Privacy Policy

Adaptiv Training · Effective Date: July 15, 2026

1. Introduction

Adaptiv Training ("we," "us," or "our") is a closed-loop training platform for endurance athletes. The Service is available as a web application and a native iOS application (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use either or both of these platforms. By creating an account or using the Service, you agree to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect the following information to personalize your training and recovery experience:

  • Name and email address
  • Password (stored in hashed form and never transmitted in plaintext)
  • Age, sex, height, and weight
  • Maximum heart rate, resting heart rate, and HRV baseline

On iOS, your resting heart rate profile and an authentication token are stored locally on your device using Apple's NSUserDefaults. This local storage is necessary to support HealthKit background delivery when the app is not actively open.

2.2 Daily Check-In Data

Each day, you may submit subjective readiness data including fatigue, soreness, and energy levels (rated 1–5), as well as injury or illness flags. This data is a first-class input into your recovery score and is used to dynamically adjust your recommended training load.

2.3 Biometric Data via Apple HealthKit

The Adaptiv Training iOS app uses Apple HealthKit with background delivery enabled. This means that health data is automatically transmitted from your device to our servers without requiring you to open the app or take any manual action. The following data types are delivered in the background:

  • Sleep data (total hours and sleep stage breakdowns) and resting heart rate and heart rate variability (HRV) are delivered to our /daily/metrics endpoint as new readings become available.
  • Apple Watch workout data — including runs, rides, swims, and other endurance activities with heart rate zones and lap data — is delivered to our /workouts/ endpoint upon workout completion.

You grant permission for this data access when you first launch the iOS app and authorize HealthKit. You may revoke HealthKit access at any time through iOS Settings (Privacy & Security → Health → Adaptiv Training). Revoking access stops future data delivery but does not automatically delete previously collected data. You may request deletion as described in Section 8.

All HealthKit data is used exclusively to compute your recovery score, training load, and personalized coaching recommendations. It is never shared with third parties, sold, or used for advertising.

2.4 Workout Data via Strava

If you connect your Strava account via OAuth, we import workout data including activity type, duration, distance, average and maximum heart rate, pace, elevation gain, and lap splits. This data is used to calculate training load metrics such as TRIMP/sRPE, your acute-to-chronic workload ratio, and fitness trends. You may also log workouts manually within the app.

When you disconnect your Strava account — whether through Adaptiv Training's settings or directly through Strava — all workout data imported from Strava is permanently and automatically deleted from our servers. Workouts you logged manually are not affected.

2.5 Workout Data via Wahoo

If you connect your Wahoo account via OAuth, we import workout data delivered as FIT-format files from your Wahoo devices (including ELEMNT GPS bike computers and KICKR smart trainers). Data imported includes workout type, duration, average and maximum heart rate, heart rate zones, lap data, power output, distance, elevation gain, and pace. This data is used to calculate training load metrics and fitness trends.

When you disconnect your Wahoo account through Adaptiv Training settings, all Wahoo-sourced workout data is permanently deleted from our servers. Workouts logged manually are not affected.

2.6 Biometric and Recovery Data via WHOOP

If you connect your WHOOP account via OAuth, we import the following data using WHOOP's authorized API scopes:

  • From read:recovery — recovery score, heart rate variability (HRV), and resting heart rate.
  • From read:sleep — sleep duration and sleep stage breakdowns.
  • From read:workout — workout type, duration, average and maximum heart rate, heart rate zones, and distance.
  • From read:body_measurement — maximum heart rate.

All WHOOP data is used exclusively to compute your recovery score and training load recommendations. When you disconnect your WHOOP account through Adaptiv Training settings, all WHOOP-sourced data is permanently deleted from our servers.

2.7 Workout Data via COROS (Pending Integration)

We are currently seeking API approval from COROS. This integration is not yet active. Once approved and enabled, and with your explicit consent, we intend to import the following data from your COROS devices via OAuth: workout type, duration, average and maximum heart rate, heart rate zones, pace, distance, and elevation gain. This data would be used solely to calculate training load metrics and fitness trends. This policy will be updated when the integration becomes available.

As with all integrations, disconnecting COROS will result in permanent deletion of all COROS-sourced data from our servers.

2.8 Workout and Health Data via Garmin (Pending Integration)

We are currently seeking API approval from Garmin. This integration is not yet active. Once approved and enabled, and with your explicit consent, we intend to import the following workout data via the Garmin Connect API: workout type, duration, average and maximum heart rate, heart rate zones, pace, distance, elevation gain, and lap data. If Garmin's Health API access is granted, we may also import daily health data including HRV, resting heart rate, and sleep. This policy will be updated when the integration becomes available.

As with all integrations, disconnecting Garmin will result in permanent deletion of all Garmin-sourced data from our servers.

2.9 Race and Performance Data

We store race results and performance records you log within the Service, including finish times, personal record (PR) flags, perceived effort (feel scores), and associated race metadata. This data is used to track your long-term performance trajectory and inform training load recommendations.

2.10 Billing Data

We use Stripe to process subscription payments. We store only your subscription status and Stripe customer identifier. We do not store, access, or process your credit card number, bank account details, or other payment credentials. All payment processing is handled entirely by Stripe in accordance with their privacy policy and PCI-DSS standards.

2.11 Automatically Collected Data

When you use the Service, we may automatically collect certain technical information such as IP address, browser type, device type and operating system, and usage patterns. This data is used solely to maintain, troubleshoot, and improve the Service.

3. How We Use Your Information

We use the information we collect exclusively to provide and improve your personal training experience. Specifically, we use your data to:

  • Calculate personalized training load recommendations and recovery scores
  • Compute your acute-to-chronic workload ratio and fitness trends
  • Dynamically adjust your training plan based on daily readiness and biometric data
  • Track race results and personal records over time
  • Manage your account and subscription
  • Communicate with you about your account or the Service
  • Maintain, troubleshoot, and improve the Service

4. What We Do Not Do With Your Data

We want to be absolutely clear about the following commitments:

  • We do not sell your personal data to any third party.
  • We do not share your data with third parties for advertising or marketing purposes.
  • We do not use your data for targeted advertising.
  • We do not use your biometric, workout, race, or health data for any purpose other than powering your personal coaching experience.
  • We do not use Apple HealthKit data to serve advertisements or to sell information to data brokers, in compliance with Apple's HealthKit guidelines.

5. Third-Party Services

5.1 Strava

We access your Strava data via OAuth with your explicit consent. We request only the permissions necessary to import your workout data. You can revoke this access at any time through Adaptiv Training settings or through your Strava account settings. Upon revocation by either method, all Strava-sourced workout data is permanently deleted from our servers. Strava's own privacy policy governs their handling of your data on their platform.

5.2 Apple HealthKit

We access Apple HealthKit data through the Adaptiv Training iOS app with your explicit authorization, including background delivery of health metrics without requiring active app use. We comply with Apple's HealthKit data use requirements, which prohibit using HealthKit data for advertising, selling to third parties, or any purpose beyond providing health and fitness services directly to you. You may revoke HealthKit access at any time through iOS Settings.

5.3 Stripe

Stripe handles all payment processing. We do not have access to your full payment credentials. Stripe's privacy policy and PCI-DSS compliance govern their handling of your payment data.

5.4 Wahoo

If you connect your Wahoo account, you authorize us to access your workout data via the Wahoo Cloud API. You may revoke this access at any time through Adaptiv Training settings. Upon disconnection, all Wahoo-sourced workout data is permanently deleted from our servers. Wahoo's own privacy policy governs their handling of your data on their platform.

5.5 WHOOP

If you connect your WHOOP account, you authorize us to access your recovery, sleep, and workout data via the WHOOP API. You may revoke this access at any time through Adaptiv Training settings. Upon disconnection, all WHOOP-sourced data is permanently deleted from our servers. WHOOP's own privacy policy governs their handling of your data on their platform.

5.6 COROS (Pending Integration)

COROS integration is pending API approval and is not yet active. When available, connecting your COROS account will authorize access to your workout data via the COROS API. Disconnecting will result in permanent deletion of all COROS-sourced data from our servers. This section will be updated when the integration is live.

5.7 Garmin (Pending Integration)

Garmin integration is pending API approval and is not yet active. When available, connecting your Garmin account will authorize access to your workout and, if applicable, daily health data via the Garmin Connect API. Disconnecting will result in permanent deletion of all Garmin-sourced data from our servers. This section will be updated when the integration is live.

6. Data Storage and Security

Your data is stored on secure cloud infrastructure provided by third-party cloud hosting providers. We implement industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords, and access controls to protect your personal information. On iOS, locally cached data (auth token and HR profile) is stored in NSUserDefaults; we recommend keeping your device protected with a passcode or biometric lock. Our hosting and infrastructure providers may have incidental access to data in server logs as part of normal service operations. While no system can guarantee absolute security, we take reasonable steps to safeguard your data.

Your data is stored and processed in the United States. If you are accessing the Service from outside the United States, please be aware that your data will be transferred to and processed in the US, which may have different data protection laws than your country of residence.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Data sourced from Strava, Wahoo, WHOOP, COROS, or Garmin is permanently deleted immediately upon disconnection of the respective integration. If you delete your account, we will delete or anonymize your remaining personal data within 30 days, except where we are required to retain certain information by law.

8. Your Rights

Depending on your location, you may have certain rights regarding your personal data, including:

  • Access: You may request a copy of the personal data we hold about you.
  • Correction: You may request that we correct inaccurate or incomplete data.
  • Deletion: You may request that we delete your personal data.
  • Portability: You may request a copy of your data in a portable format.
  • Opt-out of sale: We do not sell your personal data, so there is nothing to opt out of.

To exercise any of these rights, contact us at hello@trainadaptiv.com. We will respond within 30 days.

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). You have the right to know what personal information we collect, the right to request deletion of your data, and the right to opt out of the sale of personal information. As stated above, we do not sell your personal data. To submit a verifiable consumer request, contact us at hello@trainadaptiv.com.

10. GDPR Rights for European Users

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent local laws may apply to our processing of your personal data. The legal bases for processing are: (a) performance of a contract, where processing is necessary to provide the Service you have signed up for; (b) your consent, where you have explicitly authorized data collection such as HealthKit, Strava, Wahoo, WHOOP, COROS, or Garmin integration; and (c) our legitimate interests in maintaining and improving the Service, where those interests are not overridden by your rights.

In addition to the rights described in Section 8, EU/UK users have the right to object to processing based on legitimate interests, the right to restrict processing, and the right to lodge a complaint with your local data protection authority. Where we rely on your consent as a legal basis, you may withdraw that consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, contact us at hello@trainadaptiv.com.

11. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice within the Service prior to the change becoming effective. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

Adaptiv Training

Email: hello@trainadaptiv.com