LGPD / GDPR-aware

Privacy Policy — Coach'em

Version: 2.0 · Effective: 2026-05-29 · Last updated: 2026-05-29

1. Introduction

This Privacy Policy describes how Coach'em (“App”, “Platform”, “Service”, “we”) collects, uses, stores, shares, and protects personal data of coaches, athletes, and other users (“you”, “data subject”), in compliance with Brazil’s LGPD and applicable law.

2. Definitions

3. Controller and DPO

4. Data we collect

4.1. Account data

Email, password (Firebase Auth), profile type, optional photo, subscription status.

4.2. Training data

Workouts, assignments, completion, feedback, load history, coach–athlete linkage.

4.3. Health & wearables (optional — athletes)

Only with explicit in-app consent, between Start workout and Mark completed: heart rate aggregates, calories, distance, steps, exercise sessions from Apple Health / Health Connect.

We do not access diagnoses, ECGs, or hospital records. Aggregates may be stored in Firebase and shown to the linked coach. See Health & wearables consent.

4.4–4.6. Usage, technical, and push data

App interactions, security logs, device/OS info, optional push tokens.

5. Purposes

Service delivery, optional sports health display, security, product improvement (anonymized where possible), communications, legal compliance.

6. Legal bases (LGPD)

Consent (Art. 7 I / Art. 11 I for sensitive data), contract performance, legal obligation, legitimate interest (balanced). Wearables rely on specific, highlighted consent, revocable anytime.

7. Sharing

Linked coach (training scope); operators (Firebase/Google Cloud, Apple/Google health APIs on device, RevenueCat, Expo push); authorities when required. No sale of personal data. International transfers use LGPD Art. 33 safeguards.

8. Security

TLS, Firestore rules, authentication, aggregated health only on server, monitoring and backups. See section 13 for incidents.

9. Retention

10. Your rights (LGPD Art. 18)

Access, correction, deletion, portability, sharing information, consent withdrawal, objection. Contact: suporte.vision10@gmail.com — response within 15 days where applicable.

11–12. Cookies and notifications

Essential cookies on legal web pages; push/email for service-related messages, opt-out for marketing where offered.

13. Security incidents

Containment, ANPD notification when required, user notice without undue delay, internal records.

14–17. Changes, minors, third-party links, law

Minors require guardian consent. Brazilian law applies; EEA users may have additional GDPR rights (Arts. 15–22, 9, 44–49).

18. Related documents

19–20. Contact and effective date

suporte.vision10@gmail.com · DPO: Rodrigo Antonio Lombardo Tosi