Loading…
Loading…
What we collect, why, and what we won't do with it.
The information you give us — name, email, and anything you publish on your public site. Basic technical data needed to operate the service (sign-in events, device and browser information, IP for security and rate limiting).
With your consent, we also collect analytics: pseudonymous first-party pageviews, Core Web Vitals, coach-site interactions, and content usage, plus events delivered through Google Tag Manager to services configured in our container (currently Google Analytics). A first-party event may include your internal account id when you're signed in. We don't sell your data. For the full list of cookies and analytics events, see our cookie policy.
Without analytics consent, we may count a small allowlist of completed operational actions using only the event name and a fixed, non-identifying marker. Those counters contain no browser, location, path, referrer, visitor, account, coach, or submitted-content data.
Google Tag Manager and Google Analytics are never loaded on the private /client, /messages, or/account workspaces, even if you previously allowed analytics on a public page.
Embedded videos, social posts, and external images are a separate optional category. Before you allow it, Coloseos replaces provider frames with a labelled placeholder; external images remain absent or use a first-party fallback. Neither sends a provider request. If you allow embedded content, YouTube, Vimeo, Loom, Instagram, TikTok, Facebook, or Strava can receive your IP address, browser details, and page referrer and may use cookies or browser storage under their own privacy policies. You can open the provider's original page without granting this category. When rendered on Coloseos web pages, blog, program, event, and client- material covers selected from Pexels and images a coach links from any other external host in Markdown use the same consent boundary; relative Coloseos images do not. Cover URLs can also appear in SEO metadata and subscribed blog emails, where link-preview/search crawlers or the recipient's email client may fetch them under their own remote-image controls. Authenticated authoring pages may contact Pexels to display a cover the coach already selected, and opening or searching the Pexels picker makes the corresponding authoring request. Legacy organization and credential marks can use Google's favicon service under this same Embedded content choice; that request is separate from Google Tag Manager and Analytics.
To run your account, deliver the features you signed up for, protect the service against abuse, and meet our legal obligations. That's it.
You, your admin collaborators if any, and the vendors we rely on to run the service (hosting, email delivery, payments, bot and spam protection on our public forms via Cloudflare, and — if you grant analytics consent — Google, via Tag Manager and Analytics, acting as our data processor). Nobody else. We don't share your data with third parties for advertising.
If you separately allow embedded content, the provider hosting a selected video, post, or activity receives the connection data needed to serve it. Turning that category off removes its iframe or external image from Coloseos. Provider-domain cookies or storage already created remain controlled by that provider and your browser settings.
Colos-AI — the AI agent in your admin — works by sending your prompt plus a small amount of context (the page you're on, the specific content you're drafting, your coach profile basics) to our AI provider so it can generate the response. That provider processes the request and returns a draft to Colos-AI, which then shows it to you in the thread.
What we don't do: we don't use your data to train third-party models, we don't sell AI prompts or outputs to anyone, and we don't share them across accounts. We log enough metadata (tokens, cost, timing) to meter usage and catch abuse — not the prompt content.
Threads stay in your admin until you delete them, which you can do at any time from the Colos-AI panel. If you cancel Colos-AI, existing threads remain read-only in your account and are removed when you close the account.
If you opt in at signup, we send occasional product news, tips, and updates by email. Our marketing and product emails may include tracking that tells us whether a message was opened and which links were clicked — this helps us understand what's useful. You can unsubscribe from these emails at any time using the link in every message, or from your account settings. Essential account and service notices are always sent regardless of this preference.
You can access, correct, export, or delete your data from the admin at any time. If you live somewhere with data-protection laws (such as the GDPR), those rights apply in full.
If you can't complete a privacy request from your account, email support@coloseos.com. That address is monitored by Coloseos.
We apply standard security practices — encryption in transit, careful access control, and optional two-factor authentication for coach accounts. We can't promise perfect security; no one can. If an incident involves personal data, we assess and document it. We notify the competent authority and affected people promptly when the nature and risk of the incident require it under applicable law.
To report a suspected vulnerability or security incident, email abuse@coloseos.com. Do not include passwords, access tokens, or private client content in the first message.
We have integrated Cloudflare Turnstile for use on public forms such as booking requests, newsletter sign-up, and the site-builder funnel. When enabled, the visitor's browser connects to Cloudflare. Turnstile processes connection, browser, and device-related signals — including the IP address, TLS fingerprint, user-agent header, sitekey, and associated origin — and evaluates technical browser and behavioral signals to distinguish people from bots. Cloudflare acts as our processor when it uses those signals to protect a Coloseos form, and separately as a controller when it uses them to improve Turnstile's bot-detection capabilities. Coloseos does not use Turnstile signals for advertising. When Turnstile is off, its challenge does not load and Coloseos sends no Turnstile provider request. See Cloudflare's Turnstile Privacy Addendum.
While your account is active, and for a reasonable period after closure to meet our legal and operational obligations. You can delete your account at any time.
We'll email you before material changes to this policy take effect. The "last updated" date above reflects the current version.