AthleteOS Legal center
Terms Privacy Open app

Privacy Policy

How AthleteOS handles your data.

AthleteOS uses your account, training, recovery, sleep, calendar, and integration data to run the product, generate coaching context, protect accounts, and help you make better training decisions.

Effective June 27, 2026 Includes OAuth integrations Includes AI features
01 Connected data is opt-in.

WHOOP and Strava connect only after approval and may be limited during the private alpha. Manual entry and supported file imports remain available.

02 Tokens are protected.

Integration tokens are encrypted before storage and are not shown back to the browser.

03 You can delete your account.

Account deletion removes your active AthleteOS account data from the database.

Scope Data collected Integrations Use AI Sharing Storage Choices Retention Rights

1. Scope

This Privacy Policy applies to AthleteOS websites, app pages, accounts, dashboards, integrations, assistant features, team and coach features, exports, and related services.

This Policy does not control the privacy practices of third-party providers you connect or services that help operate AthleteOS, such as connected fitness platforms, calendar providers, hosting providers, database providers, email delivery providers, analytics providers, AI providers, or other configured providers. Their own policies apply to their services.

2. Information AthleteOS Collects

  • Account data: name, email address, password hash, session records, login status, and account settings.
  • Profile data: sport, training preferences, goals, units, role, team setup, and onboarding answers.
  • Training data: sessions, planned sessions, workouts, duration, distance, pace, load, RPE, notes, tags, and exports.
  • Recovery and health-related data: sleep, readiness, recovery, HRV, resting heart rate, strain, heart rate, steps, calories, body metrics, and wellness check-ins.
  • Calendar data: planned and completed sessions published or read through connected calendar features.
  • Team data: team membership, coach notes, athlete summaries, interventions, and coach-facing views.
  • AI interaction data: prompts, generated responses, structured context, citations, action buttons, and assistant metadata.
  • Technical and analytics data: cookies, CSRF tokens, security events, error details, request metadata, browser state, diagnostic logs, product usage events, and performance signals.

3. Connected Sources

When you connect a provider, AthleteOS receives data through that provider's API according to the scopes you approve. During the private alpha, WHOOP and Strava may be available on a limited basis. Manual logging, Garmin CSV/TCX/GPX activity import, and Apple Health CSV import can be used without an automatic connection. Google Health can be connected for Fitbit and Pixel Watch data when it is enabled for your account. Oura and Wahoo can be connected when a working connection is explicitly shown in your account. Google Calendar can be connected separately for schedule context and training-plan sync.

AthleteOS may store imported provider data, transformed metrics, sync metadata, and encrypted access or refresh tokens needed to keep the integration working. You can disconnect supported providers in the app.

  • WHOOP may provide recovery, sleep, strain, workout, body, profile, HRV, and heart-rate-related data.
  • Strava may provide activity, distance, pace, heart-rate, and effort data for the authorized user.
  • Google Health may provide Fitbit or Pixel Watch exercise, sleep, heart-rate, HRV, VO2 max, and step data for the authorized user.
  • Google Calendar provides anonymous busy-time ranges from your primary calendar for conflict detection. AthleteOS does not request or store the titles, descriptions, locations, attendees, or links of personal calendar events. AthleteOS creates and manages only a separate calendar named “AthleteOS Training” for planned-session sync; it does not edit events in your primary calendar.
  • Garmin manual imports may provide activity name and type, start time, duration, distance, heart rate, elevation, calories, and training load where present in the file.
  • Manual wearable summaries may include Body Battery, sleep score, HRV, resting heart rate, stress, training readiness, acute load, load ratio, and recovery time.
  • Other providers remain unavailable unless the app explicitly shows a working connected state.

Uploaded Garmin and health-export files are parsed for the requested import and are not intentionally retained as permanent files. AthleteOS stores the normalized activities, metrics, import outcome, and duplicate-detection identifiers needed to operate your account. Malformed rows may be recorded as non-sensitive technical errors.

4. How AthleteOS Uses Information

  • Authenticate users and protect accounts.
  • Operate dashboards, logs, analytics, reviews, calendar tools, and coach/team views.
  • Sync connected data and merge duplicate workouts from multiple providers.
  • Generate readiness, recovery, sleep, strain, load, and trend summaries.
  • Send password reset or account-related emails through the configured email provider.
  • Generate AI-assisted answers and training decision support.
  • Measure product usage, onboarding progress, feature adoption, and performance with privacy-conscious analytics.
  • Debug, secure, monitor, and improve the service.
  • Comply with legal obligations and enforce the Terms.

5. AI Processing

Ask AthleteOS and coach copilot features may send your prompt and selected structured AthleteOS context to a configured AI provider. Context can include recent sessions, metrics, sleep, recovery, wellness, planned-session or calendar context when available, team context where applicable, and integration status needed to answer your question.

AthleteOS tries to send relevant context rather than unnecessary raw account data. Do not enter sensitive information into the assistant unless you want it processed for an answer.

6. How Information Is Shared

AthleteOS may share information with:

  • service providers that host, store, email, secure, monitor, or operate AthleteOS
  • AI providers used to generate assistant and copilot responses
  • connected providers as part of OAuth, token refresh, sync, and revocation workflows
  • authorized coaches, athletes, team owners, or team members when team features make data visible
  • legal, safety, or security recipients where required by law or needed to protect rights and service integrity

7. Hosting, Storage, and Security

AthleteOS uses cloud services to operate the production product, including app hosting, database storage, account email delivery, product analytics, error monitoring, and AI assistant processing. Provider availability can change as AthleteOS evolves.

AthleteOS uses reasonable safeguards such as HTTPS, secure cookies in production, CSRF protections, password hashing, encrypted integration tokens, and access controls. No system can guarantee perfect security.

8. Cookies and Local Storage

AthleteOS uses cookies and browser storage for login sessions, session hints, CSRF protection, preferences, onboarding state, product tour state, analytics, and app functionality. Blocking these may break login or app features.

9. Your Choices

  • Disconnect an integration to stop future sync for that provider.
  • Delete sessions, logs, or settings where the app supports it.
  • Delete your account from settings where available.
  • Revoke OAuth access from the provider's own account settings if you want to cut provider-side access too.
  • Use export tools to download certain data before deletion.

10. Retention and Deletion

AthleteOS keeps data while your account is active and as needed to operate the service. Account deletion removes active account data from the production database, including sessions, check-ins, recommendations, cached calendar events, alpha feedback, waitlist requests, settings, integrations, team membership, and saved app data. Deleting an AthleteOS account does not automatically delete the separate AthleteOS Training calendar from your Google account. Limited logs, backups, or records may be kept temporarily where needed for security, fraud prevention, legal compliance, or dispute handling.

11. Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, or receive a portable copy of certain information. AthleteOS may need to verify your identity before completing a request.

12. Children's Privacy

AthleteOS is intended for adults 18 and older unless a separate team, school, club, guardian, or organization arrangement supports supervised use. If you believe a child provided information improperly, contact AthleteOS at support@athleteos.health.

13. International Processing

Information may be processed in countries other than where you live. Where required, AthleteOS takes steps intended to provide appropriate protection for international processing.

14. Changes to This Policy

AthleteOS may update this Privacy Policy as the service, providers, or legal requirements change. The effective date will be updated when the Policy changes.

15. Contact

For privacy questions, account deletion help, or data requests, contact support@athleteos.health. For product feedback or bug reports, contact feedback@athleteos.health.