Privacy policy
What is collected, where it sleeps, who touches it, for how long, and how you make it go away. No filler: there is health data in here, and it deserves exact sentences.
Last updated
01 The principle, before the detail
This site could once say that nothing was stored on our side. That is no longer true, and repeating it would be a lie: the moment there is an account, there is an athlete file, and that file lives on a server.
What is still true: the calculators compute in your browser. Your GPX track, your watts, your weigh-ins are not shipped somewhere to be crunched by a distant machine. What is sent is your profile — weight, thresholds, zones — because that is what has to follow you from one device to the next and from one tool to another.
And there is nothing to sell in any of it. No advertising, no resale, no data broker, no tracking pixel. The business model is the subscription; it never needed to be your medical file.
02 Who is responsible, and who you write to
The data controller is the publisher of the site, identified in the legal notice. There is no data protection officer: the operation is too small to be required to appoint one, so your contact is the publisher directly.
Any question, any request for access, correction or deletion: [email protected].
03 What is collected, and why
Nothing is collected "just in case". Every category below exists because a specific function depends on it.
- The account — email address, a hash of your password (never the password itself), subscription tier, creation date. Without it, no sign-in.
- Sessions — a hash of the sign-in token, expiry date, last-used date. The token itself is not stored: a copy of the database lets nobody hijack a session.
- The athlete file and sessions — weight, height, thresholds (FTP, critical power, W′, vVO2max, paces), zones, weekly availability, goals, plus your planned and completed sessions. Some of this is health data under article 9 of the GDPR: weight, heart rate, sweat rate, heart rate variability, declared injuries and constraints. It is the raw material of coaching; it is processed on the basis of your explicit consent, given at sign-up.
- Connection tokens for intervals.icu (and later Garmin or Strava) — only if you link your account. They are encrypted with AES-256-GCM before being written to the database, and never stored in the clear.
- The coach usage counter — action type, number of tokens consumed, model name, date. It drives quotas and cost. The content of your conversations with the coach is not kept in that counter.
- The newsletter, if you sign up — email address, date, the page the sign-up came from, status, unsubscribe token. Nothing else.
- Password reset tokens — as hashes, single-use and short-lived, deleted the moment they are used.
△ What stays in YOUR browser and is sent nowhere on its own: your session token, a cached copy of your profile so the first screen can paint without waiting on the network, and a reading-time counter. Clearing your browser's site data wipes them.
04 Where this data lives
The core is at home, in the literal sense.
- Accounts, the athlete file, sessions and the encrypted tokens live in a PostgreSQL database on a private server owned by the publisher, physically in France. That server opens no inbound port: it dials out to a Cloudflare tunnel, which exposes it at api.cornermanprotocol.com.
- The site you are reading is a set of static files served by Cloudflare Pages. No personal data is stored there.
- The newsletter list lives in a Cloudflare D1 database on our own account — not at the sending provider, which is only a courier.
- Database backups are encrypted (AES-256-GCM) before leaving the server, then stored on Cloudflare R2, in a bucket located in Western Europe. They are unreadable without the key, and the key never leaves the server.
05 Who else touches it
The list is short, and it is complete. Each of these providers is a processor under the GDPR: it handles this data on our behalf, for the stated purpose, and for nothing else.
- Cloudflare, Inc. (United States) — site hosting, network and tunnel access to the API, the newsletter subscriber database, and storage of the encrypted backups (bucket in Western Europe).
- Resend, Inc. (United States) — email delivery: welcome messages, password resets, newsletter. Sees your address and the content of the message sent.
- Stripe Payments Europe, Ltd. (Dublin, Ireland) — subscription payments. Stripe holds the card data; it never passes through our servers. We keep only a Stripe customer identifier.
- The language model inference provider — OpenRouter, Inc. and Groq, Inc. (United States), depending on the configuration in force. They run the models
openai/gpt-oss-120bandmeta-llama/llama-3.3-70b. See the next section: this is the only point where your data leaves the European Union. - intervals.icu — only if you link your account. There, you are the one opening the door, and you can close it again at any time from your profile.
△ None of these providers may use your data for their own purposes. No data is sold, rented or traded, to anyone, ever.
06 The transfer outside Europe, and your consent
The coach writes with the help of a language model, and that model does not run on our machine. It runs at a US inference provider, on servers located outside the European Union. It is the only transfer outside the EU in this service, and it deserves to be named rather than buried.
What goes out: the context needed for the answer — numbers already computed by the engine (thresholds, load, form of the day), the state of your week, your declared constraints, and your question. What does not go out: your email address, your password, your payment details, your connection tokens for third-party services.
This transfer rests on your explicit consent, collected at sign-up, separately from everything else. You can withdraw it at any time: withdrawing it turns off the coach features that go through the model; the calculators, your file and your exports keep working, because they never leave Europe.
There is no automated decision-making producing legal effects for you. A training plan is a proposal: you follow it, you change it, or you ignore it.
07 How long it is kept
A retention period you cannot state does not exist. Here are ours.
- Account, athlete file and sessions — as long as the account exists. Cancelling a subscription does not erase them: the account drops to the free tier and your history is waiting if you come back. Deletion is on request (see below).
- Sessions — thirty rolling days, then purged automatically. Signing out deletes the session immediately.
- Password reset tokens — a few hours at most, and deleted on first use.
- Third-party connection tokens — until you unlink the service, or delete your account.
- Coach usage counter — quotas are computed over a rolling thirty-day window; the counting rows are kept for at most three years for accounting, with no content.
- Newsletter — until you unsubscribe. The row is then not deleted: it is marked "unsubscribed". That is deliberate, and it protects you — without that trace, re-importing an old list would sign you back up against your will.
- Invoices and accounting records — ten years, as the law requires of any trader. Those cannot be deleted on request.
- Encrypted backups — seven daily, four weekly, six monthly. Which means a deletion takes up to six months to disappear from backups, the time it takes for the last monthly copy that contained you to rotate out. That is the price of a restore history, and it is said plainly.
08 Your rights, and how you use them
You can request access to your data, its correction, its deletion, its portability, the restriction of or objection to its processing, and you can withdraw any consent you gave, at any time.
Portability does not need asking: the JSON export of your full file is a button in your account, and your sessions export as .zwo, .fit and .mrc. If you leave, you leave with everything.
Deletion, on the other hand, goes by email to [email protected]. Plainly: there is not yet a "delete my account" button in the interface, it is handled by hand. Less convenient, no less effective — the account and everything attached to it is removed from the database within thirty days, and disappears from backups within the window stated above.
Every request gets an answer within one month. If that answer does not satisfy you, you can complain to the CNIL, the French supervisory authority, or to the authority of the country you live in. It is free.
09 What is done so it does not leak
Health data on a self-hosted server needs more than good intentions. What is in place:
- Passwords are stored as irreversible hashes, never in the clear.
- Session tokens are stored as hashes too: stealing the database yields no open session.
- Third-party connection tokens are encrypted with AES-256-GCM, using a key the server demands at boot — without it, it refuses to start rather than run half-configured.
- Backups are encrypted before they leave the machine.
- The server exposes no inbound port: it is reachable only through an outbound tunnel, over HTTPS.
- Sign-in attempts and coach calls are rate-limited, to cut short credential stuffing and automated use.
10 And if it leaks anyway
No system is impregnable, and claiming otherwise would be the first lie. If a data breach happens: it is reported to the CNIL within 72 hours of us becoming aware of it, and you are told directly, by email, if it is likely to put you at high risk.
The message will say what went out, when, what we did about it, and what you should do on your side. Not a press release: facts.
12 If this policy changes
It will: payments are about to open, more connectors are coming. Any substantial change — a new category of data, a new processor, a new purpose — is announced by email to account holders before it takes effect, and the revision date at the top of this page is updated.
Successive versions are visible in the public history of the site's repository. We do not rewrite the past quietly.