Privacy for coaches
Last updated 2 September 2026
This policy covers Granite for coaches, the platform at app.granite.coach. The Granite iOS app keeps everything on your phone and has its own policy.
Who we are
Granite for coaches is run by [Trading name], [Postal address], United Kingdom. ICO registration [number]. For anything in this policy, email coaches@granite.coach.
Two roles
For your own account, we are the controller of your data. For your clients' data, you are the controller and we are your processor: we hold it on your instructions, for the purpose of running your coaching, and for nothing else. The processing terms are in the terms.
What we collect from you
Your name, your email address, a hash of your password (never the password itself), the display name you choose for your clients to see, and your parameters — the weightings the engine drafts from. When billing is live: what is needed to take payment, held by the payment provider, not by us.
What we process on your behalf
Your clients' names and email addresses, the answers they give when they join (what the lifting is for, training days, experience, starting loads), the sets they log, the pain they flag, and any injury notes they write. Injury and pain notes are health data. They are used only to shape and adjust that client's programme, are visible only to you and to the client, and are never used for anything else.
The notes you write to clients, and every decision you make in the review queue, are stored so that both of you can see them.
What we never do
We do not sell data. We do not train models on your clients or on your parameters — the engine is deterministic, and nothing you or they enter changes how it works for anyone else. We do not show advertising. We do not share data with anyone except the providers below, and only so the service can run.
Where it is stored
On [hosting provider], in [region]. Data is encrypted in transit and at rest. Access is limited to what running the service needs, and every account and coaching-decision event is written to an audit log so that “who changed this” always has an answer.
Sub-processors
[Hosting provider] (storage and compute). When billing is live, [payment provider] (payments). We will update this list before adding to it.
Retention and deletion
We keep your data while you have an account. Remove a client and their account, programme, logs and notes are deleted with them. Close your account and everything under it goes too, within 30 days, apart from what we must keep for tax records. Ask for a copy of your data at any time and we send it.
Your clients' rights
Your clients can see their programme, their logs and every note you have sent them from their own login. A request from a client to access, correct or delete their data goes to you as controller; we will help you meet it.
Security
Passwords are stored hashed. Sessions are signed cookies. Every query is scoped to the coach or client it belongs to. Login attempts are rate-limited. If we ever become aware of a breach affecting your data, we will tell you without undue delay and, where the law requires, the ICO.
This website
granite.coach itself sets one item in your browser's local storage to remember whether you inverted the page. There are no analytics and no third-party scripts.
Changes
If this policy changes in a way that matters, we email you before it takes effect.