Privacy Policy
Last updated: 2026-09-10
Trainingload.ai helps you understand training load, review completed workouts, and manage training plans. Some features need health, fitness, or location data. We treat that information as sensitive and design the Service around data minimization, clear choices, and user control.
Privacy at a glance
- We do not sell personal data and do not use health, fitness, location, or AI conversation data for third-party advertising.
- Connecting fitness platforms, syncing HealthKit, using precise location, and enabling AI features are optional and controlled separately.
- You can export eligible data, disconnect providers, withdraw AI permission, delete Coach conversations and activities, or delete your account.
1. Who we are and what this policy covers
Trainingload.ai is operated by the developer identified on the app store or distribution channel through which you obtained the Service ("Trainingload.ai", "we", "our", or "us"). This Policy applies to our mobile apps, website, web app, Apple Watch experience, APIs, support, and related services. "Personal data" means information that identifies you or can reasonably be linked to you. This Policy does not replace the privacy notices of services you choose to connect.
2. Data we collect
The data we collect depends on the features you choose to use. It may include:
- Account and profile data: name, email address, profile image, language, time zone, account identifiers, sign-in provider identifiers, and a securely hashed password when password sign-in is used.
- Training and activity data: workout type, date and time, duration, distance, route and GPS coordinates, elevation, pace, speed, heart rate, power, cadence, calories, laps, training load, performance estimates, perceived exertion, and imported or generated workout files.
- Health, wellness, and body data: data you enter or authorize from HealthKit or connected services, such as body mass, resting heart rate, heart-rate variability where available, sleep, steps, active energy, recovery trends, VO2 max, thresholds, zones, goals, competitions, and plan history.
- Content and communications: Coach prompts, voice transcripts you choose to submit, AI responses, reviews and plans, notes, support messages, feedback, and files you upload.
- Connection and transaction data: connected-provider account IDs, authorization tokens, granted scopes, sync settings and status, product and subscription status, purchase and transaction identifiers, and billing support records. We do not receive or store your full payment-card number.
- Device, location, and usage data: IP address, device and browser type, operating system, app version, language, time zone, cookie or local-storage identifiers, screens and features used, access times, crash and diagnostic metadata, and precise location when you permit route recording.
3. Where data comes from
We collect personal data from the following sources:
- Directly from you when you create an account, complete your profile, upload a file, record a workout, write or dictate a Coach message, configure a plan, make a purchase, or contact support.
- From your device when you grant access to HealthKit, location, microphone, speech recognition, or other operating-system capabilities. Apple Speech Recognition may process microphone audio to produce a transcript; Trainingload.ai sends the transcript only after you choose to submit it and does not store the raw Coach recording.
- From services you connect, including Apple, Google, GitHub, Garmin, COROS, Intervals.icu, Strava, Polar, Wahoo, and Suunto, according to the permissions and sync directions you select.
- Automatically through essential service logs and, when enabled, privacy-limited analytics and diagnostics.
4. How we use data
We use personal data only for the purposes described below:
- Create and secure your account, authenticate you, remember settings, and provide support.
- Import, record, store, export, and synchronize workouts and health data at your direction.
- Calculate training load, zones, trends, performance estimates, recovery context, and plan-versus-completed comparisons.
- Provide training plans, Coach conversations, activity reviews, and user-confirmed plan adjustments.
- Process subscriptions and purchases, restore entitlements, send service messages, and maintain transaction records.
- Detect abuse, investigate errors, protect the Service, and improve reliability and product quality using minimized, aggregated, or de-identified data where practical.
5. HealthKit, location, and connected services
These integrations are optional. We request access when you choose the related feature and use the data only within the scope described to you.
- HealthKit: the iOS app may request read access to workouts and workout routes, heart rate, resting heart rate, active energy, steps, walking/running and cycling distance, running speed, and running stride length. Authorized samples and derived summaries may sync to your Trainingload.ai account so they are available across your devices.
- Precise location: the mobile app uses location to record outdoor routes, measure distance, and perform pre-start checks. For activity weather, we may send Apple WeatherKit the activity's approximate midpoint coordinate and time rather than the complete route.
- Fitness platforms: depending on the provider and your settings, we may import or export activities, planned workouts, wellness summaries, sport settings, and the identifiers needed to maintain synchronization.
- Authentication and connection credentials are used to sign you in or perform the synchronization you requested. We request the minimum practical scopes and do not use imported fitness data for advertising profiles.
- You may revoke device permission in system settings or disconnect a provider in Trainingload.ai. This stops new collection or synchronization from that source, but does not automatically delete data already imported into your account.
HealthKit data is used for health and fitness functionality and is not used for advertising, data brokerage, or sale. Trainingload.ai is not a healthcare provider, and the Service is not a medical device.
6. AI Coach and third-party AI
AI features are optional. Before any AI request is sent, the app presents a separate disclosure and asks for your explicit permission.
- Recipient: AI requests are sent to DeepSeek, operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. DeepSeek states that data it receives may be processed and stored in mainland China.
- Data sent: your submitted prompt or speech transcript and only the training context relevant to the requested feature. This may include sport, duration, distance and elevation derived from a route, aggregate heart-rate and zone data, pace, power, cadence, load, recovery trends, goals, plans, and relevant profile settings.
- Data not attached by Trainingload.ai: your name, email address, account ID, complete GPS track, and raw HealthKit samples. Your own prompt can still contain identifying or sensitive information, so do not include information that is unnecessary for the request.
- Purpose and provider use: data is sent to generate the Coach reply, plan, adjustment, or review you request. DeepSeek's current public terms state that, after secure encryption and strict irreversible de-identification, it may use inputs and outputs to a minimal extent to provide, maintain, operate, develop, or improve its services. We do not claim that DeepSeek provides zero retention or zero training.
- Storage: Trainingload.ai stores submitted prompts, transcripts, generated replies, plans, and reviews in your account to provide the feature and history. Coach conversations remain until you delete the conversation or account; reviews and plans remain with the related record until that record or account is deleted, subject to legal retention requirements.
- Control: you may decline AI and continue using non-AI features. You can withdraw permission in Mobile Me > Privacy & AI or Web Account Settings > Privacy & AI; this blocks new AI requests and automated reviews but does not delete existing results. A provider or material disclosure change requires permission again.
- Safeguards and limits: requests use encrypted transport, direct account identifiers are removed from generated training context, and AI content is not copied to a separate AI observability provider. AI output can be inaccurate and is for informational and training-support purposes, not diagnosis or medical advice.
For a provider-side deletion request concerning an AI request, contact support@trainingload.ai. We will assess and route applicable requests according to the provider's process and applicable law.
7. When we share data
We share personal data only as needed for the Service, when you direct us to, or when law requires it. Recipients may include:
- Infrastructure and storage providers, including Cloudflare R2 when configured, and database, cache, hosting, content-delivery, and security providers that operate the Service.
- Authentication and connected-service providers, including Apple, Google, GitHub, Garmin, COROS, Intervals.icu, Strava, Polar, Wahoo, and Suunto, when you sign in, connect, import, export, or disconnect.
- Billing providers, including Apple and RevenueCat for App Store purchases and supported web billing providers such as Creem or Waffo. They receive account, product, subscription, and transaction information needed to process and reconcile purchases.
- Analytics and reliability providers, including PostHog, Google Analytics, and Sentry when enabled. We configure these services to limit collection and do not intentionally send workout content, precise routes, HealthKit samples, or AI prompts and responses as analytics events.
- Apple WeatherKit for activity weather context, Apple Speech Recognition for optional dictation, email delivery providers for account and support messages, and DeepSeek for AI requests after permission.
- Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, resolve disputes, or complete a merger, financing, acquisition, or sale of assets subject to appropriate protections.
We do not sell personal data. We do not share health, fitness, location, or AI conversation data with data brokers or unrelated third parties for their advertising. We require and confirm that processors receiving user data provide the same or equivalent protection described in this Policy and required by applicable law; if that protection cannot be maintained, we will stop the affected transfer.
8. Cookies, analytics, and diagnostics
Our website and apps use local storage, cookies, and limited analytics or diagnostics to operate and understand the Service.
- Essential storage keeps you signed in, remembers settings, protects sessions, and supports requested functionality.
- PostHog and Google Analytics may receive events such as page or screen views, feature interactions, app version, platform, locale, time zone, and an account or device identifier when enabled.
- Mobile analytics disables session replay and automatic remote feature collection, disables IP-based geolocation in PostHog, and filters property names associated with prompts, messages, precise coordinates, health metrics, activity IDs, and similar sensitive content.
- Sentry may receive crash, request, device, network, and user or session metadata needed to diagnose failures on affected web properties. AI prompt and response content is not intentionally included.
- You can use browser, device, and available in-product controls to limit non-essential storage or analytics. Where applicable law requires opt-in consent, non-essential technologies should be activated only after that consent.
9. How long we keep data
We keep personal data only as long as reasonably necessary for the purpose collected, taking account of the data's nature, sensitivity, legal requirements, and whether the purpose can be achieved another way.
- Account, profile, training, HealthKit, location, plan, and imported data generally remain while your account is active or until you delete the relevant item.
- Coach conversations remain until you delete the conversation or account. Withdrawing AI permission stops new transfers but does not automatically erase existing conversations, plans, or reviews.
- Temporary local processing copies used during cloud-object-storage uploads are scheduled for deletion after 24 hours; retained source files and derived records otherwise follow the related activity or account.
- An in-app account deletion request blocks account access immediately. Automated deletion normally completes within 24 hours and may take up to 7 days. Connected credentials are revoked or cleared, stored files are deleted, and account-linked database records are purged.
- We may retain limited transaction, fraud-prevention, security, dispute, or legal records for the period required by law or reasonably necessary to establish or defend legal claims. Where practical, these records are separated from the deleted account and pseudonymized or de-identified.
10. How we protect data
We use technical and organizational measures designed to protect personal data. No system can guarantee absolute security.
- Encrypted transport for network requests and restricted access to production systems.
- Data minimization, permission scoping, deletion workflows, and separation of public and private storage.
- Secure password hashing and protection of authentication and integration credentials appropriate to their use.
- Monitoring, rate limits, audit records, and incident investigation procedures intended to detect abuse and operational failures.
11. International processing and transfers
Trainingload.ai is offered globally, and we and our providers may process data outside your country. Privacy laws in those locations may differ from those where you live.
- Depending on deployment and provider settings, infrastructure, analytics, diagnostics, billing, and connected-service data may be processed in the United States and other countries where those providers operate.
- DeepSeek states that AI request data may be processed and stored in mainland China. This location is disclosed again before you enable AI.
- Where applicable law requires it, we use recognized safeguards for international transfers, such as contractual protections, data minimization, encryption, and transfer assessments, and honor applicable rights regarding those transfers.
12. Legal bases for processing
Where laws such as the GDPR or UK GDPR apply, our legal bases depend on the feature and purpose:
- Contract: to create your account and deliver the training, synchronization, support, and billing functions you request.
- Consent: for optional permissions and processing such as connected-provider access, HealthKit, precise location, microphone and speech recognition, third-party AI sharing, and non-essential analytics where required.
- Legitimate interests: to secure, debug, and improve the Service, prevent abuse, and understand minimized usage patterns, after balancing those interests against your rights.
- Legal obligation and legal claims: to comply with tax, accounting, consumer-protection, law-enforcement, and other valid legal requirements or to establish, exercise, or defend claims.
13. Your choices and privacy rights
Depending on where you live, you may have some or all of the following rights. We may need to verify your identity before completing a request.
- Access personal data we hold about you and obtain information about how it is used and shared.
- Correct inaccurate account or profile data.
- Export eligible account and activity data in a portable format.
- Delete an activity, Coach conversation, connected service, or your account, subject to limited legal exceptions.
- Withdraw consent, object to or restrict certain processing, and opt out of sale, targeted advertising, or qualifying profiling. We do not sell personal data or use it for decisions with legal or similarly significant effects.
- Complain to your local data-protection authority. You will not be discriminated against for exercising a privacy right.
14. Children's privacy
The Service is not directed to children under 13 or a higher minimum age required by local law, and we do not knowingly collect their personal data without valid authorization. If you believe a child has provided data improperly, contact us and we will investigate and delete it where appropriate.
15. Changes to this policy
We may update this Policy when our product, providers, or legal obligations change. We will update the date above and provide additional notice or request renewed permission when a change is material and applicable law or platform rules require it.
16. Third-party notices
The providers below control their own services and publish separate privacy notices. Their policies apply when you interact directly with them. Our responsibility for processors acting on our instructions remains subject to applicable law and our agreements.
17. Contact us
For privacy questions, rights requests, or complaints, contact support@trainingload.ai. Please include your account email and the request type, but do not send passwords, authentication tokens, raw health files, or other unnecessary sensitive information by email.