Trust and security
Your clients trust you with a lot. Here is how we look after it.
CoachTide holds your client records, session notes, agreements and invoices. This page explains, in plain terms, where that information lives, who can see it, and how it is protected. It also says plainly what we do not have yet.
Last updated October 2026. The legal version is our privacy policy.
The short version
Six things worth knowing
Stored in Canada
Your records are stored at rest in Canada, in the Montreal region.
Walled off from every other coach
Each practice is kept separate by the database itself, not only by the app, so one coach can never reach another coach's clients.
Two-step sign-in
Add a code from an authenticator app to your sign-in. It is required for everyone on the CoachTide team.
We cannot browse your records
Our staff see counts, like how many clients you have. Looking inside your practice takes your permission, for 72 hours at most.
Card numbers never touch us
Payments go through Stripe, on your own account. You are the merchant, and CoachTide never stores card details.
Yours to take, or to delete
Export your data whenever you like. Delete your account and it is permanently removed after a 30-day window in which you can change your mind, apart from records the law requires us to keep.
01
Where your data lives
Your account and everything you enter, such as clients, sessions, notes, goals, agreements and invoices, is stored at rest in Canada, in the Canada Central (Montreal) region.
Some processing runs on servers in the United States, and some of the services we rely on operate internationally, so your data may travel outside Canada while CoachTide does its work. We handle personal information in a manner consistent with PIPEDA and British Columbia's PIPA.
02
How it is protected
- Encrypted in transit and at rest. Everything travels over HTTPS, and our hosting provider encrypts it where it is stored.
- Keys to your other accounts, locked away. The Stripe and PayPal keys you connect and your Google Calendar connection are encrypted a second time and kept in a separate vault. The database holds only a pointer to each one, so a copy of it on its own would not reveal them. Only our server can unlock a key, at the moment it needs it to take a payment or update your calendar. No signed-in browser can read one back, yours included: once a key is saved, the app only shows that it is there. Disconnect it and the stored key is deleted. The connections our own team uses are kept the same way. Card numbers never reach us: Stripe holds them.
- Separation the database enforces. Before any record comes back, the database itself checks that it belongs to a practice you are part of. A mistake on one screen cannot hand you someone else's data.
- Background jobs kept to one practice. A few jobs run without anyone signed in, such as sending reminders or taking a scheduled payment. Each one works on a single practice at a time, and every one is listed in a security record we keep up to date.
- Two-step sign-in that means it. It is optional for coaches. Once you turn it on, a sign-in that skipped the second step gets none of your records at all. Everyone on the CoachTide team must use it.
- No passwords needed for your clients. Clients reach their portal through single-use sign-in links sent to their own email address, and can sign themselves out of every device at once. Someone who only pays a client's invoices gets the invoices, never a way into the portal.
03
Who can see what
04
Payments
Clients pay you through Stripe, on your own Stripe account, or through your own PayPal account if you connect one. You are the merchant, and CoachTide never takes a cut.
Card details are held by the payment processor, never by us. When a client saves a card for automatic payments, they agree to it first, and we keep only the card brand, its last four digits and its expiry date.
05
AI features
When you ask the in-app Guide a question, what you type goes to our AI provider, Anthropic, only to answer it. When AI helps you import a spreadsheet, it sees only the file's structure, such as the column headings, never your clients' names, emails, notes or amounts. When AI drafts or rewrites your coach website, it sees your business details, your booking types and packages, your voice settings, and the text you ask it to rewrite, never client information. When a client uses AI help to put a reflection into words for their takeaways, only that reflection and the list's title go to Anthropic, without the client's account details, and CoachTide does not store the reflection.
In every case our AI provider keeps nothing after the answer, apart from the results of its automated safety checks and anything it must keep by law or to look into misuse, and nothing is used to train AI models. The AI features cannot browse the records stored in your practice; they see only what is described here.
CoachTide saves your Guide conversations in your practice, with the rest of your data. Our team reads one only when you send it to support, when the Guide could not answer it from our help articles, or when you grant support access.
06
The services we rely on
Each one handles only what it needs to do its job. We do not sell your information.
The full list, with what each one does and where it works, is on our sub-processors page.
Straight answers
What we do not claim
Security pages tend to promise a lot. Here is what we do not have, so you can decide with the full picture.
No certification of our own, yet
CoachTide does not hold SOC 2 or ISO 27001 certification. Supabase and Vercel, which host your data, each hold SOC 2 Type II reports.
No outside security test, yet
We have not yet had an independent firm test CoachTide for weaknesses. We plan to before CoachTide leaves beta, and we will say so here once it is done.
Not end-to-end encrypted
CoachTide has to read your records to send reminders and invoices for you, so it cannot be. Your data is encrypted in transit and at rest.
Not for medical records
CoachTide is built for coaching, not clinical care, and is not a HIPAA-covered service. Keep health records in a system made for them.
Found a problem? Tell us.
If you think you have found a security issue in CoachTide, email us and please give us a chance to fix it before sharing it publicly. We read every report and will reply within 3 business days.
security@coachtide.comWhat to include, what we promise, and what is out of scope: how to report a security problem.
Questions about your data: privacy@coachtide.com