Tuin · privacy

Your data, plainly.

Tuin is a tool shared between friends, not a company harvesting data. Here is exactly what it keeps and what it never does.

What Tuin stores

Your name and photo from Strava, your OAuth tokens (server-only, never sent to the browser), your training plan and chat history, and derived training numbers per run — distance, time, elevation, average heart rate, and computed training stress (TSS/NGP).

What Tuin never stores

Raw GPS tracks, per-second streams, or your location history. Streams are read once, in memory, to compute a run's training stress — then discarded. This is also what Strava's API agreement requires.

Health data, in the app

The iPhone app uses Apple's HealthKit; the Android app uses Health Connect. If you connect either, Tuin imports your workouts — distance, time, elevation, heart rate — to compute the same training numbers it computes for Strava runs. It never reads your location or routes: Tuin doesn't even request that permission, and health data is never used for advertising or shared with anyone. Tuin writes back to Apple Health only when you send a planned workout to your watch. Sync can be switched off in Settings any time, access can be revoked in Health → Sharing → Apps → Tuin, and deleting your account erases these workouts like everything else.

Signing in, and your email

You can sign in with Strava, Google, or Apple. Tuin keeps only what it needs to recognise you — the provider's anonymous ID and, from Google or Apple, the email they share (Apple's Hide My Email works fine). Your passwords never touch Tuin; they stay with the provider. Your email is for reaching you about your own training, never for selling.

Who sees it

Only you see your data — every table is keyed to your athlete ID and locked behind server-only access. No other athlete, no advertiser, no data broker. The single exception is the AI that writes your coaching, which has its own section below.

The AI coach

Tuin's plans and chat replies are written by Claude, an AI service run by Anthropic PBC in the United States. With your permission — asked for in the app before anything is sent, and withdrawable at any time in Settings → App — Tuin sends Claude your run summaries (date, distance, time, elevation, average heart rate and the training-stress numbers computed from them), your plan and goal race, your chat messages and Tuin's earlier replies, your first name, your stated training preferences, and the notes you write about how a session felt. That data reaches Tuin from Strava's API, from Apple Health or Health Connect if you connect them, from files you upload, and from what you type. It is used for exactly one thing: generating the coaching text you asked for. Anthropic processes it to produce the reply and does not use it to train its models; their API terms commit them to protections equivalent to those described on this page. Never sent: your GPS tracks or location, your email address, your OAuth tokens, and your payment details. If you decline, Tuin keeps importing and scoring your runs and keeps your calendar — it simply won't write or adjust a plan or reply in chat.

Ads, and counting visits

If you arrive from an ad, Tuin notes the campaign name in a cookie on your own browser for 30 days, and keeps it on your account if you sign up — purely so it can tell whether an ad was worth paying for. It's a first-party cookie holding a campaign name, not a profile of you, and it can't follow you to other sites. Separately, page visits are counted in aggregate by Vercel Web Analytics: how many people opened a page, roughly where from, on what kind of device. It sets no cookie, and it never tells Tuin who you are. Both go when your account goes.

Delete everything, any time

In the app, go to Settings → App → Delete account (there's also a "Delete account" link at the foot of every dashboard page). It erases your account, tokens, plan, chat, and every derived number — immediately and irreversibly, honoring the GDPR right to erasure. The one thing kept is the anonymous service-cost ledger (call counts and their cost — no name, no runs, no words), retained as billing records under GDPR Art. 17(3). You can also just ask Jordi, the data custodian for this group.

If you only left your email

An address on the beta list is just that — an address, plus whatever you typed in the note. It's used once, to tell you Tuin is open, and you can ask for it to be deleted at any time.

← back to Tuin

Privacy — Tuin