← Back to LiveCoach

LiveCoach is a running and fitness coaching app that uses Apple HealthKit data and AI to generate personalised training plans. This policy explains what data we collect, why, and how we protect it.

LiveCoach is operated by LiveCoach Ltd., a company registered in England and Wales (company number 17295654), registered office 66 Paul Street, London, EC2A 4NA, United Kingdom (privacy@livecoach.health). For individuals in the EU or EEA, our representative under Article 27 of the EU GDPR is Prighter EU Rep GmbH, 9 Clare Street, Dublin 2, D02 HH30, Ireland (see Contact Us).

1. Data We Collect

Account & Profile Data

When you create an account and set up your profile, we collect:

Subscription Data

LiveCoach is a paid subscription, bought through the App Store. Apple handles the payment; we never receive or store your card details, billing address, or any other payment information. What we do store, so the app knows your subscription is active, is:

Health & Fitness Data

With your permission, we read the following from Apple HealthKit:

We only read data from HealthKit — we never write to it.

Device & Technical Data

We do not collect location data, contacts, photos, browsing history, or device identifiers for advertising. Workout GPS routes are processed only on your device, to calculate distance and elevation summaries for each part of a workout — the route itself never leaves your phone.

Website Visits

When you visit livecoach.health, the content delivery network that serves the site records each request in a server log: your IP address, your browser’s user-agent string, the page requested, the site that referred you (if any), and the country the request came from. We use these logs to keep the site secure and to count how many people visit and where they arrive from.

Our lawful basis is legitimate interests (Art. 6(1)(f)): understanding whether our own website works and how people find it is a routine expectation of running a website, and the minimal data, short retention, and absence of any cross-site tracking or profiling mean it has little effect on your privacy. This is separate from the app — visiting the website creates no account and is never linked to one.

2. How We Use Your Data

Each purpose below has a lawful basis under the UK GDPR and EU GDPR:

Purpose Data Used Lawful Basis
Generate and adapt your training plan Health data, profile, goals, injury history (section 3) Explicit consent — Art. 6(1)(a) and 9(2)(a)
Run your account, authenticate you, and deliver your plan Apple ID, session tokens, profile and preferences Contract — Art. 6(1)(b)
Send push notifications Device token (plan-ready alerts only) Contract — Art. 6(1)(b)
Unlock the features your subscription pays for Subscription status from Apple (no payment details) Contract — Art. 6(1)(b)
Fix bugs, keep the service secure, prevent abuse Error diagnostics and request logs (no health data) Legitimate interests — Art. 6(1)(f)
Keep consent, legal-acceptance and deletion records Audit records (versions and timestamps, no health data) Legal obligation — Art. 6(1)(c)
Email you about the launch, if you signed up on our website First name and email address (section 5) Consent — Art. 6(1)(a)

“Contract” means the processing is necessary to provide the service you signed up for. Where we rely on legitimate interests, we have balanced them against your rights: the data involved is minimal, kept briefly, and used only to keep the service you are using working and secure — you can object at any time (see section 8).

We do not use your data for advertising, user profiling for marketing, or selling to third parties.

3. Health Data Storage & AI Processing

LiveCoach works by securely storing your health data on our servers and analysing it with AI to create and adapt your personalised training plan. Storage and AI analysis go together — the app cannot provide its coaching service without both, so we ask for your explicit consent to this processing during onboarding, and the app does not upload any health data until you have given it.

Health data is special-category data under UK and EU data protection law. Our lawful basis for processing it is your explicit consent (UK GDPR / EU GDPR Articles 6(1)(a) and 9(2)(a)). Your consent covers, together:

When your plan is generated or adapted, we send the following to Anthropic (the company behind Claude, our AI provider):

How Anthropic handles your data

Anthropic is based in the United States. This transfer is safeguarded by Anthropic’s data processing agreement, which incorporates the UK and EU approved standard contractual clauses.

All user-entered text is sanitised before being sent for processing to prevent misuse.

If we change what consent covers

If we materially change what your consent covers — the data categories, the processing, or the partners involved — the app will ask you to review and re-confirm consent before health-data syncing continues. Until you re-consent, no further health data is uploaded.

Declining or withdrawing consent

Consent is required to use LiveCoach: if you decline during onboarding, no health data leaves your device and no account data is processed for coaching — you can simply sign out. You can withdraw consent at any time by declining when the app asks you to re-confirm, by contacting us at privacy@livecoach.health, or by deleting your account from the app’s profile screen. Withdrawing consent immediately stops health-data uploads and plan updates; deleting your account additionally removes all data we already hold, permanently.

4. Third-Party Services

We use a limited number of third-party services to operate LiveCoach:

Purpose Data Shared
Authentication — Sign in with Apple (Apple) Apple-issued user token
Cloud infrastructure & data storage (Amazon Web Services) All app data (encrypted at rest and in transit)
Push notifications (Apple) Device token only
Subscription billing — App Store (Apple) Handled entirely by Apple; we receive only confirmation of what you bought and whether it is still active
AI training plan generation (Anthropic) Profile and health data (with your consent)
Error monitoring (Sentry) Crash and error diagnostics, linked to your account identifier — never health data or contact details

Our cloud infrastructure is hosted in the United Kingdom (London), which the European Commission recognises as providing adequate data protection. Health data sent for AI processing is transmitted securely and deleted by our AI provider within 30 days (retained during that window only to monitor for misuse — see section 3). No third party receives your health data except our AI provider, and only with your explicit consent.

5. Marketing Emails

If you sign up for updates on livecoach.health, we collect your first name and email address and use them to email you about the LiveCoach launch and product news. We ask for your name only so we can address the emails to you.

We also record which of our links brought you to the sign-up form — for example, our Instagram profile link, so we can see which channels people hear about us through. This is a simple label attached to the link itself (our Instagram bio link ends in ?src=ig-bio); it says which link was followed, not who followed it. We do not use cookies, advertising identifiers, or any other tracking on this website, and we cannot follow you around the internet. If you reach the form any other way, the label is simply “direct”. It is stored on the same record as your email and is deleted with it when you unsubscribe.

The sign-up form also asks three optional questions — which watch or fitness device you use, how often you train each week, and your main training goal — so we can prioritise invites while LiveCoach is in private beta (for example, inviting a mix of devices to test with). Each answer is chosen from a fixed list; nothing you type is stored, and leaving them blank does not affect your place on the list. The answers are stored on the same record as your email and are deleted with it when you unsubscribe.

Our lawful basis is your consent (UK GDPR / EU GDPR Article 6(1)(a)), given when you submit the sign-up form; we also rely on your consent to send the messages themselves under the UK Privacy and Electronic Communications Regulations (PECR).

6. Data Storage & Security

We take the security of your health data seriously and apply industry-standard protections:

7. Data Retention

Data Type Retention Period
Health snapshots 90 days, then automatically deleted
Training plans 90 days, then automatically deleted
Workout records & AI workout feedback 90 days, then automatically deleted
Coach chat history 60 days, then automatically deleted
User profile Until you delete your account
Subscription status Until you delete your account
Audit logs (consent and deletion records) Up to 7 years for legal compliance, containing no health data
Data sent to AI provider Deleted by Anthropic within 30 days of processing
Marketing email list Until you unsubscribe — the record is then deleted outright
Website visit logs 30 days, then automatically deleted

When you delete your account, all your personal data, health snapshots, and training plans are permanently removed. Deleted data also ages out of our encrypted backups automatically within 35 days. A minimal audit record (containing no health data) is retained for a limited period to satisfy legal record-keeping obligations, then automatically deleted.

8. Your Rights & Choices

Depending on where you live, you may have some or all of the following rights regarding your personal data:

To exercise any of these rights, email privacy@livecoach.health. We will respond within 30 days. If you are in the EU or EEA, you can also raise any of these rights, or a question about how we handle your data, with our EU representative — see Contact Us.

9. Apple HealthKit

In compliance with Apple’s requirements:

10. Children’s Privacy

LiveCoach is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. If we make material changes — particularly to how we handle health data or AI processing — we will notify you in the app before the changes take effect. The "effective date" at the top of this page indicates when the policy was last revised.

12. Contact Us

If you have questions about this policy or your data, contact us at:

LiveCoach Ltd.
66 Paul Street
London EC2A 4NA
United Kingdom
Registered in England and Wales, company number 17295654
privacy@livecoach.health

EU/EEA representative (Article 27 EU GDPR)
Prighter EU Rep GmbH
9 Clare Street
Dublin 2, D02 HH30
Ireland
Submit a request via Prighter's Trust Center

If you are in the EU or EEA, you can contact our representative instead of us on any matter relating to how we process your personal data — including requests to access or erase your data — by post at the address above or through the Trust Center link. They will pass your message on to us.

Version History

Date Summary of Changes
13 September 2026 Subscription Data: disclosed that we may record complimentary access we grant ourselves — friends and family of the team, partners, or goodwill — as a category, a grant date, and an optional end date. Set by us, never by the app; no payment or Apple data involved. Everything else is unchanged.
13 September 2026 Training profile: disclosed a fifth weekly-commitment tag, “other” — for a fixed weekly session the existing gym, club-run, team-sport and class tags don’t describe — and that its short note is required (the other tags’ notes remain optional), because the note is the only thing that says what the session is. Collected and used exactly as the existing commitments are: sent to our AI provider with your other training preferences when your plan is generated.
12 September 2026 Health & Fitness Data: disclosed that each day’s health data now records whether your Apple Watch was worn overnight and, if so, the first and last times it recorded your heart rate that night — worked out on your phone from when the watch recorded heart rate, without reading the values — so that a night your watch spent charging is not read as a night you did not sleep. Unlike the sleep-session times disclosed on 29 August, this is included in the daily health data sent to our AI provider, so your coach can tell a missing sleep record from a short or partial night.
6 September 2026 Device & Technical Data: disclosed that the app now records which watch or fitness tracker your Apple Health data comes from — worked out on your phone from which apps write to Apple Health, without reading any measurement, and changeable in your profile — so your coach knows which measurements your device can and cannot record. Section 3: the device brand is included in the profile information sent to our AI provider; the name of the app it was detected from is not.
5 September 2026 Named our EU/EEA representative under Article 27 of the EU GDPR — Prighter EU Rep GmbH, Dublin — in the controller details and Contact Us, with a link to their Trust Center for submitting requests, and noted that people in the EU or EEA can raise rights requests and questions through the representative. Named the Information Commissioner's Office alongside your national authority in the complaint right. No change to what we collect or how it is processed.
29 August 2026 Training profile: disclosed the weekly commitments added to the profile — days you tag as gym, club-run, team-sport, or class days, with an optional short note — collected so your training plan can schedule around your fixed weekly appointments. Like your other training preferences, they are sent to our AI provider when your plan is generated.
25 August 2026 Marketing Emails: disclosed the three optional questions added to the beta sign-up form — watch or fitness device, weekly training frequency, and main training goal — used to prioritise private-beta invites. Each answer is selected from a fixed list rather than typed, the questions are optional, and the answers are deleted with the record on unsubscribe.
17 August 2026 Added a “Website Visits” subsection to section 1 describing the server logs our content delivery network writes when someone visits livecoach.health — the fields recorded, legitimate interests as the lawful basis, and the facts that the site sets no cookies, runs no analytics or advertising scripts, shares nothing with a third party, and that the raw logs are deleted after 30 days; added a matching retention row. Marketing Emails: disclosed that the mailing list records which of our links brought you to the sign-up form (a channel label such as ig-bio, or “direct”), what it is for, that it identifies the link rather than the person, and that the label is deleted with your record when you unsubscribe.
14 August 2026 Added a Marketing Emails section covering the website sign-up list (what we collect, consent as the lawful basis, the unsubscribe link, deletion on unsubscribe, and its separation from app accounts) and a matching retention row; stated the lawful basis for every purpose in the “How We Use Your Data” table; corrected the description of error monitoring — crash reports are linked to an account identifier rather than anonymous, and never contain health data or contact details; named the third-party providers behind each service in section 4. Added the subscription to the policy for the first time — what is stored (and that Apple handles payment, so we never receive card or billing details), its purpose and lawful basis, Apple’s billing role, and its retention. Sections 5–11 renumbered to 6–12.
11 August 2026 Corrected Anthropic’s retention window (deletion within 30 days, not 7; flagged content may be kept longer) and noted the safeguards for the transfer to Anthropic in the US; stated the exact retention periods for health, plan, workout, and chat data; clarified that our infrastructure is hosted in the United Kingdom (London); noted that workout GPS routes are processed on-device only; noted the 35-day backup window after account deletion; added LiveCoach Ltd.’s registered office address to the controller identification and Contact Us sections.
27 July 2026 Added in-app self-serve data export (Profile → Export My Data) and updated the data-portability right to reference it.
23 July 2026 Clarified that explicit consent covers server-side storage of health data together with AI analysis, and is required to use the app; corrected the description of Anthropic’s data retention (up to 7 days for abuse monitoring, then deleted); added re-consent on scope changes and the right to withdraw consent.
2 April 2026 Initial version