Skip to main content

Privacy Policy

Version 1.2 · Effective September 2, 2026 · See what changed

We wrote this policy in plain language because we believe you should understand how your data is handled without hiring a lawyer. Each section starts with a human-readable summary.

The short version

  • ✓ Your data belongs to you. We never sell it.
  • ✓ There are no ads in Smagpie, and we don’t use your data for advertising. Ever.
  • ✓ Youth athlete data gets extra protection — always.
  • ✓ You can export all your data anytime, in standard formats.
  • ✓ If you leave, we delete your data when you ask. No hostage games.

Who We Are

Smagpie Coaching is built by a family of coaches in the United States. We are the company responsible for your data — not a middleman, not a subsidiary.

▸ Show full legal text

The data controller for the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil’s Lei Geral de Proteção de Dados (LGPD), and other applicable data protection laws is: Smagpie LLC, United States of America. For privacy-related inquiries: [email protected]. For EU/EEA users: our EU Representative contact details are available upon request at [email protected]. For UK users: our UK Representative contact details are available upon request at [email protected].

What We Collect

We collect your account info (name, email), your team/roster data, workout definitions, and athlete training results (activities synced from watches). We don’t collect anything we don’t need.

▸ Show full legal text

Detailed list of data collected, organized by category: Account (name, email, role, organization), Team (roster, groups, sport assignments), Workout (workout definitions, training plans, exercise selections), Activity (GPS tracks, heart rate, power, pace, RPE, session metrics synced from watches), Device Integration (access tokens for the Garmin Connect, COROS and Intervals.icu accounts an athlete chooses to connect, and device identifiers for watch sync). We do not collect biometric data beyond what is voluntarily synced through connected watches. We do not collect: Social Security numbers, driver’s license numbers, financial account numbers, precise real-time geolocation for purposes other than activity tracking, or biometric identifiers for identification purposes. For the purposes of CCPA/CPRA compliance, the following maps our data collection to CCPA categories: (A) Identifiers — name, email, username — collected, not sold, not shared for cross-context behavioral advertising; (B) Personal information per Cal. Civ. Code 1798.80(e) — name, address, phone — collected, not sold, not shared; (D) Commercial information — subscription plan, transaction history — collected, not sold, not shared; (F) Internet or network activity — log data, feature usage — collected, not sold, not shared; (G) Geolocation data — GPS tracks from activities — collected, not sold, not shared; (K) Inferences — fitness trends, training load estimates — collected, not sold, not shared. Sensitive Personal Information (CPRA): We may process precise geolocation (activity GPS data) and health-related data (heart rate, fitness metrics synced from wearable devices). This data is used solely to provide the Smagpie Coaching service and is not used for purposes other than those disclosed at the time of collection. You have the right to limit the use and disclosure of your sensitive personal information.

How We Use It

We use your data to deliver the service — scaling workouts, syncing to watches, showing compliance dashboards. Coaches can ask an AI to draft a workout from their own description; that request never includes athlete data, and a team can turn the feature off entirely. We don’t use it for advertising, profiling, or anything outside of making Smagpie work for you. And there are no ads in Smagpie at all: none in the app, none on this site.

▸ Show full legal text

Specific purposes: workout individualization (scaling intensities to athlete thresholds), watch and training-platform synchronization (sending workouts to the Garmin, COROS or Intervals.icu account an athlete has connected, and receiving completed activities back), compliance monitoring (training load, fitness/fatigue tracking), team management (roster organization, group assignments), performance analytics (1RM tracking, effort index calculations), AI-assisted workout drafting for coaches (the coach’s typed description, the team’s sport and training-zone settings and exercise names are sent to an AI provider to produce a draft workout; no athlete personal data is included, and the team’s administrator can turn the feature off for the whole team in Team Settings). Nothing you or your athletes enter is used to train AI models. We do not use your data for behavioral advertising, user profiling for third parties, or any purpose unrelated to delivering the Smagpie Coaching service. Smagpie displays no advertisements of any kind, in the coaching application or on our website: no third-party advertisements, no contextual advertisements, no sponsored content, and no advertisements targeted using your information. Because there are no advertisements, there is nothing to opt out of. The only promotional messages we send are our own coaching newsletters, which you receive only if you subscribe to them; every issue carries a one-click unsubscribe link, and we never send marketing on behalf of third parties. Transactional emails, such as a password reset or a workout notification, are part of the service and are not marketing. Under the GDPR, we rely on the following legal bases for processing: Performance of contract (Art. 6(1)(b)) — providing the coaching service, account creation, syncing workouts, compliance dashboards, billing and subscription management, transactional emails. Consent (Art. 6(1)(a)) — syncing health data from wearables (Art. 9(2)(a)), marketing communications. Legitimate interest (Art. 6(1)(f)) — security monitoring and fraud prevention, service improvement using aggregate anonymized data. Legal obligation (Art. 6(1)(c)) — compliance with tax, accounting, and legal requirements. Where we rely on legitimate interest, we have conducted a balancing test to ensure our interests do not override your rights and freedoms. You may object to processing based on legitimate interest by contacting [email protected]. Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal. You can withdraw consent through your account settings or by contacting [email protected].

Who We Share With

When an athlete connects a Garmin, COROS or Intervals.icu account, we exchange workouts and activities with it — only what’s needed. We use standard infrastructure providers (hosting, email), a bot-detection service that checks sign-ups are human, and an AI provider for coach workout drafting, which never receives athlete data and which any team can switch off. We never sell your data to third parties. We never share it with advertisers.

▸ Show full legal text

Device and training-platform connections: an athlete can connect their own Garmin Connect, COROS or Intervals.icu account from their account settings. For a connected account we send the assigned workouts to it and receive the completed activities back, and nothing else; Intervals.icu can forward those workouts on to platforms the athlete has linked there, such as Zwift and Rouvy. Each of these vendors is chosen and authorized by the athlete under the terms and privacy policy of that vendor. They are independent of Smagpie, are not our service providers, and are not covered by our data processing agreements. Disconnecting takes one click and revokes our access. Service providers (processors acting only on our instructions): cloud hosting and storage providers (data stored in the United States), Cloudflare (hosting, content delivery, DDoS protection), email service provider (transactional emails only), bot-detection service (used on account registration and on the subscription forms of our marketing website; when you complete the check, the service receives your IP address and browser and device signals directly from your browser, solely to decide whether the request comes from a person; it processes that data under a data processing agreement that limits its use to providing the bot check, and we receive only a pass or fail result), AI drafting provider (receives only the coach’s typed workout description, the team’s sport and training-zone settings and exercise names — never athlete names, results or health data — under terms that do not allow training on it; a team’s administrator can turn the feature off entirely, after which nothing is sent). Each service provider receives only the minimum data necessary for its specific function, and we have data processing agreements with all of them. We do not sell, rent, or trade personal data to any third party for any purpose. Our subprocessors may process data in jurisdictions outside your home country. We ensure each subprocessor is bound by appropriate data transfer mechanisms and contractual protections equivalent to those we apply to your data.

Children & Youth Athletes

Smagpie does not accept registrations from athletes under 13. We ask for birth month and year at registration to verify this — but we don’t store it. Once we confirm you’re 13 or older, the birth data is discarded; we keep only a verification timestamp. If registration reveals an athlete is under 13, the account is refused and no data is retained. For athletes aged 13 and up, coaches are the data controllers for their teams’ roster data and are responsible for complying with applicable law in their jurisdiction.

▸ Show full legal text

Smagpie Coaching does not accept registrations from children under the age of 13. This is a hard floor that applies globally, regardless of local age-of-consent thresholds. To enforce this floor, we ask for birth month and year at registration as a neutral age-verification step. We use that information solely to calculate whether the prospective athlete meets the minimum age requirement. We do not store birth month or year — once the age calculation is complete, the values are discarded. Instead, we record only the date and time that age verification passed. If a prospective athlete is calculated to be under 13, registration is refused and no account is created, and no birth data is retained. If we later learn that we have inadvertently collected personal information from a child under 13, we will delete that information promptly. Parents or guardians who believe their child under 13 has registered may contact [email protected] for immediate deletion. For athletes aged 13 and older, Smagpie Coaching operates under a coach-as-controller / Smagpie-as-processor model (see the “Coach-Athlete Data” section below). The coach or organization that rosters an athlete acts as the data controller with respect to that athlete’s training data and is responsible for complying with applicable privacy laws in their jurisdiction, including any safeguarding policies that apply to their organization. Regardless of jurisdiction, we apply these commitments to all data belonging to minors (ages 13–17) on our platform: minor data is never used for marketing, advertising, or profiling; minor data is never sold; minor data is never shared with third parties except as strictly necessary to deliver the coaching service (for example, syncing workouts to a wearable device that the athlete has explicitly connected); minor data is not used for AI or machine-learning model training; minor data is subject to enhanced retention limits and is deleted promptly upon account closure or upon request from the coaching organization.

Coach-Athlete Data

When a coach or organization uses Smagpie, they decide what data to collect about their athletes and how to use it. We process that data on their behalf. Your coach is responsible for having proper authority to manage your training data — we give them the tools and keep the data safe.

▸ Show full legal text

Smagpie operates in a dual-role model depending on the context of data processing. Smagpie as Controller: We act as the data controller for account registration data, billing information, service usage analytics, and direct communications with users. For this data, we determine the purposes and means of processing and are directly responsible for compliance with applicable data protection laws. Smagpie as Processor: When a coach or organization enters athlete training data — including workout assignments, performance metrics, activity results, and roster information — the coach or organization acts as the data controller, and Smagpie acts as the data processor. In this capacity, we process athlete data only on the documented instructions of the coach or organization. We provide Data Processing Agreements (DPAs) to coaches and organizations upon request, as required by GDPR Article 28. Coach Responsibilities: Coaches and organizations using Smagpie are responsible for: (a) obtaining any necessary consents from athletes or their parents/guardians before entering personal data; (b) complying with applicable privacy laws in their jurisdiction when accessing, using, downloading, or sharing athlete data; (c) ensuring that any data exported from Smagpie is handled in accordance with applicable privacy laws. Smagpie is not responsible for a coach’s or organization’s independent data handling practices outside of our platform. Athlete Visibility: Athletes on the platform can see what data their coach has entered and what has been synced from their devices. Athletes can export their own data at any time.

Health & Fitness Data

Heart rate, GPS tracks, power output, and other data from your watch are health-adjacent data with special legal protections. We treat all fitness data as sensitive. We only collect it when you connect a device or training platform, or when you or your coach enter results by hand, and we only use it to deliver the coaching service.

▸ Show full legal text

Smagpie collects and processes health and fitness data as defined under the Washington My Health My Data Act (RCW 19.373), the EU GDPR (as data concerning health under Article 9 where applicable), and analogous laws. This includes but is not limited to: GPS location tracks recorded during activities, heart rate and heart rate variability data, power output (cycling, rowing), pace and speed data, rate of perceived exertion (RPE), session duration/distance/elevation, and derived metrics such as Training Stress Score, fitness/fatigue estimates, and effort indices. Collection: We collect health and fitness data only when an athlete actively connects a wearable or training-platform account (Garmin, COROS, Intervals.icu) or when the athlete or their coach manually enters data. We do not passively collect health data. We do not collect health data from devices or sources the user has not explicitly connected. Use: We use health and fitness data solely to provide the Smagpie Coaching service, including: displaying activity results, calculating compliance metrics, tracking fitness/fatigue trends, computing individualized workout intensities, and presenting performance analytics. We do not use health and fitness data for advertising, user profiling for third parties, or any purpose unrelated to the coaching service. Sharing: Health and fitness data is shared only with: (a) the coach or organization the athlete is connected to on the platform; (b) the Garmin Connect, COROS or Intervals.icu account the athlete has connected, as necessary to send workouts and receive activities, transmitting only the minimum data required; (c) our cloud infrastructure providers for hosting and storage in the United States. We never sell health or fitness data. We do not share it with advertisers, data brokers, or any third party for commercial purposes. Consumer Health Data Rights (Washington): Washington state residents have the right to access their consumer health data, request correction or deletion, withdraw consent to collection or sharing, and receive confirmation that opt-out requests have been processed. To exercise these rights, use the self-service tools in your account settings or email [email protected].

Data Retention

We keep your data for as long as you use Smagpie. When you leave or ask us to delete your data, we do — within 30 days. We don’t hold your data hostage. Backups are purged on their normal rotation cycle.

▸ Show full legal text

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods: Account data (name, email, role) — duration of account plus 30 days after deletion request. Team and roster data — duration of account plus 30 days. Workout definitions and training plans — duration of account plus 30 days. Activity data (GPS, HR, power, pace) — duration of account plus 30 days. Device integration tokens — until disconnected or account deleted. Billing and transaction records — 7 years after transaction (tax and legal compliance). Server logs (anonymized) — 90 days (security monitoring and debugging). Support correspondence — 2 years after resolution (quality assurance). Upon receiving a valid deletion request, we delete or anonymize your personal data within 30 days. Encrypted backup copies are purged on their normal rotation cycle, not exceeding six months. We may retain limited data where required by law (e.g., tax records) or to resolve disputes, and will inform you if this applies.

International Transfers

Smagpie is based in the United States. If you’re outside the US, your data crosses borders when it reaches our servers. We use industry-standard legal mechanisms to protect your data during that transfer.

▸ Show full legal text

Smagpie LLC is based in the United States. Our infrastructure is hosted in the United States. When you use Smagpie from outside the United States, your personal data is transferred to, stored in, and processed in the United States. EU/EEA and UK Users: We transfer personal data from the EU/EEA and UK to the United States pursuant to the EU-U.S. Data Privacy Framework (DPF), and/or Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), as supplemented by any necessary additional safeguards identified through a Transfer Impact Assessment (TIA). You may request a copy of the applicable transfer mechanism by contacting [email protected]. Brazilian Users: We transfer personal data from Brazil pursuant to LGPD Article 33, relying on Standard Contractual Clauses or your explicit and specific consent for the transfer, with clear information about the international nature of the transfer provided prior to consent. Subprocessor Transfers: Our subprocessors (described in the“Who We Share With” section) may process data in jurisdictions outside your home country. We ensure each subprocessor is bound by appropriate data transfer mechanisms and contractual protections equivalent to those we apply to your data.

Cookies & Tracking

Our marketing site uses minimal cookies — just what’s needed for the site to work. The coaching application uses session cookies to keep you logged in. Analytics on our marketing site are self-hosted, cookie-less and collect no personal data; the coaching application has no analytics at all. A bot check on sign-up and on website forms sees your IP address and browser signals to tell people from bots, and nothing more. We don’t use advertising trackers or sell cookie data.

▸ Show full legal text

We use the following categories of cookies and similar technologies: Strictly Necessary Cookies — essential for the operation of our website and application, including session authentication cookies, security tokens (CSRF protection), and load balancing cookies. These cannot be disabled without breaking core functionality. Analytics — our marketing website uses analytics software that we host ourselves, on our own domain. It sets no cookies, collects no personal data, does not identify or track individual users across sites, and its data is never shared with any third party. The coaching application does not include analytics; the only third-party script it loads is the bot-detection widget on the registration page, described next. Bot Detection — on account registration and on the subscription forms of our marketing website, a third-party bot-detection service receives your IP address and browser and device signals, and may store a token in your browser for the duration of the check, solely to decide whether the request comes from a person. This is a security measure, not tracking: the service operates under a data processing agreement that limits its use of that data to providing the bot check, and we use the result only to accept or refuse the request. We do not use: third-party advertising cookies or tracking pixels, cross-site tracking technologies, fingerprinting or similar techniques to identify or track users, or social media tracking widgets. We show no advertisements, so there are no advertising cookies or advertising preferences to manage. The bot check described above is the one place browser signals are examined, and only to distinguish people from automated traffic. Cookie Controls: You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies may impair the functionality of the application. For EU/EEA and UK users, non-essential cookies (if any) are loaded only after obtaining your consent.

Your Rights

You can export your data anytime in standard formats (.fit, .csv). You can request deletion of your account and all associated data. You can update or correct your information. These aren’t buried processes — they’re buttons in your settings.

▸ Show full legal text

Right to access: view all data we hold about you and your athletes. Right to export: download your data in industry-standard formats (.fit for activities, .csv for structured data). Right to correction: update or correct any personal information. Right to deletion: request complete removal of your account and all associated data. Right to restriction: limit how we process your data. Right to object: opt out of any non-essential processing. Your rights vary depending on your jurisdiction: EU/EEA and UK Residents (GDPR/UK GDPR): Right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), right not to be subject to automated decision-making (Art. 22), right to withdraw consent, right to lodge a complaint with your local supervisory authority. California Residents (CCPA/CPRA): Right to know (categories and specific pieces of personal information), right to delete, right to correct, right to opt out of sale/sharing, right to limit use of sensitive personal information, right to non-discrimination for exercising your rights. You may designate an authorized agent to make requests on your behalf. Brazilian Residents (LGPD): Right to confirmation of processing, right of access, right to correction, right to anonymization/blocking/deletion of unnecessary data, right to data portability, right to information about shared data, right to revoke consent. Washington State Residents: Rights under the My Health My Data Act as described in the Health & Fitness Data section above. All Users: Regardless of your jurisdiction, you can always export your data, update your information, request deletion, and contact us with privacy questions. We do not discriminate against users who exercise their privacy rights. To exercise any of these rights: use the self-service tools in your account settings, or email [email protected]. We respond to all requests within 30 days (or 45 days for CCPA requests, with notice of extension if needed).

Do Not Sell or Share

We don’t sell your personal information. We don’t share it for cross-context behavioral advertising. Period.

▸ Show full legal text

California Residents (CCPA/CPRA): Smagpie does not sell personal information as defined under the California Consumer Privacy Act. Smagpie does not share personal information for cross-context behavioral advertising as defined under the CPRA. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age. We honor Global Privacy Control (GPC) signals transmitted by your browser as a valid opt-out request, as required by California law effective January 1, 2026. If you are a California resident and wish to exercise your rights under the CCPA/CPRA — including the right to know, delete, correct, or opt out — you may do so through your account settings or by contacting [email protected]. We will verify your identity before processing your request and will respond within 45 days. All Users: We do not sell, rent, license, or trade your personal data to any third party for monetary or other valuable consideration, regardless of your jurisdiction.

Data Security

We encrypt data in transit and at rest. We follow industry-standard security practices. Two-factor authentication is available to every account and required for our administrators. We don’t store credit card numbers (payments are handled by a certified payment processor).

▸ Show full legal text

Technical measures: TLS 1.2+ encryption for all data in transit, AES-256 encryption for data at rest, role-based access controls, two-factor authentication (available to every coach and athlete account, and required for every administrative account), regular security audits, automated vulnerability scanning, secure development practices. Payment processing is handled entirely by our PCI DSS-compliant payment processor — we never see, store, or process credit card numbers. Infrastructure hosted in the United States. Database backups are encrypted before they leave our servers and stored with a separate cloud storage provider in the United States (geo-redundant), apart from the production database.

Breach Notification

If we ever have a data breach that affects your information, we’ll tell you directly — not buried in a blog post six months later. We’ll tell you what happened, what data was involved, and what we’re doing about it.

▸ Show full legal text

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: Regulatory Notification — notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. For US state law breaches, we will comply with the notification timelines of each applicable state (e.g., California requires notification “in the most expedient time possible and without unreasonable delay”). User Notification — where the breach is likely to result in a high risk to your rights and freedoms, we will notify affected users directly and without undue delay via email. The notification will include: (a) the nature of the breach; (b) the categories and approximate number of individuals affected; (c) the likely consequences of the breach; (d) the measures taken or proposed to address the breach; (e) contact information for follow-up questions. Mitigation — we will take immediate steps to contain and remediate the breach, assess its scope and impact, preserve evidence for investigation, and implement measures to prevent recurrence.

Changes to This Policy

If we change this policy, we’ll let you know — by email for anything meaningful, and with a clear summary of what changed. Every version is listed in the policy history at the bottom of this page. We won’t quietly change the rules on you.

▸ Show full legal text

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. Material changes: We will notify you by email at least 30 days before the changes take effect, and will provide a clear summary of what changed and why. Where required by law, we will obtain your renewed consent before applying material changes to data processing. Non-material changes: Minor clarifications, formatting adjustments, or updates to contact information may be made without advance notice but will be reflected in a new version number and effective date at the top of this policy and in the policy history. Version History: Every revision of this policy carries a version number and an effective date, shown at the top of this page. A policy history listing each version and a summary of what changed is published at the end of this page. Complete earlier versions are available on request from [email protected].

Contact

Questions about your data? Email us at [email protected]. We’re real people and we respond within one business day.

Policy history

Every revision of this policy gets a version number and an effective date. Complete earlier versions are available on request from [email protected].

  1. Version 1.2 · effective September 2, 2026

    • Published the full retention schedule, including encrypted off-site backups on a rotation not exceeding six months.
    • Described service providers by role and confirmed that data is stored in the United States.
    • Expanded the descriptions of security measures and of health and fitness data processing.
    • Disclosed AI-assisted workout drafting for coaches: what is sent to the AI provider, that athlete data never is, and that a team can turn the feature off.
    • Disclosed the bot-detection service used on account registration and on website forms, what it receives, and the agreement it operates under.
    • Clarified that analytics on the marketing website are self-hosted and cookie-less, and that the coaching application has no analytics.
    • Listed every device and training-platform connection an athlete can make (Garmin, COROS, Intervals.icu) and separated them from our service providers: connections are authorized by the athlete under the vendor's terms and are not covered by our data processing agreements.
    • Stated plainly that Smagpie displays no advertisements of any kind, in the app or on the website, and that newsletters are opt-in with one-click unsubscribe.
    • Stated that two-factor authentication is available to every coach and athlete account and required for administrative accounts.
    • Added version numbers, effective dates and this policy history.
  2. Version 1.1 · effective April 24, 2026

    • Set a hard minimum age of 13, verified by a birth month and year check that is not stored.
    • Adopted the coach-as-controller / Smagpie-as-processor model for athlete training data.
  3. Version 1.0 · effective March 29, 2026

    • First published.