1 Who we are
ProtocolHQ ("we", "us", "our") is a coaching and athlete management platform available on web and mobile.
The platform connects coaches with their athletes, enabling workout planning, performance tracking,
wellness monitoring, and direct communication.
Our backend infrastructure is powered by Google Firebase (Firebase Authentication,
Cloud Firestore, Firebase Storage, and Firebase Cloud Messaging), which means your data is stored on
Google's secure cloud infrastructure.
2 What data we collect
We collect data in two ways: information you provide directly, and information generated by using the platform.
Email address & password
Account creation and authentication via Firebase Auth. Passwords are hashed by Firebase and never stored in plain text.
Name & role
To identify you as a coach or athlete and display your name to the people you work with.
Profile photo
Optionally uploaded by you. Stored in Firebase Storage and displayed to your coaches or athletes.
Workout & exercise data
Coaches create exercise libraries and workouts. This content is stored in Cloud Firestore and shared with assigned athletes.
Exercise media (images & video)
Coaches may upload demonstration images or videos for exercises. These are stored in Firebase Storage and accessible to assigned athletes.
Performance logs
Athletes log sets, reps, weight, duration, or distance per exercise. This data is visible to the athlete and their coaches.
Wellness check-ins
Athletes optionally submit daily sleep, soreness, and stress ratings (1–5). Visible to the athlete and their coaches.
Self-logged activities
Athletes can log their own training sessions (activity name, duration, self-reported load). Visible to the athlete and their coaches.
Messages
Direct messages between coaches and athletes, and between connected coaches. Stored in Cloud Firestore and only accessible to the participants of each conversation.
Coach notes
Private notes a coach writes about an athlete. Visible to the coach only — not shared with the athlete.
FCM device token
A unique token generated by your device used to deliver push notifications (e.g. new workout assigned, new message). Never used for advertising.
Waitlist email address
Collected via the waitlist sign-up form on our website to notify you when ProtocolHQ is available. Not used for marketing beyond that purpose.
3 How your data is stored
All user data is stored in Google Cloud Firestore, a NoSQL database with encryption at rest
and in transit. Media files (images and videos) are stored in Firebase Storage, also
encrypted at rest and served over HTTPS.
Firebase Authentication handles all credential management. We do not store passwords — Firebase handles
authentication securely and only issues tokens to our app after verifying credentials.
On mobile devices, Firestore offline persistence is enabled so that your data is cached locally,
allowing the app to function without an internet connection. This cached data is stored on your device
and cleared when you sign out.
Data residency: Firebase projects are hosted on Google's infrastructure.
Data may be stored and processed in data centres within the United States and/or the European Union depending
on Firebase region configuration.
4 Who can see your data
Access to your data is strictly controlled by Firestore security rules:
- Athletes can only read and write their own workout assignments, exercise logs, wellness entries, and activities.
- Coaches can read the data of athletes who are connected to them (i.e. athletes they have invited or who have accepted their invite).
- Coach notes about an athlete are private to the coach — the athlete cannot see them.
- Messages are accessible only to the two participants in each conversation. No other user can read them.
- Exercise and workout content created by a coach is only visible to athletes assigned to that coach, and to other coaches the coach explicitly shares it with.
- ProtocolHQ staff may access data for the purposes of troubleshooting, support, or legal compliance, subject to the same Google Cloud security controls.
We do not sell, rent, or trade your personal data to any third party, ever.
5 Push notifications
If you grant notification permissions, ProtocolHQ uses Firebase Cloud Messaging (FCM)
to send you push notifications — for example, when a new workout is assigned, or when you receive a message.
Your FCM token (a device identifier) is stored in your user profile in Firestore. It is used solely to
route notifications to your device and is never shared with third parties or used for advertising.
You can revoke notification permissions at any time in your device settings.
6 Third-party services
ProtocolHQ uses the following third-party services to operate the platform:
- Google Firebase — Authentication, Firestore database, Storage, and Cloud Messaging. Governed by the Firebase Privacy Policy.
- Google Cloud Platform — The underlying infrastructure for all Firebase services.
We do not use advertising networks, analytics tracking pixels, third-party cookies, or any behavioural
tracking services. We do not integrate with social media platforms.
7 Data retention
Your data is retained for as long as your account is active. Specific retention rules:
- Account data (name, email, role) — retained until you delete your account.
- Workout assignments & logs — retained for the lifetime of your account so coaches and athletes can review historical performance.
- Wellness check-ins — one entry per day per athlete, retained indefinitely unless deleted.
- Messages — retained until either participant deletes the conversation.
- Media files (images, videos) — retained until the coach deletes the associated exercise or account.
- FCM tokens — retained while your account is active; updated automatically if your device generates a new token.
If you delete your account, we will delete your personal data from our active systems within 30 days.
Residual copies may remain in backups for up to 90 days before being purged automatically.
8 Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — contact us to request a summary of the personal data we hold about you.
- Correction — update your name, email, and profile photo directly in the app, or contact us for other corrections.
- Deletion — contact us to request deletion of your account and associated personal data.
- Withdraw consent — revoke notification permissions at any time in your device settings.
To exercise any of these rights, contact us using the details in Section 12 below.
9 GDPR — European & UK users
If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection
Regulation (GDPR) or UK GDPR applies to how we handle your personal data. This section sets out our
obligations and your additional rights under those laws.
Data Controller
ProtocolHQ acts as the data controller for personal data collected through the platform.
This means we determine the purposes and means of processing your data. Coaches who use ProtocolHQ to
manage athletes may also act as data controllers in their own right for athlete data they collect
through the platform.
Legal basis for processing
GDPR requires us to identify the legal basis under which we process each category of personal data:
Email, name, role, password
Contract performance — necessary to create and maintain your account and provide the service.
Profile photo
Consent — you choose whether to upload a photo. You can remove it at any time.
Workout, exercise & performance data
Contract performance — core to delivering the coaching and training features you signed up for.
Wellness check-ins & self-logged activities
Consent — you choose whether to submit check-ins. This data is never required to use the platform.
Messages
Contract performance — necessary to provide the in-app communication feature.
FCM device token
Legitimate interest — delivering service notifications (e.g. new workout assigned). You can opt out via device settings at any time.
Coach notes about athletes
Legitimate interest — coaches have a legitimate interest in keeping private professional notes about athletes they train.
Waitlist email address
Consent — you choose to submit your email via the waitlist form. You can ask us to remove it at any time.
International data transfers
ProtocolHQ is built on Google Firebase, which may store and process your data on servers located outside
the EEA or UK — including in the United States. Google LLC is certified under the EU–US Data Privacy
Framework and implements Standard Contractual Clauses (SCCs) approved by the European
Commission as the legal mechanism for these transfers.
For more detail on how Google handles international transfers, see Google's
Firebase Privacy & Security page.
Your GDPR rights
In addition to the rights listed in Section 8, EEA and UK users have the right to:
- Object to processing — where we rely on legitimate interest as our legal basis, you can object to that processing at any time.
- Restrict processing — request that we limit how we use your data while a dispute is resolved.
- Withdraw consent — where processing is based on consent (e.g. profile photo, wellness check-ins), you can withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — you have the right to lodge a complaint with your local data protection authority. In the EU this is your national supervisory authority; in the UK this is the Information Commissioner's Office (ICO) at ico.org.uk.
We will respond to all GDPR-related requests within 30 days of receipt. Contact us using the details in Section 12 below.
10 Children's privacy
ProtocolHQ is not directed at children under the age of 13. We do not knowingly collect personal data
from children under 13. If you believe a child has provided us with personal data without parental consent,
please contact us and we will delete it promptly.
Athletes aged 13–17 may use the platform only with the consent of a parent or guardian.
11 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date
at the top of this page. For significant changes, we will notify you via the app or by email.
Continued use of ProtocolHQ after changes take effect constitutes acceptance of the updated policy.
12 Contact us
If you have any questions about this Privacy Policy, want to exercise your data rights, or want to
report a concern, please get in touch: