Legal

Privacy Policy

Last updated: June 2025
ProtocolHQ is built for coaches and athletes. We collect only the data needed to make the platform work, we never sell it, and we give you full control over what you share. This policy explains exactly what we collect, why, and how it is stored.

1 Who we are

ProtocolHQ ("we", "us", "our") is a coaching and athlete management platform available on web and mobile. The platform connects coaches with their athletes, enabling workout planning, performance tracking, wellness monitoring, and direct communication.

Our backend infrastructure is powered by Google Firebase (Firebase Authentication, Cloud Firestore, Firebase Storage, and Firebase Cloud Messaging), which means your data is stored on Google's secure cloud infrastructure.


2 What data we collect

We collect data in two ways: information you provide directly, and information generated by using the platform.

Data
Why we collect it
Email address & password
Account creation and authentication via Firebase Auth. Passwords are hashed by Firebase and never stored in plain text.
Name & role
To identify you as a coach or athlete and display your name to the people you work with.
Profile photo
Optionally uploaded by you. Stored in Firebase Storage and displayed to your coaches or athletes.
Workout & exercise data
Coaches create exercise libraries and workouts. This content is stored in Cloud Firestore and shared with assigned athletes.
Exercise media (images & video)
Coaches may upload demonstration images or videos for exercises. These are stored in Firebase Storage and accessible to assigned athletes.
Performance logs
Athletes log sets, reps, weight, duration, or distance per exercise. This data is visible to the athlete and their coaches.
Wellness check-ins
Athletes optionally submit daily sleep, soreness, and stress ratings (1–5). Visible to the athlete and their coaches.
Self-logged activities
Athletes can log their own training sessions (activity name, duration, self-reported load). Visible to the athlete and their coaches.
Messages
Direct messages between coaches and athletes, and between connected coaches. Stored in Cloud Firestore and only accessible to the participants of each conversation.
Coach notes
Private notes a coach writes about an athlete. Visible to the coach only — not shared with the athlete.
FCM device token
A unique token generated by your device used to deliver push notifications (e.g. new workout assigned, new message). Never used for advertising.
Waitlist email address
Collected via the waitlist sign-up form on our website to notify you when ProtocolHQ is available. Not used for marketing beyond that purpose.

3 How your data is stored

All user data is stored in Google Cloud Firestore, a NoSQL database with encryption at rest and in transit. Media files (images and videos) are stored in Firebase Storage, also encrypted at rest and served over HTTPS.

Firebase Authentication handles all credential management. We do not store passwords — Firebase handles authentication securely and only issues tokens to our app after verifying credentials.

On mobile devices, Firestore offline persistence is enabled so that your data is cached locally, allowing the app to function without an internet connection. This cached data is stored on your device and cleared when you sign out.

Data residency: Firebase projects are hosted on Google's infrastructure. Data may be stored and processed in data centres within the United States and/or the European Union depending on Firebase region configuration.


4 Who can see your data

Access to your data is strictly controlled by Firestore security rules:

We do not sell, rent, or trade your personal data to any third party, ever.


5 Push notifications

If you grant notification permissions, ProtocolHQ uses Firebase Cloud Messaging (FCM) to send you push notifications — for example, when a new workout is assigned, or when you receive a message.

Your FCM token (a device identifier) is stored in your user profile in Firestore. It is used solely to route notifications to your device and is never shared with third parties or used for advertising. You can revoke notification permissions at any time in your device settings.


6 Third-party services

ProtocolHQ uses the following third-party services to operate the platform:

We do not use advertising networks, analytics tracking pixels, third-party cookies, or any behavioural tracking services. We do not integrate with social media platforms.


7 Data retention

Your data is retained for as long as your account is active. Specific retention rules:

If you delete your account, we will delete your personal data from our active systems within 30 days. Residual copies may remain in backups for up to 90 days before being purged automatically.


8 Your rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us using the details in Section 12 below.


9 GDPR — European & UK users

If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to how we handle your personal data. This section sets out our obligations and your additional rights under those laws.

Data Controller

ProtocolHQ acts as the data controller for personal data collected through the platform. This means we determine the purposes and means of processing your data. Coaches who use ProtocolHQ to manage athletes may also act as data controllers in their own right for athlete data they collect through the platform.

Legal basis for processing

GDPR requires us to identify the legal basis under which we process each category of personal data:

Data
Legal basis
Email, name, role, password
Contract performance — necessary to create and maintain your account and provide the service.
Profile photo
Consent — you choose whether to upload a photo. You can remove it at any time.
Workout, exercise & performance data
Contract performance — core to delivering the coaching and training features you signed up for.
Wellness check-ins & self-logged activities
Consent — you choose whether to submit check-ins. This data is never required to use the platform.
Messages
Contract performance — necessary to provide the in-app communication feature.
FCM device token
Legitimate interest — delivering service notifications (e.g. new workout assigned). You can opt out via device settings at any time.
Coach notes about athletes
Legitimate interest — coaches have a legitimate interest in keeping private professional notes about athletes they train.
Waitlist email address
Consent — you choose to submit your email via the waitlist form. You can ask us to remove it at any time.

International data transfers

ProtocolHQ is built on Google Firebase, which may store and process your data on servers located outside the EEA or UK — including in the United States. Google LLC is certified under the EU–US Data Privacy Framework and implements Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for these transfers.

For more detail on how Google handles international transfers, see Google's Firebase Privacy & Security page.

Your GDPR rights

In addition to the rights listed in Section 8, EEA and UK users have the right to:

We will respond to all GDPR-related requests within 30 days of receipt. Contact us using the details in Section 12 below.


10 Children's privacy

ProtocolHQ is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data without parental consent, please contact us and we will delete it promptly.

Athletes aged 13–17 may use the platform only with the consent of a parent or guardian.


11 Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via the app or by email. Continued use of ProtocolHQ after changes take effect constitutes acceptance of the updated policy.


12 Contact us

If you have any questions about this Privacy Policy, want to exercise your data rights, or want to report a concern, please get in touch:

✉️

ProtocolHQ Privacy

Email us at overseas.radar@gmail.com for privacy requests, data enquiries, or account deletion requests.