Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains how Coachium and Transforming Sports (together, "Coachium", "we", "us", or "our") collect, use, disclose, and protect personal information. It applies to coachium.app, the Coachium web application, the Coachium mobile application, and any related sites, applications, support, content, and services that link to this Policy (the "Services").

If you have a question or want to exercise a privacy right, contact team@coachium.app.

1. Our Role

Coachium is responsible for personal information used to administer accounts, subscriptions, security, support, product analytics, and the operation of the Services.

Teams, clubs, schools, businesses, and other organizations that use the Services ("Organizations") may also add or manage information about their members, staff, players, participants, or other people. An Organization normally decides why and how that information is used. For that Organization-controlled information, the Organization is generally the controller or business and Coachium acts as its processor or service provider. Privacy requests about Organization-controlled information may therefore need to be handled by the relevant Organization.

2. Information We Collect

The information we collect depends on how you use the Services.

Account and profile information

We may collect your name, email address, profile image, biography, role, organization membership, preferences, sign-in method, account status, and authentication and security information. If you sign in through another provider, we receive the profile information that provider makes available to us.

Organization and participant information

You or an Organization may provide information about staff, coaches, players, participants, or other members. This may include names, contact details, roles, jersey numbers, dates of birth, physical measurements, attendance, availability, performance and development records, evaluations, survey responses, notes, and similar operational records.

Some Organization-controlled records may reveal sensitive information, such as an injury, illness, wellness status, medical clearance, treatment, or other health-related information. Organizations are responsible for having an appropriate legal basis, providing required notices, obtaining required permissions or consents, and limiting access to this information.

Content and communications

We process content you create, submit, upload, import, record, publish, or share. This can include text, diagrams, documents, comments, messages, posts, polls, calendar information, images, video, audio recordings, attachments, search queries, AI prompts and responses, and generated or exported files. Files may include technical metadata such as type, size, dimensions, duration, storage path, access level, and upload history.

Purchases and entitlements

When you obtain a paid subscription, membership, or other entitlement, we may receive your billing contact information, plan, purchase source, subscription and payment status, transaction identifiers, amount, currency, and related records. Payments may be processed by a payment provider or app marketplace. We do not receive or store full payment-card numbers.

Device, usage, and diagnostic information

We may collect IP address, browser and device type, operating system, app and build version, device identifiers used for app operation, screens or pages viewed, interactions, timestamps, referring information, search and download activity, performance information, crash reports, network status, and security or error logs.

On the web, privacy-filtered session replay may be enabled for some sessions to help us reproduce errors and understand usability. A replay can record interaction patterns and rendered interface state. We configure our monitoring tools to avoid recording sensitive form values and to limit diagnostic data, but no filtering system is perfect.

Notifications and mobile permissions

If you enable push notifications, we process a push token and related device, platform, app-version, and delivery information. You can turn push notifications off in the Services or your device settings.

The mobile application may ask for access to your camera, photos, or files when you choose to capture, upload, or save content. The web application may ask for microphone access when you choose to record audio. We access these capabilities only after you invoke the relevant function and grant permission. You can revoke device permissions in your operating-system or browser settings.

Cookies, local storage, and offline data

We use cookies, secure device storage, browser storage, and similar technologies to keep you signed in, protect the Services, remember preferences, support offline use, preserve drafts, measure usage, and diagnose problems. Mobile devices may temporarily store encrypted session information and limited account or Organization data so the application can load reliably and support permitted offline behavior. Local data is cleared or replaced through sign-out, account changes, expiry rules, or application controls, although operating-system backups may follow the device provider's rules.

Support, feedback, and marketing

We collect information you send when you contact support, report a problem, join a waitlist, respond to a survey, or provide feedback. If you ask to receive product or marketing communications, we use your contact details and communication preferences for that purpose. You can opt out of marketing messages using the unsubscribe link or by contacting us. We may use anti-abuse services to protect public forms and sign-up flows.

3. Where Information Comes From

We collect information:

  • Directly from you.
  • From an Organization administrator or another authorized user.
  • Automatically from your browser, device, or use of the Services.
  • From sign-in, payment, app marketplace, communications, or other providers you choose to use.
  • From integrations that you authorize.

If you provide information about another person, you must have authority to do so and must give that person any notice or choice required by law.

4. Why We Use Information

Where applicable law requires a legal basis, we rely on the bases described below.

| Purpose | Typical legal basis | | ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | | Provide accounts, collaboration, content storage, communications, processing, exports, subscriptions, and support | Perform a contract or take steps at your request | | Authenticate users, manage permissions, protect data, prevent abuse, and maintain reliability | Contract and our legitimate interests in operating a secure service | | Diagnose errors, understand product usage, and improve usability and performance | Our legitimate interests, or consent where required | | Send optional marketing communications | Consent or another basis permitted by local law | | Maintain transaction, tax, accounting, security, and compliance records | Legal obligation and legitimate interests | | Establish, exercise, or defend legal claims and respond to lawful requests | Legal obligation and legitimate interests | | Process Organization-controlled information according to an Organization's instructions | The Organization's documented instructions and applicable data-processing terms |

We do not use personal information for third-party targeted advertising, and we do not sell personal information for money. If the legal meaning of "sale" or "sharing" in your location gives you additional rights, you may contact us to exercise them.

5. AI and Automated Processing

When you choose to use an AI-assisted or automated media function, the content you submit and the information needed to perform your request may be sent to a specialist processing provider. We use the result to respond to your request, generate an editable draft, analyze media, or provide the requested function. We may retain inputs, outputs, safety records, and technical metadata as part of your content or to operate and protect the Services.

Automated outputs can be incomplete or inaccurate and must be reviewed by a person. Coachium does not use these tools to make solely automated decisions that produce legal or similarly significant effects about players, staff, or other individuals.

We do not authorize providers to use Organization-controlled content for their own advertising. Provider retention and model-improvement practices can vary by service and contractual setting, so do not submit confidential or sensitive information to an AI function unless you and your Organization are permitted to do so.

6. How We Disclose Information

We may disclose information to:

  • Your Organization, its administrators, and authorized users, according to roles and sharing settings.
  • People or services you direct us to share with, including through links, embeds, exports, publications, integrations, or app marketplace functions.
  • Providers that support hosting, authentication, storage, communications, push notifications, payments, analytics, error monitoring, customer support, media processing, exports, and AI-assisted processing.
  • Professional advisers, insurers, auditors, and authorities where reasonably necessary.
  • A buyer, investor, successor, or other participant in a merger, financing, reorganization, insolvency, or sale of all or part of the business, subject to appropriate confidentiality protections.
  • Other parties when required by law, needed to protect rights or safety, or authorized by you.

Our service providers may use personal information only to perform services for us or as otherwise permitted by their contracts and applicable law. We remain responsible for selecting providers appropriate to the information and function involved.

7. Sharing and Publishing Content

Organization administrators can access and manage information within their Organization according to their permissions. If you publish content, create a public or shareable link, authorize an integration, or send an export, the recipient may be able to view, download, copy, or further distribute that content. Review the audience and contents before sharing.

Deleting your account does not necessarily remove content that belongs to an Organization, was created collaboratively, was shared with others, or must remain to preserve another user's records. We may instead remove or de-identify your account information from that content where appropriate.

8. Retention and Deletion

We keep personal information only for as long as reasonably needed for the purposes described in this Policy. The period depends on the type of information and context:

  • Account and service content is generally kept while the account or relevant Organization remains active, until it is deleted, or until the Organization instructs us otherwise.
  • Organization-controlled information is retained according to the Organization's instructions and its use of the Services.
  • Temporary processing files, signed links, and generated artifacts may expire automatically after the relevant task or availability period.
  • Transaction, consent, security, fraud-prevention, audit, and legal records may be kept for the period reasonably required by law or to establish and defend claims.
  • Backups and distributed caches are overwritten on a rolling schedule and may retain deleted information for a limited period before it is removed.

You can close access to your account from the account-security settings in the web or mobile application. Because some records may belong to an Organization or need additional review, closing access is not always the same as erasing every associated record. To request deletion of your personal information, use our account deletion page or contact team@coachium.app. We will verify the request and delete or de-identify information unless we are permitted or required to retain it.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, tenant and role restrictions, protected storage, encryption in transit, monitoring, backups, and incident-response processes where appropriate. No service can guarantee absolute security. You are responsible for protecting your credentials, devices, exports, and Organization access settings.

10. International Transfers

We and our providers may process information outside your country. Where required, we rely on recognized adequacy decisions, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism. Contact us if you would like more information about the safeguards relevant to your information.

11. Your Rights and Choices

Depending on your location and our role, you may have the right to:

  • Access and receive a copy of your personal information.
  • Correct inaccurate or incomplete information.
  • Delete personal information.
  • Restrict or object to certain processing.
  • Receive portable information you provided to us.
  • Withdraw consent at any time, without affecting earlier lawful processing.
  • Opt out of direct marketing.
  • Appeal a decision or use an authorized agent where local law provides those rights.
  • Complain to your local data protection authority.

You can manage some profile, permission, notification, and account choices in the Services or your device settings. For other requests, contact team@coachium.app. We may need to verify your identity. If an Organization controls the information, we may send the request to that Organization or ask you to contact its administrator.

Residents of the European Economic Area or United Kingdom may complain to the supervisory authority where they live or work. These rights are subject to exceptions under applicable law.

12. Children and Young Athletes

The Services are intended for adult coaches, staff, Organization administrators, and other authorized users. A person under 16, or under the minimum age required to consent to an online service in their country, may not create or manage an account independently. They may use an account only when invited or authorized by an Organization and with the involvement and permission of a parent or guardian where required.

Organizations may manage information about children and young athletes. The Organization is responsible for safeguarding, age-appropriate notices, access controls, parental or guardian permissions, and any additional requirements that apply to schools, clubs, employment, health information, or youth sports.

If you believe a child has provided personal information without appropriate authorization, contact us so we can investigate and take appropriate action.

13. Third-Party Sites and Services

The Services may contain links to or integrations with third-party services. Their own terms and privacy notices govern information they process independently. Review those notices before directing content to a third party.

14. Changes to This Policy

We may update this Policy to reflect changes in law, technology, providers, or our practices. We will update the date above and provide additional notice when a change is material and applicable law requires it. Earlier versions may be requested by contacting us.

15. Contact

For privacy questions, requests, or complaints, contact:

Coachium / Transforming Sports team@coachium.app