CoachTide
Trust and security

Trust and security

Your clients trust you with a lot. Here is how we look after it.

CoachTide holds your client records, session notes, agreements and invoices. This page explains, in plain terms, where that information lives, who can see it, and how it is protected. It also says plainly what we do not have yet.

Last updated October 2026. The legal version is our privacy policy.

The short version

Six things worth knowing

Stored in Canada

Your records are stored at rest in Canada, in the Montreal region.

Walled off from every other coach

Each practice is kept separate by the database itself, not only by the app, so one coach can never reach another coach's clients.

Two-step sign-in

Add a code from an authenticator app to your sign-in. It is required for everyone on the CoachTide team.

We cannot browse your records

Our staff see counts, like how many clients you have. Looking inside your practice takes your permission, for 72 hours at most.

Card numbers never touch us

Payments go through Stripe, on your own account. You are the merchant, and CoachTide never stores card details.

Yours to take, or to delete

Export your data whenever you like. Delete your account and it is permanently removed after a 30-day window in which you can change your mind, apart from records the law requires us to keep.

01

Where your data lives

Your account and everything you enter, such as clients, sessions, notes, goals, agreements and invoices, is stored at rest in Canada, in the Canada Central (Montreal) region.

Some processing runs on servers in the United States, and some of the services we rely on operate internationally, so your data may travel outside Canada while CoachTide does its work. We handle personal information in a manner consistent with PIPEDA and British Columbia's PIPA.

02

How it is protected

  • Encrypted in transit and at rest. Everything travels over HTTPS, and our hosting provider encrypts it where it is stored.
  • Keys to your other accounts, locked away. The Stripe and PayPal keys you connect and your Google Calendar connection are encrypted a second time and kept in a separate vault. The database holds only a pointer to each one, so a copy of it on its own would not reveal them. Only our server can unlock a key, at the moment it needs it to take a payment or update your calendar. No signed-in browser can read one back, yours included: once a key is saved, the app only shows that it is there. Disconnect it and the stored key is deleted. The connections our own team uses are kept the same way. Card numbers never reach us: Stripe holds them.
  • Separation the database enforces. Before any record comes back, the database itself checks that it belongs to a practice you are part of. A mistake on one screen cannot hand you someone else's data.
  • Background jobs kept to one practice. A few jobs run without anyone signed in, such as sending reminders or taking a scheduled payment. Each one works on a single practice at a time, and every one is listed in a security record we keep up to date.
  • Two-step sign-in that means it. It is optional for coaches. Once you turn it on, a sign-in that skipped the second step gets none of your records at all. Everyone on the CoachTide team must use it.
  • No passwords needed for your clients. Clients reach their portal through single-use sign-in links sent to their own email address, and can sign themselves out of every device at once. Someone who only pays a client's invoices gets the invoices, never a way into the portal.

03

Who can see what

YouEverything in your practice.
Teammates you inviteYour clients, sessions and notes, plus the extra areas you switch on for them, such as billing or settings. Key actions, such as exports, permission changes, money changes and client deletions, are recorded in a log only the owner can read, and nobody can edit.
Your clientsOnly their own sessions, invoices, goals, messages and shared documents, in their portal.
CoachTide staffYour name, email and plan, plus counts: how many clients, sessions and invoices you have, and when you last signed in. Nothing inside your client records. We can look inside your practice only if you grant support access from a help request. It ends after 72 hours, you can withdraw it sooner, and every use is logged.

04

Payments

Clients pay you through Stripe, on your own Stripe account, or through your own PayPal account if you connect one. You are the merchant, and CoachTide never takes a cut.

Card details are held by the payment processor, never by us. When a client saves a card for automatic payments, they agree to it first, and we keep only the card brand, its last four digits and its expiry date.

05

AI features

When you ask the in-app Guide a question, what you type goes to our AI provider, Anthropic, only to answer it. When AI helps you import a spreadsheet, it sees only the file's structure, such as the column headings, never your clients' names, emails, notes or amounts. When AI drafts or rewrites your coach website, it sees your business details, your booking types and packages, your voice settings, and the text you ask it to rewrite, never client information. When a client uses AI help to put a reflection into words for their takeaways, only that reflection and the list's title go to Anthropic, without the client's account details, and CoachTide does not store the reflection.

In every case our AI provider keeps nothing after the answer, apart from the results of its automated safety checks and anything it must keep by law or to look into misuse, and nothing is used to train AI models. The AI features cannot browse the records stored in your practice; they see only what is described here.

CoachTide saves your Guide conversations in your practice, with the rest of your data. Our team reads one only when you send it to support, when the Guide could not answer it from our help articles, or when you grant support access.

06

The services we rely on

Each one handles only what it needs to do its job. We do not sell your information.

The full list, with what each one does and where it works, is on our sub-processors page.

SupabaseDatabase, sign-in and file storage. Stored in Canada (Montreal).
VercelRuns the app itself, and carries AI requests to Anthropic. Servers in the United States.
ResendDelivers the emails CoachTide sends for you.
Stripe and PayPalTake payments, on your own accounts.
TwilioSends text reminders from a shared CoachTide number. Nothing is texted until you switch text reminders on for your practice, and then only to clients who have agreed to receive them. A client can reply STOP at any time.
AnthropicPowers the in-app Guide, import help, website writing, and takeaways help for clients. Keeps nothing but its safety check results, and trains on nothing.
GoogleYour calendar, if you connect it; spam protection on our forms; and visitor counts on our public pages only, never inside the app.

Straight answers

What we do not claim

Security pages tend to promise a lot. Here is what we do not have, so you can decide with the full picture.

No certification of our own, yet

CoachTide does not hold SOC 2 or ISO 27001 certification. Supabase and Vercel, which host your data, each hold SOC 2 Type II reports.

No outside security test, yet

We have not yet had an independent firm test CoachTide for weaknesses. We plan to before CoachTide leaves beta, and we will say so here once it is done.

Not end-to-end encrypted

CoachTide has to read your records to send reminders and invoices for you, so it cannot be. Your data is encrypted in transit and at rest.

Not for medical records

CoachTide is built for coaching, not clinical care, and is not a HIPAA-covered service. Keep health records in a system made for them.

Found a problem? Tell us.

If you think you have found a security issue in CoachTide, email us and please give us a chance to fix it before sharing it publicly. We read every report and will reply within 3 business days.

security@coachtide.com

What to include, what we promise, and what is out of scope: how to report a security problem.

Questions about your data: privacy@coachtide.com