Privacy Policy
Effective date: June 15, 2026
1. Introduction
Tracklete ("we", "our", or "the app") is an athlete performance platform that helps athletes track workouts, discover coaches, and connect with training communities. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it. By using Tracklete you agree to this policy.
2. Data we collect
Account & profile
- Email address — required for one-time-code (OTP) sign-in.
- Profile details — name, role (athlete/coach/admin), gender (optional), university or institution affiliation, and coach connection state.
Health & performance
- Apple Health / Google Health Connect data — when you grant permission, we read steps, distance, active energy (calories), heart rate, and sleep. This is read on-device; a daily summary subset is uploaded so your coach can see trends.
- Workout sessions — duration, distance, pace, calories, activity type, and (for outdoor workouts) the GPS route of your session.
- Evaluations — ratings (performance, endurance, technique, attitude) entered by your coach.
Location
- Approximate & precise location — used while you are actively in the app to draw your run/ride on a live map, compute distance and pace, and find coaches and communities within 30 km. We do not track location in the background.
Community content
- Community memberships, posts, and check-ins you create within Tracklete.
Pluto AI
- When you use the Pluto AI assistant, your questions plus relevant context (recent workouts, evaluations, streak) are sent to OpenAI to generate responses. We disclose this and require your consent the first time you open Pluto.
3. How we use your data
- Provide the core functions — tracking workouts, connecting you with coaches, generating AI insights.
- Calculate metrics like calories, pace, and progress trends.
- Match you to nearby coaches or communities based on location.
- Diagnose crashes and improve the app.
We do not sell your data, run cross-app tracking, or use your data to train third-party AI models.
4. Third-party services
- Supabase — backend database + authentication. Your profile, workouts, health summaries, GPS routes, evaluations, and community content are stored on Supabase infrastructure.
- OpenAI — the language model behind Pluto AI. The text of your Pluto conversations plus a small context snippet are sent to OpenAI to generate responses.
- Apple HealthKit / Google Health Connect — on-device health frameworks. We only read the categories you authorize.
- Resend — delivers your sign-in code emails.
5. Your rights
- Access — view your profile, workouts, and history any time in the app.
- Delete — Settings → Delete Account permanently removes your account and all associated data within 30 days.
- Revoke permissions — Health and Location can be revoked any time in your device settings.
- Revoke Pluto AI — Settings → Pluto AI lets you withdraw consent and clear your chat history.
- Export — email support@tracklete.app for a copy of your data.
6. Data retention
We keep your data while your account exists. On deletion, all rows associated with your user id are removed within 30 days. Backups containing your data are rotated out within 60 days.
7. Children
Tracklete is not directed to children under 13 and we do not knowingly collect their data.
8. Security
We use HTTPS for all data transmission and row-level security so you can only access your own data. Contact support@tracklete.app with any concern.
9. Changes
We may update this policy. Material changes will be communicated in-app before they take effect.
10. Contact
support@tracklete.app