Privacy Policy

Last updated: 2026-09-12

Overview

Coaching Dashboard (“we”, “us”, “our”) provides tools to analyse coaching sessions using AI and manual notes (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

Information we collect

  • Account information: when you sign in with Google, we receive your name, email address, profile photo, and a Google user identifier.
  • Google OAuth tokens: when you sign in with Google, we receive access tokens and may receive a refresh token for the Drive and Sheets access described below. Active coaches may separately authorize Calendar access. These tokens let the Service continue authorized operations without asking you to consent on every request.
  • Content you provide: recordings, transcripts, notes, and any other materials you upload or import into the Service.
  • Usage and device data: basic logs needed to operate and secure the Service (e.g., request metadata, timestamps, error logs).

Google Drive access

As part of Google sign-in, we request read-only Drive access so the Service can import files you explicitly reference in the app or in configured workflows, including direct-link import and coaching-session tracker ingestion. We use imported content to generate the session analysis and insights you request. We do not request permission to create, edit, or delete files in your Drive.

  • Scope: we request https://www.googleapis.com/auth/drive.readonly.
  • What we access: files and metadata (for example, file IDs, names, and MIME types) required to import the Google Drive content that you submit to the Service.
  • What we do not do: we do not browse your Drive for unrelated purposes, and we do not modify or delete Drive content.

Google Sheets access

As part of Google sign-in, we request read-only Sheets access so the Service can read configured coaching-session tracker and DS spreadsheet data used for coaching operations and analysis. We do not create, edit, or delete spreadsheet content.

  • Scope: we request https://www.googleapis.com/auth/spreadsheets.readonly.
  • What we access: values from the configured spreadsheets and ranges required for the session tracker and DS analysis.
  • What we do not do: we do not browse unrelated spreadsheets or modify or delete spreadsheet content.

Google Calendar access

Active coaches are separately asked to authorize read-only Calendar access. AVC reads the primary calendar's time zone and bounded event details for requested date windows: Google event ID, title, start and end time, all-day status, location, and meeting link. For administrator-run, read-only schedule analysis, AVC reads only opaque event IDs, status, transparency, start time, and end time across calendars writable by the connected account. The schedule analysis does not request event descriptions or attendees, and it does not expose calendar names, event titles, locations, or meeting links. AVC does not create, edit, or delete Google Calendar events. The reduced primary- event details can be viewed by the coach and authorized organization administrators inside the Service. When AVC matches a primary-calendar event to a coaching session, it stores the event ID, times, and meeting link with that session. When you connect Google Calendar to OpenCal for scheduling, OpenCal requests full Calendar access so it can read availability and manage the booking events it creates on the connected calendar. OpenCal does not create, rename, share, or delete calendars and does not expose unrelated event content beyond what is needed to check availability and synchronize its own bookings.

  • AVC coach availability scope: https://www.googleapis.com/auth/calendar.readonly lets AVC read bounded primary-calendar event details and content-minimal busy-event metadata on calendars writable by the connected account. AVC never modifies Google Calendar with this scope.
  • OpenCal booking scope: https://www.googleapis.com/auth/calendar lets OpenCal read your availability, create booking events, update or cancel a booking when it is rescheduled, and, when configured for a booking, create a Google Meet conferencing link. OpenCal does not use this scope to create, rename, or delete calendars, and does not access any Google service other than Calendar with it.

Data protection mechanisms

  • Authenticated access controls: app APIs require an authenticated session. Administrative operations (including admin Google Sheet ingestion settings and job controls) are restricted to admin-authorized requests.
  • Session integrity: session cookies are signed on the server, set as HTTP-only, and validated on each protected request.
  • OAuth token handling: Google OAuth tokens are stored server-side and refreshed server-side for ongoing authorized operations.
  • Credential redaction in logs: server logging redacts token, authorization, secret, and password fields before output.
  • Encrypted transport: communication with Google APIs and other external APIs used by the Service occurs over HTTPS.

How we use information

  • To provide, maintain, and improve the Service.
  • To authenticate you and keep your account secure.
  • To process uploaded/imported content to generate analysis outputs you request.
  • To troubleshoot issues and prevent abuse.

Sharing

We do not sell Google user data. We may share information with service providers that help us operate the Service (for example, hosting and database providers). They are permitted to process data only to provide services to us and not for their own purposes.

Retention

We retain information for as long as needed to provide the Service. You can delete uploaded/imported items in the Service. You can also revoke app access from your Google Account permissions at any time.

Your choices

  • Revoke Google access: you can revoke the app's grant at any time through your Google Account security settings. Revocation ends the Service's access to Google Drive, Sheets, and Calendar data; you must authorize the app again before those connected features can resume.
  • Delete content: you can delete imported/uploaded items in the Service.
  • Contact us: you can request account deletion or ask privacy questions using the contact details below.

Google API Services User Data Policy

Coaching Dashboard's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the user-facing features described in this policy and never to serve advertisements. Authorized organization administrators may view the reduced Calendar event details described above for scheduling and coaching operations after a coach authorizes the Calendar connection. We do not otherwise allow humans to read Google user data except with the user's affirmative consent for specific data, for security purposes such as investigating abuse, or to comply with applicable law.

Contact

For privacy questions or requests, contact support@trilogy.com.