Privacy Policy

Last updated: February 12, 2026

1. Information We Collect

Account information: When you create an account, we collect your email address and password (hashed, never stored in plain text).

Athlete profile: You may optionally provide your age, sex, weight, rowing experience, and training preferences. This information is used to personalize your training plans.

Workout data: When you connect your Concept2 Logbook account via OAuth, we access your workout history including dates, distances, split times, stroke rates, and heart rate data. We store this data to provide analytics and coaching.

Usage data: We collect standard server logs (IP address, browser type, pages visited) for security and performance monitoring.

2. How We Use Your Data

  • Display your workout history, personal records, and progress charts on your dashboard
  • Analyze training trends and detect plateaus using deterministic algorithms
  • Generate personalized training plans and post-workout coaching insights using AI (Claude API)
  • Power the AI coach chat with context from your workout history and training data
  • Send email notifications (workout insights, weekly summaries) when you have them enabled
  • Process subscription payments via Stripe

3. Third-Party Services

We use the following third-party services to operate SplitCoach:

  • Concept2 Logbook API — to read your workout data via OAuth. We only request read access to your results.
  • Anthropic (Claude API) — to generate training plans, workout insights, training analysis narratives, and AI coach responses. Your workout data and profile are sent to Claude for processing but are not used to train AI models.
  • Stripe — to process subscription payments. We do not store your credit card information; Stripe handles all payment data.
  • Resend — to deliver transactional emails (workout insights, weekly summaries).

4. Data Retention

Your workout data and account information are retained as long as your account is active. If you delete your account, all associated data (workouts, plans, insights, chat history) is permanently deleted from our database.

5. Data Security

All data is transmitted over HTTPS. Concept2 OAuth tokens are stored encrypted. Passwords are hashed using bcrypt. API keys and secrets are stored as environment variables, never in client-side code. All database queries are scoped to the authenticated user.

6. We Do Not Sell Your Data

We do not sell, rent, or share your personal data or workout data with third parties for marketing purposes. Your data is used solely to provide and improve the SplitCoach service.

7. Your Rights

You can:

  • Access and export your data at any time via the dashboard
  • Update or correct your profile information in Settings
  • Disconnect your Concept2 Logbook account at any time
  • Delete your account and all associated data by contacting us
  • Opt out of email notifications in Settings

8. Cookies

We use essential cookies for authentication (session tokens). We do not use tracking cookies or third-party analytics cookies.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

10. Contact

If you have questions about this privacy policy or your data, contact us at privacy@splitcoach.com.