Legal
Privacy Policy
Last updated July 19, 2026
What we collect
When you create an account, we collect your email address. If you connect Strava, Wahoo, and/or Hammerhead, we receive your athlete/user ID and activity data (rides, runs, distance, elevation, heart rate, power, and similar metrics) from that service's API, with your authorization. If you connect RunGap instead, the same categories of activity data arrive differently: RunGap is a separate app you configure yourself to send us a workout file whenever you sync one, using a webhook address and passkey we generate for your account, see "Who we share it with" below for how that differs from an API connection. If you connect more than one and the same real-world workout is reported by each, we keep only one copy of it rather than storing it twice. We also store the goals and training plans you create within Training Signals.
Your Functional Threshold Power (FTP) is either a value you enter yourself in Settings or an estimate we compute from your own synced power-meter rides. We do not read it from your Strava athlete profile. You can enter your body weight directly in Settings; it is stored in kilograms internally and used only for performance calculations (watts per kilogram).
If you connect a recovery device or service (Oura, WHOOP, or Apple Health via the iOS app) we receive and store daily recovery summaries with your authorization: readiness/recovery scores, sleep scores and sleep duration, overnight heart-rate variability (HRV), and resting heart rate. We store daily summaries only, not raw sensor streams. For WHOOP we also import the workouts you record, sport, start and end time, strain, average and maximum heart rate, and distance where available, so your training history works even if WHOOP is your only tracker. Apple Health data is read on your device by our iOS app and sent to us as those same daily summaries; you control access in iOS Settings > Privacy & Security > Health, and disconnecting a recovery service in Connections deletes its stored recovery data (and, for WHOOP, its imported workouts) from our systems.
If you use the Athlete Memory or AI coaching features, we store the profile notes you or your AI coach write (injury history, equipment, preferences, training load feedback, and other notes) along with an append-only audit log recording every change (who made it and when). You can view and edit this data on your Profile page at any time.
How we use it
We use this data to calculate training load, fitness, and recovery metrics (including watts per kilogram when both FTP and body weight are set), generate training plans, and provide coaching advice. Some coaching messages are generated or rewritten by Anthropic's Claude API for eligible accounts. Anthropic acts as our subprocessor. It processes this data solely to return coaching text to you, on our behalf and under our contract, not for its own purposes. We send only derived training context (goals, fitness/fatigue metrics, FTP, power zones, body weight, athlete memory notes, daily recovery summaries such as readiness scores, sleep duration, HRV, and resting heart rate, and similar summaries), never your raw Strava, Wahoo, or Hammerhead activity feed, and, as a data-minimization measure, not your activity names/titles either. We do not use this data to train, fine-tune, or build AI models, and, under Anthropic's commercial terms, data submitted through our API integration is not used to train their models. We do not currently build searchable embeddings or vector indexes from your data; if that changes, we will update this policy and describe what is indexed and how it is deleted.
None of that happens until you say so. Before any of your training reaches Anthropic we show you what is sent, name who receives it, and ask. Saying no costs you the written coaching and nothing else: your plan, your sync, your charts and your records all keep working. You can change your answer either way at any time under "How your data is used" in Settings. Turning it off stops the next send rather than recalling what has already gone, and while it is off we generate no coaching text at all.
Who we share it with
We rely on a small set of subprocessors that handle data on our behalf under contract: Supabase to store account and training data, Anthropic to generate some coaching messages (see above), and Vercel to host the application. We source activity data from Strava, Wahoo, and/or Hammerhead under your authorization, which you can revoke at any time in that service's own account settings, or by disconnecting it from our Connections page. If you connect RunGap, activity data arrives because you configured RunGap yourself to send it to a webhook address we generate for your account, RunGap is not a subprocessor we hold a data-sharing agreement with, and we have no way to reach into RunGap or revoke its access from our side; that's controlled entirely within RunGap's own settings on your device. We do not sell your data, and we do not disclose your Strava, Wahoo, Hammerhead, or RunGap-sourced data to any party other than these subprocessors and you.
Cookies and analytics
We use a session cookie/local storage entry to keep you signed in -- this is required for the app to function and isn't optional. We use Vercel Web Analytics for aggregate traffic insights, which does not use cookies or collect personally identifiable information.
We also keep our own basic traffic counts, without cookies: the page path, the country/region/city your network resolves to, the host that linked you to us (the site name only -- never the full address, so we never see what you searched for), and, on blog posts, whether a reader scrolled far enough and stayed long enough to have read the piece. Each of these is stored against a one-way visitor code derived from your IP address and the current date -- we never store the IP itself, and because the code changes daily it stops being linkable to you tomorrow.
Your data, your control
You can disconnect Strava, Wahoo, Hammerhead, and/or RunGap from the Connections page, or delete all of your data at any time from Settings. For Strava, Wahoo, and Hammerhead, disconnecting revokes our access on that service's side and deletes the activities and FTP estimates synced from it. RunGap has no such access to revoke. We delete the activities and connection on our side, but you should also remove the webhook from RunGap's own settings so it stops trying to send workouts to a URL that no longer accepts them. Either way, this keeps your goals, training plans, and coaching history. Deleting your data removes those too, along with everything your coach worked out about you: its notes, what it remembers about your body and your training, and your whole conversation history. It also empties your profile of what you told us about yourself, including your FTP, your weight and weight history, your threshold pace, the sports you do and the days you can train, and it removes every connected source along with the credentials that let one push data to us. You are signed out when it finishes. Your login still works, and signing back in starts you over from setup. Your coach also keeps a change history, so you can see when it updated something it knows about you. The wording of each change is kept for 30 days and then dropped, leaving only the record that a change happened. Three things are kept on purpose. Billing records, because deleting them would strip the subscription you are still paying for and erase our record of a purchase you might later dispute. A small amount of cost-accounting and abuse-prevention logging, which holds identifiers and counts, never anything you wrote or anything the coach concluded. And the record that you accepted these terms, which is a version number and a date, kept because it exists to be produced later. Synced activity data from Strava, Wahoo, or Hammerhead is also automatically purged after 365 days even if you stay connected, consistent with Strava's API Agreement. RunGap-sourced activity data is not subject to this automatic purge, since RunGap can be used to import years of historical training history in one go and Strava's API Agreement doesn't apply to it. It's retained until you disconnect RunGap or delete your data.
Contact
Questions about this policy? Contact us at support@trainingsignals.cc.