Skip to content
All documentsPortuguês
Legal document · 01

Privacy Policy

Read the full version or use the contents to jump directly to the section you need.

Version
1.3
In force since
08 April 2026
Last updated
27 July 2026
Draft — pending legal review before publication
In this document
  1. 1. Introduction
  2. 2. Data Controller and Data Protection Officer
  3. ⚠️ [UNDER LEGAL REVIEW] Qualification of the data controller
  4. 3. Personal Data Collected
  5. 4. Purpose of Data Processing
  6. 5. Legal Basis for Processing
  7. 6. Consent and Health Data
  8. 7. Data Sharing with Third Parties
  9. 8. International Data Transfers
  10. 9. Data Retention
  11. 10. Rights of Data Subjects
  12. 11. Data Security
  13. 12. Cookies
  14. 13. Minors
  15. 14. Changes to This Policy
  16. 15. Contact

Last updated: 27 July 2026 Version: 1.3


1. Introduction

iBetterCoach ("we" or "our") provides a software-as-a-service (SaaS) platform (the "Platform") intended for personal trainers and exercise professionals, nutritionists, and managers and owners of gyms and academies. This Privacy Policy describes how we collect, use, store and protect the personal data of Platform users, in compliance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and Portuguese Law no. 58/2019 of 8 August, which adapts Portuguese law to GDPR.

By using the Platform, the user declares having read, understood and fully accepted this Privacy Policy. If you do not agree with the terms described here, you should not use the Platform.


2. Data Controller and Data Protection Officer

2.1 Data controller

The data controller for personal data is:

iBetterCoach [legal entity name TBD] [Address TBD] [VAT/Tax ID TBD] General email: general@ibettercoach.com

2.2 Data Protection Officer (DPO)

iBetterCoach has appointed a Data Protection Officer (DPO), who can be contacted for any matter related to the processing of your personal data or to the exercise of your rights:

DPO email: dpo@ibettercoach.com Data protection email: privacy@ibettercoach.com

2.3 iBetterCoach's role in the processing chain

⚠️ [UNDER LEGAL REVIEW] Qualification of the data controller

This point is being determined through legal advice and may change the framing of several sections of this document. There are two possible readings of iBetterCoach's role: (a) Data processor of the Athlete's data, processed on behalf of the Professional (data controller), under the terms of the DPA; or (b) Data controller, possibly as joint controllers with the Professional (Art. 26 GDPR), given that iBetterCoach maintains a direct relationship with the Athlete (own account, acceptance of the Terms and consent provided directly to the Platform) and processes data for its own purposes (metrics/gamification, product improvement and security). The final determination will be reflected in this section, in the DPA document and in the consent flows. Pending validation by a lawyer specialised in GDPR.

2.4 Nature of the service — assistance tool and user responsibility

iBetterCoach is a professional decision support tool, not a healthcare provider, and does not replace medical, nutritional or clinical advice. All suggestions, calculations and prescriptions generated by the Platform are intended to be reviewed and validated by the Professional. In case of any doubt about a health matter, symptom, medication or clinical condition, the user must consult a doctor or other qualified healthcare professional.

Possibility of errors and inaccuracies. The Platform's calculations and automated rules may produce information that is incorrect, outdated, incomplete or unsuitable for the specific case. Calculations may rely on assumptions that do not apply to every person, and scientific guidelines evolve over time. For these reasons, no information presented by the Platform should be treated as absolute truth without validation by the Professional and, whenever appropriate, by a healthcare professional. The user must keep a critical eye on what the Platform presents and report any content that appears incorrect or dangerous to support.

Personal responsibility of the user. Each user (Professional or Athlete) is responsible for their own decisions, for the truthfulness of the data they enter and for how they act on the information presented by the Platform. The Platform provides information and suggestions; the final decision is always the person's. The user undertakes to act with common sense, respect their own physical limits, follow the guidance of their healthcare professional and seek medical help whenever they feel symptoms, pain, discomfort or any warning sign.

Full details of this limitation are set out in the Legal Notice and Medical Disclaimer, which forms an integral part of this Policy.


3. Personal Data Collected

3.1 Professional Data (Personal Trainer / Gym Manager)

  • Full name and identification details
  • Email address
  • Phone number
  • Authentication data (managed by the authentication provider Clerk)
  • Billing and payment data (processed by third-party payment providers)
  • Professional information (gym, role, specialisations)

3.2 Athlete Data

Athlete data originates from distinct contexts, which it is important to distinguish:

(a) Data entered by the Athlete in the mobile application

  • Manual anthropometric measurements (weight, waist perimeter, hip perimeter and other measurements recorded by the Athlete themselves)
  • Wearable data synchronised automatically (see section 3.3)

(b) Clinical and anamnesis data entered by the Professional in the web application

The anamnesis and sensitive clinical data are not entered in the mobile application by the Athlete, but rather in the web application by the Professional, within the scope of the professional relationship, and include:

  • Diagnosed medical conditions
  • Medications in use (name, dosage, frequency)
  • Surgical history
  • Allergies and food intolerances
  • Lifestyle habits (sleep, smoking, alcohol consumption, stress levels)
  • Cardiovascular screening results (ACSM protocol)
  • Cardiovascular risk factors

(c) Body photographs

  • Body photographs, strictly optional, uploaded by the Athlete in the mobile application or by the Professional in the web application with the Athlete's authorisation — only permitted for Athletes aged 18 or over; submission by minors under 18 is subject to a technical block

(d) Other identification and monitoring data

  • Full name, date of birth, gender
  • Contact details (email, phone)
  • Emergency contact
  • Body composition data (body fat percentage, lean mass, BMI)
  • Training data (plans, execution, loads, RPE, progression)
  • Nutritional data (meal plans, preferences, supplementation)
  • Physical assessment data (protocols, results, normative tables)
  • Training goals and objectives
  • Clinical team (names and contacts of healthcare professionals)

3.3 Wearable and Health Data (automatic synchronisation from the Athlete's device)

The mobile application may automatically synchronise health data from Apple Health or Health Connect, subject to the Athlete's prior consent (see section 6). The synchronised data includes:

  • Steps and physical activity
  • Heart rate
  • Resting heart rate
  • Sleep data
  • Heart rate variability (HRV)
  • VO₂max
  • Training sessions
  • Other data the Athlete authorises to share from Apple Health or Health Connect

3.4 Platform Usage Data

  • Access logs (authentication logs, IP addresses, timestamps)
  • Interface interactions (features used, pages visited)
  • Device data (browser type, operating system)
  • Cookies strictly necessary for the operation of the Platform

4. Purpose of Data Processing

Personal data is processed for the following purposes:

4.1 Service Delivery

  • Management of user accounts (professionals and gyms)
  • Creation and management of athlete profiles
  • Generation of training prescriptions and nutrition plans
  • Health screening and risk assessment
  • Calculation of metabolic and performance metrics
  • Application of physical assessment protocols
  • Monitoring of athlete progress and evolution
  • Synchronisation of wearable data and processing of the synchronised health data for the following purposes: (i) reading of the Athlete's habits by the Professional, within the scope of the monitoring; and (ii) presentation of metrics to the Athlete themselves in a logic of gamification and adherence

4.2 Service Improvement

  • Improvement of prescription algorithms
  • Identification and correction of technical errors or issues
  • Development of new features

4.3 Security and Compliance

  • Prevention of unauthorised access
  • Detection of abusive or fraudulent use
  • Compliance with legal and regulatory obligations
  • Maintenance of audit logs

4.4 Communication

  • Sending service-related notifications (essential)
  • Technical support communications
  • Updates on changes to the service or legal terms

5. Legal Basis for Processing

The processing of personal data is based on the following legal grounds set out in GDPR (the allocation of roles and, consequently, the legal basis applicable to each category are subject to the qualification under legal review — see section 2.3):

  • Performance of a contract (Art. 6(1)(b)) — processing is necessary for the provision of the service contracted by the user.
  • Consent (Art. 6(1)(a) and Art. 9(2)(a)) — for health data and sensitive data, processing is based on the explicit consent of the data subject (see section 6).
  • Legitimate interest (Art. 6(1)(f)) — for service improvement and Platform security.
  • Legal obligation (Art. 6(1)(c)) — for compliance with applicable legal obligations.

6. Consent and Health Data

6.1 Nature of the Data

The Platform processes health data, which constitutes a special category of personal data under Art. 9 GDPR. The processing of these data is only lawful with the explicit, freely given, specific and informed consent of the data subject themselves — the Athlete — under Art. 9(2)(a) GDPR (subject to the qualification under legal review — see section 2.3).

6.2 Consent is given by the Athlete

The consent under Art. 9(2)(a) is always given by the Athlete themselves on a dedicated page, through a personal link with a one-time token sent to their email or, if they are already authenticated, directly on the Platform. This channel is independent of the Professional, and the Professional's device is not used to give consent. The Professional cannot give this consent on behalf of the Athlete. The full terms of this consent are detailed in the Informed Consent for Processing of Health Data document, which forms an integral part of this Policy.

Each choice is recorded separately, with the version and cryptographic digest (SHA-256) of the text actually presented. Authorisation for body photographs is separate and optional: refusing it does not prevent use of the Platform's other features; only photographic assessment remains unavailable.

The Athlete may withdraw their consent at any time, without affecting the lawfulness of prior processing (Art. 7(3) GDPR), by contacting privacy@ibettercoach.com or by using the mechanisms provided in the Platform.

Withdrawal of authorisation for photographs immediately blocks new reads and new issuance of signed URLs. A bearer URL issued before withdrawal may remain functional for no more than 15 minutes.

6.3 Specific consent for wearable data synchronisation

The automatic synchronisation of health data from Apple Health or Health Connect (section 3.3) is subject to a separate, specific and optional consent:

  • Optional — the mobile application works without this consent; its absence does not prevent the use of the remaining features.
  • Prior — the consent is required before any synchronisation. The order is always: (1) legal consent on the Platform → (2) operating system permission (Apple Health / Health Connect) → (3) data synchronisation.
  • Two distinct consents — two "yeses" are required: the legal consent given in the iBetterCoach application and the permission granted at operating system level. The operating system permission does not replace, nor dispense with, the legal consent given on the Platform.
  • Revocable — it may be withdrawn at any time (Art. 7(3) GDPR), ceasing synchronisation for the future.

iBetterCoach records the version, text and date of the consent given, for evidentiary and audit purposes.

6.4 Professional's responsibility

Without prejudice to the consent given by the Athlete, the Professional using the Platform is responsible for:

  • Informing the Athlete, before processing begins, about the nature and purpose of the data that will be entered into the Platform
  • Presenting the Athlete with the Art. 9 consent flow whenever the Athlete is onboarded to the Platform
  • Not entering health data into the Platform without the Athlete having previously given the required consent
  • Ensuring the truthfulness and updating of the data entered
  • Keeping a record of the professional-athlete relationship in the context of which the data is processed

6.5 Minors

The Platform is intended for Athletes aged 16 and over. The submission of body photographs is prohibited for minors under 18 and is subject to a technical block (see sections 3.2 and 13).

⚠️ [to be confirmed by the lawyer] In the case of Athletes aged 16 or 17 and where health data is involved (special categories, Art. 9 GDPR), it is being confirmed whether the consent of the Athlete themselves is sufficient or whether the consent of the holder of parental responsibility is also required.


7. Data Sharing with Third Parties

iBetterCoach does not sell personal data to third parties. Data may be shared in the situations described in this section.

7.1 Sub-processors

iBetterCoach uses a limited set of sub-processors for the provision of the service. All sub-processors are bound by contracts that include data protection clauses pursuant to Art. 28 GDPR. Where a sub-processor is located outside the European Economic Area (EEA), the transfer is protected by the Standard Contractual Clauses (SCC) approved by Commission Decision (EU) 2021/914 and, where applicable, by the EU-US Data Privacy Framework (DPF).

Sub-processorPurposeData categoriesLocationSafeguard
Supabase Inc.PostgreSQL database and file storageAll Platform data, including health dataEU — Ireland (eu-west-1)DPA + SCC
Clerk Inc.Authentication, session management and organization managementIdentity, email, session and organization IDsUSADPA + SCC + DPF
Vercel Inc.Web application hosting, edge functions, CDNTechnical: IP, HTTP headers, access logsEU — Dublin (dub1)DPA + SCC + DPF
Resend, Inc.Transactional service email delivery (account deletion notices, operational notifications)Email address, name and message contentEU (eu-west-1)DPA + SCC
Stripe, Inc.Payment processing and billingProfessional Customer identity and email, billing address, tax ID and subscription data; card data is tokenised by Stripe and never reaches iBetterCoachUSA (with Irish entity Stripe Payments Europe Ltd.)DPA + SCC + DPF

Payment processor. The Professional's card data (PAN, CVV) is tokenised directly in the browser by Stripe; iBetterCoach does not receive or store full payment instrument data. Clerk does not process payments.

7.2 User-enabled integrations (not sub-processors)

The Platform allows the Athlete to synchronise wearable data from Apple Health and Health Connect. These integrations operate based on the Athlete's explicit authorisation on their device, and the respective providers do not process data on behalf of iBetterCoach — they provide the Athlete's device platform. iBetterCoach only receives the data the Athlete authorises to share.

7.3 Updates to the sub-processor list

iBetterCoach reserves the right to change the list of sub-processors. Any addition or replacement will be communicated 30 days in advance, giving the B2B customer the option to object under the terms of the DPA.

7.4 Access within the Platform context

  • The Athlete's data is accessible to the Professional(s) who have an active and authorised relationship with the Athlete.
  • In multi-gym contexts, only Professionals with explicit permissions access the data.
  • Gym managers access operational data of trainers on their team.
  • Authorised iBetterCoach technical personnel, with restricted read-only access, exclusively for Platform operation, security and support. Each access to an Athlete record is automatically logged with the identity of the person who accessed it, the date and time, the screen viewed and the purpose.

7.5 Legal obligations

iBetterCoach may have to share data with competent authorities (CNPD, judicial authorities, police) when required by law, court order or substantiated request from a public authority.


8. International Data Transfers

Some of our service providers involve transfers of data outside the European Economic Area (EEA), in particular to the United States of America in the case of Clerk (authentication) and Stripe (payments). In these situations, we ensure that adequate safeguards are in place, namely:

  • Standard contractual clauses approved by the European Commission (SCC)
  • The EU-US Data Privacy Framework (DPF), where the recipient is certified
  • Adequacy decisions of the European Commission
  • Other mechanisms set out in GDPR

9. Data Retention

9.1 Account Data

  • Maintained while the account is active
  • After cancellation, data is retained for a maximum period of 30 days to allow reactivation, after which it is deleted or anonymised

9.2 Athlete Data

  • Maintained as long as there is an active relationship between the professional and the athlete
  • When the athlete is archived, data is retained for a period of 2 years for clinical history and audit purposes, after which it is deleted or anonymised
  • The professional may request early deletion of an athlete's data

9.3 Usage Data and Logs

  • Access logs: retained for 12 months

9.4 Billing Records (tax/accounting retention)

Billing and accounting records are subject to a statutory tax retention period — approximately 10 years in Portugal (⚠️ [to be confirmed by the lawyer] the exact period to be confirmed by the lawyer/accountant). These records are not deleted upon account deletion; only the associated user identifier is anonymised, while the data strictly necessary to comply with tax and accounting obligations is retained.


10. Rights of Data Subjects

Under GDPR, data subjects have the following rights:

  • Right of access — obtain confirmation and a copy of the personal data processed
  • Right of rectification — request correction of inaccurate data
  • Right to erasure ("right to be forgotten") — request deletion of data, under the conditions provided by law (see section 10.1 regarding the scope and limits of this erasure)
  • Right to restriction of processing — request restriction of processing in certain circumstances
  • Right to data portability — receive data in a structured, commonly used and machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact: privacy@ibettercoach.com

The data subject also has the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) — www.cnpd.pt

10.1 Account deletion and scope of erasure

Account deletion deletes or anonymises the personal data and health data of the data subject. However, data whose retention is required by law is not deleted, in particular:

  • the billing and accounting records, retained for the applicable statutory period (see section 9.4), in respect of which only the user identifier is anonymised;
  • ⚠️ [to be confirmed by the lawyer] any clinical record that a healthcare professional may have a legal duty to retain.

iBetterCoach does not delete "everything": it deletes the personal data it can delete and retains only what the law obliges it to keep. At the moment of the deletion action, the user is presented with a transparent indication of what is deleted and what is retained, why and for how long (for example: "this deletes your profile and health data; billing records are retained for X years due to a legal obligation").

Mechanisms available for deletion:

  • in the mobile application (in-app);
  • on a dedicated public page;
  • in the account settings of the web application.

11. Data Security

iBetterCoach implements appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encryption of data at rest
  • Data isolation by context (multi-tenant)
  • Role-based access control (RBAC)
  • Secure authentication with session management
  • Audit logs of access and critical operations
  • Regular backups
  • Validation and sanitisation of all inputs
  • Secure error responses (without exposure of internal data)

12. Cookies

The Platform uses a single category of cookies: strictly necessary cookies, which are indispensable to the operation of the service. They include Clerk authentication and session cookies and the sidebar_state cookie, which remembers whether the sidebar is open. They are always active and do not depend on consent. The Platform does not set non-essential cookies.

We do not use advertising, marketing or remarketing cookies. Details of the cookies, purposes, providers and durations are set out in the Cookie Policy.


13. Minors

The Platform is intended for Athletes aged 16 and over and is not intended to be used by minors under 16.

The submission of body photographs is prohibited for minors under 18 and is subject to a technical block on the Platform.

⚠️ [to be confirmed by the lawyer] In the case of Athletes aged 16 or 17, and where health data is involved (special categories, Art. 9 GDPR), it is being confirmed whether the consent of the Athlete themselves is sufficient or whether the consent of the holder of parental responsibility is also required (see section 6.5).


14. Changes to This Policy

iBetterCoach reserves the right to update this Privacy Policy at any time. Changes will be communicated to users through the Platform or by email. Continued use of the Platform after the communication of changes constitutes acceptance thereof.


15. Contact

For privacy and data protection matters:

Email: privacy@ibettercoach.com Address: [Address TBD]


This document is part of the iBetterCoach product governance and must be reviewed by a lawyer specialised in data protection before publication.

This document may be updated. The version in force is always the one available on this page.

Other legal documents

View all
  • Terms of Use
  • Athlete Terms
  • Cookie Policy
  • Legal Notice & Medical Disclaimer
  • Informed Consent — Health Data
  • Data Processing Agreement (DPA)
  • Acceptable Use Policy
  • Subscription & Billing Terms
  • Refund Policy
  • Service Level Agreement (SLA)
In this document
  1. 1. Introduction
  2. 2. Data Controller and Data Protection Officer
  3. ⚠️ [UNDER LEGAL REVIEW] Qualification of the data controller
  4. 3. Personal Data Collected
  5. 4. Purpose of Data Processing
  6. 5. Legal Basis for Processing
  7. 6. Consent and Health Data
  8. 7. Data Sharing with Third Parties
  9. 8. International Data Transfers
  10. 9. Data Retention
  11. 10. Rights of Data Subjects
  12. 11. Data Security
  13. 12. Cookies
  14. 13. Minors
  15. 14. Changes to This Policy
  16. 15. Contact
Legal documentation and transparency · © 2026 iBetterCoach