Privacy Policy
Last updated 28 July 2026
TrainScript OS is software for fitness coaches. This policy explains what we collect, why we have it, who else touches it, and how to get it back or delete it.
There are two kinds of people in this document. Coaches hold accounts with us. Clients are the people coaches train; they generally do not have accounts, and their information reaches us because a coach entered it or because they filled in an intake form their coach sent them.
Health information — read this part
Intake forms and client profiles can contain health information: injuries, medical conditions, movements to avoid, and free-text notes a coach or client writes. This is sensitive, and it is the reason this policy exists in the form it does.
We use it for one purpose: producing and displaying training programs for that client. We do not sell it, we do not use it for advertising, and we do not use it to train AI models.
It is sent to our AI provider as part of generating a program — see “AI processing” below. Coaches should not enter health detail beyond what a program actually needs, and should tell their clients that an AI service is involved.
We are not a healthcare provider, and TrainScript OS is not a medical record system. If you are subject to HIPAA or a comparable regime, we are not currently set up to be your processor for that purpose.
What we collect
Coach account. Name, email address and authentication details, handled by our authentication provider. Your coaching methodology, templates and settings. Billing details are handled by our payment provider — card numbers never reach our servers.
Client information, entered by a coach or submitted through an intake form. Name and contact details, training goals, experience, schedule and available equipment, and the health information described above.
Content you create. Programs, exercises, notes and the edits you make to them.
Operational data. Logs and error reports needed to keep the service running and to diagnose failures. We configure our error monitoring not to attach request bodies, headers or cookies, so program and client content should not appear in error reports.
AI processing
Program generation sends the relevant parts of your methodology and your client's profile — including health information you have entered — to OpenAI, which returns generated program content.
We send this under OpenAI's API terms, which as of the date above provide that API data is not used to train their models. We do not send client names or contact details where they are not needed for the output.
If you are not comfortable with client information being processed by a third-party AI service, do not enter it. This applies especially to health detail.
Who else processes data
We use these providers to run the service. Each processes only what it needs for its function.
- Clerk — accounts, sign-in and sessions.
- Neon — the database holding your programs, clients and settings.
- Vercel — hosting and delivery of the application.
- OpenAI — AI program generation, as described above.
- Stripe — subscription payments. Card details go to Stripe directly and are never stored by us.
- Resend — transactional email such as intake links and account notifications.
- Sentry — error monitoring, configured to exclude request contents.
Getting your data out, and deleting it
Export. Programs can be exported from the app at any time as PDF or spreadsheet.
Deletion. Archiving a client or program hides it from your workspace but retains the underlying record. If you want data permanently deleted rather than archived, email us and we will delete it. We will confirm when it is done.
Client requests. A client who wants their information corrected or deleted should normally ask their coach, who controls it. If they contact us directly we will work with the coach to action it.
Closing an account. Ask us and we will delete your account and the content in it. Backups roll off on their own schedule, so deletion is not instantaneous everywhere.
How long we keep things
We keep your content for as long as your account is open, because that is what makes it usable. After an account closes we delete or anonymise content that no longer has a purpose, other than records we need to keep for accounting and legal reasons.
Security
Data is encrypted in transit and at rest by our infrastructure providers. Access is limited to what is needed to operate and support the service. No system is perfectly secure, and we will not pretend otherwise — if we become aware of a breach affecting your data we will tell you.
Changes and contact
If this policy changes in a way that materially affects you, we will say so rather than quietly updating the date at the top.
Questions, or a data request: privacy@trainscript.ai.