Legal

Privacy Policy

Last updated 29 September 2026

Ascension holds health and performance data, which is the most sensitive kind of record a coaching business keeps. This page sets out exactly what this build collects, where it lives, and who can read it — in plain terms, matching the software.

What we collect

Coach accounts: your name, business name, email address, timezone, bio, the focus areas you selected at signup, and your notification preferences.

Athlete accounts: an email address and a password for each athlete you invite, plus the record of when they last opened their portal.

Coaching data you and your athletes enter: wearable metrics (sleep, HRV, resting heart rate, strain, weight), nutrition entries and macro targets, training sessions and set logs, protocol checklists, check-ins, messages, blood-marker values, and any lab documents uploaded to the vault.

Enquiries: if you use the contact form, we store the name, email address and message you send.

Where it lives

In this build everything is stored in a single SQLite database on the machine that runs Ascension, alongside any uploaded lab files. There is no third-party analytics, no advertising network, and no external data processor in the path.

Lab files are written to a folder beside the database. A file is only readable by the athlete who uploaded it and the coach whose roster they are on.

Passwords and sign-in

Passwords are stored as scrypt hashes with a unique random salt for every account. The plaintext password is never written to disk and cannot be recovered from the hash — not by us, and not by anyone who reads the database file.

Signing in sets a single httpOnly session cookie which lasts fourteen days. Only a hash of the session token is stored, so the database cannot be replayed as a login. Changing your password immediately invalidates every existing session, including the current one.

Who can see your data

A coach sees the athletes on their own roster and nobody else's. An athlete sees their own record and their own coach — never another athlete's. Both rules are enforced server-side on every request, not just hidden in the interface.

Automated reasoning (RIS) reads your metrics to detect physiological patterns. Its recommendations are held for coach approval before they take effect; it does not message anyone and it does not change a plan on its own.

Retention, export and deletion

Data is kept for as long as the account is open. You can ask for an export or a full deletion of an account and its coaching records at any time by emailing the address below, and it will be actioned without a retention argument.

Records that a coach deletes inside the app — an individual log entry, a lab document, a message — are removed from the database rather than hidden.

Cookies

One cookie, and only when you sign in: ascension_session, which identifies your session. It is marked httpOnly so page scripts cannot read it, and it is sent only over HTTPS when you are on a secure connection. There are no tracking or advertising cookies.

Not medical advice

Ascension is coaching software. It does not diagnose, treat or prevent disease, and it is not a substitute for a clinician. Blood markers and biometrics are shown so that you and your coach can act on them with proper context.

Questions about any of this, or a request we have not covered? Email contact@ascensioncoaching.com.