Privacy Policy
Athlea processes health data — heart rate, HRV, sleep, body weight, injuries, food and recovery signals. Under UK data protection law that is one of the most tightly protected categories of personal data there is, and it deserves a policy that says plainly what happens to it.
This policy covers the athlea.ai website and the Athlea apps. Where something only applies once a feature has actually launched, we say so rather than describing a product that does not exist yet.
Who we are
Athlea Ltd (“Athlea”, “we”, “us”) is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are answerable for it.
Our representative in the European Union
Athlea Ltd is established in the United Kingdom. Because we offer our services to people in the European Economic Area, we have designated a representative in the European Union under Article 27 of the EU GDPR. You can contact our representative about anything to do with our processing of your personal data, in addition to contacting us directly.
Contacting our representative has the same effect as contacting us. You can also complain to the data protection supervisory authority in your own country.
What this policy covers
- The website at athlea.ai — the marketing pages, the waitlist and enquiry forms, and the website assistant.
- The Athlea apps — the iOS app and the web app at app.athlea.ai, including everything you connect to them.
It does not cover other companies’ services. If you connect Apple Health or Garmin Connect, or pay through Stripe, those companies have their own privacy policies covering what they do with your data on their side.
The data we collect
On the website
- Your email address and your explicit confirmation that we may contact you, when you join the waitlist.
- Your email address, sport, role and organisation size, when you use the professional enquiry form.
- Whatever you type into the website assistant, and the reply it generates. Please do not put health details or anything sensitive into it — it is a sales and information tool, not a clinical one.
- Technical data needed to run the site and stop abuse: your IP address and browser user agent. We do not store either in the clear against a waitlist entry — both are hashed with a secret salt before they are recorded, so they can be used to spot repeat abuse but not to look you up.
In the apps
- Account data — name, email address, password credentials, and your subscription status.
- Profile and training data — sport, experience, goals, training history, sessions completed, and self-reported benchmarks such as an FTP band or a recent race time.
- Health data — heart rate, heart rate variability, resting heart rate, sleep, training load and recovery signals, body weight and composition, food and nutrition logs, supplements you look up, injuries, symptoms and pain reports, and menstrual cycle data where you choose to provide it.
- Data from devices and services you connect — Apple Health, Garmin Connect, and Bluetooth sensors such as heart rate straps, power meters and trainers.
- Usage and diagnostic data — logs of requests, errors and crashes, used to keep the service working.
- Payment data — once subscriptions go live, payments will be processed by Stripe. Stripe handles card details directly. We receive confirmation of payment, the last four digits, and billing country, and never see or store a full card number.
Health data and explicit consent
Heart rate, HRV, sleep, weight, injuries, nutrition and menstrual cycle data are all “special category” data under Article 9 of the UK GDPR. We are only allowed to process it if one of a short list of conditions applies. The condition we rely on is your explicit consent (Article 9(2)(a)), given separately from agreeing to the terms.
You are asked to opt in specifically, before any health data is connected or entered. The request is separate from account creation and separate from accepting the terms. You can withdraw it at any time, in the app or by emailing us, and withdrawing is as easy as giving it.
If you withdraw consent, the features that depend on health data stop working — there is no adaptive coaching without training and recovery data. Withdrawing does not make past processing unlawful, but it does mean we stop, and you can ask us to delete what we hold.
We do not use your health data for advertising, we do not sell it, and we do not share it with advertisers, data brokers or insurers. That is a firm commitment, and for Apple Health data it is also a contractual obligation we owe Apple.
Why we are allowed to use it
Apple Health and HealthKit
If you connect Apple Health, the Athlea iOS app reads only the data types you approve in the iOS permission screen. You can see and change those permissions at any time in Settings → Privacy & Security → Health → Athlea, and you can revoke them all without deleting your account.
Apple imposes specific conditions on apps that read HealthKit data. We commit to all of them:
- HealthKit data is used only to provide health and fitness features to you — never for advertising, marketing, or any use unrelated to the coaching you asked for.
- HealthKit data is never sold, rented, or disclosed to data brokers, advertisers, or information resellers.
- HealthKit data is not disclosed to any third party without your explicit consent, and then only to deliver a feature to you.
- HealthKit data is not stored in iCloud, and is not used for any research without your separate, informed, opt-in consent.
- Disconnecting Apple Health stops further reads immediately. You can ask us to delete data already synced at any time, and we delete it within 30 days of the request.
Garmin Connect
This section describes specifically how data from your Garmin device and Garmin Connect account is collected, used, processed and stored, and who else touches it. It exists as a standalone section so it can be linked to directly.
What we collect from Garmin
Connecting Garmin authorises Athlea, through Garmin’s OAuth flow, to pull your activity and wellness data — workouts and their routes, heart rate, heart-rate variability, resting heart rate, sleep, and daily activity summaries. We request only the scopes the product needs, and the connection refreshes periodically in the background so your plan stays current without you having to export anything. We never receive your Garmin password.
What we use it for
Garmin data is used to build and adapt your training, nutrition and recovery guidance — reading your load, readiness and sleep so a plan can be adjusted to the athlete you actually are on a given day — and to show you your own history inside the app. It is used for nothing else. We do not use it for advertising, we do not profile you for marketing, and we do not sell it.
Who processes it
To generate coaching guidance, the relevant parts of your Garmin data are sent to our enterprise large-language-model sub-processor, Microsoft Azure OpenAI, running inside Athlea’s own Azure tenant under a data processing agreement. Under that agreement your data is not used to train or fine-tune any model and is not made available to other customers. Microsoft may retain prompts and outputs for up to 30 days solely for abuse monitoring, after which they are deleted; we are working to have this retention disabled entirely for our production systems.
Beyond that, Garmin data is handled only by the infrastructure processors listed in Who we share data with — hosting, database and storage providers acting on our instructions under contract. It is not sold, not shared for any third party’s own purposes, not passed to data brokers, and not disclosed for advertising.
Where it is stored, and for how long
Garmin data is stored in our production database on Microsoft Azure, encrypted in transit with TLS and encrypted at rest by the platform using AES-256. We keep it for as long as your Athlea account is active and you remain connected to Garmin. If you close your account, or disconnect Garmin, we delete it within 30 days.
You can disconnect from inside the Athlea app, or revoke Athlea’s access from your Garmin Connect account settings. Revoking at Garmin stops the sync at source. Garmin data already synced is deleted within 30 days of disconnection. You can also ask us to delete it at any time — see Your rights.
Garmin also imposes contractual conditions on developers using its API — including limits on how its data may be displayed, combined and retained. We comply with the Garmin Developer Program terms in force for our integration.
AI and automated decisions
Athlea generates training and nutrition guidance using large language models. To do that, relevant parts of your training and health data are sent to a model provider acting as our processor, under a contract that restricts what they may do with it.
- We do not permit our model providers to use your data to train their general-purpose models.
- No decision that produces a legal or similarly significant effect on you is made solely by automated means, so Article 22 of the UK GDPR is not engaged. Coaching output is a recommendation you are free to ignore.
- You can always reach a person. Email privacy@athlea.ai and a human will read it.
What the models can and cannot do, and where AI-generated imagery appears on this site, is set out in the AI Disclosure.
Who we share data with
We use a small number of service providers to run Athlea. They process data on our instructions under written contracts, and cannot use it for their own purposes. We do not sell personal data.
We may also disclose data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case this policy travels with the data.
Where your data goes
Several of the providers above are US companies or operate globally, so some data is likely to be processed outside the UK. Where that happens, transfers must be covered by an appropriate safeguard — an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement, or on the UK Addendum to the EU Standard Contractual Clauses, with each processor. You can ask us for a copy of the safeguard that applies to a particular transfer by writing to privacy@athlea.ai.
This website is served from Microsoft and Vercel infrastructure in the European Economic Area, and our production database and model processing run in Microsoft Azure.
How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, then delete it. Where a fixed period is not sensible, the criteria we use are set out below.
Your rights
Under UK data protection law you can ask us to do all of the following, free of charge. We will respond within one month.
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted.
- Restriction — have us pause processing while a dispute is sorted out.
- Portability — receive the data you gave us in a machine-readable format, or have it sent to another service.
- Objection — object to processing we base on legitimate interests, and to direct marketing at any time.
- Withdraw consent — including consent to process health data, at any time.
Email privacy@athlea.ai to exercise any of these. If you are not happy with how we handle it, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.
Deleting your account
You can delete your Athlea account and the data attached to it from inside the app, and by emailing privacy@athlea.ai. Apple requires apps that let you create an account to let you delete it from inside the app too, so this route will always exist on iOS.
Deletion removes your profile, training history and health data. A small amount of data survives deletion where the law requires it — billing records for tax, and a suppression record so we do not email you again after you have unsubscribed. Backups are purged on the rotation described above.
Security
Data is encrypted in transit. Access to production systems is limited to the people who need it. Abuse-prevention metadata is hashed with a secret salt rather than stored in the clear, and the salt is required in production so it cannot be skipped by accident.
Your data is encrypted at rest by our cloud platform using AES-256. If a breach happens that puts your rights at risk, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you directly where the law requires.
Children and young athletes
Athlea is built for adults. The minimum age to hold an account is 18. We do not knowingly collect data from anyone below that age, and will delete it if we find we have.
If Athlea is later offered to under-18s — through clubs, schools or academies — this section needs rewriting to cover parental consent, age verification, and a children’s data protection impact assessment under the ICO’s Age Appropriate Design Code.
Changes to this policy
We will update this page when what we do changes. If a change materially affects how your health data is used, we will tell you directly rather than quietly editing the page, and where the change requires fresh consent we will ask for it.
Contact
Questions or corrections about this document go to privacy@athlea.ai. Athlea Ltd is registered in England & Wales with company number 15171507, at 86-90 Paul Street, London EC2A 4NE, United Kingdom.