01 Who we are

Jordi Espanyol ("I", "me", or "Developer"), operating as an independent developer, is the controller of the personal data collected through the Project Summit iOS application ("the App").

The App is an adaptive cycling training platform for iOS.

Contact email: privacy@projectsummit.app

02 Data we collect

The App collects data in the following categories:

CategoryExamplesSource
Account & identityName, email addressProvided by you
Training & performanceFTP, power zones, TSS, CTL/ATL, training load metricsCalculated by the App
Activity dataRides, GPS routes, power output, heart rate, cadence, speedStrava, Hammerhead Karoo, Apple HealthKit
Health & recoveryHRV (RMSSD), resting heart rate, sleep duration and qualityApple HealthKit
Device & usageiOS version, app version, anonymised crash logsDevice automatically
Health data — HRV, heart rate, and sleep data are classified as sensitive health data. They are used exclusively for training adaptation calculations and are never shared with advertisers or sold to third parties.

03 How we use your data

Data is used solely to provide and improve the App's core functionality:

  • Generate and adapt personalised cycling training plans
  • Calculate training load, fatigue, and recovery readiness
  • Estimate eFTP and power curve via the CP2 model
  • Push structured workouts to connected platforms via intervals.icu
  • Detect skipped sessions and cascade plan adjustments
  • Diagnose and fix application errors

We do not use your data for advertising, profiling for commercial purposes, or sale to third parties.

04 Third-party integrations

Project Summit connects to the following external services. Each operates under its own privacy policy.

ServicePurposeData shared
StravaImport completed activitiesRead-only activity access via OAuth 2.0
Hammerhead KarooImport completed activities & push structured workoutsDirect, two-way device connection
intervals.icuWorkout distribution to Garmin, Zwift, MyWhooshStructured workout data
Apple HealthKitRead sleep, HRV, and activity dataNo data written back; read-only queries
SupabaseBackend database & serverless functionsTraining plan data stored securely in EU region

You may disconnect any integration at any time from the App's settings or directly from the third-party platform.

05 Data storage & security

Your data is stored on Supabase infrastructure hosted in the EU (West Europe) region. Data in transit is encrypted using TLS 1.2+. Data at rest is encrypted at the storage layer by Supabase.

Access to backend services is protected by row-level security policies. Only your authenticated user account can read or modify your personal training data.

HealthKit data is queried locally on-device and transmitted to the backend only as a unique aggregated recovery metric. Raw biometric samples are never uploaded.

06 Data retention

Your data is retained for as long as your account is active. If you request account deletion:

  • Your personal data will be permanently deleted within 30 days
  • Anonymised, aggregated training statistics that cannot be re-linked to you may be retained for product improvement
  • Backup copies are purged within 90 days of account deletion

07 Your rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the data held about you
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format
  • Restriction — limit how your data is processed
  • Objection — object to certain types of processing
  • Withdraw consent — stop receiving our emails at any time

To stop receiving our emails, use the unsubscribe link in any email we send you (or your mail app's own "Unsubscribe" button). It takes effect immediately and does not delete your account or your training data.

To exercise any of these rights, contact us at privacy@projectsummit.app. Requests will be responded to within 30 days.

If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection authority (DPA).

08 Children's privacy

Project Summit is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided personal data to the App, please contact us and we will delete it promptly.

09 Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification at least 7 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the App after the effective date constitutes acceptance of the updated policy.

10 Cookies & website analytics

This section covers projectsummit.app itself, separately from the data the App collects (sections 1–9 above).

We use PostHog, an EU-hosted analytics provider, to understand how visitors use the site. Traffic is proxied through our own domain (projectsummit.app/ingest) rather than sent to PostHog directly. Analytics cookies are opt-in: nothing is loaded or set until you choose "Accept" in the cookie banner shown on your first visit.

StoragePurposeSet when
summit_consent (localStorage)Remembers your cookie choiceAs soon as you accept or reject
summit_site_v1 (localStorage)Remembers your theme and language preferenceAlways — essential, no consent required
PostHog cookies & identifiersPage views, clicks, and heatmaps to improve the siteOnly if you accept analytics cookies

You can change your choice at any time using the "Cookie settings" link in the footer.

11 Contact

For privacy-related questions, requests, or complaints:

Jordi Espanyol
Project Summit — Privacy Enquiries
Email: privacy@projectsummit.app