Privacy Policy
Last updated: June 30, 2026
1. Overview
Your privacy matters to us. Leo generates revenue exclusively through subscriptions you pay — we do not sell, monetize, or share your data for advertising purposes.
This policy describes what data we collect, why we collect it, how we protect it, and what rights you have.
2. Data Controller
The data controller is Talaria, a sole proprietorship registered in France, operating the service "Leo - AI Running Coach".
Contact: [email protected]
3. Data Collected
We collect the following categories of data:
- Account data: name, email address (via secure authentication), Google account ID if you sign in with Google
- Runner profile data: age, weight, height, heart rate zones, preferred terrain, goals — provided voluntarily by you during coaching conversations
- Sports activity data: activities synced from Strava — and, if you connect it, Suunto or Polar — including distance, duration, elevation, heart rate, cadence, pace, GPS traces
- Health data: heart rate, wellness data (fatigue, sleep quality, soreness, biomechanical observations). This data is processed based on your explicit consent (GDPR Art. 9.2.a).
- Coaching data: your conversations with the AI coach, training plans, coaching decisions, and session feedback
- Payment data: managed exclusively by Stripe. We do not store any credit card numbers or banking details on our servers.
- Security data: IP addresses, device information, usage logs, and access timestamps — collected for fraud prevention and service security
- Communication data: emails and messages exchanged with our support team
4. Strava & Suunto Integration
Leo connects to your Strava account via OAuth 2.0 to sync your sports activities. Here are the details of this integration:
- Data retrieved: activities (type, distance, duration, elevation, heart rate, cadence, pace), athlete profile (Strava ID), gear (shoes)
- Token storage: Strava access and refresh tokens are stored securely in our database, encrypted in transit (TLS). We never store your Strava password.
- Data caching: Strava data is cached for a maximum of 7 days. Beyond this period, data is automatically deleted or refreshed from Strava. Data is refreshed automatically every 30 minutes to ensure accuracy and reflect any updates you make on Strava.
- Deletion sync: if you delete data from Strava, those deletions will be reflected in Leo within a maximum of 48 hours.
- Revocation and data deletion: you can revoke Leo's access to your Strava account at any time from Strava settings. Upon revocation, your Strava access tokens and all Strava-sourced activity data will be deleted from our database within 48 hours.
- Account deletion: if you delete your Leo account, all data including Strava-sourced data is permanently deleted from our systems.
- Strava write scope: when you connect Strava to Coach Leo, the consent screen includes the
activity:writepermission alongside read access. Strava lets you grant or decline this permission separately from the others. Granting it does nothing on its own — it simply allows Coach Leo to write the activity description enrichment described below, if you choose to turn it on. If you decline it, the connection still works and only the enrichment stays unavailable. - Activity description enrichment (off by default): the enrichment stays off until you turn it on yourself from /me → Notifications. Once enabled, a short, deterministic recap (plan vs actual, race countdown, XP earned) is appended to the description of each new running activity, 10 minutes after upload, in your own language. The recap is appended after any text you wrote — your own description is never overwritten. You can turn it off again at any time in the same place, or by revoking Strava access entirely from Strava settings.
- Visibility: a user's Strava data is only displayed to that user inside Coach Leo. No cross-user data sharing. The optional description blurb described above is visible only on the athlete's own Strava feed, exactly like any text the athlete writes themselves.
Suunto: Coach Leo also offers an optional Suunto integration. When you connect it, the same principles apply:
- Connection: Leo connects to your Suunto account via OAuth 2.0 through the Suunto Cloud API. We never store your Suunto password.
- Data retrieved: workouts and their metrics (type, distance, duration, elevation, heart rate, cadence, pace) — read-only. Leo never posts to or modifies your Suunto account.
- Token storage: Suunto access and refresh tokens are stored securely in our database, encrypted in transit (TLS).
- Revocation and data deletion: you can disconnect Suunto at any time from your Coach Leo settings, or revoke access from your Suunto account. Upon revocation, your Suunto tokens and Suunto-sourced activity data are deleted from our database. If you delete your Leo account, all Suunto-sourced data is permanently deleted as well.
- Visibility: your Suunto data is only displayed to you inside Coach Leo. No cross-user data sharing.
Your use of Suunto is also governed by Suunto's own Terms of Use and Privacy Policy.
Polar: Coach Leo also offers an optional Polar integration. When you connect it, the same principles apply:
- Connection: Leo connects to your Polar account via OAuth 2.0, through the Polar AccessLink API. We never store your Polar password.
- Data retrieved: workouts and their metrics (type, distance, duration, elevation, heart rate, cadence, pace) — read-only. Leo never posts to or modifies your Polar account.
- Token storage: the Polar access token is stored securely in our database, encrypted in transit (TLS) and at rest. On connection, an anonymous technical identifier is registered with Polar to link your AccessLink account to Coach Leo.
- Revocation and data deletion: you can disconnect Polar at any time from your Coach Leo settings, or revoke access from your Polar Flow account. On disconnect, the token and the activities imported from Polar are deleted.
- Visibility: your Polar data is only displayed to you inside Coach Leo. No cross-user data sharing.
5. Connected Watch Apps (Garmin Connect IQ and others)
Coach Leo offers companion apps that run directly on connected watches — starting with a Garmin Connect IQ app, with other platforms (Suunto, Apple Watch, etc.) to follow. These apps let you sign in to your Coach Leo account and follow your session of the day natively on your watch.
- Authentication (OAuth 2.0): you sign in to your Coach Leo account from the watch app via OAuth 2.0 (the login step happens on your phone). The app receives a Coach Leo access token and never sees your password. The token is stored on your device and used only to request your training data from Coach Leo.
- Data retrieved: once you are signed in, the app downloads your session of the day — the workout we prescribed for you (structure, target paces or heart-rate zones, distances and durations) — from the Coach Leo API as a workout file (e.g. FIT), so you can run it on your watch. The app does not read activity data back from your watch; your completed runs continue to reach Coach Leo through Strava (or another connected source).
- Data submitted to Coach Leo, not to the watch maker: any data the app collects or transmits in this flow — your authentication and the request for your daily session — is submitted to Coach Leo and is governed solely by this Privacy Policy. It is not submitted to Garmin (or to any other watch-platform provider), and Garmin is not responsible for the data handled by the Coach Leo app. Your separate use of the watch and its own companion app (for example Garmin Connect) remains governed by the watch maker's terms and privacy policy.
- Revocation: removing the watch app, or signing out of your Coach Leo account from it, stops any further data exchange. Deleting your Coach Leo account removes the associated access tokens as described above.
6. AI Integration
Leo operates as an MCP (Model Context Protocol) server that you connect to the AI service of your choice (Claude, ChatGPT, etc.). In this context:
- Your sports data is transmitted to the AI service only within the context of your coaching conversation
- We do not control the processing performed by the third-party AI service. Please consult the privacy policy of the service you use (e.g., Anthropic, OpenAI).
- Your data is not used by Leo to train AI models. However, the third-party AI provider's data policies apply to any data sent to their service.
- When using Leo via the web or mobile app, or messaging channels (Telegram, WhatsApp), conversations are routed through our servers and processed by the AI provider we select. In this case, your data is subject to both this policy and the AI provider's policy.
7. Purposes of Processing
Your data is processed for the following purposes:
- Provide personalized AI coaching service
- Generate adaptive training plans
- Analyze your performance and progression
- Prevent injuries through training load analysis
- Manage your subscription and billing
- Ensure the security and integrity of the service
- Respond to your support requests
- Improve the service (anonymized, aggregated usage analysis only)
8. Legal Basis
| Data type | Legal basis |
|---|---|
| Account data | Contract performance |
| Strava / Suunto training data | Explicit consent |
| Health data (HR, wellness) | Explicit consent (GDPR Art. 9.2.a) |
| Coaching data | Contract performance |
| Payment data | Contract performance & legal obligation |
| Security data (logs, IP) | Legitimate interest |
| Communication data | Legitimate interest |
| Session cookies | Strictly necessary |
9. Data Retention
- Account data: retained while your account is active + 1 year after account deletion (for compliance and dispute resolution)
- Coaching data: retained while your account is active, deleted upon account deletion
- Cached Strava data: maximum 7 days, refreshed automatically every 30 minutes
- Strava data upon revocation: all Strava-sourced activity data and access tokens are deleted within 48 hours of access revocation or account deletion
- Security data: retained for 1 year (rolling)
- Communication data: retained for 2 years from last interaction
- Billing data: retained per legal obligations (up to 10 years under French commercial law)
- Cookies: maximum 13 months
After account deletion, all personal data is permanently removed from our production systems within 30 days. Encrypted backups may retain data for up to 90 days before automatic purge.
10. Data Sharing
Your data may be shared with the following services:
- Better Auth (self-hosted on our servers): authentication and session management
- Stripe (US, EU): payment and subscription management
- Strava (US): activity sync (read-only)
- Suunto (Finland): activity sync (read-only), if you connect it
- Polar (Finland): activity sync (read-only), if you connect it
- AI providers: within your coaching conversations. When using the web or mobile app, or messaging, your conversations — including health and training data — are sent to Anthropic (Claude, United States) to generate Leo's responses. By default, Anthropic does not use these inputs or outputs to train its models. The public "Lab" Q&A feature uses DeepSeek and never includes your personal data. When using MCP, you choose your own provider.
- Hetzner (Finland): infrastructure hosting
- Cloudflare (US): CDN and DDoS protection
- PostHog (EU): Anonymous product analytics to improve the service. No personal data is stored in cookies.
We do not share any data with advertising platforms, data brokers, or advertisers, even with your consent (in compliance with the Strava API Agreement).
We may disclose data if required by law, legal process, or government request.
11. Data Security
- Encryption in transit (TLS/HTTPS on all endpoints)
- Self-hosted authentication with encrypted sessions
- Principle of least privilege for data access
- PostgreSQL database with restricted access
- Strava tokens stored server-side, not accessible to the browser
- Infrastructure hosted in Europe (Hetzner, Finland), behind Cloudflare
Breach notification: in case of a security breach involving personal data, we commit to notify Strava within 24 hours and the CNIL within 72 hours of discovering the incident. Affected users will be notified without undue delay.
12. International Data Transfers
Your personal data is primarily processed within the European Economic Area (EEA), on servers located in Finland.
Some of our service providers (Stripe, Strava, AI providers, Cloudflare) may process data outside the EEA, including in the United States. These transfers are governed by:
- The European Commission's Standard Contractual Clauses (SCCs)
- EU-US Data Privacy Framework certifications where applicable
- Adequate provider security certifications (SOC 2, ISO 27001)
13. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to portability: receive your data in a structured, machine-readable format (JSON/CSV)
- Right to object: object to processing based on legitimate interest
- Right to restriction: restrict the processing of your data
- Consent withdrawal: you may withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
14. Your Rights — US Consumers
If you are a resident of the United States, you may have additional rights under state consumer privacy laws, including the California Consumer Privacy Act (CCPA) and similar state laws.
- Right to know: you may request that we disclose what personal information we have collected about you, the categories of sources, and the purposes for which it is used.
- Right to delete: you may request the deletion of your personal information, subject to certain exceptions.
- Right to opt-out of sale: we do not sell your personal information. We do not share your data with advertisers, data brokers, or any third parties for monetary or other valuable consideration.
- Non-discrimination: we will not discriminate against you for exercising any of these rights.
To exercise any of these rights, contact us at [email protected]. We will respond within 45 days.
15. Cookies
We only use cookies that are strictly necessary for the service to function:
- Session cookie: required for authentication and maintaining your logged-in state
We use PostHog for anonymous session analytics to improve the service. PostHog runs in cookieless mode (in-memory only) — no tracking cookies or persistent identifiers are stored on your device. We do not use any advertising cookies. No cookie consent banner is required because we only use strictly necessary cookies.
16. Minors
Leo is intended for individuals aged 16 and over. We do not knowingly collect data from minors under 16 years of age. If you believe a minor has provided us with personal data, please contact us and we will promptly delete it.
17. Strava API Agreement Compliance
In compliance with the Strava API Agreement, we commit to the following principles:
- Strava data is displayed only to the authenticated user who generated it
- Strava data is cached for a maximum of 7 days
- We do not sell, share, or use Strava data for AI/ML model training
- We do not share any data with advertising platforms, data brokers, or advertisers
- Upon access revocation, tokens are deleted within 48 hours
- If a user deletes data on Strava, deletions are reflected in Leo within 48 hours
- We notify Strava within 24 hours in case of a data breach
- The "Powered by Strava" badge is displayed wherever Strava data is presented
Where you connect Suunto, we likewise comply with the Suunto Cloud API agreement we have signed with Suunto: Suunto data is shown only to the authenticated user who generated it, is never sold, shared with advertisers/data brokers, or used for AI/ML model training, and tokens and Suunto-sourced data are deleted upon access revocation or account deletion.
When you connect Polar, we likewise honor the Polar AccessLink API terms: Polar data is only displayed to the authenticated user who generated it, is never sold, shared with advertisers or data brokers, or used to train AI/ML models, and the token and Polar-derived data are deleted upon access revocation or account deletion.
18. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons.
For significant changes, we will notify you by email or through an in-app notification at least 15 days before the changes take effect. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
19. Contact & Complaints
For any questions regarding this policy or to exercise your rights:
Talaria — [email protected]
Physical mailing address: available upon request at [email protected]
If you believe that the processing of your data constitutes a violation of the GDPR, you have the right to lodge a complaint with your local data protection authority. For users in France, this is the CNIL (Commission Nationale de l'Informatique et des Libertes): www.cnil.fr