Privacy Policy
Effective and last updated:
Effort Signal uses your account and activity data to provide and protect the training analysis you request. We do not sell data, run ads, or use personal data for marketing.
Scope and controller
This Privacy Policy explains how Effort Signal, the operator of effortsignal.com (“Effort Signal,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal data when you use the website, applications, APIs, activity analysis, and related features (the “Service”).
Effort Signal is the controller of personal data processed for the purposes described here. Connected services remain independent controllers for their own practices. For privacy questions or requests, contact privacy@effortsignal.com.
Our privacy commitments
- No data sales: We do not sell personal data or consumer health data.
- No advertising: We do not use your data for ads, targeted advertising, or marketing.
- Service use only: We process activity data to provide, secure, support, and improve the Service you request.
- Your rights: You can request access, correction, export, restriction, objection, or deletion as applicable.
Personal data we process
| Category | Examples |
|---|---|
| Account and profile | Email address, name, account identifier, optional date of birth and avatar, timezone, units, display preferences, and sport or training settings. |
| Authentication and security | Password hash, Google account identifier and verified email or name when you use Google sign-in, short-lived access credentials, refresh-session records, CSRF tokens, security events, and account access history. |
| Activity, fitness, and health-related data | FIT, TCX, and GPX files; activity names and timestamps; sport and device details; routes and precise location; heart rate and HRV; power, pace, speed, cadence, elevation, temperature, calories, training load, intervals, laps, body-mass or threshold settings, and derived analyses. |
| Connected-service data | Provider name, external account and activity identifiers, authorization scopes, encrypted connection credentials, sync status, and webhook or delivery metadata for services such as Garmin, Polar, Strava, or Wahoo when enabled. |
| Technical and usage data | IP address, request time and URL, browser and device information, network and diagnostic data, application version, error details, and necessary cookie or local-preference values. |
| Communications | Support, legal, and privacy correspondence and information needed to verify and answer a request. |
Where data comes from
- You: account details, profile settings, files, tags, edits, support messages, and privacy requests.
- Your devices and files: watches, cycling computers, sensors, and exported FIT, TCX, or GPX records.
- Services you connect: Google identity claims when you choose Google sign-in, plus provider accounts, authorized activity downloads, and webhook events when an integration is enabled.
- Automatic collection: browsers, network requests, security systems, cookies, server logs, and error-monitoring tools when you use the Service.
- Derived by Effort Signal: zones, quality indicators, training load, intervals, comparisons, and other analyses calculated from the data above.
Purposes and legal bases
| Purpose | EU/EEA/UK legal basis, where applicable |
|---|---|
| Create and authenticate your account; import, store, analyze, and display activities; apply preferences; provide support. | Performance of our contract with you or steps you request before entering it. |
| Process health-related sensor and fitness data needed for the analysis you request. | Performance of the requested Service under Article 6 and, where Article 9 applies, your explicit consent obtained separately. |
| Protect accounts, prevent abuse, troubleshoot errors, maintain availability, and improve reliability and accessibility. | Our legitimate interests in operating a secure and useful Service, balanced against your rights. |
| Maintain records, respond to lawful requests, enforce terms, and establish or defend legal claims. | Legal obligation or our legitimate interests in compliance and legal protection. |
| Enable an optional provider connection or other optional processing. | Your request, contract, or consent, depending on the feature and applicable law. |
When explicit consent is legally required, we will ask for a clear, separate affirmative action before the relevant processing. This Policy is notice, not consent. You may withdraw consent at any time; withdrawal does not affect earlier lawful processing but may make health-data features unavailable.
We do not use personal data for marketing, advertising, targeted advertising, or data brokerage. Essential account, security, import-status, legal, and support messages are operational communications, not marketing.
Derived metrics and automated processing
The Service automatically parses activity files and derives training and fitness metrics. These calculations help you inspect your own data; they are not used to determine eligibility for employment, insurance, credit, healthcare, housing, or another legal or similarly significant decision. We do not profile you for advertising or marketing. See the Terms of Service for important limits on medical and training reliance.
How data is disclosed
We disclose personal data only in the following circumstances:
- Infrastructure and processors: hosting and database providers, Backblaze for private object storage, Cloudflare for delivery and security, and Sentry for application diagnostics. They process data under instructions to provide operational services.
- Map display: when you open a route map, OpenFreeMap receives network data and the map-tile coordinates needed to render the visible area. Effort Signal does not send your activity’s route geometry to OpenFreeMap.
- Elevation data: when an imported GPX track lacks usable elevation, Amazon Web Services receives Effort Signal’s server network data and the public terrain-tile coordinates needed to complete the profile. We do not send your account identifier, GPX file, or full route geometry.
- Connected providers: Garmin, Polar, Strava, Wahoo, or another service when you direct us to connect, import, disconnect, or otherwise interact with that service.
- Google sign-in: Google receives the OpenID authentication request when you choose Continue with Google and returns the basic identity claims you authorize.
- Legal and safety: authorities, courts, advisers, or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish and defend claims.
- Service transfer: a successor or transaction participant in a merger, financing, reorganization, bankruptcy, or transfer of the Service, subject to confidentiality and applicable privacy law.
- At your direction: another recipient when you ask us to export or disclose data.
We have not sold personal data or shared it for cross-context behavioral advertising in the preceding 12 months. We do not sell consumer health data, and we do not knowingly sell or share personal data of anyone under 16.
Cookies and browser storage
Effort Signal uses only storage needed for authentication, security, navigation, and product preferences. We do not use advertising or marketing cookies.
- Refresh-session cookie: an HttpOnly, same-site credential that keeps you signed in and expires after up to 30 days unless rotated, revoked, or removed sooner.
- CSRF cookie: a same-site security value that helps prevent unauthorized account actions.
- Local storage: limited interface preferences, such as whether chart navigation is expanded. Personal activity records are not stored there by design.
- Session storage: temporary navigation and scroll state that is scoped to the browser session.
Blocking necessary cookies may prevent sign-in. Browser privacy signals such as Global Privacy Control do not change current practices because we do not sell or share data for targeted advertising; if those practices ever change, we will honor legally required signals and provide notice first.
Retention and deletion
We retain each category only for as long as reasonably necessary for the disclosed purpose, taking account of your account status, requested features, security, dispute and legal needs, backup integrity, and applicable limitation periods.
| Data | Retention criteria |
|---|---|
| Account and profile | While the account is active and afterward only as needed to complete a deletion request, protect the Service, resolve disputes, or meet law. |
| Activity files, health-related data, and derived analysis | While needed to provide your activity library and analysis, or until a valid permanent-deletion request, subject to legal exceptions and restricted backups. |
| Provider connections | Until disconnected, expired, or no longer needed for the integration, with limited records retained for security and audit needs. |
| Logs, diagnostics, and request records | For the shortest period reasonably needed for security, reliability, incident response, and legal claims under configured infrastructure and processor schedules. |
| Privacy and legal requests | As needed to demonstrate compliance, prevent fraud, and respond to follow-up requests. |
Current activity deletion is reversible: deleting an activity in the interface removes it from your active library but may retain its original and derived data for recovery. Email privacy@effortsignal.com for permanent deletion. Data in access-restricted backups may remain until that backup is securely retired; if a backup is restored, applicable deletion requests will be reapplied.
Security
We use measures designed for the sensitivity of activity data, including encrypted transport, hashed passwords, short-lived access credentials, same-site session protection, access controls, private object storage, generated media paths, file validation, encrypted provider credentials when stored, monitoring, and backups. No system can guarantee absolute security. You should use a unique password, protect your devices, and notify us promptly of suspected compromise.
International data transfers
The Service and its providers may process data in countries other than your own. Where EU, EEA, UK, or other law restricts international transfers, we use a legally recognized mechanism made available for the relevant transfer, such as an adequacy decision, contractual safeguards, or another permitted derogation, and apply supplementary safeguards where required. You may request information about the safeguard relevant to your data by contacting us.
Your privacy rights
Depending on your location, you may have the right to confirm processing; access or obtain a portable copy; correct inaccurate data; delete data; restrict or object to processing; withdraw consent; opt out of sale, targeted advertising, or qualifying profiling; limit certain uses of sensitive data; and appeal a denied request. We do not discriminate against you for exercising a privacy right.
Submit a request or appeal to privacy@effortsignal.com. Describe the right you wish to exercise and the account email involved. We may verify your identity and authority using information proportionate to the request. An authorized agent may submit a request where law permits, but we may require proof of authority and direct verification. We respond within the time and provide any appeal process required by applicable law.
Some rights have exceptions—for example, where data is needed for security, legal obligations, another person’s rights, or legal claims. If we deny a request, we will explain the basis where required.
EU, EEA, and UK information
In addition to the rights above, you may lodge a complaint with the data-protection authority in the country where you live or work or where you believe an infringement occurred. You may object at any time to processing based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims. Because we do not use personal data for direct marketing, there is no marketing objection workflow to manage.
Health data may be a special category of personal data. Where explicit consent is the applicable Article 9 condition, you can withdraw it by contacting us. The Service does not make solely automated decisions that produce legal or similarly significant effects.
U.S. state privacy notice
To the extent a U.S. state privacy law applies, this section supplements the rest of the Policy. In the preceding 12 months, we collected the following statutory categories for the purposes described above:
| Statutory category | Examples and business-purpose disclosures |
|---|---|
| Identifiers and customer-record information | Email, name, account and provider IDs, IP address, optional birth date, and profile details; disclosed to infrastructure, security, support, and diagnostics providers. |
| Protected characteristics | Age inferred from an optional birth date where provided; processed for user-selected calculations and legal eligibility, not marketing. |
| Internet or electronic-network activity | Requests, interactions, browser information, logs, session records, and diagnostics; disclosed to hosting, Cloudflare, and Sentry for operations and security. |
| Geolocation | Activity routes and precise GPS coordinates; stored by infrastructure processors and used to render maps and route analysis. |
| Sensory, physiological, and health-related information | Heart rate, HRV, power, movement, temperature, body settings, exercise, and device sensor data; disclosed only to processors needed for the requested Service. |
| Inferences | Training load, zones, intervals, fitness comparisons, quality indicators, and related analyses derived for your use. |
| Sensitive personal information | Account credentials, precise geolocation, and health or physiological data; used only to authenticate, secure, and provide the Service you request. |
We obtain these categories from you, your devices and files, connected providers, automatic technical collection, and our own calculations. We have not sold or shared any category for cross-context behavioral advertising in the preceding 12 months. We do not use or disclose sensitive personal information to infer characteristics outside the requested Service.
State residents may use the request process above for applicable access, correction, deletion, portability, opt-out, consent-withdrawal, limitation, and appeal rights. Our separate Consumer Health Data Privacy Policy provides the notice and request details required for health data under laws such as the Washington My Health My Data Act.
Children
The Service is for people aged 18 or older. We do not knowingly collect personal data from a child. If you believe a child has provided data, contact us so we can investigate and delete it as required.
Third-party services and links
A connected provider, map service, or external link may have its own terms and privacy policy. This Policy does not govern a third party’s independent collection or use. Review those policies before enabling an integration or following an external link.
Changes and contact
We may update this Policy when the Service, providers, or law changes. We will post the revised Policy and update the date above. We will provide additional notice or seek consent before a material new use where applicable law requires it.
Contact: Effort Signal, the operator of effortsignal.com, at privacy@effortsignal.com. Terms questions may be sent to legal@effortsignal.com.