Privacy Policy
Last updated 2026-08-17
TrainerCue is a CRM for coaches. This policy says what we store, where it goes, and what your rights are, in plain words. The data in your workspace belongs to you; we use it to run the service for you and for nothing else. We do not sell personal data, we do not show ads, we do not run third-party analytics or tracking, and we do not train AI models on your data.
Because TrainerCue is built for fitness and health coaching, some information in a coach's workspace can relate to a person's health. That data has its own standalone policy: Consumer Health Data Privacy (and for Nevada, Nevada Consumer Health Data Privacy). Read those alongside this one.
What we store
Your account. Your email address and a password handled by our authentication provider (we never see or store the password itself). Creating an account requires confirming your email; account emails such as confirmation and password reset are sent only when you ask for them.
Waitlist emails. While new signups are paused before launch, the signup page collects an email address for the launch waitlist. It is used for exactly one thing: telling you when TrainerCue launches, with the founding offer attached. It is not shared, not used for any other marketing, and removed on request at any time through the privacy request page, no account needed.
Your workspace. Everything you or your team put into the CRM: lead names and contact details (email, phone, social handles), notes, timeline activity, tasks, pipeline stages, templates, automation rules, custom fields, day logs, work sessions, and weekly reviews.
Intake form submissions. If you connect a lead intake form, the answers people submit are routed into your workspace as leads and timeline entries. A raw copy of the most recent submission is kept per form purely to power the setup screen, and is automatically purged after 90 days of form inactivity.
Instagram inbox. If you connect a professional Instagram account, we store the direct messages and comments that account receives and sends, including the audio of voice messages and each sender's public profile picture, so you can read, listen, and answer here. See the Instagram section below for what that includes and how long it is kept.
Integration data, only if you connect them: Google Calendar (we read your day's events to display them and write the blocks you create; tokens are stored encrypted) and Calendly (booking events for your leads; credentials stored encrypted). Disconnecting an integration deletes its credentials.
Your leads' data: who is responsible
For the personal data of the leads and clients you manage, you are the data controller and we are the processor: we handle that data only on your instructions, to run the service. Our Data Processing Agreement governs this in detail.
If one of your leads asks about their data, that request is yours to answer, and the tools to honor it are built in: view, edit, export, and delete their record. A lead can also come to us directly through the privacy request page, which works without an account, and we will coordinate with you to honor it.
Instagram messages and comments
When you connect an Instagram account, people who message or comment on that account have their username, display name, public profile picture, message or comment text, and the audio of any voice messages they send stored in your workspace inbox. We use that data for exactly one thing: showing you the conversation, with their picture beside it and voice messages playable in place, so you can reply. We do not use it for advertising, profiling, or anything else, we do not analyze or transcribe voice recordings, and we never feed any of it to an ad platform.
Message and comment content, voice-message audio included, is kept for 90 days and then automatically deleted. A stored profile picture follows the same clock: when a conversation has been quiet for 90 days, its picture is deleted too. The conversation record itself (who wrote, when, and reply counts, without the message content) is kept while the account stays connected, so your outreach statistics stay accurate. Disconnecting Instagram deletes the stored conversation history, records, audio, and profile pictures included. If you convert a conversation into a CRM lead, the contact details you chose to save live on as a lead record under your control.
People in those conversations do not need a TrainerCue account to exercise their privacy rights: the privacy request page accepts requests from anyone, and deletion requests arriving from Meta's own data deletion tools are honored automatically.
Where your data lives, and who touches it
The service runs on Supabase Pte. Ltd. (database, authentication, and file storage, in a United States region) and Vercel Inc. (application hosting in the United States). Transactional email, such as a new-lead alert to your own inbox, is sent through Resend; those alerts can carry a lead's name and intake answers in the message they deliver to you. If you connect them, data also flows to Meta Platforms, Inc. (Instagram messaging, as an independent company under its own terms), Google LLC (Calendar), and Calendly under their own privacy policies. Our sign-up and password-reset forms may be protected by Cloudflare, Inc. (Turnstile), a bot check that runs in your browser on those public pages only.
The complete, versioned list, with a way to reach each company, lives at Subprocessors. One disclosure worth making proactively: our database provider Supabase lists OpenAI, LLC among its own subprocessors for natural-language features of its platform; TrainerCue itself sends no customer data to any AI vendor.
We do not sell or share personal data for advertising, and we do not engage in targeted advertising, so opt-out preference signals such as Global Privacy Control are satisfied by default. We will never sell consumer health data; that is a hard product rule, not a preference.
How it is protected
All traffic is encrypted in transit (TLS), and data is encrypted at rest (AES-256) by our hosting infrastructure. Third-party credentials, such as calendar and Calendly tokens, are additionally encrypted at the application layer (AES-256-GCM).
Every workspace is isolated at the database layer with row-level security, enforced by the database itself on every query rather than by application code, so a request made in one account's context cannot return another account's records. We maintain an automated adversarial test suite that verifies these isolation rules on every change.
Access to any stored file goes through short-lived signed links generated for an authenticated, authorized user. Access to production systems is limited to the founder.
Our infrastructure providers maintain independent security certifications including SOC 2 Type II and ISO 27001. TrainerCue itself is an independent company and has not yet undergone a third-party security audit. Security practices and vulnerability reporting: Security.
How long we keep it
Your data stays as long as your account is active. CRM records you delete (leads, tasks, notes, templates, and similar) go to your workspace trash, restorable for 30 days, then are permanently purged. Instagram message and comment content ages out automatically as described above. Raw intake submission snapshots are purged after 90 days of form inactivity. You can export your leads and tasks as CSV, or your whole workspace as JSON, from Settings at any time.
When data is deleted, it is removed from our production systems. Where our infrastructure provider maintains rolling database backups, deleted data expires from those automatically on the provider's short retention cycle; we do not restore deleted data.
Deleting everything
You can request permanent deletion of your entire workspace from Settings, or through the privacy request page. We erase the account, leads, timelines, tasks, Instagram data, integrations, trash, stored files, all of it, and confirm to you when it is done. Deletion requests are completed within 30 days.
Your rights
You can access, correct, export, or delete your data, and withdraw any consent you have given. Most of that is self-serve in the app. For everything else, the rights page explains each right, and the request page is how you exercise them, with or without an account. We respond within 45 days, and if we ever deny a request you can appeal. We do not discriminate against anyone for exercising their rights.
Cookies
The only cookies are the ones that keep you signed in and make the app work for you. No tracking cookies, no ad pixels, no fingerprinting.
If something goes wrong
If a security incident affects your data, we will notify you without undue delay after we become aware of it, tell you what happened and what we are doing, and notify regulators where the law requires it.
Where we operate
TrainerCue is offered to coaches located in the United States. See the Terms of Service for what that means for your account.
Changes
If this policy changes in a way that matters, we will update this page, bump the date at the top, and flag material changes to you directly. If we ever collect new categories of data or use data for new purposes, we will update this policy and ask for your consent before doing so.
Contact
Privacy questions and requests: privacy@trainercue.com. Security reports: security@trainercue.com.