Privacy Policy
Last updated: 2026-08-08
1. Introduction
Trainomics ("we", "us", "our") operates the Trainomics platform (trainomics.app), a training and physiological testing platform for athletes, coaches, and physiotherapists. We are committed to protecting your privacy and processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection laws.
This Privacy Policy explains what data we collect, why we collect it, how we process it, and your rights regarding your personal data.
2. Data Controller
The data controller responsible for processing your personal data is:
TrainomicsEmail: privacy@trainomics.app
Website: trainomics.app
3. Data We Collect
3.1 Account Data
- Name, email address, and profile information
- Authentication credentials (managed via Supabase Auth)
- Role and subscription tier
- Business/organization affiliation
3.2 Health and Fitness Data
With your explicit consent, we collect and process health-related data including:
- Physiological test results (VO2max, lactate thresholds, heart rate zones)
- Training activities (duration, distance, heart rate, power, pace)
- Daily health metrics (resting heart rate, HRV, sleep, stress)
- Body composition data
- Injury and rehabilitation records
3.3 Data from Third-Party Integrations
When you connect external services, we receive data from those providers:
- Garmin — Activities, daily summaries, sleep, HRV, and heart rate data via the Garmin Health API
- Oura — Sleep, readiness, activity, HRV, and resting heart rate
- WHOOP — Recovery, sleep, cycle strain, workout summaries, HRV, and resting heart rate
- Apple Health — Read-only workouts, sleep, activity, body mass, and recovery data authorized on your iPhone
- Health Connect — Read-only workouts, sleep, activity, body mass, and recovery data authorized on your Android device, including data shared by Samsung Health
You can disconnect any integration at any time from your account settings, which stops further data collection from that service.
3.4 Usage Data
- Log data (IP address, browser type, pages visited)
- Feature usage patterns for service improvement
3.5 Safety and Moderation Data
When you report another user or message, we store the reporting and reported user identifiers, the selected reason, any details you provide, references to the relevant conversation or message, the report status, and review information. When you block a user, we store the identities of the two accounts and when the block was created.
4. How We Use Your Data
We process your personal data for the following purposes:
- Service delivery — Providing training programs, physiological test analysis, training zone calculation, and daily workout recommendations
- AI-powered features — Generating personalized training programs, analyzing performance trends, and providing coaching insights using AI models (data is sent to AI providers in anonymized form where possible)
- Integration sync — Importing and processing data from connected services (Garmin, WHOOP, Oura, Apple Health, and Health Connect) to provide a unified training view
- Communication — Sending essential service notifications, trial expiry warnings, and weekly training summaries
- Safety and moderation — Enforcing user blocks, investigating reports, preventing abuse, and documenting moderation decisions
- Service improvement — Analyzing aggregated, anonymized usage patterns to improve the platform
5. Legal Basis for Processing
Under the GDPR, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)) — Processing necessary to provide the services you have subscribed to
- Explicit consent (Art. 9(2)(a)) — Processing of health data, which requires your explicit consent
- Legitimate interest (Art. 6(1)(f)) — Service improvement and security monitoring
You may withdraw your consent at any time by contacting us or by disconnecting integrations and deleting your account.
6. Third-Party Services and Integrations
6.1 Garmin data processing
We use the Garmin Health API and Garmin Training API only after you connect your Garmin Connect account and authorize data sharing. Depending on the permissions and APIs you enable, we may collect and process Garmin activity summaries, activity details, heart-rate zones, heart-rate samples, laps, daily summaries, sleep data, resting heart rate, stress, heart rate variability, body composition data, deregistration notices, permission-change notices, Garmin user identifiers, and encrypted access tokens. When you choose to send a workout from Trainomics to Garmin Connect, we also process the workout name, schedule date, sport, steps, targets, and notes needed for that transfer.
We use Garmin data to show your training and recovery history, calculate training load and readiness, match Garmin activities to completed sessions, personalize workout and program recommendations, help coaches and physiotherapists support assigned athletes, and send workouts to Garmin Connect when requested. Garmin data may be combined with other training data in Trainomics to provide a unified view of your progress.
Garmin data is stored in our PostgreSQL database hosted by Supabase. Garmin webhook notifications may be processed by our application hosting and by a dedicated Garmin webhook service running on Google Cloud Run. Relevant Garmin-derived training context may be processed by third-party AI providers (Anthropic Claude, Google Gemini, and OpenAI) only when you use AI-powered features and that context is needed to generate the requested training insight, recommendation, or plan. We do not send your name or email address to AI providers as part of Garmin-derived AI context, and we do not sell Garmin data or use it to train or fine-tune general-purpose AI models.
Coaches, physiotherapists, or other team members only see Garmin data when they are authorized to access your athlete profile in Trainomics. Trainomics does not claim that any Garmin-derived analysis, recommendation, or AI-generated insight is endorsed by or affiliated with Garmin.
You can revoke Garmin access at any time in Trainomics settings or through Garmin Connect. Disconnecting Garmin deregisters the integration, removes the local Garmin token, and stops future Garmin collection and AI processing of newly received Garmin data. Historical Garmin-derived records may remain in your account history so your training logs, reports, and previously generated insights continue to work, unless you request deletion or delete your account.
Any future changes to this Garmin data-processing section will be submitted to the Garmin Connect Developer Program team for written approval before implementation.
6.2 AI Providers
We use third-party AI providers (Anthropic Claude, Google Gemini, OpenAI) to power AI-assisted training features. When using AI features, relevant training context is sent to these providers to generate responses. We do not send your name or email to AI providers. Each provider has their own privacy policy and data processing agreements in place.
6.3 Payment Processing
Payments are processed by Stripe. We do not store credit card numbers. Stripe's privacy policy governs payment data processing.
7. Data Storage and Security
Your data is stored in a PostgreSQL database hosted by Supabase with the following security measures:
- Integration tokens are encrypted at rest using AES-256
- All data transfers use TLS/HTTPS encryption
- Role-based access control ensures coaches only see their assigned athletes
- Multi-tenant architecture with strict data isolation between organizations
- Regular security monitoring and access logging
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Specifically:
- Account data — Retained until account deletion
- Training and health data — Retained until account deletion or upon request
- Integration tokens — Deleted when you disconnect an integration or delete your account
- Temporary OAuth state — Expires after 10 minutes and is automatically purged
- AI conversation history — Retained until account deletion
- User blocks — Retained until you unblock the user or either account is deleted
- Content reports — Retained while needed to investigate the report, enforce platform safety, and document moderation decisions; reports are also removed if the reporting or reported account is deleted
- Agent audit records — Retained for up to 7 years for security and accountability
- Completed privacy requests — Retained for 3 years to document how the request was handled
- Required financial records — Retained for up to 7 years, then automatically deleted
After account deletion, we remove personal data from active systems within 30 days, except where retention is required by law. Encrypted backup copies age out under the backup provider's retention schedule and are not restored for ordinary product use.
9. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Access — Request a copy of your personal data
- Rectification — Correct inaccurate personal data
- Erasure — Request deletion of your personal data ("right to be forgotten")
- Data portability — Receive your data in a structured, machine-readable format
- Restriction — Request restriction of processing
- Objection — Object to processing based on legitimate interest
- Withdraw consent — Withdraw consent for health data processing at any time
You can submit and track an access or deletion request in Privacy Settings or contact us at privacy@trainomics.app. We will respond within 30 days.
10. International Data Transfers
Your data may be processed by third-party services (AI providers, Supabase) located outside the EU/EEA. In such cases, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.
11. Children's Privacy
Trainomics is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
TrainomicsEmail: privacy@trainomics.app
Website: trainomics.app
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se.