practice.coach
How it worksPricingAboutContact
Log inStart free
Legal

Privacy Policy

Effective date: June 11, 2026 · Last updated: June 11, 2026

1. Who We Are

The Practice.coach platform (https://www.practice.coach) is operated by MMXXV Labs s.r.o., Company ID (IČO) 11945320, VAT ID CZ11945320, with registered office at Hasičská 930/53, Hrabůvka, 700 30 Ostrava, Czech Republic, registered in the Commercial Register kept by the Regional Court in Ostrava, Section C, Insert 87316 (referred to as "we", "us", or the "controller"). We are the data controller for personal data we process in accordance with applicable privacy laws including GDPR.

Contact: privacy@mmxxvlabs.io

2. Data We Collect

We collect only data necessary to operate the platform:

  • Identity data: name, email address, and (if you sign in with Google) your profile picture
  • Coaching data: AI session transcripts, audio recordings of sessions with clients, ICF competency evaluations, journal entries, notes and contact details about your real coaching clients, daily challenge submissions
  • Google Calendar data (only if you connect Calendar): event titles, attendee names and emails, start and end times, location, and description of your upcoming events
  • Technical data: IP address, browser user-agent, access timestamps (server logs)
  • Payment data: processed exclusively by Stripe; we retain only your Stripe customer ID, subscription ID, and the last 4 digits of your card for display in your account — we never store full card numbers or CVV

3. How We Use Your Data

Each data type is used for a specific purpose:

  • Email and name — account creation, magic-link sign-in, transactional emails (payment receipts, session reminders)
  • Google profile picture — displaying your avatar in the app
  • AI session transcripts and audio — ICF competency evaluation, LorelAI feedback, and summary generation; this content is sent to LLM providers (Google Gemini, xAI) as input for inference — see §6
  • Journal entries — generating titles and surfacing connections across your own entries
  • Your clients' data — maintaining records of real client sessions and generating pre-session briefs; we process this strictly on your instructions (you are the controller, we are the processor — see §8)
  • Google Calendar data — used solely to display upcoming client sessions in the app and to generate pre-session briefs
  • Payment data — billing, tax invoicing, and fraud prevention together with Stripe
  • Technical logs — security, error debugging, and performance monitoring

We never sell your coaching data to third parties, and we never use it to train AI models — our contracts with Google Gemini and xAI explicitly cover this restriction.

4. Legal Basis for Processing

  • Contract performance — processing necessary to deliver the service
  • Legitimate interest — security, fraud prevention, analytics
  • Consent — marketing communications (withdrawable at any time)

5. Google Sign-In and Google Calendar (OAuth)

5.1 Basic sign-in (scopes openid, email, profile). When you sign in with Google, we receive only your name, email address, and profile picture — used solely to create and identify your account. We do not request access to your Google Drive, Gmail, or any other Google services beyond this basic authentication.

5.2 Google Calendar integration (optional, scope https://www.googleapis.com/auth/calendar.readonly). If you explicitly connect Calendar in Settings, we read only the following fields for upcoming events: event title, attendee names and emails, start and end times, location, and description. This data is used solely to display upcoming client sessions in the app and to generate pre-session text briefs. Calendar events are not stored in our database — they are fetched on demand at view time and discarded when you leave the page. You can disconnect the integration at any time in Settings; once disconnected, we stop reading from your calendar.

5.3 Google API Limited Use. Practice.coach's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the Google Calendar integration feature within the platform and is not sold, not shared with third parties, not used for advertising, and not used to train AI models.

6. Data Sharing and Processors

We share your data only with the following processors, each contractually bound to protect it:

  • Supabase (EU) — PostgreSQL database and object storage; holds all account data and coaching content
  • Vercel (USA, EU/US SCCs) — application hosting (serverless functions and static assets)
  • Stripe (USA, EU/US Data Privacy Framework) — payment processing; you enter card details directly into Stripe — they never touch our servers
  • Resend (USA, EU/US SCCs) — transactional email delivery (magic-link, payment notifications)
  • Sentry (USA / EU region, EU/US SCCs) — error monitoring; contains only technical stack traces with no PII (email and other PII is stripped by the redactor in server/_core/sentry.ts)
  • Google LLC (USA, EU/US Data Privacy Framework):
    • OAuth + Calendar API — see §5
    • Gemini API (LLM) — transcripts, journal entries, and evaluation prompts are sent as inference input (ICF evaluation, supervision, title generation)
  • xAI (USA, EU/US SCCs) — Grok LLM for AI sessions, speech-to-text (STT), and text-to-speech (TTS); transcripts and short audio clips are sent as inference input
  • Forge (optional fallback LLM) — used only when Gemini and xAI are unavailable; if the platform has no Forge API key configured, it is not engaged at all
  • Zapier (USA, EU/US SCCs, only if you opt in) — outbound webhooks to your own Zapier account for automations you configure yourself

What "sent as inference input" means. When you use AI sessions, ICF evaluation, or title generation, the relevant content (transcript, audio, or text) is sent via API to the LLM providers above. The contractual terms with Google and xAI in this mode explicitly prohibit using the content to train their models. Your coaching data therefore does not enter the training datasets of these models.

7. Where Data is Processed and International Transfers

Primary data location. Your account data and coaching content are stored in a Supabase project located in the European Economic Area (EU region).

Sub-processors in the US (with appropriate safeguards). Some sub-processors (Vercel, Stripe, Resend, Sentry, Google APIs, xAI) process data outside the EEA, typically in the United States. Where this happens, the transfer is safeguarded by the EU Standard Contractual Clauses approved by the European Commission and, where the provider is certified, the EU–US Data Privacy Framework. We can provide a copy of the safeguards on request.

8. Processing Your Clients' Data

If you upload data about your real coaching clients (e.g. session transcripts, notes, or contact details), you are the controller of that data and we act as your processor, processing it only on your instructions and to provide the service. This data may include special categories of personal data (e.g. health information). You are responsible for having a valid legal basis (typically the client's consent or a contract) before uploading it.

This processing is governed by our Data Processing Agreement (DPA), which forms part of this Policy.

9. Data Retention

Retention varies by data type:

  • Account data (name, email, profile) — for the lifetime of the account plus 30 days after cancellation (for recovery)
  • Coaching content (transcripts, journal, client notes, evaluations) — for the lifetime of the account, or until you delete it; on account cancellation, deleted within 30 days
  • Google Calendar data — not retained; fetched on demand and discarded after the view
  • Payment records (Stripe IDs, invoices) — 7 years per Czech accounting and VAT law
  • Server access logs — 30 days
  • Sentry error events — 90 days (Sentry default retention)

You can request earlier deletion at any time — see §10.

10. Deletion and Data Subject Requests

You have two ways to request deletion of your data:

  • Self-serve account cancellation — if a "Delete account" action is available in Settings, use it. Once confirmed, we lock the account and delete all associated data within 30 days (except data we must retain by law — see §9).
  • Email request — if self-serve is unavailable or you're not sure, email privacy@mmxxvlabs.io. We respond within 30 days.

The same routes also let you exercise other GDPR rights (access, rectification, portability, objection) — see §11.

11. Your Rights (GDPR)

  • Right to access your data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to object to processing
  • Right to lodge a complaint with your supervisory authority (in the Czech Republic: ÚOOÚ, www.uoou.cz)

To exercise your rights, contact: privacy@mmxxvlabs.io

12. US State Privacy Rights (e.g. California)

If you are located in the United States, state privacy laws (such as the California Consumer Privacy Act / CPRA, and similar laws in Virginia, Colorado, Connecticut and other states) may give you rights to access, correct, and delete your personal data, and the right not to be discriminated against for exercising them. We do not "sell" your personal information or "share" it for cross-context behavioral advertising as those terms are defined under these laws. To exercise your rights, contact us at privacy@mmxxvlabs.io.

13. Cookies

We use only first-party cookies needed to run the platform: (1) an authentication cookie that signs you in and keeps your session, and (2) a cookie that remembers your sidebar preference. We do not use third-party advertising or tracking cookies. If we add analytics in the future, we will use a privacy-friendly solution and update this Policy.

14. Security

Data is encrypted in transit (TLS/HTTPS) and at rest (Supabase encrypts database and object-storage content at the storage layer). Access to production data is restricted to authorized operations personnel on a need-to-know basis. PII (emails, names) is stripped from logs sent to Sentry by a dedicated redactor on both client and server.

15. Age Restriction

The platform is intended for professional coaches and is not directed to anyone under the age of 18. We do not knowingly collect personal data from children.

16. Changes to This Policy

We will notify you of material changes by email at least 14 days in advance. The current version is always available at https://www.practice.coach/privacy.

practice.coach

Where you grow as a coach.

·
Product
  • How it works
  • Session reflection
  • Practice with an AI client
  • Pricing
  • What's new
Company
  • About
  • Contact
  • Blog
  • Privacy & data protection
  • Terms of Service
practice.coach — built in Ostrava !!!© 2026 MMXXV Labs