Data Privacy Statement

Your data, protected by design

We built Autotelic Drive so busy professionals can train with complete confidence — in the program and in the platform behind it. This statement explains, in plain language, how your personal information, health goals, and training data are kept confidential and secure.

Last updated: August 12, 2026

1. Introduction & Account Security

The absolute confidentiality of your personal information, health goals, and training data is our highest priority. Your account is protected by encrypted user authentication, and access to every part of the platform is gated behind your private credentials. No other client can view, reach, or infer your information.

We never share, sell, or disclose your details to third parties. Your information is used solely to deliver and personalize your coaching experience.

2. Infrastructure & Data Encryption

Autotelic Drive is built on enterprise-grade infrastructure that maintains SOC 2 Type II and ISO 27001 certifications — independently audited standards that confirm rigorous, continuous protection of customer data.

All information moving between your device and our servers is fully encrypted in transit using TLS 1.2 or stronger. Data at rest is encrypted using industry-standard AES-256 encryption. These controls protect your information whether you are actively using the platform or not.

3. Advanced Data Isolation (Our Custom Safety Precautions)

Beyond certified infrastructure, we engineered additional security mechanisms into the platform architecture itself to seal potential data exposure windows before they can ever be reached.

We enforce strict Row-Level Security (RLS) across all backend client tables. Your workout routines, uploaded progress metrics, and training data are completely isolated at the database level and cannot be viewed or accessed by any other user or client.

All user inputs are protected by strict server-side validation to block unauthorized database requests.

4. Secure Payment Processing

We never see, store, or process credit card numbers directly. All financial transactions are handled securely through Stripe, a PCI-DSS certified payment provider. Your card details are entered on Stripe's encrypted checkout and never touch our servers.

5. Data Ownership & Rights

You retain full ownership of your data. At any time, you may request a complete copy of your profile and training records, or ask us to permanently delete your account — in compliance with data privacy standards such as GDPR and CCPA.

To exercise any of these rights, simply reply to any correspondence from your coach or reach out through the contact details provided with your membership. We will respond promptly and act on your request without unnecessary delay.

This statement is reviewed and updated whenever our safety or security controls change. The date above reflects the most recent review.