You are asking your clients to trust a phone call that carries your name. That only holds up if what sits behind it is handled properly.
This page is the plain version, including the parts that do not flatter us. If anything here turns out to be out of date, treat it as a bug and tell us.
Our server is in Sydney, Australia. It is a private server we run ourselves, not shared hosting, and your account data sits on it.
That is only half an answer, so here is the other half. Placing a phone call, sending a text, turning a call into a summary and emailing you all need outside providers, and most of those providers are in the United States. Your clients' details pass through them to get that work done. They are listed further down rather than left for you to guess at.
Everything personal your account holds is encrypted where it is stored:
The method is AES-256-GCM, applied field by field in the database and file by file on disk.
The part that matters more than the algorithm: the keys are not kept on that server. Each key is split in two, and one half lives on a machine somewhere else entirely. The server rebuilds them in memory when it starts, and never writes them down. We tested that by restarting the server with no copy of the keys on it at all, and watching it come back on its own.
So a copy of our server's disk is ciphertext with nothing on it that opens it.
Running the calls means handing parts of your clients' data to other companies. This is all of them.
| Provider | What it does | What it receives |
|---|---|---|
| Voice provider | Places the check-in call | The client's phone number, the call audio, the transcript |
| Telnyx, Twilio | Sends and receives texts, carries the calls | The client's mobile number and the message |
| Anthropic | Turns a call into your summary, flags anything urgent | The text of the transcript |
| Postmark | Sends email | Email addresses and message content |
| Zoom | Only if you connect it: brings in session recordings | The recordings you choose to pull in |
| Stripe | Your billing | Your card and company details, never client data |
Recordings of your check-in calls stay with the voice provider. We hold the transcript and a playback link, not the audio file.
When you upload a recording yourself, to build a client or a program from a session, that one is transcribed on our own machine and the audio is not sent anywhere.
There is no third-party analytics or tracking inside the app. No Google Analytics, no session recording, no advertising pixels once you are signed in. Our error monitoring is our own and stays on our server.
You should hear this part from us rather than find it out later.
You can download a complete copy of your account any time from Settings: your clients, your programs, the transcript of every call and your billing history. You do not have to ask us, and you do not have to be leaving.
We do not sell personal information, and one coach's client information is never shown to another coach. The full detail is in our privacy policy and terms.
If you think you have found a security issue, email privacy@shoup.ai and say what you found and how to reproduce it. We will confirm we have it, and we will not come after anyone who reports something in good faith and does not go digging through other people's data to prove it.
Last reviewed 11 August 2026
Ask before you sign up, not after. If the answer is unflattering you will get it anyway.
Request access