HigherCoach by HigherOps / Legal

HigherCoach privacy policy

Last updated 2026-09-18

DRAFT for review. Not in force. A lawyer reviews this before the first paying workspace.

This policy explains what HigherCoach keeps, where, who can see it and for how long. HigherOps [REVIEW: full legal entity name and address] operates HigherCoach. For the data in a customer's workspace, the customer decides what is processed and HigherOps processes it on their behalf. [REVIEW: controller and processor roles, and whether a data processing agreement is offered]

What we collect

  • Your account. Your name, email address and profile picture from the sign-in provider you use (Google or Microsoft), and which workspaces you belong to with what role. HigherCoach has no passwords of its own.
  • Your workspace's conversations. Transcripts and their metadata (title, time, participants' names and email addresses, the source they came from) from the sources your workspace connects: Fellow, Fireflies, or a pasted transcript.
  • What HigherCoach produces from them. Call classifications, analyses, highlights, signals, company pages, company briefs and weekly syntheses.
  • HubSpot data, if your workspace connects HubSpot. The HubSpot company each company matches, its lifecycle stage, open deal amounts and owner names, and the deals HigherCoach creates when someone asks it to.
  • Invitations. The email address and role of each person a workspace admin invites.
  • Your workspace settings. The company profile, roster, call types, prompts and integration settings your admins enter. Integration keys are stored encrypted (AES-256-GCM); the app shows only their last four characters.
  • Usage metering. For each model call: the purpose, provider, model, token counts, an estimated cost and the time. It is used for the usage page and your spend cap.
  • Operational records. Job and run records, an audit log of administrative actions in your workspace (who changed what, and when), and error reports (see "Error reporting").
  • Sign-in records. Our sign-in provider, Supabase Auth, keeps each session's IP address and browser details, and a log of sign-in events.
  • Cookies. Only cookies the app needs to work: the sign-in session (and a short-lived one used while signing in), the workspace you last opened, and short-lived ones that carry an invitation or onboarding step through sign-in. Your light or dark theme choice is stored in your own browser. No advertising or analytics cookies.

Where it is stored

  • The database and sign-in service are hosted by Supabase on Amazon Web Services in the United States (us-east-1, North Virginia).
  • The application runs on Railway in the United States (region us-west2). Its logs can include call titles, company names, email addresses and error messages. [REVIEW: Railway log retention period]
  • The full list of companies that process data for HigherCoach is in the subprocessor list.

Who can see it

  • Members of your workspace see every call, analysis and signal in that workspace. Admins also manage settings, integrations and members.
  • HigherOps operators can access workspace data only to provide support at the customer's request or with their consent, to keep the service secure and running, or where the law requires it. [REVIEW: operator access logging commitment]
  • Your model provider receives the transcript text and prompts needed for each analysis, under your own account with them.
  • Nobody else. We do not sell data and we do not use it to train models.

How long we keep it

WhatHow long
A deleted workspace, and everything in itPurged permanently 30 days after it is deleted
TranscriptsKept until the workspace sets a retention period, which must be at least 30 days; after it, the transcript text is removed and the analysis is kept
Ingest records (which recordings were seen and what happened to each)30 days after a recording was last seen
Analyses, syntheses, signals and company pagesKept for the life of the workspace
Usage metering and the audit logKept for the life of the workspace
Your account (name, email, profile picture)Kept until you ask us to delete it; it is not removed when a workspace is deleted. Supabase's own sign-in logs are kept on its schedule after that [REVIEW: Supabase Auth log retention]
Database backups[REVIEW: 7 days of daily database backups on production; point-in-time recovery deferred, so the worst case is losing up to one day rather than seconds; confirm and state the backup retention]

Purges run automatically every 15 minutes.

Deleting your data

To delete a workspace and everything in it, email support@higherops.io from an admin account of that workspace. [REVIEW: HigherCoach has no delete-workspace button yet; update this section when it does.] To shorten how long transcripts are kept, a workspace admin sets the retention period in the workspace settings. To remove yourself from a workspace, ask one of its admins. To delete your account itself, email support@higherops.io from its address. [REVIEW: HigherCoach has no delete-account button; confirm the response time]

Error reporting

When something breaks, HigherCoach sends an error report to Sentry, from our servers and from your browser. Each report is scrubbed before it is sent: values under names such as api key, token, secret or password are removed, known key and token formats are redacted, email addresses are cut to their domain, any text over 1000 characters (such as a transcript) is replaced by its length, and no cookies or local program variables are sent. Scrubbing works by pattern, so a secret in an unfamiliar format inside an error message could still be sent; Sentry is on the subprocessor list for that reason.

Your rights

Depending on where you are, you may have the right to access, correct, delete or export your personal data, and to object to or restrict its processing. Most of it belongs to your workspace, so ask your workspace admin first; you can also contact us at support@higherops.io. [REVIEW: jurisdictions served, response time and supervisory authority]

Changes

We will tell workspace admins by email before a material change. The date at the top shows the current version.

Contact

support@higherops.io