Privacy Policy
Last updated: 13 July 2026
Fondista is an adaptive running-coach app. This policy explains what personal data the app collects, why, who processes it, and the choices you have. We collect only what the app needs to build and adapt your training plan. We do not sell your data, and we never use your health data for advertising.
Who we are
Fondista is operated by Paul-Antoine Dostie-Guindon, an individual developer (the “data controller”). For any privacy question or request, contact paulantoinedg@gmail.com.
Data we collect and why
- Account — your email address and password (stored only as a secure hash by our authentication provider). Used to create and secure your account and sign you in.
- Profile & goals — name, date of birth (optional), experience level, units preference, your race, goal date and goal time, and how many days a week you can train. Used to personalise your training plan.
- Training data — your fitness estimate and pace zones, your generated plans, completed runs you log (distance, duration, pace, and per-interval detail), your “too easy / about right / too hard / skipped” session ratings, and the record of every plan change. Used to build your plan and adapt it to how your training actually goes.
- Health data (Apple Health) — only if you connect Apple Health: completed running workouts (date, distance, duration, pace), heart rate for those workouts, and VO2max estimates. Used to import runs you’ve already done and to track your fitness trend. See the section below.
- Purchases — records of in-app purchases (a plan-credit pack) and the resulting credit balance. Used to grant what you bought and prevent duplicate credits. Payment itself is handled by Apple — we never see your card details.
- Free-text notes — anything you write in the onboarding “anything we should know?” box. Used to place sessions around your schedule, travel, or niggles.
Apple Health (HealthKit)
Read-only, with your consent. Connecting Apple Health is entirely optional and off until you turn it on. When you do, the app requests read-only access to your running workouts, running distance, workout heart rate, and VO2max. The app never writes anything to Apple Health.
Runs and VO2max estimates read from Apple Health are stored on our backend (see below) so your plan can adapt over time. In line with Apple’s rules, health data obtained through HealthKit is never used for advertising or marketing, and is never sold or shared with third parties for their own purposes. You can disconnect Apple Health at any time in the app, and revoke access in the iOS Health app’s settings.
How your data is used
- To generate your training plan and adjust it as you train.
- To show your progress, history of plan changes, and fitness trend.
- To operate the app: authentication, saving your data, and processing purchases.
- To keep the service secure and debug problems.
We do not use your data for advertising, and we do not sell your personal data.
Service providers we share data with
We use a small number of processors that handle data on our behalf, only to provide the app:
- Supabase — hosts our database and authentication and stores your account and training data, protected by row-level security so each account can only access its own data.
- Anthropic (Claude) — when you generate a plan, your training context and any onboarding notes you wrote are sent to Anthropic’s API to propose the plan’s shape. This data is used only to generate your plan; it is not used to train models and is not used for advertising.
- Apple — processes in-app purchases and provides HealthKit. Your payment details are handled by Apple and are never shared with us.
We may also disclose data if required by law. We do not otherwise share your personal data with third parties.
How long we keep it
We keep your data for as long as your account exists. You can permanently delete your account at any time from Profile → Delete account. Deleting your account removes your profile, goals, plans, logged runs, session ratings, adaptation history, imported health data (including VO2max), and purchase records from our backend. This is immediate and cannot be undone.
Security
Data is encrypted in transit. Access is scoped per-account by row-level security, so one account can never read another’s data. Passwords are stored only as secure hashes by our authentication provider.
International transfers
Our providers may process data on servers outside your country, including in the United States. Where required, we rely on appropriate safeguards for such transfers.
Children
Fondista is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect data from them.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can delete your account in-app, and for any other request contact us at paulantoinedg@gmail.com.
Changes to this policy
If we change this policy we will update the date at the top of this page. Significant changes will be reflected in the app.
Contact
Questions or requests: paulantoinedg@gmail.com.