Training Vibes
Privacy Policy
Effective and last updated: August 30, 2026
This Privacy Policy explains how Tana Jackson, operating under the Training Vibes name ("Training Vibes," "we," "us," or "our"), handles information when you use Training Vibes applications or the trainingvibes.app website (collectively, the "Services"). Some sections apply only when you use the corresponding app or connected feature.
1. Information you provide or import
The apps process information you enter or choose to import, which may include profile settings, training plans, workout and exercise records, equipment, notes, preferences, and archive files. We use this information to provide planning, workout history, progress, recovery, synchronization, backup, and related app features.
If you email us, we receive your email address, message, and any information you include so we can respond. If a website signup form is offered and you submit it, we use the submitted contact information for the updates described with that form.
2. Apple Health and HealthKit data
TrainingVibes accesses HealthKit only after you grant permission. The app may request access to the following categories for workout import and detail capture:
- workouts, including activity type, dates, duration, and associated metadata;
- heart rate and active energy burned;
- running, walking, and cycling speed;
- running and cycling power, and cycling cadence;
- walking/running, cycling, swimming, and wheelchair distance; and
- workout routes and their location coordinates.
HealthKit data is used only to import, display, analyze, and preserve your training history and details for your benefit. Training Vibes does not use HealthKit data for advertising, marketing, or data mining, and does not sell it or use it to train artificial-intelligence or machine-learning models.
3. Oura data
TrainingVibes connects to Oura only when you choose to authorize the connection. It requests Oura's daily permission and retrieves daily readiness, daily sleep, and sleep-period records. The app uses these records to show recovery context alongside your training.
The normalized Oura recovery history retained by TrainingVibes may include:
- dates, Oura document identifiers, observation dates, import dates, update dates, completeness information, and record provenance;
- readiness score and contributor scores for activity balance, body temperature, HRV balance, previous-day activity, previous night, recovery index, resting heart rate, and sleep balance;
- body-temperature deviation and temperature-trend deviation;
- sleep score and contributor scores for deep sleep, efficiency, latency, REM sleep, restfulness, timing, and total sleep; and
- average HRV, average and lowest heart rate, average breathing rate, awake time, deep/light/REM/total sleep duration, time in bed, sleep latency, sleep efficiency, bedtime start and end, and the selected main sleep period.
TrainingVibes normalizes Oura responses on your device. It does not retain the complete raw Oura API response or detailed time-series samples. It does not sell Oura data, use it for advertising or marketing, share it with data brokers, or use it to train artificial-intelligence or machine-learning models.
4. Credentials, connection data, and security requests
Oura access and refresh tokens are stored in the device Keychain as non-synchronizing, device-local credentials. The app also keeps limited synchronization metadata, such as its provider, environment, and last completed date, so it can resume imports safely.
Release builds use a Cloudflare-hosted token broker to exchange, refresh, and revoke Oura credentials. The broker receives the authorization code or credential needed for the requested operation, an Apple DeviceCheck token, technical request information such as an IP address and user-agent, and rate-limit state. It does not receive Oura health-data responses and does not persist Oura token pairs, authorization codes, or health data. Oura health-data requests go directly from the app to Oura.
5. Storage and synchronization
App data is stored on your device. Where CloudKit synchronization is enabled, Training Vibes also synchronizes training records, workout details, profile and planning information, and normalized recovery records through private CloudKit databases associated with your iCloud account. This lets supported devices restore or synchronize your data. Private CloudKit records are not made public or shared with other Training Vibes users.
Oura credentials are not stored in CloudKit or a synchronizing iCloud Keychain. Cloudflare Web Analytics may process limited website request and device information to provide aggregate traffic measurements. Training Vibes does not combine website analytics with HealthKit or Oura data.
6. How information is used
We process information only as needed to:
- provide the training, workout, recovery, import, and synchronization features you request;
- authenticate connected-service requests and protect the Services from abuse;
- diagnose failures, maintain reliability, and provide support;
- understand aggregate website traffic and improve the website; and
- comply with applicable law and enforce our terms.
7. Service providers and disclosure
We do not sell or rent personal information. Information is processed by:
- Apple, when you use HealthKit, Keychain, iCloud, or CloudKit features;
- Oura, when you authorize and use the Oura connection;
- Cloudflare, which hosts the website and token broker, provides security and rate limiting, and supplies aggregate web analytics; and
- our email provider, when you send us a message or request updates.
When a provider processes personal information on our behalf, we require the provider to limit its processing to the service it provides and to protect the information with the same or equivalent protections described in this policy. We may also disclose information when required by law, to protect rights and safety, or in connection with a business transfer subject to appropriate privacy protections. We do not disclose HealthKit or Oura health data for those providers' advertising or independent marketing purposes.
8. Retention and deletion
Training, profile, planning, workout, and recovery records are retained until you delete them, ask us to delete them, or they are no longer needed to provide the Services. Synced CloudKit records may remain associated with your iCloud account and available to other connected devices after you remove the app from one device. Deleting the app alone therefore may not delete synchronized records.
Oura data is retained only for the recovery-history feature you requested. Selecting Disconnect stops future Oura account access and revokes or clears the device's credentials, but does not by itself delete the normalized recovery history already stored by TrainingVibes. Selecting Delete Recovery Data permanently deletes normalized Oura recovery records from TrainingVibes' local and private CloudKit storage; it does not delete records held by Oura or delete unrelated Training Vibes data. Training Vibes will delete app-controlled Oura data within 72 hours of a verified deletion request.
Support messages and contact information are retained while needed to respond, maintain reasonable support records, or comply with law. Limited security and operational logs may be retained for a reasonable period to prevent abuse and investigate incidents; the broker is designed not to log credentials or health payloads.
9. Your choices and rights
- You can review or change HealthKit permissions in Apple system settings. Revoking permission stops future HealthKit access but does not automatically delete records you already imported into TrainingVibes.
- You can disconnect Oura and separately use Delete Recovery Data in the app.
- You can delete individual app records using available app controls or contact us for access, correction, or deletion help.
- You can opt out of product emails using the instructions in the message or by contacting us.
Depending on where you live, you may have additional privacy rights. We may need to verify your request before acting on it.
10. Security
We use safeguards appropriate to the sensitivity of the information, including system permission prompts, device Keychain storage, private CloudKit databases, encrypted network connections, application authentication, rate limits, and credential redaction. No storage or transmission method is completely secure, so absolute security cannot be guaranteed.
11. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact us if you believe a child has provided personal information so we can review and delete it as appropriate.
12. Changes to this policy
We may update this policy as the Services or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when required.
13. Contact
To ask a privacy question or request access, correction, or deletion, email [email protected]. Please do not include health details or credentials in an unencrypted email.