Trust

How we use
your data

Plain English. No clauses. What we collect, what we do with it, where it sits, and the things we will never do. If you want the legal version, the Privacy Policy and DPA are next door.

  • SOC 2 Type 1
  • UK GDPR
  • Updated 22 July 2026

The short version

Four things, before the detail.

  • You sign up. We hold your email, name, and what you do on the Platform. Enough to run coaching, support, and billing.

  • When you paste a deal, a transcript, or a draft email, that text goes to an AI provider so a coach can answer.

  • We do not train any AI provider's foundation models on your data. The providers we use commit to the same.

  • We do not sell your data. We do not share it with other customers. Coaches never see another customer's deals.

What we collect

Four categories. Nothing hidden.

  • 01

    Account data

    Name, email, job title, password (hashed), and what you sign up for.

  • 02

    Usage data

    Which coaches you talk to, when, how long, and how the Platform performs. This is how we know what to build next.

  • 03

    Content you give us

    Messages to coaches, transcripts you paste in, documents you upload to your Knowledge Base, roleplay recordings if you use voice.

  • 04

    Billing data

    Handled by Stripe. We see the invoice, not your card.

What we do with it

It runs the Platform. That is the whole job.

  • Run the Platform

    Show you the right coach. Remember your past sessions. Bill you correctly.

  • Coach you

    Send your messages to the AI provider that powers the coach you are talking to. The response comes back, we render it, you see it.

  • Make the product better

    Aggregate, anonymised metrics. Retention, feature use, error rates. Never re-identified, never sold.

  • Support you

    When you raise a ticket, we read it. When you book onboarding, we prep based on what you have done.

The coaches and your data

Each account is a wall. Each user-and-Coach combo is a window.

Nothing leaves your account. Nothing in your account is visible to any other account. Inside your account, a user talks to a Coach and that conversation is theirs.

Each account, walled off from every other account.
  • User and Coach

    Each conversation belongs to the user who had it.

    Every Coach runs its own prompt and its own methodology. A conversation between a user and their Coach is a window: the user sees it, the Coach sees it. Other ordinary users in your account do not. The exceptions are your account admins and, on Team and Enterprise, Bryce and team analytics. No user or Coach in any other account sees it, ever.

  • Bryce, the analytics layer

    Bryce sees the sessions, inside your account, so the team can be coached.

    Bryce is your account-level analytics and insight layer. He can read user sessions with their Coach across the account, so leaders get the read on what is working and where the gaps are. He never crosses the account wall, and his reports stay inside your account.

If you are a rep using this

Your data, and who gets to see it.

Most of this page is written for the person who bought the Platform. This part is for the person using it. Who can see your coaching depends entirely on which plan you are on, so start there.

  • Free and Individual No other user. There is no Bryce, no admin and no team analytics on these plans, and nobody else on your account to see anything. Your coaching is yours.
  • Team, 2 to 10 seats Whoever owns the account gets Bryce and team analytics, so they can see coaching activity across the seats they pay for. That is what the plan is for, and it is listed on the pricing page.
  • Enterprise, 11+ seats Everything Team has, plus SSO, SCIM and audit logs. Your organisation owns the account and decides who administers it.
  • 01

    What we hold about you

    Your name, email and job title. Which coaches you speak to, when, and for how long. Everything you type or paste into a coach. Your roleplay recordings, if you practise by voice.

  • 02

    Whose data it is

    If you signed up yourself on Free or Individual, you are our customer and you deal with us directly. If your company bought Team or Enterprise, they own the account. They are the data controller, we are the processor, and we act on their instructions.

  • 03

    Getting it changed or deleted

    Signed up yourself? Email us and we will handle it. On a company account? Ask them first, because we act on the account owner instruction. Either way we delete within 30 business days of the Services ceasing, whether that is a monthly cancellation or an annual term running out.

Where your data sits

Your database is in the UK. Several sub-processors are not.

The Platform runs on Google Cloud and the primary database is in the United Kingdom. Anam, which powers avatar video, is also UK. Gleap, our in-platform support chat, is in Austria.

Everything else is in the United States. That includes the AI providers your coaching runs through (OpenAI, Anthropic) and voice transcription (Deepgram), and it also includes Pinecone, which stores and searches the documents you upload to your Knowledge Base. So this is not only data in transit for an inference call: Knowledge Base content is stored in the US. Those transfers are made under standard contractual clauses and the UK Addendum.

* We are exploring a US-managed variant for US customers who need their primary data in-region. If that is a requirement for you, talk to us.

The full list of sub-processors lives in Annex 2 of the DPA. We notify customers 14 days before adding any new sub-processor and give you the right to object.

Sub-processors

All the tools we use to maximise your experience and value.

  • Google Cloud Cloud hosting, primary database, data centre services UK
  • Anam Avatar video UK
  • Gleap In-platform support chat Austria
  • OpenAI AI inference US
  • Anthropic AI inference US
  • Deepgram Voice transcription US
  • Pinecone Knowledge Base storage and search US
  • Sentry Error monitoring US
  • Mixpanel Product analytics US
  • Kit Email US
  • Recall Meeting transcription (optional add-on) US
  • Pipedream Workflow automation US

The authoritative list, with full processing detail, lives in Annex 2 of the DPA. Stripe handles card payments and is named in our Privacy Policy rather than Annex 2, because billing is our own commercial relationship with you and not customer data we process on an account owner's instructions.

The line we hold

What we will never do.

  • Train foundation models on your data

    Not us, and not the AI providers we send your coaching through. Their enterprise terms cover this; ours codify it.

  • Cross-pollinate your data across accounts

    Your Knowledge Base is yours. Your transcripts are yours. Nothing in your account is visible to any other account.

  • Sell your data, or any derivative of it

    Never to advertisers, never to data brokers, never to competitors.

  • Quietly add a new sub-processor

    You get 14 days notice, and you get the right to object.

If you want it deleted, or have a question

If you want it deleted

30 business days from cessation, sub-processors included.

Email legal@handle.tech. We delete your data, and instruct our sub-processors to do the same, within 30 business days of the Services ceasing, matching clause 11 of the DPA. The exception: where law requires us to keep it (billing records, fraud-prevention logs).

Using the Platform through your employer? Send the request to them first. They are the controller, so we act on their instruction. Write to us anyway and we will tell them and help them answer you.

A question that is not covered

Real human. Same-day reply.

Email legal@handle.tech. Same-day reply on business days. No ticket maze, no clause-hunting.

The legal version, if you want it

This page is the plain-English read. The Privacy Policy and Data Processing Agreement are the binding documents, and they say the same thing in full.

Read the DPA
  • SOC 2 Type 1
  • UK GDPR
  • No model training