Privacy Policy Beta
The short version: We collect only what we need to run the app. We never sell your data. We never share it with advertisers. Your health and activity data stays between you and Fresh Legs.
1. Who We Are
Fresh Legs ("we", "us", or "our") is a beta-stage personal workout planning application available at freshlegs.xyz. This policy describes how we collect, use, and protect your information when you use the Fresh Legs app (the "Service").
Contact us at: legal@freshlegs.app
2. What Data We Collect
2A. Data You Provide Directly
- Your workout plans, sessions, exercises, and training notes.
- Post-workout feedback: mood ratings, effort (RPE), strength levels, and free-text notes.
- Running routes, waypoints, and location names you save.
- Gear items (shoes, bikes, etc.) and the mileage you attribute to them.
- Training log entries, including dates and linked activities.
2B. Account Data
When you create an account, we collect your name, email address, and a hashed password. This is stored securely in Supabase, our database provider. We use this solely to authenticate you and sync your data across devices.
2C. Data from Oura Ring
When you connect your Oura Ring via OAuth, we access the following data from Oura's API on your behalf:
- Daily readiness score and contributing factors.
- Sleep duration, sleep stages, and sleep efficiency.
- Overnight heart rate variability (HRV).
- Resting heart rate.
- Body temperature deviation.
2D. Data from Garmin Connect
When you connect your Garmin account, we access:
- Workout type, duration, and distance.
- Average and maximum heart rate.
- Elevation gain and GPS route data.
- Pace, cadence, and calorie estimates.
- Heart rate zone breakdown.
2E. Data from Suunto
When you connect your Suunto account via OAuth, we access:
- Workout type, duration, and distance.
- Average heart rate.
- Elevation gain.
- Activity timestamps and names.
We access only the data scopes necessary to display your activities within Fresh Legs. We do not access sleep data, weight data, or any data category not listed above.
2F. GPX Import Data (Coros, Amazfit)
If you manually import a GPX file, we process the GPS track points, timestamps, and derived statistics (distance, elevation gain, duration) from that file. This data is stored in your account the same way as any other activity.
2G. Technical Data
- No cookies, analytics trackers, or advertising identifiers are used.
- Service Worker and PWA installation state are stored locally in your browser only.
- We do not collect IP addresses, device identifiers, or browsing history.
3. How We Use Your Data
We use your data solely to operate the Service:
- Displaying your Oura readiness, sleep, and HRV data in the Today and Log tabs.
- Showing your Garmin and Suunto activity metrics alongside your manual log entries.
- Calculating gear mileage based on activities you tag.
- Syncing your workout plan, log history, routes, and gear across your devices.
- Displaying your weekly progress chart.
- Generating GPX files for routes you build.
We do not use your health data for advertising, profiling, machine learning training, or any purpose other than displaying it back to you within the app.
4. Data Storage and Security
Your workout plans, log entries, routes, and gear data are stored in Supabase (PostgreSQL), protected by row-level security so only you can access your own data.
Third-party OAuth tokens (Oura, Suunto) and Garmin credentials are stored encrypted at the server level and are never exposed to your browser or logged in plain text.
All data in transit is protected by HTTPS. Our serverless API acts as a secure proxy — your credentials and tokens never appear in your device's outgoing network requests.
5. Data Sharing
We do not sell your data. We do not share your health or activity data with third parties except:
- Oura API — your token is used to request your own data from their servers.
- Garmin Connect — your credentials are used to authenticate and retrieve your activities.
- Suunto Cloud API — your OAuth token is used to retrieve your activities.
- Supabase — our database and authentication provider, which processes and stores your data under their privacy policy.
- Vercel — our hosting provider, which processes requests but does not access your health data.
- If required by law, court order, or to protect the safety of users.
We never transfer your data to ad networks, data brokers, or any advertising or monetisation toolset. This is also a contractual obligation under our Suunto API agreement.
6. Third-Party API Compliance
6A. Oura
Our use of the Oura API is governed by Oura's API Terms of Use. You can revoke access at any time from the Settings tab or at cloud.ouraring.com/personal-access-tokens. We only request data scopes necessary for the features described above and do not request write access to your Oura account.
6B. Garmin
Fresh Legs uses a direct Garmin Connect integration. Your Garmin email and password are stored securely and used only to retrieve your activity data. We do not post to, modify, or delete any data in your Garmin account.
6C. Suunto
Our use of the Suunto Cloud API is governed by the Suunto Cloud API Agreement. In compliance with that agreement:
- We do not store your Suunto password — only an OAuth access token issued by Suunto.
- We only fetch activity data necessary to operate the Service.
- We display a "Works with Suunto" indicator in the Settings tab as required by the agreement.
- We do not transfer Suunto data to any advertising or monetisation service.
- If you disconnect your Suunto account, we stop fetching your data and delete your stored token promptly.
- You can request deletion of any Suunto data we hold by contacting legal@freshlegs.app.
7. Your Rights
- Access or export your data at any time from the app.
- Delete your account and all associated data by contacting legal@freshlegs.app.
- Disconnect any third-party integration (Oura, Garmin, Suunto) from the Settings tab at any time.
- Request correction of inaccurate personal data.
- Withdraw consent to third-party data access by disconnecting the integration.
8. Data Retention
We retain your data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it by law.
Third-party tokens (Oura, Suunto) and Garmin credentials are deleted immediately upon disconnection.
9. Children
Fresh Legs is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at legal@freshlegs.app.
10. Changes to This Policy
We will update this policy as the product evolves. Material changes will be communicated via an in-app notice. Continued use of the Service after changes constitutes acceptance of the revised policy.
The current version of this policy is always available at freshlegs.xyz/privacy.html.
11. Contact
For questions about this policy, email us at legal@freshlegs.app.