Privacy Policy
Version 2.4 — July 31, 2026
1. Who We Are
Gradescale is operated by:
Thomas Mortelmans (sole trader)
Switzerland
Email: legal@gradescale.fit
A postal contact address is available on request to any user or authority via the email above.
For users in the European Economic Area, the United Kingdom, and Switzerland, Thomas Mortelmans is the data controller for the personal data described in this policy.
Gradescale is currently an invitation-only closed beta, offered in Switzerland, the European Economic Area, and the United Kingdom only. An account can only be created with an invitation we issue, which is how we control who is admitted. It is not offered to users in the United States, and we do not knowingly enrol them.
EEA and UK representative. We have assessed whether a representative must be appointed under Article 27 GDPR and Article 27 UK GDPR, and have documented that assessment. We will appoint and name representatives here if and when the processing ceases to fall within the Article 27(2) exception, and in any event before we admit users beyond the closed beta.
2. What Gradescale Does
Gradescale is a training analytics platform for endurance athletes. It takes the training data you choose to connect or upload and turns it into analysis: fitness and fatigue modelling, workout insights, readiness scores, and personal records. Your data is used to run the service for you. We do not sell it, and we do not use it for advertising.
3. Where Your Data Comes From
- Training accounts you connect. You can authorise Gradescale to import your activities from services such as Strava, or from other training platforms and devices we support. You control the connection: you can disconnect at any time, either in Gradescale or at the provider, and disconnecting leads to the deletion of the data we imported for you (see Section 11). Each provider's own privacy policy governs what that provider does.
- Files you upload and information you enter directly (check-ins, goals, planned workouts, settings, your email address).
- Technical data created by using the service (see Section 4).
4. What We Collect
- Account data: your athlete identifier at the connected provider, display name, profile picture, and the email address you give us. Sign-in credentials for connected providers are held as encrypted tokens and are deleted when the session they belong to ends, when you disconnect, or when your account is deleted.
- Training data: activities (title, sport, time, distance, elevation) and their detailed recordings — power, heart rate, cadence, altitude, GPS location, and speed.
- Well-being check-ins you choose to submit: sleep, stress, soreness, and similar.
- Derived data we compute: training load, readiness scores, performance models, personal records.
- Consent and acknowledgement records: when we present a legal document to you we record the document and version (including a fingerprint of the exact text), the time, your IP address, browser or app details, platform, language shown, and the country it came from. We record what you actually did with each document, because they are not the same act:
- Terms of Service — accepted.
- This Privacy Policy — provided to and acknowledged by you.
- Health-data processing — explicitly consented to.
- Product analytics — consented to, or refused.
- Coach sharing — explicitly consented to.
- Newsletter — consented to.
- Feedback you send us: the text you write, the page you were on, your rating, which features you say you used, and what you tell us is missing. If you attach screenshots (up to three per report), we store the images. Location metadata is removed from them on your device before upload, but a screenshot still shows whatever was on your screen, which is usually your own training data. Feedback text is free-form, so it often contains health information — symptoms, injuries, how a session felt. Please treat it as you would any message about your health. Where you tell us it is fine to reply, we keep your email address with the report; where you do not, we do not.
- Technical data: IP address and request metadata in short-lived infrastructure logs; error reports that are data-minimised before they leave your device or browser (Section 14); and, only if you opt in, product-usage events (Section 7). When you send feedback we may also attach diagnostic context from that browser session — recent in-app errors, which screens you moved through, the requests the app made and whether they succeeded, and the app version — so a report can be acted on without a conversation. The same minimisation as our error reports applies: location coordinates and the query part of web addresses (which can carry invitation links) are stripped before it leaves your browser, and we never capture your stored sign-in credentials.
- Payment data: none. Payments are switched off during the closed beta and no payment provider processes your data. Before enabling paid subscriptions we will name the provider, the data it receives, the legal bases, and the transfer safeguards in this policy.
5. Health Data and Your Explicit Consent
Heart-rate data, well-being check-ins, and the physiological metrics we derive from them say something about your body. Data protection law treats this as a special category of personal data, and we process it only with your explicit consent, which we ask for separately in the Health Data Processing Consent. That document — a separate, unticked checkbox at signup and a separate prompt for existing users — records the explicit consent (GDPR Art. 9(2)(a)) we rely on for all health-related processing in Gradescale.
It also explains how withdrawal works: withdrawing your health-data consent takes effect immediately — processing stops, access to the service ends, and deletion of your health and training data begins. Withdrawal cannot be cancelled, and the 30-day grace period that applies to ordinary account deletion does not apply to it. We keep a minimal record of the consent you gave and of your withdrawal, as evidence.
6. Why We Use Your Data, and On What Legal Basis
- Running the service you signed up for — importing, storing, and analysing your training data, syncing your settings between devices, and authenticating you: performance of a contract (Art. 6(1)(b)), and for health-related processing your explicit consent (Art. 9(2)(a)) as described in Section 5.
- Product analytics — only with your separate opt-in consent (Art. 6(1)(a)); see Section 7.
- Transactional account emails — verification, deletion confirmations, and service notices: performance of a contract (Art. 6(1)(b)), or our legitimate interests (Art. 6(1)(f)) where the message is not strictly contractual.
- Newsletter and product marketing — your consent (Art. 6(1)(a)).
- Optional weather lookup for an activity — performance of the feature you requested (Art. 6(1)(b)); any consent required for the underlying location data is obtained separately.
- Coach relationship administration — invitations, roster, and revocation: performance of a contract (Art. 6(1)(b)).
- Disclosing health-related training data to a coach — your separate explicit consent (Art. 9(2)(a)); see Section 12.
- Support correspondence — performance of a contract (Art. 6(1)(b)) and our legitimate interests (Art. 6(1)(f)) in resolving your request.
- Consent, withdrawal, and deletion records — compliance with a legal obligation (Art. 6(1)(c)) and our legitimate interests (Art. 6(1)(f)) in demonstrating compliance and defending legal claims.
- Mobile app distribution and, in future, subscription entitlements— performance of a contract (Art. 6(1)(b)) and compliance with app-store obligations.
- Security and service stability — short-lived technical logs, abuse prevention, and error reports: our legitimate interests (Art. 6(1)(f)). We rely on legitimate interests only where, after weighing the interests and risks involved, the processing is proportionate and your rights do not take precedence.
- Legal obligations (Art. 6(1)(c)) — keeping records the law requires us to keep, and responding to lawful requests.
We do not use your data for advertising or sell it to anyone.
7. Analytics, Cookies, and Similar Technologies
Strictly necessary storage. Signing in sets a session cookie (nb_session) that only authenticates you, and a short-lived cookie that protects the sign-in flow against forgery. The apps also use local storage on your device for settings and offline data. None of this tracks you across other websites.
Product analytics are off by default. Nothing analytics-related loads, runs, or sets an identifier until you choose "Accept" in the consent banner — on any page, including our public pages. If you accept, feature-usage events (for example, "a sync ran", "a page was opened") are recorded under a one-way-hashed identifier and processed for us by an EU-hosted analytics provider. These events do not contain your training values, health data, location traces, or email address. If your browser sends a Do Not Track signal, we treat that as a refusal. You can withdraw at any time in Settings or via the banner; withdrawal stops collection immediately and does not affect the service.
If you withdraw, we delete the analytics events already collected about you— both the events held by our analytics provider and the first-party events on our own systems. We do not keep them under an alternative legal basis. Analytics events are in any case deleted within 90 days.
We use no advertising cookies, no tracking pixels, and no fingerprinting.
8. Who Receives Your Data
We disclose personal data only to the recipients below, their vetted subprocessors, recipients you authorise, and otherwise where the law requires it.
Data sources (independent controllers):
- Connected training providers (e.g. Strava): they are the source of the data you authorise us to import and are independently responsible for their own processing.
Strava API usage information. Strava may monitor and collect information about Gradescale's access to and use of the Strava API. Strava may use that information for purposes including operating and improving its API and platform, providing support, and checking compliance with its developer terms. Strava processes this information under its own privacy policy.
Service providers (processors working for us):
- Cloudflare — hosting our API and database at its global edge network, and storing the screenshots you attach to feedback (Cloudflare R2).
- GitHub, Inc. (United States) — our issue tracker. When you send feedback, we file it as an issue in our private repository so it can be fixed and tracked. That issue quotes your feedback text as you wrote it, together with the page you were on, your rating, and a shortened reference to your account rather than your name or email. Where you attached screenshots, it carries expiring links to view them (below). Because feedback is free text, it regularly contains health information, so GitHub processes health data on our behalfwhen it does. GitHub is not permitted to use any of it for its own purposes. If you would rather your words were not stored in our issue tracker, please do not put anything in a feedback form you are not comfortable with us keeping there — email us instead at privacy@gradescale.fit.
- Vercel — hosting the web application.
- Sentry — error monitoring; reports are data-minimised and pseudonymised before sending (Section 14).
- PostHog (EU Cloud) — consent-based product analytics (Section 7), hosted in the EU.
- Resend — transactional email (account, deletion confirmations, beta notices): receives your email address and the message content.
- Ghost(Pro) — newsletter delivery for the waitlist and product updates, only where you opted in.
- Open-Meteo — historical weather lookup, only if you enable weather display. The request is made by our servers, not your browser, so Open-Meteo does not receive your IP address or any identifier for you. It receives only the activity date and a coordinate rounded to two decimal places (roughly one kilometre) — never your precise route. The response is cached at our edge for up to a year; historical weather is immutable and the cached record contains no data about you.
App distribution:
- Apple and Google — distribution of the mobile app and the related device and diagnostic information they process as independent controllers under their own policies. This applies today, even though payments are disabled.
- RevenueCat — subscription entitlement management. Not in use during the closed beta; it will process data only if and when paid subscriptions are enabled.
Recipients you authorise:
- Your coach — only after you accept a coach's invitation and give consent; see Section 12.
Payments. Payments are disabled during the closed beta and no payment provider processes your data. If we enable payments, we will name the provider, the data categories it receives, the legal bases, and the transfer safeguards in this policy before the integration goes live.
Other disclosures: professional advisers under confidentiality, authorities where legally required, and a successor if the business is transferred (your data would remain subject to this policy).
9. International Transfers
Some of the providers above process data outside the European Economic Area, the United Kingdom, and Switzerland, including in the United States. Where they do, we rely on recognised safeguards: the EU-US Data Privacy Framework (including its UK Extension and the Swiss-US framework) where the provider is certified, and otherwise the applicable standard contractual clauses with the required UK and Swiss adaptations. You can ask us about the safeguard applying to a specific provider at legal@gradescale.fit.
10. How Long We Keep Your Data
- Training and derived data: for as long as your account exists. Deleted through the flows in Section 11.
- Provider connections and their tokens: for as long as the connection exists. A Strava connection is held per sign-in session and ends when you sign out on that device, use "Log out everywhere", or the session is purged. Connections to other providers — recovery services, head units and watches — belong to your account rather than to a browser session and survive signing out; they end when you disconnect the provider, revoke access at the provider, withdraw health-data consent, or delete your account.
- Sign-in sessions: deleted after 30 days without activity, or immediately on sign-out or "Log out everywhere".
- Product analytics events: deleted within 90 days, and sooner if you withdraw analytics consent (Section 7).
- Consent, withdrawal, and deletion records: 10 years from the date of the record, as evidence of compliance and for the limitation period for legal claims. These contain no training or health measurements.
- Accounts left undecided on health consent: suspended immediately, and disposed of after 90 days without a decision via the ordinary 30-day cancellable deletion.
- Coach access audit log: 12 months. Administrative audit log: 12 months.
- Coach notes and comments about you: for as long as the coaching relationship exists; deleted with your account.
- Feedback you send us, and any screenshots attached to it: kept until you delete your account. There is no automatic expiry on these — they are removed when your data is erased (Section 11) or when you disconnect your provider, along with everything else. The issue we file in our tracker is kept for the life of that tracker; ask us and we will delete or redact it.
- Links to view a feedback screenshot: the links placed in our issue tracker are signed and stop working after 90 days. This is the link, not the image: the image itself is kept as described above. Anyone holding a working link can view that one image, so we only put them in the private tracker.
- Support correspondence: 24 months from the close of your request.
- Transactional email delivery logs: 30 days.
- Newsletter records: until you unsubscribe or your entry is deleted. A minimal suppression record (your email address and the fact you unsubscribed) is kept indefinitely so we cannot accidentally re-subscribe you; it is separate from newsletter engagement history, which is deleted.
- Waitlist entries: 12 months from signup.
- Security and abuse records: rate-limit windows 24 hours; sign-in state records 30 minutes.
- Error reports: deleted automatically after at most 90 days.
- Records we are legally required to keep (for example accounting records once payments exist): the period the applicable law requires — currently 10 years under Swiss law.
Residual copies in operational backups expire within 30 days and are never restored into active processing.
11. Deleting Your Data and Disconnecting
Three self-service routes, each confirmed in writing by email where we have your address:
- Disconnect a training provider (in Gradescale, or by revoking access at the provider): imports stop immediately and the stored connection is removed. Where the provider notifies us that you revoked access, we also delete the personal data we imported from it and confirm the deletion by email; you can request that deletion directly at any time.
- Delete your account (Settings > Delete My Account): your sessions are ended immediately and a 30-day grace period starts, during which you can cancel from Settings. We confirm the request by email, and again when deletion completes. After the grace period, your personal data is deleted from active systems within 7 days; only records we must keep as legal evidence (such as consent and deletion records) remain.
- Withdraw your health-data consent (Settings > Health data consent): takes effect immediately — processing stops, connected-provider access is revoked, coach access ends, and deletion of your health and training data begins at once, with no grace period. It cannot be cancelled. Your health and training data are deleted from active systems within 7 days. Residual copies in operational backups expire within 30 days and are never restored into active processing. Where a processor holds affected health data, we instruct it to delete that data as part of the same process. See the Health Data Processing Consent for details.
12. Coaches
If you accept a coach's invitation, you give separate, explicit consent under Article 9(2)(a) GDPR for that named coach to receive health-related training data about you. The invitation names the coach and lists what they will be able to see before you decide:
- Heart-rate data
- Sleep, stress, and soreness check-ins
- Readiness scores
- GPS routes
- Power data
- Physiological models and performance estimates
- Notes and comments from other coaches on your account
- Planned and completed workouts
Your coach can also add comments and notes and plan workouts for you. You can revoke this consent at any time in Settings > Coach, which ends the coach's access immediately. Revoking coach consent does not delete your account or withdraw your general health-data consent. We keep an internal log of coach access to your data (what was viewed, when, from where) for 12 months, for accountability; it is not shared externally.
13. Your Rights
To exercise any right, email legal@gradescale.fit. We answer within one month and may ask you to verify your identity in a proportionate way. Most requests can also be handled directly in the app (export in Settings > Export My Data, deletion per Section 11).
- EEA: you have the rights in the GDPR — access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, withdrawal of consent, and complaint to your supervisory authority.
- United Kingdom: the equivalent rights under the UK GDPR and Data Protection Act 2018, with complaints to the ICO.
- Switzerland: the rights provided by the Federal Act on Data Protection, with complaints to the FDPIC.
Gradescale is not offered in the United States during the closed beta, so US state privacy laws are not addressed here. If we open the service to US users we will publish the additional notices those laws require before doing so.
Data portability covers the data you provided; our export additionally includes the analysis we computed for you. Data imported from a connected provider is also available from that provider directly.
14. Security
- All traffic between your devices and Gradescale is encrypted in transit.
- Sessions are integrity-protected with signed tokens; provider credentials are stored encrypted, with keys held separately from the data.
- Error reports are data-minimised and pseudonymised before transmission: identifying fields are stripped or hashed, and location data is removed. Server logs pass through automatic redaction of credentials and secrets.
- Access to systems and data is restricted to what each component needs, and we monitor our dependencies for known vulnerabilities.
No system is perfectly secure. If you find a vulnerability, please report it to legal@gradescale.fit (see also our security.txt).
15. Automated Analysis
Gradescale evaluates your training data to produce scores, models, and suggestions — this is profiling in the legal sense, limited to your athletic training. It is informational: no Gradescale output produces legal or similarly significant effects about you, and every training decision remains yours (or your coach's). Scores respond mainly to your recent and longer-term training load, the intensity and duration of your activities, and the check-ins you submit. Missing or incomplete data may reduce the completeness or reliability of a score or recommendation.
16. Age Requirement
Gradescale is for adults. You must be 18 or older, and account creation requires an explicit confirmation of this. If you believe someone under 18 has an account, contact legal@gradescale.fit and we will delete the data.
17. Changes to This Policy
The version number above always identifies the current text. We record which version of this policy was provided to and acknowledged by you and, separately, the exact text of each consent you gave. How we handle changes depends on what changes:
- Editorial clarifications: we publish the new version.
- New or changed processing described in this notice: we inform you in the app or by email before it takes effect.
- New optional processing based on consent (and any new special-category processing): we ask for that consent separately — continued use alone is never treated as consent.
Previous versions are available on request.
18. Contact
Thomas Mortelmans — Switzerland — legal@gradescale.fit (postal contact available on request).
We aim to acknowledge enquiries within 5 business days and resolve them within one month. If you are unsatisfied, you can complain to your data protection authority (Section 13).