Privacy Policy
Last updated: September 7, 2026 · Effective: September 7, 2026
This policy explains what data Nordik Lab collects, why, how it is used, and what rights you have. Nordik Lab is a training platform for endurance athletes and coaches. We connect to your fitness and health services so we can show your training, recovery, and readiness data in one place. Some of that data is health data — we treat it with care and are transparent about how it is handled.
If you have questions or requests about your data, contact us at contact@nordiklab.com.
1. Who we are
Nordik Lab is the data controller for personal data processed through this platform. For GDPR purposes, the controller is reachable at contact@nordiklab.com. If you are in the EU or UK and want to contact us about a GDPR rights request, use this same address.
2. Data we collect
Account data
When you create an account we collect your name, email address, and role (athlete or coach). You may optionally add a profile picture and other profile details. You can sign up with an email and password, with Google, or with Sign in with Apple. With Sign in with Apple, we receive your name only on your first sign-in, and if you choose Hide My Email we receive an Apple private relay address instead of your real email — that relay address becomes your account email. Authentication is handled by Supabase; we never see or store your Apple or Google password.
Waitlist and launch updates
When you join the Nordik Lab waitlist, we collect your email address and a record of your consent to receive launch and early-access updates. We use this information only to contact you about Nordik Lab's launch or access availability. You can unsubscribe at any time or ask us to delete your waitlist information by contacting us.
Training and activity data
When you connect a device or service, Nordik Lab receives the data scopes you authorize. This includes workout records, GPS tracks, pace, power, cadence, speed, elevation, duration, distance, sport type, and associated metadata from any connected provider.
Health and biometric data
Some data we receive is health or biometric data under GDPR (special category data under Article 9). This includes: heart rate data from any source used as a physiological indicator; HRV (heart rate variability); resting heart rate; respiratory rate; sleep performance, sleep duration, and sleep stage data; recovery scores and readiness metrics (WHOOP, Garmin, Polar Nightly Recharge, Suunto); body battery (Garmin); breathing rate, tidal volume, and minute volume (Tymewear); body weight; data read from Apple Health with your permission in the iOS app; and internal training load scores derived from physiological measurements. We process this data only where you have explicitly connected the relevant provider, entered it directly into your profile, or otherwise provided it, and only for the purposes described in this policy.
Fueling and nutrition guidance data
If you use Nordik Lab's auto-generated fueling guidance for planned workouts, we collect and store the fueling preferences you set — including whether auto-generated fueling guidance is turned on, your caffeine opt-in choice, and any personal carbohydrate ceiling, sweat-rate, or sodium override values you enter — together with your body weight and date of birth from your profile. We use this information, alongside a workout's planned duration and target zones, to compute the carbohydrate, fluid, sodium, and (where you've opted in and are eligible) caffeine targets shown for that session, in the same way we use your HR, HRV, and readiness data to power other in-app training and recovery guidance. These generated targets are stored against the specific planned session they were calculated for.
If you use the Pro Nutrition Planner, we additionally store the nutrition kits (bottle count and volume, mix preference, and per-kit automatic-caffeine permission), custom foods, and recipes you create — including any name, brand, serving size, and nutrient values you enter — together with the itemized fueling schedule (timing, product or recipe used, and amounts) generated for each planned session. Custom foods and recipes are athlete-entered and are not independently verified by Nordik Lab.
Coach–athlete relationship data
If you connect with a coach or athlete inside Nordik Lab, we record that relationship and the permissions associated with it, including your Coach AI Access setting for that coach's connected AI assistant.
Messages and shared files
When you use Messages, we store the message content, sender and recipient, timestamps, read status, and files or workout references you choose to share. Message attachments may include images, PDFs, text files, CSV files, or fitness files. We use this information to deliver coach–athlete communication, show shared training context, prevent abuse, and secure the service.
Nordik Intelligence data
When you use Nordik Intelligence, we store your conversation messages, generated artifacts (workouts, training blocks, charts), remembered athlete preferences, and any context files you upload to the assistant. See Section 7 for how AI processing works.
Usage data
We collect basic usage information such as pages visited and features used to operate and improve the service. We do not use advertising trackers or sell usage data.
Uploaded files
If you upload .fit files (from COROS, Garmin, Suunto, Wahoo, Hammerhead, Tymewear, SkiSens, or any ANT+/BLE-compatible device), Nordik Lab processes the file to extract workout data and stores the parsed records in your athlete record.
3. Legal bases for processing (GDPR)
If you are in the EU or UK, we process your data under the following legal bases:
Performance of contract (Art. 6(1)(b))
Account information, training and activity data, coach–athlete relationships, and usage data necessary to deliver the platform and its core features.
Explicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Health and biometric data is special category data under Article 9. We process it only where you have taken a deliberate action to connect a health data provider (WHOOP, Polar, Garmin, Suunto, Apple Health) or upload health-relevant files. By connecting a provider or uploading such data, you give explicit consent. You can withdraw consent at any time by disconnecting the provider (or revoking Health access in iOS Settings) or requesting data deletion.
Coach AI Access and third-party assistants
Your Coach AI Access setting controls whether a connected coach assistant can access your Nordik training data. New coaching relationships start with this setting enabled, and you can disable it at any time from Settings → Connections. Where applicable law requires a separate consent or additional control for particular data, including health data, Nordik Lab will provide that control before processing that data through the coach assistant.
Legitimate interests (Art. 6(1)(f))
Security monitoring, fraud prevention, and service improvement analytics, where our interests do not override your rights.
4. How we use your data
- Display your training load, recovery, readiness, and performance metrics in your athlete and coach dashboards
- Support coach–athlete planning, session review, workout scheduling, and performance analysis
- Deliver coach–athlete messages and the files or workouts users choose to share in those conversations
- Compute training load scores, fitness trends, stress balance, session execution quality, and sport-specific analytics
- Match and deduplicate workouts from multiple sources into a unified training record
- Generate Nordik Intelligence responses, insights, and artifacts using your training data and preferences as context
- Deliver planned workouts to connected devices (Garmin, Wahoo, Hammerhead) where enabled
- Send launch and early-access updates to people who have joined the Nordik Lab waitlist
- Maintain integration sync state and troubleshoot failures
- Operate, secure, and improve the Nordik Lab platform
5. Sharing and disclosure
Coaches
Athletes control who can see their data. A coach can only view an athlete's training and readiness data after the athlete has accepted a coaching relationship inside Nordik Lab. Athletes can end that relationship at any time, which immediately revokes the coach's access.
Coach AI assistant connections:a coach may optionally connect their coaching account to a third-party AI assistant (Claude or ChatGPT) through Nordik Lab's coach connector. This is separate from, and requires more than, an active coaching relationship — the connector can read a specific athlete's data and, where the relationship permissions and connection scopes allow, add notes, manage workouts, or update plans only when that athlete's Coach AI Access setting is enabled for that coach from their own Settings. New coaching relationships start with this setting enabled; existing connections keep their current setting, including a previous choice to leave it off. Re-activating an old relationship does not silently turn a previous off choice back on. Athletes can turn it off at any time, which takes effect on the coach's very next request. See Section 7 for what data this can expose and to whom.
Messages
Messages and shared files are visible to the participants in that conversation. Nordik Lab does not provide end-to-end encrypted messaging; limited authorized personnel may access message data only when needed to provide support, investigate abuse or security issues, or comply with law.
Service providers
We use a small number of infrastructure providers who process data only as strictly necessary to operate the service. These include our hosting provider (Vercel), PostHog (for limited product analytics), Sentry (for error monitoring in both the web app and the iOS app), and Google (for the Gemini AI models that power Nordik Intelligence). Service providers are contractually bound to protect your data and may not use it for their own purposes.
If you or your coach connects Nordik Lab to Claude or ChatGPT (see Section 7), Anthropic (Claude) or OpenAI (ChatGPT) act as an additional sub-processor for that connection, and only for the data scopes authorized by the connection and subject to the athlete's Coach AI Access setting for coach connections.
Strava
When you use the Strava integration, personal data is disclosed to Strava pursuant to the Strava API Agreement. Strava may monitor and collect usage data related to your use of the Strava API. If you revoke Nordik Lab's access to your Strava account, we will delete your Strava-sourced data from our systems upon request.
No sale of data
Nordik Lab does not sell your personal data, training data, health data, or usage data to advertisers, data brokers, or any third party. This includes data received from Strava, WHOOP, Polar, Garmin, Suunto, Concept2, Wahoo, Hammerhead, Tymewear, and SkiSens.
Legal requirements
We may disclose data if required by law, court order, or to protect the rights, property, or safety of Nordik Lab, our users, or the public.
6. Third-party integrations
Each integration is governed by that provider's own privacy policy. Nordik Lab only receives the scopes you authorize. Below is what we receive from each.
Strava (OAuth)
Workout summaries, GPS tracks, pace, heart rate, power, elevation, activity metadata
WHOOP (OAuth)
Recovery score, HRV, resting heart rate, sleep performance, sleep duration, respiratory rate, day strain, and workout records
Polar (OAuth)
Training sessions, heart rate, speed, cadence, Nightly Recharge sleep and recovery scores
Garmin (OAuth via Garmin Health API)
Activities, GPS, heart rate, HRV, sleep stages, body battery, stress score, and device records
Suunto (OAuth)
Workout records, GPS, heart rate, sleep, and recovery data from Suunto Cloud
Concept2 (OAuth)
SkiErg workout records, power, heart rate, cadence, and speed from the Concept2 Logbook
Wahoo (OAuth)
Planned bike workouts pushed to ELEMNT devices, completed ride records
Hammerhead (OAuth)
Planned workouts pushed to Karoo devices, completed ride records when sync is enabled
Tymewear (.fit file upload)
Breathing rate, tidal volume, minute volume, and internal load streams from Tymewear garments
SkiSens (.fit file upload)
Nordic ski power, cadence, and technique streams
COROS / other devices (.fit file upload)
Workout data from any ANT+ or BLE-compatible device that exports standard .fit files
Weather shown alongside your calendar and workouts is fetched from Open-Meteo using approximate location coordinates only; no account identifiers are sent to the weather service.
Apple Health (HealthKit)
The Nordik Lab iOS app can read data from Apple Health if — and only if — you grant permission in iOS. We read: heart rate variability (HRV), resting heart rate, respiratory rate, workout heart rate streams, sleep analysis, and workout records. This data is used solely to provide the training and recovery features you asked for: readiness tracking, training load, and syncing workouts recorded by other apps and devices. If you use Nordik Intelligence, recovery and readiness summaries derived from this data may be included in AI prompts as described in Section 7.
Our HealthKit commitments:we never use Apple Health data for advertising, marketing, or similar purposes; we never sell it; we never share it with third parties for their own purposes; and we never use it for any purpose other than providing the features described in this policy. You can revoke the app's Health access at any time in iOS Settings → Privacy & Security → Health, which immediately stops all further reads.
7. AI and automated processing
Nordik Intelligence is powered by Google Gemini (currently the Gemini 2.5 and 3.5 Flash model families, depending on the feature). When you send a message or request an artifact, Nordik Lab constructs a prompt that may include: your question, recent training summaries, your saved preferences, and uploaded context files. This prompt is sent to Google's Gemini API for processing.
Strava data and AI:Per Strava's API Agreement, activity data obtained via the Strava API is not used to train or fine-tune AI models. Nordik Lab does not train AI models on your Strava data.
No AI model training on your data: Nordik Lab does not train or fine-tune any AI model using your personal data, health data, or training records.
Google's data practices:Data sent to the Gemini API is subject to Google's API Terms of Service and privacy policies. We use the Gemini API under Google's standard commercial terms, which include data protection commitments. Gemini API data is not used by Google to train their general models without your separate consent to Google.
Nordik Intelligence generates editable drafts, analysis, and suggestions. Its output is not a substitute for professional coaching, medical advice, or clinical judgment. You remain responsible for all training and health decisions.
AI assistant connectors (Claude, ChatGPT)
Separately from Nordik Intelligence, Nordik Lab lets you connect your account to a third-party AI assistant — Claude (Anthropic) or ChatGPT (OpenAI) — using the Model Context Protocol (MCP). For your own account, this is an opt-in integration you set up yourself from Settings → Connections; connecting one does not enable the other. When you interact with Claude or ChatGPT after connecting, that assistant can call back into Nordik Lab to read (and, if authorized, write) your training data, and Anthropic or OpenAI processes whatever you and the assistant exchange as part of that conversation, subject to that provider's own API terms and privacy practices. Nordik Lab does not control what Claude or ChatGPT does with data once it leaves our API — review Anthropic's and OpenAI's own privacy policies for how they handle API inputs.
Coach connections:a coach's Claude/ChatGPT connection can read a specific athlete's data and, where the relationship permissions and connection scopes allow, add notes, manage workouts, or update plans only if that athlete has both (a) an active coaching relationship and (b) Coach AI Access enabled for that coach in the athlete's own Settings. New coaching relationships start with Coach AI Access enabled; existing connections keep their current setting. The setting is re-checked on every request, so turning it off takes effect immediately, even mid-conversation. Nordik Lab keeps a record of which athlete's data a coach's connected assistant accessed and when, for audit purposes.
Fueling data and connectors:your fueling preferences and auto-generated carbohydrate, fluid, sodium, and caffeine targets (see Section 2) are training data exposed through the same MCP tools as the rest of your training record, so a connected Claude or ChatGPT assistant can read them under this same disclosure — and, for a coach's connection, only under the same active-relationship and "Coach AI Access" conditions described above.
8. Data retention
Nordik Lab retains your data for as long as needed to operate your account, support coaching workflows, and comply with legal obligations. Athletes can delete their account themselves from Settings on the web or in the iOS app; coach accounts can request deletion by email. Deletion removes your workouts and health records, readiness and scoring history, provider sync data, alerts and insights, coaching relationships, and your sign-in credentials. We complete deletion or anonymization within 30 days, except where we are required to retain records by law.
Messages and shared files are retained while the relevant account is active, unless deleted sooner under our operational retention practices. We may retain limited records for longer where needed to investigate abuse or security incidents, resolve disputes, or meet legal obligations.
For coach AI connections, we retain a limited audit record of which athlete's data was accessed, which coach's connection accessed it, the tool used, and when the access occurred. These records support security and account review and are deleted with the related account, subject to legal retention requirements.
When you disconnect a provider, Nordik Lab stops pulling new data from that provider. Previously synced records remain in your athlete record unless you request full deletion of those records.
If you revoke Nordik Lab's OAuth access to Strava, we will delete Strava-sourced data from our systems upon your written request to contact@nordiklab.com.
9. International data transfers
Nordik Lab uses infrastructure primarily based in the United States (Vercel hosting, Google Gemini API). If you are in the EU or UK, your data may be transferred to and processed in the United States. Where required by GDPR, such transfers rely on the EU Standard Contractual Clauses (SCCs) or other approved transfer mechanisms incorporated in our agreements with service providers. By using Nordik Lab, EU and UK users acknowledge this transfer.
10. Cookies
Nordik Lab uses session cookies strictly to authenticate you and maintain your login state. We do not use advertising cookies, tracking pixels, or analytics cookies. We do use PostHog for limited product analytics with memory-only storage: it receives broad route usage and an account role, never training, health, biometric, name, or email data. Automatic interaction capture is disabled, and session recording is turned off. We do not record or replay your screen. We use Sentry to monitor application errors; when an error occurs it receives the error itself and technical context such as the page address, browser, and the sequence of actions leading up to it, with sensitive URL parameters removed. See our Cookie Policy for details.
11. Your rights
GDPR rights (EU and UK)
If you are in the EU or UK, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate personal data
- Erasure — request deletion of your personal data where it is no longer necessary, or where you withdraw consent
- Restriction — request that we limit how we process your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw consent for health data processing at any time by disconnecting the relevant provider
To exercise any of these rights, contact contact@nordiklab.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
CCPA rights (California)
If you are a California resident, you have the right to:
- Know what categories of personal information we collect and how they are used
- Delete your personal information
- Opt out of the sale or sharing of your personal information — Nordik Lab does not sell or share your personal information for cross-context behavioral advertising
- Non-discrimination for exercising your privacy rights
To make a California privacy request, contact contact@nordiklab.com.
Deleting your account
Athletes can delete their account and data directly from Settings on the web or in the iOS app — no email required. Coach accounts can request deletion at contact@nordiklab.com. See Section 8 for what deletion removes.
Disconnecting integrations
You can disconnect any integration at any time from Settings → Integrations. Nordik Lab will immediately stop pulling new data from that provider. You can also revoke OAuth access directly from each provider's account settings (Strava, WHOOP, Polar, Garmin, Suunto, Concept2, Wahoo, Hammerhead) to prevent any further data sharing at the source.
You can turn Coach AI Access off for an individual coach from Settings → Connections. This blocks future requests from that coach's connected AI assistant immediately, but it does not recall information that was already sent to the third-party assistant.
12. Children
Nordik Lab is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it.
13. Security
Nordik Lab uses HTTPS/TLS for all data in transit. OAuth tokens and credentials are stored encrypted and are never exposed in client-side code or API responses. Access controls ensure that each user can only access their own data, and coaches can only access data for athletes with an active authorized relationship. A connected coach AI assistant also requires the athlete's Coach AI Access setting and is checked on every request.
Message attachments are stored privately and are available only through authenticated, authorized requests. We limit supported file types and attachment sizes to reduce harmful or excessive uploads. Do not send files you would not want a conversation participant to access.
No security system is perfect. If you discover a security issue, please report it to contact@nordiklab.com.
14. Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects when the policy was last revised. For material changes, we will notify you through the platform or by email before the change takes effect.
15. Contact
For privacy questions, data requests, account deletion, or GDPR rights requests, contact us at contact@nordiklab.com. We aim to respond within 30 days.
If you are reviewing this application as part of an integration partner review (Strava API review, WHOOP partner review, Garmin Health API review, etc.), this page reflects the data practices for all supported integrations.
