How we handle your data
Plain-language answers about how CLKS protects your account, your coaching data, and your privacy plus how to reach us with a request.
Access & authentication
CLKS accounts are protected by email-and-password sign-in and Google sign-in. Sessions are scoped by role (admin, coach, client), and each user only sees data they own or are assigned to.
Live session passcodes are never exposed in browser data fetches; clients and coaches retrieve them through a server-side helper that checks the requester's relationship to the session.
Platform & hosting
CLKS runs on Lovable Cloud, which provides managed Postgres with row-level security, an edge serverless runtime, and TLS in transit. Lovable's platform features are factual capabilities — they are not a substitute for an independent security certification.
Data we collect
- Account information (name, email, role).
- Coaching session metadata (schedule, status, summary).
- Workbook responses you submit during a session.
- Contact and consultation form submissions you send to us.
- Operational logs needed to deliver reminders, recordings, and calendar invitations.
Subprocessors & integrations
- Lovable Cloud — application hosting, database, and storage.
- Zoom — live coaching sessions and recordings.
- Managed transactional email from
notify.clks.life— reminders, invitations, and confirmations. - Google — optional sign-in provider.
Cookies & analytics
CLKS uses cookies that are strictly necessary to keep you signed in. No third-party advertising or cross-site tracking is wired into the app at this time.
Retention & deletion
Account and session records are retained for up to 24 months after the engagement ends, after which they are deleted or anonymised. Email delivery logs are kept for 12 months for deliverability and audit. You can request earlier deletion at any time via the contact below.
Privacy requests
To access, correct, export, or delete your personal data, use the form below. We respond within 5 business days.
Security & incident contact
For security questions or to report a suspected incident, please fill the above form.
Security policy
CLKS follows a small set of practical security commitments that shape day-to-day operations:
- Least privilege. Every database table is protected by row-level security. Access is granted per role (admin, coach, client) and reviewed when roles change.
- Encryption. All traffic to CLKS is served over TLS. Credentials, session tokens, and Zoom passcodes are stored and transmitted using managed secrets — never embedded in client bundles.
- Secrets management. API keys and service credentials live in server-only environment variables and are rotated when a contributor leaves or a key is suspected to be exposed.
- Change review. Production changes go through a review step before they ship, and database migrations are version-controlled.
- Monitoring. Authentication, email delivery, and server-function errors are logged so we can investigate suspicious activity.
- Incident response. If a confirmed incident affects your data, we will notify affected users by email within 72 hours of confirmation, describe what happened, and explain the steps we are taking.
This policy is reviewed at least once a year and whenever a major platform change occurs.
Vulnerability reporting
If you believe you have found a vulnerability in CLKS, please fill the above form with reproduction steps. We acknowledge reports within 5 business days and do not pursue good-faith researchers who:
- Test only against their own accounts and data.
- Avoid accessing, modifying, or destroying data that does not belong to them.
- Do not run automated scanners that degrade service for other users.
- Give us a reasonable window to remediate before any public disclosure.
Compliance
CLKS does not currently claim formal certifications such as SOC 2, ISO 27001, GDPR, HIPAA, or PCI DSS. If you require a specific attestation for procurement, contact us and we will respond with what we can provide.
Questions?
We're happy to walk through anything on this page in more detail.
Contact usLast reviewed: 2026-06-18