Version 1.0 · 10 September 2026
VeloGrit is a cycling coach that reads your training and health data from intervals.icu and bases its advice on it. That requires processing data about your health. This statement describes what that data is, why it's processed, who gets to see it, and what rights you have. It applies to VeloGrit, available at velogrit.cc.
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
No data protection officer has been appointed. That isn't required for a project of this size: the processing isn't large-scale and doesn't form the core activity. Questions about this statement can be sent to the address above.
Using that access token, VeloGrit retrieves the following data from your intervals.icu account:
Heart rate variability, resting heart rate, sleep and VO2max are data concerning health. That is a special category of personal data under Article 9 GDPR, subject to stricter rules. See Chapter 4.
This data is not stored. It is fetched live from intervals.icu the moment you open a screen or ask the coach a question, used to compose your answer, and then discarded. So there is no store of your HRV, sleep or ride data on VeloGrit's servers. What is retained is what you enter yourself and what the coach replies to you.
| Purpose | Which data |
|---|---|
| Giving you a training plan and coaching advice | Training and health data, check-ins, FTP, weight |
| Showing your progress in charts and the trophy case | Training data, power curves |
| Sending you a sign-in link and separating your account from other users | Email address, sign-in code, session token, user ID |
| Keeping AI costs from running out of control | Usage data |
| Detecting faults and securing the service | Technical logs |
| Improving the service based on your experience | What you report yourself; no automatic analysis of your data |
Your data is not used commercially. It is not sold, not rented out, and not shared with advertisers, insurers, employers or data brokers. No advertising is shown and no profiles are built for marketing purposes. Your data is also not used to train AI models — not by VeloGrit and, under the terms of the API VeloGrit uses, not by Anthropic either.
For ordinary personal data, processing rests on consent (Article 6(1)(a) GDPR). You give that consent by creating an account with your email address and connecting your intervals.icu account.
For health data, the prohibition in Article 9(1) GDPR applies. Processing rests on the exception for explicit consent (Article 9(2)(a) GDPR). By connecting your intervals.icu account while knowing it holds HRV, sleep and heart rate data, you give that explicit consent.
Consent is voluntary and always revocable. You revoke it by deleting your account through the app's settings, or by revoking VeloGrit's access in your intervals.icu settings. Withdrawing consent does not affect the lawfulness of processing before that point. Without this data VeloGrit cannot function; the service then stops.
For the hosting provider's security logs, the basis is legitimate interest (Article 6(1)(f) GDPR) in keeping the service available and secure.
Your data is shared with the following parties, acting either as processor or as an independent controller:
| Party | Role and what they receive |
|---|---|
| Cloudflare, Inc. | Hosting and storage. All data mentioned in this statement resides on their infrastructure. |
| Anthropic PBC | Provides the language model behind the coach. Receives the data sent along with a coaching conversation: your question and its context, including your recent training and health data, FTP and weight. |
| Resend | Sends the sign-in links. Receives only your email address and the content of that email. |
| intervals.icu | Source of your training and health data. Your relationship with intervals.icu falls under their own privacy terms, not this statement. |
No one else gets access. There are no staff members, no third-party analytics services and no trackers. VeloGrit's administrator can technically access the stored data because he manages the storage; that only happens for maintenance and troubleshooting.
Cloudflare and Anthropic are based in the United States and may process data outside the European Economic Area. That transfer takes place on the basis of the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. Both parties offer a data processing agreement as part of their terms.
| Data | Retention period |
|---|---|
| Your account, training data, check-ins and coaching conversations | Until you delete your account, and up to one month afterwards |
| Your access token for intervals.icu | Encrypted, until you delete your account or revoke the connection |
| Coaching conversations | One year; they expire automatically after that |
| HRV, sleep, rides, power curves | Not stored |
| Sign-in codes | 15 minutes, or until used |
| Session token | 30 days, or until you sign out |
| Usage data | Per calendar month; deleted when the account is deleted |
| Data held by Anthropic | Automatically deleted within 30 days of receipt, under their API usage policy |
| Technical logs at Cloudflare | Per Cloudflare's retention policy |
An inactive account is deleted after six months of no use. You'll be notified of this beforehand at the email address you sign in with, so you can sign in if you want to keep it.
Your intervals.icu token is stored encrypted (AES-256-GCM). The decryption key isn't in the storage but in the server environment, so access to storage alone isn't enough to read your token. You can also revoke that token at any time via intervals.icu's own settings. VeloGrit doesn't process passwords and has no access to your intervals.icu account itself.
Should a data breach be discovered despite these measures, posing a risk to your rights and freedoms, you will be informed and the breach will be reported to the Dutch Data Protection Authority, in line with Articles 33 and 34 GDPR.
Under the GDPR you have the following rights:
Send a request to the address in Chapter 1. You'll receive a response within one month. To prevent data from ending up with the wrong person, additional information may be requested to link your request to your account.
If you disagree with how a request was handled, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague — autoriteitpersoonsgegevens.nl.
VeloGrit uses a language model to generate training advice based on your data. This is not automated decision-making with legal effect within the meaning of Article 22 GDPR: the advice has no legal consequences and doesn't affect you in any significant way. You are always free to disregard the advice.
VeloGrit is not a medical device and doesn't give medical advice. The advice is based on sports-physiology rules of thumb and on the data you provide. It is no substitute for a doctor, sports physician, physiotherapist or dietitian.
Consult a doctor before starting a training programme, especially with existing complaints, cardiovascular conditions, injuries, pregnancy or medication use. If you experience chest pain, dizziness, shortness of breath or other worrying symptoms during or after exercise, stop immediately and seek medical help.
A language model can make mistakes and give inaccurate or unwise advice. Judge every piece of advice with common sense, and listen to your body.
VeloGrit is a paid service with a free trial period. The advice is generated with the help of a language model; the service is under continuous development and may change. What you can expect from us, and where the limits lie, is set out in the terms of service; those take precedence over what's stated here.
To the extent permitted by law, no liability is accepted for:
This exclusion does not apply in cases of intent or deliberate recklessness, and not to the extent that mandatory law prohibits it. If you are a consumer, your statutory rights remain fully in force; a liability exclusion cannot override them.
The obligations arising from the GDPR are not limited by this chapter. Your rights under Chapter 8 remain fully in effect.
VeloGrit sets one cookie: a session token that keeps you signed in. This is a strictly necessary functional cookie; no consent is required for it, so no cookie banner appears. No analytics cookies, tracking cookies or third-party cookies are set.
The app also keeps a copy of your data in your browser's local storage, so screens load faster. That copy is cleared when you sign out.
A full overview of what's stored in your browser is in the cookie policy.
VeloGrit is not directed at people under the age of 16. If you are under 16, only use the service with the consent of a parent or guardian.
This statement may be updated, for instance if the app changes or a new party becomes involved in the processing. The current version is always available on this page, with the date and version number at the top. In case of significant changes, users are actively notified via the email address or channel through which they were invited.
Questions about this statement:
Back to VeloGrit · About VeloGrit · Terms of Service · Cookie Policy