Privacy Policy
Last Updated: October 11, 2026
Jump to section…
Last Updated: October 11, 2026 Effective Date: May 1, 2026
This Privacy Policy explains how FORMD APP, INC. ("FORMD," "we," "us," "our"), a Delaware corporation formerly known as FORMD APP LLC, a Florida limited liability company, which converted into FORMD APP, INC. effective October 1, 2026, collects, uses, discloses, and protects personal data through:
- The FORMD iOS Mobile App (the "Mobile App");
- The FORMD website at tryformd.com and any subdomains (the "Website");
- The FORMD Coach Platform at coach.tryformd.com (the "Coach Platform");
- All related services, APIs, and offerings (collectively with the items above, the "Services").
This Policy applies to (a) Athletes who use the Mobile App; (b) Coach Customers and Authorized Users who use the Coach Platform; (c) website visitors who browse tryformd.com without registering; and (d) applicants to the FORMD Ambassador Program.
This Policy is incorporated into our Terms of Service. Capitalized terms not defined here have the meanings given there. The Cookie Policy and the Data Processing Agreement form part of this framework and are referenced where relevant.
Plain-language summary at the top. We collect what we need to operate the Services, keep you safe, and provide accurate training plans and predictions. We do not sell your data. We use sub-processors (listed in Section 9) to run the platform. Fitness and health data is treated as sensitive; we do not use HealthKit data for advertising or marketing under any circumstances. You have rights, and we honor them. Contact privacy@tryformd.com to exercise any right.
1. Roles: Controller, Processor, Joint Controller
Different parts of the Services involve FORMD playing different data-protection roles. This matters for who is accountable to whom.
| Context | FORMD's Role | Other Roles |
|---|---|---|
| Athlete uses the Mobile App without a Coach (DTC Pro subscriber) | Controller of the Athlete's personal data | Athlete is the data subject |
| Athlete is connected to a Coach via the Coach Platform | Processor acting on the Coach's documented instructions | The Coach is the controller of Athlete personal data processed for the Coach's coaching purposes; the Athlete is the data subject |
| Athlete uploads data to FORMD via the Mobile App that FORMD also uses to provide and improve the Services | Joint Controller with the Coach (in the limited overlap where FORMD's own purposes apply) | See Section 1.1 below |
| Coach uses the Coach Platform | Controller of the Coach's own personal data (account, billing, support) | The Coach is the data subject for their own data |
| Website visitor browses tryformd.com | Controller | Visitor is the data subject |
| Ambassador Program applicant | Controller | Applicant is the data subject |
1.1 The Joint-Controller Overlap
FORMD operates the Services for two purposes that can overlap with respect to the same Athlete data: (a) providing services to the Coach (where FORMD acts as processor under the Coach's instructions), and (b) operating, securing, and improving the Services for all Users (where FORMD acts as controller for its own legitimate interests and the Athlete's safety and product experience). To make this clear and lawful:
- For coaching-purpose processing (e.g., presenting Athlete data on the Coach's dashboard, generating Coach-driven training plans), FORMD acts as processor and the Coach acts as controller, governed by the DPA.
- For Service-operation processing (e.g., security monitoring, fraud prevention, error logging, aggregated analytics, model training on de-identified data), FORMD acts as controller and is accountable directly to the Athlete under this Policy.
- Where a single processing activity advances both purposes simultaneously (rare in practice), FORMD and the Coach are joint controllers and have allocated their respective responsibilities in the DPA. Athletes may exercise their rights against either or both.
This structure is unusual and is one of the most consequential drafting choices in our legal package. It is explained transparently here so Athletes and Coaches can hold us accountable.
2. Personal Data We Collect
We collect the categories of data described below. Not every category is collected from every User; the actual data we hold for you depends on which products you use and which features you enable.
2.1 Account and Profile Data
- Name, email address, password (hashed; we never see it in plaintext), date of birth, and gender;
- Profile photo (optional);
- Coach role, gym affiliation, location, biography, specialties (Coach Customers and Ambassadors);
- Time zone, language, and notification preferences.
2.2 Fitness and Performance Data ("Special Category" under GDPR Art. 9 — see Section 3)
- Height, weight, body composition (where you choose to provide it);
- Training history, workout logs, completed exercises, sets, reps, weights, and durations;
- Race results (HYROX and other functional fitness events), splits, station performance;
- Race finish-time predictions, station baselines, readiness scores, and analytics derived from your inputs;
- Heart-rate data, heart-rate variability (HRV), sleep data, and other physiological metrics provided through HealthKit (Section 4) or other connected services;
- Training plans assigned by your Coach, your engagement with those plans, and messages exchanged with your Coach.
2.3 Payment and Billing Data
- For Coach Plans: name on card, billing address, last four digits of payment card, card brand and expiration, and Stripe customer/subscription identifiers. We do not store full card numbers, CVV codes, or magnetic stripe data. Stripe is the merchant of record's payment processor and stores card data on its PCI-DSS-certified systems.
- For FORMD Pro (Mobile): RevenueCat customer identifiers, App Store transaction identifiers, subscription status, entitlement state. We do not see your Apple ID, your card data, or your App Store purchase history beyond FORMD-related transactions.
2.4 Communications Data
- Support inquiries (in-app chat via Intercom, email correspondence);
- Survey responses, feedback, NPS scores;
- Messages exchanged between Coach and Athlete on the Coach Platform.
2.5 Device and Usage Data
- Device type, operating system, OS version, app version, browser type and version, IP address, referrer URL, screen size, and time zone;
- App and website interactions: pages viewed, features used, buttons tapped, sessions started and ended, error reports;
- Approximate location derived from IP address (city/region level). The Mobile App may collect precise location only where you have explicitly granted iOS location permission and only for features that require it (currently: none — we do not currently use precise location for any feature).
- Crash and error logs, including stack traces and the state of the app at the time of an error.
2.6 Cookies and Similar Technologies
See the Cookie Policy for the detailed inventory.
2.7 Apple HealthKit Data (Mobile App, with your explicit permission)
With your explicit permission, the Mobile App reads certain Apple HealthKit data types from your iOS device, including workout data, heart rate, HRV, sleep data, and activity data. FORMD's HealthKit commitments are set out in Section 4. They are legally binding commitments under Apple's HealthKit Guidelines and are unaffected by anything else in this Policy.
2.8 Data from Third Parties
- Connected fitness and wearable services (e.g., Strava, Garmin): if you choose to connect, we receive activity, workout, route, and performance data (for Strava, route and location fields are discarded on receipt and never stored; see Section 6.4) and — for services that provide them (e.g., Garmin) — health and recovery metrics such as heart rate, heart-rate variability (HRV), resting heart rate, sleep, stress, Body Battery, Training Readiness, and VO2 max, subject to your settings and consent on those services. How this connected-service data is handled — and, importantly, our binding commitment that it is never shared with or processed by any external AI provider — is described in Section 6.4.
- Sub-processors and infrastructure providers: we receive operational data (e.g., authentication events from Supabase, payment events from Stripe, error events from Sentry).
- Public sources and referrals: for Coach Customers, we may receive contact information through referral programs, manually entered referrals, or public business listings used to verify Coach identity.
- Public race result databases. The FORMD Results feature aggregates publicly available HYROX race results sourced from HYRESULT (hyresult.com), a public race-result index. FORMD displays this data with attribution and provides a one-click removal path for any athlete who does not want their public race result shown in FORMD. Contact privacy@tryformd.com to request removal.
2.9 Data We Do Not Collect
- We do not collect government-issued identification numbers (SSN, Social Security Number, driver's license number), except in the limited Ambassador Program context where required by IRS Form W-9 / W-8 reporting for U.S. payee tax purposes (see Section 2.10).
- We do not collect biometric identifiers (fingerprints, voiceprints, faceprints, retinal scans).
- We do not knowingly collect data from children under thirteen (13).
2.10 Ambassador Program Data
Ambassadors receive payouts and are subject to U.S. tax-information reporting obligations. For Ambassadors, we additionally collect tax form data (Form W-9 for U.S. persons, Form W-8BEN/W-8BEN-E for non-U.S. persons), payout details (PayPal email or other payout instrument), and Ambassador-specific performance data. This data is processed under a U.S. tax-compliance legal basis and retained per IRS requirements (typically seven (7) years).
3. Special Category / Sensitive Personal Data
Fitness and health data — including heart rate, HRV, sleep, training load, and certain inferences about physical condition — is classified as a "special category of personal data" under GDPR Article 9 (UK GDPR Article 9), and as "sensitive personal information" under California's CPRA, "consumer health data" under the Washington My Health My Data Act, and similar terms under other state laws.
3.1 Lawful Basis for Special Category Processing
We process special category data on the following lawful bases under GDPR/UK GDPR (the basis depends on the purpose):
| Purpose | Lawful Basis (GDPR Art. 6 / Art. 9) |
|---|---|
| Provide, personalize, and improve the Services (workout plans, predictions, readiness) | Art. 6(1)(b) (performance of contract) + Art. 9(2)(a) (explicit consent at signup and at HealthKit connection) |
| Connect to a Coach and share data with the Coach | Art. 6(1)(b) (contract) + Art. 9(2)(a) (explicit consent at the moment of accepting the Coach invitation) |
| Maintain Service security, prevent fraud and abuse | Art. 6(1)(f) (legitimate interest) + Art. 9(2)(g) (substantial public interest, in the limited subset where applicable) |
| Comply with legal obligations | Art. 6(1)(c) + Art. 9(2)(g) |
| Aggregated, de-identified analytics | Art. 6(1)(f) (legitimate interest) — outputs do not identify individuals |
For Coach Platform processing where FORMD acts as processor under the Coach's instructions, the Coach is responsible for establishing the lawful basis under Articles 6 and 9, and FORMD's role is to follow the Coach's instructions in accordance with the DPA.
3.2 Sensitive Personal Information under U.S. State Laws
Under CPRA (California), the FDBR (Florida), VCDPA (Virginia), CPA (Colorado), and similar laws, fitness and health data is "sensitive personal information." For California residents, you have the right to limit the use and disclosure of sensitive personal information as described in Section 11. We do not use sensitive personal information for purposes beyond providing the Services as described in this Policy.
California CMIA non-applicability. FORMD is not a healthcare provider as defined under California Health & Safety Code §56.05(m) and is not subject to the California Confidentiality of Medical Information Act (CMIA). Fitness and training data you share with us is governed by the California Consumer Privacy Act (CCPA/CPRA) sensitive personal information framework described in this Section 3.2.
3.3 Washington My Health My Data Act
Washington residents have additional rights under the Washington My Health My Data Act ("MHMDA"), which classifies certain fitness and physiological data as "consumer health data." For Washington residents:
- We obtain affirmative opt-in consent before collecting or sharing consumer health data, in accordance with MHMDA's heightened consent standard;
- We do not sell consumer health data without your separate, valid authorization;
- You may withdraw consent and request deletion at any time at privacy@tryformd.com;
- We have designated a privacy contact for MHMDA inquiries (see Section 14).
4. Apple HealthKit — Binding Commitments
The following commitments apply to all data we read from Apple HealthKit. They are required by Apple's HealthKit Guidelines and are binding on FORMD regardless of any other provision of this Policy.
4.1 What HealthKit Data We Read
With your explicit permission granted through the iOS Health app, the Mobile App reads the following HealthKit data types:
- Workout Data — exercise type, duration, calories burned, distance, route (where present), workout history;
- Heart Rate — resting heart rate, active heart rate during workouts, walking heart rate average, real-time heart rate;
- Heart Rate Variability (HRV) — used to assess recovery and readiness;
- Sleep Data — duration, time asleep/in bed, sleep stages, quality metrics (where present);
- Activity Data — daily step count, active energy burned, exercise minutes, stand hours.
You may grant or revoke permission for each data type independently at any time in iOS Settings → Privacy & Security → Health → FORMD.
4.2 How We Use HealthKit Data
HealthKit data is used exclusively to provide and improve the health and fitness features of FORMD, specifically:
- Personalize training intensity, volume, and exercise selection based on your workout history and recovery;
- Provide recovery and readiness recommendations from HRV and sleep trends;
- Auto-import completed workouts so you don't have to log them manually;
- Improve race finish-time predictions using your physiological metrics;
- Assess daily training readiness.
4.3 What We Will Never Do With HealthKit Data
In accordance with Apple's HealthKit Guidelines and our binding commitments to you:
- We will NEVER sell HealthKit data. Under no circumstances. Not to data brokers, not to advertisers, not to anyone.
- We will NEVER share HealthKit data with third parties for advertising or marketing purposes.
- We will NEVER share HealthKit data with third parties for purposes unrelated to providing or improving health and fitness features.
- We will NEVER disclose HealthKit data to third parties except (a) with your explicit, written consent; (b) to sub-processors who are bound by confidentiality and who require the data solely to provide the Services to FORMD; or (c) where required by law.
- We will NEVER use HealthKit data for any purpose other than providing health and fitness services as described in this Policy.
4.4 HealthKit Data Storage, Encryption, and Retention
- Where possible, HealthKit data is processed on-device to minimize transmission;
- HealthKit data transmitted to our servers is encrypted in transit (TLS 1.3) and at rest (AES-256);
- HealthKit data is stored separately from other user data, with additional access controls and audit logging;
- HealthKit data is retained only as long as needed to provide the health and fitness features. When you delete your account or revoke HealthKit permission, we delete your HealthKit data from our servers within thirty (30) days, except where retention is required by law.
4.5 Coach Access to HealthKit Data
A Coach who is connected to an Athlete may see workout data, performance data, and certain readiness indicators that are derived from HealthKit input. Coaches do not see raw HealthKit data types you have not chosen to share with them. The data shared with Coaches is governed by the in-product permission disclosure shown to the Athlete at the moment of connecting to a Coach.
5. How We Use Personal Data
We use personal data for the following purposes. Where required by GDPR/UK GDPR, we identify the lawful basis.
| Purpose | Lawful Basis (GDPR) |
|---|---|
| Create and authenticate accounts; deliver the Services you signed up for | Art. 6(1)(b) — contract |
| Generate AI training plans, race predictions, station baselines, and other personalized features | Art. 6(1)(b) — contract; Art. 9(2)(a) — explicit consent for fitness/health data |
| Process payments, billing, refunds, and tax compliance | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation |
| Send transactional messages (account, billing, security, important platform notices) | Art. 6(1)(b) — contract |
| Send product updates and marketing (with your consent where required) | Art. 6(1)(a) — consent (where required); Art. 6(1)(f) — legitimate interest (where allowed) |
| Provide customer support | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest |
| Detect, prevent, and respond to fraud, abuse, and security threats | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) — legal obligation |
| Maintain logs, backups, audit trails, and disaster recovery | Art. 6(1)(f) — legitimate interest |
| Conduct aggregated, de-identified analytics to improve the Services | Art. 6(1)(f) — legitimate interest; data is de-identified before analysis |
| Train, fine-tune, or evaluate AI/ML models that operate the Services (e.g., workout-plan generator, exercise swap recommender). We use only de-identified or aggregated data for cross-user model improvement; we do not use a single user's identifiable HealthKit data to train models that benefit other users. | Art. 6(1)(f) — legitimate interest, with strict de-identification |
| Comply with legal obligations and respond to valid legal process | Art. 6(1)(c) — legal obligation |
| Defend, exercise, or establish legal claims | Art. 6(1)(f) — legitimate interest |
6. AI/ML and Automated Decision-Making
6.1 What's Automated
The Services use automated processing to:
- Generate AI-drafted training plans (using a third-party large-language-model provider — currently OpenAI — under our enterprise data-processing agreement and configured to not retain training data beyond what is needed to return the response);
- Compute race-readiness scores, projected finish times, and station baselines from your training data;
- Recommend exercise swaps and adjust workout difficulty;
- Detect fraud, abuse, and security anomalies.
6.2 No "Solely Automated" Decisions With Legal or Similarly Significant Effects
These automated processes do not produce decisions that have legal or similarly significant effects on you within the meaning of GDPR Art. 22. Training plan content is informational and educational, not medical advice, and you remain free to follow, modify, or ignore any recommendation. Where you would like a human review of an automated suggestion, contact privacy@tryformd.com or your Coach.
6.3 OpenAI Subprocessor
Prompts and responses sent to OpenAI for training-plan generation include only the minimum context needed to produce a useful plan (e.g., training preferences, baseline times, race goals). HealthKit identifiers and raw HealthKit data are not sent to OpenAI. Our agreement with OpenAI configures the API to not use customer data for OpenAI's own model training. See the DPA for further detail.
6.4 Connected Wearable and Health Data — No External AI or Third-Party Processing
The data we obtain from connected wearable and health services — including Apple HealthKit, Garmin (via the Garmin Connect Developer Program APIs), and Strava — meaning the samples, measurements, records, and identifiers those services provide to us — is never shared with, transmitted to, processed by, or otherwise made available to any external artificial-intelligence provider (including OpenAI) or any third-party data-processing service. The single, narrow exception for certain derived training-trend indicators is described in the third paragraph of this Section; that exception never applies to Garmin or Strava data.
This connected-service data is processed solely within FORMD's own systems — for example: calibrating your training baselines, computing recovery- and readiness-based adjustments to your prescribed training load, importing your completed activities, and displaying your metrics back to you. These computations run on our own infrastructure, not on any artificial-intelligence provider's systems.
Our AI-assisted features (currently powered by OpenAI, as described in Sections 6.1–6.3) operate on the profile information and goals you enter directly (such as race goal, division, training days, and equipment), together with a limited set of derived training-trend indicators — for example, a seven-day resting-heart-rate or heart-rate-variability trend expressed as a change relative to your own recent baseline — that are computed within FORMD's own systems from connected-service data where you have enabled recovery-based personalization. These indicators describe only the direction and size of a change in your own recent trend. The raw connected-service samples, measurements, and identifiers from which they are computed are never sent to any external artificial-intelligence provider. Data obtained from the Garmin Connect Developer Program APIs is never shared with, transmitted to, or processed by any external artificial-intelligence provider in any form, whether raw or derived; this exclusion is enforced by a structural source filter in our systems and is a condition of our participation in that program. Data obtained from Strava is likewise never shared with, transmitted to, or processed by any external artificial-intelligence provider in any form, whether raw or derived.
Strava. If you connect Strava, we import the activities you recorded on Strava in the last 7 days, including activities you have set to "Only You": the sport type, start time, duration, distance, and average heart rate. Strava's API also sends route and location fields; we discard them and never store them. While you are connected we keep your Strava athlete ID and encrypted access tokens on our servers, and your Strava display name on your device. Strava data is shown only to you: it is never shown to coaches or other users, never used for advertising or analytics, and never sent to any artificial-intelligence provider in any form, whether raw or derived. We keep imported Strava activity data for no more than 7 days. When you disconnect Strava in the app, we revoke FORMD's access with Strava, delete your Strava activity data immediately, confirm the deletion in the app, and delete the rest of your Strava connection record within 30 days. If you revoke FORMD in your Strava settings instead, we delete the same data on the same schedule. Strava may monitor and collect usage data about how FORMD uses the Strava API and may use that data for any business purpose, including improving the Strava API and the Strava platform, providing support, and ensuring compliance with Strava's API Agreement.
These are binding commitments and a condition of our participation in wearable-partner developer programs (including the Garmin Connect Developer Program). They apply regardless of any other provision of this Policy.
7. How We Share Personal Data
We do not sell your personal data. We do not engage in cross-context behavioral advertising. We share personal data only as described below.
7.1 With Your Coach (Athletes)
If you are an Athlete connected to a Coach, the Coach has access to your Athlete Data on the Coach Platform for the purposes of coaching you. The categories of data available to the Coach are disclosed at the time you accept the Coach's invitation. Data imported from Strava is never available to Coaches (Section 6.4). The Coach acts as a controller of that data for the Coach's purposes.
7.2 With Service Providers (Sub-processors)
We share personal data with the sub-processors listed in Section 9, each of which performs functions on our behalf under contractual obligations consistent with this Policy and (where applicable) GDPR Art. 28 / SCCs.
7.3 With FORMD Personnel and Contractors
Our personnel and approved contractors access personal data only on a need-to-know basis, under confidentiality obligations, and subject to access controls and audit logging.
7.4 With Legal and Government Authorities
We may disclose personal data when we reasonably believe disclosure is required by law, regulation, valid legal process (subpoena, warrant, court order), or to protect rights, property, or safety. Where legally permitted, we will notify the affected User.
7.5 In Connection With Business Transactions
If FORMD is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of substantially all assets, personal data may be transferred as part of that transaction. The acquirer will be bound to honor the commitments in this Policy or a successor policy that is no less protective.
7.6 With Your Consent
Where you give us specific, informed consent (e.g., to share a workout to social media, to publish a testimonial), we share data in accordance with that consent.
7.7 Aggregated and De-identified Data
We may share aggregated and de-identified data that cannot reasonably be used to re-identify a person. We do not attempt to re-identify, and we contractually prohibit recipients from attempting to re-identify, such data.
8. International Transfers
Our infrastructure is primarily hosted in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with cross-border data-transfer rules, your personal data will be transferred to and processed in the United States and other jurisdictions where our sub-processors operate.
We rely on the following lawful transfer mechanisms:
- Standard Contractual Clauses (SCCs) — the European Commission's 2021 SCCs (Modules 2 and 3 as applicable) and, for U.K. transfers, the U.K. International Data Transfer Addendum, are incorporated into our contracts with all relevant sub-processors and into the DPA;
- Supplementary measures — encryption in transit and at rest, access controls, and (where applicable) data minimization to reduce reliance on jurisdictional protections;
- Adequacy decisions — where applicable to a destination country.
You can request a copy of the applicable transfer mechanism by emailing privacy@tryformd.com.
9. Sub-processors
We use the following sub-processors to operate the Services. Each is bound by a written agreement consistent with GDPR Art. 28 (where applicable) and our security and confidentiality requirements.
| Sub-processor | Service Provided | Categories of Data Processed | Hosting Location | Transfer Mechanism (for EU/UK data) |
|---|---|---|---|---|
| Supabase, Inc. | Database (Postgres), authentication, file storage | Account, profile, fitness, support data | US East (AWS) | SCCs |
| Stripe, Inc. | Payment processing for Coach Plans (subscriptions, billing, customer portal) | Coach billing, payment, tax data | Global (primary US) | SCCs |
| RevenueCat, Inc. | Subscription management for FORMD Pro (Mobile) | Mobile subscription state, App Store entitlement events | US (AWS) | SCCs |
| Resend, Inc. | Transactional email delivery | Recipient email, message content | US (AWS) | SCCs |
| Mixpanel, Inc. | Product analytics | Pseudonymized usage events, device data | US (Google Cloud) | SCCs |
| Functional Software, Inc. (Sentry.io) | Error monitoring and crash reporting | Error events, stack traces, device data | US | SCCs |
| Intercom, Inc. | In-product customer support | Support conversations, contact data | US (AWS) | SCCs |
| OpenAI, L.L.C. | AI training-plan generation (prompts and responses) | Training preferences, baseline times, race goals, plan output. No raw HealthKit data. | US | SCCs; OpenAI configured to not use customer data for model training |
| Cloudflare, Inc. | Edge security, DDoS mitigation, request routing | IP addresses, request metadata | Global edge | SCCs |
| Vercel, Inc. | Website hosting (tryformd.com) | Request logs, deployment metadata | Global edge | SCCs |
| Expo (Expo Go / EAS) | Mobile push notification delivery, OTA update distribution | Device push tokens, notification payload metadata, device identifiers | US (AWS) | SCCs |
| Apple Inc. (via the App Store and HealthKit) | App distribution, in-app purchase, HealthKit data source | Apple ID identifier (transactional only), purchase data, HealthKit data (with your permission) | US | Apple's published terms |
| Google Cloud (subprocessor of certain providers above) | Underlying cloud infrastructure for some sub-processors | As applicable | US | Indirect (via the contracting sub-processor) |
We update this list whenever we add, remove, or change a sub-processor. Material changes will be communicated in advance under the change-notice process in Section 13. Coach Customers can view a real-time list at tryformd.com/sub-processors and may, where required by their applicable law, object to a new sub-processor in accordance with the DPA.
Note on HYRESULT: HYRESULT (hyresult.com) is described in Section 2.8 as a public race-result data source that FORMD reads from. HYRESULT does not act as a FORMD sub-processor under GDPR Art. 28 (FORMD does not transmit Customer Personal Data to HYRESULT; HYRESULT publishes race results independently and FORMD reads them as it would any public record). It is intentionally not in the sub-processor table for that reason.
10. Data Retention
We retain personal data for the periods set out below, longer where required by law, shorter where a reasonable business purpose has ended.
| Data Category | Retention Period |
|---|---|
| Active account and profile data | While the account is active |
| Athlete fitness and performance data | While the account is active; 30 days after deletion request, then deleted or anonymized |
| Coach Customer billing data | Active period + 7 years (tax/audit) |
| Support conversations | 3 years from last interaction |
| Error logs and crash reports | 90 days |
| Audit logs (security, admin actions) | 1 year (longer for incidents under investigation) |
| Backup and disaster-recovery snapshots | Up to 35 days, then automatically purged |
| HealthKit data (after revocation or account deletion) | Deleted within 30 days |
| Strava activity data | Up to 7 days from import; deleted immediately when you disconnect Strava or revoke FORMD in Strava (Section 6.4) |
| Ambassador tax records (W-9, W-8BEN, payouts) | 7 years (IRS) |
| Anonymized / aggregated analytics | Indefinitely (no longer personal data) |
| Data subject to a legal hold | Until the hold is lifted |
When you delete your account, we delete or anonymize the categories above on the schedules indicated. Some residual data may persist in routine backups for up to 35 days; restored backups are purged of deleted accounts on next overwrite. Aggregated analytics that no longer identify you may be retained indefinitely.
11. Your Rights
11.1 Rights We Honor for All Users
Subject to verification of your identity and lawful exceptions, you may:
- Access the personal data we hold about you and receive a copy in a portable, machine-readable format;
- Correct inaccurate or incomplete personal data;
- Delete your personal data;
- Restrict or object to certain processing (e.g., direct marketing, legitimate-interest processing);
- Withdraw consent where processing is based on consent (without affecting processing already performed);
- Lodge a complaint with a supervisory authority. EU/UK Users may complain to the data protection authority of their habitual residence; California Users may complain to the California Privacy Protection Agency; other jurisdictions have their own authorities.
11.2 GDPR / UK GDPR Rights (Articles 15–22)
In addition to Section 11.1, EU/UK Users have the right to data portability and rights related to automated decision-making (Section 6 explains why GDPR Art. 22 is generally not engaged here). You may exercise these rights free of charge once per twelve-month period; we may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests.
11.3 California (CCPA / CPRA)
California residents have the rights to know, delete, correct, opt out of sale or sharing for cross-context behavioral advertising (which we do not engage in regardless), limit the use and disclosure of sensitive personal information (Section 3.2), and not be discriminated against for exercising these rights. To exercise:
- Email privacy@tryformd.com with the subject line "California Privacy Request";
- Use our online request form at tryformd.com/privacy/request (when published);
- Authorized agents may submit requests on your behalf with proof of authorization.
We will respond within 45 days (extendable by 45 more with notice).
11.4 Florida Digital Bill of Rights (FDBR)
Florida residents may confirm processing, access, correct, delete, port, and opt out of targeted advertising, sale, or profiling for decisions producing legal or similarly significant effects. We do not engage in targeted advertising or sale of personal data. Exercise rights at privacy@tryformd.com.
11.5 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Other State Consumer Privacy Laws
Residents of these states may exercise rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling. Submit requests at privacy@tryformd.com. We will respond within the statutory time frame applicable to each state (typically 45 days, extendable as permitted).
11.6 Washington My Health My Data Act
Washington residents have the rights described in Section 3.3, including the right to confirm processing, access, delete consumer health data, and withdraw consent.
11.7 New York SHIELD Act
For New York residents, our security program is designed to satisfy the SHIELD Act's reasonable-security requirements. We provide breach notification under Section 12 in accordance with SHIELD Act timelines for New York residents affected.
11.8 How to Submit a Request
- Email: privacy@tryformd.com (subject line should describe the right being exercised — e.g., "Access Request," "Deletion Request," "Opt-Out of Sensitive Data").
- In-product: Settings → Privacy → Manage My Data (Coach Platform and Mobile App).
- For Athletes connected to a Coach: Where the Coach is the controller, we will (a) facilitate the request to the Coach if your request relates to coaching data, and (b) act directly on the request for any data where FORMD is the controller. We respond within thirty (30) days unless statutory law allows longer.
11.9 Verification
We will take reasonable steps to verify your identity before responding (typically by confirming control of the email address on the account, or by other means proportionate to the sensitivity of the request). For Authorized Agents, we may require additional documentation.
11.10 No Retaliation
We will not retaliate against you for exercising any right under this Policy or applicable law.
12. Security and Breach Notification
12.1 Security Program
We implement administrative, physical, and technical safeguards designed to protect personal data, including:
- Encryption in transit (TLS 1.2+ everywhere; TLS 1.3 where supported) and at rest (AES-256);
- Strong authentication (Supabase Auth with email + password, and OAuth providers as applicable);
- Role-based access control (RBAC) and least-privilege access for FORMD personnel;
- Audit logging of administrative actions;
- Routine vulnerability scanning and dependency management;
- Security testing (internal review and, periodically, third-party assessment);
- Data minimization (we collect what we need and no more);
- Incident-response runbooks and tabletop exercises.
No system is perfectly secure; we cannot guarantee absolute security.
12.2 Breach Notification
If we become aware of a personal data breach that creates a risk to the rights and freedoms of natural persons, we will:
- Notify the relevant supervisory authority within 72 hours (or, where the breach affects only Coach Platform data processed under the DPA, notify the Coach without undue delay so the Coach can meet its 72-hour obligation as controller);
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
- For U.S. state law breaches, comply with the notification timelines and content requirements of each applicable state law (e.g., Florida, California, New York SHIELD, Washington);
- Document and retain breach records under GDPR Art. 33(5).
New York SHIELD Act — direct notification. For New York residents, we will notify you directly, without unreasonable delay, if a breach affects your private information as defined under the New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act).
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent change. For material changes (e.g., new data uses, new sub-processors, changes to your rights), we will notify you by email (where we have your email) and by in-product banner at least thirty (30) days before the change takes effect. Continued use of the Services after the effective date of an updated Policy constitutes acceptance.
14. Contact Us
FORMD APP, INC. Email (privacy): privacy@tryformd.com Email (legal): legal@tryformd.com Email (support): support@tryformd.com Email (security): security@tryformd.com Mailing: Mailing address available upon written request to legal@tryformd.com, State of Florida, United States Web: tryformd.com
Privacy Contact for U.S. State Laws: Adam Aboelmatty / FORMD APP, INC., privacy@tryformd.com.
EU / UK Representative: FORMD is in the process of appointing its Article 27 representatives for the European Union and the United Kingdom; this section will be updated with their names and contact details upon completion of that appointment. In the interim, EU and UK data subjects may direct any inquiry to privacy@tryformd.com.
If you read this whole document — thank you. You're the kind of careful person we want using FORMD. If anything here is unclear or seems wrong for your situation, write to privacy@tryformd.com and we'll talk to you, not at you.