This notice explains the current STRYVR beta data flows. It should be reviewed by qualified counsel before a broader commercial launch.
Data we process
Account and profile details; training, nutrition, habits, goals, recovery and wearable records; movement-derived measurements; optional progress media; support requests; and Coach conversations.
Why we process it
To operate the account, calculate athlete-facing trends, adapt training and nutrition guidance, synchronize connected services, provide support, protect the service, and meet deletion or access requests.
AI and camera processing
Movement camera frames are processed in the browser by default; derived measurements may be saved. Reviewed meal descriptions, relevant Coach context, and explicitly enabled physique-comparison images may be sent to the configured AI provider. A first physique baseline stays in the browser and is not sent because there is nothing to compare. Later comparisons retain one browser-local reference and save only the directional result in STRYVR entities. AI output is guidance, not medical diagnosis.
Processors and integrations
STRYVR currently relies on Base44 for authentication, data, hosting, and functions; Polar AccessLink for connected wearable data; Anthropic for configured Coach and meal-parsing features; and browser-delivered MediaPipe components for pose estimation.
Retention and deletion
Records remain while the account is active unless deleted through an available control. Account deletion attempts to revoke Polar access, delete user-scoped entity records, and remove the Base44 login account. If legacy uploaded progress-media URLs require storage cleanup, the automated flow stops before deleting anything and directs the user to support.
Your controls
Settings provides portable JSON export, notification preferences, Polar disconnect, individual record controls where supported, and permanent account deletion. Use the Support page for access, correction, privacy, or legacy-media deletion requests.
Security and limits
User-owned records are intended to be isolated by Base44 row-level permissions. Production launch still requires two-account isolation testing and review of deployed schemas, secrets, logs, and callback configuration.