Access control
Every record is protected by per-user access rules enforced in the database, not just in the app. Teammates can only read what your privacy settings allow; admins act through audited server functions.
Coach cannot write on its own
Coach proposes drafts. The database rejects any change linked to a draft that you have not confirmed, and every confirmed change has an audit entry with Undo.
Transport and storage
All traffic uses HTTPS. Photos and attachments live in private storage with signed, expiring links. Provider tokens for connected apps are stored server-side only and revoked on disconnect or deletion.
Sign-in
Email/password with reset links and Google sign-in. Sessions expire and can be ended by signing out on any device.
Report a vulnerability
Please report security issues through Support with the category "Security". We acknowledge reports within three business days and do not pursue good-faith researchers.