Athlete data, treated like it matters.

Training, health, and wearable data get the same protection whether you train alone or with a team of fifty.
AES-256 at rest
TLS 1.2+ in transit
Hosted in Canada
GDPR and CCPA

Security is a build decision, not a policy page.

Everything below is how the product is built and run today.
01 · Infrastructure
Where it runs
Google Cloud, in Canada, and the code refuses to run anywhere else.
Canadian data residency
GoodCoach runs on Google Cloud in the Montréal region (northamerica-northeast1). The region is pinned in our infrastructure code, which refuses to deploy to any other one.
Network isolation
The database has no public address: it lives on a private network and is reachable only from our own servers. Public traffic reaches the application through Cloudflare, never directly.
02 · Data protection
How it is protected
Your training history, health metrics, and wearable data belong to you.
Encrypted at rest
Every database disk and backup is encrypted at rest with AES-256, the Google Cloud default we do not switch off.
Encrypted in transit
Everything between your device and our servers uses TLS 1.2 or higher. Every connection is HTTPS.
A record of who looked
Changes to your data are logged with who made them and what changed, and reads of health data are logged too. Athletes can see who has viewed theirs.
Backed up daily
Automated daily backups plus point-in-time recovery, encrypted and kept in Canada, so your history is recoverable to the minute.
03 · Access control
Who can reach it
A short list of people, only when there is a reason.
Internal access
A small number of authorized staff can reach customer data, and only when the work requires it. Access is granted and revoked through one reviewed tool, and role-based access control runs throughout the product.
AI features, disclosed
Features that use AI send the text they need to a model provider hosted in the United States. Your training history and health records stay in Canada; only the prompt for that feature leaves.
04 · Compliance
What we hold ourselves to
Standards we follow today, and the one we are working toward.
GDPR and CCPA
We follow the privacy standards that govern athlete data, including PIPEDA, GDPR and CCPA: you can export your data yourself, and deleting your account is a 30-day grace period followed by a permanent delete, not a hidden flag.
SOC 2 Type II, in progress
We are working toward SOC 2 Type II and do not claim it yet. Until then, the audit log, the Canadian residency and the deletion behaviour above are the controls we can show you today.

Found a hole? Tell us.

Send security reports to security@goodcoach.ca. We acknowledge within 24 hours, work with you to verify it, and keep you posted until it is closed.
goodcoach
Every part of performance in one place — for athletes, coaches, and the organizations behind them.
Supported by
© 2026 GoodCoach
Built in Saskatchewan, Canada