Privacy Policy
Last updated: October 2026
1. What we collect
Account data: email, password hash, name, and role. We store login attempt timestamps and IP addresses for brute-force protection.
Athlete profile: FTP, max HR, weight, goals, weekly training hours, sports, injury history, training templates, and commute preferences.
Third-party data (with your consent):
- Strava — OAuth tokens (encrypted), cached activity data (distance, speed, power, heart rate, GPS routes, raw JSON payloads).
- Garmin Connect — email and password (encrypted), daily health snapshots (sleep score, HRV, resting HR, stress, body battery, steps), weigh-ins and smart-scale body composition (weight, body fat %, muscle and bone mass, body water, BMI, visceral fat, metabolic age).
AI prompts: All prompts sent to the AI provider and responses received are logged for quality and debugging purposes.
2. How we use your data
- Generate personalized training plans and weekly workouts.
- Analyze completed activities to give feedback and adjust future plans.
- Monitor app health via error tracking (Sentry) and performance analytics (Vercel Analytics, only on Vercel deployments).
- Enforce rate limits on AI generation to prevent abuse.
3. Data sharing
We do not sell your data. Data is shared only with the services you explicitly connect:
- Strava / Garmin — for syncing your activities and health data.
- Google Gemini — your athlete profile and recent activities are sent as context to generate training plans.
- Vercel / Sentry — anonymous error and performance data, only in production.
4. Data retention
- Account and profile data: retained until you delete your account.
- Strava activities: retained until account deletion or manual re-sync.
- Garmin health data: retained until account deletion. Each sync refreshes the last ~7 days of metrics; weigh-in and body-composition history is kept up to ~3 years back to power trend charts.
- AI logs: retained for 90 days, then purged.
- Login attempts: retained for 30 days.
5. Your rights (GDPR)
You have the right to access, correct, export, and delete your data. Use the Settings → Data & privacy panel to export or delete your account. For other requests, email us.
6. Security
Passwords are hashed with bcrypt. OAuth tokens and Garmin credentials are encrypted with AES-256-GCM. All database connections use TLS. We enforce rate limiting on authentication and AI endpoints.
7. Cookies & local storage
We store your theme preference and last sync timestamps in your browser's localStorage. No marketing or third-party tracking cookies are used. Vercel Analytics and Sentry load only in production and collect anonymous usage data.
8. Contact
For privacy questions or data requests, contact us through your account settings or the support channels listed on the site.