# Prime Coach Privacy Policy
Last Updated: January 20, 2026
Introduction
This Privacy Policy describes how Flyweight Development Oy (“we,” “us,” or “our”) collects, uses, and shares information when you use the Prime Coach application and related services (collectively, the “Service”).
Prime Coach is a performance coaching application that helps coaches record, transcribe, and analyze coaching sessions using artificial intelligence.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Data Controller
The data controller responsible for your personal data is:
Flyweight Development Oy
Business ID: 3135270-3 (FI31352703)
Email: [email protected]
Information We Collect
Account Information
When you create an account, we collect:
- Phone number (required) — Used for authentication via SMS verification
- Email address (optional) — For account-related communications
- First and last name (optional) — For personalization
- Language preference — To provide the Service in your preferred language
Organizational Data
If you use organizational features, we collect:
- Organization names and membership information
- Group names, age categories, and sports disciplines
- Member roles and permissions
Session and Recording Data
When you use coaching features, we collect:
- Audio recordings — Voice recordings of coaching sessions that you create
- Transcripts — Text transcriptions generated from your audio recordings
- AI analysis results — Feedback and ratings generated by analyzing your coaching sessions
- Session metadata — Duration, timestamps, and activity data
Usage Data
We automatically collect certain information when you use the Service:
- Device information (device type, operating system)
- App usage patterns and feature interactions
- Error logs and performance data
How We Use Your Information
We use the information we collect to:
- Provide the Service — Authenticate your account, process recordings, generate transcripts, and deliver AI-powered coaching analysis
- Improve the Service — Analyze usage patterns to enhance features and user experience
- Communicate with you — Send service-related notifications and respond to inquiries
- Ensure security — Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations — Meet applicable legal requirements
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Performance of contract |
| Recording, transcription, and AI analysis | Performance of contract |
| Service improvements and analytics | Legitimate interests |
| Security and fraud prevention | Legitimate interests |
| Legal compliance | Legal obligation |
| Marketing communications (if any) | Consent |
Third-Party Service Providers
We use the following third-party services to operate the Service. These providers process data on our behalf and are contractually obligated to protect your information:
Convex (Backend Infrastructure)
- Purpose: Database, real-time sync, file storage, and backend functions
- Data processed: All user data, recordings, transcripts, and session data
- Location: Data may be stored globally on AWS infrastructure
- Compliance: SOC 2 Type II, HIPAA, GDPR compliant
- More information: Convex Security | Convex DPA
Twilio
- Purpose: SMS delivery for phone number verification (OTP)
- Data processed: Phone numbers, verification codes
- More information: Twilio Privacy
Deepgram
- Purpose: Speech-to-text transcription of audio recordings
- Data processed: Audio recordings, generated transcripts
- More information: Deepgram Privacy
ElevenLabs
- Purpose: Speech-to-text transcription of audio recordings
- Data processed: Audio recordings, generated transcripts
- More information: ElevenLabs Privacy
OpenRouter (AI Analysis)
- Purpose: AI-powered analysis of coaching session transcripts
- Data processed: Transcript text for analysis
- More information: OpenRouter Privacy
PostHog (Analytics)
- Purpose: Product analytics to improve the Service
- Data processed: Usage data, feature interactions, anonymized metrics
- Location: EU-hosted
- More information: PostHog Privacy
Data Retention
We retain your data as follows:
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Audio recordings | Until you delete them or your account |
| Transcripts | Until you delete them or your account |
| AI analysis results | Until associated recording is deleted or account deletion |
| Usage/analytics data | Until you delete your account |
When you request account deletion, we will delete your personal data within 30 days, except where we are required to retain certain information for legal or compliance purposes.
Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Secure authentication using phone verification
- Access controls and audit logging
- Regular security assessments
Our infrastructure provider, Convex, maintains SOC 2 Type II compliance and undergoes regular third-party security audits.
International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States. When we transfer data outside the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with our service providers
- Compliance with the EU-U.S. Data Privacy Framework where applicable
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
For All Users
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request deletion of your personal data
- Data portability — Request your data in a portable format
Additional Rights (EEA, UK, Switzerland)
- Restrict processing — Request limitation of how we process your data
- Object to processing — Object to processing based on legitimate interests
- Withdraw consent — Withdraw consent at any time where processing is based on consent
- Lodge a complaint — File a complaint with your local data protection authority
For California Residents (CCPA)
- Right to know — What personal information we collect and how it is used
- Right to delete — Request deletion of your personal information
- Right to opt-out — We do not sell personal information
- Non-discrimination — We will not discriminate against you for exercising your rights
To exercise any of these rights, please contact us at [email protected].
Children’s Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly.
Note: While coaches may work with minors (kids and teenagers), only adult coaches (18+) may create accounts and use the Service.
Do Not Track
The Service does not respond to “Do Not Track” browser signals. However, we do not track users across third-party websites.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the “Last Updated” date
- Sending you a notification through the Service (for significant changes)
We encourage you to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Flyweight Development Oy
Business ID: 3135270-3 (FI31352703)
Email: [email protected]
For data protection inquiries in the EU, you may also contact your local data protection authority.
Summary
| Aspect | Details |
|---|---|
| Data Controller | Flyweight Development Oy |
| Contact | [email protected] |
| Minimum Age | 18 years |
| Data Location | Global (via Convex/AWS) |
| Analytics | PostHog (EU-hosted) |
| Retention | Until account/data deletion |
| Deletion Timeline | Within 30 days of request |
| GDPR Compliant | Yes |
| CCPA Compliant | Yes |