Appearance
Authority Doc / Public V1 Privacy
Privacy and retention define what CoachMe collects, how long it lives, and how it leaves the system.
This page is the source of truth for privacy posture, data classification, consent, retention, export, deletion, anonymization, media purge, mobile cache purge, legal hold, incident response, and privacy evidence.
UAE FirstGCC ReadyWellness OnlyPrivacy Minimal
Note
This is an engineering authority document and not legal advice.
Scope
This authority owns privacy posture and retention behavior for Public V1, while adjacent authority docs keep their own mechanics and transport rules.
This Authority Owns
- Data classes.
- Consent.
- Disclaimer.
- Retention.
- Export.
- Deletion.
- Anonymization.
- Media purge.
- Mobile cache purge triggers.
- Legal hold.
- Incident workflow.
- Privacy test evidence.
This Authority Does Not Own
- Final legal advice.
- Clinical workflows.
- Role checks.
- REST envelope shape.
- Mobile sync mechanics.
- Event/outbox mechanics.
- Provider contracts.
- Observability tooling detail.
Product Boundary
Public V1 is a wellness product. Product language, workflow shape, and retention decisions must reinforce that wellness-only boundary.
Allowed Public V1 Language
- Wellness coaching, onboarding, forms, programs, daily logging, progress, nutrition, and communication.
- Wellness disclaimers, consent notices, and privacy-minimal collection.
- Coach-client relationship, personal workspace, and support/admin access with scoped privacy controls.
Disallowed Public V1 Language And Behavior
diagnosistreatmentmedical adviceclinical care planprovider-patient relationshipemergency triagedisease-management workflowsclaims that CoachMe prevents, treats, or cures a condition
Jurisdiction
Public V1 launches as UAE-first and GCC-ready, but only after formal legal review sets the production release boundary.
Launch Position
Public V1 is UAE-first and GCC-ready. Production launch requires legal review for UAE PDPL and each target GCC country before accepting real users, and each additional GCC country needs a launch checklist before activation.
Open Business Jurisdiction Decision
The UAE business licensing jurisdiction—mainland, DIFC, ADGM, or another free zone—must be selected before formal review. Production cannot accept real users until the reviewer confirms the rules applicable to that selected jurisdiction.
Minor Boundary
Minors are out of Public V1 unless legal review approves age gates, guardian consent, and minor-data retention.
Data Classes
Each data class carries a sensitivity label and a default handling rule that feature pages inherit unless this authority explicitly says otherwise.
| Data Class | Examples | Sensitivity | Default Rule |
|---|---|---|---|
| Account and identity | Name, email, phone, login identity, locale, account settings. | Moderate | Collect the minimum needed for account creation, authentication, and privacy communication. |
| Workspace and relationship | Coach workspace membership, client invitations, relationship status, assignments, ownership context. | Moderate | Retain only as long as the relationship and audit requirements need it. |
| Sensitive wellness profile | Goals, habits, allergies, injuries, onboarding answers, measurements, nutrition preferences, wellness notes. | High | Gate behind explicit notice and consent, scoped access, and export/delete controls. |
| Execution data | Workout logs, daily check-ins, task completion, nutrition logs, progress milestones. | High | Retain per relationship state and privacy request status, with correction through amendment records. |
| Sensitive media | Progress photos, voice notes, form attachments, sensitive uploads. | High | Use protected storage, signed URLs, lifecycle records, and purge receipts. |
| Communications | Messages, playback events, attachment references, communication receipts. | High | Scope to relationship participants and reason-coded support/admin access only. |
| Operational data | Device registrations, sync receipts, request ids, rate limits, moderation flags, delivery receipts. | Moderate | Separate operational observability from user-facing product data and retain only policy-bound history. |
| Identifiable/minimized operational telemetry | Pino logs, Sentry events, diagnostic identifiers, and approved internal ids in restricted operational context. | Restricted | Minimize before export, restrict access, and expire no later than 30 days after creation. |
| Strictly aggregate operational/synthetic metrics | Metrics and synthetic results with no subject identifiers, free text, raw samples, or user-controlled dimensions. | Moderate | Retain no longer than 13 months while irreversibly non-identifying. |
| Audit, legal, and security | Audit events, legal hold records, deletion receipts, security incident evidence, breach records. | Restricted | Keep immutable or append-only evidence with the narrowest permitted access path. |
Note
Sensitive wellness/media/communication/diagnostic data must not be sold, used for ads, exposed to broad analytics, reused for unrelated model training, or shared across contexts in Public V1.
Operational Telemetry Windows
Operational evidence expires by data class; provider settings cannot expand these maxima.
Operational telemetry retention windows
| Class | Maximum | Lifecycle rule |
|---|---|---|
| Identifiable/minimized telemetry | 30 days | Logs, Sentry events, diagnostic identifiers, and approved internal ids expire within 30 days of creation. |
| Synthetic logs and diagnostic samples | 30 days | Use the same short window; never retain request content or secrets. |
| Strictly aggregate metrics/synthetics | 13 months | Allowed only while irreversibly non-identifying. Any linkable dimension moves the signal into the 30-day class. |
| Provider configuration | No greater than the class maximum | Record actual windows in Integration Register. Incompatible fixed windows keep the provider Conditional or evidence Blocked. |
Deletion Interaction
Stop new subject-linked capture when deletion/anonymization takes effect. Remove safe direct links early where supported; otherwise minimized evidence ages out within 30 days. Non-identifying aggregates are not subject-specific deletion targets.
Audit And Legal Separation
Ordinary logs and Sentry events are not audit records. Copying telemetry does not create compliant security/legal evidence. Legal hold blocks expiry only for explicitly scoped records under the legal-hold workflow.
Release evidence retention windows
| Evidence Class | Maximum | Privacy Rule |
|---|---|---|
| Non-identifying release manifest | Product lifetime | Limited to commit, artifact digest, versions, migrations, check outcomes, approval, and production outcome; no user, device, request, or telemetry identifiers. |
| Synthetic screenshots and videos | One year | Allowed only after automated and manual verification that the artifact contains synthetic UI data with no real identifier, telemetry, credential, or production content. |
| Detailed CI logs and failed-test artifacts | 30 days | Use synthetic data only and follow the synthetic-log maximum. Shorten or quarantine immediately when a secret or real identifier appears. |
| Accidental production or identifiable content | Not normal release evidence | Quarantine, investigate, and delete under the incident and applicable data-class rules. |
Consent And Notice
Consent is a versioned ledger, not a single checkbox. Every high-sensitivity flow must record the notice shown, the surface used, and withdrawal handling.
Versioned Consent Ledger Fields
user_id- Active account/context.
- Privacy policy version.
- Terms version.
- Wellness disclaimer version.
- Sensitive wellness data consent version.
- Media consent version.
- Optional marketing consent version.
- Language/locale shown.
- Accepted timestamp.
- Source app surface.
- IP/device/request metadata where legally appropriate.
- Withdrawal timestamp.
- Withdrawal reason category.
Required Consent Gates
- Registration.
- Sensitive onboarding.
- Media.
- Coach access explanation.
- Marketing opt-in.
- Withdrawal.
Retention Policy
Retention defaults follow relationship and account lifecycle. Deviations require legal review and an explicit documented rule.
| State | Public V1 Default | Rule |
|---|---|---|
| Active relationship | Retain active records. | Keep data available for the active service relationship and approved privacy rights handling. |
| Paused relationship | Retain active records with reduced activity. | Pause reminders and pressure workflows without forcing premature deletion. |
| Ended relationship days 0-30 | Read-only retention window. | The 30-day ended-relationship window is the default. |
| Ended relationship after day 30 | Delete or anonymize by default. | Apply delete/anonymize after day 30 unless legal hold or required retention applies. |
| Deleted/anonymized relationship | Remove normal product access. | Keep only required audit, legal, and security evidence. |
| Account deletion requested | Start scoped deletion workflow. | Verify identity, calculate impact, revoke sessions/devices, purge caches, and execute delete/anonymize jobs. |
| Workspace closed | Block normal use and move to retention/export/delete rules. | Relationship and workspace closure do not preserve indefinite operational access. |
| Backups | Expire by backup policy. | Deleted records may persist only until backup rotation and replay deletion complete. |
Legal-Review-Dependent Windows
- Tax/accounting records if payments enter scope.
- Audit/security logs.
- Legal claims.
- Breach records.
- Country-specific requirements.
Default Posture
Public V1 uses retention windows that are short, scoped, and reviewable. Any longer window must identify its legal or operational reason and the exact data classes it covers.
Relationship-End Cleanup
Relationship end is a privacy event, not only a workflow state transition. Access, cache, reminders, and pending operations all change immediately.
Immediate Effects
- Immediate coach edit lock.
- Reminder suppression.
- 30-day read-only window.
- Mobile cache purge/lock.
- Signed media URL expiry.
Cleanup Path
- Pending offline operation rejection or cleanup scoping.
- Delete/anonymize after day 30 unless legal hold or required retention applies.
- Preserve only the scoped records covered by legal hold or required retention rules.
Export, Correction, Deletion
Privacy rights handling must be scoped, auditable, and explicit about what is included, excluded, corrected, deleted, and retained.
Export
Include allowed profile, relationship summary, forms, workouts, nutrition, measurements, messages, media files/references, consent history, and privacy request status.
Exclude private coach notes, other users' data, raw diagnostics, unrelated workspace records, and support/admin-only audit payloads.
Correction
Use amendment records for immutable history so the platform can correct user-visible facts without erasing auditability.
Deletion And Anonymization
- Intake.
- Verification.
- Scope calculation.
- Active relationship/workspace impact review.
- Optional export offer.
- Session/device revocation.
- Mobile cache purge command.
- Media purge jobs.
- Database delete/anonymize jobs.
- Audit/legal/security retention decision.
- Deletion receipt.
Media And Object Storage
Sensitive media gets a stricter lifecycle than general records because raw objects, signed URLs, and purge timing can leak more than normal structured data.
Storage And Access Rules
- Protected object storage.
- Short-lived signed URLs.
- No long-lived signed URL persistence.
- Canonical media records after upload completion and policy validation.
- Audited support playback/download.
- Safe progress photo export packaging.
Lifecycle And Purge Rules
- Lifecycle states
PENDING_UPLOAD,AVAILABLE,QUARANTINED,PENDING_PURGE,PURGED, andFAILED_PURGE. - Idempotent purge jobs.
- Purge receipts.
Mobile Cache
Privacy purge triggers define when local state must be removed or locked. offline-sync-protocol owns mechanics.
- Confirmed logout.
- Account switch.
- Device revocation.
- Relationship end.
- Workspace suspension/closure.
- Permission revocation.
- Account deletion.
- Retention expiry.
- Legal/security incident.
Legal Hold
Legal hold freezes purge only for the scoped records tied to a case. It does not create broad indefinite retention across unrelated data.
Minimum Legal Hold Fields
- Case id.
- Reason code.
- Owner.
- Target scope.
- Data classes covered.
- Created timestamp.
- Expiry/review date.
- Release process.
- Audit events.
Scope Rule
Legal hold blocks purge only for scoped records.
Incident Response
Privacy incidents follow one explicit workflow so containment, evidence preservation, review, and notification decisions do not drift between teams.
- Classify incident.
- Freeze risky access/tokens.
- Preserve evidence.
- Notify security/legal/compliance owner.
- Identify affected data classes/users.
- Decide user/regulator notification path through legal review.
- Record remediation and closure.
Observability owns detection and a sanitized technical timeline. Suspected exposure, unauthorized access, or privacy impact enters this Privacy incident workflow immediately.
Feature-Page Rules
Every feature page that handles user or operational data must point back to this authority and spell out its privacy behavior in concrete terms.
- Identify data classes.
- Identify owner context.
- Identify consent/notice dependency.
- Identify retention window.
- Identify relationship-end behavior.
- Identify account-deletion behavior.
- Identify media purge behavior.
- Identify mobile cache purge trigger.
- Identify export inclusion.
- Identify correction/amendment behavior.
- Identify audit events.
- Identify legal hold behavior.
- Identify privacy tests.
Required Privacy Test Cases
Release evidence must prove that notices, consent, boundaries, retention windows, purge paths, scoped access, and backup replay all behave the way this authority says they do.
| Evidence Area | Required Proof |
|---|---|
| Consent/notice | Versioned ledger records, locale capture, and withdrawal handling. |
| Wellness disclaimer | Registration and sensitive-flow gating proves the wellness-only posture is shown before collection. |
| Ended relationship read-only lock | Coach edits stop immediately and retained history becomes read-only. |
| 30-day cleanup | Default 30-day window triggers delete/anonymize jobs unless scoped retention blocks them. |
| Account deletion | Identity verification, session/device revocation, purge jobs, and receipt creation. |
| Export exclusions | Private coach notes, other users' data, raw diagnostics, unrelated workspace records, and support/admin-only audit payloads stay out. |
| Correction amendments | Immutable history remains intact while corrected values are surfaced properly. |
| Media purge | Protected storage objects, lifecycle state changes, and purge receipts complete idempotently. |
| Signed URL expiry | Short-lived access expires and long-lived persistence is blocked. |
| Mobile cache purge | Each purge trigger removes or locks local data according to scope. |
| Offline operation rejection after permission/retention change | Pending operations are rejected or cleaned up when permission or retention changes invalidate them. |
| Scoped legal hold | Purge stops only for the records covered by the hold. |
| Support/admin grant | Reason-coded, scoped, audited access gates sensitive reads, playback, download, export, and delete operations. |
| Audit separation | Audit/legal/security evidence remains separate from standard product views and exports. |
| Backup deletion replay | Backup rotation and replay deletion close the final copy path after primary deletion. |
Related Docs
These pages define the adjacent authority boundaries that privacy and retention depends on but does not absorb.
Workflow state map
Lifecycle states that trigger read-only, purge, and delete/anonymize transitions.
Roles and permissions
Access boundaries for sensitive wellness data, media, communications, and support/admin grants.
API contract standard
Export, delete, and consent endpoints must use the common REST contract.
Event and outbox standard
Deletion, purge, and incident workflows that rely on backend events and outbox guarantees.
Offline sync protocol
Owns mobile cache mechanics, purge execution, and offline operation rejection behavior.
Integration Register
External providers and self-hosted application boundaries, including processor data paths, provider retention, cache rights, fallbacks, and launch evidence.
Observability Plan
Defines operational signal and incident-detection needs while this authority owns telemetry classification, retention, deletion interaction, and privacy response. Operational telemetry never replaces audit evidence.
Test And Release Gate
Defines when privacy tests, retention jobs, and deletion/export verification block merge or release.