This Privacy Policy explains how Kardiacs LLC ("Kardiacs," "we," "us") collects, uses, and shares personal data when you use the Kardiacs mobile and watch apps, the Kardiacs websites (kardiacs.com and the signed-in dashboard at app.kardiacs.com), and related services (the "Service"). Kardiacs LLC is the data controller for this data. Contact: legal@kardiacs.com.
| Category | Examples | Source |
|---|---|---|
| Identity & profile data | The app works without an account: after you accept these terms and pass the age check, it creates an anonymous identity for your install (a random identifier managed via AWS Cognito, with no email or name) under which your synced data is stored. If you later choose to sign in with Apple or Google, we also receive your email address and authentication identifiers, and the data stored under your anonymous identity is merged into your account. Profile details you enter — date of birth (used to verify the minimum age), weight, and fitness parameters (e.g., FTP, heart-rate zones) — are collected either way. On devices that support it we also ask Apple for the age range declared on your Apple Account, to check the date of birth you gave us; we receive a range (such as “16–17”), never a date of birth, and it stays on your device and is never sent to our servers | Created automatically after consent (anonymous identity); you, if you sign in and in your profile; Apple, if you choose to share your declared age range |
| Workout & activity data | Structured workouts you create or import; indoor and outdoor activity recordings: power, cadence, speed, heart rate, elevation, duration, timestamps; activities recorded by other apps or devices that you import from Apple Health / Health Connect or Strava | Your connected trainer and sensors, your device's GPS during outdoor activities, and services you connect |
| Health data (sensitive) | Heart-rate variability, resting/recovery heart rate, blood oxygen, respiratory rate, VO₂max estimates, sleep data. Read on your device and used only there — readiness analysis runs locally and these metrics are never uploaded to our servers. With your permission we also write your weight back to Apple Health / Health Connect, so the figure you enter in Kardiacs stays consistent with the rest of your health data; nothing else is written. | Apple Health / Health Connect, only with your explicit permission |
| Location & route data | Routes you deliberately keep — favorites and GPX files you import — which sync to your own account as route shapes. Routes you plan and addresses you search for stay on your device. See “What stays on your device”. | You / your device, with location permission |
| Music listening data (optional) | Your most-played and recently played songs, albums, and artists from Apple Music — collected only if you enable AI music features, and used solely to generate playlist suggestions | Apple Music / your media library, with your permission |
| Third-party connections | OAuth access tokens for services you link (e.g., Strava, Spotify) | You, when you connect an account |
Basic technical data needed to run and improve the Service: device model and OS version, app version, crash and error reports (via Firebase Crashlytics and Sentry, including device state and, for Bluetooth troubleshooting, a log of recent trainer connection events), app-usage analytics events (via Google Firebase Analytics, e.g. which features are used), performance measurements, a push-notification token if you allow notifications (via Firebase Cloud Messaging), and API request metadata (such as timestamps and IP addresses in server logs). Remote configuration (Firebase Remote Config) is used to enable or adjust features, which involves delivering configuration values to your device. When the app creates its anonymous identity, Apple's App Attest service confirms to us that the app is a genuine App Store copy; this sends a one-time cryptographic attestation of your device's integrity, which we verify and do not store.
In the apps. We show banner ads served by Google AdMob. Before ads start, iOS asks whether the app may use your device’s advertising identifier (IDFA) — the App Tracking Transparency prompt. If you allow it, Google may use the IDFA to personalise the ads you see and to measure them. If you decline, you still see ads, but they are not personalised and the identifier is not used. Either way, Google may process device information, coarse location derived from IP address, and ad-interaction data to serve ads, measure them, and prevent fraud, as described in Google's Privacy Policy. Our Firebase Analytics data is linked to AdMob to measure ad revenue. We never use your health data, workout data, or precise location to target ads.
On the dashboard. The signed-in dashboard at app.kardiacs.com shows ads served by Google AdSense. Google may set and read cookies or similar browser storage on that site, and may process your IP address, coarse location derived from it, browser and device information, and how you interact with an ad, in order to serve and measure ads and to prevent fraud — as described in how Google uses information from sites that use its services. In the EEA and the UK, personalised advertising and any non-essential storage are used only where you have consented; without consent you are shown non-personalised ads.
Nothing about your account or your training is sent with an ad request, on either surface. The pages carrying ads also show your profile, health history and route plans; none of that is passed to Google. We never use your health data, workout data, or precise location to target ads, and we do not tell Google who you are.
Users under 18 are never shown personalised advertising. Where your date of birth or your Apple Account's declared age range tells us you are under 18, ad requests are marked as being for a user under the age of consent, ad content is capped at the most general rating, the ad-personalisation signal from our analytics is switched off, and you are not shown the App Tracking Transparency prompt or any full-screen ad.
We use your data to: provide the Service (control your trainer, run workouts, record and store your activities and routes, sync across your devices); sync your data with third-party services you connect, such as uploading activities to Strava; generate fitness insights such as readiness and recovery indicators from your health metrics; plan routes and provide outdoor maps and turn-by-turn guidance (routes are worked out on your device; what leaves it are requests for map, route, and elevation tiles, and — only when you search for an address — the text you type, with an approximate position to bias the results. These lookups return an answer and are not stored as your data); generate suggestions such as workout playlists (see Section 4); send you push notifications if you opt in; show ads as described above; understand feature usage and improve the Service; maintain security, prevent abuse, debug problems, and comply with legal obligations.
We do not sell your personal data, and we do not use your health data for advertising or share it with data brokers.
Where GDPR or UK GDPR applies, we process your data on these bases: contract performance (account, workout, activity, route, and purchase data needed to deliver the Service); explicit consent (location data and music listening data — you may withdraw consent at any time in your device settings or the app; Apple Health / Health Connect metrics are read on your device under your permission and are never transmitted to us); legitimate interests (security, fraud prevention, crash diagnostics, usage analytics, service improvement, and showing contextual ads); and legal obligation where we must retain or disclose data by law.
This is a fixed policy, not a setting you have to find. Your Apple Health / Health Connect metrics are never uploaded — readiness analysis runs entirely on your device. Mapbox’s usage telemetry is switched off. GPS coordinates are stripped from an activity before it is uploaded, and Kardiacs does not send your activities to any other service — if you want a ride on Strava or Garmin Connect, you export the file and share it yourself, which puts that choice in your hands each time. Routes are planned on your device — the search that builds them runs on your phone against map data it has already downloaded, so no route request, start point, or destination is sent anywhere. When you search for an address, the text you type goes to our maps provider to find it, and the map's centre goes with it to bias results toward where you are looking — rounded to about a kilometre, never your exact position. Weather forecasts are requested for the same rounded position. Map, route, and elevation tiles are requested by tile, which identifies an area of several kilometres rather than a place.
One deliberate exception applies on every platform: routes you choose to keep — favorites and GPX files you import — upload to your own account so they appear on your other devices. They describe a route’s shape rather than a record of where you have been, and they are never shared with other users. Separately, maps, navigation, and address search send your position to look up directions, addresses, and elevation as you use them; those lookups return an answer and are not stored as your data.
The public site at kardiacs.com is static: it has no accounts, no forms, no analytics, and no advertising, and it sets no cookies.
The dashboard at app.kardiacs.com signs you into the same account the apps use and is another client of the same service — the profile, equipment, activity and route data it shows is the data described above, not a separate collection. Three things are kept in your browser by us: your sign-in tokens, held in session storage and discarded when you close the tab; the short-lived values that secure the sign-in exchange itself; and your light/dark preference. None of those is an advertising or tracking identifier. The dashboard also carries advertising, and Google may set its own cookies or browser storage for that — see Advertising above.
Routes are planned in your browser, exactly as they are on your phone. The dashboard downloads the same map and terrain tiles for the area you are planning in and runs the same route planner locally; no route, start point, or destination is sent to us or to any mapping provider. Importing a GPX file reads it in the browser — the file is not uploaded.
The public site at kardiacs.com carries no advertising; the signed-in dashboard does.
We share data only as needed to operate the Service:
| Recipient | Purpose | What they receive |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, and authentication for all Service data | All data described above, stored in our AWS environment |
| Anthropic | Cloud AI-generated suggestions (e.g., daily workout playlists, when you use the cloud AI engine) | The prompt content needed for the suggestion (e.g., workout characteristics and your music-taste summary); not your identity, account, or health records |
| Google (Firebase, AdMob, AdSense) | Crash reporting, usage analytics, remote configuration, push notifications, banner ads in the apps, and advertising on the signed-in dashboard | Device and app information, crash reports, analytics events, push token, and ad-request data as described above; not your health records or activity contents |
| Sentry (Functional Software, Inc.) | Crash and performance monitoring | Crash reports, device context, and diagnostic breadcrumbs (e.g., trainer Bluetooth connection events); not your health records |
| Mapbox | Outdoor maps and address search | Map tile requests for the area being displayed, the text of an address search with a position rounded to about a kilometre, and your IP address. Routes are planned on your device, so no route, start point, or destination is sent to Mapbox. Mapbox usage telemetry is disabled |
| Amazon Web Services — Registry of Open Data | Elevation (terrain) data used to calculate climb and to plan routes over hills | Requests for the public terrain tiles covering the area you are viewing, planning in, or have downloaded for offline use, which include your IP address; the tiles are open data served from a public bucket, and no account or identifier of yours is sent with the request |
| Strava, Spotify, and other services you connect | Features you enable (importing your past activities from Strava, playlists) | Only the data needed for that integration, under your authorization. Kardiacs does not upload your activities to Strava — the connection reads your history in, it does not send anything out; governed by their own privacy policies |
| Cloudflare | Hosting and delivery of the websites, and protecting them from abuse | The requests your browser makes to kardiacs.com and app.kardiacs.com, including your IP address, browser user agent, and the pages requested. Cloudflare acts as our processor for this and does not receive your account or health data |
| Apple / Google | App distribution | Platform data under their policies |
Some AI features run entirely on your device: the daily readiness narrative and, when you choose the on-device engine, music suggestions. On iPhone this uses Apple Intelligence (Apple's on-device Foundation Models); on Android it uses Gemini Nano through Android's AICore. The health metrics used to write the readiness narrative are processed only on your phone and are never sent to us or to any AI provider for that feature.
We may also disclose data if required by law, to protect rights and safety, or as part of a merger or acquisition (in which case this policy continues to apply to data collected before the change, and we will notify you of any new controller).
We keep your data for as long as your identity — anonymous or account — is active. Activities, workouts, and saved routes remain stored so you can access your history. If you sign in, the data stored under your anonymous identity is merged into your account and the anonymous identity is deleted; where the account already holds a copy of something, the account's copy is kept.
Inactivity. If you do not use the Service for 59 consecutive days, we delete all of the data stored for your identity — including your activities, workouts, saved routes, profile, and equipment settings — whether or not you ever created an account. Any use of the app that reaches our servers counts as activity and resets this period, so simply opening the app and recording, syncing, or saving anything keeps your history. This deletion is permanent and we cannot recover the data afterwards. If you want to keep a copy of your history, you can export your activities as FIT files at any time.
When you delete your account — or, if you never created one, use Delete My Data in the app — we delete your personal data from our production systems within 30 days, and from backups within 90 days, except where the law requires longer retention. You can also delete individual activities, workouts, and routes in the app, and disconnect third-party services at any time (which deletes the stored tokens).
Data is encrypted in transit (TLS) and at rest in our AWS storage. Access to your data is authenticated with your identity's token, and our backend enforces per-identity isolation so no identity — anonymous or account — can access another's data. Third-party service tokens are stored server-side rather than on your device where practical. No system is perfectly secure; if a breach affects your personal data we will notify you and regulators as required by law.
Our servers are located in the United States. If you use the Service from the EU, UK, or elsewhere, your data is transferred to and processed in the US. For EU/UK data we rely on appropriate safeguards, including the EU–US Data Privacy Framework (where our providers are certified) and Standard Contractual Clauses.
Depending on where you live, you have the right to access, correct, delete, and receive a copy of your personal data, to withdraw consent, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. You can exercise most of these directly in the app (export your activities as FIT files, delete data, and delete your account — or, without an account, delete everything stored for your anonymous identity) or by emailing legal@kardiacs.com. We respond within the timelines required by law (generally 30 days under GDPR, 45 days under California law).
EU/UK: you may lodge a complaint with your data protection authority. California: we do not sell personal information. If you allow the advertising identifier at the App Tracking Transparency prompt, our advertising may constitute "sharing" for cross-context behavioral advertising under the CCPA/CPRA. Declining that prompt leaves your ads unpersonalised; you may also contact us with any request. We collect the categories described in Section 1 for the purposes in Section 2; you may exercise your rights via the contact above, including through an authorized agent. We treat similar rights under other US state privacy laws equivalently.
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. Onboarding requires a date of birth and does not proceed for anyone under 16 — no identity is created and nothing is stored on our servers before that check passes. On devices that support it we also ask Apple for the age range declared on your Apple Account and use it to check the date of birth you gave us; where the two disagree we apply the lower age, so a declared range below 16 stops onboarding just as a date of birth below 16 does. For a child, and for a teenager in a Family Sharing group, that range is set by their guardian.
Accounts require you to be at least 18. Sign-in is refused below that age, and if we determine that an existing account belongs to someone under 18 we sign that account out — the account and the data stored under it are retained, and they may sign in again once they turn 18. Structured workouts are also restricted to users 18 and over, and users under 18 are never shown personalised advertising (see “Advertising” above).
If you believe a child has created an identity or account, contact us and we will delete it.
We may update this policy from time to time. For material changes we will notify you in the app or by email before they take effect. The effective date at the top always reflects the current version.
Kardiacs LLC
Email: legal@kardiacs.com