Last updated: 30 August 2026
Privacy policy
Up turns real conversations into coaching. That only works if what you upload stays yours. This page explains, in plain language, what we collect, why, who can see it, and how to get rid of it.
Who this covers
This policy applies to upcoach.app — the marketing site and the product at /app — operated by Up. If you use Up through an employer or a team, this policy still describes how we handle your data; it does not give your employer rights over it that are not written here.
What we collect
Account data: your email address and an authentication credential, handled by our auth provider. We never see your password in readable form.
Beyond that, we hold only what the product needs:
- Profile data you choose to give us — name, avatar, role, seniority, company size, team size, industry, and what you want to get better at. We use it to calibrate feedback to your situation; it is never treated as evidence about you.
- Conversation data — the transcripts and meeting files you upload, or that arrive through an integration you connected (Google Drive, Read.ai, Fathom), plus everything derived from them: analyses, observations, evidence quotes and pattern reports.
- Product feedback — whether a piece of feedback was useful to you, and the reason you optionally write, so we can tell whether Up is actually helping.
- Technical data — standard server and security logs, and the minimum needed to keep a session alive and remember your language and theme.
What we do with it
We use your data to produce your feedback, to keep your history available to you, to operate and secure the service, and to understand whether the product works — measured through your usefulness ratings, not by reading your conversations for interest.
We do not sell your data. We do not use your conversations to build advertising profiles. We do not send your conversations to your employer, your manager, or anyone else.
AI processing
To generate an analysis, the transcript text is sent from our servers to a large language model through OpenRouter, which routes it to the model that produces the result. The request is made server-side; the model provider processes the text in order to return the analysis.
We do not train models on your conversations, and we ask our providers not to use content sent through their APIs for training. If you would rather a conversation never reach a model provider, do not upload it — the analysis cannot be produced without it.
Who can see your conversations
You. Every table that holds your content is behind row level security keyed to your account, so another user physically cannot read your transcripts, analyses or reports.
A small number of our staff can reach stored data when it is strictly necessary to operate the service — investigating an error you reported, or answering a legal obligation. There are no public rankings, no leaderboards, and no reports about you sent to anyone.
If you explicitly choose to share a piece of feedback with us to improve the product, only that item is shared, and you can retract it.
Integrations you connect
If you connect Google Drive, we request read-only access and use it solely to read the meeting files in the folder you point us at. If you connect Read.ai or Fathom, they send us the meetings you configure them to send.
Integration credentials are stored encrypted (AES-256-GCM) with a key that lives only on our servers. You can disconnect any integration from Settings at any time: that stops future imports and removes the stored credential. Content already imported stays until you delete it, as described below.
Google user data
Up's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: we request read-only access to Google Drive; we use it only to read the meeting files in the folder you choose and import them as your transcripts; we do not use that data for advertising; we do not sell it or transfer it to third parties except to operate the service at your request, for security purposes, or where the law requires it; and no human reads it, except with your explicit permission to resolve a support issue you raised, for security reasons, or where required by law.
You can revoke access at any time from Settings in Up, or from your Google account's permissions page.
Service providers
We rely on a short list of providers to run Up. Each one processes data only to provide its service to us:
- Supabase — database, authentication and file storage.
- Vercel — application hosting.
- OpenRouter, and the model providers it routes to — analysis generation.
- Resend — transactional email, such as sign-up confirmation.
- Google, Read.ai and Fathom — only if you connect them.
Retention and deletion
We keep your data while your account exists. You can delete a single meeting and its analyses at any time from your history, or delete all of your data from Settings. Closing your account deletes the content attached to it.
Deletions reach our providers' backups on their normal rotation rather than instantly. Aggregate, non-identifying counts already computed may survive a deletion.
Your rights
Depending on where you live, you have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. Most of this is available directly in the product; for anything else, write to us and we will answer.
Where the GDPR applies, our legal bases are the performance of our contract with you (providing the coaching you asked for), our legitimate interest in keeping the service secure and working, and your consent where you gave it — for example, connecting an integration.
Cookies
We use only the cookies the service needs: one to keep you signed in, one to remember your language, and one to remember light or dark. No advertising cookies, no cross-site tracking.
International transfers
Our providers may process data outside your country, including in the United States. Where required, those transfers rely on standard contractual clauses or an equivalent safeguard.
Children
Up is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a minor has created an account, write to us and we will remove it.
Changes
If we change this policy materially, we will update the date at the top and, for anything significant, tell you in the product or by email before it takes effect.
Contact
Questions, requests or complaints about privacy: privacy@upcoach.app.