Privacy Policy
Last updated: March 10, 2026 · Effective: March 10, 2026
1. Introduction
MYPEAK.AI ("we," "us," "our") operates the MYPEAK.AI platform (the "Service"), accessible at mypeakai.lovable.app and related applications. We are committed to protecting your privacy and ensuring transparency about how we collect, use, store, and share your personal data.
This Privacy Policy applies to all users of the Service and complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the data handling requirements of our wearable device integration partners including Polar Electro, WHOOP Inc., and Ōura Health.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the Service.
2. Data We Collect
2.1 Account Information
- Email address
- Full name (optional)
- Sport preferences and training goals
- Timezone
2.2 Health & Fitness Data from Connected Devices
When you connect wearable devices (Polar, WHOOP, Oura, Strava, Garmin), we access only the data categories you explicitly authorize through each provider's OAuth consent screen. This may include:
- Heart rate data (resting, active, and maximum)
- Heart rate variability (HRV)
- Sleep duration, stages, and quality scores
- Activity data (distance, duration, pace, calories)
- GPS route data
- Recovery and readiness scores
- Body temperature deviations
- Respiratory rate
- Training load and strain scores
- Step count and active minutes
- VO2 Max estimates
2.3 Manually Entered Data
- Self-reported recovery metrics (HRV, resting heart rate, sleep hours)
- Subjective wellness ratings
- Race goals and training plans
- Coach notes (for team/coaching features)
2.4 Usage Data
- Pages viewed and features used
- Device type and browser information
- IP address (anonymized after 30 days)
- Interaction timestamps
3. How We Use Your Data
We process your data exclusively for the following purposes:
- Provide the Service: Generate personalized training recommendations, readiness scores, injury risk assessments, and performance predictions.
- AI-Powered Insights: Our AI coaching system analyzes your health and training data to deliver actionable recommendations. This processing is essential to the core functionality of the Service.
- Communication: Send daily training recommendations, weekly insight summaries, and injury alerts (if enabled in your preferences).
- Improve the Service: Analyze anonymized, aggregated data to improve our algorithms. Individual health data is never used for this purpose without explicit consent.
- Coach/Team Features: If you join a team, share specified data with your coach as determined by your permission settings.
4. Wearable Device Integrations
We integrate with third-party wearable platforms via their official OAuth 2.0 APIs. Each integration adheres to the respective platform's developer terms and data handling requirements.
Polar Electro
- We access data via the Polar Accesslink API with your explicit OAuth authorization.
- Data accessed: daily activity, training sessions, sleep data, and physical information.
- We do not store raw Polar API responses beyond what is necessary for the Service.
- You can revoke access at any time via your Polar Flow account or our Devices settings.
- We comply with Polar's Accesslink API Terms of Use.
WHOOP
- We access data via the WHOOP Developer API with your explicit OAuth authorization.
- Data accessed: recovery scores, strain scores, sleep performance, heart rate, and HRV.
- We use WHOOP data solely to generate training insights within the Service.
- We do not share WHOOP data with any third parties.
- You can disconnect WHOOP at any time, and we will delete all stored WHOOP data within 30 days.
- We comply with the WHOOP Developer API Terms of Service.
Oura Health
- We access data via the Oura API v2 with your explicit OAuth authorization.
- Data accessed: sleep analysis, readiness scores, activity summaries, heart rate, HRV, and body temperature.
- We process Oura data exclusively within the Service to provide health and training insights.
- We do not sell, rent, or share Oura data with any third parties.
- You can revoke access via your Oura account settings or our Devices page.
- We comply with the Oura Developer API Terms of Use.
Strava
- We access data via the Strava API v3 with your explicit OAuth authorization.
- Data accessed: activity summaries, GPS routes, heart rate, pace, and performance metrics.
- We display the "Powered by Strava" attribution as required.
- We comply with the Strava API Agreement.
Universal Integration Principles:
- We only request the minimum data scopes necessary for the Service.
- OAuth tokens are stored securely with AES-256 encryption and are never exposed to the client.
- Token refresh is handled server-side via secure backend functions.
- We never cache or store data beyond what is needed for active Service functionality.
- Disconnecting a device removes all associated tokens and queues data for deletion.
5. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3.
- Encryption at Rest: All stored data, including health metrics and OAuth tokens, is encrypted using AES-256.
- Access Controls: Backend functions use Row-Level Security (RLS) to ensure users can only access their own data.
- Secret Management: API keys and OAuth client secrets are stored in secure, encrypted environment variables and are never exposed to client-side code.
- Regular Audits: We conduct periodic security reviews and vulnerability assessments.
6. Data Sharing & Third Parties
We never sell your health data to third parties, insurers, advertisers, or data brokers.
We may share data only in the following limited circumstances:
- Coach/Team Sharing: If you voluntarily join a coaching team, your coach can view the data you explicitly authorize (configurable per athlete).
- Service Providers: We use infrastructure providers (hosting, database) that process data on our behalf under strict data processing agreements.
- AI Processing: Training recommendations may be generated using third-party AI models. Only anonymized, contextual data is sent—never your name, email, or identifiable information.
- Legal Requirements: We may disclose data if required by law, court order, or to protect our legal rights.
7. Data Retention
- Active Account: We retain your data for as long as your account is active and the Service is being provided.
- Account Deletion: Upon account deletion, all personal data and health metrics are permanently deleted within 30 days. Anonymized aggregate data may be retained.
- Device Disconnection: When you disconnect a wearable device, associated OAuth tokens are deleted immediately and device-specific health data is deleted within 30 days.
- Waitlist Data: If you join our waitlist, your email is retained until you convert to a user or request removal.
8. Your Rights
8.1 Rights Under GDPR (EU/EEA Users)
- Right of Access: Request a copy of all data we hold about you.
- Right to Rectification: Correct inaccurate personal data.
- Right to Erasure: Request permanent deletion of your data ("right to be forgotten").
- Right to Data Portability: Export your data in a standard machine-readable format (JSON/CSV).
- Right to Restrict Processing: Limit how we use your data.
- Right to Object: Object to data processing for specific purposes.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
8.2 Rights Under CCPA (California Residents)
- Right to Know: Request disclosure of data collected, sources, purposes, and third parties.
- Right to Delete: Request deletion of personal information.
- Right to Opt-Out: We do not sell personal information. No opt-out is necessary.
- Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA rights.
8.3 How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@mypeak.ai. We will respond within 30 days (GDPR) or 45 days (CCPA). You may also delete your account and all associated data directly from your account settings.
9. Cookies & Tracking
Essential Cookies (Required)
Authentication session cookies and preference storage. These are necessary for the Service to function.
Analytical Cookies (Optional)
Anonymous usage analytics to improve the Service. No cross-site tracking. No advertising cookies. No retargeting pixels.
You can disable analytical cookies in your browser settings. Essential cookies are required for the app to function properly.
10. Children's Privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will delete that data immediately. If you believe a child has provided us with personal data, please contact us at privacy@mypeak.ai.
11. International Data Transfers
Your data may be processed in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent protections.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before the changes take effect. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
13. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email: privacy@mypeak.ai
General Support: support@mypeak.ai
If you are in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority (DPA).