Privacy Policy
Last updated: July 31, 2026
Data We Collect
- Location Data. GPS coordinates during active ride recording. Used to map routes, calculate distance/speed, and provide navigation. Background location is used only during active recording sessions.
- Health & Fitness Data. Heart rate, workout history, and body metrics via Apple HealthKit. Used for training analytics (TSS, CTL/ATL), zone distribution, and workout summaries. This data stays on your device unless you enable Strava sync, cloud backup, or AI coaching (see below).
- Biometric Data. Face ID / Touch ID for app unlock. Biometric data is processed entirely on-device by Apple's Secure Enclave. We never access or store biometric templates.
- Account Information. Name and email from Sign In with Apple. Used to personalize your profile and sync data across devices via our cloud service.
- Workout & Training Data. Ride recordings, gym workout sessions, training plans, and gear information. Stored locally on your device and optionally synced to our cloud service for backup.
How We Use Your Data
- Training Analytics. Your ride and workout data is analyzed on-device to compute training load (TSS), fitness trends (CTL/ATL), and recovery recommendations.
- Cloud Backup. When signed in, your athlete profile is synced to Supabase (our cloud provider) for cross-device access. Activity data is stored locally with optional iCloud backup.
- Strava Integration. When you connect Strava, we exchange OAuth tokens to import/export activities. Your Strava credentials are stored securely in the iOS Keychain.
- AI Features. AI coaching is optional and requires your explicit consent before first use. You choose which AI provider answers — Google Gemini, Anthropic Claude, OpenAI or xAI Grok — in Settings → AI Provider, and only the provider you select receives anything. When you use it, the following is transmitted to that provider to generate responses: your coaching conversation, first name, training metrics (power, heart-rate averages, CTL/ATL/TSB, FTP), body stats, goals, and injury notes you share with the coach, and — if you use the meal scanner — photos of your food. GPS coordinates are never sent. If you do not enable AI features, nothing is ever sent to any AI provider.
Data Storage & Security
- Local Storage. All workout data is stored in your device's Documents directory with automatic backup files. Keychain is used for all authentication tokens and API keys.
- Cloud Storage. Athlete profiles are stored in Supabase with Row Level Security (RLS) — only you can access your data. All transmissions use TLS 1.3 encryption.
- No Selling of Data. We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes. Period.
Third-Party Services
- Strava. Activity import/export via their official API. Subject to Strava's own privacy policy.
- Supabase. Cloud database and authentication. Data is stored in AWS data centers with SOC 2 compliance.
- Apple HealthKit. Read/write health data per your explicit permission grants. Apple prohibits using HealthKit data for advertising.
- AI Providers (Google, Anthropic, OpenAI, xAI). Optional AI coaching, gated behind in-app consent. Requests go only to the single provider you select in Settings → AI Provider. Data sent there is handled under that company's API terms and privacy policy; we do not control their retention. Disable AI features at any time to stop all transmission.
Your Rights
- Access & Export. You can export all your data at any time from Settings → Data Backup.
- Deletion. Settings → Delete Account permanently removes your account, all cloud data, and your sign-in identity from our servers, and wipes local data. Uninstalling the app removes all local data.
- Opt-Out. All integrations (Strava, HealthKit, AI coaching, Cloud Sync) are opt-in. The app functions fully offline with local-only storage.
Contact
For privacy inquiries: privacy@tuckerpratt.com