Documentation

Security and privacy

CoachFile stores the real, sensitive things your clients say, so we treat that responsibility seriously. The short version:

  • Your data is encrypted in transit with TLS 1.3 and at rest with AES-256.
  • Each coach's data is isolated at the database level. One coach cannot reach another coach's data, and that isolation is checked by automated tests on every change.
  • No one on our side has standing access to your client notes. Access happens only when you authorize it or the law compels it, and both are logged.
  • We do not sell your data, do not use it for advertising, and do not use your client records to train AI models.
  • You can export or delete all of your data at any time.

For the full detail, see our Security page and our Privacy Policy. CoachFile is built for non-clinical coaching and is not HIPAA-compliant; the boundaries are in our Terms of Service.