Skip to content

Authority Doc / Public V1 Privacy

Privacy and retention define what CoachMe collects, how long it lives, and how it leaves the system.

This page is the source of truth for privacy posture, data classification, consent, retention, export, deletion, anonymization, media purge, mobile cache purge, legal hold, incident response, and privacy evidence.

UAE FirstGCC ReadyWellness OnlyPrivacy Minimal

Note

This is an engineering authority document and not legal advice.

Scope

This authority owns privacy posture and retention behavior for Public V1, while adjacent authority docs keep their own mechanics and transport rules.

This Authority Owns

  • Data classes.
  • Consent.
  • Disclaimer.
  • Retention.
  • Export.
  • Deletion.
  • Anonymization.
  • Media purge.
  • Mobile cache purge triggers.
  • Legal hold.
  • Incident workflow.
  • Privacy test evidence.

This Authority Does Not Own

  • Final legal advice.
  • Clinical workflows.
  • Role checks.
  • REST envelope shape.
  • Mobile sync mechanics.
  • Event/outbox mechanics.
  • Provider contracts.
  • Observability tooling detail.

Product Boundary

Public V1 is a wellness product. Product language, workflow shape, and retention decisions must reinforce that wellness-only boundary.

Allowed Public V1 Language

  • Wellness coaching, onboarding, forms, programs, daily logging, progress, nutrition, and communication.
  • Wellness disclaimers, consent notices, and privacy-minimal collection.
  • Coach-client relationship, personal workspace, and support/admin access with scoped privacy controls.

Disallowed Public V1 Language And Behavior

  • diagnosis
  • treatment
  • medical advice
  • clinical care plan
  • provider-patient relationship
  • emergency triage
  • disease-management workflows
  • claims that CoachMe prevents, treats, or cures a condition

Jurisdiction

Public V1 launches as UAE-first and GCC-ready, but only after formal legal review sets the production release boundary.

Launch Position

Public V1 is UAE-first and GCC-ready. Production launch requires legal review for UAE PDPL and each target GCC country before accepting real users, and each additional GCC country needs a launch checklist before activation.

Open Business Jurisdiction Decision

The UAE business licensing jurisdiction—mainland, DIFC, ADGM, or another free zone—must be selected before formal review. Production cannot accept real users until the reviewer confirms the rules applicable to that selected jurisdiction.

Minor Boundary

Minors are out of Public V1 unless legal review approves age gates, guardian consent, and minor-data retention.

Data Classes

Each data class carries a sensitivity label and a default handling rule that feature pages inherit unless this authority explicitly says otherwise.

Data ClassExamplesSensitivityDefault Rule
Account and identityName, email, phone, login identity, locale, account settings.ModerateCollect the minimum needed for account creation, authentication, and privacy communication.
Workspace and relationshipCoach workspace membership, client invitations, relationship status, assignments, ownership context.ModerateRetain only as long as the relationship and audit requirements need it.
Sensitive wellness profileGoals, habits, allergies, injuries, onboarding answers, measurements, nutrition preferences, wellness notes.HighGate behind explicit notice and consent, scoped access, and export/delete controls.
Execution dataWorkout logs, daily check-ins, task completion, nutrition logs, progress milestones.HighRetain per relationship state and privacy request status, with correction through amendment records.
Sensitive mediaProgress photos, voice notes, form attachments, sensitive uploads.HighUse protected storage, signed URLs, lifecycle records, and purge receipts.
CommunicationsMessages, playback events, attachment references, communication receipts.HighScope to relationship participants and reason-coded support/admin access only.
Operational dataDevice registrations, sync receipts, request ids, rate limits, moderation flags, delivery receipts.ModerateSeparate operational observability from user-facing product data and retain only policy-bound history.
Identifiable/minimized operational telemetryPino logs, Sentry events, diagnostic identifiers, and approved internal ids in restricted operational context.RestrictedMinimize before export, restrict access, and expire no later than 30 days after creation.
Strictly aggregate operational/synthetic metricsMetrics and synthetic results with no subject identifiers, free text, raw samples, or user-controlled dimensions.ModerateRetain no longer than 13 months while irreversibly non-identifying.
Audit, legal, and securityAudit events, legal hold records, deletion receipts, security incident evidence, breach records.RestrictedKeep immutable or append-only evidence with the narrowest permitted access path.

Note

Sensitive wellness/media/communication/diagnostic data must not be sold, used for ads, exposed to broad analytics, reused for unrelated model training, or shared across contexts in Public V1.

Operational Telemetry Windows

Operational evidence expires by data class; provider settings cannot expand these maxima.

Operational telemetry retention windows

ClassMaximumLifecycle rule
Identifiable/minimized telemetry30 daysLogs, Sentry events, diagnostic identifiers, and approved internal ids expire within 30 days of creation.
Synthetic logs and diagnostic samples30 daysUse the same short window; never retain request content or secrets.
Strictly aggregate metrics/synthetics13 monthsAllowed only while irreversibly non-identifying. Any linkable dimension moves the signal into the 30-day class.
Provider configurationNo greater than the class maximumRecord actual windows in Integration Register. Incompatible fixed windows keep the provider Conditional or evidence Blocked.

Deletion Interaction

Stop new subject-linked capture when deletion/anonymization takes effect. Remove safe direct links early where supported; otherwise minimized evidence ages out within 30 days. Non-identifying aggregates are not subject-specific deletion targets.

Ordinary logs and Sentry events are not audit records. Copying telemetry does not create compliant security/legal evidence. Legal hold blocks expiry only for explicitly scoped records under the legal-hold workflow.

Release evidence retention windows

Evidence ClassMaximumPrivacy Rule
Non-identifying release manifestProduct lifetimeLimited to commit, artifact digest, versions, migrations, check outcomes, approval, and production outcome; no user, device, request, or telemetry identifiers.
Synthetic screenshots and videosOne yearAllowed only after automated and manual verification that the artifact contains synthetic UI data with no real identifier, telemetry, credential, or production content.
Detailed CI logs and failed-test artifacts30 daysUse synthetic data only and follow the synthetic-log maximum. Shorten or quarantine immediately when a secret or real identifier appears.
Accidental production or identifiable contentNot normal release evidenceQuarantine, investigate, and delete under the incident and applicable data-class rules.

Consent is a versioned ledger, not a single checkbox. Every high-sensitivity flow must record the notice shown, the surface used, and withdrawal handling.

  • user_id
  • Active account/context.
  • Privacy policy version.
  • Terms version.
  • Wellness disclaimer version.
  • Sensitive wellness data consent version.
  • Media consent version.
  • Optional marketing consent version.
  • Language/locale shown.
  • Accepted timestamp.
  • Source app surface.
  • IP/device/request metadata where legally appropriate.
  • Withdrawal timestamp.
  • Withdrawal reason category.
  • Registration.
  • Sensitive onboarding.
  • Media.
  • Coach access explanation.
  • Marketing opt-in.
  • Withdrawal.

Retention Policy

Retention defaults follow relationship and account lifecycle. Deviations require legal review and an explicit documented rule.

StatePublic V1 DefaultRule
Active relationshipRetain active records.Keep data available for the active service relationship and approved privacy rights handling.
Paused relationshipRetain active records with reduced activity.Pause reminders and pressure workflows without forcing premature deletion.
Ended relationship days 0-30Read-only retention window.The 30-day ended-relationship window is the default.
Ended relationship after day 30Delete or anonymize by default.Apply delete/anonymize after day 30 unless legal hold or required retention applies.
Deleted/anonymized relationshipRemove normal product access.Keep only required audit, legal, and security evidence.
Account deletion requestedStart scoped deletion workflow.Verify identity, calculate impact, revoke sessions/devices, purge caches, and execute delete/anonymize jobs.
Workspace closedBlock normal use and move to retention/export/delete rules.Relationship and workspace closure do not preserve indefinite operational access.
BackupsExpire by backup policy.Deleted records may persist only until backup rotation and replay deletion complete.
  • Tax/accounting records if payments enter scope.
  • Audit/security logs.
  • Legal claims.
  • Breach records.
  • Country-specific requirements.

Default Posture

Public V1 uses retention windows that are short, scoped, and reviewable. Any longer window must identify its legal or operational reason and the exact data classes it covers.

Relationship-End Cleanup

Relationship end is a privacy event, not only a workflow state transition. Access, cache, reminders, and pending operations all change immediately.

Immediate Effects

  • Immediate coach edit lock.
  • Reminder suppression.
  • 30-day read-only window.
  • Mobile cache purge/lock.
  • Signed media URL expiry.

Cleanup Path

  • Pending offline operation rejection or cleanup scoping.
  • Delete/anonymize after day 30 unless legal hold or required retention applies.
  • Preserve only the scoped records covered by legal hold or required retention rules.

Export, Correction, Deletion

Privacy rights handling must be scoped, auditable, and explicit about what is included, excluded, corrected, deleted, and retained.

Export

Include allowed profile, relationship summary, forms, workouts, nutrition, measurements, messages, media files/references, consent history, and privacy request status.

Exclude private coach notes, other users' data, raw diagnostics, unrelated workspace records, and support/admin-only audit payloads.

Correction

Use amendment records for immutable history so the platform can correct user-visible facts without erasing auditability.

Deletion And Anonymization

  • Intake.
  • Verification.
  • Scope calculation.
  • Active relationship/workspace impact review.
  • Optional export offer.
  • Session/device revocation.
  • Mobile cache purge command.
  • Media purge jobs.
  • Database delete/anonymize jobs.
  • Audit/legal/security retention decision.
  • Deletion receipt.

Media And Object Storage

Sensitive media gets a stricter lifecycle than general records because raw objects, signed URLs, and purge timing can leak more than normal structured data.

Storage And Access Rules

  • Protected object storage.
  • Short-lived signed URLs.
  • No long-lived signed URL persistence.
  • Canonical media records after upload completion and policy validation.
  • Audited support playback/download.
  • Safe progress photo export packaging.

Lifecycle And Purge Rules

  • Lifecycle states PENDING_UPLOAD, AVAILABLE, QUARANTINED, PENDING_PURGE, PURGED, and FAILED_PURGE.
  • Idempotent purge jobs.
  • Purge receipts.

Mobile Cache

Privacy purge triggers define when local state must be removed or locked. offline-sync-protocol owns mechanics.

  • Confirmed logout.
  • Account switch.
  • Device revocation.
  • Relationship end.
  • Workspace suspension/closure.
  • Permission revocation.
  • Account deletion.
  • Retention expiry.
  • Legal/security incident.

Legal hold freezes purge only for the scoped records tied to a case. It does not create broad indefinite retention across unrelated data.

  • Case id.
  • Reason code.
  • Owner.
  • Target scope.
  • Data classes covered.
  • Created timestamp.
  • Expiry/review date.
  • Release process.
  • Audit events.

Scope Rule

Legal hold blocks purge only for scoped records.

Incident Response

Privacy incidents follow one explicit workflow so containment, evidence preservation, review, and notification decisions do not drift between teams.

  1. Classify incident.
  2. Freeze risky access/tokens.
  3. Preserve evidence.
  4. Notify security/legal/compliance owner.
  5. Identify affected data classes/users.
  6. Decide user/regulator notification path through legal review.
  7. Record remediation and closure.

Observability owns detection and a sanitized technical timeline. Suspected exposure, unauthorized access, or privacy impact enters this Privacy incident workflow immediately.

Feature-Page Rules

Every feature page that handles user or operational data must point back to this authority and spell out its privacy behavior in concrete terms.

  • Identify data classes.
  • Identify owner context.
  • Identify consent/notice dependency.
  • Identify retention window.
  • Identify relationship-end behavior.
  • Identify account-deletion behavior.
  • Identify media purge behavior.
  • Identify mobile cache purge trigger.
  • Identify export inclusion.
  • Identify correction/amendment behavior.
  • Identify audit events.
  • Identify legal hold behavior.
  • Identify privacy tests.

Required Privacy Test Cases

Release evidence must prove that notices, consent, boundaries, retention windows, purge paths, scoped access, and backup replay all behave the way this authority says they do.

Evidence AreaRequired Proof
Consent/noticeVersioned ledger records, locale capture, and withdrawal handling.
Wellness disclaimerRegistration and sensitive-flow gating proves the wellness-only posture is shown before collection.
Ended relationship read-only lockCoach edits stop immediately and retained history becomes read-only.
30-day cleanupDefault 30-day window triggers delete/anonymize jobs unless scoped retention blocks them.
Account deletionIdentity verification, session/device revocation, purge jobs, and receipt creation.
Export exclusionsPrivate coach notes, other users' data, raw diagnostics, unrelated workspace records, and support/admin-only audit payloads stay out.
Correction amendmentsImmutable history remains intact while corrected values are surfaced properly.
Media purgeProtected storage objects, lifecycle state changes, and purge receipts complete idempotently.
Signed URL expiryShort-lived access expires and long-lived persistence is blocked.
Mobile cache purgeEach purge trigger removes or locks local data according to scope.
Offline operation rejection after permission/retention changePending operations are rejected or cleaned up when permission or retention changes invalidate them.
Scoped legal holdPurge stops only for the records covered by the hold.
Support/admin grantReason-coded, scoped, audited access gates sensitive reads, playback, download, export, and delete operations.
Audit separationAudit/legal/security evidence remains separate from standard product views and exports.
Backup deletion replayBackup rotation and replay deletion close the final copy path after primary deletion.

These pages define the adjacent authority boundaries that privacy and retention depends on but does not absorb.

Workflow state map

Lifecycle states that trigger read-only, purge, and delete/anonymize transitions.

Roles and permissions

Access boundaries for sensitive wellness data, media, communications, and support/admin grants.

API contract standard

Export, delete, and consent endpoints must use the common REST contract.

Event and outbox standard

Deletion, purge, and incident workflows that rely on backend events and outbox guarantees.

Offline sync protocol

Owns mobile cache mechanics, purge execution, and offline operation rejection behavior.

Integration Register

External providers and self-hosted application boundaries, including processor data paths, provider retention, cache rights, fallbacks, and launch evidence.

Observability Plan

Defines operational signal and incident-detection needs while this authority owns telemetry classification, retention, deletion interaction, and privacy response. Operational telemetry never replaces audit evidence.

Test And Release Gate

Defines when privacy tests, retention jobs, and deletion/export verification block merge or release.

CoachMe internal planning documentation.