This policy explains what personal data Coachium collects, the purposes and legal bases for processing, the categories of third parties involved, how long data is kept, and the rights you can exercise.
01 Data Controller
The data controller for Coachium is the developer operating under the trade name Coachium, based in Türkiye. For any data-protection inquiry or rights request, use the contact address in Section 13 of this page.
02 Data We Collect
- Account data: Name and email returned by your Sign in with Apple credential (we accept the private relay email option).
- User content: Client profiles (name, phone, notes), session records (date, duration, notes, audio recordings, attachments), coaching-tool entries (wheel-of-life scores, values, goals, etc.), general coach notes, and group/folder metadata — all created by you inside the app.
- AI inputs and outputs: When you explicitly use transcription or summary features, the related audio file or note text is sent to our AI sub-processor (see Section 04); the returned transcript or summary is stored on your account.
- Subscription status: A flag indicating whether you have an active Premium subscription. Payment details are never shared with us.
- Diagnostic data: Device model, OS version, app version, and anonymized crash and error reports.
03 Purposes & Legal Basis
- Provide the app: Store your content so you can retrieve it across sessions and devices. Legal basis: performance of the contract of service (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)).
- AI features: Transcribe recordings and generate summaries when you tap the feature. Legal basis: performance of contract — you requested the feature (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)). Where audio or notes contain special-category data such as health, religious belief, or trade-union membership, processing relies on your explicit consent for that category (KVKK Art. 6/2; GDPR Art. 9(2)(a)), captured the first time you enable AI features.
- Subscription management: Gate premium features and restore purchases. Legal basis: contract performance.
- Diagnostics: Identify and fix bugs, improve stability. Legal basis: legitimate interest in a functional service (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
04 Third-Party Sub-processors
We rely on a small number of named third-party providers — each under its own contractual and security commitments — to deliver parts of the service. Data is shared only as needed for the functions below.
- Authentication, in-app purchases & push notifications — Apple Inc. (United States). Sign in with Apple returns an account identifier plus the name and email you choose to share (private relay supported). The App Store handles purchases; we receive only an active-subscription flag. Apple Push Notification service delivers reminders. We never receive payment details.
- Cloud hosting, database, file storage, backend logic, crash diagnostics & website hosting — Google LLC (Firebase / Google Cloud). Primary storage region: European Union. Operational and administrative access may occur from the United States under Google's contractual safeguards (DPF / Standard Contractual Clauses).
- AI transcription & summarization — OpenAI, L.L.C. (United States), using the Whisper speech-to-text model and the GPT family of large language models. Audio you choose to transcribe and notes you choose to summarize are sent via our server-side proxy to OpenAI only when you tap the feature. Under OpenAI's API terms, your inputs and outputs are not used to train their models. Transcripts and summaries are statistical outputs and may contain errors; they are not clinical records and must be reviewed before reliance.
We may add, replace, or remove sub-processors over time (for example, to use a different AI provider for cost or quality reasons). Material changes will be reflected here and surfaced via an in-app notice on next launch, as described in Section 10.
05 Cross-Border Transfers
Your content is primarily stored on cloud infrastructure located in the European Union. Transfers outside Türkiye and the EU/EEA occur in the following situations:
- To the United States — when you use AI features, when you authenticate with your Sign in with Apple credential, when push notifications are delivered, and when crash reports are submitted.
- Within the European Economic Area — routine cloud storage and database operations.
EU/EEA → United States. Transfers from the EU/EEA to the United States rely on the European Commission's adequacy decision of 10 July 2023 for recipients certified under the EU-U.S. Data Privacy Framework, and on the European Commission's Standard Contractual Clauses (Decision 2021/914) for recipients not certified under that framework. Apple, Google, and OpenAI are recipients we work with on this basis.
Türkiye → abroad. Cross-border transfers from Türkiye are made under the amended KVKK Article 9 (Law no. 7499 effective 1 June 2024) and the implementing Regulation of 10 July 2024, primarily on the basis of appropriate safeguards (Art. 9/2-b) — the standard contractual clauses published by the Turkish Personal Data Protection Authority — with the required notification to the Authority within five business days of execution. Where you enable AI features for the first time you are also asked for explicit consent specific to that feature (Art. 9/6) for occasional cases not otherwise covered.
You can withdraw your consent and stop cross-border processing at any time by deleting your account (Settings → Account → Delete Account), which revokes the Sign in with Apple grant and erases stored content within the periods set out below.
06 Retention & Account Deletion
Account deletion (in-app, available to all users): You can permanently delete your account at any time from Settings → Account → Delete Account. Deletion is irreversible. On confirmation we (a) revoke the Sign in with Apple refresh token with Apple, (b) erase your Firestore documents and Cloud Storage objects within 30 days, (c) cycle out automated backups within 90 days, and (d) delete diagnostic events within 90 days. We do not retain your data for marketing, analytics, or re-identification after deletion.
- Account and content: Retained while your account is active.
- Authentication refresh token: Revoked with the authentication provider and deleted on our side immediately on account deletion.
- Diagnostic data: Crash and error events retained up to 90 days, then deleted.
- Rate-limit counters: Rolling 24-hour window; auto-expire.
07 Your Rights (KVKK Art. 11 & GDPR)
You have the right to:
- Learn whether your personal data is being processed, and request information about the processing.
- Learn the purposes of processing and whether the data is used accordingly.
- Learn the categories of third parties — domestic or abroad — to whom your data is transferred.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction of your personal data, subject to statutory retention obligations.
- Request that any correction or deletion be communicated to third parties to whom the data was transferred.
- Object to outcomes reached solely through automated processing that produce an adverse effect on you.
- Request compensation if you suffer damages arising from unlawful processing.
- Withdraw any consent previously given, without affecting the lawfulness of prior processing.
To exercise these rights, email the contact address in Section 13. We respond within 30 days as required by KVKK Art. 13.
08 Data Security
All network traffic is encrypted in transit (TLS 1.2+). Database security rules enforce per-user access — no user can read or write another user's content. API keys are stored in secure cloud secret storage and never ship inside the app. The AI proxy applies per-user rate limits and audio-size caps on the server side.
09 Children's Privacy
Coachium is a professional tool for adult coaches, therapists, and mentors. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age. If we learn that a user under 13 has created an account, we will delete the account and any associated data without unreasonable delay. Parents or guardians who believe their child has provided personal information to us may contact us at the address in Section 13 to request deletion.
10 Do Not Track & Tracking Technologies
Coachium does not track users across third-party websites or services and does not run advertising or analytics SDKs that build cross-service profiles. Because we do not engage in such tracking, we do not respond differently to "Do Not Track" (DNT) browser signals. We do not knowingly permit third parties to collect personally identifiable information about an individual consumer's online activities over time and across different websites when a consumer uses the app or this website.
11 US State Privacy Rights
This section applies to residents of US states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Maryland, Minnesota, and any other state granting equivalent rights. Coachium is operated by a small developer that does not meet the revenue or data-volume thresholds of most US state comprehensive privacy laws and does not sell or share personal data; we voluntarily honor the consumer rights below for all US residents.
Categories of personal information. The categories listed in Section 02 are the same categories we collect from US residents. We disclose information only to the sub-processors listed in Section 04, solely for the business purposes described in Section 03. We have not sold or shared personal information in the preceding 12 months, and we do not engage in targeted advertising or profiling for decisions that produce legal or similarly significant effects.
Sensitive personal information. Audio recordings, transcripts, session notes, and coaching-tool entries you create may reveal information about a person's mental or physical health, and audio recordings may be considered biometric information under the CCPA. We use this sensitive personal information only to provide the services you have requested. We do not use or disclose sensitive personal information for any purpose that would trigger the "Right to Limit" under California Civil Code §1798.121.
Your rights. Subject to the law of your state, you may:
- Know / Access: Request the categories and specific pieces of personal information we hold about you, and a copy in a portable format.
- Correct: Request correction of inaccurate personal information.
- Delete: Request deletion of your personal information (use Settings → Account → Delete Account in the app, or email us).
- Opt out of sale or sharing / targeted advertising / profiling: We do not engage in any of these activities, so no opt-out is required, but we will honor a request if you submit one.
- Limit use of sensitive personal information (California): we already limit such use to providing the service you requested.
- Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised these rights.
- Appeal (Virginia, Colorado, Connecticut, and similar states): if we deny a request, you may appeal by replying to our response email. If the appeal is denied, you may contact your state attorney general.
How to exercise these rights. Email the contact address in Section 13 from the address tied to your account. We verify identity by matching the request email to the account email. Authorized agents may submit requests with written authorization. We respond within 45 days, extendable by 45 more days where the law allows.
Shine the Light (California Civil Code §1798.83). We do not share personal information with third parties for their direct marketing purposes.
12 Changes
We may update this policy over time. Changes take effect when we update the effective date in the header. For material changes, we'll also surface an in-app notice on next launch.
13 Contact
Questions, requests, or complaints?
Data Protection Contact:
ozgekdioglu@icloud.com