Privacy Policy
Who we are. Custom Gains is operated by TaaviTaavi OÜ, a company registered in Estonia ("we", "us"). We are the data controller for the personal data described below. Questions or requests: taavi@customgains.fit.
This policy explains what personal data we collect when you use Custom Gains at customgains.fit and our app, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).
Data we collect
- Account data — your name and email address, and an encrypted (hashed) password if you sign up with one. If you sign in with Google, we receive your basic profile (name, email).
- Garmin Connect data — when you choose to connect Garmin, we access your training and activity data (for example workouts, distance, duration, heart rate, pace and cadence) so the coach can build and adapt your plan and push structured workouts to your device. Your Garmin connection credentials and session tokens are encrypted at rest and used only to provide this service.
- Connected training sources (Strava, Oura) — when you choose to connect Strava or Oura, we read only your own activity and recovery data (for example distance, pace, heart rate, duration and readiness) to personalize your plan. These are read-only connections; we do not post to them. Access tokens are encrypted at rest, used only to provide your coaching, and revoked when you disconnect. We never access other users' data.
- Coaching content — your goals, the chat messages you exchange with the AI coach, the workouts and plans created for you, and any weight entries you log.
- Billing data — if you subscribe, our payment processor handles your card details; we receive your subscription status and billing metadata (we never see or store full card numbers).
- Usage and diagnostic data — basic analytics (pages viewed, key actions) and error/crash diagnostics, used to operate and improve the product.
- Support data — messages, screenshots or recordings you voluntarily send us through the in-app feedback tool.
Why we use it & legal bases
- To provide the service — run your account, generate and sync workouts, adapt your training (legal basis: performance of our contract with you).
- To connect a data source (Garmin, Strava, Oura) — only after you explicitly link it and accept our data-processing consent (legal basis: your consent, which you can withdraw at any time by disconnecting the source).
- To take payment — manage subscriptions and invoices (legal basis: contract).
- To secure and improve the product — analytics, error monitoring, fraud and abuse prevention (legal basis: our legitimate interests in a reliable, secure service).
AI processing
Your coaching conversations and the training data needed to build your plan are sent to a large-language-model provider (Anthropic) purely to generate your coaching responses and workout plans. This is inference only: your data is never used — by us or by the provider — to train, fine-tune or improve any artificial-intelligence or machine-learning model. Anthropic does not train its models on data sent through its API. We send only the data needed to produce your own coaching, we never sell or share your training data for advertising, and data obtained from a connected source is used solely to serve you.
Service providers we share data with
We share the minimum data necessary with vetted processors who act on our instructions:
- Anthropic — AI coaching responses (inference only; does not train its models on your data).
- Garmin — to read your activities and publish workouts to your devices, at your request.
- Strava, Oura — read-only, to read your own activity and recovery data when you connect them.
- Stripe — payment processing.
- Hosting & infrastructure — our servers are hosted in the EU.
- PostHog (analytics) and Sentry (error monitoring) — operated in EU data regions.
- Resend — transactional email (e.g. password resets, reminders).
We do not sell your personal data.
International transfers
We aim to keep data within the EU/EEA. Where a provider processes data outside the EEA, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Data retention
We keep your personal data for as long as your account is active and as needed to provide the service. When you delete your account we delete or anonymise your personal data within a reasonable period, except where we must retain certain records (for example billing records) to meet legal obligations.
Security
We protect your data with encryption in transit and at rest, access controls, and reputable infrastructure providers. Sensitive items such as Garmin credentials and tokens are encrypted at rest. No system is perfectly secure, but we work to safeguard your information and to limit who can access it.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. You can disconnect Garmin or request account deletion from within the app, or email us at taavi@customgains.fit. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.
Children
Custom Gains is not intended for children under 16, and we do not knowingly collect their data.
Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the "Last updated" date above; significant changes will be communicated to you where appropriate.
Contact
TaaviTaavi OÜ, Estonia
Email: taavi@customgains.fit