Last updated: May 19, 2026

Privacy Policy

1. Introduction

DA2 ("we," "us," or "our") is an AI-powered endurance training platform that generates personalized, race-specific training plans and adapts them based on your actual workout performance. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, mobile apps, and services at da2-one.vercel.appand The Daily Athlete iOS app (collectively, the "Service").

This policy is designed to comply with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act") as applicable. For users in the European Union, this policy also addresses rights under the General Data Protection Regulation (GDPR).

By using the Service, you consent to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account we collect your email address and an optional display name. Sign-in is via email magic link only — we do not collect passwords, and we do not offer third-party social sign-in.

2.2 Profile Information

You may optionally provide additional profile data such as age range, experience level, height, weight, sport preferences, training goals, bio, and timezone.

2.3 Training Plan & Event Information

When you create a training plan, we collect your event type (swim, bike, run, triathlon, strength, mobility), event date, training goal, current fitness level, available weekly training hours, and training history. This data is essential for generating your personalized, race-specific periodized training plan.

2.4 Workout & Health-Related Data

We store all workout data you log in the app or sync from third-party services. This includes workout type, date, duration, distance, pace, heart rate, elevation, calories, laps/splits, power, and any notes or descriptions you add. We use this data to adapt your plan weekly — updating volume, intensity, and focus based on your actual performance.

Note on health data: some workout data (heart rate, calories, body metrics) may be classified as health-related or sensitive personal data under certain jurisdictions. We treat all such data with the same level of protection as described in this policy. This data is used solely for generating your training plan, adapting it weekly, and providing you with training analytics and insights.

Location data: when you connect Strava, the activity records we sync may contain GPS tracks (route polylines) for workouts you recorded outdoors. We display these in the app as a map on the activity detail view. We do not collect location data directly from your device.

2.5 Third-Party Service Data

When you connect third-party fitness services, we access and store data from those platforms:

  • Strava: activity summaries and detailed activity data (distance, duration, pace, heart rate, elevation, laps, splits, GPS polylines, and activity metadata). We access this data via the Strava API using OAuth 2.0 authorization that you explicitly grant.

You can disconnect Strava at any time from your Settings page, which revokes our access to new data from Strava.

2.6 Coach Collaboration Data

If you accept a coach invitation, the linked coach can read your training plan, planned and completed workouts, and athlete profile. Coaches can also assign workouts to you. You can remove a coach link at any time from Settings.

3. How We Use Your Information

We use your data to:

  • Generate your personalized, race-specific periodized training plan
  • Adapt your plan weekly based on your actual workout performance
  • Sync your Strava workouts and merge them with your plan
  • Provide training analytics and performance insights
  • Allow coaches you link to view, comment on, and collaborate on your plan
  • Send transactional emails for authentication (magic link sign-in)
  • Provide, maintain, and improve the Service
  • Detect and prevent abuse, fraud, or unauthorized access

We do not collect or use your data for advertising, ad measurement, or cross-app/cross-website tracking. We do not sell your data.

4. Data Storage and Security

Your data is stored in our Supabase project (Postgres database, file storage, and authentication) and served through Vercel infrastructure. We use industry-standard security measures including:

  • Supabase authentication with email magic-link verification
  • Postgres Row-Level Security policies restricting data access to the owning user (and, where applicable, their linked coach)
  • HTTPS encryption for all data in transit
  • OAuth 2.0 for the Strava connection (no third-party passwords stored)
  • Secure on-device storage of session tokens via the platform secure enclave (iOS Keychain / Android Keystore)
  • Regular automated backups by our infrastructure providers

While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Third-Party Services

The Service integrates with the following third-party services. Each has its own privacy policy:

  • Supabase: authentication, database, file storage, and transactional email delivery for sign-in magic links — Privacy Policy
  • Vercel: hosting and deployment of the web app and Next.js API routes — Privacy Policy
  • Strava: workout sync (only if you choose to connect) — Privacy Policy
  • Inngest: background job orchestration for Strava sync and webhook processing — Privacy Policy
  • Apple App Store / TestFlight: iOS app distribution. Apple may collect download and crash diagnostics per its own policies — Privacy Policy

Coach Collaboration:when a coach is linked to your account, that coach's identifying information (email, display name) is stored and they can read your training plan, workouts, and related data while the link is active. Coaches operate under separate terms and their own privacy obligations.

6. Data Sharing

We do not sell, rent, or trade your personal data, and we do not use it for advertising or tracking. We may share data only in these limited cases:

  • Coach collaboration: when you accept a coach invitation, that coach has access to your training plan, workouts, athlete profile, and event information. Sharing is limited to coaches you explicitly link and ends when you remove the link.
  • Service providers: we use the third-party services listed above to operate the platform. They process data on our behalf under their respective privacy policies.
  • Legal requirements: we may disclose data if required by law, legal process, or government request.

7. Your Rights

Under the DPDP Act, IT Act, and GDPR (where applicable), you have the following rights as a Data Principal:

  • Right to Access: view all data we hold about you through your profile and settings pages
  • Right to Export / Portability: request a full export of your data
  • Right to Correction: update your profile information at any time through Settings
  • Right to Erasure: request deletion of your account and all associated data by contacting us
  • Right to Disconnect: revoke access to Strava at any time from Settings
  • Right to Withdraw Consent: withdraw consent for data processing at any time (this may affect Service functionality)
  • Right to Nominate: under the DPDP Act, you may nominate another person to exercise your rights in case of your death or incapacity

To exercise any of these rights, contact our Grievance Officer (see Section 13 below) at rsareen@gmail.com. We will respond to requests within 30 days.

8. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Data Protection Board of India (once constituted under the DPDP Act) without unreasonable delay, and in any case within 72 hours of becoming aware of the breach
  • Notify affected users via email and/or in-app notification as soon as practicable
  • Provide details of the nature of the breach, the data affected, and the measures taken to mitigate it
  • Document the breach and remediation steps in our internal records

For EU users, breach notifications will also comply with GDPR Article 33/34 requirements where applicable.

9. Data Retention

We retain your data for as long as your account is active and the data is necessary for the purposes described in this policy. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or legitimate business purposes (e.g., backup integrity, fraud prevention, legal compliance).

Automated backups containing your data are pruned on a regular schedule by our infrastructure providers (Supabase and Vercel). After their retention windows expire, backup data is permanently deleted.

10. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from minors. Under the DPDP Act, processing personal data of children requires verifiable consent from a parent or lawful guardian.

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at rsareen@gmail.com. We will take steps to delete such data promptly.

11. International Data Transfers

Your data may be processed and stored in servers located outside India (Supabase, Vercel, Inngest, and Strava all operate cross-border infrastructure). By using the Service, you consent to the transfer of your data to these locations. We ensure that all third-party processors maintain appropriate security measures.

For EU users: data transfers outside the EEA are conducted in accordance with GDPR requirements, relying on the third-party processors' own compliance mechanisms (e.g., Standard Contractual Clauses).

12. Tracking and App Privacy (Apple)

The Daily Athlete iOS app does nottrack you across other companies' apps or websites and does not link your data with data from third parties for advertising or measurement. We have not implemented Apple's App Tracking Transparency prompt because we do not track. The data we collect — email, name, training and workout data, user ID, and workout GPS routes from Strava — is linked to your account for the purpose of providing the app's core functionality and is declared as such in our App Store privacy disclosures.

13. Changes to This Policy

We review and update this Privacy Policy at least annually, or more frequently when required by changes in law, our practices, or the Service. We will notify you of material changes by email and by posting the updated policy on this page with a revised "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

We are actively monitoring the rollout of the DPDP Rules (expected full enforcement by 2027) and will update this policy as new requirements are enacted.

14. Grievance Officer & Contact

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the following person has been designated as the Grievance Officer for the purpose of this Privacy Policy:

DA2 Support

Grievance Officer & Data Protection Contact

Email: support@da2.coach

Grievances will be acknowledged within 24 hours and resolved within 30 days from the date of receipt. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (once constituted) or the relevant supervisory authority in your jurisdiction.