Privacy
Last updated 31 August 2026
PTOps is software for personal trainers and their clients. It holds health and training information, which deserves a straight explanation rather than a long one. This page describes what the software actually does today.
Who this covers
PTOps is used by two kinds of people. Coaches run a coaching business on it. Clients are coached by them and use it to see their plan, log training, record nutrition and check in.
Your agreement is with your trainer, not with PTOps. A trainer buys PTOps as software for their business. If you are a client, you are coached by that trainer — PTOps is the system they run their business on.
Who decides what
Your trainer decides what is recorded about you and why. They choose to coach you, what to collect in the course of it, and what to do with it. The client record in PTOps is their record of their coaching business.
PTOps provides the service and decides how the software works. That includes a standardised set of product decisions that apply to every business using it: which check-in questions are asked, which health measurements may be read from a phone, which laboratory markers are recognised, and what coaching guidance may be attached to a result. Your trainer cannot change those, and we think you should know that rather than assume your trainer chose them.
PTOps is responsible for its own account and platform information — a trainer’s account with us, and the records we keep to run and support the service.
PTOps does not use your coaching data for its own purposes. It is not analysed for product research, not used to build or train anything, not sold, and not shared with anyone beyond the companies listed below that are needed to run the service. There is no analytics, no advertising and no tracking.
How responsibility is formally divided between a trainer and PTOps under data protection law — and for which specific activities — is a question we are taking legal advice on before general release. We would rather say that than state a tidy answer we have not checked.
What PTOps holds
Account and profile. Name, email address, and the business you belong to. Passwords are handled by our authentication provider and are never visible to PTOps or to your coach.
The coaching relationship. Which coach works with which client, consent records, and where applicable a pre-activity health questionnaire.
Consultations. Notes your coach writes, and structured facts about you — goals, injuries, constraints, preferences — each marked as entered by your coach or derived from a consultation, and each reviewable and correctable by your coach.
Training and performance. Programs written for you, sessions, the sets you log, and strength test results.
Check-ins. Your answers to the daily and weekly questions your coach asks, including which questions were asked and which you left unanswered.
Nutrition. Meals and drinks you log, their nutritional values, and the targets your coach sets.
Health data from your phone. If you connect Apple Health or Health Connect, PTOps reads a fixed, short list of measurements — steps, resting heart rate, active energy, workouts, and sleep on Android. Nothing else.
Diagnostics. Bloodwork, DEXA and body-composition reports you or your coach upload, and the individual measurements read from them.
Scheduling. Appointments, availability, and cancellations.
Health data
Bloodwork, body composition, resting heart rate and sleep are health information about you. PTOps treats them as the most sensitive data it holds, and two design decisions follow from that.
The health list is fixed, and there is nowhere else for data to go. Apple Health and Health Connect expose well over a hundred kinds of measurement. PTOps requests a short list and the database will physically refuse anything outside it — there is no general-purpose field for a health app to write into. Menstrual cycle, blood glucose, blood oxygen, ECG and everything else are not requested and could not be stored if they were.
A missing reading is never turned into a zero. If you decline to share a measurement, or simply do not own a device that records it, PTOps stores nothing and shows your coach “no data yet”. It does not fill the gap with a number, and on Apple devices it will not claim you declined, because Apple deliberately makes a refusal indistinguishable from an absence and PTOps will not guess.
You can disconnect Apple Health or Health Connect at any time from your phone’s own settings. PTOps stops receiving new readings immediately. Readings already recorded remain with your coach.
Diagnostics, bloodwork and body composition
Reports you upload are stored in a private location that is not publicly reachable. When your coach or you open one, PTOps generates a link that expires after five minutes, and generates it at the moment you click rather than embedding it in the page.
PTOps reports what the laboratory measured and how the laboratory flagged it. It does not apply its own thresholds to your results, and it does not diagnose. Interpretation beyond a trainer’s scope is referred to a doctor — see the terms.
Consultation recordings and transcripts
PTOps is designed to record consultations, transcribe them, and draw structured facts from what was said, with your coach reviewing every one before it is used.
This is not yet switched on. No audio is captured and no transcription service is connected. Nothing is recorded today. When it is built, consent is recorded before any capture begins, and this page will be updated before the feature is available.
Calendar connections
A coach may connect a Google Calendar so PTOps can avoid booking clients over their existing commitments.
PTOps never receives the contents of your calendar. It uses Google’s free/busy endpoint, which returns only the start and end times of periods when you are busy. Event titles, attendees, locations and meeting links are not returned by that endpoint, and there is no field anywhere in the PTOps database that could hold one.
The connection credential is encrypted with a key that is not in the database. The token Google issues is sealed using AES-256-GCM before it is stored, and the key lives in the server environment rather than alongside the data. Someone holding a copy of the database alone could not use it.
PTOps also stores an identifier for the connected account so a reconnection matches the same calendar. That identifier is hashed — the coach’s Google email address is not kept. Read access is requested; write access is requested only if a coach turns on two-way sync.
You can disconnect a calendar at any time in PTOps, which deletes the stored credential.
AI-assisted processing
PTOps is designed to use AI to draft and summarise — never to decide. A coaching decision always belongs to your coach, and generated material is presented to them for review, editing, approval or rejection.
No AI provider is currently connected. Nothing you enter is sent to a third-party model today. Weekly review drafts are produced by software running inside PTOps from your own recorded data, and no coach-facing surface presents generated text as anything other than a suggestion. This page will be updated before any external model receives your data.
Payments and billing
PTOps does not currently process payments. No payment provider is connected and no card details have ever been handled. When payments are introduced, card details will be handled by the payment provider and will not pass through PTOps. This page will be updated before that happens.
Who can see what
Access is enforced by the database itself rather than by the screens, so a mistake in an interface cannot expose data it should not.
- A coach sees the clients of their own business, and no others.
- A client sees only their own information.
- Coach-facing clinical guidance and weekly review drafts about a client are not readable by that client — there is no permission that would allow it.
- A client cannot alter their own health readings or check-in history after the fact; those are observations, not claims.
PTOps staff. A small number of administrative accounts can reach data across businesses. That capability exists so the service can be operated and supported — investigating a fault, restoring something, answering a support request. It is limited to accounts explicitly granted it, and its use is recorded. It is not used to read client health information for any purpose of ours, and no feature of PTOps does so.
Companies that help run PTOps
These are the only third parties that receive data today.
- Supabase — hosts the database, authentication and file storage. All application data lives here.
- Vercel — hosts and serves the applications. Requests pass through Vercel to reach PTOps.
- Google — only if a coach connects a calendar, and only free/busy times as described above.
There is no analytics service, no advertising, no tracking pixels and no error-reporting service. PTOps sets cookies only to keep you signed in.
Keeping and deleting information
Your coach controls the client records in their business. Information is kept while the coaching relationship exists and afterwards as part of the business’s records.
PTOps does not yet provide a way to delete an account or erase a person’s data, and this section will not pretend otherwise. Building that path — and being precise about what can and cannot be removed without destroying records a coaching business needs — is planned work before general release. If you want your information removed, contact us and we will tell you honestly what we can do at that time.
Some records are deliberately difficult to erase because they exist to keep an accurate history: who approved a training plan, who reviewed a laboratory result, who confirmed a nutrition entry. Removing those would leave a coaching record that says something happened without recording who did it.
Your rights
Depending on where you live you may have rights over your personal information, including to see it, correct it, or ask for it to be deleted. If you are a client, the quickest route for most requests is your coach, who controls the record. You can also contact us at support@getptops.com and we will help.
We would rather tell you plainly where the software cannot yet do something than agree to a request and quietly not honour it — see the section above.
Contact
For questions about PTOps, your account, privacy, or your data rights, contact support@getptops.com.
One address, deliberately. A page listing several mailboxes implies a team behind each of them, and it is better to answer everything at one place we actually monitor.
Changes
PTOps is in active development, and several sections above describe features that are not yet switched on. This page is updated when what the software does changes — not afterwards.