Privacy Policy
Effective 17 September 2026
1. Who is responsible
CoachLayer is operated by ZON, based in France. For the data described in section 2, ZON is the data controller in the sense of the GDPR. For content your systems send through the API (section 3), you are the controller and ZON acts as your processor. Privacy questions and requests: support@justzon.com.
2. Data we collect about you
- Account data. Email address and a password (stored by our authentication provider; we never see the password itself), your name or company name if you give one, and account settings. Legal basis: performing our contract with you.
- API keys and usage. Keys are stored hashed, never in clear. For each API call we record metadata: endpoint, credits charged, timestamps, request identifier, token counts and coarse cost telemetry. Legal basis: contract (metering and billing) and legitimate interest (capacity planning, abuse prevention).
- Billing data. Subscriptions and payments are handled by Stripe; we store your plan, invoices and payment status, never full card numbers. Legal basis: contract and legal obligation (accounting records).
- Anti-abuse data. Signup and failed-authentication events are rate-limited per IP address; IP addresses used for this are stored hashed. Legal basis: legitimate interest (keeping the free tier alive).
- Support. Emails you send us, so we can answer them. Legal basis: legitimate interest.
The site uses no advertising trackers.
3. Data flowing through the API
Requests you send to the API can contain content about your end users, for example workout logs or training questions. This content is processed transiently to produce the response: the proxy is stateless per call, request content is not written to a durable store on our side, and it is not used to train models. What we keep is the usage metadata described above, which does not include your end users identities. You are responsible for having a lawful basis to send this content, and for not sending data your own privacy commitments do not allow. A signed data processing agreement is available on request.
4. Subprocessors
We use a short list of infrastructure providers under data processing agreements:
- Supabase (database and authentication),
- Vercel (hosting and delivery),
- Stripe (payments),
- model inference infrastructure used to generate coaching responses, bound by agreements that prohibit training on your data. We do not publish the identity of inference providers; the current list is available to customers on request under confidentiality.
Some providers process data outside the European Economic Area. Where they do, transfers rest on adequacy decisions or standard contractual clauses.
5. Retention
- Account data: for the life of the account, then deleted or anonymised.
- Usage and billing records: kept as long as needed for metering and for the retention periods French accounting and tax law impose.
- Hashed anti-abuse counters: short rolling windows, then discarded.
- API request content: not retained, as described in section 3.
6. Your rights
Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to support@justzon.com and we will answer within a month. You can also complain to the CNIL (cnil.fr), the French supervisory authority.
7. Security
Traffic is encrypted in transit. API keys are hashed, tenant data is isolated with row-level security in a dedicated schema, authentication is delegated to a dedicated provider, and access to production is restricted. No system is perfectly secure; if a breach affects your data we will notify you as the GDPR requires.
8. Changes
We will update this policy as the service evolves and change the date at the top. For material changes we will tell you by email or in the dashboard.