Coachium

Privacy Policy

How Coachium collects, uses, and protects your data — with the specifics required by Turkish data-protection law (KVKK) and the EU GDPR.

Effective May 3, 2026 Türkçe

This policy explains what personal data Coachium collects, the purposes and legal bases for processing, the categories of third parties involved, how long data is kept, and the rights you can exercise.

Coachium is not a HIPAA-covered service. The app is not designed to store, process, or transmit Protected Health Information (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act, or equivalent electronic health-record information regulated by any other jurisdiction. If your use of client data is regulated by HIPAA, KVKK health-data provisions, GDPR special-category rules, or your professional licensing body, you are solely responsible for ensuring your use of Coachium complies with those obligations. Coachium is not intended for use in a medical or psychiatric emergency: if you or someone you support is in crisis, contact local emergency services (911 in the US, 112 in the EU/Türkiye) or a crisis line such as the 988 Suicide & Crisis Lifeline (US). In the United States, Coachium voluntarily applies the FTC Health Breach Notification Rule (16 CFR Part 318) and will notify affected users, the FTC, and where required the media within 60 days of any unauthorized disclosure of identifiable health information. See our Terms of Use, Section 01.

01 Data Controller

The data controller for Coachium is the developer operating under the trade name Coachium, based in Türkiye. For any data-protection inquiry or rights request, use the contact address in Section 13 of this page.

02 Data We Collect

03 Purposes & Legal Basis

04 Third-Party Sub-processors

We rely on a small number of named third-party providers — each under its own contractual and security commitments — to deliver parts of the service. Data is shared only as needed for the functions below.

We may add, replace, or remove sub-processors over time (for example, to use a different AI provider for cost or quality reasons). Material changes will be reflected here and surfaced via an in-app notice on next launch, as described in Section 10.

05 Cross-Border Transfers

Your content is primarily stored on cloud infrastructure located in the European Union. Transfers outside Türkiye and the EU/EEA occur in the following situations:

EU/EEA → United States. Transfers from the EU/EEA to the United States rely on the European Commission's adequacy decision of 10 July 2023 for recipients certified under the EU-U.S. Data Privacy Framework, and on the European Commission's Standard Contractual Clauses (Decision 2021/914) for recipients not certified under that framework. Apple, Google, and OpenAI are recipients we work with on this basis.

Türkiye → abroad. Cross-border transfers from Türkiye are made under the amended KVKK Article 9 (Law no. 7499 effective 1 June 2024) and the implementing Regulation of 10 July 2024, primarily on the basis of appropriate safeguards (Art. 9/2-b) — the standard contractual clauses published by the Turkish Personal Data Protection Authority — with the required notification to the Authority within five business days of execution. Where you enable AI features for the first time you are also asked for explicit consent specific to that feature (Art. 9/6) for occasional cases not otherwise covered.

You can withdraw your consent and stop cross-border processing at any time by deleting your account (Settings → Account → Delete Account), which revokes the Sign in with Apple grant and erases stored content within the periods set out below.

06 Retention & Account Deletion

Account deletion (in-app, available to all users): You can permanently delete your account at any time from Settings → Account → Delete Account. Deletion is irreversible. On confirmation we (a) revoke the Sign in with Apple refresh token with Apple, (b) erase your Firestore documents and Cloud Storage objects within 30 days, (c) cycle out automated backups within 90 days, and (d) delete diagnostic events within 90 days. We do not retain your data for marketing, analytics, or re-identification after deletion.

07 Your Rights (KVKK Art. 11 & GDPR)

You have the right to:

To exercise these rights, email the contact address in Section 13. We respond within 30 days as required by KVKK Art. 13.

08 Data Security

All network traffic is encrypted in transit (TLS 1.2+). Database security rules enforce per-user access — no user can read or write another user's content. API keys are stored in secure cloud secret storage and never ship inside the app. The AI proxy applies per-user rate limits and audio-size caps on the server side.

09 Children's Privacy

Coachium is a professional tool for adult coaches, therapists, and mentors. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age. If we learn that a user under 13 has created an account, we will delete the account and any associated data without unreasonable delay. Parents or guardians who believe their child has provided personal information to us may contact us at the address in Section 13 to request deletion.

10 Do Not Track & Tracking Technologies

Coachium does not track users across third-party websites or services and does not run advertising or analytics SDKs that build cross-service profiles. Because we do not engage in such tracking, we do not respond differently to "Do Not Track" (DNT) browser signals. We do not knowingly permit third parties to collect personally identifiable information about an individual consumer's online activities over time and across different websites when a consumer uses the app or this website.

We do not sell your data. We do not use it for advertising. We do not build cross-service profiles. Ever.

11 US State Privacy Rights

This section applies to residents of US states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Maryland, Minnesota, and any other state granting equivalent rights. Coachium is operated by a small developer that does not meet the revenue or data-volume thresholds of most US state comprehensive privacy laws and does not sell or share personal data; we voluntarily honor the consumer rights below for all US residents.

Categories of personal information. The categories listed in Section 02 are the same categories we collect from US residents. We disclose information only to the sub-processors listed in Section 04, solely for the business purposes described in Section 03. We have not sold or shared personal information in the preceding 12 months, and we do not engage in targeted advertising or profiling for decisions that produce legal or similarly significant effects.

Sensitive personal information. Audio recordings, transcripts, session notes, and coaching-tool entries you create may reveal information about a person's mental or physical health, and audio recordings may be considered biometric information under the CCPA. We use this sensitive personal information only to provide the services you have requested. We do not use or disclose sensitive personal information for any purpose that would trigger the "Right to Limit" under California Civil Code §1798.121.

Your rights. Subject to the law of your state, you may:

How to exercise these rights. Email the contact address in Section 13 from the address tied to your account. We verify identity by matching the request email to the account email. Authorized agents may submit requests with written authorization. We respond within 45 days, extendable by 45 more days where the law allows.

Shine the Light (California Civil Code §1798.83). We do not share personal information with third parties for their direct marketing purposes.

12 Changes

We may update this policy over time. Changes take effect when we update the effective date in the header. For material changes, we'll also surface an in-app notice on next launch.

13 Contact

Questions, requests, or complaints?

Data Protection Contact:

ozgekdioglu@icloud.com