach.com
Timeline:
- Request received immediately
- Session deleted from active use within 30 days
- Once anonymized and archived, it is retained per the above and cannot be un-anonymized or linked back to you
We're exploring additional data controls, including a paid option to opt out of the research archive entirely. This section will be updated if and when that becomes available.
6. International Data Transfers & Compliance
GDPR (European Union)
If you're in the EU:
- Your data is processed in compliance with GDPR
- You have rights: access, portability, deletion, correction
- We have a Data Processing Agreement (DPA) available on request
- Our data processor is Supabase (EU-based, SOC 2 compliant)
CCPA (California)
If you're in California:
- You have rights: access, deletion, opt-out of data sales
- We don't sell personal information
- We don't use personal info for targeted advertising
Canada, Australia, Other Jurisdictions
- We comply with local privacy laws where applicable
- Your data may be transferred to the US for processing (see below)
Data Transfer to US
- Our servers are hosted in the US (Supabase/AWS)
- Transfers occur under standard contractual clauses (EU users)
- Transfers are necessary for service delivery
7. Security
Encryption
- In transit: All data encrypted via HTTPS/TLS
- At rest: Transcripts encrypted in database (AES-256)
- Passwords: Hashed via bcrypt, never stored in plaintext
Access Controls
- Only authorized employees can access raw data
- Anonymized research data accessible to analysis team
- Role-based access (engineers, support, researchers)
- Multi-factor authentication required for admin access
Incident Response
- Breaches are investigated immediately
- Affected users notified within 72 hours (per GDPR)
- Incidents logged and reported to relevant authorities
Third-Party Security
- Stripe: PCI DSS Level 1 compliant
- Supabase: SOC 2 Type II certified
- Deepgram: SOC 2 compliant
- Anthropic: SOC 2 compliant
8. Cookies & Tracking
Cookies We Use
- Session token: Keeps you logged in
- Authentication: Verifies your identity
- Preferences: Remembers your settings (dark mode, etc.)
- Analytics: Tracks feature usage (no third-party pixel tracking)
Cookies We Don't Use
- ❌ No Google Analytics
- ❌ No Facebook Pixel
- ❌ No ad tracking
- ❌ No third-party cookies
Cookie Consent
- By using the Service, you consent to essential cookies
- Analytics cookies are optional (you can disable in settings)
9. Your Rights & Choices
Right to Access
- Request a copy of your data anytime by emailing privacy@soloaicoach.com
- Includes transcripts, analyses, account info
Right to Correction
- Update your email, name, preferences anytime
- Contact support for other corrections
Right to Deletion
- Request deletion of your account and all raw data
- Processed within 30 days
- Anonymized data retained for research (cannot be un-anonymized)
Right to Portability
- Request your data in a portable format (JSON/CSV) by emailing privacy@soloaicoach.com
Right to Object
- Object to our use of your data for research
- We'll honor requests within 30 days
- May affect your access to research-powered features
10. Children's Privacy
- The Service is not intended for children under 18
- We do not knowingly collect data from minors
- If we learn we've collected child data, we delete it immediately
11. Third-Party Links
- We are not responsible for third-party websites or privacy practices
- Our Privacy Policy does not apply to external links
- Read third-party privacy policies before using their services
12. Changes to Privacy Policy
- We may update this policy anytime
- Changes posted here and take effect immediately
- Continued use constitutes acceptance
13. Contact & Data Protection Officer
Questions about privacy or requests for your data?
Email: privacy@soloaicoach.com
Mailing Address: 223 W 38th St, P.O. Box #416, New York, NY 10018
Website: soloaicoach.com
For EU users:
- Data Protection Officer: privacy@soloaicoach.com
- Local privacy authority: EU users may lodge a complaint with the data protection authority in their country of residence
Version: 1.0
Last Updated: August 2026
Next Review: August 2027