Privacy Policy
Last updated: September 3, 2026
Coachbench is a workbench for professional coaches: client management, engagements, sessions, workshops, assessments and the coaching tools around them. This page explains what data we store, why, for how long, who else sees it, and how you can export or delete it.
What data we store
Each row is a data category with its underlying tables (technical evidence), its purpose, the proposed legal basis, the retention period, and its recipients.
- Account
- Your name, e-mail address and a hashed password (or a linked Google account) — Better Auth tables `user` / `account` / `verification`.
- Purpose: Sign-in and account recovery.
- Legal basis: Performance of the contract between the coach and Coachbench (Art. 6(1)(b) GDPR). Proposal — to be confirmed by counsel
- Retention: Until you delete your account (Settings → Privacy). Deletion removes the account row immediately; sessions and linked OAuth accounts cascade with it.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Organization
- Your workspace: name, logo, optional custom document branding, and the subscription plan/status (`organizations`, `organization_branding`, `subscriptions`).
- Purpose: Operating the workspace you subscribed to; billing.
- Legal basis: Performance of the contract between the coach and Coachbench (Art. 6(1)(b) GDPR). Proposal — to be confirmed by counsel
- Retention: Until the organization is deleted (sole owner deletes their account, or explicitly deletes the organization).
- Recipients: Hosting operator; a payment processor only once billing is actually enabled (no full card numbers are ever stored by Coachbench).
- Members and invitations
- Who belongs to your organization and at what role, plus pending seat invitations by e-mail (`memberships`, `org_invitations`).
- Purpose: Team access control.
- Legal basis: Performance of the contract between the coach and Coachbench (Art. 6(1)(b) GDPR). Proposal — to be confirmed by counsel
- Retention: Memberships until removed or the account/organization is deleted. Invitations until accepted, revoked or expired.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Outbound e-mail (invitations, reminders, password reset) is sent through the provider the operator has configured (SMTP or Resend) — a sub-processor only when mail is configured at all.
- Clients
- Master data of the people or organizations a coach works with: name, company, e-mail, phone, address, notes, tags, status, AI-processing consent, and the manual communication log (`clients`, `client_interactions`).
- Purpose: Running the coaching relationship (CRM).
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Until the coach deletes the client record. Deletion cascades to contacts, teams, communication log, engagements and — per the deletion preview shown before every delete — the personal data listed there; see “Your rights” below.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Contacts
- Named individuals at a client (sponsor, buyer, team lead, …): name, role, e-mail, phone, position, notes (`client_contacts`, `client_team_members`).
- Purpose: Knowing who to address within a client organization.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the client they belong to.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Teams
- A client's team roster grouping contacts (`client_teams`), used by team pulses and assessment campaigns.
- Purpose: Measuring the same group repeatably (e.g. before/after a workshop series).
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the client they belong to.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Engagements
- The container for a client relationship's lifecycle and light internal economics: title, objective, status, dates, contracted sessions, fee model/amount, notes (`engagements`).
- Purpose: Tracking a coaching engagement end to end.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the client they belong to (cascade already in place).
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Contracts
- Coaching agreements — bilateral coach↔client or triangle coach↔client↔sponsor — as template-driven form content (`contracts`).
- Purpose: Documenting what was agreed (scope, confidentiality, reporting rules).
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the client the contract is filed under; a contract with no client link is deleted with its project.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Sessions (incl. coach's private notes)
- Coaching session logs: template-driven content and the coach's CONFIDENTIAL private notes. Never included in any PDF/report; excluded by default from the client dossier export too, with an explicit, coach-only opt-in for the coach's own use (`sessions`, `session_templates` is the seeded, content-free template catalogue).
- Purpose: The coaching record itself.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted — including the coach's private notes — together with the client the session is filed under (previously such sessions merely lost their client link and survived; that gap is closed).
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Projects, activities and canvases
- Coaching/facilitation engagements across every tool (Design Thinking, Problem Solving, Leadership) with their phase progress and the content you type into method canvases and worksheets (`projects`, `project_phases`, `activities`, plus the Problem-Solving working tables `hypotheses`, `evidence_entries`, `ps_experiments`, `pdca_cycles`, `kata_storyboards`/`kata_steps`, `measures`, `accepted_causes`, `learn_logs`). Portfolio epic hypotheses (Scaling Workbench) reuse the same `hypotheses`/`evidence_entries`/`ps_experiments` tables, tagged `tool: portfolio_agility` — unlike the rest of this row, an epic hypothesis has NO project at all; it exists directly under the organization.
- Purpose: The actual coaching/facilitation work product.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Until the coach deletes the project (deletes everything listed here for that project) or, for a client-linked project, until the client is deleted (the project itself is kept and only unlinked; its content stays with the coach's own workspace). A portfolio epic hypothesis has no project to hang off: the coach deletes it directly on its own page (which also deletes its MVP experiment and evidence entries), otherwise it is kept until the organization itself is deleted.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Workshops, photos and participation
- Workshop agendas, decisions, actions, parking-lot entries and series (`workshops`, `workshop_items`, `workshop_decisions`, `workshop_actions`, `workshop_parking_entries`, `workshop_series`); uploaded flip-chart/room PHOTOS, which may show identifiable people (`workshop_photos` — for a photo flagged as showing identifiable people the uploader must confirm both storage and that the people shown consented to the photo being taken and used, and that confirmation is stored on the photo row with its time and the confirming account: `consent_confirmed_at`, `consent_confirmed_by_id`); and account-free participant input from live tools (dot voting, gradients, brainwriting, premortem) that is stored WITHOUT any identity, IP address or user agent by database design (`participation_links`/`participation_responses`, `participation_sessions`/`polls`/`poll_votes`/`submissions`).
- Purpose: Running and documenting facilitated workshops.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the workshop; photo bytes are erased explicitly (not only the metadata row) when an organization or account is deleted. A client link on a workshop is removed (not the workshop) when that client is deleted. The consent record of a photo lives and dies with that photo — it is proof about the photo, so it is never kept once the photo is gone, and never dropped while the photo remains.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Assessments, campaigns and responses
- One measurement occasion per subject (`assessment_campaigns`), tokenised rater invitations that never link back to a response (`assessment_invitations`), and the submitted answers themselves — attributable only to a rater CATEGORY, never a person, and released only once a minimum-response floor is met (`assessment_responses`). The instrument questions themselves (`instruments`/`instrument_items`) are shared platform content, not personal data.
- Purpose: 360°/self-assessment, feedback collection, Character-OS profiling.
- Legal basis: Consent of the rater/assessed person, given at the tokenised invitation (Art. 6(1)(a) GDPR); processed on behalf of the coach for anything client-scoped. Proposal — to be confirmed by counsel
- Retention: Deleted together with the client the campaign is filed under, or when the coach deletes it directly; a rater may also withdraw their own response via the one-time withdrawal link in their invitation.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Team pulses
- A thin before/after pairing of two team-pulse assessment campaigns for the same team (`team_pulses`); the actual responses live in the Assessments category above.
- Purpose: Showing the delta between two measurement occasions.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: The pairing record's client/team link is removed when that client is deleted; the pairing itself is kept as an org-level history record (its campaigns are deleted with the client per the Assessments row above).
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Sponsor objectives, three-way checkpoints and pulse responses
- Objectives the sponsor names for an engagement (`engagement_objectives`); the sponsor's own tokenised intake, never re-usable once submitted (`sponsor_intake_tokens`); the two contracted three-way checkpoints and the coach's own curated, releasable progress text for each objective — never a raw excerpt (`impact_checkpoints`, `impact_checkpoint_entries`); and the perceived-change pulse, whose responses carry a stakeholder CATEGORY (sponsor/manager/peer/direct report/other) but never an identity and only NUMBERS, never free text (`change_pulses`, `change_pulse_invitations`, `change_pulse_responses`). A task-only Character-OS blueprint (`character_os_task_blueprints`) also lives here — by construction it rates a TASK, never a person, and holds no personal data.
- Purpose: Proving coaching value to the sponsor within an agreed, curated boundary.
- Legal basis: Consent of the sponsor/stakeholder at the tokenised intake, where the legal basis and retention promised at that moment are snapshotted on the token itself (Art. 6(1)(a) GDPR); sponsors and stakeholders are named third parties who never consented to the coaching relationship as such. Proposal — to be confirmed by counsel
- Retention: Deleted together with the engagement, which is deleted together with its client. Independently of that, the retention window promised at the tokenised intake is now actually enforced by a scheduled sweep: the sponsor's own entries (intake token, non-adopted objectives, the free-text criterion and confidentiality boundary of adopted ones, and the sponsor's own rating in a three-way checkpoint) are erased once the engagement has ended plus the promised window (default 12 months); stakeholder pulse answers and invitations are erased on their own clock, the promised window after the answer was submitted. An adopted objective keeps its title, because from the agreement onwards it is engagement content the coach's own records hang on.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Decisions
- Versioned decision records: frame, options, criteria, assumptions, dissent, the chosen option and rationale, plus later outcome reviews (`decisions`, `decision_reviews`).
- Purpose: A durable, auditable decision trail for the engagement.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: A decision is a durable audit record: deleting its project or client REMOVES the link only, it never deletes the record itself — you can delete a decision directly instead.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient. Only reaches an AI provider when the coach actively uses a KI-Copilot feature AND — for anything client-scoped — the client's AI-processing consent is switched on; see “AI providers” below.
- Boards
- Kanban and matrix boards for team, programme, large-solution and portfolio flow (the Scaling Workbench, M1-E40): board instances, their columns, matrix rows, cards (title, description, size label) and dependency arrows between cards, plus an append-only log of every column move (`boards`, `board_columns`, `board_rows`, `board_cards`, `board_card_edges`, `board_card_transitions`). The board template catalogue itself (`board_templates`, `board_template_columns`) is shared platform content, not personal data.
- Purpose: Visualizing and moving work through the team/programme/portfolio flow stages of the Scaling Workbench.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted when the coach deletes the board (cascades to its columns, rows, cards, dependency arrows and movement log), or when the organization is deleted. For a client-linked board, deleting the client REMOVES the link only (`boards.client_id` is set to null) — the board itself is kept and its content stays with the coach's own workspace, the same as a client-linked project or workshop.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Archived cases
- A closed Problem-Solving engagement's durable memory: copied title, tags, methods used, and free-text cause/solution summaries — deliberately DENORMALIZED so the record survives the deletion of the project or learn log it came from (`case_archives`).
- Purpose: Organizational memory and case-similarity hints for future engagements.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: When the client is deleted the client LINK is removed (anonymized) — the archive row itself is kept as organizational memory. This does NOT automatically scrub the client's name or other identifying detail from the free-text summary/tag fields if the coach typed one in; edit or delete the archive entry directly for that.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Development goals, journals and nudges
- The Development Engine: goals, if-then/WOOP experiments, GAS ratings, Immunity-to-Change maps (`goals`, `experiments`, `gas_ratings`, `immunity_maps`); the client's OWN reflection journal, reachable via a capability-token link and structurally excluded from every sponsor/report surface (`journal_entries`, `journal_tokens`); and scheduled transfer/review e-mail nudges with their unsubscribe list (`transfer_nudges`, `nudge_suppressions`). Seeded program templates (`program_templates`) are platform content, not personal data.
- Purpose: Longitudinal development tracking and transfer support between sessions.
- Legal basis: Processed on behalf of the coach, who is the data controller for their own clients (Art. 28 GDPR processor relationship). A data processing agreement (DPA) between the operator and each coach is a legal prerequisite that has not yet been reviewed or signed. Proposal — to be confirmed by counsel
- Retention: Deleted together with the project it hangs off; a project stays with the coach's own workspace when its client is deleted, so this data is not touched by a client deletion unless the coach also deletes the project.
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- AI audit metadata
- WHO called WHICH AI feature, WHEN, with which model and how many tokens — deliberately content-free: neither table has a prompt or response column (`ai_invocations`, `copilot_audit_logs`).
- Purpose: Cost transparency, abuse detection, EU-AI-Act accountability.
- Legal basis: Legitimate interest in operating and securing the AI features responsibly (Art. 6(1)(f) GDPR). Proposal — to be confirmed by counsel
- Retention: Until the organization is deleted; not user-deletable individually (it is the accountability record itself).
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
- Technical session data
- Login sessions needed to keep you signed in, including IP address and browser user-agent (Better Auth `session` table); a content-free, best-effort adoption log of which feature was used, with no free text or names (`usage_events`).
- Purpose: Keeping you signed in; product-usage insight for the operator.
- Legal basis: Performance of the contract (staying signed in, Art. 6(1)(b) GDPR) and legitimate interest in security and product operation (Art. 6(1)(f) GDPR). Proposal — to be confirmed by counsel
- Retention: Sessions until sign-out or expiry, and in any case until the account is deleted (cascade).
- Recipients: The hosting operator only (see “Where your data is stored” above); no other recipient.
Where your data is stored
Server location: self-hosted in the EU — to be confirmed by the operator. This placeholder is deliberately left in place until the operator enters the actual hosting location of this instance. We do not sell your data or share it with third parties for advertising.
AI providers
AI features require explicit, per-client consent (see "Your rights" below) and run server-side over minimized, allowlist-checked excerpts — never raw data. Each row shows what an AI feature actually sends and what the provider retains afterward.
Editorial Coach
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
Only the problem description and the answers the coach typed into the Socratic dialogue are sent. No client master data, no CRM fields.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Problem Solving — AI copilot
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
Allowlisted fields only (problem statement, cause labels, decision frame, revealed premortem reasons). Participant names and identities are never sent; premortem reasons are read only after the round is closed and revealed.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Leadership — AI copilot
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
A minimized, org-scoped project context (goals, GAS ratings, recent protocol excerpts). Journal entries are never fetched; pattern analysis additionally requires a per-project opt-in.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Facilitation — AI copilot
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
Coach-view data only: the facilitator's own agenda and observations, plus a server-injected method catalogue. No participant data and no anonymous-vote content reach the model.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Client-prep brief
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
Allowlisted fields from exactly two sources: decision-audit outcomes (title, status, open concerns) and assessment score deltas (dimension keys and numeric means). Reflection-journal content and raw session free-text are never read; deltas appear only above the anonymity floor; the client's identity is never sent.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Sponsor report — wording assistance
Anthropic PBC (EU-Standardvertragsklauseln / EU SCCs)
Only the already-released sponsor report model: the contracted objective titles, the coach's own curated progress text, and min-n-suppressed aggregate means. Session content, journal entries and individual stakeholder answers are never read, so they cannot be sent; suppressed figures reach the model as nulls, never as numbers.
No prompt or model output is stored by the platform. Only content-free metadata (org, user, feature, model, token counts, timestamp) is retained for accountability and cost reporting. The provider does not train on API data.
Transfer to Anthropic PBC (USA) under the EU Standard Contractual Clauses (SCCs). A dedicated data processing agreement with this provider is a legal review item, not yet reviewed or signed.
Why we process your data
Two different roles, not one: for account, organization and billing data, Coachbench is itself the controller (performance of the contract with you as a coach, Art. 6(1)(b) GDPR). For your clients' data — master data, sessions, workshops, assessments and everything else you record about them — the coach is the controller, and Coachbench processes it on the coach's behalf (Art. 28 GDPR). A data processing agreement between operator and coach is a prerequisite for that, but has not yet been reviewed or signed. The precise legal basis per category is in the data catalog above.
How long we keep it
We keep your data for as long as your account and organization exist. Deleting a client deletes their sessions (incl. the coach's private notes), contracts, sponsor objectives and responses, three-way checkpoints, pulse responses, contacts, teams, communication log entries, and campaigns with their responses; archived cases are anonymized (the client link is removed, free text is left as-is unless edited separately); projects are kept and only unlinked. The preview shown before every deletion states the exact counts. Backups, where they exist, are rotated on a limited schedule and are not separately scrubbed.
Your rights: access, rectification, export and deletion
Access and portability: from Settings → Privacy you can export a complete JSON copy of your organization at any time; every client page also offers a complete client dossier export. Rectification: all master data can be edited directly in its forms. Deletion: you can delete a single client (with a preview of what is deleted, what is anonymized, and what is only unlinked), delete your organization entirely, or delete your whole account. Deletion is immediate and cannot be undone. Withdrawing AI consent: the toggle on every client page. If you are in a region with statutory data rights (e.g. GDPR access, rectification, erasure, restriction and portability), these controls are how you exercise them; contact us for anything the self-service tools do not cover — in particular a request from a client who is not themselves a user of the platform: please forward it to your coach, who responds as the controller.
Restriction of processing (Art. 18 GDPR) and objection to processing (Art. 21 GDPR) are deliberately not exposed as switches in the application: please assert these two rights with your coach as the controller. They decide on them and arrange for them to be carried out; the operator acts only on their instruction in this respect. If your request concerns your own account and your own organisation, use the contact given below instead.
Contact
Placeholder — to be filled in by the operator before production use: operator name/company, postal address, contact e-mail for privacy requests and, where applicable, a data protection officer's contact details. Until then, direct privacy questions the in-app tools do not cover to the operator of your Coachbench instance.