CoachYantra

Privacy

Last changed 1 September 2026

In short

We do not keep a record of what is said in a coaching session. There is no notes field anywhere in this product. That is not a setting you can switch on; the code refuses to build if somebody adds one.

We store the facts of the work — who was coached, when, for how long, what it cost. Those are what produce an invoice, a timesheet and an hours log.

A coach’s private reflections, and anything a coachee writes for themselves, are encrypted. A coach cannot read a coachee’s journal unless the coachee chooses to share it. Neither can we.

If you connect a calendar, we read it to recognise your sessions and to show you your own week. Your entries stay yours: they are encrypted before they are stored, only you can see them, and nobody you coach ever sees more than whether a slot is free. When we add your protected time back, we write it to a calendar we create, and we are technically unable to alter or delete any appointment you made.

Who we are

CoachYantra is practice-management software for coaches, operated by To confirm: legal entity name, registered address, and registration number. In this page “we” means that company and “you” means whoever is reading: a coach who uses CoachYantra, or a coachee whose coach does.

The two kinds of people in this product

A coach is our customer. They decide what to record about the people they coach, and they are responsible for having a lawful basis to do so. A coachee is a person their coach works with. For coachee information we act on the coach’s instructions rather than our own.

To confirm: The exact designation of each party under the Digital Personal Data Protection Act 2023 and, where relevant, the UK and EU GDPR — who is the Data Fiduciary or controller and who is the processor — is open decision D8 and needs counsel before this page is published

What we store, and the one thing we never do

We store the shape of the work, not its content. For each session: when it was scheduled, when it actually started and ended, what kind of session it was, whether the person attended, what it billed, and whether it counts toward the coach’s accreditation hours.

About a coachee, a coach may record: name, email address, phone number, employer, job title, city and country, and where they are for tax purposes. Only what the coach chooses to enter.

We do not store what was discussed. There is no session-notes field, no transcript field, and no summary field in our database. A build gate scans every database change for one and fails the build if it appears. This is the product’s central promise, and it is enforced mechanically rather than by policy.

Private writing is encrypted, including from us

Three kinds of writing are encrypted before they reach our database: a coach’s own journal, a coachee’s own journal, and the commitments a coachee sets themselves. The database physically rejects any attempt to write them unencrypted.

A coach cannot read a coachee’s journal or commitments unless the coachee explicitly shares an entry. Our staff cannot read any of it in the ordinary course of running the service.

Recordings, where a coachee has consented to one, are held separately and deleted 90 days after they have been submitted for their purpose.

Google Calendar

Connecting a calendar is optional and can be disconnected at any time. When connected, we ask for two separate permissions and use each narrowly.

Reading. We look at events to recognise which are coaching sessions, so a coach does not have to type them twice, to work out when they are free, and to show them their own week inside the product. A coach’s own entries are encrypted before they are stored, with the same protection as their private journal — so a copy of our database reveals nothing about anyone’s appointments. We cannot change anything we read, and we never show one person’s calendar to another: a coachee booking a slot sees only whether it is free.

Writing. We create a separate calendar of our own in the account and write only there — the buffers and blocks a coach has committed to, so nobody books over them. The permission we hold reaches that calendar and nothing else, so we are technically incapable of editing or deleting an appointment made by a person. By default what we write says only “Buffer”, never a client’s name, because work calendars are often visible to colleagues.

CoachYantra’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not allow humans to read it except where required for security or law, and we do not use it to train generalised artificial-intelligence models. You can revoke our access at any time at myaccount.google.com/permissions.

Who else touches it

  • Supabase — our database and file storage, hosted in Mumbai, India.
  • Vercel — runs the application itself.
  • Google — only if a coach connects a calendar, and only as above.
  • Anthropic — only where a coach uses the two optional assistive features: suggesting coaching competencies from their own journal entry, and summarising patterns across their own entries. Only that coach’s own words are sent, never a coachee’s journal. The features are off unless configured, and they say so on screen rather than guessing when unavailable.
  • To confirm: email delivery provider, once chosen — not yet in the product

We do not sell personal information, and we do not use it for advertising.

Where it lives

In India, in Supabase’s Mumbai region. Every coach’s data is walled from every other coach’s in the database itself rather than by application code, and that wall is tested against a real database on every build.

How long we keep it

  • Session and financial records: eight years by default, because that is a common tax record-keeping period. A coach can change this for their own practice. To confirm: D1 — confirm with your accountant before publishing
  • Recordings: 90 days after submission.
  • Security and audit logs: two years.
  • Journals and commitments: until deleted. They belong to the person who wrote them, so we do not expire them on a timer.

Your rights

You may ask for a copy of your information, ask us to correct it, or ask us to delete it. A coach can export their practice at any time without asking us. If you are a coachee, approach your coach first — they hold the relationship and the record. If that does not resolve it, contact us and we will act on it directly.

To confirm: grievance officer name and contact, required under the DPDP Act; and a representative for UK or EU coachees if the product is offered there

Security

Private writing is encrypted at rest. Data is separated per coach at the database level. Access to production is limited and logged. No system is perfect, and we will tell you promptly and plainly if something happens that affects you.

Children

CoachYantra is not intended for anyone under 18, and we do not knowingly hold information about children.

Changes

If we change how any of this works we will update this page and tell coaches before it takes effect. The date at the top is when it last changed.

Contact

To confirm: privacy contact address, postal address, and grievance officer details

This page describes what the software actually does; every factual claim in it is checked by a test or a database constraint in the product. It is not legal advice, and the marked gaps need a lawyer before it is published.