Permissions & Privacy
Understand direct coaching relationships, team roles, masked profiles, and safe access revocation.
Coach access is based on explicit relationships and team roles. Seeing a person in a roster does not always mean you can open all of their private training data.
Direct coaching relationship
A direct relationship is created when:
- a coach accepts an athlete's personal invite code;
- an athlete accepts a coach-generated share or email invitation;
- a coach approves a public start-page request;
- a valid team onboarding flow explicitly creates the relationship.
Coach-scoped athlete APIs verify this relationship before returning private profile, calendar, planned-workout, or completed-workout information.
Team visibility
Team roles determine which management tabs and actions are available. Staff roles are Owner, Admin, and Coach. An Athlete member can see team-level roster and staff information, but athlete cards may be masked.
A masked card hides private metrics and cannot be opened. This prevents broad team membership from automatically becoming private athlete-data access.
Invitation safeguards
- Coach and team invitations expire after seven days.
- Email-restricted invitations can only be accepted by the intended email.
- Pending invitations can be revoked.
- Public start submissions require coach approval before access is granted.
- The request queue warns when an athlete reports existing active coaches.
Revoking access
Athletes can remove a direct coach from Coaching → Team → My Coaches. Revoking a pending invitation prevents future acceptance but does not remove an already-established relationship.
Removing an athlete from a group only removes group membership. Deleting a team removes the team and its groups; do not use it as a substitute for managing an individual direct coaching relationship.
Data-handling guidance
- Access only the athlete information needed for coaching.
- Do not share screenshots or exports without the athlete's permission.
- Treat wellness, recovery, body, and nutrition data as sensitive.
- Use the coach-scoped views instead of asking for athlete passwords.
- Confirm a relationship has been revoked when coaching ends.
