TRAINABLE — PRIVACY POLICY Last updated: September 2026 Trainable ("the app", "we") is an iOS training app for endurance athletes. This policy explains what data we collect, why, and how it's handled. WHAT WE COLLECT - Account information: the email address you sign up with. You can also sign in with Google, in which case Google shares your email address and basic profile information with us - we never see or receive your Google password. You can instead choose "Continue without an account", which creates an anonymous account tied only to your device. - Activity data from Strava: once you connect your Strava account, we pull your completed activities (duration, distance, heart rate, power, cadence, GPS-derived speed/elevation, and per-second stream data) so we can compute training load and give you workout analysis. - Athlete-entered data: your primary sport, experience level, weekly hours available, preferred rest days, injuries or limitations, any upcoming event, and your FTP, threshold heart rate, max heart rate and resting heart rate. These are asked for during setup and can be changed at any time in Settings. They are used to calculate your training zones and to shape how your plan progresses. - Apple Health data: if you grant permission, we read your heart rate, resting heart rate, heart rate variability (HRV), VO2 max, active energy, sleep, and workouts from Apple Health. These are used to estimate your training zones, judge your daily readiness, and adjust your plan. We only ever read from Apple Health - we never write to it. You can decline any individual metric, or revoke access entirely, in the iOS Health app; the app continues to work without them, using whatever data it does have. Health data is never used for advertising and is never sold. - Data from other platforms you connect: if you connect Garmin, TrainingPeaks, or Intervals.icu, we access only what's needed for the features those integrations provide (for example: reading completed activities, or writing planned workouts to your calendar). Each of these is opt-in and can be disconnected at any time in Settings. - Trainable Sync (Garmin Connect IQ watch app): if you install this separate app on a Garmin device, here is exactly how it works. In the iOS app, Settings > Garmin generates a short pairing code and stores it against your account - this code is the only credential the watch app uses, there is no separate login. The watch app sends that code and your device's local weekday directly to our server (garmin-workout-sync) over HTTPS. The server looks up your account by that code and returns your planned workouts for the rest of the current week - each one's type, duration, and interval structure (warmup/work/recovery/cooldown steps and any power/heart rate targets) - as FIT files, which your Garmin device saves as workouts. This happens automatically in the background, roughly every 90 minutes, without you opening either app. Each check first asks whether your plan has changed since the last sync and downloads nothing if it hasn't. After a sync, the watch reports back one number - how many Trainable workouts it currently holds - so the iOS app can show you whether your workouts actually reached the device. You can stop all of this at any time by uninstalling the watch app or regenerating your pairing code. No other account data (email, activity history, health data, connected-platform tokens) is ever sent to or requested by the watch app, and the pairing code itself contains no personal information. You can invalidate a pairing code at any time by tapping "Regenerate Code" in Settings > Garmin, which immediately makes the old code stop working. HOW WE USE IT - To compute standard training-load metrics (CTL/ATL/TSB, TSS) from your activity history. - To generate a personalized weekly training plan and per-workout analysis, using Anthropic's Claude API and/or Groq's API depending on your settings. The data sent to these providers is your workout numbers and training context - not used by us to train any model. - To let you export or push structured workouts to a device or platform you've connected. WHERE IT'S STORED Your data is stored in a Supabase-hosted Postgres database, access- controlled so only your authenticated account can read or write your own data. THIRD PARTIES WE SHARE DATA WITH We only share data with services you've explicitly connected, and only for the purpose of the feature you're using: - Strava — to read your activity data (with your authorization). - Garmin, TrainingPeaks, Intervals.icu — only if and once you connect them, for reading activity/wellness data or writing planned workouts as described above. - The Trainable Sync Garmin Connect IQ app — communicates only with our own backend (garmin-workout-sync), not with Garmin's servers directly; Garmin's OS on your device receives the resulting workout file once downloaded. - Anthropic (Claude) and Groq — to generate AI training analysis and plans. We do not sell your data, and we do not share it with anyone beyond what's listed here. YOUR CONTROL OVER THIS DATA - You can disconnect any connected platform (Strava, Garmin, TrainingPeaks, Intervals.icu) at any time from Settings. - You can request deletion of your account and all associated data at any time from within the app (Settings > Delete Account), or by emailing us below. CHILDREN Trainable is not directed at, and should not be used by, children under 13. CHANGES TO THIS POLICY If this policy changes in a material way, we'll update the date at the top of this document. CONTACT matthewd7772@gmail.com