Privacy policy

Coach Alex is a WhatsApp running coach. This page explains what data we collect, why, and how to delete it. Plain English, no lawyer-speak.

What we collect

WhatsApp & Twilio

We send and receive WhatsApp messages through Twilio (our messaging infrastructure provider). Twilio processes the messages on our behalf and stores them per its own retention policy. We store every message in our own database for context windows and audit. Chat logs are retained for as long as your account is active.

Strava integration (optional)

If you connect Strava, we ask for the activity:read_all scope only. We read your activity metrics (distance, duration, pace, heart rate, elevation, cadence) to send you post-run coaching and adjust your training. We do NOT read your personal info, friends, kudos, segments, GPS streams, or the free-text activity titles you write. Only derived metrics are forwarded to our LLM provider — never the raw Strava payload. You can disconnect Strava at any time from your Strava settings page (Apps → Coach Alex → Revoke access). Strava signals us via a deauthorization webhook within seconds and we automatically purge your Strava tokens and athlete_id from our database. Your training history (runs, plans, sessions) remains intact so you can continue coaching via text / tap / screenshot logging — to delete that historical data too, email the address below.

OpenAI / language model usage

For free-form coaching replies and run recaps, we send your message + a small amount of context (recent run, last check-in) to OpenAI's GPT models. OpenAI processes the request and returns a coaching response. Per our agreement with OpenAI, the data we send is NOT used to train their models. We log the call metadata (tokens, cost) but not the LLM response body separately — the response is stored only as part of your chat history.

Infrastructure providers

Your data is stored in a managed Postgres database hosted on Supabase (EU region). The backend API runs on Railway (US region). Both providers act as sub-processors under data-processing agreements. When we introduce paid subscriptions, payments will be handled by Stripe (US, with EU data-processing agreement) and your payment details will NEVER touch our database — Stripe handles them end to end.

Legal basis (GDPR)

The legal basis for processing your data is the performance of the coaching service you actively requested (Article 6.1.b — contract). The optional health-related fields (age, weight, perceived effort) are processed only with your explicit consent (Article 6.1.a + Article 9.2.a) — you can refuse them and the basic coaching still works.

Non-EU data transfers

Some sub-processors (OpenAI, Stripe, Railway) operate from the United States. Each transfer is covered by Standard Contractual Clauses approved by the European Commission. You can request the specific SCC text at any time via the contact email below.

Your rights

You can request deletion of all your data at any time by emailing the address below. We will purge your row from our database within 7 days, which cascades to all linked data (chat logs, run events, plans, sessions). You can also pause coaching by simply not messaging — there is no recurring charge and we never send unsolicited promotional messages.

Updates

If we update this policy in a way that materially changes what data we collect or how we use it, we will send you a one-time WhatsApp notification before the change takes effect.

Questions or deletion request?

contact@foulay-running.com
← Back to home