VeloMind
EnglishSlovenščina

Privacy Policy

Effective October 9, 2026

VeloMind is a cycling coach: it plans your training, reads your recovery and suggests what to eat around your rides. To do that it has to process personal data, some of it about your health. This policy explains what we collect, why, who else sees it, how long we keep it and what you can do about it. It applies to the website at velomind.si and the VeloMind apps.

1. Who is responsible

The controller of your personal data is the VeloMind operator. For anything about your data or this policy, write to [email protected].

2. What we collect

Your account

  • Your name, email address and password (stored only as a secure hash), or your Google account's ID, name and email if you sign in with Google.
  • When you accepted these terms, whether you confirmed your email address, and your notification settings.
  • Your plan: your trial's end, and for Pro, the subscription's status, billing interval and renewal date from Paddle.

Your training profile

  • Birth year, weight, FTP, riding experience, weekly hours and riding days, whether you have an indoor trainer, your goals and events.
  • Food preferences: diet, what you avoid (including allergies), dislikes and likes.

Health and fitness data

This is a special category of personal data under the GDPR (Article 9), and we only process it with your explicit consent:

  • Daily recovery signals: sleep, heart-rate variability (HRV), resting heart rate, how you feel, and notes you add.
  • Your rides: date, duration, distance, power, heart rate, training load, peak efforts and time in zones, from files you upload or from intervals.icu if you connect it. We don't store GPS tracks or where you rode.
  • Your plans, recommendations, meal plans, weekly reviews, how rides and plans felt to you, and your conversations with the coach.

Technical data

  • Sign-in sessions (device type and app version for the mobile app), push notification tokens if you allow notifications.
  • A log of the emails and notifications we sent you, and a record of AI use (which feature ran, token counts and cost) so we can keep costs and abuse in check.
  • Your IP address, used briefly to limit repeated sign-in attempts and kept in our logs for security.

3. Why we use it, and on what legal basis

  • To provide VeloMind (your account, plans, recovery calls, meals, reports): necessary to perform our contract with you (Article 6(1)(b) GDPR).
  • To process your health and fitness data: your explicit consent (Article 9(2)(a)), given when you create your account. You can withdraw it at any time by deleting your data or account (see section 8); VeloMind can't coach you without it.
  • Morning and weekly emails and push notifications: your consent, which you can turn off in your profile or with the link in every email.
  • Security, abuse prevention and cost limits (rate limits, AI budgets, logs, backups): our legitimate interest in running a safe and affordable service (Article 6(1)(f)).
  • Service emails (confirming your address, resetting your password): necessary for the contract.

We don't sell your data, show you ads or use your data to train AI models.

4. How AI is used

VeloMind's coach, planners and reports use AI models from OpenAI. When they run, the relevant part of your training profile and data (for example this week's rides and recovery signals) is sent to OpenAI to produce an answer. Your name and email address are not sent. We ask OpenAI not to store these requests, and under its API terms OpenAI doesn't use them to train its models. Health questions may also be screened automatically so the coach can point you to a doctor when it should. AI suggestions are made automatically, but nothing about your account is decided by AI alone in a way that has legal or similarly significant effects.

5. Who else processes your data

  • OpenAI (USA): AI models, as described above.
  • Our email provider: to deliver emails you asked for.
  • Google: sign-in with Google if you use it, and Firebase Cloud Messaging to deliver push notifications to the app.
  • intervals.icu, only if you connect it: we read your rides and wellness data from it, and can send planned workouts to it.
  • Strava, only if you connect it: we write a VeloMind ride report into the description of your Strava activities. We don't store data from Strava or use it for AI; Strava processes what we write under its own privacy policy.
  • Paddle (Paddle.com Market Ltd, UK), only if you buy Pro: as our reseller it processes your payment, address for VAT and invoices as an independent controller, under its privacy policy. We receive your subscription's status and Paddle's customer and subscription IDs, never your card details.
  • Cloudflare: our network and DNS provider, which passes your traffic to our servers.
  • Hosting: our servers and their backups are in the European Union.

Some of these providers are outside the European Economic Area. Where that is the case, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. We may also disclose data where the law requires it.

6. How long we keep it

  • Your account and training data: until you delete them or your account.
  • Database backups: 14 days, after which deleted data is gone from them too.
  • Sign-in sessions: 30 days on the web and 90 days in the app after last use. Email confirmation links: 48 hours. Password reset links: 60 minutes.
  • Rate-limit counters: minutes to a day. Server logs: a few weeks.

7. Cookies and storage

We only use what the site needs to work, so there's no cookie banner: a sign-in cookie (vm_session), short-lived cookies that protect sign-in with Google and connecting Strava against forgery (vm_google, vm_strava), and your colour theme saved in your browser's local storage. No analytics or advertising cookies.

8. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • have it corrected, most of which you can do in your profile;
  • have it deleted, and withdraw your consent;
  • restrict or object to how we process it;
  • receive the data you gave us in a portable format.

You can do the main ones yourself, any time: in Profile → Your data you can download everything we store about you as a JSON file, or delete your account and all its data (a Pro subscription is cancelled first). For anything else, write to [email protected] from your account's email address; we'll answer within a month. If you think we're handling your data unlawfully, you can complain to the Slovenian data protection authority, the Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si), or the authority where you live.

9. Security

Connections are encrypted with HTTPS, passwords are hashed, tokens for connected services are encrypted at rest, and access to the servers is restricted. No system is perfectly secure; if a breach puts you at risk, we'll tell you and the authority as the law requires.

10. Age

VeloMind is for people aged 16 and over. We don't knowingly collect data from younger children.

11. Changes

When this policy changes we'll update the date above, and for significant changes tell you by email or in the app before they apply. See also our Terms of Service.

PricingPrivacy PolicyTerms of ServiceRefund policy
VeloMind home