Skip to main content

Privacy Policy

Last updated September 6, 2026

Athlon is a fitness-coaching app that organizes your training, syncs data from wearables and workout apps you choose to connect, and uses AI to help you plan and reflect on your training. This policy describes what we collect, how we use it, and how you can remove it.

Athlon is operated by JC Technologies LLC. The current release is Explore, a map of bathrooms, water fountains and tracks. The sections below on connected providers and AI coaching describe features that arrive in later releases; nothing in them is collected until you use those features.

We take the position that the data is yours. We store it to make the app work; we do not sell it, license it to third parties, or use it to train public AI models.

Location

Explore uses your device’s location, with your permission, to show your position on the map, to compute distances and walking directions, and to attach a crowd report to where you are standing. Location is read only while the app is open and is not stored except as part of a crowd report you submit. Denying location leaves the map usable; you can search for a place instead.

Explore contributions

When you add a place, suggest an edit, confirm or deny a spot, leave a review, report a crowd level, report content, or hide a contributor, we store that contribution with your account. Places, edits and reviews are visible to other users; crowd reports are aggregated; abuse reports and hidden-contributor lists are private to you and to our moderation. We filter submitted text and act on reports within a day. If you delete your account, your reports, crowd reports and blocks are deleted with it, and places you added remain on the map with no link to you.

What we collect

From you directly:

  • Account info (email, name, password hash) via Supabase Auth.
  • Profile details you enter: age, biological sex, height, weight, goals, preferred training split, timezone, distance unit.
  • Workouts, sets, intervals, and notes you log in the app.
  • Health documents you upload (lab results, imaging) — stored in a private, per-user storage bucket.
  • AI chat messages and the responses Athlon generates.

Connected providers

You can connect third-party services. Athlon requests only the scopes listed below and writes to a service only where its entry says so.

WHOOP

If you authorize WHOOP, Athlon may request the following scopes: read:recovery, read:cycles, read:sleep, read:workout, read:profile, read:body_measurement, and offline (to keep syncing in the background). We fetch recovery scores, sleep stages, physiological cycles, workouts, profile, and body measurements to power the recovery- and strain-aware features in the app.

Strava

Activity and profile read scopes, to display your workouts alongside in-app logs and attribute them to gear.

Hevy

API key read access, to import your routines and strength workouts.

Apple Health (planned)

Read access to activity, sleep, and body data on your device.

Google Calendar

If you connect Google Calendar, Athlon requests the https://www.googleapis.com/auth/calendar scope. It uses that access to create a calendar named “Athlon” in your Google account and to create, update and delete workout events inside that calendar, and to read changes you make to those events so both sides stay in sync. Athlon does not read, modify or share events in any other calendar. Google Calendar data is used only to provide this sync; it is never sold, used for advertising, or used to train AI models. Athlon’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Disconnecting Google Calendar in Settings revokes the grant and removes the stored tokens.

How your data is stored

  • Databases and file storage are hosted on Supabase with row-level security: your rows are readable only by your authenticated session.
  • OAuth access and refresh tokens and third-party API keys are encrypted at rest with AES-256-GCM before being written to the database.
  • Backend services run on Vercel; traffic is TLS-encrypted in transit.
  • Tokens are never sent to your browser. All provider API calls happen server-side.

How we use your data

  • To display your workouts, recovery, sleep, and body metrics in the app.
  • To generate AI suggestions (e.g. recovery-adjusted workout recommendations, chat answers). Prompts may include a subset of your recent metrics and workouts to give the model relevant context.
  • To sync newly imported workouts to connected calendars.
  • To send transactional email (account actions, errors).

We do not sell or license your data. We do not share it with third parties for advertising. We do not use your data to train third-party AI models; model providers we use (e.g. Anthropic via the Vercel AI Gateway) operate under agreements that prohibit training on our traffic.

Map tiles and imagery come from Apple Maps on iOS, including Look Around, and from CARTO, MapTiler or Esri on the web; those services receive your device’s map requests. Place data comes from OpenStreetMap and from other users. Sign in with Apple and Google receive only what you authorize at sign-in; if you hide your email with Apple, we hold the relay address Apple provides. We use Sentry for error reports and Vercel Speed Insights for page performance; neither is used for advertising.

Retention and deletion

  • Disconnecting a provider removes the provider tokens and the data Athlon synced from that provider, typically within minutes. This includes derived rows (sleep summaries, recovery scores, cycles) sourced from that provider.
  • Deleting your account removes everything we hold about you — workouts, health documents, chat history, provider connections, and your Explore reports and blocks — via a cascade delete from your user record. Places you added to the map stay, with no link to you.
  • We retain de-identified aggregate statistics (e.g. error counts, sync durations) for operations and reliability.
  • A deletion audit log records when a provider disconnect happened for compliance; it contains no user-identifying data beyond the user id for the time window needed.

Your rights

  • Access & export: email us to request a copy of your data (workouts, provider data, health documents, chat history, contributions) in JSON or CSV.
  • Correction: edit profile fields and workouts directly in the app.
  • Deletion: disconnect individual providers from Settings, or delete your account to purge everything.
  • Portability: exports are in open formats so you can move your data to another service.

Not a medical service

Athlon is not a medical or healthcare service. We are not a HIPAA Covered Entity or Business Associate, and nothing shown in the app is medical advice. Do not rely on Athlon to diagnose, treat, or manage a health condition. Talk to a qualified clinician for medical questions.

Children

Athlon is not intended for children under 13. If you believe a child has provided data to us, email the address below and we will delete it.

Changes to this policy

We may update this policy as Athlon evolves. Material changes will be announced in-app. Continued use after a change means you accept the updated policy.

Contact

Questions, requests, or data concerns:

JC Technologies LLC. john@athlon.dev.