Last Updated: March 12, 2026
ICU Coach ("we", "our", "the app") is an AI-powered training coach application for endurance athletes. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable data protection laws.
The data controller responsible for your personal data is:
We process your personal data based on the following legal grounds:
Health data is only accessed when you explicitly grant permission through your device's health settings. You can revoke this permission at any time.
| Data Type | iOS (HealthKit) | Android (Health Connect) |
|---|---|---|
| Sleep Duration & Quality | ✅ | ✅ |
| Heart Rate Variability (HRV) | ✅ | ✅ |
| Resting Heart Rate | ✅ | ✅ |
| Heart Rate | ✅ | ✅ |
| Weight | ✅ | ✅ |
| Blood Oxygen (SpO2) | ✅ | ✅ |
| VO2 Max | ✅ | ✅ |
| Steps | ✅ | ✅ |
| Body Fat Percentage | ✅ | ✅ |
| Active & Total Calories | ✅ | ✅ |
| Distance | ✅ | ✅ |
| Basal Metabolic Rate | ✅ | ✅ |
If you enable Health Sync in the app, the device health metrics listed in the table above (including sleep, HRV, resting heart rate, heart rate, weight, SpO2, VO2 Max, steps, body fat percentage, calories, distance, and basal metabolic rate where available) may be synced to your Intervals.icu wellness account using your OAuth-authorized connection. This sync is used for core app functionality such as wellness continuity, dashboard readiness, and coaching insights. You can disable Health Sync at any time from Settings.
When you accept a coach's invitation to join their team, you explicitly consent to sharing your Intervals.icu training data with that coach. This connection is established through the standard Intervals.icu OAuth flow — you authorize access on the Intervals.icu consent screen before any data is shared.
When you join a coaching team, the following data is collected and stored:
The following Intervals.icu data becomes accessible to your coach through their authorized connection:
Your coach accesses this data using your individually authorized OAuth token — no additional data access is granted beyond what you approved on the Intervals.icu consent screen. When you revoke the coach connection, the stored encrypted token is permanently deleted.
The following data is collected automatically to maintain app stability and improve the service:
Before any data is sent to an AI service, the app asks for your explicit consent. You must review and accept which data is shared, who it is shared with, and how it will be used. You can decline at any time, in which case no data is sent and AI features will not be available until you provide consent.
When you use AI-powered features (Auto Coach, reports, nutrition advice, race predictions), the following data may be sent to your selected AI provider:
Data is sent to one of the following AI providers, depending on your configuration:
All AI providers are subject to their own privacy policies. Data sent for AI analysis is:
We do NOT use your data for advertising, profiling, or automated decision-making that produces legal effects.
| Data Type | Retention Period | Location |
|---|---|---|
| Intervals.icu OAuth tokens & AI provider API keys | Until you delete them or uninstall the app | Your device (SecureStore) |
| App settings & preferences | Until you delete them or uninstall the app | Your device (AsyncStorage) |
| Cached training data | Automatically refreshed; stale data expires within 24 hours | Your device (AsyncStorage) |
| AI usage counters | Reset daily; cleared on uninstall | Your device (AsyncStorage) |
| Crash reports (Sentry) | 90 days (Sentry default retention) | Sentry servers (EU — Frankfurt, DE) |
| Subscription data (RevenueCat) | As per RevenueCat's retention policy | RevenueCat servers (US) |
| Cloud AI processing data | Not stored — discarded after response | Vercel (US) |
| Coach-athlete relationship data | Until the athlete or coach revokes the connection, or upon deletion request | Supabase (EU — Frankfurt, DE) |
| Encrypted OAuth tokens (coaching) | Until the connection is revoked — deleted immediately upon revocation | Supabase (EU — Frankfurt, DE), encrypted with AES-256-GCM |
| Coach push notification token | Until coach disables notifications or uninstalls the app | Supabase (EU — Frankfurt, DE) |
| Rate limiting metadata | Automatically expires within 60 seconds | Upstash Redis (serverless, EU) |
The app integrates with the following third-party services. Each has its own privacy policy governing their data handling:
| Service | Purpose | Data Shared | Server Location |
|---|---|---|---|
| Intervals.icu | Training data platform | OAuth-based authorized access token; planned workouts created by the app; selected wellness metrics synced from device health when Health Sync is enabled | EU |
| Google Gemini | AI analysis (optional) | Anonymized training context for AI processing | US |
| OpenAI | AI analysis (optional) | Anonymized training context for AI processing | US |
| Sentry | Crash reporting & error monitoring | Device info, OS version, crash data, IP address | EU (Frankfurt) |
| RevenueCat | Subscription & purchase management | Anonymous user ID, purchase receipts, entitlements | US |
| Open-Meteo | Weather data | Geographic coordinates only (no personal data) | EU |
| Apple HealthKit | Health data (iOS) | Read-only access with your permission | Your device |
| Google Health Connect | Health data (Android) | Read-only access with your permission | Your device |
| Supabase | Coach-athlete relationship database | Athlete ID, display name, coach ID, invite token, connection status | EU (Frankfurt) |
| Expo Push Service | Remote push notifications for coaches | Expo push token, notification title and body text | US |
| Upstash Redis | API rate limiting & abuse prevention | Anonymized request identifier, request count (no personal data) | EU |
We encourage you to review each service's privacy policy.
Some third-party services process data in the United States. When your data is transferred outside the European Economic Area (EEA), we rely on:
Crash reporting data (Sentry) and coach-athlete relationship data (Supabase) are processed within the EU (Frankfurt, Germany).
With your permission, the app can send local push notifications to remind you of your daily training readiness. These notifications are:
Coaches may receive remote push notifications when team-related events occur, such as:
These notifications are delivered via the Expo Push Notification Service. Coach push tokens are stored in our database (Supabase, EU — Frankfurt) and are used solely for delivering team activity notifications. Coaches can disable push notifications at any time from the app, which removes the stored token from the server.
We do NOT sell, rent, or share your personal data with any third parties for marketing or advertising purposes.
Your data is only shared with third-party services in the following circumstances:
ICU Coach is not intended for use by children under 16. We do not knowingly collect data from children. If you believe a child under 16 has provided us with personal data, please contact us so we can take appropriate action.
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through an in-app notice. The latest version will always be available within the app. We recommend reviewing this policy periodically.
For questions, data requests, or concerns about this Privacy Policy, contact us at:
We will respond to your request within 30 days.