Privacy notice

What we collect when you use Agonos as a coach or visit this site, why, who touches it, and what you can ask us to do about it.

Updated

Who is responsible

For your own account and your use of Agonos, the controller is Agonos. Contact: contact@agonos.app.

For your clients' data, you are the controller and we act on your instructions. Which clients exist, what is recorded about them and how long it is kept are your decisions, not ours. The terms of that arrangement are in the data processing agreement.

If you are a client using the mobile app, the notice written for you is the app privacy notice.

What we collect

Account. Your name, email address, password (stored hashed, never in readable form), the organisation you belong to and your role in it.

What you put in. Programmes, templates, sessions, notes, messages, files and the client records you create. We hold this for you; we do not mine it.

Billing. Your plan, subscription state, invoices and the country used for VAT. Card details go straight to our payment processor and never reach our servers.

Technical. Ordinary server logs — IP address, timestamp, the request, the browser or app version — kept briefly so we can debug faults and spot abuse.

This website. Two cookies, both functional: one remembers the language you chose, one tells the site whether you are already signed in so the button can say "Open dashboard" instead of "Start for free". There is no analytics, advertising or tracking on this site, which is why you have not been asked to consent to any.

Why, and on what basis

To provide the service you signed up for — running your account, storing your work, delivering the app to your clients. Legal basis: performance of a contract.

To bill you. Contract, and our legal obligation to keep accounting records.

To keep the service secure and working — logs, abuse prevention, fault diagnosis. Legal basis: our legitimate interest in a service that stays up and is not attacked.

To answer you when you write to us. Contract, or legitimate interest.

To send you service email — sign-in links, receipts, changes that affect you. Contract. These are not marketing and you cannot unsubscribe from a receipt.

Marketing email, if we ever send any, only with your consent, withdrawable in one click.

We do not sell personal data, and we do not use it to train models.

Who processes it for us

Processor What for Where
Supabase Database, authentication, file storage European Union (Frankfurt)
Vercel Hosting and delivery of the web applications Global edge, EU regions for compute
Stripe Payments, subscriptions and invoicing EU and US, under its own safeguards
Apple (APNs) Delivering push notifications to iPhones Apple's infrastructure
Google (FCM) Delivering push notifications to Android phones Google's infrastructure

Customer data is stored in the European Union. Where a processor operates outside it, the transfer relies on the European Commission's standard contractual clauses and that processor's own supplementary measures. The current list is maintained in the DPA; we update it there when it changes.

How long we keep it

While your account exists, plus a short window after you close it so an accidental deletion can be undone.

Invoices and accounting records for as long as tax law requires, which is longer than the account itself and which we cannot shorten on request.

Technical logs for a short operational window, then rotated out.

When you close an organisation, the client records inside it go with it. Tell your clients before you do.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, or have it handed to another provider. You can withdraw consent at any time, which does not undo processing that already happened.

Write to contact@agonos.app from the address on your account and we will answer within one month. There is more detail, including what to do about data belonging to your clients, on the GDPR page.

If you think we have handled it badly you can complain to your national data protection authority — in France, the CNIL.

Security

Traffic is encrypted in transit and data is encrypted at rest by our hosting provider. Every table in the database enforces per-organisation isolation in the database itself rather than in application code, so an account cannot read another organisation's rows whatever the application above it does. Access to production data is limited to the people who need it.

No system is perfect. If you find a vulnerability, write to contact@agonos.app before disclosing it publicly and we will work with you.

Changes

If we change what we collect or why, we update this page and move the date at the top. A change that materially affects you is announced in the product rather than left here to be found.

Get your evenings back.

Start for free