Effective date: October 6, 2026
CorrCoach is operated by Joseph McLoughlin from the United States. For privacy requests, legal notices, data-rights requests, or questions about this policy, email [email protected].
We collect account details, authentication and security records, onboarding profile data, subscription and entitlement records, support messages, preferences, waitlist and marketing choices, and the training data needed to operate CorrCoach.
Training data can include planned workouts, completed workouts, route and GPS data when you record or import it, heart-rate and HRV data, sleep and recovery data, derived head- and wrist-movement summaries from supported active workouts, device metadata, shoe and nutrition add-on records, coach/team relationship records, social privacy settings, and integration metadata from providers you connect. CorrCoach does not retain the raw headphone or wrist-motion sample stream.
We use your IP address to protect sign-in and other actions from abuse. We store only a scrambled fingerprint of it that can't be turned back into your address, and we delete that fingerprint after 90 days.
Depending on how you use CorrCoach, these records can include identifiers, account and commercial information, internet or device activity, precise-location data from workouts, consumer health data, inferences used for training recommendations, and communications with CorrCoach.
Data is used to create and display training plans, personalize recommendations, calculate scores and summaries, sync integrations, process subscriptions, secure your account, prevent abuse, provide support, troubleshoot product issues, honor legal requests, and improve CorrCoach when your settings allow it.
CorrCoach is not a medical provider and does not use health data to diagnose, treat, or monitor medical conditions.
When enabled by you, third-party providers such as Stripe, Apple, Strava, Garmin, Wahoo, email delivery providers, analytics providers, and infrastructure providers process data needed for billing, app delivery, activity sync, notifications, and service operation under their own terms and policies.
We do not sell personal health, workout, sleep, heart-rate, route, precise-location, or payment credential data. We do not share it with advertisers for targeted advertising. Any future research, model-improvement, or de-identified commercial data-use program must use separate consent controls, legal review, vendor/partner terms, and explicit launch approval before activation.
CorrCoach limits vendor processing to the purpose needed for the service, support, security, billing, analytics, or integration work they perform.
CorrCoach does not send athlete fitness data to OpenAI or Anthropic to train their models. Training intelligence runs through CorrCoach-controlled planning systems. Eligible Pro Data Lockdown coaching can run on a supported iPhone; other planning may use CorrCoach-hosted systems.
Necessary cookies and storage keep sign-in, security, billing, support, and app routing working. Optional analytics can be used to understand page views, waitlist signup, signup flow, lane interest, and onboarding completion when allowed by your consent settings and CorrCoach environment configuration.
CorrCoach does not send health, workout, sleep, heart-rate, GPS route, precise-location, payment credential, or private training data to public analytics providers. You can review or change analytics and marketing consent from Privacy / Data settings.
Analytics and marketing cookies are separate from necessary authentication cookies. CorrCoach turns optional analytics on only where that is legally allowed, and requires opt-in where opt-in consent is required or jurisdiction is uncertain.
Optional account-level consent controls let you choose whether CorrCoach can use privacy-safe product analytics, derived personalization outcomes, anonymized aggregate research, future commercial data-use consideration, or promotional marketing communications beyond the processing needed to run your account and training features.
These controls are off by default, versioned, auditable in your account data export, and revocable from Privacy / Data settings. Disabling a category stops future use for that optional purpose; required security, billing, support, legal, and service-operation processing may continue where necessary.
CorrCoach will not sell, externally share, or commercially export personal health, workout, sleep, heart-rate, route, precise-location, or payment data under these controls before legal counsel review, vendor due diligence, data-processing terms, explicit launch approval, and server-side activation gates.
CorrCoach uses rule-based planning and AI-assisted features to draft workouts, summarize completed sessions, explain training context, and answer account-safe coaching questions. AI output can be incomplete or wrong. You remain responsible for deciding whether a workout, intensity, route, nutrition suggestion, or recovery recommendation is appropriate for you.
The product goal is private training intelligence: local AI systems process the training context needed for the feature without making your fitness history model-training material for outside AI labs.
AI requests are limited to the training context needed for the feature, and guardrails are used to block prompt injection, credential requests, server-internal requests, other-user data requests, unsafe medical or legal advice, and unrelated tasks. Do not enter medical emergencies, protected third-party secrets, or another person's private data into AI coach prompts.
Blocked AI events may be logged for security review using categories, hashes, and redacted snippets instead of raw prompt storage.
Connecting a health or activity integration is optional. Before connecting, CorrCoach asks you to affirmatively accept the health-data disclosure, and the platform lets you choose the data types you authorize. Creating an account alone does not grant Apple Health access. Authorized health, activity, workout, recovery, sleep, heart-rate, HRV, device and integration data is used for the training, recovery, scores and personalization features you request.
On iPhone and iPad, Summary limits native Health sync to workout summaries. Standard adds routes, heart-rate averages, HRV, resting heart rate and sleep metrics. Maximum optionally adds supported workout sensor streams, daily heart-rate and HRV windows, respiratory rate, blood oxygen and sleeping wrist temperature. Availability depends on compatible sources, recorded samples and your permissions; a missing sample does not tell us whether you denied read access. Lowering the setting limits future collection and does not erase records already saved.
Apple Health and HealthKit data is used only for evident health and fitness functionality, service operation, and personalization you request. CorrCoach does not use this data for advertising, marketing, unrelated data mining, or eligibility decisions; does not sell it; and does not share it with data brokers.
When you enable Apple Health or Apple Watch sync, the specific categories you authorize may be transmitted to CorrCoach's backend and contracted service processors only as needed to operate the health and fitness service you requested. CorrCoach does not expose raw HealthKit records, precise routes, or private recovery signals to coaches, teams, or support operators by default.
You can revoke CorrCoach's Apple Health access from Apple Health or iOS privacy settings, disconnect other integrations where supported, change optional consent settings, export account data, or request account deletion from CorrCoach settings. Revoking access stops future collection from that source; previously retained records remain subject to your export and deletion controls and CorrCoach's legal retention obligations.
CorrCoach is not a medical provider and does not use health data to diagnose, treat, or monitor medical conditions.
Review the separate Consumer Health Data Privacy notice for health-data categories, sources, sharing limits, sale restrictions, deletion controls, and geofencing posture.
CorrCoach is a consumer training and wellness app and is not a HIPAA-covered entity. We do not currently act as a business associate to healthcare providers or health plans. If we later integrate with covered entities and sign Business Associate Agreements, we will handle that data as protected health information under HIPAA and update our applicable policies and safeguards.
CorrCoach is not directed to children under 13, and children under 13 may not create accounts or use CorrCoach. If we learn that we collected personal information from a child under 13 without a legally valid parent or guardian process, we will delete or disable the account data as required.
Users ages 13 through 17 may use CorrCoach only with parent or guardian consent and supervision, or through an authorized school, team, or coach program that has the required permissions. Parents, guardians, schools, and authorized coaches can contact us to review or request deletion of a minor user's account data where legally permitted.
Minor accounts use the most protective defaults available for social visibility, marketing, research consent, coach visibility, and optional data sharing unless a legally valid parent, guardian, school, or team process allows a different setting.
Some US state privacy laws provide rights to know or access personal information, correct inaccurate information, delete information, obtain a portable copy, opt out of sale or sharing, opt out of targeted advertising or certain profiling, limit use and disclosure of sensitive personal information, appeal a denied request, and use an authorized agent.
CorrCoach does not sell or share personal information for cross-context behavioral advertising. We also do not use sensitive personal information beyond service operation, security, safety, personalization you request, legal compliance, or other purposes allowed by law unless you provide a separate consent.
CorrCoach will not discriminate against you for exercising privacy rights, but some features may stop working if the data needed to provide them is deleted, disconnected, or no longer authorized.
Depending on where you live, we process data to perform our contract with you, with your consent, for legitimate security and product-operation interests, to protect vital or safety interests where applicable, and to meet legal obligations. Users may have rights to access, correct, export, delete, restrict, or object to certain processing. Some regions also provide rights to withdraw consent, lodge a complaint with a regulator, or appeal a privacy decision.
CorrCoach is operated from the United States. If you use CorrCoach from the EU, UK, Canada, Australia, or another region, your data may be processed in the United States and other locations where our providers operate, subject to appropriate contractual and security controls such as data-processing terms, transfer safeguards, and vendor review where required.
CorrCoach uses workout history, goals, recovery signals, preferences, and AI-assisted outputs to suggest training content. These recommendations do not make legal, financial, employment, insurance, credit, or similarly significant decisions about you. You can stop, ignore, or change training suggestions, and you remain responsible for safe training choices.
We retain account, billing, training, integration, support, security, and legal-acceptance records only as long as needed for the purposes described in this policy, unless a longer period is required for legal, tax, fraud-prevention, billing, dispute, backup, or security reasons.
You can request account data export or account deletion from settings. You may also request correction of inaccurate profile information, disconnect integrations where supported, change analytics or marketing consent, and contact us about privacy rights that apply in your region.
We use reasonable technical and organizational measures to protect your data, including account security controls, token handling, provider consent gates, and least-necessary data access patterns. No internet service can guarantee absolute security.
If a breach-notification law applies to CorrCoach, including the FTC Health Breach Notification Rule or state laws that apply to consumer health apps outside HIPAA, we will provide required notices to affected users and regulators.
Accessibility requests and accommodation feedback are handled through support. Review the Accessibility Statement for CorrCoach's current accessibility posture and contact path.
For privacy requests, email [email protected].