Privacy Policy
Last updated: September 9, 2026
Overview
This Privacy Policy explains how Coaching Explained collects, uses, and shares personal information. It covers two different groups of people, because Coaching Explained plays two different roles:
- Organizations (and the managers who administer them) — businesses and individuals who subscribe to a Coaching Explained account. For organization account data, Coaching Explained is the data controller.
- Staff / Employees — people invited by an organization manager to take courses under that organization’s account. For their training progress and related data, the organization is generally the data controller (it’s their employer, and their relationship with their staff), and Coaching Explained acts as the organization’s data processor / service provider, as described further in our Data Processing Agreement.
If you’re a staff member and want to exercise a privacy right, your first stop should usually be the organization that invited you — but you’re welcome to contact us directly at privacy@coachingexplained.com and we’ll assist or route your request.
Information we collect
From organization managers
- Account information: name, email address, password (stored as a salted hash, never in plain text), organization name.
- Billing information: handled directly by Stripe — we receive subscription/payment status but never see or store full card numbers.
- Content you configure: courses, videos, lesson thumbnails, questions, and any organization-authored training material.
- Support and contact-form communications you send us.
From staff / employees
- Account information: name, email address, and password, provided when joining via an organization’s access code.
- Usage data: video watch progress, question responses, course completion status, and certificates earned.
- Basic technical data (IP address, browser user-agent) used transiently for rate-limiting, abuse prevention, and security logs.
Visibility to your manager. If you’re a staff member, your organization’s manager — and any staff member your organization has promoted to “editor” — can see your course progress, quiz/question responses, and completion certificates, and can leave comments on your answers. This is core to how the Service works: your organization is using it to track and support your training, the same way it would track training completed through any other workplace system. It is never visible to any other organization. Your organization is responsible for telling you this data exists as part of onboarding you as staff; Coaching Explained’s role is to process it on their behalf, as described in our Data Processing Agreement.
How we use information
- To operate the Service — course access, progress tracking, certificate issuance, and (for eligible plans) AI-assisted content generation.
- To send transactional and account emails — welcome messages, invites, password resets, billing receipts, course-completion notices, and answer-review notifications.
- To detect and prevent abuse, enforce rate limits and plan quotas, and keep the Service secure.
- To monitor, diagnose, and fix errors (via Sentry).
- To improve the Service and develop new features.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use your content or progress data to train our own foundation models. When you use an AI generation tool, relevant content (e.g. a video transcript, or your own manual instructions) is sent to our AI sub-processors (Anthropic, OpenAI, AssemblyAI) solely to produce that output. Submissions through each provider’s commercial API are governed by that provider’s own API/business terms, which — unlike their free consumer products — generally exclude API inputs and outputs from being used to train the provider’s models by default; see each provider’s own terms for specifics.
International data transfers
Coaching Explained and the sub-processors listed above are based in the United States. If you’re located in the European Economic Area, United Kingdom, or Switzerland, your personal information will be transferred to and processed in the United States and potentially other countries whose laws may differ from your own. Where required, such transfers are made on the basis of the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or a sub-processor’s own certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), to the extent each sub-processor participates in that framework. Contact privacy@coachingexplained.com if you’d like more detail on the transfer mechanism used for a specific sub-processor.
Data retention
- Organization and staff account data is retained for as long as the account is active.
- If an organization’s subscription is cancelled, its data is retained for 90 days (to allow reactivation) before being permanently deleted, except where we’re required to retain it longer by law.
- Progress data, question responses, and certificates are retained until the organization deletes them or closes its account, subject to the same grace period.
- Billing records are retained as long as required by tax and accounting law.
- Deleting a course, video, or account removes the underlying records, though recent backups may retain a copy for a limited time before they age out.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. To exercise any of them, email privacy@coachingexplained.com — we may need to verify your identity first, and we’ll respond within the timeframe required by the law that applies to your request (commonly around 30 days).
EU / UK GDPR
Right to access, rectify, erase, or restrict processing of your personal information; right to data portability; right to object to processing (including profiling); right to withdraw consent where processing is based on consent; and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
Right to know what personal information we’ve collected, right to delete it, right to correct inaccurate information, right to limit use of sensitive personal information, and the right to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
Brazil (LGPD)
Right to confirmation of processing, access, correction, anonymization, portability, and deletion of your personal information, and the right to lodge a complaint with the ANPD.
Canada (PIPEDA) & Australia (Privacy Act)
Right to access and request correction of your personal information, to withdraw consent where applicable, and to complain to the Office of the Privacy Commissioner of Canada or the Office of the Australian Information Commissioner (OAIC), respectively.
If you’re in a jurisdiction not listed above, contact us — we aim to honor equivalent rights under your local law regardless.
AI transparency
On plans where AI tools are enabled, an organization manager or authorized content editor can generate video quiz questions, text/slide lessons, or full courses using AI. Generated content is clearly presented for review inside the course editor before it’s ever published to staff — nothing generated by AI reaches an employee automatically without the organization choosing to publish it.
AI content generation is performed by the provider a given tool is configured to use (currently Anthropic for text/questions, OpenAI for slide images), based on the organization’s own video transcripts, uploaded material, or written instructions — not by a Coaching Explained employee reviewing each request in real time.
AI is used in the Service to help author training content, never to grade it or evaluate a staff member. Multiple-choice quiz scoring is a deterministic comparison against the answer key an organization’s manager or editor set (or approved, for an AI-drafted question) when the lesson was published — it is not an AI judgment. Written-answer review, comments, and any broader assessment of a staff member’s performance are made by the organization’s own human managers.
Children's privacy
The Service is intended for adult staff and organization managers, and account holders must be old enough to form a binding contract in their jurisdiction. We don’t knowingly collect personal information from anyone under the age of 16. If you believe a minor has provided us personal information through the Service, contact privacy@coachingexplained.com and we’ll delete it.
Security
We use industry-standard safeguards, including encryption in transit (TLS) across the Service, hashed passwords, and access controls limiting who can reach production data. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security — but we work to keep these protections current and will notify affected organizations of any breach as required by applicable law.
Changes to this policy
We may update this Privacy Policy from time to time. We’ll post the revised version here with an updated “Last updated” date, and for material changes we’ll provide at least 14 days’ notice by email or in-product notice before they take effect.
Contact us
Questions about this Privacy Policy, or a privacy right you’d like to exercise? Email privacy@coachingexplained.com, or reach us through the contact page. For a copy of our Data Processing Agreement or a signed addendum, email legal@coachingexplained.com.