hybridAF
Performance OS
← Back to hybridAF

Privacy Policy

Effective June 30, 2026 · Last updated June 30, 2026

This Privacy Policy explains how hybridAF ("hybridAF," "we," "us") collects, uses, stores, shares, and protects your information when you use our web and iOS applications and related services (the "Service"). We built hybridAF as a personal training, recovery, and planning tool, and we treat the data you entrust to us - including sensitive health and calendar data - with care. By using the Service you agree to this Policy.

1. Who we are

hybridAFis operated by an individual developer (the "operator"). For any privacy request or question, contact us at peeranatsugsavanvit@gmail.com. We act as the data controller for the personal data described below.

2. Information we collect

We collect only what the Service needs to function, in these categories:

  • Account & identity data - handled by our authentication provider (Clerk): your name, email address, username, and authentication credentials. Passwords are managed and hashed by Clerk; we never see or store your raw password. If you sign in with Google, we receive your basic profile and email from that provider.
  • Health & fitness data - if you connect a data source (Garmin or Strava, or Apple Health on our iOS app; WHOOP, Oura, and Fitbit are supported where enabled) or enter it yourself, we collect metrics such as heart-rate variability (HRV), resting and max heart rate, sleep stages and duration, steps, calories, body battery, stress, respiration, SpO₂, VO₂max, training load, bodyweight, and workout/activity details (including GPS-derived routes and streams where provided). This is sensitive personal data and is used solely to power your dashboards, recovery scoring, and training plan.
  • AI Coach data - the AI Coach is optional. When you send it a message, a summary of your training and health data is transmitted to our AI provider (Anthropic) to generate a reply. Anthropic processes it to return that response and does not use it to train its models.
  • Google Calendar data - if you connect Google Calendar, we access your calendar events (titles, times, locations, descriptions, colors) to display and let you manage your schedule in the app. We request the minimum scope needed and store an encrypted refresh token to keep your calendar in sync.
  • Content you create - to-dos, notes (including any images you embed), workouts and routines, body metrics, training goals, and planned sessions.
  • Technical & usage data - your IP address (used transiently for security and rate limiting), device/browser information, and basic diagnostic/error data. We use cookies and local storage strictly for authentication sessions and to remember interface preferences. On the iOS app, if you enable notifications we store an Apple push notification (APNs) device token to deliver readiness reminders; you can turn notifications off in iOS Settings at any time.

We do not collect payment information, and we do not knowingly collect data from children (see Section 10).

3. How we use your information

  • To provide, operate, secure, and improve the Service.
  • To authenticate you and keep your account and data isolated from other users.
  • To compute personalized insights (e.g. recovery and training metrics) from the data you connect.
  • To sync data from the sources you connect (e.g. Garmin, Strava, Apple Health, Google Calendar) into the app.
  • If you use the optional AI Coach, to send a summary of your data to our AI provider (Anthropic) to generate your reply.
  • To detect, prevent, and respond to abuse, fraud, errors, and security issues.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use your health, calendar, or content data for advertising or to train generalized AI/ML models. We also do nottrack you across other companies' apps or websites, and we use no advertising or cross-app tracking SDKs.

4. Google user data - Limited Use disclosure

hybridAF's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google Calendar is:

  • used only to provide and improve the calendar features you see in the app;
  • not transferred or sold to third parties, except as necessary to provide the Service, for security/legal reasons, or with your consent;
  • not used for advertising;
  • not used to train generalized or non-personalized AI/ML models;
  • not read by humans unless we have your explicit consent, it is necessary for security or to comply with law, or the data is aggregated and anonymized.

You can revoke hybridAF's access to your Google account at any time via Google Account permissions.

5. How we share information (sub-processors)

We do not sell your data. We share it only with the infrastructure providers required to run the Service, each acting as our processor under appropriate safeguards:

  • Clerk - authentication and user management.
  • Supabase - managed PostgreSQL database (your app data).
  • Vercel - application hosting, serverless compute, and privacy-friendly usage analytics.
  • Upstash - Redis used for transient rate-limiting counters.
  • Sentry - error monitoring and diagnostics (technical and error data, transient IP).
  • Anthropic - AI provider for the optional AI Coach, used only when you message it; it does not train its models on your data.
  • Google - Calendar API (only if you connect it).
  • Garmin and Strava - fitness data sources (only if you connect them; WHOOP, Oura, and Fitbit where enabled).

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the Service.

6. Data storage, location & security

Your data is stored in the United States (database hosted in AWS, us-east-1). We protect it with industry-standard measures: encryption in transit (HTTPS/TLS), encryption at rest, encrypted storage of third-party access tokens, per-user data isolation, and access controls. No method of transmission or storage is 100% secure, but we work to protect your information and review our practices regularly.

7. Data retention

We retain your personal data for as long as your account is active or as needed to provide the Service. When you delete content, it is removed from our active database. When you delete your account or request erasure, we delete your personal data and disconnect linked Garmin/Google tokens, except where we must retain limited information to comply with legal obligations or resolve disputes. Backups are purged on a rolling basis.

8. Your rights & choices

Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, to object to certain processing, and to withdraw consent. You can export all of your data and permanently delete your account yourself, at any time, from Profile → Data & account in the app (deletion erases your data and disconnects linked services). For any other request, email peeranatsugsavanvit@gmail.com. You can also disconnect Garmin, Strava, or Google at any time from within the app or via the provider's own settings.

EEA/UK (GDPR): our legal bases for processing are your consent (for connecting health/calendar data), performance of our agreement with you, and our legitimate interests in securing and improving the Service. You may lodge a complaint with your local data-protection authority.

California (CCPA/CPRA):we do not sell or "share" your personal information. You have the right to know what we collect, to request deletion, and to not be discriminated against for exercising your rights.

9. Sensitive health data

Health and fitness metrics are sensitive. We process them only to deliver the Service's core features to you, never for advertising, and never sold. We are not a healthcare provider, and hybridAF does not provide medical advice - its insights are informational only and are not a substitute for professional medical guidance.

10. Children's privacy

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

11. International transfers

If you access the Service from outside the United States, your data will be transferred to and processed in the U.S. and other countries where our processors operate, which may have different data-protection laws than your own. Where required, we rely on appropriate safeguards for such transfers.

12. Changes to this policy

We may update this Policy from time to time. We will revise the "Last updated" date above and, for material changes, take additional steps as required by law. Your continued use of the Service after changes take effect constitutes acceptance.

13. Contact us

Questions, requests, or concerns about this Policy or your data? Email peeranatsugsavanvit@gmail.com.

This document describes hybridAF's current data practices. It is provided in good faith to inform users and satisfy platform requirements; it is not legal advice.