Privacy Policy
Last updated: August 11, 2026
- We use your training data to personalize plans and insights.
- You control which integrations are connected and can disconnect anytime.
- You can request access, export, or deletion of your data.
SHIFT ("we", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our training platform.
2.1 Information you provide
- Account data: name, email address, date of birth, password
- Athlete profile: weight, height, FTP, training history, experience level
- Training goals, target races, and discipline preferences
- Communications with coaches and support
2.2 Information from connected services
- Training sessions and activity data from Strava and Garmin Connect
- Health metrics (HRV, sleep, recovery scores) from Oura, WHOOP, and Ultrahuman
- Body composition data (weight, body fat) from Withings
- Activity and health data from Health Connect (Android)
All third-party connections use OAuth 2.0. We store refresh tokens encrypted with AES-256-GCM. You can disconnect any integration at any time from your account settings.
2.3 Information collected automatically
- Platform usage data and interaction events
- Technical information: IP address, browser, device type, operating system
- Error and performance diagnostics
2.4 Health and safety screening
- Injury information you enter during onboarding: a free-text description and, where you select them, structured injury flags (such as the affected area)
- When you chat with the AI coach, your messages are screened in real time for emergency-symptom phrases so we can direct you to seek medical care; these messages are not stored as a medical record
We collect this information only to keep your training safe — to flag contraindications before a plan is generated or adjusted, and to gate unsafe recommendations. It is treated as sensitive, is visible only to you and your assigned coach, and is never sold or shared with advertisers or other third parties.
- Generate personalized AI training plans tailored to your goals and fitness
- Track your performance, training load (CTL/ATL/TSB), and progress over time
- Enable coach oversight, feedback, and coaching assistance
- Improve our services, algorithms, and user experience
- Send important training notifications and plan updates
- Comply with legal obligations
Marketing email and unsubscribe
With your account you may receive occasional product and lifecycle email (such as weekly summaries, tips, and news). Every marketing message includes a one-click unsubscribe (the List-Unsubscribe one-click standard, RFC 8058) as well as an in-message link. Unsubscribing takes effect immediately and stops marketing email without affecting essential account email (verification, password reset, and security notices). You can also change your email preferences from your account settings.
We use AI services from Anthropic (Claude) and OpenAI to generate training plans, coaching responses, and athlete insights. When processing a request:
- Your training data, health metrics, athlete profile, and conversation history may be sent to the AI provider as context
- AI providers process this data to generate a response and do not permanently store your data after processing
- We do not permit AI providers to use your data to train their models
You may opt out of AI-powered features by contacting support. Without AI processing, personalized plan generation will not be available.
Who we share your data with:
- Your coach: Access to your profile, plans, and performance metrics
- AI services: Anthropic and OpenAI (as described in Section 4)
- Integrations: Strava, Garmin, Oura, WHOOP, Ultrahuman, Withings, Health Connect (only with your authorization via OAuth)
- Service providers: Hosting (Vercel, Fly.io), error monitoring (Sentry), email delivery
We do not sell your personal information to third parties.
We implement technical and organizational security measures to protect your information:
- Encryption in transit: All connections use HTTPS/TLS
- Password hashing: Passwords are hashed with bcrypt and never stored in plaintext
- Token encryption: Integration tokens are encrypted at rest with AES-256-GCM
- Database security: PostgreSQL with row-level security (RLS) policies
- Access controls: Role-based access; coach access limited to assigned athletes
- Monitoring: Security and error monitoring with Sentry
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update incorrect information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a structured format
- Restriction: Limit processing of your data
- Objection: Object to certain uses of your data, including AI processing
To exercise these rights, contact: support@shifttraining.app
We keep your information while your account is active or as needed to provide services.
When you request account deletion, your profile, training plans, health records, chat history, and personal settings are permanently deleted within 30 days.
Certain operational records may be retained in anonymized form for a limited period after account deletion:
- Audit logs: up to 180 days
- Email delivery logs: up to 90 days
- Product analytics events: up to 365 days (anonymized upon account deletion)
- Error logs: up to 30 days
These retained records have personal identifiers removed and are used only for service reliability, security monitoring, and legal compliance.
We use essential cookies to:
- Keep you signed in
- Remember your preferences (language, dark/light theme)
Third-party analytics
We use Vercel Analytics and Speed Insights to collect anonymous, aggregated performance metrics. These tools do not use cookies and do not collect personally identifiable information. They are loaded on all pages.
First-party product analytics
We collect product usage events (such as page views, feature usage, and onboarding progress) to improve the product experience. These events may be associated with your account and include technical context such as device type, referral source, and session identifiers. This data is used internally and is not shared with third parties.
We also collect lifecycle events (such as plan requests, integration connections, and coaching interactions) to understand how the product is used and to improve the experience. These events are forwarded to Vercel Analytics.
There is currently no user-facing opt-out for product analytics.
First-party activation identifier
Before you create an account we generate a first-party identifier that is stored locally on your device (not a third-party cookie or advertising ID). We use it to measure activation — understanding whether visitors who reach the product go on to complete sign-up and onboarding — and to help prevent abuse and fraudulent sign-ups. This identifier is strictly necessary for those purposes, remains first-party, and is not shared with third parties.
SHIFT is designed for athletes aged 13 or older. If you are under 16, you need parental or legal guardian consent to use the platform.
Your data may be processed on servers located outside your country of residence (U.S., Europe). We implement appropriate safeguards to protect your information during these transfers.
We may update this policy from time to time. We will notify you of significant changes by email or via a notice in the platform. The "Last updated" date at the top indicates when it was last modified.
For questions about this Privacy Policy or how we handle your data:
- Email: support@shifttraining.app
- Data controller: SHIFT Training Platform