Privacy Policy
Last updated August 22, 2026
The short version
Oxygon works entirely on your device and does not require an account. If you choose to sign in, your race plans, saved products, and settings are backed up to our server so they sync across your devices — nothing else. There are no analytics, no advertising, and no tracking of any kind, and your data is never sold or shared for marketing.
What the app stores on your device
Whether or not you sign in, the app saves the following locally using Apple's standard on-device storage (UserDefaults):
- Your race plans (distances, target times, checkpoints, fuel and reminders)
- Products you save or scan
- Your saved Favorites (pace, time, and distance combinations)
- Your profile (age, weight, and optional resting/maximum heart rate) and your unit, appearance, and accent colour preferences
- Activities you record with the app: the route (location, only while an activity is running), pace, and — if you connect them — heart rate from a strap, glucose from a sensor, and temperature/humidity from an environment tag
- Training sessions you import from Strava, Apple Health, Health Connect or intervals.icu (summaries: date, distance, time, heart rate, elevation), any lab report you import, and the coach profile and training plan built from them
Signed out, none of this leaves your device, and deleting the app deletes it.
If you create an account
Signing in is optional and exists solely to back up your data and sync it between your devices. If you do sign in:
- Your email address is stored to identify your account and to send you sign-in codes. There is no password.
- Your race plans, recorded activities, imported training-session summaries, coach profile and plan, saved products, favorites, and settings — including the profile fields above (age, weight, heart rate) — are stored on our server so they can be restored on your other devices.
This data is hosted on Supabase on servers in the European Union, and is protected by row-level security so that your account is the only one able to read or write your data. It is used only to provide sync. It is never sold, never shared with advertisers, and never used to profile you.
You can sign out at any time, which stops syncing and leaves your data on the device. To delete your account and everything stored with it, use Delete Account in Settings — it removes your account and all synced data permanently, and leaves your plans on this device. You can also email the address below.
Third parties we rely on
- Supabase — hosts your account and synced data (EU region). Acts only as our processor.
- FairyMail — delivers your sign-in code emails, and receives your email address to do so.
- Strava (only if you connect it) — with your permission we read your activities and profile to compute your training metrics and history. Strava data is shown only to you, is never used with the AI assistant, and is never shared with anyone. Strava may collect usage data about this integration under its API Policy. Disconnect any time in Settings → Connected apps, or at strava.com/settings/apps.
- Apple Health (only if you allow it) — workouts, heart rate and related samples are read on your device to compute your training metrics. Nothing is written back.
- Health Connect (Android, only if you allow it) — workouts, distance, elevation and heart rate are read on your device to compute your training metrics. Nothing is written back. Oxygon asks for history beyond the last 30 days because a training plan is built against a whole year — thirty days cannot tell a base phase from a taper. Revoke any time in Settings, or in Health Connect itself.
- intervals.icu (only if you connect it) — with the API key you provide we read your activity summaries and wellness data to compute your training metrics and history. The key is stored on your device only. Disconnect any time in Settings.
- Anthropic — when you ask the coach or the race assistant a question, the question, your plan and your interview answers are sent to Anthropic's API to produce the reply. If you import a lab report, the document itself is sent there too, once, so its stage table can be read; nothing it returns is used until you have checked it on screen. Strava data is never included. Anthropic does not train on API data.
- Open-Meteo — the forecast for a race location is fetched from their public weather API; only coordinates and dates are sent.
- Crew link (only if you share one) — while an activity is running, your position, pace, heart rate and glucose are published to a private link you choose to share, so your crew can follow you. Anyone with the link can see it for the duration of the activity.
- Open Food Facts — when you scan a product barcode, the barcode is sent to their public database to look up its nutrition. No personal data or account information is included in that request.
What the app does not do
- No analytics, crash reporting, or usage tracking
- No advertising or ad tracking
- No access to contacts or photos; location is used only while you record an activity and is stored with that activity
- No selling or sharing of your data with third parties for their own purposes
- No account required — every feature except sync works signed out
Changes to this policy
If this policy ever changes — for example, if a future version of the app adds a feature that uses data differently — this page will be updated and the "Last updated" date above will reflect that.
Contact
Questions about this policy can be sent to zanon.robert@gmail.com.