Legal

Privacy Policy

Last updated: 26 March 2026

1. Who we are

Coach Pilot is an AI-powered leadership coaching platform operated by ARPD Ltd (“we”, “us”, or “our”). If you have any questions about this Privacy Policy or how we handle your data, please contact us at support@arpd.co.uk.

2. What data we collect and why

Account information

When you sign up, we collect your email address, first and last name, and optionally your company name. This is used to create your account, identify you across sessions, and tailor the coaching experience to your organisation.

Coaching conversation content

All messages you send and receive during coaching sessions are stored to allow you to review past conversations, build ongoing context, and generate session summaries. You control how long this content is retained through your Settings page.

Technical data

We log your IP address and browser type for security purposes — specifically to detect suspicious access patterns, investigate account compromise, and maintain audit trails. This data is stored in our audit log system and is not used for advertising or behavioural profiling.

Session data

We store a server-side session record (linked to your account) that keeps you signed in for up to 6 hours of activity. Sessions are cleared on logout or inactivity.

3. AI processing — Anthropic

Coach Pilot uses Claude by Anthropic to power its coaching conversations. When you send a message, its content is transmitted to Anthropic's API to generate a coaching response.

Anthropic processes this data as a data processor on our behalf. They do not use your conversation content to train their models by default. For more detail, see Anthropic's Privacy Policy.

Please do not include highly sensitive personal information — such as medical records, financial details, or personal data of third parties who have not consented — in your coaching sessions.

4. Cookies

Coach Pilot uses two strictly necessary cookies. These are required for the application to function and cannot be opted out of while using the service. We do not use any tracking, advertising, or analytics cookies.

Cookie namePurposeDuration
connect.sidSession identifier — keeps you signed in between page loads.6 hours of inactivity
csrf_tokenSecurity token — prevents cross-site request forgery (CSRF) attacks on your account.Session

5. Data retention

Your account data (email, name, company) is kept for as long as your account is active. If you request account deletion, we will remove it within 30 days, except where we are required by law to retain it longer.

Coaching conversation content is retained according to the settings configured for your organisation. Administrators can set retention to summaries only, or summaries plus full conversation history. You can review and change these settings on the Settings page.

Audit log data (including IP addresses) is retained for a period determined by your organisation's configuration.

Sign-in link tokens expire automatically after 15 minutes and are invalidated once used.

6. Your rights under GDPR

If you are located in the UK or European Economic Area, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate data.
  • Deletion — request that we erase your personal data, subject to any legal retention requirements.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to how we process your data in certain circumstances.
  • Restriction — ask us to limit processing while a dispute is resolved.

To exercise any of these rights, please email us at support@arpd.co.uk. We aim to respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

7. Data security

We take appropriate technical and organisational measures to protect your personal data:

  • Coaching conversations are encrypted in transit (HTTPS/TLS) and at rest.
  • All data is isolated by organisation using row-level security (multi-tenancy).
  • Access to data is restricted to authenticated, authorised users only.
  • Security headers, rate limiting, and CSRF protection are applied to all API endpoints.
  • Authentication uses secure, hashed passwords with industry-standard bcrypt hashing.

8. Third-party services

Other than Anthropic (described in section 3), we use the following third-party infrastructure:

  • Replit — cloud hosting and database infrastructure. Data is stored on servers in accordance with Replit's data processing agreement.

We do not sell or share your personal data with any third party for marketing or advertising purposes.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For significant changes, we will notify users by email where possible. Continued use of Coach Pilot after changes are published constitutes acceptance of the updated policy.

10. Contact

For any privacy-related questions or requests, please contact: support@arpd.co.uk