Skip to content

Free today. More features coming soon.See what’s coming

Privacy Policy

What SurgeIQ Lab stores, why, who else is involved, and your choices. This policy describes how the product actually works today.

Published

Browsing the public site

The public pages and tools (guides, the power zone calculator and the workout builder) work without an account. Values you type into the calculators stay in your browser. When you download a FIT file from the workout builder, the workout is sent to our server only to build the file and is not stored. We don’t use analytics or advertising cookies on these pages.

Your account

  • Sign-in details: your username and a hashed password (we never store the password itself), and whether you signed up as an athlete or coach.
  • Profile: the details you choose to add — name, gender, FTP, weight, weekly training hours, goal, target race date and home location.
  • Training data: your workouts and plans (including their structured steps), completion status, and daily training state such as readiness and load.

We use this data to run the product: to show your calendar, calculate zones and training load, suggest a daily session, and build workout files.

Strava

If you connect Strava, we store the access and refresh tokens Strava issues so we can import your activities, and we store a summary of each imported ride: name, start time, duration, distance, average and normalised power, average heart rate, average cadence and a training-load figure. Disconnecting Strava in the app removes the stored tokens. Strava’s own privacy policy covers data on Strava.

Coaches

A coach can invite you by username. Until you accept the invitation in your profile, the coach sees only that the invitation exists — not your profile or training. Once you accept, the coach can see your profile and training calendar and can place draft workouts on it that you don’t see until the coach publishes them. You can remove a coach at any time, which ends their access. Coaches can’t see your password or Strava tokens.

Cookies and browser storage

We use two cookies that are necessary for signing in and security: a session cookie that keeps you signed in, and a CSRF cookie that protects forms from cross-site attacks. We don’t use local storage or tracking cookies.

Where data is stored

Account and training data is stored in a managed PostgreSQL database hosted by our database provider (Supabase) and accessed only by our application server. Workout file downloads are generated on our server.

Your choices

  • You can edit your profile and training data in the app at any time.
  • You can disconnect Strava in the app.
  • You can accept or decline coach invitations, and remove a coach, in your profile.
  • To request a copy of your data or deletion of your account, contact us via our contact page from the email linked to your account, or include your username.

Changes

If we change how data is handled — for example by adding analytics or advertising — we will update this page first and change the “updated” date above.