Skip to content

Legal

Consumer Health Data Privacy Policy

Last updated July 2026

CourseRecon — Consumer Health Data Privacy Policy Effective Date: 5 July 2026

This policy explains how CourseRecon handles consumer health data as defined by the Washington My Health My Data Act and Nevada SB 370. It supplements our general Privacy Policy and applies to all users; the appeal rights in section 6 are specific to Washington and Nevada residents.


1. Consumer Health Data We Collect

When you connect Strava or upload an activity file, we collect data that these laws treat as health data:

  • Heart-rate measurements, including per-reading heart-rate streams recorded during activities
  • Derived fitness and exertion metrics — training load, aerobic base, fatigue resistance, and the readiness scores we compute from your training
  • Precise location data of recorded activities (GPS tracks), which can reveal where you exercise
  • Biological sex and heart-rate zones, where present in your Strava profile
  • Self-reported effort and race-outcome information, if you take part in our validation study

We collect this data only with your consent, which you give when you connect Strava or upload an activity file, and only to the extent needed to provide the services you request.

2. Sources

  • Strava, via OAuth, after you explicitly connect your account
  • Activity files (FIT/GPX/TCX) you upload directly
  • Information you type into CourseRecon (e.g. survey responses)

3. How We Use It

  • To compute your course-specific race-readiness scores and training analysis (the core service)
  • To generate AI-written analysis of your readiness (see the Privacy Policy, §8.2)
  • To show your readiness to a coach — only if you accept that coach's invitation
  • To validate and improve our readiness model using study data you contributed

We do not use consumer health data for advertising, and we do not sell it. We do not use geofencing around health-care facilities or anywhere else.

4. Who We Share It With

Service providers (processors) acting on our instructions: Supabase (database hosting, USA), Vercel (application hosting and AI request routing, USA), Anthropic (AI-generated analysis, USA), Sentry (error monitoring — session replays have all text masked), and Resend (email delivery — message content only, not health measurements).

Your coach, only while you are a member of their squad: readiness scores, training summaries, and race entries. Leaving the squad removes their access and deletes their notes about you.

We have no affiliates, and we never sell consumer health data. Sharing beyond the above would only happen with your separate authorization, or where required by law.

5. Your Rights

  • Access and portability — see your data in the app anytime, and download everything we hold via Settings → Privacy → Download my data, or by emailing privacy@courserecon.app
  • Withdraw consent — disconnect Strava in Settings; this deletes our stored copy of your Strava activity data, including heart-rate and GPS streams
  • Delete — delete your account in Settings (removes all consumer health data we hold), or email us; study contributions are removed on request
  • We will never discriminate against you for exercising these rights.

We respond to requests within 45 days.

6. Appeals (Washington and Nevada residents)

If we refuse to act on a request, you may appeal by replying to our response or emailing privacy@courserecon.app with "Appeal" in the subject line. We will respond within 45 days. If your appeal is unsuccessful, you may contact your Attorney General:

7. Security and Retention

Consumer health data is stored with the safeguards described in our Privacy Policy §5 (encryption in transit and at rest, row-level security, least-privilege access) and retained only while you keep it on your account — disconnecting Strava or deleting your account removes it, and a daily retention process cleans up residual data.

8. Contact

Privacy contact: privacy@courserecon.app CourseRecon LTD, Auckland, New Zealand