⚠️ Draft scaffold — not legal text. This page is a placeholder that lists the sections and points real counsel needs to cover. Do not ship it as-is. Replace each section with lawyer-reviewed copy before any public launch or app-store submission.
Last updated: [DATE]
Why this policy exists separately
Training data like heart rate, HRV, sleep duration, and body composition is treated as a special category of personal data under GDPR Article 9. It also falls under the Android Health Connect disclosure requirements and Apple HealthKit app-store guidelines. We keep a dedicated policy so the handling is easy to read in one place.
What health data we process
Through your connected Garmin, Polar, or Strava account, and optionally through Apple Health or Android Health Connect:
- Heart rate during activities and at rest
- Heart-rate variability (HRV) where your device reports it
- Sleep duration and sleep-stage data where available
- Activity distance, pace, and elevation
- Perceived effort (RPE) you enter yourself
- Basic profile data (age, weight) you enter during setup
What we use it for — and nothing else
- Generating and adapting your training plan
- Calibrating your pace and heart-rate zones
- Showing you your training load, recovery trend, and progress
- Explaining why the plan changed (“Your HRV dropped, so we reduced the Tuesday session”)
We never use health data for advertising, sell it to third parties, share it with insurers, or train general-purpose models on it.
Where it lives
[TODO: list hosting region(s) and encryption details. Typical for EU-first products: AWS Frankfurt or OVHcloud, encrypted at rest with AES-256, encrypted in transit over TLS 1.2+.]
How long we keep it
Your training data stays on your account for as long as you have a subscription. If you cancel, it stays in read-only mode for 90 days in case you resubscribe. After 90 days we permanently delete it. You can also delete it yourself at any time from the app — that takes effect within 24 hours.
Your rights
You can export your full training history as CSV at any time from your account settings. You can request that we delete it sooner than the 90-day window. All GDPR rights apply.
Android Health Connect disclosure
[TODO: paste the standard Health Connect disclosure exactly as required by Google. Include the “TrainPlan will use this data solely to…” phrasing Google dictates.]
Apple HealthKit disclosure
[TODO: paste the HealthKit-specific privacy and purpose disclosure as required in the App Store submission.]
Data-breach notification
If your health data is compromised in a breach, we will notify you directly within 72 hours of becoming aware, per GDPR Article 33.
Questions
Email our data team at privacy@trainplan.app. Our DPO [TODO: if one has been appointed — not required below 250 employees unless core activity involves large-scale processing of special categories, which we do; appoint one] can be reached at the same address.