Legal

Privacy Policy

Effective date: May 20, 2026  ·  Last updated: September 23, 2026

Haptics collects the minimum data needed to provide its features. Your ride data and AI Coach conversations are synced to Google Firebase so they work across your devices. We do not sell your data, show ads, or share your data with third parties except as described below.

Haptics is available on iPhone, Apple Watch, Android, Wear OS, and Garmin devices. This policy covers all platforms.

What we collect and why

Account information

Haptics offers two sign-in options:

Sign in with Apple. Apple provides a one-time name and an optional private relay email address. Your name is displayed within the app but is never transmitted to our servers or stored in our database. If you choose to hide your email, Apple provides a private relay address instead; we never see your real email.

Sign in with Google. Google provides your name and email address to Firebase Authentication (Google's own infrastructure). Your name is displayed within the app but is never written to our database. Your email is held by Firebase Authentication for account management purposes only.

In both cases, your account is identified in our database solely by an opaque Firebase-generated UID (e.g. vK9mX3pQr2...), never by your name or email.

Ride and training data

Completed rides, imported routes, indoor workout records, and app settings (FTP, power zones, heart rate zones, weight, emergency contact) are stored in Google Firestore under your account. This enables cross-device sync and powers AI Coach analysis.

AI Coach conversations

Messages you send to the AI Coach are transmitted to our Firebase Cloud Functions backend, which forwards them to one of our AI providers for processing — see AI providers under Third-party services for who receives what. Your conversation history is stored in Firestore under your account so the AI Coach can maintain context across sessions.

Anthropic does not use API inputs or outputs to train its models. See Anthropic's privacy policy.

Real-time AI coaching during rides

When the AI Cadence Coach or mid-ride coaching features are active, anonymised ride telemetry — including cadence history (steps or revolutions per minute), heart rate, road grade, and elapsed time — is sent to our Firebase Cloud Functions backend approximately every 45 seconds. This data is forwarded to Anthropic's Claude API to generate real-time coaching cues and cadence target adjustments. This telemetry is not stored after the coaching response is returned.

Rider memory

The AI Coach extracts a short summary of your training profile (fitness level, goals, preferences across cycling, running, and swimming) from your conversations and stores it in Firestore. This is used to personalize future coaching responses. You can view and delete this in Settings.


Where your data lives

DataWhere
Live location during a rideOn-device only, unless you switch on live sharing for that ride — see Live ride sharing
Heart rate (Apple Watch / Wear OS)On-device during the ride; saved into completed ride records in Firestore
Cadence (BLE sensor / Garmin / Wear OS)On-device during the ride; saved into completed ride records in Firestore
Samsung Health ride dataSynced to Firestore under your account on Samsung devices
Strava / Ride with GPS OAuth tokensStored securely server-side in Firestore (never your password)

Third-party services

Google Firebase (Auth + Firestore + Cloud Functions)

Your account data, ride history, AI Coach conversations, and rider memory are stored in Google Firebase. Google's privacy policy.

AI providers

Haptics uses more than one AI provider, because different tasks suit different models. Which provider receives a given piece of data depends on the feature you use.

Anthropic (Claude) — AI Coach conversations, pre-ride briefings, real-time coaching cues, training plans, and monthly performance reports. Anthropic does not use API inputs or outputs to train its models. Anthropic's privacy policy.

Google (Gemini) — workout video you submit for movement analysis, food photos you submit for nutrition analysis, and route briefings. For these features the data sent includes the video or photograph itself, and your FTP and body weight where the feature uses them. Google's privacy policy.

OpenAI — we may route some AI Coach conversations to OpenAI. Where we do, the data sent is the same conversation content described under AI Coach conversations above, and nothing further. OpenAI's privacy policy.

We do not sell your data to any of these providers, and none of them receives your name, email address, or precise location.

RevenueCat (Subscriptions)

Subscription purchases are managed by RevenueCat. RevenueCat receives your App Store transaction data (product ID, purchase date, expiry) to verify entitlements. We never see your payment information. RevenueCat's privacy policy.

Meta (Advertising measurement)

To understand which of our advertising campaigns are effective, we use Meta's advertising tools:

The Haptics app itself does not use the advertising identifier (IDFA) and does not track you across other apps or websites. The subscription measurement above is performed server-to-server and is not tied to a device identifier, and we do not show ads inside the app.

Our marketing website uses cookies for the Meta Pixel. Where required by law (for example, for visitors in the EEA and UK), we ask for your consent before these cookies are set. Meta's privacy policy.

Apple StoreKit (In-App Purchases)

All payment processing is handled by Apple. Apple's privacy policy.

Strava (optional, user-initiated)

If you connect Strava, Haptics exchanges the OAuth authorisation for an access token, which is stored securely server-side in Firestore under your account and used solely to upload completed rides from Haptics to your Strava account. We never import activity data from Strava, and we never see or store your Strava password.

Ride data analyzed by the AI Coach comes exclusively from Haptics' own on-device recording, not from data retrieved via Strava's API. This is consistent with Strava's API agreement, which prohibits the use of Strava-sourced data in AI or machine-learning models. Strava's privacy policy.

Ride with GPS (optional, user-initiated)

If you connect Ride with GPS to import routes, the OAuth access token is stored securely server-side in Firestore under your account and used to make API requests to api.ridewithgps.com on your behalf. Imported route data is stored under your account. We never see or store your Ride with GPS password. Ride with GPS's privacy policy.

Calendars — Apple, Google and Outlook (optional, iOS)

If you turn on Calendar availability and connect a calendar, Haptics reads only when you are busy so your training plan can work around your schedule. We never read event titles, locations, attendees, notes or any other event content.

When you generate a training plan, the busy days are reduced to labels such as “Week 2 Tuesday” and sent to our servers and on to our AI provider (Anthropic) as part of the plan request. Exact times and calendar names are not sent. You can disconnect a calendar or withdraw the Calendar availability consent at any time in Settings.

Haptics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Microsoft's privacy statement.

Garmin Connect IQ (optional, paired device)

On iOS and Android, Haptics communicates with paired Garmin watches and Edge cycling computers via the Garmin Connect IQ Mobile SDK. Haptics sends route cues, coaching messages, and workout data to your Garmin device. Your Garmin device sends heart rate and cadence sensor readings back to the Haptics app during rides. This sensor data is used on-device for haptic feedback and real-time coaching, and is included in completed ride records saved to Firestore. We do not transmit this data to Garmin's servers. Garmin's privacy policy.

Samsung Health (optional, Samsung devices — Android only)

On Samsung Android devices, Haptics can sync completed rides from Samsung Health. Ride data (distance, duration, heart rate) is stored in Firestore under your account. Samsung Health's privacy policy.

Wear OS / Google Health Services (Android only)

On Android, the Haptics Wear OS app reads heart rate, distance, and calories from Google Health Services on your paired Wear OS watch during rides. This data is used on-device to display real-time metrics and is included in completed ride records saved to Firestore via your Android phone. We do not share this data with Google beyond what Health Services itself collects. Google's privacy policy.

PostHog (Product analytics)

We use PostHog to understand how the app is used (for example, which features are opened) so we can improve it. PostHog records in-app usage events along with basic device and app-version information, linked to your Haptics account identifier so that we can investigate problems you report and understand how the app performs for real users. We do not send PostHog your name, email address, ride routes, or health data. We do not combine these events with data from other companies, we do not use them for advertising, and we do not sell them. PostHog's privacy policy.

Google Analytics (Website analytics)

Our marketing website uses Google Analytics 4 to understand aggregate visitor traffic: how many people visit, which pages they view, and which countries and referral sources they come from. Google Analytics uses cookies and records pseudonymous usage data; we do not use it to identify you by name or email, and we do not use it for advertising. Where required by law (for example, for visitors in the EEA and UK), we ask for your consent before these cookies are set. Google's privacy policy.

MailerLite (Email marketing)

If you sign up for our beta waitlist or mailing list, your name and email address are stored with MailerLite, our email marketing provider. MailerLite may record whether you open an email (via an invisible tracking pixel) and whether you click links in our emails (via Google Analytics link tracking). This helps us understand which emails are useful and improve future communications. You can unsubscribe at any time using the link in any email we send. MailerLite's privacy policy.


Location data

Haptics requests "When In Use" location access to track your position along a route during a ride. Your location data is used on-device for navigation and haptic cues, and is not transmitted to us or to anyone else — unless you switch on live sharing for a ride, which is described below.

Live ride sharing

Nothing here happens unless you turn it on. Live sharing is off by default, you switch it on from inside a ride, and it applies to that ride only. Riding without switching it on transmits no route and no position at any point.

What is sent while you are sharing. The route you are following and your live ride data — speed, heart rate, power, cadence, distance, elapsed time and your position on the route — are sent to our Firebase backend so that the page behind your link can draw them. They are sent only for as long as sharing is on.

Who can see it. Only someone holding your link, and only after signing in with Google. The link is a random 32-character token that cannot be guessed, and it is never listed anywhere. If you restrict the link to named people, only those people, signed in with those exact accounts, can open it. Your ride is never public, and the page never reveals your account or email to whoever is watching.

Where you start and finish is withheld by default. About 300 m at each end of the route is removed before a spectator sees it, and your position is hidden while you are inside those zones, so a link does not show the address you set off from. You can switch this off per link if a ride does not start somewhere private.

When it is deleted. The route and ride data are deleted when your ride ends, or the moment you switch sharing off — whichever comes first. If the app is closed or killed mid-ride and never gets to say so, a scheduled job on our backend deletes them instead. The link itself stops working when the ride ends and expires within 12 hours regardless.

Apple Health (HealthKit) data

What we read. With your permission, Haptics reads three things from Apple Health, and nothing else:

Where it goes. Heart rate read during a ride is used on-device for real-time metrics and is included in the completed ride record saved to Firestore. The recovery measurements are stored in Firestore under your account, as a single current snapshot that each sync replaces. Workouts read from Apple Health are copied to Firestore under your account so they survive reinstalling the app or changing handset, and so they appear in the web portal. Without this they would exist only on the one phone that read them.

How it is used, including by AI. Apple Health workouts form part of the training history the AI Coach analyses. When you ask for an analysis, the numbers from those workouts — not your name, and never your location — are sent to our Firebase Cloud Functions backend and forwarded to one of our AI providers to generate coaching. The recovery measurements travel the same path, and are also the one case where coaching is generated without you asking: when a reading is unusual — a high resting heart rate, low heart rate variability or a short night — the backend generates a single short note and puts it in your chat, at most once a day. See AI providers above for who receives what.

What we never do with it. We do not use Apple Health data for advertising, marketing, or any use-based data mining. We do not sell it, and we do not share it with data brokers. We do not store Apple Health data in iCloud. You can revoke access at any time in the Health app under Sharing → Apps, and you can delete individual workouts from within Haptics.

Workouts written by Strava are treated differently. Where a workout in Apple Health was written by the Strava app, Haptics identifies it as Strava's and excludes it from AI analysis, because Strava's API terms do not permit it — see Strava above. This is why we record which app wrote each workout.

Sleep you log yourself. If you enter a night's sleep by hand (for example because you didn't wear your watch to bed), Haptics stores the bedtime, wake time, hours slept and the number of times you woke in your account in Firestore. It is used for your recovery and sleep scores and shared with the AI Coach in the same way as sleep from Apple Health. It is not written to Apple Health. You can remove an entry in the app, and it is deleted with your account.

Health Services data (Wear OS)

The Haptics Wear OS app reads heart rate, distance, and calories from Google Health Services during rides. This data is used on-device to display real-time metrics and is relayed to your paired Android phone to be saved in Firestore as part of your completed ride record. We do not share Health Services data with any third party.

Firebase Crashlytics (Crash reporting)

We use Firebase Crashlytics to collect anonymous crash reports when the app unexpectedly quits. Crashlytics captures the stack trace, device model, iOS version, and app version at the time of the crash. This data is used solely to identify and fix bugs. Crashlytics does not collect your name, email, location, or any personal identifiers. Firebase privacy policy.


Analytics and advertising

We use PostHog for product analytics to understand in-app usage (see the PostHog section above), Google Analytics to understand aggregate visitor traffic on our marketing website (see the Google Analytics section above), MailerLite to send and track our emails (see the MailerLite section above), and Meta's advertising tools to measure how well our marketing campaigns perform (see the Meta section above). We do not show ads inside the app, we do not sell your personal data, and aside from the advertising measurement described above we do not track you across unrelated apps or websites. Crash data collected by Crashlytics is used solely for debugging and is not used for advertising or profiling.

Data retention

Your Firestore data (rides, conversations, settings) is retained as long as your account exists. You can delete your account and all associated data in the app (Settings → Account & Privacy → Delete Account), or by following the steps on our account deletion page.

Children's privacy

Haptics is not directed at children under 13. We do not knowingly collect data from children.

Your rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. If you are in the EEA or UK, you have additional rights under GDPR, including the right to data portability and the right to lodge a complaint with your local supervisory authority.

Changes to this policy

We will update this page if our data practices change. The "Last updated" date at the top reflects the most recent revision.

Contact

Questions or data requests: support@haptics.coach