Off Season Coach
Privacy
Privacy Policy
Effective [DATE]
The short version. We collect what's needed to make a personalized coaching app work: your email, your name, the workouts you choose to share with us, and the messages you send your AI coach. We send a summary of your workouts and goals to Anthropic when you ask the app to generate an AI training plan. We don't sell your data, we don't use it for advertising, and you can delete your account from inside the app at any time.
1. Who we are
Off Season Coach is an iOS app for runners and running coaches. "Off Season Coach", "we", "us", and "our" refer to Seven P's LLC, the operator of the app and the website at offseasoncoaching.com. We are the data controller for the personal data described in this policy.
2. What we collect
You give us, directly
- Email address — for sign-in via Sign in with Apple. If you use Apple's "Hide My Email" feature, we only ever see the Apple relay address.
- Display name — the name you choose to show to your coach, athletes, and team members.
- Training goals and inputs — race targets, weekly mileage goals, any notes you provide when generating an AI plan.
- Messages — the contents of conversations you have with your coach or athletes inside the app.
- Team and group memberships — which teams or running groups you join, and whom you invite.
From your device, with your permission
- Workout data from Apple HealthKit — durations, distances, paces, route GPS points, heart-rate summaries, and cadence for the workouts you choose to import. See the Apple HealthKit data section for specifics.
- Live workout tracking data — when you record a workout in the app, we collect GPS coordinates, pace, and motion data for the duration of the workout.
- Push notification token — an opaque identifier from Apple that lets us send you notifications when your coach posts a plan or sends a message.
Automatically
- Purchase records — when you buy AI credit through Apple's In-App Purchase, we record that you purchased credit and how much. We never see your payment card or Apple ID password.
- Limited diagnostic data — error logs and timestamps stored on our servers when something fails (e.g. an API request times out). These logs do not include your data, only what went wrong and when.
3. How we use it
We use the data above to:
- Authenticate you, run the app, and deliver the features you use
- Generate personalized training plans using AI when you ask us to
- Deliver messages between you and other users in your teams or groups
- Send push notifications you've subscribed to
- Process In-App Purchases and credit your account
- Diagnose problems, prevent abuse, and improve the app
- Comply with legal obligations
We do not use your data for advertising. We do not sell your data. We do not allow third parties to access your data for their own purposes.
4. Who we share it with
We share specific data with the following service providers, and only to the extent necessary for them to perform their function. None of them sells or independently markets your data.
- Apple — Sign in with Apple authentication, In-App Purchase processing, push notification delivery (APNs), HealthKit (your data stays on your device unless you choose to share it; HealthKit is not a server-side service).
- Supabase, Inc. — database hosting, authentication, file storage, and serverless function execution. All your app data lives in a Supabase project we control.
- Anthropic, PBC — AI model provider. When you generate an AI plan, we send a summary of your workouts and training goals to Anthropic's Claude API. See the AI plan generation section.
- Resend, Inc. — transactional email delivery. When you send a team invite by email, the recipient's email address and the invite contents are sent through Resend.
- Cloudflare, Inc. — hosting and DNS for offseasoncoaching.com, including the invite landing page that recipients see when they tap an invite link.
5. Apple HealthKit data
Off Season Coach uses Apple HealthKit. Apple has specific rules about HealthKit data and we follow all of them.
What we read
With your permission, we read the following workout types from HealthKit: running, walking, cycling, and other cardio workouts you've recorded. For each workout we may read duration, distance, average and split pace, calories, heart-rate samples, cadence, and route GPS points.
What we write
With your permission, we write workouts that you complete inside the Off Season Coach app back to HealthKit, so they appear in your activity history alongside workouts from other apps.
What we do not do with HealthKit data
- We do not use HealthKit data for advertising or marketing.
- We do not sell HealthKit data.
- We do not share HealthKit data with third parties except as described below, with your specific consent.
- We do not use HealthKit data to make decisions about insurance eligibility or employment.
HealthKit data and AI plan generation
When you ask the app to generate a personalized training plan, a summary of your recent workouts is sent to Anthropic. This summary is derived from HealthKit data and may include workout durations, distances, paces, and workout types. We do not send heart-rate samples, GPS coordinates, sleep data, body composition, or any HealthKit data outside running and walking workouts. The first time you generate a plan, the app shows a disclosure screen explaining this and asks for your explicit acknowledgment. You can revoke HealthKit access entirely at any time by going to iOS Settings → Privacy → Health → Off Season Coach.
6. AI plan generation
Personalized training plans are generated by Anthropic's Claude AI based on a summary of your workouts and the goals you provide.
What we send to Anthropic
- Workout durations, distances, paces, and workout types from the last several weeks
- Your stated training goals (e.g. "marathon in 12 weeks") and race targets
- Any notes you typed when requesting the plan
What we do not send
- Your name, email, phone number, or any other personally identifying information
- Your location, GPS coordinates, or specific workout routes
- Heart-rate samples, sleep data, or any HealthKit data outside running and walking workouts
- Messages you've sent to your coach or athletes
- Any data from other users (your athletes' data is never sent when you generate your own plan)
How Anthropic handles the data
We use Anthropic's commercial API under their Commercial Terms of Service. Under those terms, Anthropic does not use your inputs or the model's outputs to train their AI models. Anthropic retains API data for a limited period for safety and abuse detection purposes. You can read Anthropic's policy at anthropic.com/legal/commercial-terms.
AI-generated content is not medical advice
Training plans generated by AI are suggestions, not medical or professional fitness advice. They are not a substitute for consultation with a doctor, physical therapist, or certified running coach. You should not follow an AI-generated plan if you have a condition that requires medical supervision of exercise, and you should always consult a healthcare professional before starting a new training program.
7. How long we keep it
- Account data (email, name, profile) — for as long as your account is active. Deleted when you delete your account.
- Workout data — for as long as your account is active. Deleted when you delete your account.
- Messages — for as long as your account is active. When you delete your account, messages you sent are replaced with a placeholder so the threads remain readable to other participants but no longer contain your content.
- AI plan requests — request summaries are retained for up to 90 days for abuse detection, then deleted.
- Purchase records — retained for the period required by tax and accounting laws (typically 7 years), even after account deletion.
- Diagnostic logs — typically deleted within 30 days.
8. Your rights and choices
Depending on where you live, you may have specific rights under laws like the GDPR (EU/UK), CCPA/CPRA (California), or other regional privacy laws. These rights generally include:
- Access — request a copy of the data we have about you
- Correction — fix data that's wrong
- Deletion — delete your account and associated data (see the next section)
- Objection / Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Withdraw consent — for processing based on consent (like HealthKit access)
To exercise any of these rights, email us at info@offseasoncoaching.com. We'll respond within 30 days. We may need to verify your identity before acting on the request.
If you're in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
9. Deleting your account
You can delete your account from inside the Off Season Coach app: open Settings, scroll to Account, tap "Delete Account", and follow the prompts.
When you delete your account:
- Your profile, name, email association, and training data are deleted from our servers
- Workouts you've recorded in the app and stored on our servers are deleted (workouts in your own HealthKit on your phone are untouched)
- Plans, messages, and other content you created are either deleted or anonymized so the rest of the app keeps working for people you shared them with
- Any unused AI credit is forfeited and is not refundable (Apple's policy for consumable In-App Purchases)
- If you currently own a team or running group, you'll need to either transfer ownership or delete the team first; the app will walk you through this
Account deletion is irreversible. If you change your mind later, you'll need to create a new account.
10. Children's privacy
Off Season Coach is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you are between 13 and 18, you may use the app only with the involvement of a parent, legal guardian, or supervising adult coach. If you believe a child under 13 has provided us with personal data, contact us at info@offseasoncoaching.com and we will delete it.
11. Security
We protect your data using industry-standard security practices: TLS encryption for all data in transit, encrypted storage at rest, role-based access controls on our database, and the principle of least privilege for our staff and tools. No system is perfectly secure, however, and we cannot guarantee absolute security. If we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll notify you inside the app and update the "Effective" date at the top. Your continued use of the app after a change takes effect means you accept the updated policy.
For questions about this Privacy Policy or how we handle your data: