Privacy Policy
EVAD ("the app", "we") is a personalized athlete training app operated by Trackside Athletics LLC, a Utah limited liability company. This policy explains what data the app collects, how it is used, and your choices. We keep this short and accurate to what the app actually does.
Information you provide
- Account: your email address and password, used to create and secure your account. Authentication is handled by Supabase (our backend provider); we never store your password ourselves. You may instead sign in with Apple (Sign in with Apple), in which case Apple provides your name and an email address (or a private relay address) to create your account, or with Google (Sign in with Google), in which case Google provides your name and the email address on your Google account.
- Athlete profile: information you enter to personalize your training — including your name, age, sport, event/specialty, team level, season and next competition, primary goal, target timeline, training days and session length, equipment and facility access, body weight, height, years training, experience level, training-style and intensity preferences, personal records (PRs), any injury notes, your typical hours of sleep per night, and how you rate your current stress and your school or work load. The app also reads your device's time zone and stores it with your profile so your program's start and target dates line up with your local calendar.
- Training activity: workouts you log (exercises, sets, reps, loads), completed sessions, daily goals, supplements you track (name, dosage, timing, and notes), and journal entries (including mood and notes).
How your information is used
- To generate and display your personalized training program and daily focus goals.
- To track your progress, calendar, and history across the app.
- To keep you signed in and sync your data across your devices.
We do not sell your data, show third-party advertising, or use third-party analytics/tracking SDKs.
Product analytics
To understand how the app is used and improve it, we record first-party product-usage events — for example, which screen you're on and which features you interact with — in our own app_events table. These events are linked to your account (user ID) but never leave our own backend. We do not use a third-party analytics SDK, and we do not track you across other apps or websites. Athlete-entered values (profile fields, workout numbers, journal text) are not included in these events.
Some of these events are recorded before you have an account. If you go through setup while signed out, the app holds them in storage on your own device and sends us nothing. When you create an account — or sign in to an existing one — at the end of that same setup, those events are attached to that account and uploaded then, so their timestamps can predate the account itself. If you never sign in, they stay on the device and are never sent to us. Like every other event described here, they contain no athlete-entered values: they record which setup steps you reached, and whether a sign-in attempt started, succeeded, failed, or was cancelled, along with the method used and a generic error category.
Crash and diagnostics
If the app crashes or hits an error, we collect a diagnostic report to help us fix it: the error message and stack trace, the screen you were on, the app version and build, and basic device information (platform, OS version, device model). These reports are linked to your account so we can reproduce the issue, and are stored in our own crash_reports table. We do not use a third-party crash-reporting SDK.
CREW — social features
CREW is EVAD's optional social layer, and it stays off until you claim a handle and accept the CREW community terms. Doing so creates a CREW profile — your handle, display name, bio, sport, and your Coach EVAD mascot loadout — which other athletes can find by searching your handle. Your athlete profile (PRs, body weight, age, injury notes) is stored separately and is never shown on CREW.
CREW is friends-only. Your account is private from the moment you claim a handle: a follow arrives as a request, and nothing you post is visible to anyone until you approve them. There is no public feed, no way to post to everyone, and no direct messages. Every post is either My Crew (the athletes you have approved) or Only me — those are the only two options, and our servers refuse a post published any wider. If you are under 16 you cannot turn the approval step off at all.
What you publish to CREW — posts and the workout/PR/streak card they render, captions, comments, likes, and your follower and following lists — is visible to the approved followers the post is addressed to. CREW carries no photos or other uploaded images: a post is a card generated from your own training data plus the text you write, and there is no way to attach a file to one. In Profile → CREW & Privacy you can change which of the two visibilities new posts default to, and turn off discoverability so your handle stops appearing in athlete search. Saves are private to you.
Safety signals. You can block another athlete, and you can report a post, comment, or profile. A report records who reported what, the reason you selected, and any note you add. Reporting a post or comment hides it from you straight away, and it stays hidden from you. It is hidden from everyone automatically once three different athletes whose accounts are at least a week old have reported it — a threshold that stops a couple of brand-new throwaway accounts from taking down someone else's post. Reports from newer accounts still reach us. We review reports ourselves so we can hide or remove content and act on accounts, and reporting a profile is always a manual call rather than an automatic one. Blocks and reports are not disclosed to the person you blocked or reported.
You can delete any post or comment you posted at any time. Deleting your account removes your CREW profile, posts, comments, likes, saves, and follows along with the rest of your data.
Website link analytics
Our website uses short attribution links of the form evadtraining.com/go/<channel>/<campaign> in social posts and ads. When you tap one, we redirect you to the site's home page and record one first-party click event: the channel and campaign tag from the link itself, the referring page address truncated to 200 characters, the two-letter country code Cloudflare's edge derives from the connection, and the browser user-agent string truncated to 128 characters (so we can filter out link-preview bots).
That event is written to Cloudflare Analytics Engine — the same infrastructure that already serves the site. It sets no cookie, stores no IP address, and is not linked to your EVAD account or to any other event. We use it only to count taps per channel. The website uses no third-party analytics or advertising trackers.
Data retention and deletion
We keep your profile, program and training history for as long as your account exists, so your progress stays intact across your devices. Product-usage events are kept for up to 180 days after we receive them and are then deleted by a daily cleanup; the navigation events that record which tab or screen you opened are deleted after 45 days. Crash reports and the AI usage log described under 'AI program generation' are not aged out on a fixed schedule. Product-usage events, crash reports and the AI usage log are all removed when you delete your account. Two things have their own clocks: the abuse counters described under 'AI program generation' expire after 2 and 48 hours, and the website click events described under 'Website link analytics' are kept no longer than Cloudflare Analytics Engine retains them.
When you delete your account from Settings → Delete Account, the account itself is removed immediately: your login is destroyed, your records cascade out of our database, and the account cannot be signed in to or recovered. If you signed in with Apple, we also ask Apple to revoke the app's sign-in link — that step needs a quick Apple confirmation at delete time, and if you skip that prompt the link simply remains on Apple's side (you can remove it yourself in Settings → [your name] → Sign in with Apple).
Some of that work happens outside the database — sweeping any residual stored files, clearing the rate-limit counters keyed to your account, and completing the Apple revocation — and any one of those steps can fail for reasons on a provider's side. Rather than report a partly finished deletion as done, we record the deletion as a durable job and retry the remaining steps automatically: the first retry is about 15 minutes later, and repeated failures back off to at most 8 hours between attempts. Most residual cleanup finishes within hours. That job record is kept either way — see below. If a step is still failing after 30 attempts we stop retrying and leave it for a person to finish by hand, rather than claim a cleanup that never happened. The Apple revocation is the one exception: its credential is single-use and short-lived, so we retry it only a handful of times, and if it still fails we record that outcome permanently instead of holding the credential — the sign-in link then stays removable on Apple's side as described above. Deletion is irreversible — once your account is deleted we do not restore it or its data.
Some records outlive your account:
When our automatic content filter flags text you entered on your CREW profile — your handle, display name, bio, or sport — it stores a moderation record holding your account identifier and a short excerpt (up to 300 characters) of the flagged text. That record is not attached to a post, so the deletion cascade does not remove it; we keep it to act on repeat abuse and to meet our legal obligations, and it is never shown to other athletes. Flags on posts and comments are deleted along with the post or comment itself.
We also keep the deletion job itself. It records your account identifier and the time each cleanup step finished, and we keep it whether the deletion succeeded or failed — it is the only proof we have that a deletion was asked for and carried out. It holds no training data, no journal entries, and no profile text, and only we can read it.
AI program generation
Nothing is sent until you say yes. Before EVAD builds your first program it shows you a card listing the categories of profile data that would go to Anthropic — including the health-adjacent ones such as your age, body metrics, injuries, sleep and stress, and post-practice check-ins — and naming what is not sent: your name, your email, your password, your journal entries, and your CREW posts. Our server enforces this: until you agree, a generation request is refused. You can change your answer at any time in Settings, under 'AI program generation'. Turning it off stops anything further going to Anthropic and stops EVAD building or adjusting programs for you, though the program you already have stays exactly as it is; you can turn it back on whenever you want. If we materially change what gets sent, we ask you again. We keep a record of your decision, when you made it, and the version of the disclosure you saw — that record is included in your data export.
When you generate a training program or daily goals, the relevant parts of your athlete profile and recent training context are sent to Anthropic's Claude API to produce the program text. This request is routed through our own secure server (a Cloudflare Worker) and is gated by your signed-in session. We do not send your email, password, or journal entries for this purpose beyond the training context needed to build the program. Anthropic processes this data under its own terms and, for API usage, does not use it to train its models by default.
To stop one person from running up the cost of that service, our proxy admits each request against short-lived abuse counters. Those counters are keyed by a salted, truncated hash of the network address the request arrives from — we do not store the address itself — and each counting window closes after 2 or 48 hours: once it closes it stops counting, and the next request starts a fresh window at zero. The row holding that hash and its count stays in our database until we clear it. Counters are used for rate limiting only, never to profile or track you. A shortened form of that same hash also appears in the operational logs described under 'Where your data is stored'.
We also keep an operational record of each AI request so we can see what the service costs us and catch failures: which route ran, which program and phase it was for, which model answered, how many tokens the call used, how long it took, how many retries it needed, whether it succeeded, and the provider's request identifier and error category. These rows are linked to your account, and they hold identifiers and counts only — no prompt text, no profile values, and no program content. They are our own cost and reliability records rather than data you authored, so they are not included in the export file (the file itself says so); they are removed when you delete your account.
Where your data is stored
Your data is stored in a Supabase (PostgreSQL) database with row-level security, so your records are only accessible to your authenticated account. Data is transmitted over encrypted connections (HTTPS/TLS).
We protect it with the controls we can actually point at. Your records sit behind row-level security, so a query can only return rows belonging to your authenticated account. Everything travels over encrypted connections (HTTPS/TLS). On your phone, the token that keeps you signed in is encrypted at rest with a key held in the iOS Keychain rather than stored as plain text — your password itself is never stored by us at all. After repeated wrong-password attempts for the same email, the app stops accepting further attempts on that device for 15 minutes; this is a speed bump on that device, not a lock on your account, and our authentication provider applies its own limits on top of it. Our website is served with HSTS, a strict content-security policy, and framing and MIME-sniffing protections. No system is perfectly secure and we will not tell you otherwise — but if we ever discover a breach affecting your personal information, we will notify you, and any regulator we are required to notify, as promptly as we can once we understand what happened.
We also make an encrypted backup of the database on a daily schedule, so an outage or a mistake cannot lose your training history. The backup is encrypted on our own computer with a passphrase only we hold, before it leaves that computer, and the encrypted file is then stored in the operator's Apple iCloud Drive. Apple holds only the encrypted file and cannot read what is inside it.
Our server also keeps short-lived operational logs so we can diagnose errors and abuse. A log line records what happened — which route was called, which limit was hit, which step failed — along with the first eight characters of your account id and a short prefix of the same salted hash of the network address described under 'AI program generation'. These lines are not written to hold your personal information, but when generation or a database write fails, the error text they capture can include parts of the generated program (for example exercise names) or the technical error returned by our database. They never contain your password. Cloudflare retains these logs for a limited period set by our hosting plan and then deletes them automatically; they are not kept indefinitely and we do not archive them elsewhere.
Data sharing
We share data only with the service providers that operate the app and site on our behalf:
- Supabase — authentication and database storage.
- Anthropic — AI generation of program/goal text, as described above.
- Cloudflare — the secure proxy that routes AI requests, the hosting and content delivery for our website, and the first-party click counts described under "Website link analytics".
- Apple — Sign in with Apple (if you use it), App Store purchases if we ever offer paid features, revoking the Apple sign-in link when you delete your account, and iCloud Drive, which stores our encrypted database backups (Apple stores the encrypted file and cannot read its contents).
- Google — Sign in with Google (if you use it). Google receives the sign-in request and confirms who you are to us; we receive your name and the email address on your Google account. Google is not sent your training data, and we use no other Google service.
- ntfy.sh — a notification service that pages us when CREW reports are waiting to be reviewed, so we can get to them quickly. It receives only totals: how many reports are open, how many items they concern, how long the oldest has waited, and how many were flagged severe. It never receives your identity, your handle, or anything you or anyone else posted.
Other than the providers named above, we do not share your data with any third parties — no advertisers, no data brokers, and no third-party analytics or tracking services. We do not sell your data.
Your choices and rights
- Access/update: you can view and edit your profile, goals, and metrics in the app's Settings.
- Export your data: you can download a copy of your account data as a
.jsonfile from Settings → Export My Data — your profile and training history, your CREW profile and content, your consent records, and the product-analytics events recorded about your use of the app. The file itself names what it deliberately leaves out. - Control what CREW shows: your account is private by default and follow requests need your approval — athletes 16 and over can turn that approval step off, and under 16 it always stays on. You can also set each post's visibility (My Crew or Only me), change your default, approve or remove followers, turn off discoverability, block athletes, and delete any post or comment you posted — see "CREW — social features" above.
- Delete your account: you can permanently delete your account and all associated data — including your CREW content, your product-analytics events, and your crash/diagnostic reports — from Settings → Delete Account. The account is removed immediately and irreversibly; the residual cleanup described under "Data retention and deletion" continues automatically afterwards, and the records that outlive the account are described there.
- Questions or requests: contact us at the email below.
Children's privacy
EVAD is not directed to children under 13, or under 16 in the European Economic Area, and we do not knowingly collect personal information from them. If we learn that an account belongs to someone below the age that applies where they are, we contact the account holder, give them a chance to export their data, and close the account.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
For privacy questions or data requests, contact: evad.training.support@gmail.com