athletedata

How we protect your training and health data.

Controls

Reviewed September 29, 2026

Data and privacy

ControlStatus
  • Your data is never sold

    We never sell your data, share it for advertising, or use it to build advertising profiles.

  • Only the apps you connect

    We only read the apps and devices you connect, in the categories you approve on each app's own consent screen.

  • Nothing written back unless you ask

    We only send data to a connected app when you ask for it: a workout to your watch or training platform, an event to your calendar, or a line on your activity you can switch off.

  • Data deleted when you leave

    Deleting your account erases your data after a 7-day window in which you can change your mind: database records, uploaded files, analytics profile and payment customer record.

  • Access revoked at your apps

    Disconnecting an app, or deleting your account, revokes our access at that app wherever the app supports it.

  • Only anonymous facts survive deletion

    After deletion we keep a small record of business facts (such as the day you signed up) under a one-way code, with no name, email or health data.

  • A copy of your data on request

    Email privacy@athletedata.health and we send you a copy of your data. We answer every data request within 30 days.

AI and your data

ControlStatus
  • No training on your data

    We do not use your data to train or fine-tune AI models, and neither do the AI providers that generate your coaching. Some providers keep requests for a short time only to detect abuse, then delete them.

  • Only what a reply needs

    Each request sends the AI provider the relevant part of your data (profile, recent training, the conversation), not your whole account.

  • Routing limited to no-training hosts

    Where requests pass through a model router, our account only allows hosts that do not train on the data they receive.

  • Coach memory you can see and correct

    You can ask the coach what it remembers about you, and ask it to correct or forget anything.

Infrastructure security

ControlStatus
  • Data encrypted at rest

    Our database, its backups, and every file you upload are encrypted on disk.

  • Data encrypted in transit

    Every page and app connection uses HTTPS, and our database refuses unencrypted connections.

  • App credentials encrypted separately

    The credentials that connect your apps get a second layer of encryption with a key kept outside the database.

  • Secrets kept in a managed vault

    API keys and passwords our services use live in AWS Secrets Manager, never in code.

  • Database credentials rotated automatically

    The database administrator password is managed and rotated by AWS.

  • Backups and failover

    The database runs in two availability zones with automatic failover, and keeps 7 days of point-in-time backups.

  • Files never publicly reachable

    Uploaded documents sit in storage that blocks all public access.

Access control

ControlStatus
  • Admin access limited to named accounts

    Our internal admin tools only open for a short, named list of team accounts.

  • Internal tools cannot read credentials

    The tools our team uses to investigate a problem cannot read the credentials that connect your apps or the keys to your account.

  • Human coaches see only what you share

    If you join a coach's team, they see the training and recovery data you agree to share. They never see your conversations with the AI coach.

Product security

ControlStatus
  • Secure sign-in

    Sign-in runs through our authentication provider, with Google or a confirmed email address. We never store your password.

  • Deletion you control

    You can delete your account yourself from your dashboard at any time, with no need to contact us.

  • Vulnerability reporting

    Security reports go to privacy@athletedata.health, published in our security.txt.