Privacy notice
Version 1.14 · 18 September 2026
This notice tells you what we do with your data. It is written to be read, not to be survived — if any part of it is unclear, that is our failure and we would like to know.
Who we are
Hussein Bahaaeldin ("we") is the data controller for the personal data described here.
- Contact for anything in this notice: duraro.support@gmail.com
- Postal address: U3 14, 68161 Mannheim, Germany
- Data protection officer: none appointed. We are not required to appoint one: we are not a public authority, and our core activities do not involve large-scale processing (Art. 37(1)). Contact us directly.
What this app is, in one line
Duraro reads training and wellness records from sources you link on your phone, works out your fitness, fatigue and form, and shows you a plain- language brief on your phone. Where it has no real measurement it says so rather than estimating — that is the product's core promise, and it shapes what we hold.
1. What we collect
From a source you link — intervals.icu using the API key you give us, or Apple Health using the permission you choose on your phone:
- Training sessions — type, name, date and time, distance, duration, average and maximum heart rate, time in each heart-rate zone, your heart-rate zone boundaries, your threshold heart rate, the training load figure, and whether power was measured or estimated.
- Your own words on a session. We keep any notes you wrote on your own sessions. The app reads them to work out what a session was for.
- Record-keeping that goes with a session — the session's own reference number, which app uploaded a session, and when the record was created. We keep these so the same session is never counted twice, and for no other reason.
- Daily wellness — heart rate variability, resting heart rate, sleep duration, sleep stages, your device's own sleep score, and weight, where your devices record them.
- Figures intervals.icu works out itself — intervals.icu's own fitness figure and intervals.icu's own fatigue figure. We keep these alongside the ones this app works out, so the two can be compared and a disagreement can be shown to you rather than hidden.
- HealthKit replay facts — HealthKit heart-rate samples are used in memory and not saved. For a sufficiently covered workout we keep its observed heart-rate coverage, three-zone zone distributions, the training load figure, its load method, and its measurement tier, so the result can be explained and replayed without retaining the sample stream.
From you directly:
- Your age, experience level, timezone, which sports you do, when you started each, and how many hours a week you train.
- Any physiological test results you record — threshold and LT1 heart rates, FTP, critical swim speed — and the date and method of each.
- Anything you write in your own profile notes.
- Your answers to the app's setup questions.
- If you select V2 adult beta, your voluntary per-sport training stage, four complete weeks of athlete-confirmed actual work (including linked work only once), separately labelled off-app sessions or source gaps, and manual reports of completion, actual duration, effort, purpose and pain. An unreported session remains unknown. You review and approve each four-week plan before it is saved. Your dated resource-access and time-flexibility declarations, engine/code pin, owned-activity links, session intent, explicitly confirmed missed/extra work and voluntary pain/illness/assessment-concern answers. These local reports support training review and conservative holds; they are not a diagnosis. Voluntary planning context also records declared terrain access, familiar aero position, deliberate fatigued-sprint intent, strength experience/exercise/sets/repetitions/load and key-session separation, individually tested carbohydrate/fluid rates and declared heat/altitude exposure. Unknown values stay unknown; dated declarations shape reviewed prescriptions without estimating physiological capacity or authorizing progression without separately confirmed intent and next-day recovery. Optional recovery reviews record your current interpretations, severity and persistence; concordant abnormalities may reduce one discretionary exposure and severe signals hold hard work. Familiar mobility records a documented need, region, goal, method, dose and tolerated response within the existing warm-up. Optional body mass, sex at birth, gender, competition/technical experience, work/school stress and dated travel/time off stay local; identity alone does not alter dose. You can use the earlier engine and leave these answers blank.
Generated by us about you:
- Fitness, fatigue and form figures; zone distributions; load ratios; the dated daily reports; and a record of the coaching sentences you were shown.
- In V2 beta, structured future plans, source hashes and confidence-labelled assessments/decisions, complete append-only before/after plan revisions, safe undo records and local validator-failure markers. Missing tolerance can use an explicitly labelled population/engineering starter prescription; this is never stored as an observed athlete measurement. Rollback preserves history. These records are included in your account export and deletion.
Operational: when each part of the app last ran and whether it worked, and log lines recording what happened, tagged with your account so they can be separated from anyone else's.
Most of this is health data. Under the GDPR it is "special category" data with extra protection, and we treat it that way.
2. Why, and on what legal basis
| What we do | Article 6 basis | Article 9 condition |
|---|---|---|
| Fetch your records, compute your figures, produce your brief and your plan | 6(1)(b) — performing the agreement you entered when you set the app up. Without this processing there is no service | 9(2)(a) — your explicit consent to us processing your health data |
| Keep your account, consent record and operational logs working | 6(1)(b), and 6(1)(c) where the law requires us to keep a record | — |
| Keep a minimal record that we erased someone when asked | 6(1)(c) and Art. 5(2) accountability — we must be able to show we did it | — |
| If you separately accept AI coaching, send a bounded request to the named processors for coach wording or a proposed training-strategy choice | 6(1)(a) — your separate AI permission | 9(2)(a) — your explicit AI permission |
Why we ask for consent as well as relying on the agreement. The law requires a separate, explicit permission before anyone processes health data. The agreement makes the service lawful; your consent is what allows the health data inside it. You can withdraw that consent at any time — see §7.
We do not use your data to make automated decisions with legal or similarly significant effects. The app gives training guidance you are free to ignore. For future AI-assisted planning, a model may propose one choice among strategies built on your phone; the phone checks constraints and can reject the proposal. The model cannot create workouts, change measurements or publish a plan. For session interpretation and explanations, a separate bounded request carries only the phone assessment code, a reported-pain attention flag encoded in that assessment, confidence and request-local statement aliases. It contains no raw readings, dates, pain descriptions or saved notes. The model can assemble only supported statements; the phone rejects contradictory assessments, missing safety statements or unsupported wording and uses its own explanation.
3. Who else sees it
When you connect intervals.icu, it remains a separate service you use. It controls the records in your intervals.icu account under its own privacy policy. Duraro controls what it reads into this app and the analysis it makes here; your intervals.icu account terms do not replace this notice or Duraro's health-data permission.
- intervals.icu — the source of your training and wellness records. We read from your account with the key you supply, and — only after you approve a plan — we write planned sessions into your calendar there.
Apple Health data is read on your phone under the device permission you choose. We do not upload Apple Health workouts or raw readings to intervals.icu. If you connect both sources, a plan informed by them may be written there only after your approval. We do not sell your data or share it with advertisers or analytics providers. Nothing of yours is sent to an AI or language-model provider unless you separately grant the AI permission, in a build of the app where the coach is connected — today, only the invitation-only test builds described below.
Hosting and model provider for the AI feature
The AI coach is off in the App Store version of the app and connected in invitation-only TestFlight test builds, for athletes we have invited and who separately grant the AI permission. The same two companies serve both.
- Hetzner — we rent one small server in Helsinki, Finland from Hetzner Online GmbH, a German company; Hetzner Finland Oy runs that location. It is the machine that carries your question to the AI coach below. It never stores your training records, your reports or your plans. When app AI is enabled, it holds only a note of what you permitted, which expires after 30 days. The App Store version of the app has no configured AI destination. An invitation-only test build has one: a separate relay that accepts only that build, proved by Apple's App Attest, and only after your AI permission has been recorded there.
- Mistral AI — a French company in Paris whose language model writes the coach's replies. Our recorded agreement and account settings provide for no training on submitted data and zero prompt and reply retention. We use Mistral's EU endpoint. Its agreement permits some processing outside the EEA under safeguards; we have not obtained an EEA-only promise, and we do not make one.
In the App Store version, the AI coach and AI-assisted planning are switched off and the app sends no athlete AI payload. In an invitation-only test build they work only after you grant the AI permission, and stop when you withdraw it. This testing happens before an independent legal review of these documents, which will take place before any public launch; if that matters to you, refuse the AI permission — everything else in the app works without it. The revised AI permission dated 15 September 2026 is separately offered and can be refused or withdrawn without losing the app or its deterministic plan. Grants under older forms do not cover the revised interpretation and explanation purpose; the app asks again.
Where the coach is connected, the coach request can include your typed question, recent training and wellness summaries, changes in those summaries, the app's computed figures, planned-session summary, confidence and data-quality flags. Saved notes are sent only if you tick their separate box. A planning request instead contains only generated candidate identifiers, sport and relative capacity signals, and short request-local goal aliases. It contains no athlete identifier, raw training history, exact dates, name, email or account details. Each request type has a fixed field allow-list in the software. The provider can return words or propose one candidate; the phone checks the proposed choice against your goals, locks, availability, resources and dose limits, and falls back to its own choice if it fails. It cannot create workouts or upload a plan.
Where your training data lives: on your own device. The relay does not store training records; if AI is enabled, it can hold short-lived consent and device-authentication records. Anything intervals.icu holds is governed by its own privacy policy and your account with it.
If you connect intervals.icu, we read from the account you connect using the key you provide. We write planned sessions there only after your explicit upload approval. Its own privacy policy and your account govern records it processes. If you use Apple Health alone, an intervals.icu account and key are not required and we do not send Apple Health records there.
4. How long we keep it
In short: while you use the app, and not long after you stop. The full table is available on request from duraro.support@gmail.com; the summary is:
| Kept for | |
|---|---|
| Your training, wellness and derived figures | While in use; deletion is due 30 days after withdrawal or closure and runs on the next app open; an in-app erasure request runs immediately |
| Your daily reports and plans | The same |
| Consent record | While active, then 3 years after withdrawal or closure — evidence of what we were permitted to do |
| Proof that we erased you | 3 years. It records your account name, the date, and how much was removed — nothing about your health |
| Operational logs | 12 months; the latest integrity anchor retains only timestamps and hashes, without your account identifier |
If processing is restricted, we keep the records and stop ordinary processing; you can still request export or erasure. Expired consent evidence and deletion receipts are removed after verification, leaving a checkpoint of counts and hashes without your account identifier. Deletion cannot run while your phone is off or the app is not running.
Be aware of one honest limitation: log lines written before 30 August 2026 do not record whose they are, and nobody can now determine it. They are never included in an erasure, and we say so rather than claiming a clean sweep.
5. Where it is stored, and how it is protected
V2 beta selection, reports and symptom-review receipts live in the same account-local protected storage as your training data. Full V2 plan revisions are separate from earlier-engine plan history. No new upload or raw-health model request is created by beta selection; AI still needs its separate grant and the enabled processor route. Withdrawal stops ordinary processing of these records too, and the same account-erasure process removes them.
Your data lives in a separate storage area per person — not a shared database with name labels — so one person's data is not reachable from another's. If you use intervals.icu, your key is kept in your phone's Keychain, never in a file inside the app, and signing out forgets it.
Before an intervals.icu pull writes data, we check the account it came from against the one you declared and refuse on any disagreement. Nothing can be uploaded to your calendar without you approving it first, and the app is built so that it cannot happen — it is not a warning we could forget.
No personal data is ever kept in our source code repository, and an automated check fails our build if any appears.
6. Your rights
You have the right to:
- Access — a copy of what we hold about you.
- Rectify — correct anything wrong. Note: records that came from intervals.icu are corrected there, not here; we re-read them each time.
- Erase — have everything deleted. See §7.
- Restrict or object to processing.
- Portability — receive your data in a machine-readable form.
- Withdraw consent at any time, without giving a reason.
- Complain to a supervisory authority — ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI Baden-Württemberg), because that is where we are established. You may complain to the authority where you live, where you work, or where the problem happened — it does not have to be ours.
How to use any of them: contact duraro.support@gmail.com. We answer within one month (Art. 12(3)), and will tell you if we need longer and why. It is free; we would only charge for a request that is manifestly excessive, and we would explain first.
7. Withdrawing consent, and being erased
These are two different things and you can ask for either.
- Withdrawing consent stops us processing your health data going forward. We stop fetching new records and stop computing anything from what we already hold. What we already did stays lawful — withdrawal is not retroactive.
- Erasure removes what we hold.
It is as easy to withdraw as it was to give (Art. 7(3)): one message to duraro.support@gmail.com, or Your data on the front screen of the app.
You can do both from the app — Your data on the front screen. Saving a copy writes two files inside the app and offers them to you straight away, to save to Files or send wherever you choose. Deleting asks you to type DELETE under a list of exactly what will go, and it also signs the phone out and forgets your key.
What erasure cannot reach, stated plainly because you should know before you rely on it:
- your intervals.icu account and everything in it — that is yours and theirs, and we cannot delete it. Ask them, or delete it yourself.
- your API key, if it is in a configuration file on your own computer — we tell you exactly which lines to remove. On a phone this is not a gap: the key is in the Keychain and deleting your data forgets it.
- any backup you made yourself, wherever you put it.
- log lines written before 30 August 2026, as explained in §4.
Everything else goes: your records, your reports and your plans, deleted in full, and your lines removed from the shared logs including the detail printed beneath any error. We keep a receipt — your account name, the date, and counts of what was removed — because we have to be able to show we did it.
8. Do you have to give us this data?
Not by law, and there is no contract obliging you. But the app cannot work without your training records — a coach with no training data has nothing to coach. If you decline, or withdraw consent, the service stops.
9. Children
This service is not for anyone under 18. We do not knowingly hold a child's data. If you believe we do, tell us and we will erase it.
10. Changes
If we change what we do with your data, we will update this notice and its version number. If the change materially affects health data processing we will ask for your consent again rather than treating silence as agreement.
This notice covers processing by Duraro only. intervals.icu, Hetzner and your device maker each have their own.