Client data safety, in plain English

Give each part of client data the right door and the right key.

HiringCoachAI uses clear access boundaries, client controls, protected infrastructure, and honest retention rules. No jargon, no claim of zero risk, and no hiding important limits.

The 30-second answer

Four boundaries that matter in everyday coaching.

Access follows the relationship

A coach cannot browse every client. Server checks tie protected data to the specific coach-client connection.

Clients have sharing controls

After acceptance, clients can change any of the six categories, including core workspace access.

Private stays separate

Coach-private notes use a different access boundary from the shared log and are excluded from the client's export.

Export and close-out are built in

Signed-in people can export a broad account archive. Coaches can export notes before choosing immediate, scheduled, or indefinite retention.

Who can see what

A connection is the key. Permissions decide which rooms open.

HiringCoachAI checks both identity and the coach-client relationship before protected data is returned. If a category is off, coach access to that category is rejected.

1

The client

Owns their account and can manage supported career-content categories.

2

The relationship

Names the client, the connected coach, the status, and the allowed sharing scope.

3

The coach

Sees the shared workspace and only the career categories the relationship allows.

Core coaching workspaceGoals, assignments, sessions, intake, and shared coaching activity
  • Applications
  • Career profile
  • Networking
  • Interview preparation
  • Writing

Existing and default relationships begin with supported categories shared. In the scoped acceptance flow, the core coaching workspace starts on. After acceptance, the client can change any of the six categories, including workspace access.

Private and shared records

A private note is not just a shared note with a hidden label.

Shared

Built for joint work

  • Shared log and relationship activity
  • Goals, assignments, sessions, and feedback
  • Materials shared with an explicit role
  • Client-visible history where the workflow says it is shared
Coach private

A separate server-side boundary

  • Private context and private coaching notes
  • Ordinary product access is coach-only and server-authorized
  • Excluded from the client's account export
  • Included in the coach's close-out retention choice
  • Limited authorized administrative access remains possible under published support, security, and legal policies

Private notes and context

What a coach writes about a client, and where it can go.

Server-only access

Private notes and the client context card are checked against the signed-in coach and the relationship on every read and write.

The client can never read them

Private notes and context sit in a separate boundary from the shared log. The client's product access does not reach this data.

Note content stays on the coach surface

A private note is never emailed, never sent in a notification, and never included in the client's account export. The one exception is the coach's own retention export, described below.

Context is coach-only, with one narrow exception

People, care flags, key dates, and values sit behind the same access checks as private notes and are excluded from the client's export. A saved value can appear inside a check-in reminder the coach sends to themselves; it is never sent to the client.

Two retention modes

A coach can keep full narrative notes, or switch to a minimal mode that stores only structured items and hides the narrative composer.

The close-out purge

Ending an engagement lets the coach export notes first, then choose immediate deletion, a scheduled deletion window, or indefinite retention.

How the system protects data

Several practical layers, each doing a different job.

Secure traffic

HTTPS protects data moving between the browser and HiringCoachAI.

Protected storage

Google Cloud provides platform encryption at rest. Selected restricted fields receive additional application-side encryption.

Default-deny rules

Firestore denies anything not explicitly allowed, while most coach data is handled through authenticated server APIs.

Permission checks

The signed-in person, relationship role, relationship status, and content category are checked before access.

Safer diagnostics

Error monitoring disables default personal-data collection and strips common secrets such as cookies and authorization headers.

Public accountability

The Trust Center publishes documented controls, policies, providers, limitations, and reporting paths.

The data lifecycle

Safety also means knowing what happens at the end.

  1. 1

    Connect

    A client accepts the relationship and sees the sharing choices available to that flow.

  2. 2

    Work

    Coach and client use shared records, while private coach context stays in its separate boundary.

  3. 3

    Export

    Account owners can request an authenticated archive. Coaches can export relationship notes before close-out.

  4. 4

    Close or delete

    End the relationship, revoke ordinary shares, choose note retention, or delete the account. Each is a distinct action.

Account deletion removes data from active product systems, but limited billing, audit, contract, legal, and backup-window records may remain under the published retention policy.

When another service is involved

The boundary should stay visible.

AI

Only for a feature that needs it

Supported AI features send the context needed for that call. Session AI can include private coach notes; a transcript is included only after the coach confirms client consent. Standard provider retention can still apply.

See providers and triggers
Payments

Sensitive payment credentials stay with Stripe

Stripe captures card numbers and coach bank, identity, and tax-input details. HiringCoachAI stores identifiers, amounts, fees, payout status, refunds, disputes, and records needed to operate and document the workflow.

Open payments help
Google Drive

One marked folder, not the whole Drive

HiringCoachAI creates one marked folder. A dedicated service account is shared only on that folder, including files and folders placed directly beneath it. It does not receive access to the rest of the Drive.

See service providers

What we will not claim

Trust grows when the limits are easy to find.

  • No zero-risk promise. No online service can honestly guarantee perfect safety.
  • No HiringCoachAI SOC 2 claim. Infrastructure providers have their own attestations; HiringCoachAI does not currently claim its own.
  • No zero AI retention promise. Standard provider abuse-monitoring retention can apply.
  • No instant, total deletion promise. Limited legal, financial, audit, and backup-window records may remain.
  • No HIPAA claim. Protected health information is outside the supported service scope.

Questions coaches hear

Clear answers you can explain to a client.

Search the coach FAQ

A client asks a question you cannot answer?

Do not guess. Bring it to us.

Security concerns go to [email protected]. Privacy and data-rights questions go to [email protected].