Legal

Privacy Policy

Athlea processes health data — heart rate, HRV, sleep, body weight, injuries, food and recovery signals. Under UK data protection law that is one of the most tightly protected categories of personal data there is, and it deserves a policy that says plainly what happens to it.

This policy covers the athlea.ai website and the Athlea apps. Where something only applies once a feature has actually launched, we say so rather than describing a product that does not exist yet.

Draft last revised 23 August 2026Effective date 23 August 2026

Who we are

Athlea Ltd (“Athlea”, “we”, “us”) is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are answerable for it.

Legal entity
Athlea Ltd, company number 15171507 (England & Wales)
Registered office
86-90 Paul Street, London EC2A 4NE, United Kingdom
ICO registration
Registration pending. Athlea Ltd is registering with the UK Information Commissioner’s Office as a data controller; we will publish the registration number here once it is issued.
Privacy contact
Data protection officer
We have not appointed a data protection officer. We do not currently meet the threshold in Article 37 of the UK GDPR, which applies to organisations whose core activities involve processing special-category data on a large scale. We keep this under review as we grow, and will appoint one and publish their details here if the threshold is met.

Our representative in the European Union

Athlea Ltd is established in the United Kingdom. Because we offer our services to people in the European Economic Area, we have designated a representative in the European Union under Article 27 of the EU GDPR. You can contact our representative about anything to do with our processing of your personal data, in addition to contacting us directly.

EU representative
Prighter Germany GmbH, acting as EU representative on behalf of Athlea Ltd
Postal address
Heidestraße 40, 10557 Berlin, Germany

Contacting our representative has the same effect as contacting us. You can also complain to the data protection supervisory authority in your own country.

What this policy covers

  • The website at athlea.ai — the marketing pages, the waitlist and enquiry forms, and the website assistant.
  • The Athlea apps — the iOS app and the web app at app.athlea.ai, including everything you connect to them.

It does not cover other companies’ services. If you connect Apple Health or Garmin Connect, or pay through Stripe, those companies have their own privacy policies covering what they do with your data on their side.

The data we collect

On the website

  • Your email address and your explicit confirmation that we may contact you, when you join the waitlist.
  • Your email address, sport, role and organisation size, when you use the professional enquiry form.
  • Whatever you type into the website assistant, and the reply it generates. Please do not put health details or anything sensitive into it — it is a sales and information tool, not a clinical one.
  • Technical data needed to run the site and stop abuse: your IP address and browser user agent. We do not store either in the clear against a waitlist entry — both are hashed with a secret salt before they are recorded, so they can be used to spot repeat abuse but not to look you up.

In the apps

  • Account data — name, email address, password credentials, and your subscription status.
  • Profile and training data — sport, experience, goals, training history, sessions completed, and self-reported benchmarks such as an FTP band or a recent race time.
  • Health data — heart rate, heart rate variability, resting heart rate, sleep, training load and recovery signals, body weight and composition, food and nutrition logs, supplements you look up, injuries, symptoms and pain reports, and menstrual cycle data where you choose to provide it.
  • Data from devices and services you connect — Apple Health, Garmin Connect, and Bluetooth sensors such as heart rate straps, power meters and trainers.
  • Usage and diagnostic data — logs of requests, errors and crashes, used to keep the service working.
  • Payment data — once subscriptions go live, payments will be processed by Stripe. Stripe handles card details directly. We receive confirmation of payment, the last four digits, and billing country, and never see or store a full card number.

Health data and explicit consent

Heart rate, HRV, sleep, weight, injuries, nutrition and menstrual cycle data are all “special category” data under Article 9 of the UK GDPR. We are only allowed to process it if one of a short list of conditions applies. The condition we rely on is your explicit consent (Article 9(2)(a)), given separately from agreeing to the terms.

What explicit consent means here

You are asked to opt in specifically, before any health data is connected or entered. The request is separate from account creation and separate from accepting the terms. You can withdraw it at any time, in the app or by emailing us, and withdrawing is as easy as giving it.

If you withdraw consent, the features that depend on health data stop working — there is no adaptive coaching without training and recovery data. Withdrawing does not make past processing unlawful, but it does mean we stop, and you can ask us to delete what we hold.

We do not use your health data for advertising, we do not sell it, and we do not share it with advertisers, data brokers or insurers. That is a firm commitment, and for Apple Health data it is also a contractual obligation we owe Apple.

Why we are allowed to use it

Running your account and delivering the service
Performance of our contract with you — Article 6(1)(b)
Health and fitness data
Your explicit consent — Article 6(1)(a) and Article 9(2)(a). Withdrawable at any time.
Waitlist and marketing email
Your consent — Article 6(1)(a). Every message has an unsubscribe link.
Security, abuse prevention and rate limiting
Our legitimate interests in keeping the service available and not being abused — Article 6(1)(f). This is why IP and user agent are hashed and briefly retained.
Billing records, tax and accounting
Legal obligation — Article 6(1)(c)
Defending legal claims
Legitimate interests, and for health data Article 9(2)(f)

Apple Health and HealthKit

If you connect Apple Health, the Athlea iOS app reads only the data types you approve in the iOS permission screen. You can see and change those permissions at any time in Settings → Privacy & Security → Health → Athlea, and you can revoke them all without deleting your account.

Apple imposes specific conditions on apps that read HealthKit data. We commit to all of them:

  • HealthKit data is used only to provide health and fitness features to you — never for advertising, marketing, or any use unrelated to the coaching you asked for.
  • HealthKit data is never sold, rented, or disclosed to data brokers, advertisers, or information resellers.
  • HealthKit data is not disclosed to any third party without your explicit consent, and then only to deliver a feature to you.
  • HealthKit data is not stored in iCloud, and is not used for any research without your separate, informed, opt-in consent.
  • Disconnecting Apple Health stops further reads immediately. You can ask us to delete data already synced at any time, and we delete it within 30 days of the request.

Garmin Connect

This section describes specifically how data from your Garmin device and Garmin Connect account is collected, used, processed and stored, and who else touches it. It exists as a standalone section so it can be linked to directly.

What we collect from Garmin

Connecting Garmin authorises Athlea, through Garmin’s OAuth flow, to pull your activity and wellness data — workouts and their routes, heart rate, heart-rate variability, resting heart rate, sleep, and daily activity summaries. We request only the scopes the product needs, and the connection refreshes periodically in the background so your plan stays current without you having to export anything. We never receive your Garmin password.

What we use it for

Garmin data is used to build and adapt your training, nutrition and recovery guidance — reading your load, readiness and sleep so a plan can be adjusted to the athlete you actually are on a given day — and to show you your own history inside the app. It is used for nothing else. We do not use it for advertising, we do not profile you for marketing, and we do not sell it.

Who processes it

To generate coaching guidance, the relevant parts of your Garmin data are sent to our enterprise large-language-model sub-processor, Microsoft Azure OpenAI, running inside Athlea’s own Azure tenant under a data processing agreement. Under that agreement your data is not used to train or fine-tune any model and is not made available to other customers. Microsoft may retain prompts and outputs for up to 30 days solely for abuse monitoring, after which they are deleted; we are working to have this retention disabled entirely for our production systems.

Beyond that, Garmin data is handled only by the infrastructure processors listed in Who we share data with — hosting, database and storage providers acting on our instructions under contract. It is not sold, not shared for any third party’s own purposes, not passed to data brokers, and not disclosed for advertising.

Where it is stored, and for how long

Garmin data is stored in our production database on Microsoft Azure, encrypted in transit with TLS and encrypted at rest by the platform using AES-256. We keep it for as long as your Athlea account is active and you remain connected to Garmin. If you close your account, or disconnect Garmin, we delete it within 30 days.

You can disconnect from inside the Athlea app, or revoke Athlea’s access from your Garmin Connect account settings. Revoking at Garmin stops the sync at source. Garmin data already synced is deleted within 30 days of disconnection. You can also ask us to delete it at any time — see Your rights.

Garmin also imposes contractual conditions on developers using its API — including limits on how its data may be displayed, combined and retained. We comply with the Garmin Developer Program terms in force for our integration.

AI and automated decisions

Athlea generates training and nutrition guidance using large language models. To do that, relevant parts of your training and health data are sent to a model provider acting as our processor, under a contract that restricts what they may do with it.

  • We do not permit our model providers to use your data to train their general-purpose models.
  • No decision that produces a legal or similarly significant effect on you is made solely by automated means, so Article 22 of the UK GDPR is not engaged. Coaching output is a recommendation you are free to ignore.
  • You can always reach a person. Email privacy@athlea.ai and a human will read it.

What the models can and cannot do, and where AI-generated imagery appears on this site, is set out in the AI Disclosure.

Who we share data with

We use a small number of service providers to run Athlea. They process data on our instructions under written contracts, and cannot use it for their own purposes. We do not sell personal data.

Vercel
Website and application hosting, and delivery logs
Cloudflare
Turnstile bot protection on the waitlist and enquiry forms
Microsoft Azure Cache for Redis
Redis store used for rate limiting. It holds hashed identifiers only, never a plain email or IP address
Microsoft Azure OpenAI
The website assistant. Your message text is sent to the model to generate a reply
Sanity
Content management for marketing pages
Resend
Transactional and waitlist email
Stripe
Payments and subscription billing, once subscriptions launch
In-app model provider
Microsoft Azure OpenAI, running in Athlea’s own Azure tenant under a data processing agreement — see AI and automated decisions

We may also disclose data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case this policy travels with the data.

Where your data goes

Several of the providers above are US companies or operate globally, so some data is likely to be processed outside the UK. Where that happens, transfers must be covered by an appropriate safeguard — an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement, or on the UK Addendum to the EU Standard Contractual Clauses, with each processor. You can ask us for a copy of the safeguard that applies to a particular transfer by writing to privacy@athlea.ai.

This website is served from Microsoft and Vercel infrastructure in the European Economic Area, and our production database and model processing run in Microsoft Azure.

How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for, then delete it. Where a fixed period is not sensible, the criteria we use are set out below.

Waitlist entries
Until you accept an invitation to join Athlea, or 24 months from signup, whichever comes first. If we close the waitlist without launching, we delete it within 30 days and tell you we have done so. You can ask to be removed at any time
Account and profile data
For as long as your account is open, and deleted within 30 days of account closure
Health and training data
For as long as your account is open. Deleted within 30 days of account closure, or within 30 days of you withdrawing consent for us to process it
Hashed abuse-prevention metadata
One hour — the rate-limit window. The values are one-way hashes, never the IP address or user agent themselves
Website assistant conversations
Deleted within 30 days. We do not use them to build a profile of you
Billing and tax records
Six years from the end of the accounting period they relate to, as UK tax law requires
Backups
Deleted data can persist in encrypted backups after it is removed from live systems. We do not restore it into live systems, and it is overwritten in the ordinary backup cycle within six months

Your rights

Under UK data protection law you can ask us to do all of the following, free of charge. We will respond within one month.

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct data that is wrong or incomplete.
  • Erasure — have your data deleted.
  • Restriction — have us pause processing while a dispute is sorted out.
  • Portability — receive the data you gave us in a machine-readable format, or have it sent to another service.
  • Objection — object to processing we base on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — including consent to process health data, at any time.

Email privacy@athlea.ai to exercise any of these. If you are not happy with how we handle it, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.

Deleting your account

You can delete your Athlea account and the data attached to it from inside the app, and by emailing privacy@athlea.ai. Apple requires apps that let you create an account to let you delete it from inside the app too, so this route will always exist on iOS.

Deletion removes your profile, training history and health data. A small amount of data survives deletion where the law requires it — billing records for tax, and a suppression record so we do not email you again after you have unsubscribed. Backups are purged on the rotation described above.

Security

Data is encrypted in transit. Access to production systems is limited to the people who need it. Abuse-prevention metadata is hashed with a secret salt rather than stored in the clear, and the salt is required in production so it cannot be skipped by accident.

Your data is encrypted at rest by our cloud platform using AES-256. If a breach happens that puts your rights at risk, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell you directly where the law requires.

Children and young athletes

Athlea is built for adults. The minimum age to hold an account is 18. We do not knowingly collect data from anyone below that age, and will delete it if we find we have.

If Athlea is later offered to under-18s — through clubs, schools or academies — this section needs rewriting to cover parental consent, age verification, and a children’s data protection impact assessment under the ICO’s Age Appropriate Design Code.

Changes to this policy

We will update this page when what we do changes. If a change materially affects how your health data is used, we will tell you directly rather than quietly editing the page, and where the change requires fresh consent we will ask for it.

Contact

Questions or corrections about this document go to privacy@athlea.ai. Athlea Ltd is registered in England & Wales with company number 15171507, at 86-90 Paul Street, London EC2A 4NE, United Kingdom.

The rest of the legal surface