Privacy policy
This policy is written by the team, not a lawyer. Questions: contact us directly.
What we collect
Account email, the workout profile answers from onboarding, health and activity data from Garmin or your phone's on-device health store, Google Calendar free/busy times, and the weekly plans generated for your account.
Health and fitness data
We pull heart rate, sleep, and activity data from Garmin, and free/busy calendar times from Google, solely to generate your own weekly workout plan. If you connect your phone's on-device health store instead of Garmin, the app reads steps, distance, active calories, heart rate, weight, exercise/workouts, sleep, and heart rate variability from Health Connect (Android) or Apple Health (iOS). This access is read-only — the app never writes data back to Health Connect or Apple Health. This data is never sold, never used for advertising, and never used to train generalized AI or machine learning models.
How we use your data
The data above is sent to Anthropic's Claude to generate your weekly plan. Approved workouts are pushed back to your own Garmin and Google Calendar accounts.
Limited Use
Our use of raw and derived user data received from Google Workspace APIs (including your Google Calendar free/busy times) adheres to the Google API Services User Data Policy, including the Limited Use requirements (view policy). The Claude/Anthropic call described above generates your weekly plan and nothing else — Google user data is not used to develop, improve, or train generalized AI or machine learning models.
Who we share it with
Supabase (database and login), Railway (hosting), Anthropic (generates your weekly plan), Resend (sends account emails). We don't sell your data.
How we protect your data
All traffic to and from the dashboard runs over HTTPS/TLS. Your Garmin and Google account tokens are encrypted (Fernet) by the application before they're written to the database, so they're never stored in readable form. The database itself is hosted on Supabase, which encrypts stored data at rest at the platform level — that's provided by the hosting platform, not something we implement ourselves. API keys, the encryption key, and database credentials are supplied only as environment variables on our host (Railway) and are never committed to the source code.
How long we keep it
Your data is kept as long as your account is active and is deleted when your account is deleted. Deletion removes it from our application database; copies already pushed to your own Garmin and Google accounts stay there under your control.
Deleting your data
Delete your account and all its data any time from Settings, or submit a request at /delete-account if you can't log in.
Contact
See "Deleting your data" above to submit a deletion request. Questions can be sent to the same address that sends your account emails.