Openness
Privacy and the AI coach
Which data never leaves the platform and how explanations about your wellbeing are produced.
6 min read
To work out your load and the status of the day, the platform stores some fairly sensitive things about you: heart rate, variability, sleep, answers about how you feel, your health questionnaire. Next to all that lives the AI coach — an assistant that explains decisions in plain language. There is a line between these two worlds, and it is built as a prohibition, not a preference.
What is stored and where
Your profile, your health questionnaire answers and their outcome, any training restriction and the rule that fired, symptoms you have flagged, your cycle log and pregnancy flag, injury history, heart rate, variability, sleep, your morning check-in answers and the calculated readiness — all of it sits in the platform's database on servers in Russia.
None of it travels outwards: neither Strava nor intervals.icu receives it, nor analytics, nor a language model. We rent our servers, our email and our cloud from contractors in Russia, and they act on the operator's instructions — the list is in the Policy.
The language model does not see this
Medical and personal data are never passed to a language model — in no form at all, anonymised included.
The ban also covers what the engine derives from them: the colour and reason of your readiness, signs of illness, cycle data, pregnancy, signs of energy deficiency, injuries and the medical reason for a change to your plan. A derived value inherits the regime of its source: the sentence “today is amber because your variability has dropped” is information about your condition too.
Removing your name and email is not enough. Anonymisation on its own does not open the door for health fields, and that is written down as a rule, not as an intention.
What does go to the assistant: anonymised, non-medical training context — your training phase, load scores, your goal, planned sessions and what each of them is for, the non-medical fact that a session was completed, and an action the engine has already allowed. Everything else is cut off at the entrance.
Medical explanations are written by a template, not the model
When the platform explains why a day is red or why the plan has been paused, the text is assembled by a template written in advance, with your values slotted into it. The screen receives a template number and safe substitutions, not text invented by a model.
Two consequences follow. The explanation is identical under identical conditions, and it can be checked. And it keeps working even if the language model is unavailable entirely.
What the AI coach can do
The assistant reads only the permitted part of your data and cannot change the plan directly. It does not lift restrictions and draws no conclusions about your health.
What it can do is ask the engine: move, shorten, swap or remove a session, rebuild the week. The engine prepares a proposal showing “before — after”, you accept or reject it with one tap, and only then is the change applied — with a fresh check on the server.
Hard safety rules — a full stop and a paused plan — are applied and lifted by the calculation itself, with no involvement from the model and no way around it.
The rule is simple: the engine calculates and decides, the assistant explains. The numbers in its answer are the same ones on your session card, not invented afresh.
Consents and your control
Ordinary personal data, health data and the daily wellbeing check-in are three separate consents, not one shared tick box: for health data the law requires a separate consent, and we ask for it separately. The wellbeing check-in and the cycle log are off by default; the check-in is switched on by its own separate consent.
Any consent can be withdrawn, with no reason given. Here is what happens to the calculation when you do: that channel goes to “no data”, not to “normal”. An amber or red day will not turn green because of a withdrawal, and restrictions already in force will not be lifted — switching off data collection is not a way to remove a restriction.
The consequences differ from one consent to another. Withdrawing consent for the check-in switches the questionnaire off and deletes the history of your answers, and affects nothing else. Withdrawing consent for health data stops the key functions: without heart rate, variability and the questionnaire the platform does not calculate load and does not build a plan, and the data itself is deleted within no more than 30 days.
Notifications and the Strava caption are two separate switches in your profile, and both can be turned off at any time. The notification is a single text without details because it passes through Apple's and Google's servers; the Strava caption is off by default, and before you switch it on you see samples for every outcome — undershoot and overshoot included — and exactly what goes out: training figures, nothing about health or readiness.
Viewing your data, exporting it, your account settings and deleting your account are never blocked — including by the consent-update screen. Otherwise the only way to refuse consent would be to stay in the product.
What is kept longer than the rest
Your confirmation that you saw a doctor and were cleared to return to training goes into a separate log: the date and time of the confirmation, the date of the visit you gave, your IP address and browser details, the version, the language and the exact text you were looking at in that moment. Without this there is no way to prove what exactly you confirmed.
The log survives a withdrawal of consent and is kept for as long as your account exists, and for up to three years after it is deleted. This is stated directly in the Policy rather than done quietly. It is not used in running the service after a withdrawal: not in calculations, not in restrictions, not in the interface.
The platform does not ask for or store your diagnosis, medical documents, medication names or the medical reason for a restriction. Only the user can record the confirmation, from their own account: support and administrators have no such action.
Where to find the details
The full list of data, the purposes of processing, retention periods, your rights and how to withdraw consent are in the Privacy Policy. It also says who the operator is and where to write with questions about your data.
The medical disclaimer — “the service is not a medical service and does not replace a doctor” — lives in the Terms of Use and in the consent texts. We deliberately do not repeat it on every screen in the interface: repeated at every step, it stops being read. But the route to help is always there in the interface — and how that works is described in “Safety and where medicine begins”.
Terms in this article
What to read next
- Data and connectionsWhere your workouts come from, what the platform computes itself, and what happens when data doesn't arrive.
- Readiness: your traffic lightHow the platform decides whether to push today or hold back — and why it sometimes stays honestly silent.
- How we make methodology decisionsWhy some rules are fixed, some adjustable, and some we don't ship at all.