™

Privacy Policy

Last updated September 17, 2026

This policy describes how nlaapp.com handles information for the agency website, trial, billing, Coaching Hub, and the browser app. The NLA iPhone app has its own privacy policy. Read both if you use both, because they share one account and one database.

Scope, and why there are two privacy policies

This policy covers the website: pages on nlaapp.com used to market, sign up for, and run an NLA organization, plus /client in a browser. It does not rewrite the iPhone app Privacy Policy. App-only features (the AI assistant, on-device calendar sync, local notifications, and consumer App Store or Google Play payments) are described there, and we are leaving that document in place.

Honesty about the overlap: the website and the app use the same login and the same Supabase project. Goals, tasks, habits, projects, and related tracking rows are not copied into a second database when you open them on the web. Coaching-only rows (invites, chat, session notes, organization membership, billing status) are created by this website. If a fact is about a shared row, both policies can apply. If a fact is only about the iPhone app, the app policy governs.

This policy also does not cover the separate 5-Week Reset program, which has its own pages under /5-week-reset.

Questions or privacy requests: matt@nlaapp.com.

Who is responsible for the data

For your own account (email, password, profile, and the tracking you create for yourself), NLA decides how the product stores it and is responsible for that product decision.

For coaching records an agency puts in NLA (roster, assignments to clients, chat, session notes), the organization is deciding what to collect from its clients and why. We process that information to run the product they bought. Agencies need their own client-facing privacy notice and a lawful reason to coach those people. We do not currently offer a signed data processing addendum as a self-serve download. If you need one, email us.

Information we collect

Account. Email, password (hashed by our auth provider, not stored by us in plain text), name, optional username, and the time you agreed to terms. If you enable two-factor authentication, the authenticator setup lives with our auth provider.

Auth infrastructure. Supabase logs IP addresses and basic device or session information on sign-in, sign-up, and similar events as part of running authentication. Session cookies on your browser keep you signed in. We do not run a separate advertising or product-analytics SDK on this website.

Organization. Agency name, owner, members, archive state, MFA requirement, trial dates, subscription status, Stripe customer and subscription ids, and the client-capacity batch selected at checkout.

Invites. Email addresses you type when inviting a coach or client, the token, and whether the invite was accepted.

Coaching work. Assigned goals, tasks, habits, and projects; completion and streak data the product shows a coach; chat messages between a coach and a client; session notes; and goal-sharing choices a client makes when they accept an invite.

Shared tracking data. The same goals, tasks, habits, projects, and journal entries described in the app privacy policy, because they are the same rows. A coach does not get a copy of a client's private journal or personal goals unless the product's author-lock rules allow that specific item.

Billing. The owner starts Stripe Checkout. Stripe collects card details. We never see or store the full card number. We store Stripe customer and subscription identifiers, the capacity batch id, and subscription status so the organization can keep working after payment.

App premium grant. When someone joins through an organization, we send their account identifier to RevenueCat so we can grant consumer-app Premium. RevenueCat does not receive coaching chat or journal contents. Consumer payments they make themselves stay under the app policy.

Deletion and audit. Account deletion requests, whether the organization flagged retention, and a limited audit log of sensitive org actions (invites, archive, ownership, deletion review).

What we do not collect on this website

  • We do not use advertising SDKs or a product-analytics SDK on the agency website.
  • We do not collect card numbers ourselves. Stripe does that at checkout.
  • We do not access your phone's contacts, camera, microphone, or location from this website.
  • We do not use the website to send your journal or goals to Anthropic. If you use the iPhone AI assistant, that is described in the app privacy policy and happens only when you use that feature.

How we use the information

  • Create and run your account, organization, and invites
  • Show each coach the work they assigned, and show the owner what they need to run the agency
  • Deliver chat and session notes
  • Charge the owner through Stripe and keep subscription status in sync
  • Grant included app Premium through RevenueCat
  • Send transactional email: invites, ownership transfer, deletion review, and similar product mail
  • Diagnose bugs and keep the service secure

We do not sell your information. We do not rent it. We do not use agency-workspace data to train a public AI model.

We do not currently send marketing newsletters for the agency product. Account email (verification, password reset) is sent by Supabase. If we later add optional marketing email, it will be opt-in and this policy will be updated first.

Who can see coaching data

Author-lock is a product rule enforced in the database, not a promise that nobody at NLA can ever access the systems. In the product:

  • A coach sees what that coach assigned, plus chat and session notes on that relationship.
  • Another coach on the same client does not see the first coach's work.
  • A client's personal tracking stays out of every coach's hub unless it was assigned or shared as the invite flow allows.
  • The organization owner can see across the roster. That is the intentional override for complaints and offboarding, and it is described up front in the product.

People at NLA can access production systems when we have to operate, repair, or secure the service. We are a small team. We do not go reading client journals for fun, and we do not use that access for advertising.

Cookies

The website uses cookies and similar storage that are required to keep you signed in and to run the app (Supabase session cookies), plus a small first-party preference that remembers whether you Accepted or Rejected optional cookies on the banner. We do not currently set advertising cookies or a third-party analytics cookie. Full detail, and what Accept vs Reject means today, is in the Cookie Policy.

Processors we use for the website

These companies process information on our behalf to run nlaapp.com:

  • Supabase: authentication and the database
  • Stripe: organization checkout, invoices, and cards
  • Resend: transactional email (invites, deletion review, ownership transfer)
  • Vercel: hosting this website
  • RevenueCat: promotional Premium grant on the consumer app account

Each has its own privacy policy. We are responsible for what we send them. Data is typically stored in the United States.

Retention and deletion

We keep account and organization data while the account exists. You can request deletion from Account.

  • If you have no coaching relationship, deletion is immediate and wipes the account. There is no grace period to undo it.
  • If you have a coaching relationship, the account is deactivated immediately and the organization reviews the record (currently within 30 days). The owner can flag retention if they need the history. That exists so a client cannot silently erase an agency's file.

Deleting a website account is the same login as the iPhone app, so it also removes that app account. It does not cancel an App Store or Google Play subscription the person bought themselves. Cancel those in Apple or Google settings, as the app terms say. It also does not, by itself, cancel the organization's Stripe subscription. The owner cancels that in Refunds and cancellation.

Stripe, Supabase, and email providers may keep residual logs or invoices for the period their own rules or the law require, after we delete the live account.

Children

The website is not directed at children under 13, and we do not knowingly collect information from them. Organization accounts are for adults. If you believe we have information about a child under 13, email matt@nlaapp.com and we will delete it.

State privacy rights

If you are a California resident, we do not sell or share personal information as those words are used in the CCPA/CPRA. You can ask us what we have, ask us to delete it (subject to the coaching-relationship review above), and ask us not to use it for advertising we do not currently do. Email matt@nlaapp.com. We will not discriminate against you for making that request.

We do not currently operate a European establishment or offer a self-serve GDPR pack. If you are an agency that needs a DPA or a specific international-transfer clause, email us before you put EU client data in the product rather than assuming the paperwork exists.

Changes

If we make material changes, we will update the date above. Continued use of the website after a change means you accept the updated policy.

Contact

Privacy questions and requests: matt@nlaapp.com. Terms for this website: Terms of Service. iPhone app documents: app Terms and Privacy.