Stradori
PrivacyBack home

Privacy policy

Last updated: 2026-07-18

This policy explains what personal data Stradori processes, on what legal basis, where it goes, how long it is kept, and the rights you hold over it.

Who is responsible

The data controller is Pedro Teixeira, an individual based in Spain, operating Stradori in a personal capacity; no company has been incorporated at this time. For any matter concerning this policy or your data, contact [email protected]. Requests receive a reply within 30 days at the latest.

What we process, and why

Account data — email address, password (stored only as a hash), display name, timezone. Processed to operate your account: authentication, security notifications, and correct display of dates and times. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

Training and health data — your activity uploads and the metrics they contain (such as heart rate and power), the profile details you choose to share, your goals, the season training plans the coach builds from them, and the content of your conversations with the coach. This data concerns your health and is special-category data under Art. 9 GDPR. It is processed solely to analyze your training, and only with your explicit consent — the checkbox at signup. You may withdraw consent at any time (see “Your rights”); because the service cannot function without this data, withdrawal entails deletion of your account.

Service usage — a record of how much you use the coach: the number of tokens sent and received per interaction, an indicative cost, the type of analysis run, and the timestamp. This data is used to enforce the usage allowance included in your plan and to show you your own usage in the app. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in billing reconciliation, abuse investigation, and capacity planning (Art. 6(1)(f) GDPR).

Security data — IP addresses in rate-limiting counters and server logs. Legal basis: our legitimate interest in protecting the service against abuse and unauthorized access (Art. 6(1)(f) GDPR).

Newsletter — if you subscribe to our newsletter (for example through the form on our website), your email address. It is used only to send you news and updates about Stradori. Legal basis: your consent (Art. 6(1)(a) GDPR). Signup is double opt-in — your address joins the list only after you confirm it through a link we email you — and every newsletter carries an unsubscribe link, which withdraws your consent and removes you from the list. You do not need an account to subscribe, and subscribing does not create one.

Providing personal data is neither a statutory nor a contractual obligation; however, an account cannot be created without account data, and the analysis cannot run without training data.

Stradori does not serve advertising and does not sell personal data.

Automated analysis

The coach is an AI system; conversations with it are not with a human. Stradori performs profiling in the sense of Art. 4(4) GDPR: it automatically computes fitness metrics (training load, form, goal feasibility) and generates plans and debriefs from your data. No decision producing legal or similarly significant effects is taken solely by automated means (Art. 22 GDPR): all output is advisory, the reasoning behind it is visible, and every recommendation can be overridden. The coach does not provide medical advice, diagnosis, or treatment.

Recipients and transfers

Stradori’s application, database, and worker run on servers in the EU. The following processors are engaged under data processing agreements:

  • Hetzner (EU, Germany) — provides the cloud servers that host the Stradori application, database, and background worker, with your data stored at rest in Hetzner’s data centres in Germany.
  • OpenAI (US) — performs the AI analysis. Receives profile and training context at the time of each analysis. Under our agreement, OpenAI does not use this data for training and retains it only briefly for abuse monitoring.
  • Resend (US) — delivers transactional email (verification, password resets). Receives your email address.
  • Pydantic Logfire (EU) — error and performance monitoring, hosted in Logfire’s EU region. To monitor and improve the quality and reliability of the coach, these traces include the content of coach conversations and the training context behind each analysis, identified by account ID only. Our marketing website and app also send Logfire basic browser telemetry (the addresses of pages viewed, how quickly pages and features load, and error details) so we can detect and fix problems; on the marketing website this includes visitors without an account. It stores nothing on your device and relies on our legitimate interest in keeping the service reliable.
  • Cloudflare (US) — operates the network in front of our site (security and content delivery) and provides cookieless, aggregate web analytics. As it routes traffic to us, it processes that traffic in transit, including IP addresses.
  • Klaviyo (US) — runs our newsletter signup form and holds the subscriber list.

Transfers to the United States are safeguarded by the EU–US Data Privacy Framework or by standard contractual clauses concluded with each provider; a copy of the applicable safeguards is available on request.

If you link Telegram, messages exchanged with the coach pass through Telegram’s platform under Telegram’s own terms. The Telegram channel is optional; the web application provides the full service without it.

Retention

  • Profile, activities, chat, goals, and training plans — retained while the account exists; deleted with the account.
  • Service usage records — retained while the account exists; deleted with the account.
  • Email verification and linking tokens — single-use and short-lived; removed by a daily cleanup once used or expired.
  • Internal delivery records (which email was sent, and to whom) — deleted after 30 days.
  • Newsletter subscription — your email stays on the list until you unsubscribe.
  • Accounts that never verify their email — deleted 30 days after creation.
  • Backups — automated daily database backups, encrypted and kept in secure European storage for a short, bounded disaster-recovery period (currently 30 days), then automatically deleted; deleted account data ages out of backups over that period.

Your rights

Under the GDPR you have the right to access, rectify, export (data portability), and erase your data; to restrict processing while a dispute about it is resolved; to object to processing based on legitimate interest (the security and analytics processing described above); and to withdraw consent at any time, as easily as it was given. Profile data can be edited directly in the application. For any other request — export, erasure, restriction, objection — write to [email protected]; requests are fulfilled within 30 days. You also have the right to lodge a complaint with a supervisory authority; in Spain, that is the AEPD (aepd.es).

Marketing

Product updates are sent only with separate opt-in consent, and every such email contains an unsubscribe link. Creating an account does not subscribe you to marketing.

Cookies

Stradori sets one cookie: the session cookie that keeps you signed in. It is strictly necessary, so no consent banner is required. Web analytics (Cloudflare Web Analytics) is cookieless and aggregate. Legal basis for the analytics: our legitimate interest in measuring site traffic.

Age

Stradori is intended for athletes aged 16 and over.

Changes

Material changes to this policy are announced by email before they take effect, and the date above is updated accordingly.