Who We Are

Pheidi is an independent training-plan service operated by John Farrell, publisher of the Pheidi app on Google Play and the App Store and of the websites pheidi.training and app.pheidi.training. The developer is the data controller for the personal data described here. This policy covers the Pheidi web app, the Pheidi Android app, the Pheidi iOS app, and the marketing site. Contact details are in Section 14.

1. Information We Collect

When you use Pheidi, we collect the following information to provide and improve our service:

  • Account information: Email address and display name when you create an account, plus the authentication tokens issued to your signed-in devices.
  • Training data: Race times, running experience, schedule preferences, injury notes, time zone, and goal race information you provide during onboarding and plan creation, along with the plans and completed workouts generated from them.
  • Usage data: How you interact with the app, including pages visited, features used, and workout completions.
  • Device information: Browser type, operating system, app version, and screen size, for compatibility and performance purposes.
  • Diagnostics and app analytics (mobile apps): The mobile apps send crash reports, error diagnostics, and app-interaction events to our error-monitoring provider. These carry a random per-install identifier, never your name, email, or account. See Section 10, including how to switch this off.
  • Push notification identifiers (mobile apps): If you enable push notifications, we store the notification handle your device's operating system issues (FCM on Android, APNs on iOS) so we can deliver training reminders.
  • Connected accounts (Strava): If you connect Strava activity sync, we store an encrypted access grant and import your running activities (distance, moving time, date, and type) to mark your plan's workouts complete. This is optional and separate from signing in with Strava. You can turn it off at any time, which revokes our access and deletes the imported Strava activity data. Raw imported activities are also automatically purged within 7 days on an ongoing basis, and Strava-sourced data is never used in AI features. We never post anything to your Strava account.
  • Uploaded activity files: If you import a .fit file exported from a watch, we read only its summary values (duration, distance, heart rate) to log the workout. Position data inside the file is never read and never stored.
  • Health, fitness, and location data (mobile apps only): If you use the Pheidi Android or iOS app and grant permission, we access workout, distance, and heart-rate data through Google Health Connect or Apple HealthKit, and, for in-app run tracking, your device's GPS location. See Section 3 for details. The web app does not access this data.

2. How We Use Your Information

We use your information to:

  • Generate and personalize your training plan based on your fitness level, schedule, and goals.
  • Adjust your plan when you miss workouts, change your schedule, or update your race goals.
  • Send you training-related notifications and plan updates (if you opt in).
  • Diagnose crashes and errors, and improve the app's training algorithms and user experience.
  • Respond to support requests.

3. Health, Fitness, and Location Data (Mobile Apps)

The Pheidi mobile app can optionally use your device's location services, and is planned to connect to your device's health store in a future release. Anything described here is off by default, requires your explicit permission at the operating-system level, and can be revoked at any time. None of it is available in, or used by, the web app or marketing site.

Health and fitness data

Pheidi does not currently connect to Google Health Connect or Apple HealthKit. The app requests no health permissions, reads nothing from your device's health store, and has never written anything into it.

This is about your device's health store specifically, and not about fitness data generally. Pheidi does hold fitness data you give it directly: the distance, duration, pace and heart rate of workouts you log yourself, upload as a .fit file from a watch, record with in-app run tracking, or import from Strava. Those are covered in Sections 1 and 8. Your heart-rate zones and resting/maximum heart rate, if you enter them, are part of your profile.

Syncing completed workouts with your device's health store is planned. This policy will be updated before that ships, and the feature will be optional, off by default, and gated on your explicit operating-system permission.

The commitment, now and after it ships: health and fitness data would be used only to track and synchronize your training. It would never be sold, never shared with third parties, never used for advertising, and never transferred to anyone other than the hosting providers that store it on our behalf. It would never be used to train, fine-tune, or evaluate any AI or machine-learning model. You would be able to revoke access at any time in your device's Health Connect or Apple Health settings. Our use of Health Connect data will follow the Health Connect Permissions policy, requesting only the permissions the features actually need.

Location data

The mobile app includes in-app run tracking. If you grant the location permission, the app uses your device's GPS location to measure the distance, pace, and duration of a run only while you have actively started a run in the app. The permission is requested the first time you tap Start, never at launch, and the app never requests background-location access.

While a run is in progress, tracking continues if your screen locks or you switch apps. On Android this runs as a foreground service, which shows a persistent notification for as long as the run is recording, so it is always visible when location is in use. Tracking stops the moment you finish or discard the run.

We do not store your route. GPS coordinates exist only in your device's memory during the run, in a local crash-recovery buffer on your device, and in the request that sends the run to our server to compute its totals. They are never written to our database and never written to our logs. What we keep is the resulting summary: start time, duration, moving time, distance, and pace. The consequence is deliberate — Pheidi has no route maps, no route thumbnails, and no GPX export. Location data is never sold, never shared with third parties, and never used for advertising or AI training.

The web app and marketing site do not access GPS or device location.

Google Play Data Safety

These integrations correspond to the following declarations on the Google Play Data Safety form. In every case the data is encrypted in transit, is not shared with third parties, and can be deleted on request (Section 9):

  • Location (precise): collected with permission during an active tracked run; optional; used for app functionality. No route or coordinate data is retained.
  • Personal info (name, email address): collected; required to have an account; used for app functionality and account management.
  • App activity (app interactions): collected; used for app functionality and analytics; can be switched off in Settings.
  • App info and performance (crash logs, diagnostics): collected; used for app functionality and analytics; can be switched off in Settings.
  • Device or other IDs: a random per-install identifier and a push notification handle; used for app functionality and analytics.
  • Health and fitness (fitness info): collected; used for app functionality. This covers workout distance, duration, pace and heart rate that you log, upload, record, or import from Strava — not data from Google Health Connect or Apple Health, which Pheidi does not access at all.
  • Data deletion: you can delete your account and all associated data yourself from Settings inside the app, and our web deletion page covers the case where the app is no longer installed.

None of this data is collected for advertising, and we do not sell or share personal data as those terms are used in US state privacy laws.

4. Information We Do Not Collect

  • We do not collect payment information (Pheidi is free).
  • We do not use advertising cookies, advertising identifiers, or ad networks, and we do not sell, rent, or trade your personal data.
  • Apart from the run-tracking location access described in Section 3, we do not access your device's location. We do not access your device's health store (Google Health Connect or Apple Health) at all, on any surface.
  • We do not access your contacts, photos, microphone, camera, call logs, SMS messages, or the list of apps installed on your device.

5. Artificial Intelligence and Your Data

We never use your data to train AI. Your training data, your Strava activities, and any health data you connect are used only to generate and adjust your own training plan. We do not use them, or any data derived from them, to train, fine-tune, evaluate, or otherwise improve any artificial-intelligence or machine-learning model, and we never sell or provide your data to a third party for that purpose.

Your plan is produced by transparent, rule-based logic grounded in published sports-science research and established coaching methodology, not by an AI model deciding your training. Where Pheidi offers an optional AI assistant that can read your plan at your request, your data is used only to answer you in the moment; it is not retained for model training, and data that originates from a connected service such as Strava is withheld from those AI features. Health, fitness, and location data is likewise never sent to AI features.

6. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share data with:

  • Service providers: Cloud hosting and database (Microsoft Azure), transactional email and SMS delivery (Azure Communication Services, Postmark), error monitoring and diagnostics (Azure Application Insights), and push notification delivery (Google FCM, Apple APNs). These providers only access data necessary to perform their functions.
  • Legal requirements: If required by law, regulation, or legal process.

The service providers above act only as data processors with limited, contractual access to perform these functions on our behalf; they are not independent third parties and may not use your data for their own purposes. We never sell, rent, trade, or share your health, fitness, or location data for advertising, and that data never leaves the hosting and storage providers that hold it for us.

7. Data Storage and Security

Your data is stored securely in Microsoft Azure using industry-standard encryption in transit (TLS) and at rest. Access tokens on mobile devices are held in the operating system's encrypted secure storage, and the Android app disables cloud backup and device-to-device transfer of its local data. We follow security best practices to protect your information.

8. Data Retention

  • Account, profile, training plans, and workout history: retained while your account is active; deleted when you delete your account.
  • Fitness data (workout distance, duration, pace, heart rate, heart-rate zones): retained with your workout history while your account is active; deleted when you delete your account. No data is read from Google Health Connect or Apple Health, so none of that is retained (Section 3).
  • Location: GPS coordinates are never retained. Run summaries are retained like other workout history.
  • Imported Strava activities: automatically purged within 7 days, and immediately when you disconnect Strava.
  • Push notification handles: deleted when you disable notifications, sign out, or delete your account.
  • Crash logs and diagnostics: retained by our error-monitoring provider for up to 90 days, then deleted automatically.

9. Your Rights, and Deleting Your Account

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your account and all associated data.
  • Export your training data.
  • Disconnect Strava activity sync from Settings, which revokes our access and removes imported activity data. You can also revoke access from your Strava account's connected-apps settings.

Account deletion

In the app. Settings has a Delete account section at the bottom. It asks you to confirm twice, and then deletes immediately — there is no waiting period, no confirmation email, and no way to undo it. This is the fastest route and the one to use if you can still sign in.

If you have already uninstalled. Our account deletion page explains the email route: write to support@pheidi.training from the address on the account. Requests are actioned within 30 days.

Either route removes your profile, training plans, workout history, run summaries, imported activity data (and revokes our Strava access), push notification handles, your authentication tokens, and any AI assistant connections you authorized.

One exception: bug reports. Feedback and bug reports you submitted are unlinked from your account rather than deleted, because a bug report describes a fault in Pheidi that may still need fixing. We remove the link to your account, so the report is no longer associated with you and never appears in anyone's account again. We do not edit the text you wrote: if you included your name, email address or anything else identifying in the report itself, that text stays. Tell us and we will delete a specific report outright.

Anonymous aggregated statistics that cannot identify you, and records we are legally required to keep, may also be retained.

To exercise any other right, contact us at the email below.

10. Cookies, Analytics, and Diagnostics

Marketing website

We use Google Analytics 4 (GA4) to understand how visitors use our marketing site. GA4 uses cookies to collect aggregated, pseudonymous usage data such as pages visited, session duration, and referral source.

If you are in the EU, EEA, or Switzerland, we apply Google's Consent Mode v2 with a region-scoped default-deny: no analytics cookies are set until you accept. A first-visit banner asks for your choice. We do not use advertising cookies anywhere.

Changing your choice: Your preference is saved in your browser's local storage under the key pheidi_consent_v1. To revoke or change your consent, clear that key (via your browser's site data tools) and the banner will reappear on your next visit. You can also opt out of GA at any time using your browser's cookie settings or a browser extension like Google Analytics Opt-out.

Mobile apps

The Android and iOS apps do not use Google Analytics and contain no advertising SDK. They send crash reports, error diagnostics, and a small set of app-interaction events to Azure Application Insights so we can find and fix problems. These records carry a random identifier generated on your device at install time, the app version, and the device platform — never your email, name, or account identifier. Event values are filtered before sending, so free text you type, such as an injury note, is never included.

Opting out: open Settings → Privacy in the mobile app and turn analytics off. Nothing further is sent from that device.

11. Third-Party Links

Our articles and site may contain links to external websites and research papers. We are not responsible for the privacy practices of those sites.

12. Children's Privacy

Pheidi is not directed to children under 13, and the app is not designed for or targeted at children. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. If you believe a child has provided us with data, contact us at the address below.

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on our site or sending an email. The "Last updated" date at the top of this page indicates when this policy was last revised.

14. Contact Us

If you have questions about this privacy policy or your data, contact the developer at:

Email: support@pheidi.training

Account deletion requests: pheidi.training/delete-account/