1. Who We Are
TrailMath is a trail running training planning tool operated by SC EXPRESS DESIGN SRL (CUI RO19127375), Brașov, Romania (data controller within the meaning of the EU General Data Protection Regulation, "GDPR").
Contact: support@trailmath.run
2. Scope
This Privacy Policy applies to personal data processed through the TrailMath web application at app.trailmath.run, the TrailMath mobile applications, and the marketing site at trailmath.run.
You must be at least 16 years old to use TrailMath. We do not knowingly collect data from anyone under 16. If we become aware that a user is under 16, we will delete their account and associated data promptly.
By creating an account you agree to our Terms of Use. When you connect third-party platforms (Strava, Garmin), their own privacy policies also apply – see Section 6.
TrailMath supports guest accounts – you may begin using the app without providing an email address. Guest accounts store the same training and profile data described below, associated with a device-generated identifier. If you later register with an email, your guest data is linked to the new account.
3. Data We Collect
3.1 Account Data
Email address and password (hashed with bcrypt) when you create a registered account. Guest users are identified by a device-generated identifier and do not provide an email or password until they choose to register.
3.2 Profile and Onboarding Data
Running experience level, weekly volume, training preferences, race objectives (including target race name, date, distance, elevation, and priority), and scheduling preferences (preferred training days, available days per week) – provided during onboarding or updated later in account settings.
3.3 Training Data
Training plans, scheduled sessions, completion status, session notes, actual vs. planned metrics (distance, duration, pace, elevation), and session-level data such as warmup/cooldown structure, interval targets, and RPE (Rate of Perceived Exertion) values that you record within the app.
3.4 Health and Injury Data
If you use the injury tracking feature, we collect: injury location, type, severity, pain level, date of onset, and any notes you provide. This data may include information that qualifies as health data under GDPR Article 9. We process this data on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide by voluntarily entering injury information in the app. You can delete individual injury records at any time.
3.5 Strength Training Data
If your plan includes strength sessions, we collect: exercises performed, sets, repetitions, weight, rest periods, and exercise completion status.
3.7 Connected Platform Data
When you connect Strava or Garmin (see Section 6), we receive activity data including: activity type, name, date, duration, distance, elevation gain, heart rate summaries (average, max), and sport type.
We also temporarily store the raw API response from each platform, which may contain additional metadata beyond the fields listed above (such as gear, splits, laps, or GPS summaries). Imported activity records, including raw responses, are automatically deleted after 7 days. Training metrics derived from matched activities (duration, distance, elevation) are stored as part of your training history.
3.8 Push Notification and Device Data
If you enable push notifications on your mobile device, we store a device token (provided by Firebase Cloud Messaging) associated with your account. This token is used solely to deliver notifications you have opted into. You can disable push notifications at any time through your device settings, which effectively prevents further notifications. Device tokens are deleted when you disable notifications or delete your account.
3.9 Technical Data
IP address, browser type, device information, and request logs collected automatically.
3.10 Usage and Analytics Data
If – and only if – you turn on product analytics in the mobile app, we collect usage events describing how you move through the app: screens viewed, workouts completed, training blocks started and finished, and app open and session events. These events carry coarse device and country information and a pseudonymous app instance identifier linked to your account identifier. They never contain your name, email address, GPS tracks, health or injury data, or free text you have written. See Section 7.3 for the full description, including how to withdraw.
This category covers the mobile app only. Analytics on the marketing site at trailmath.run is a separate matter, described in Section 10.1.
3.11 Newsletter Consent Record
If you subscribe to the newsletter (see Section 4.8), we keep a record of that consent: your email address, the date and time, the IP address and browser user agent the request came from, which page or screen you subscribed from, your language, and the version of the wording you agreed to.
An IP address is personal data, so we are telling you plainly that we store one here. We keep it for a single purpose: the GDPR requires us to be able to demonstrate that a person actually consented (Art. 7(1)), and an unsubscribe request or a complaint can arrive long after the fact. It is never used to locate you, to profile you, or for any other purpose.
If you later unsubscribe, we keep that evidence for a limited period and then strip the IP address and user agent from it - see Section 11. If you never registered an account, you can still see and delete everything we hold about your subscription; Section 13 explains how.
3.12 Race Coach Questions From Our Race Pages
On some race pages you can type a question for the Coach before you have an account. When you continue, we send the text of your question, the race and your language to our app, which holds it for 30 minutes so it can appear in the Coach once your plan is ready. It is then deleted, whether or not it was used. The link you follow carries only a random reference to it, never the question itself, and the question is not sent to our analytics or written to our logs. Your IP address is used, without being stored with the question, to stop the form being abused.
Please leave health or medical details out of this question. It exists to carry a question about the race into the app, not to collect anything about your body - if you have an injury, the Coach in the app has a dedicated, confirmed way to record it.
If you have Premium and are signed in, a race page can also show a chat with the Coach about that race. That chat is part of the Coach in your account: your messages and the replies are stored with your account, deleted automatically after 90 days (see Section 11), included in your data export, and deleted with your account. The chat is shown from our app inside the race page; signing in happens on our app's own page.
4. How We Use Your Data
4.1 Core Service
- Generate and manage your training plans based on your goals, preferences, and fitness level
- Send essential account-related emails (password resets, security alerts)
4.2 Activity Matching
When activities arrive from Strava or Garmin, we match them against your planned sessions to automatically track completion and calculate training load metrics.
4.3 Volume Estimation and Historical Import
At the time you connect a platform, we import up to 90 days of historical activities. This backfill establishes your recent training volume baseline, which is used to generate safe and effective training plans – avoiding sudden load spikes that could lead to injury.
4.4 Garmin Workout Push
If you connect Garmin with the training_api scope, TrailMath can send upcoming
workout structures to your Garmin device. Details of what is sent are described in
Section 6.3.
4.5 Push Notifications
If enabled, we send notifications about upcoming sessions, plan updates, or coach messages. You can disable notifications at any time through your device settings.
4.6 Diagnostics
- Diagnose technical issues and prevent abuse
- Monitor service health and performance
4.7 Product Analytics
- Understand which features are actually used, so we can prioritise what to improve
- See where people abandon a training block or a workout flow
- Measure whether the changes we ship make the app better or worse
We use this data for product improvement only. We do not use it for advertising, we do not build behavioural or advertising profiles from it, and we do not sell or rent it. It is collected in the mobile app only, and only if you opt in – see Section 7.3.
4.8 Newsletter
If you ask for it, we send an occasional newsletter with training ideas and product news - roughly twice a month. It is entirely optional and separate from the account emails in 4.1: you can use every part of TrailMath without it, and declining costs you nothing.
You can subscribe from our website, from the newsletter checkbox when you create an account, or from Notifications in your account settings. That checkbox is never pre-ticked, and subscribing is never bundled into accepting our Terms. Subscribing sometimes carries an introductory discount on TrailMath Premium; the discount is the reason we ask, not a reason you must stay.
You can leave at any time, with one click from the unsubscribe link in every newsletter, or from Notifications in your account settings. Leaving the newsletter does not affect your account or the emails described in 4.1, and we do not ask why.
The newsletter is a different setting from the training emails in 4.1. Turning one off does not turn off the other, in either direction.
We do not sell your data, use it for advertising, or build advertising profiles. We send marketing email - our newsletter - only to people who asked for it, and you can stop it in one click.
6. Connected Platforms
6.1 How Connections Work
Platform connections use the OAuth 2.0 authorization protocol. When you connect Strava or Garmin, you are redirected to that platform's website where you grant TrailMath specific permissions. We never see or store your platform password.
OAuth access tokens and refresh tokens are stored with application-level AES-256-CBC encryption in our database. Tokens are used solely to communicate with the connected platform on your behalf.
6.2 Strava
Permissions requested
We request the read and activity:read_all scopes. The
activity:read_all scope grants access to all activities including those
you have marked as private on Strava. We request this broader scope because many trail
runners mark training activities as private while still wanting them included in their training
plan tracking. You can revoke this access at any time (see Section 6.5).
Data flow direction
Strava → TrailMath only. We do not write any data back to Strava.
Data received
Activity type, name, date, duration, distance, elevation gain, heart rate summary, and the raw API response (which may include additional metadata such as gear, splits, or laps).
Retention of imported data
Imported activity records, including raw API responses, are retained for up to 7 days, then permanently deleted. Training metrics already written to matched sessions (duration, distance, elevation) remain as part of your training history. See Section 11 for the full retention overview.
Webhook verification
Strava delivers activity updates via webhooks. We verify inbound webhooks by matching the
subscription_id against our registered subscription.
Historical import
At connection time, we import up to 90 days of past activities. After that, new activities are received via Strava's webhook event system in near-real-time.
Activity deletion
If you delete an activity on Strava, we receive a webhook notification and remove the corresponding imported record from TrailMath within 48 hours. Training metrics already recorded on your sessions (duration, distance, elevation) are retained as part of your training history.
Disconnection
When you disconnect Strava from TrailMath, we call the Strava deauthorization endpoint to revoke our access tokens, and delete all tokens and cached activity imports from our database. Training metrics already recorded on your sessions are retained as part of your training history.
6.3 Garmin
Permissions requested
We request activity_export (to receive your activities) and
training_api (to send workouts to your device) scopes. The OAuth flow uses
PKCE (Proof Key for Code Exchange) for added security.
Data flow direction
Bidirectional. We receive activity data from Garmin and can send workout structures to your Garmin device.
Data received from Garmin
Activity type, name, date, duration, distance, elevation gain, heart rate summary, and the raw API response.
Retention of imported data
Imported activity records, including raw API responses, are retained for up to 7 days, then permanently deleted. Training metrics already written to matched sessions (duration, distance, elevation) remain as part of your training history. See Section 11 for the full retention overview.
Data sent to Garmin
When you choose to push a workout to your Garmin device, we send: workout name, date, duration, sport type, and structured steps (warmup, intervals, cooldown, pace/heart-rate zones, exercise names, sets, and reps for strength workouts). No personal information, email address, or cross-platform data is included in outbound workout payloads.
Webhook verification
Garmin delivers activity updates via webhooks. We verify inbound Garmin webhooks using HMAC-SHA256 signature validation.
Disconnection
When you disconnect Garmin from TrailMath, we delete all OAuth tokens from our database. Note: Garmin's API does not provide a remote token revocation endpoint, so we cannot programmatically revoke access on their side. You can revoke TrailMath's access directly from your Garmin Connect account settings. Workouts previously pushed to your device will remain on the device.
6.4 Third-Party Privacy Policies
Strava and Garmin are independent data controllers for data they hold about you. They are not sub-processors of TrailMath – you connect to them directly via OAuth, and their privacy practices are governed by their own policies:
6.5 Your Control
- All platform connections are optional – TrailMath works without them.
- You can disconnect any platform at any time from your account settings.
- You can also revoke access directly from your Strava or Garmin account settings.
7. Mobile Apps and Push Notifications
TrailMath is available as a mobile application. The mobile app accesses the same account and data described in this policy.
7.1 Push Notifications
If you opt in to push notifications, we use Firebase Cloud Messaging (FCM) operated by Google to deliver them. When you enable notifications, your device provides a registration token which we store and associate with your account. This token is an opaque identifier – it does not contain personal information.
Notification messages are composed on our servers in the EU. To deliver them, we send Google's Firebase Cloud Messaging service only the device registration token (an opaque identifier) along with a brief, generic prompt (e.g., "You have a session today"). No detailed training data, personal identifiers, or message content beyond this brief prompt is transferred to Google.
You can disable push notifications at any time through your device's notification settings. When you disable notifications or delete your account, we delete the associated device tokens.
7.2 App Store Distribution
The mobile app is distributed through the Google Play Store and/or Apple App Store. These platforms may collect their own data (crash reports, install analytics) governed by their respective privacy policies. TrailMath does not control or receive this data.
7.3 Product Analytics (Mobile App)
The mobile app can report product analytics through Firebase Analytics (Google Analytics 4), operated by Google. We use it for one purpose: to understand how the app is used so that we can improve it. It is not used for advertising, it is not used to build profiles about you, and the data is never sold or rented.
Analytics is off by default. Nothing is collected unless you actively opt in on a first-run prompt, and collection stays disabled at the SDK level until you do. You can decline – the app works the same either way.
What is collected when you enable it: screens you view, workouts you complete, training blocks you start and finish, app open and session events, coarse device information (device model, operating system version, app version), your approximate country as derived from your IP address, and a pseudonymous app instance identifier that we link to your account identifier so events from the same account can be counted consistently. That identifier is pseudonymous rather than anonymous: on its own it does not identify you, but we can relate it back to your account.
What is never collected: your name, your email address, GPS tracks or any location data more precise than approximate country, health or injury data, and any free text you have written (session notes, injury descriptions, and similar).
Where it is processed: Firebase Analytics processes this data in the United States. Google participates in the EU-US Data Privacy Framework, which provides the safeguard for that transfer. See Section 9.
How to withdraw: open Settings → Product analytics in the app and turn the setting off. Withdrawal takes effect immediately – the app stops sending events at once – and it also resets the local analytics identifier, so that any later opt-in begins from a new one. Withdrawing does not affect the lawfulness of processing that already took place. If you want analytics data already held by Google to be deleted, email us at support@trailmath.run.
Product analytics runs in the mobile app only. It is not active when you use TrailMath in a web browser. Analytics on the marketing site is described separately in Section 10.1.
8. Sharing and Recipients
We do not sell your data. We do not share data with advertisers.
8.1 Sub-Processors
We use the following sub-processors to provide the service:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting, database, backups | Germany (EU) |
| Bunny Fonts (BunnyWay d.o.o.) | Web font delivery | EU |
| Brevo (Sendinblue SAS) | Email delivery: account emails such as password resets and security alerts, replies to messages you send us through the contact form, and the newsletter if you subscribe to it. | France (EU) |
| Google LLC (Firebase Cloud Messaging) | Push notification delivery (when enabled). Only device registration tokens (opaque IDs) are shared with Google for message routing; notification content is composed in the EU. | EU/US |
| Google LLC (Firebase Analytics / Google Analytics 4) | Product analytics in the mobile app (only if you opt in) and aggregate traffic measurement on the marketing site. Never used for advertising or profiling. See Section 7.3 and Section 10.1. | EU/US |
8.2 Connected Third-Party Platforms
Strava and Garmin are independent data controllers, not sub-processors. Data flows to and from these platforms are initiated by you through OAuth connections. See Section 6 for details.
8.3 Legal Requirements
We may disclose personal data if required by law, regulation, legal process, or governmental request.
9. International Transfers
All primary data is stored on Hetzner servers in Germany.
When you connect Strava or Garmin, data is transferred to and from services in the United States. These transfers occur on the basis of your explicit consent (Art. 49(1)(a) GDPR) – you actively initiate each connection knowing data will be transferred to the US.
Firebase Cloud Messaging (if push notifications are enabled) receives device registration tokens – opaque identifiers with no personal data – to route notifications. These tokens may be processed in the US. The notification content itself is a brief, generic prompt composed on our EU servers. Google participates in the EU-US Data Privacy Framework.
Analytics data is processed in the United States. If you turn on product analytics in the mobile app, the usage events described in Section 7.3 are processed by Google in the US. The same applies to the aggregate Google Analytics data collected on the marketing site (Section 10.1). Both transfers rely on Google's participation in the EU-US Data Privacy Framework. For the mobile app, the processing additionally rests on your consent, which you can withdraw at any time.
We recommend checking whether each provider participates in the EU-US Data Privacy Framework or offers Standard Contractual Clauses for additional safeguards.
10. Cookies, Local Storage, and Device Storage
10.1 Cookies
Cookies are used on the web surfaces only – the marketing site at trailmath.run and the web application at app.trailmath.run. The mobile app does not use cookies at all; what it stores on your device is described in Section 10.3, and the analytics it can report is described in Section 7.3.
Three of the cookies below are essential: without them you cannot sign in, submit a form safely, or see the right navigation once signed in. The other two are analytics cookies set by Google Analytics 4, which we use to measure aggregate traffic to the marketing site – how many people visit, which pages they read, and roughly where they arrive from.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
trailmath_session |
Essential | Session authentication | Session (expires on browser close or after configured lifetime) |
XSRF-TOKEN |
Essential | Cross-site request forgery protection | Session |
tm_signed_in |
Essential | Tells trailmath.run you are signed in to the web app, so its header shows "Go to dashboard" instead of "Sign in". Contains no user identifier or secret - only a signed-in display hint - and is never used to grant access | The length of your web app session; removed when you log out |
_ga |
Analytics | Google Analytics 4 – distinguishes visitors in order to produce aggregate traffic statistics | 2 years |
_ga_P5MQ620Q86 |
Analytics | Google Analytics 4 – maintains session state for those same statistics | 2 years |
The two analytics cookies are off until you accept them. On your first visit we
load Google Analytics with storage consent denied, so no _ga cookie is written and
no analytics identifier is stored, and we show a banner asking for your choice. Refusing is a
single click and takes exactly as much effort as accepting. If you refuse, the analytics cookies
are never set.
You can change your mind at any time using the Cookie settings link in the footer of any page on trailmath.run. Withdrawing consent stops further collection; to have data already collected deleted, email us at the address in Section 1.
On either surface we do not use tracking pixels, we do not use third-party advertising cookies, and we do not use cookies to build advertising profiles.
10.2 Local Storage (Browser)
We use browser localStorage to store your dark mode preference and your cookie consent choice. Both are non-tracking, functional storage that stays on your device and is not sent to our servers.
10.3 Device Storage (Mobile)
The mobile app may store authentication tokens and user preferences in secure device storage (Keychain on iOS, Keystore on Android). This data remains on your device and is cleared when you log out or uninstall the app.
The app also stores your product analytics choice as a local preference, so that it is remembered between launches and you are not asked again. If you have turned product analytics on, the Firebase SDK additionally stores a local app instance identifier on the device. Turning product analytics off resets that identifier, and both items are removed when you uninstall the app. See Section 7.3.
11. Retention
| Data Category | Retention Period |
|---|---|
| Account and profile data | Until account deletion |
| Training data (plans, sessions, notes, strength data) | Until account deletion |
| Health and injury data | Until you delete the record or delete your account |
| Processed activity data (matched sessions) | Until account deletion |
| Imported activity records (Strava/Garmin) | Retained for up to 7 days, then permanently deleted. Training metrics derived from matched activities are retained as part of your training history. |
| OAuth tokens (connected platforms) | Deleted immediately on disconnect |
| Coach conversation history | Until account deletion |
| Push notification device tokens | Until you disable notifications or delete your account |
| Usage and analytics data (mobile app, only if you opt in) | Retained by Google for the event-data retention period configured on our Google Analytics property, then deleted automatically. Withdrawing consent stops further collection and resets the local identifier; to have data already collected deleted, email us. |
| Newsletter subscription | Until you unsubscribe. Unsubscribing is immediate; we keep a suppression record afterwards so that a later import cannot put you back on the list by accident. |
| Newsletter consent evidence (IP address, browser user agent) | Kept while you are subscribed, and for 12 months after you unsubscribe, so we can answer a complaint about an email we sent. After that the IP address and user agent are erased and only the non-identifying fact that consent existed remains. |
| A question typed on a race page (Race Coach) | 30 minutes, then deleted automatically, whether or not it was used |
| Race Coach chat on a race page (Premium, signed in) | 90 days, then deleted automatically, or earlier if you delete your account |
| Technical/security logs | Retained for a limited period for debugging and security purposes |
When you delete your account, active data (profile, training data, conversations, tokens, and connected platform data) is deleted immediately from our production database. Encrypted database backups are overwritten according to our backup rotation schedule.
12. Security
We employ the following technical measures to protect your data:
- Encryption in transit: TLS 1.2 or higher for all connections
- Encryption at rest: Application-level AES-256-CBC encryption for sensitive fields (OAuth tokens, API keys); Hetzner infrastructure-level protections for underlying storage
- Password hashing: bcrypt with per-user salts
- OAuth security: PKCE for Garmin, state parameter validation for all OAuth flows
- Webhook verification: HMAC-SHA256 signature validation on inbound Garmin webhooks; subscription ID matching for Strava webhooks
- Token storage: OAuth tokens stored with application-level AES-256-CBC encryption
- CSRF protection: Token-based cross-site request forgery protection on all state-changing requests
Data breach notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33 GDPR) and notify affected users without undue delay (Art. 34 GDPR) where the breach is likely to result in a high risk.
13. Your Rights
Under the GDPR, you have the right to:
- Access (Art. 15) – Request a copy of the data we hold about you
- Rectification (Art. 16) – Correct inaccurate personal data
- Erasure (Art. 17) – Request deletion of your account and associated data
- Restriction (Art. 18) – Request that we limit processing of your data in certain circumstances
- Portability (Art. 20) – Export your training data in a standard, machine-readable format
- Objection (Art. 21) – Object to processing based on legitimate interest
- Withdraw consent (Art. 7(3)) – Where processing is based on consent (e.g., platform connections, injury data, push notifications, mobile app product analytics, the newsletter), you may withdraw consent at any time without affecting the lawfulness of prior processing
Account deletion is available directly within the app under account settings. You can also request deletion by emailing us.
If you subscribed to the newsletter without creating an account, these rights still apply to you, and you do not need an account to use them. Every newsletter carries a link to your own preference page. From there you can unsubscribe, download a copy of everything we hold about your subscription, and delete it outright - no email to us, and no proof of identity beyond the link itself, which only you received.
To exercise any of these rights, email support@trailmath.run. We will respond within 30 days. If we need an extension (up to 60 additional days for complex requests), we will inform you within the initial 30-day period.
Supervisory authority: If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
14. Changes and Contact
Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. For significant changes (new data categories, new sub-processors, changes to your rights), we will provide at least 14 days' advance notice via in-app notification or email before the changes take effect.
Minor clarifications or formatting changes may be made without advance notice. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
For any questions about this privacy policy, your data, or to exercise your GDPR rights:
SC EXPRESS DESIGN SRL (CUI RO19127375)
Brașov, Romania
Email: support@trailmath.run