Legal
Privacy Policy
Effective Date: February 15, 2026
1. Introduction
Welcome to Coach Watts ("we," "our," or "us"). This service is operated by Watt Mind Kft., a company headquartered in Gödöllő, Hungary. We are committed to protecting the privacy of your personal and physiological information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our AI-powered coaching application (the "Service").
2. Information We Collect
We act on the principle of Data Minimization, collecting only what is strictly necessary to provide accurate AI coaching.
A. Account & Identity Data
Identifiers: Name, email address, profile picture, and authentication credentials (via providers like Google, Apple, or email).
B. Sensitive Health & Biometric Data
Note: Under Hungarian and European Union Law (GDPR), this is classified as "Sensitive Data" which requires your explicit consent.
We collect physiological data only when you connect third-party services (such as Strava, Garmin, Whoop, etc.), including:
- Performance Metrics: Power outputs (Watts), Heart Rate, GPS routes, speed, cadence, and duration.
- Biometrics: Weight, height, date of birth (used for age and heart rate zone calculation), FTP, Vo2Max.
- Recovery: Heart Rate Variability (HRV), Resting Heart Rate, Sleep stages, and Sleep quality.
C. Technical & Usage Data
Device information, IP address, browser type, and interaction logs with our AI chat interface.
3. How We Use Your Data
We use your data for specific, limited purposes:
| Purpose | Data Types Used |
|---|---|
| Provide Coaching Services | Health & Biometric Data, Account Data |
| Account Management | Account Data |
| Service Improvement | Usage Data (Aggregated/Anonymized) |
| Security & Compliance | Usage Data, Account Data |
AI Analysis: We process your Health Data using Google Gemini (Vertex AI) to generate personalized training insights.
No Training on Your Data: We utilize enterprise-grade API agreements which state that your personal health data is NOT used to train Google's public AI models. Your data remains contained within our deployment environment.
4. Legal Basis for Processing
We process your personal information based on the following legal grounds:
- Contractual Necessity: To create your account and deliver the services you requested.
- Explicit Consent: We obtain your explicit consent before collecting and processing your Sensitive Health Data. You may withdraw this consent at any time by disconnecting your data sources.
- Legitimate Interests: To improve our services, ensure security, and detect fraud.
5. Sharing and Disclosure
We do not sell your personal data. We disclose data only to the following trusted processors who assist in operating our Service:
- Cloud Infrastructure: Supabase & Vercel (Database and Hosting).
- AI Processors: Google Cloud Platform (Vertex AI).
- Payment Processors: Stripe (for billing).
- Legal Obligations: We may disclose data if required by law, subpoena, or to protect the safety of any person.
API Limited Use Disclosure: Our use and transfer of information received from Google APIs (e.g., Health Connect) to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. International Data Transfers
Watt Mind Kft. is located in Hungary (European Union).
Data Storage: While we are headquartered in the EU, our trusted cloud providers (Supabase, Vercel, Google Cloud) may process data in the United States or other regions. We ensure that such transfers are protected by standard contractual clauses (SCCs) or other legally recognized transfer mechanisms to ensure a level of data protection equivalent to that in the EU.
7. Data Retention & Deletion
Retention: We retain your Health Data only as long as you maintain an active account to build longitudinal training history.
Deletion: You can request account deletion at any time via the "Danger Zone" in the app settings. Upon request, all personal data is permanently purged from our active databases within 30 days.
8. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: Know what data we hold about you and receive a copy.
- Right to Correction: Fix inaccurate or incomplete personal data.
- Right to Deletion: Request full deletion of your data ("Right to be Forgotten").
- Right to Portability: Receive your data in a structured, machine-readable format.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Object: Object to our processing of your data based on legitimate interests.
- Right to Withdraw Consent: Stop the processing of your Health Data at any time.
To exercise these rights, please contact us at [email protected].
Supervisory Authority
If you believe we have not processed your data in accordance with GDPR, you have the right to lodge a complaint with your local data protection authority. In Hungary, this is:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
H-1055 Budapest, Falk Miksa utca 9-11.
https://naih.hu
9. Children
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We reserve the right to modify this policy. If we make material changes to how we handle your Health Data, we will notify you via email or in-app alert.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices:
