Privacy Policy
Last updated: April 22, 2026
1. Introduction
EliteCoach AI, LLC ("EliteCoach AI," "we," "our," or "us") operates the EliteCoach AI platform available at https://elitecoach.bz (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, password, and profile photo when you register.
- Business Information: Coaching business name, billing address, and payment information processed securely through Stripe.
- Client Data: Health metrics, check-in responses, progress photos, workout logs, nutrition data, and other coaching-related information you or your clients submit.
- Communications: Messages, support tickets, and feedback you send to us or through the platform.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, click patterns, and navigation paths.
- Device Information: IP address, browser type, operating system, device identifiers, and screen resolution.
- Cookies and Tracking: Session cookies for authentication, preference cookies, and analytics cookies. See Section 8 for details.
2.3 Information from Third Parties
- OAuth Providers: When you sign in via Manus OAuth, we receive your name, email, and profile photo.
- Wearable Devices: If you connect WHOOP, Oura, Apple Health, Garmin, or other devices, we receive biometric data you authorize.
- Stripe: We receive payment confirmation and subscription status. We do not store full card numbers.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process payments and manage subscriptions
- Enable coaches to manage clients and deliver coaching services
- Generate AI-powered insights, workout plans, meal plans, and check-in analyses
- Send transactional emails (receipts, password resets, system alerts)
- Send marketing communications (with your consent; you may opt out at any time)
- Improve and personalize the Service through analytics
- Detect, prevent, and address fraud, abuse, and security incidents
- Comply with legal obligations
4. Multi-Tenant Data Isolation
EliteCoach AI operates as a multi-tenant platform. Each coaching business ("Tenant") has a fully isolated workspace. Data from one Tenant is never accessible to another Tenant. Tenant Admins control all data within their workspace, including coach and client data. We implement strict database-level and application-level controls to enforce this isolation.
5. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
5.1 Service Providers
We share data with trusted third-party vendors who assist in operating our Service, including:
- Stripe — Payment processing
- TiDB/PlanetScale — Database hosting
- Manus AI — Authentication and AI services
- Amazon Web Services / Cloudflare — Infrastructure and CDN
All service providers are contractually bound to protect your data and use it only for the purposes we specify.
5.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of EliteCoach AI, LLC, our users, or the public.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service prior to such transfer.
6. Health and Fitness Data
Our Service processes sensitive health and fitness data including body weight, body composition, workout performance, nutrition logs, biometric data from wearables, and bloodwork results. This data is:
- Stored encrypted at rest using AES-256 encryption
- Transmitted over TLS 1.3
- Accessible only to the client, their assigned coach(es), and the Tenant Admin
- Never sold or shared with advertisers or data brokers
- Used by our AI systems only to generate insights for the client's benefit within their coaching relationship
By using the Service, you consent to the collection and processing of health data as described in this policy. Clients may request deletion of their health data at any time (see Section 9).
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Active accounts: Data retained indefinitely while the account is active.
- Cancelled accounts: Data retained for 90 days after cancellation to allow for reactivation, then permanently deleted.
- Backup data: May persist in encrypted backups for up to 30 additional days after deletion.
- Legal holds: Data subject to legal proceedings may be retained longer as required by law.
8. Cookies and Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality. Cannot be disabled.
- Preference Cookies: Remember your settings and preferences (e.g., theme, language).
- Analytics Cookies: Help us understand how users interact with the Service (aggregated, anonymized data).
You can control non-essential cookies through your browser settings. Note that disabling certain cookies may affect Service functionality.
9. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain processing activities, including direct marketing.
- Restriction: Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
10. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will promptly delete such information. If you believe we have inadvertently collected information from a child under 13, please contact us at [email protected].
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards including Standard Contractual Clauses approved by the European Commission.
12. Security
We implement industry-standard security measures to protect your information, including:
- AES-256 encryption for data at rest
- TLS 1.3 for data in transit
- Multi-tenant data isolation at the database level
- Regular security audits and penetration testing
- Role-based access controls with principle of least privilege
- Automated anomaly detection and intrusion prevention
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information is collected, used, shared, or sold
- The right to delete personal information held by businesses
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, contact us at [email protected] with "CCPA Request" in the subject line.
14. GDPR Rights (EEA/UK Residents)
If you are located in the European Economic Area or United Kingdom, our legal basis for processing your personal data includes:
- Contract performance: Processing necessary to provide the Service you've requested
- Legitimate interests: Improving the Service, fraud prevention, and security
- Consent: Marketing communications and non-essential cookies
- Legal obligation: Compliance with applicable laws
You have the right to lodge a complaint with your local data protection authority.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new policy on this page with an updated "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice within the Service
Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: