Vitra Coach is built so that we cannot read your clients’ health data. This page explains how — and what we do and don’t store.
End-to-end encryption. Every client data snapshot is sealed on the client’s device to the coach’s public key using libsodium sealed boxes (X25519). It can only be opened with the coach’s private key.
Server-blind storage. Our object store and database hold ciphertext only — sealed blobs, public keys, wrapped private keys, and anonymous identifiers. There is no admin override and no analytics pipeline over client data. Decryption happens exclusively in the coach’s browser.
Anonymous pairing. Clients pair with a one-time code. No name or email is transmitted — only an anonymous handle. Coach-side nicknames and notes are encrypted to the coach’s key or kept on-device.
Passwordless access. Coaches sign in with a magic link plus a single recovery code, with optional passkey (Face ID / Touch ID) unlock. Sessions are capped and location-aware.
| We store | We never see |
|---|---|
| Sealed ciphertext blobs | Plaintext wearable / health data |
| Coach & client public keys | Client private keys |
| Coach private key, wrapped under their recovery secret | The unwrapped coach private key |
| Anonymous client handles | Client names, emails, or identity |
We use the following service providers to run Vitra Coach. Client health data reaches them only as ciphertext.
Data residency. The database (Neon) is hosted in Washington, D.C., USA (US East, iad1); sealed blobs (Cloudflare R2) are stored in Western Europe. Because all client health data is stored only as ciphertext sealed to the coach, its physical location cannot expose it.
Data retention. Sealed client-metric history is retained for 2 years on Starter and Pro, and 5 years on Studio. Older ciphertext is automatically deleted by age (never decrypted). Analytics use recent trailing windows, so day-to-day insight is unaffected.
Certifications. Vitra Coach holds no third-party security certifications (such as SOC 2 or ISO 27001) at this time. Our protection is architectural — end-to-end encryption and server-blind storage mean we cannot read client health data even if compelled to.
GDPR. No client identity is transmitted — clients pair under an anonymous handle, and their health data is stored only as ciphertext sealed to their coach. For a coach’s own account data (email, billing) we act as the data controller; for the client ciphertext we relay, we act as a data processor.
HIPAA / BAA. Vitra Coach is not HIPAA-certified and does not currently offer a signed Business Associate Agreement. The server-blind design means we never receive unencrypted PHI.
Found a security issue? Email pt@amplifiedcreations.com. We aim to acknowledge reports promptly and will keep you updated as we investigate. Please give us reasonable time to remediate before any public disclosure.
Last reviewed: 2 July 2026 · Amplified Creations Lda · Estrada de São Tiago Nº376, 2415-543 Marrazes, Portugal