CoachBeacon logo

CoachBeacon

CoachBeacon is the all-in-one operating system for fitness coaches. Coaches plan nutrition and workouts, track client check-ins and progress, send WhatsApp reminders, analyze blood reports, and run their entire coaching business in one system.

Loading CoachBeacon...

Privacy Policy  ·  Terms of Service

Privacy Policy

Last updated: June 23, 2026

Effective date: January 1, 2025

1. Introduction

CoachBeacon ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our coaching client portal, workout logging tools, Google Sheets Add-on, and related services.

This policy applies to all users of CoachBeacon, including:

  • Coaches: Fitness professionals who use CoachBeacon to manage clients
  • Clients: Individuals who access their coaching plans through the portal
  • Website visitors: Anyone who visits coachbeacon.in

CoachBeacon operates from India and is committed to handling personal data in line with India's Digital Personal Data Protection Act, 2023 (the DPDP Act). Section 16 explains our roles under the DPDP Act, your rights as a Data Principal, and how to reach our Grievance Officer.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Name, email address, phone number (for coaches during onboarding)
  • Portal Configuration: Coach branding (logo, accent color), business name, portal URL slug, feature settings
  • Communication: Messages sent to support, feedback, and inquiries

2.2 Information Collected Automatically

  • Device Information: Browser type, operating system, screen resolution
  • Usage Data: Pages visited, features used, time spent on pages
  • Log Data: IP address, access times, error logs for debugging
  • Cookies: Session cookies for authentication (no third-party tracking cookies)

2.3 Information from Google Services

When you authorize CoachBeacon through Google OAuth, we access:

  • Email Address: For user identification and authentication
  • Basic Profile: Name and profile picture (for display purposes)
  • Google Sheets Data: Client meal plans, workout schedules, and progress data stored in your designated coaching spreadsheet
  • Google Drive (Coaches only): To copy template files during initial onboarding setup
  • Google Meet (Coaches & team members only): Permission to create Google Meet meeting spaces on your behalf when you start a one-click client video call. We only create the meeting and receive its join link and code — we never access meeting content, recordings, transcripts, or participant lists

3. Google API Data Disclosure

This section specifically addresses our use of Google APIs and complies with the Google API Services User Data Policy, including the Limited Use requirements.

3.1 OAuth Scopes We Request

Scope Purpose User Type
openid Authenticate your identity All users
email Identify you and match to your coach All users
profile Display your name in the portal All users
spreadsheets Read/write coaching data in Google Sheets Coaches & Clients
drive Copy template files during onboarding setup Coaches only
meetings.space.created Create Google Meet video call spaces on your behalf for one-click client calls Coaches & team members only

3.2 How We Use Google Data

  • Client Portal: Read your Google Sheet in real-time to display personalized plans - data is rendered on-demand and NOT permanently stored on our servers
  • Coach Onboarding: One-time file copy to your Drive during initial setup; files are created in YOUR Drive using YOUR storage quota
  • Authentication: Verify identity and maintain secure session
  • Writing Portal URL: After setup, we write your unique portal URL back to your spreadsheet cell
  • Instant Meet Calls: When a coach or team member starts a call, we create a Google Meet meeting space via the Google Meet REST API and share the join link with the coach and their client (WhatsApp/email). This scope is create-only: we cannot read call audio or video, recordings, transcripts, or any meetings created outside CoachBeacon

3.3 Limited Use Disclosure

CoachBeacon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only use Google data for the purposes described in this policy
  • We do NOT sell, rent, or lease Google user data to any third party
  • We do NOT use Google user data for advertising, marketing, or profiling purposes
  • We do NOT allow humans to read Google user data except:
    • With explicit user consent for support purposes
    • For security investigations or legal compliance
    • When aggregated and anonymized for internal analytics
  • We do NOT transfer Google data to AI/ML models for training purposes

3.4 Data Retention & Deletion

  • Google Sheet Data: Read in real-time on each request; NOT cached or stored on our servers
  • Google Meet: Only the meeting link and code are processed to deliver call invites; call content, recordings, and transcripts are never accessed or stored
  • OAuth Tokens: Encrypted and stored securely; automatically expire and require re-authorization
  • Revocation: You can revoke access anytime via Google Account Permissions
  • Upon Revocation: We immediately lose all access to your Google data; cached session tokens are invalidated

4. Google Sheets Add-on

CoachBeacon is also available as a Google Workspace Add-on for Google Sheets, providing automation directly within your spreadsheet environment.

4.1 Add-on Permissions

When you install the CoachBeacon Sheets Add-on, it requests access to:

  • Google Sheets: Read and write data in your coaching spreadsheet (Client_Tracker, Assessment, Update sheets)
  • Google Drive: Copy client planner templates and manage folder structures
  • Gmail (send only): Send notification emails when new clients are onboarded or updates are received
  • External URLs: Communicate with coachbeacon.in for license validation and account sync
  • Script Triggers: Install form submission and edit triggers for automation

4.2 Add-on Data Processing

  • The add-on processes form submissions locally within your Google account
  • Client data (names, emails, phone numbers) is stored ONLY in your own Google Sheets
  • License validation sends only your coach slug to our servers - no client data is transmitted
  • Email notifications use your Google account's email quota, not ours
  • All spreadsheet operations occur within Google's infrastructure

4.3 What We DO NOT Access via Add-on

  • Other spreadsheets in your Drive (only the installed spreadsheet)
  • Your email inbox or sent emails
  • Your Google contacts, calendar, or other Google services
  • Files outside the coaching folder structure

4.4 Uninstalling the Add-on

You can uninstall the add-on at any time via Extensions → Add-ons → Manage add-ons. Uninstalling removes all triggers and permissions but preserves your spreadsheet data intact.

5. How We Use Your Information

We use collected information for the following purposes:

5.1 Service Delivery

  • Display your personalized workout and nutrition plans
  • Enable real-time data sync between coaches and clients
  • Process workout logs and track fitness progress
  • Send service notifications (check-in reminders, account updates)
  • Send WhatsApp check-in reminders via Meta WhatsApp Cloud API (only if the client has opted in)

5.2 Service Improvement

  • Analyze usage patterns to improve features (anonymized/aggregated)
  • Debug technical issues and fix bugs
  • Develop new features based on user needs

5.3 Communication

  • Respond to support inquiries
  • Send account and service-related notifications
  • Share platform updates and announcements (not marketing emails)

6. Data Storage & Security

6.1 Where Data is Stored

  • Google Sheets Data: Remains in YOUR Google account; we only read and display it
  • Workout Logs: Stored in our secure PostgreSQL database (Supabase)
  • Coach/Client Metadata: Stored in our PostgreSQL database
  • Authentication Tokens: Encrypted and stored in our database; session tokens stored locally in your browser
  • Uploaded Photos: Stored in Cloudflare R2 (cloud object storage)
  • My Link / Bio Page Configuration: Coach branding, theme settings, links, testimonials, and lead-form configuration stored in our PostgreSQL database. Lead submissions (name, phone, email, goals, source) are written to the coach's own Google Sheet and an instant notification email is sent to the coach. Lead data is visible only to the coach and their team
  • Invoice Generator Data: Invoice configuration (business name, GSTIN, bank details, branding), saved packages, and invoice history (line items, amounts, status) are stored in our PostgreSQL database. Invoice PDFs are generated on demand and not permanently stored on our servers. Invoice data is visible only to the coach who created it
  • Blood Report PDFs: Uploaded files are sent directly to Google Gemini for AI parsing and are NOT permanently stored on our servers; the extracted biomarker data is returned to the client and displayed in-portal only
  • Health Connect Data (Android): Step counts read from Google Health Connect on the device; used to auto-fill daily check-in forms. Step data is NOT uploaded to or stored on our servers - it is processed entirely on-device
  • Error & Crash Reports: We use Sentry for error tracking. Sentry collects device type, OS version, browser/app version, and error stack traces. No personally identifiable information (name, email, phone) is sent to Sentry
  • Free Tools (coachbeacon.in/tools): All 47 public calculators require no login and store no user data - all calculations happen locally in the browser

6.2 Security Measures

  • Encryption in Transit: All data transmitted via HTTPS/TLS 1.3
  • Encryption at Rest: Database encryption for sensitive fields
  • Password Hashing: bcrypt with salt for any stored passwords
  • Access Controls: Role-based access; coaches only see their own clients
  • Rate Limiting: Protection against brute-force attacks
  • Security Headers: Helmet.js for HTTP security headers, CORS restrictions
  • Regular Audits: Periodic security reviews and dependency updates

For a full description of our technical and organizational security measures, see our Reasonable Security Safeguards document.

6.3 Data Retention Periods

Data Type Retention Period
Workout Logs Indefinite (until account deletion)
Coach Account Data Until account deactivation + 12 months
Client Portal Sessions 90 days from last access
OAuth Tokens Until revoked or expired
Server Logs 30 days
Error/Crash Reports (Sentry) 90 days
WhatsApp Send Logs 12 months
Support Records 2 years from last interaction

7. Data Sharing

We do NOT sell, trade, or rent your personal information. We share data only in these limited circumstances:

7.1 With Your Coach

  • Clients: Your workout logs, progress, and submitted updates are visible to your assigned coach
  • This sharing is fundamental to how the coaching service works

7.2 Service Providers

  • Resend: Email delivery for service notifications
  • Meta (WhatsApp Cloud API): WhatsApp messaging for opted-in check-in reminders (phone number shared only when client opts in)
  • Telegram (Bot API): Group chat reminders via @coachbeacon_bot. We collect and store the coach's Telegram user ID and the Telegram group chat ID in our coaching Google Sheet to deliver automated reminders. No Telegram messages are stored on our servers beyond a delivery log (status, scheduled time, sent time) kept for operational diagnostics. See Section 14 for full Telegram disclosure.
  • Supabase: Database hosting
  • Cloudflare: CDN, DDoS protection, photo storage
  • Firebase: Application hosting, Firestore document storage, and push notification delivery (FCM)
  • Sentry: Error and crash reporting for service reliability (no PII transmitted)
  • Google Cloud: Google Sheets API, OAuth services
  • Google Gemini (AI): Blood report PDF parsing and personalised recipe generation. Data sent to Gemini is used solely to generate a response and is not used to train Google's models. See Section 13 for full AI disclosure.

7.3 Legal Requirements

  • When required by law, subpoena, or court order
  • To protect our rights, property, or safety
  • To prevent fraud or illegal activity
  • In connection with a merger, acquisition, or sale of assets (with user notice)

8. Your Rights

As a Data Principal under India's Digital Personal Data Protection Act, 2023 (the DPDP Act), you have the following rights regarding your data. Coaches and team members can exercise these by contacting CoachBeacon support. Clients exercise these rights through their coach, who is responsible for their data and holds their consent; CoachBeacon support can help route a request to the coach. See Section 16 for full DPDP details.

8.1 Access & Portability

  • Request a copy of your personal data
  • Export your workout logs in machine-readable format
  • View all data we have about you

8.2 Correction

  • Request correction of inaccurate personal data
  • Update your profile information through the portal

8.3 Deletion

  • Request deletion of your personal data
  • Coaches: Contact support@coachbeacon.in to delete your account
  • Clients: Contact your coach to remove you from their system
  • Some data may be retained for legal compliance (support and account records)

8.4 Revoke Access

  • Revoke Google account access anytime via Google Account Permissions
  • Uninstall the Google Sheets Add-on to remove all triggers and permissions

8.5 Withdraw Consent

  • Withdraw your consent at any time, as easily as you gave it
  • Withdrawal applies going forward and does not undo processing already carried out lawfully
  • Some records, such as consent and billing history, are kept for as long as the law requires

9. Cookies & Tracking

9.1 Cookies We Use

  • Session Cookies: Essential for authentication; expire when you close browser or after inactivity
  • Preference Cookies: Remember your settings (theme, language)

9.2 What We DON'T Use

  • Third-party tracking cookies (Google Analytics, Facebook Pixel, etc.)
  • Advertising cookies
  • Cross-site tracking

10. Children's Privacy

CoachBeacon is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal information, we will delete it immediately. If you believe a child has provided us with personal data, please contact us at support@coachbeacon.in.

Under the DPDP Act, the personal data of a child (anyone under 18) may be processed only with the verifiable consent of a parent or legal guardian. Where a coach chooses to work with a client under 18, the coach is the Data Fiduciary for that client and is responsible for obtaining and keeping that parental or guardian consent. CoachBeacon cannot verify the real age of the people a coach adds, so this duty stays with the coach.

11. International Data Transfers

CoachBeacon is operated from India. Your data may be processed in:

  • India: Primary operations and support
  • United States: Cloud infrastructure (Firebase, Supabase, Cloudflare)
  • European Union: Some CDN edge nodes

By using our services, you consent to the transfer of your data to these locations. We ensure appropriate safeguards are in place for international data transfers.

12. Push Notifications & Email Data

CoachBeacon uses push notifications and email for coach-client communications. This section explains how we handle notification-related data.

12.1 Data We Process

  • Push Subscription Tokens: Browser push notification subscriptions for reminder delivery
  • Email Addresses: Coach and client emails for notification delivery
  • Notification Delivery Status: Sent and failed statuses for service quality
  • Consent Records: When and how notification consent was granted or withdrawn

12.2 How We Use Notification Data

  • Deliver plan reminders and check-in notifications to clients
  • Send service updates and account notifications to coaches
  • Track delivery status for service quality improvements
  • Provide opt-out mechanisms when requested

12.3 What We Do NOT Do

  • We do NOT sell or share notification data with advertisers
  • We do NOT send marketing or promotional messages
  • We do NOT use notification data for profiling or targeting
  • We do NOT store notification content beyond delivery confirmation

12.4 Lawful Basis

We process notification data based on: (a) Explicit consent from users when enabling push notifications, (b) Legitimate interest in providing service notifications, and (c) Contractual necessity to deliver agreed-upon features.

13. AI Features & Gemini Disclosure

CoachBeacon uses Google Gemini, a generative AI service, to power two specific features: blood report analysis and personalised recipe generation. This section explains exactly how Gemini processes your data.

13.1 Blood Report PDF Parsing

  • Clients can upload a blood report PDF through their portal. This file is sent to Google Gemini to extract biomarker values (e.g. haemoglobin, B12, ferritin, TSH).
  • The PDF is sent directly to Gemini's API and is NOT stored on CoachBeacon servers. Only the extracted structured data (biomarker names and values) is returned and displayed in the portal.
  • The extracted data is visible to the client and their assigned coach. It is not shared with any other party.
  • Uploading a blood report is entirely optional. The feature requires explicit client action - no automatic uploads occur.

13.2 AI Recipe Generation

  • Clients can request AI-generated recipes based on their food plan ingredients, calorie targets, and dietary preferences set by their coach.
  • Only the plan parameters (ingredient names, macro targets, dietary flags) are sent to Gemini. No personally identifiable information (name, email, phone number) is included in the AI request.
  • Generated recipes are displayed directly to the client and are not stored permanently on our servers.

13.3 Gemini Data Use Policy

  • Data submitted to Gemini via the API is not used to train Google's AI models (per Google's API terms)
  • We do not use Gemini to process any data obtained via Google OAuth (Sheets, Drive, Gmail) - those are kept strictly separate
  • We do not use AI to make automated decisions that legally or significantly affect users
  • You can choose not to use AI features at any time; they are opt-in actions, not background processes

13.4 ScanBeacon (Supplement Label Analyzer)

  • ScanBeacon operates as a separate Telegram bot that analyses supplement labels submitted by users (photo or text). The submitted image or ingredient text is sent to Google Gemini for analysis. The PDF report is delivered back to the user inside Telegram and forwarded to the admin Telegram for visibility.
  • Only the supplement label image/text is sent to Gemini. No personally identifiable information is included in the request. Submitted images are not permanently stored on CoachBeacon servers beyond the active analysis session.
  • Per-user scan history (product name, scan date, total scans) is stored in a Google Sheet for quota enforcement and audit. Access is invite-only via redeemable codes.

13.5 ScriptBeacon (Coaching Script Generator)

  • ScriptBeacon is an in-portal tool that uses Google Gemini to draft long-form coaching scripts (lead replies, retention messages, missed-check-in nudges, doctor-coach communications) on demand.
  • Only the prompt parameters (scenario, tone, persona, optional context entered by the coach) are sent to Gemini. No client personal data is included in the request unless the coach explicitly types it into the prompt - and we recommend keeping prompts generic.
  • Generated scripts and their input parameters are saved to the coach's history for re-opening, stored in our PostgreSQL database. Coaches can delete history entries at any time from the portal.
  • Access is gated by a per-coach monthly quota. Quota usage is tracked for billing and audit.

13.6 Free Public Tools (coachbeacon.in/tools)

CoachBeacon offers 47 free fitness calculators at coachbeacon.in/tools. These tools require no login and collect no personal data. All calculations run entirely in your browser. No inputs, results, or usage data are sent to our servers. These tools are available to anyone with no account required.

14. Telegram Group Bot (@coachbeacon_bot)

CoachBeacon operates a Telegram bot (@coachbeacon_bot) that coaches can deploy into client group chats to deliver automated coaching reminders. This section discloses exactly what data is collected and how it is used.

14.1 Data We Collect via Telegram

  • Telegram User ID (coach only): Collected when a coach sends a /start message to @coachbeacon_bot in a private DM, used to link the coach's CoachBeacon account to their Telegram identity. This ID is stored in the coach's own Google Sheet (tgb_coaches tab).
  • Telegram Group Chat ID: Collected when a coach adds @coachbeacon_bot to a client's Telegram group. Used to identify which group receives which scheduled reminders. Stored in the coach's Google Sheet (tgb_groups tab).
  • Group Configuration Settings: Water goal (litres), daily reminder frequency, active/inactive status, group name - all stored in the coach's Google Sheet. No client names or phone numbers are stored by the bot.
  • Message Delivery Log: A record of each scheduled message (type, scheduled time, sent time, delivery status) is stored in the coach's Google Sheet (tgb_message_log tab) for operational diagnostics and deduplication. Message content is not logged.

14.2 How We Use Telegram Data

  • Routing scheduled reminder messages to the correct Telegram group chat
  • Deduplication - preventing duplicate sends if a scheduled job re-runs
  • Linking a coach's CoachBeacon account to their Telegram user for bot command authorization
  • Allowing coaches to pause, resume, or reconfigure reminders per group

14.3 What We Do NOT Do with Telegram Data

  • We do NOT read, store, or process any messages sent by users inside the group chat
  • We do NOT collect the names, usernames, phone numbers, or profile photos of group members
  • We do NOT sell, share, or use Telegram data for any purpose other than reminder delivery
  • We do NOT use Telegram data to train AI models
  • The bot only sends outgoing reminder messages - it does not scrape or monitor group activity

14.4 Data Storage & Deletion

  • All Telegram-related data (coach Telegram ID, group chat IDs, delivery logs, configuration) is stored in the coach's own Google Sheets - under their own Google account using their own storage quota
  • No Telegram data is permanently stored on CoachBeacon servers beyond in-memory processing during message dispatch
  • Coaches can delete bot data by removing the bot from any group and clearing the relevant rows from their Google Sheet
  • Revoking Google OAuth access immediately terminates CoachBeacon's ability to read or write Telegram data in the Sheet

14.5 Telegram API Compliance

@coachbeacon_bot operates strictly within Telegram's Bot API terms of service. The bot is an admin-only tool controlled entirely by coaches. Client group members can leave any group at any time to stop receiving messages. Coaches can remove the bot from any group at any time via Telegram group settings.

15. Android Mobile App

CoachBeacon is available as an Android app. The app wraps the same web portal in a native shell using Capacitor, with additional native features described below.

15.1 Health Connect Integration

  • The app can request permission to read step count data from Google Health Connect on your device.
  • Step data is read on-device only and used to auto-fill the daily check-in form. It is NOT uploaded to or stored on our servers.
  • Health Connect access is optional and requires explicit user permission. You can revoke it anytime in Android Settings → Apps → CoachBeacon → Permissions.
  • We do NOT access heart rate, sleep, weight, blood pressure, or any other Health Connect data category - only steps.

15.2 Permissions Requested

Permission Purpose
INTERNET Connect to CoachBeacon servers
CAMERA Take progress photos for check-ins
READ_MEDIA_IMAGES Select existing photos for upload
health.READ_STEPS Read step count from Health Connect (optional)

15.3 Data Collected by the App

  • The Android app does NOT collect any data beyond what the web portal collects (described in Sections 2 and 6).
  • No background data collection occurs. The app only communicates with our servers when you are actively using it.
  • Crash reports are sent to Sentry (see Section 6.1) and contain no personally identifiable information.

16. Indian Data Protection (DPDP Act, 2023) & Grievance Redressal

CoachBeacon operates from India and handles personal data in line with India's Digital Personal Data Protection Act, 2023 (the DPDP Act) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

16.1 Our Roles Under the DPDP Act

  • Your account data: CoachBeacon is the Data Fiduciary. We decide how it is used to run the platform, and we answer for it directly.
  • A coach's client data: the coach is the Data Fiduciary and CoachBeacon is only the Data Processor. The coach decides what is collected and why; we store and process it solely on the coach's instructions.
  • Clients do not give CoachBeacon a separate consent. The coach is the responsible party and holds each client's consent.

16.2 Grievance Officer

In accordance with the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer:

Grievance Officer: Shubham Modi

Email: support@coachbeacon.in

Phone: +91 808-404-1998

Address: 304B Shiv Sarovar Apartment, School Road Purani Ranchi, Jharkhand 834001

16.3 Your Rights as a Data Principal

  • Access: ask for a copy of the personal data held about you
  • Correction: fix anything that is wrong, out of date, or incomplete
  • Erasure: ask for your data to be deleted once it is no longer needed (subject to legal retention requirements)
  • Withdraw consent: take back your consent at any time, as easily as you gave it (withdrawal applies going forward)

Coaches and team members can exercise these rights by contacting CoachBeacon support. Clients exercise these rights through their coach, who holds their data and consent; CoachBeacon support can help route a request to the coach.

16.4 How to File a Privacy Complaint

  • Email your complaint to support@coachbeacon.in
  • Include your registered email, description of the privacy concern, and evidence
  • You will receive acknowledgment within 24 hours
  • Investigation and resolution within 15 days (30 days for complex issues)

16.5 Data Protection Board of India

If your concern is not resolved to your satisfaction, you have the right to raise a complaint with the Data Protection Board of India.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes:

  • We will update the "Last updated" date at the top
  • For material changes, we will notify you via email or in-app notification
  • Continued use of the service after changes constitutes acceptance

18. Contact Us

For questions, concerns, or requests regarding this Privacy Policy:

CoachBeacon Fitness Portal

Email: support@coachbeacon.in

Phone: +91 808-404-1998

Address:

304B Shiv Sarovar Apartment, School Road Purani Ranchi

Old Mukti Gas, Ranchi G.P.O., Jharkhand, PIN: 834001, India

We aim to respond to all privacy-related inquiries within 48 hours on business days.