Privacy Policy

Effective date: April 27, 2026 · Last updated: September 8, 2026

Quadratic, Inc. (“CoachingOS,” “we,” “us,” or “our”) operates the platform available at www.coachingos.com (the “Service”). This Privacy Policy explains how we collect, use, store, and protect information about you when you use the Service.

1. Information we collect

Account information

When you create an account we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your Google profile information (name, email, profile picture) via OAuth.

Coaching data

When you use CoachingOS to manage your practice, we collect and store coaching-related data including client information and coaching notes, goals and progress tracking, session records, booking and scheduling information, and time blocks.

Google Gmail data

With your explicit permission, CoachingOS connects to your Gmail account using Google's OAuth 2.0 protocol and requests the following access:

  • gmail.readonly — We use read access in three ways.

    Contact discovery. We request messages in metadata format only — the From, To, Cc, Subject and Date headers — from the mailbox label and date range you choose, to identify people you have communicated with. Message bodies are never requested for this. The first scan of any mailbox is always started by you; once started, CoachingOS keeps that mailbox up to date daily until you disconnect it.

    Coaching context. For messages involving people already in your CoachingOS contact list, we read the message body to extract coaching-relevant details and propose them for your approval. This happens while you are using CoachingOS, and on a daily sync, over a rolling 30-day window.

    On request. When you ask CoachingOS to fill in missing information about a specific client, we read recent messages with that person to find it.

    In every case the body is used to produce the result and then discarded. Email body content is never stored on our servers, and we never read messages that involve nobody in your contact list.

  • gmail.send — We send email from your address only when you have written the message yourself or approved a draft CoachingOS prepared for you. An approved message is delivered either immediately, when you press Send now, or on our once-daily send, which is limited to ten messages per coach per day. No message is ever sent without your approval. We do not send bulk or marketing mail.

Data extracted from Gmail (recipient names and email addresses) is stored in your private CoachingOS workspace and used solely to help you manage your professional network.

Google Calendar data

With your explicit permission, CoachingOS connects to your Google Calendar using Google's OAuth 2.0 protocol and requests the calendar scope (read and write access). Sign-in with Google requests only your basic profile; Gmail and Calendar access is requested separately when you click Connect Google.

  • Read — We read events from your Google Calendar to extract attendee names and email addresses for contact discovery, display your real schedule alongside your coaching time blocks, and match calendar events to contacts to detect coaching sessions. The first calendar scan is always started by you, over a date range you choose; once connected, CoachingOS also refreshes a recent window of your calendar daily to keep sessions and attendees up to date, until you disconnect it.
  • Write — When you publish a time block, we create and manage a separate Google calendar named “CoachingOS” and sync your coaching time blocks to it. Separately, if you turn on “Add to Main” for a block, we also write a copy of that event to your primary calendar so the slot appears taken; that copy carries the same title, description and attendees as the block, and will send invitations if you also enable Notify. Both are per-block choices you make. We do not overwrite or bulk-modify your existing calendar events outside these features.

After you connect Google Calendar, your schedule may update when Google notifies us of calendar changes or when you click Sync now. This is separate from the manual contact-discovery scan described above.

Google Contacts data

With your explicit permission, CoachingOS requests the contacts.readonly scope when you connect Google. We use it for two things. First, fetching profile photos for eligible contacts — active clients, prospects and fellow coaches — on the contact detail page. Second, when you run the Clients & Deals mission and ask us to fill in where your clients work, reading the organisation field for people already in your client and prospect list. We never override a photo you uploaded manually, and we never write to your Google Contacts.

Microsoft Outlook Mail data

With your explicit permission, CoachingOS connects to your Microsoft Outlook account using Microsoft's OAuth 2.0 protocol (Microsoft Graph) and requests the following access:

  • Mail.Read — We read your Outlook mail to identify people you have communicated with and to detect coaching-related activity. Recipient names, email addresses, and a limited excerpt of message content are used for this purpose within your private CoachingOS workspace.
  • Mail.Send — We send email from your address only when you have written the message yourself or approved a draft CoachingOS prepared for you. An approved message is delivered either immediately, when you press Send now, or on our once-daily send, which is limited to ten messages per coach per day. No message is ever sent without your approval. We do not send bulk or marketing mail.

Microsoft Outlook Calendar data

With your explicit permission, CoachingOS requests the Calendars.ReadWrite scope when you connect Microsoft. We read events from your Outlook Calendar to extract attendee names and email addresses, display your schedule alongside your coaching time blocks, and match calendar events to contacts to detect coaching sessions. When you publish a time block and Outlook is your connected calendar, we create and manage a separate Outlook calendar named “CoachingOS” and sync your published blocks to it; if you turn on “Add to Main” for a block, we also write a copy of that event to your primary Outlook calendar. Both are per-block choices you make. We do not overwrite or bulk-modify your existing Outlook events outside these features.

Microsoft Contacts data

With your explicit permission, CoachingOS requests the Contacts.Read scope when you connect Microsoft. We use this only to fetch profile photos for eligible contacts from your saved Outlook contacts on the contact detail page. We never override a photo you uploaded manually.

Usage data

We collect analytics data about how you use the Service (page views, feature interactions, session duration) using PostHog. This data is used to improve the product and is not sold or shared with third parties for advertising.

Session recordings

To understand where coaches get stuck, we may record how the Service is used — clicks, scrolling and navigation. These recordings are masked: on-screen text and anything you type are replaced before the recording leaves your browser, so your clients' names, email addresses and deal values are not captured. Web addresses are reduced to the page you were on, without the record you were viewing.

Turning it off

You can switch usage data off at any time under Usage data in your profile menu. This stops collection in your browser and on our servers, and it does not affect any other part of the Service.

2. How we use your information

  • To provide and operate the Service
  • To surface contact candidates from your Gmail and Calendar so you can grow your network
  • To extract coaching-relevant details from messages involving your contacts, for your approval
  • To detect coaching sessions and enrich your contacts from your connected Outlook Mail and Calendar
  • To send emails you have composed or approved, immediately or on our once-daily send
  • To sync your coaching time blocks to a separate Google calendar when you publish them
  • To display your coaching analytics and practice data
  • To communicate with you about the Service (product updates, support)
  • To detect and prevent fraud, abuse, and security incidents

3. How we store and protect your data

Your data is stored on Convex's infrastructure, which is hosted on AWS in the United States. Data is encrypted at rest and in transit. OAuth tokens (used to access Gmail, Google Calendar, Outlook Mail, and Outlook Calendar) are stored securely and never exposed in client-side code or logs.

We retain your data for as long as your account is active. You may delete your account and associated data at any time by contacting us at support@coachingos.com.

4. Data sharing

We do not sell your data. We do not share your Gmail, Google Calendar, Outlook Mail, or Outlook Calendar data with third parties except as necessary to operate the Service. Those providers are our infrastructure provider, Convex, and the AI providers we use to process content on your behalf — Anthropic and OpenAI. Message bodies and calendar event details are sent to an AI provider only to produce a result you asked for or will be asked to approve, such as extracting a coaching detail or classifying a meeting. They are processed under agreements that prohibit using your content to train their models, and they are not retained by us. We will disclose data if required by law or to protect the rights, property, or safety of CoachingOS, our users, or the public.

5. Google and Microsoft API data use

CoachingOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft Graph data is consistent with the same principles.

  • We only request access to Gmail, Google Calendar, Outlook Mail, and Outlook Calendar data that is necessary to provide the features described in this policy.
  • We do not use this data to serve advertisements.
  • We do not use this data to develop, improve, or train generalized AI or machine learning models. Where we send content to an AI provider to produce a result for you, it is used to produce that result only, under terms that prohibit training on it.
  • We do not allow humans to read this data unless you have given explicit permission or it is required for security purposes.
  • We do not transfer this data to third parties except as required to provide our service, and only with your permission.

6. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent for data processing
  • Export your data in a portable format
  • Revoke Google OAuth access at any time via your Google Account permissions
  • Revoke Microsoft OAuth access at any time via your Microsoft Account permissions
  • Disconnect your Gmail, Calendar, or Outlook integration within CoachingOS under Contacts → Integrations

7. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.

8. Third-party services

Our application may integrate with third-party services (Google Calendar, Gmail, Microsoft Outlook Mail and Calendar, etc.). Your use of these services is subject to their respective privacy policies. CoachingOS is not responsible for the privacy practices of third-party services.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice in the Service. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.

10. Contact us

Questions or requests regarding this Privacy Policy should be sent to: support@coachingos.com

Quadratic, Inc. · www.coachingos.com