LOCUS FIT

Privacy Policy

Last updated: August 2026

This policy covers the Locus Fit coaching web platform and the Locus Fit iOS app, which are two ways into the same account and the same data. The Locus Fit Garmin watch app collects very different things and has its own privacy policy. What you may and may not do with the service is set out in the terms of service.

Locus Fit (“we”) builds training analysis software for sprint kayak and canoe. This policy explains what the platform and the iOS app collect about you, why, who can see it, and how to get it deleted. It applies to both athletes and coaches.

The short version: we collect your training data so that you and the coaches you train under can analyse it. We do not sell it, we do not advertise, and you can have it deleted by sending one email.

What we collect

Account and profile

Your email address and display name. You can sign in with an email address and password, with Google, or with Apple; when you use Google or Apple, we receive your email address and name from them and never see your password. If you use Apple’s Hide My Email, we only ever hold the relay address Apple gives us, and we treat it as your real address — account email we send goes there.

If you complete onboarding or your coach fills in your profile, we also store training details you or your coach provide: date of birth, sex, height, weight, discipline (canoe or kayak), paddling side, maximum heart rate, heart-rate and stroke-rate zones, and the squad, team and training groups you belong to. Some of this is health information, and we treat it that way.

Training sessions

When a session reaches the platform — uploaded by you, by your coach, or fetched with your authorisation from a linked watch account — we store the activity file and what we derive from it:

  • the raw activity (FIT) file, which contains your GPS track, heart rate, speed and motion-sensor data
  • session summaries: distance, duration, pace, heart rate, calories, stroke rate, stroke count and training effect
  • the intervals we detect within the session, and how they compare against the workout you were prescribed
  • motion-sensor analysis derived from the file, used to measure stroke mechanics
  • anything you add yourself: rate of perceived exertion, readiness, and session notes

Things you upload

Coaches can upload photographs of training whiteboards, printed schedules and time-control sheets, and files of regatta results, so we can read the prescribed workouts and results out of them. These images and files often contain other athletes’ names and times. We store the uploaded file and the structured data we extract from it, and we only make it visible within the squad it was uploaded to.

If you link your watch account

You can optionally link the account you use with your watch vendor so that new sessions reach the platform without manual uploads, and you can unlink it at any time. If you link one, we store the account’s email address and an access token, both encrypted at rest. We never store the account’s password. We then retrieve, on your behalf:

  • your paddling and training activities, including their files
  • daily wellness metrics: sleep, resting heart rate, heart-rate variability, stress, body battery, steps, respiration, blood-oxygen saturation and training readiness

This data is retrieved solely to display your training and recovery to you and to the coaches of squads you have joined. It is never sold, shared with data brokers or advertisers, or used for any purpose beyond the analysis described in this policy. Data originating from your watch vendor is submitted to Locus Fit, not to the vendor, and the vendor has no responsibility or liability for how we handle it. Unlinking the account stops all further retrieval.

Using the iOS app

The iOS app is a view onto the same account, so it collects the same training data described above rather than a separate set. Two things are specific to it:

  • Your sign-in tokens are held in the iOS Keychain on your own device, encrypted by the system and readable only by this app. Signing out removes them.
  • If you allow notifications, we store the notification token Apple issues for your device, along with the platform and app version, so we can send you a session report when it is ready. Turning notifications off in iOS Settings stops it being used.

The app has no third-party analytics or advertising SDK in it. It does not track you across other apps or websites, and it does not read your location in the background — the GPS in your sessions comes from the activity file your watch recorded, not from your phone. It does record how you use the app itself, on our own servers, which is described next.

How you use the app

We record what happens as you use the web platform and the iOS app: which screens you open, which steps of setting up your account you complete, which errors you hit, and when a link to your watch vendor fails. Each record holds the screen or route, what the outcome was, an error code where there was one, a random identifier for your browser or device, and your account once you are signed in. Screen names are stored as routes rather than addresses, so the record says you opened a session, not which one.

This is collected by our own servers and stored in our own database. There is no third-party analytics or advertising SDK involved — no analytics company receives anything about you, nothing is sold, and nothing is shared. We use it for one purpose: to find what is broken and to finish what people cannot. A sign-up step that half of people abandon, or an integration that has been failing quietly for a fortnight, is invisible to us otherwise.

If your browser sends a Do Not Track or Global Privacy Control signal, the web app sends none of this from your browser and leaves off the identifier described above.

Technical logs

Like any web service, our servers keep short-lived request logs — timestamps, IP address, and which endpoint was called — for reliability, security and debugging. We do not use them for profiling or advertising, and we do not share them.

How we use it

  • To show you and your coaches your sessions, intervals, trends and training load
  • To match a completed session against the workout you were prescribed and grade how closely you hit it
  • To generate written session reports (see below)
  • To deliver the scheduled workouts and training zones that your watch fetches
  • To send you and the squad owner service email about your account, such as sign-up and upload notifications
  • To see which parts of the app people get stuck in or fail to finish, so we can fix them
  • To operate, secure, debug and improve the platform

We do not use your data for advertising, we do not profile you for anyone else, and we do not make automated decisions about you that have legal or similarly significant effects.

Automated analysis and AI providers

Session reports and some workout parsing are generated with large-language-model services run by Anthropic, Google and Microsoft Azure, and with Google’s vision models when reading an uploaded photograph. What we send them is the training content needed to produce the output: session and interval metrics, the prescribed workout, your training zones, your display name, and the contents of an uploaded image where applicable.

We use these services under their business API terms, which state that data submitted through the API is not used to train their models. We do not send your email address, date of birth, or watch-account credentials to them.

Who can see your data

  • You. Everything on your own account.
  • Coaches of squads you belong to. Your profile, sessions, session files, reports, training load, test results and — if you have linked your watch account — your daily wellness metrics. This is the point of the product: joining a squad means sharing your training data with that squad’s coaches. Leaving the squad ends that access.
  • Other athletes. Only where the platform is explicitly showing squad-level information, such as crew rosters, regatta results and squad leaderboards. Other athletes cannot open your session files or wellness data.
  • Us. Locus Fit staff can access accounts and session data where it is needed to run the service, investigate a fault or answer a support request. This access is restricted to the operator of the service.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not disclose it to anyone else except where we are legally required to.

Service providers

We use the following providers to run the platform. Each processes data only to provide their service to us:

  • Railway — application hosting and database
  • Google Firebase — sign-in and account authentication
  • Apple — Sign in with Apple, if you choose it, and delivery of notifications to the iOS app
  • Google Cloud Storage — storage of activity files and uploaded images
  • Resend — transactional email delivery
  • Anthropic, Google and Microsoft Azure — the automated analysis described above
  • Your watch vendor — the source of synced activity and wellness data, if you link an account; they handle the data on their side under their own privacy policy

These providers operate infrastructure in several countries, including the United States, so your data may be stored or processed outside your own country and may be subject to the laws of those countries.

Research use

We may use training data to research paddling performance — for example, to improve stroke detection or build performance benchmarks. This only happens if you have explicitly opted in, it is recorded against your account as a separate consent, and you can withdraw it at any time by emailing us. Data used for research is identified by a research code rather than your name. Without your opt-in, your data is never used for research.

How long we keep it

We keep your account and training data for as long as your account is active, because training history only has value over time — comparing this season against the last is the entire point. If you delete your account, we delete it as described below. Technical logs are kept for a short period and then rotate out. The usage records described above are kept for about six months and then deleted; only aggregate daily counts, which are not about any one person, survive that.

Your rights and deleting your data

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or withdraw a consent you have given. Depending on where you live, these rights come from Canadian privacy law (PIPEDA), the UK and EU GDPR, or a comparable local law.

To exercise any of them, email support@locus.fit. We will respond within 30 days. Deleting your account removes your profile, sessions, activity files, reports and any stored watch-account link and synced wellness data. Some information may remain in encrypted backups for a short period before those rotate out.

You can unlink your watch account at any time from your account settings without deleting the rest of your account. If you believe we have mishandled your data, you may complain to your national privacy regulator — in Canada, the Office of the Privacy Commissioner.

Security

Traffic to the platform is encrypted in transit. Linked watch-account details and access tokens are encrypted at rest with a key held separately from the database. Watch tokens are stored only as a cryptographic hash. Access to production data is limited to the operator of the service. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant regulator as the law requires.

Young athletes

The platform is built for organised squads, which include junior athletes. Accounts for athletes under 16 should be set up with the involvement of a parent or guardian, and a parent or guardian may exercise any of the rights above on their behalf by emailing us. We do not knowingly collect data from children outside a squad context.

Changes to this policy

If we change what we collect or who we share it with, we will update this page and change the date at the top. Material changes will be emailed to account holders.

Contact

Questions, requests, or anything you think this page gets wrong:

support@locus.fit · locus.fit

Locus Fit is an independent developer and is not affiliated with, sponsored by, or endorsed by Garmin. Activity files on your watch and in Garmin Connect are handled by Garmin under Garmin’s own privacy policy.