athletedata
How we protect your training and health data.
Controls
Reviewed September 29, 2026Data and privacy
Your data is never sold
We never sell your data, share it for advertising, or use it to build advertising profiles.
Only the apps you connect
We only read the apps and devices you connect, in the categories you approve on each app's own consent screen.
Nothing written back unless you ask
We only send data to a connected app when you ask for it: a workout to your watch or training platform, an event to your calendar, or a line on your activity you can switch off.
Data deleted when you leave
Deleting your account erases your data after a 7-day window in which you can change your mind: database records, uploaded files, analytics profile and payment customer record.
Access revoked at your apps
Disconnecting an app, or deleting your account, revokes our access at that app wherever the app supports it.
Only anonymous facts survive deletion
After deletion we keep a small record of business facts (such as the day you signed up) under a one-way code, with no name, email or health data.
A copy of your data on request
Email privacy@athletedata.health and we send you a copy of your data. We answer every data request within 30 days.
AI and your data
No training on your data
We do not use your data to train or fine-tune AI models, and neither do the AI providers that generate your coaching. Some providers keep requests for a short time only to detect abuse, then delete them.
Only what a reply needs
Each request sends the AI provider the relevant part of your data (profile, recent training, the conversation), not your whole account.
Routing limited to no-training hosts
Where requests pass through a model router, our account only allows hosts that do not train on the data they receive.
Coach memory you can see and correct
You can ask the coach what it remembers about you, and ask it to correct or forget anything.
Infrastructure security
Data encrypted at rest
Our database, its backups, and every file you upload are encrypted on disk.
Data encrypted in transit
Every page and app connection uses HTTPS, and our database refuses unencrypted connections.
App credentials encrypted separately
The credentials that connect your apps get a second layer of encryption with a key kept outside the database.
Secrets kept in a managed vault
API keys and passwords our services use live in AWS Secrets Manager, never in code.
Database credentials rotated automatically
The database administrator password is managed and rotated by AWS.
Backups and failover
The database runs in two availability zones with automatic failover, and keeps 7 days of point-in-time backups.
Files never publicly reachable
Uploaded documents sit in storage that blocks all public access.
Access control
Admin access limited to named accounts
Our internal admin tools only open for a short, named list of team accounts.
Internal tools cannot read credentials
The tools our team uses to investigate a problem cannot read the credentials that connect your apps or the keys to your account.
Human coaches see only what you share
If you join a coach's team, they see the training and recovery data you agree to share. They never see your conversations with the AI coach.
Product security
Secure sign-in
Sign-in runs through our authentication provider, with Google or a confirmed email address. We never store your password.
Deletion you control
You can delete your account yourself from your dashboard at any time, with no need to contact us.
Vulnerability reporting
Security reports go to privacy@athletedata.health, published in our security.txt.