Brick
TermsPrivacyHealth dataAttributions

Privacy Policy

Effective 2026-07-29. This policy explains what Brick ("we", "us") collects, why, where it lives, and the rights you hold over it. Brick is built privacy-first: your training and health data exists to coach you, and for no other purpose.

1. What we collect

  • Account data — name, email, and authentication identifiers (managed by Supabase Auth; passwords are hashed, never visible to us).
  • Training data — activities, workout files (FIT), power/heart-rate/pace streams, plans, races, and gear you connect or upload from Strava, intervals.icu, or manually.
  • Health data (special category) — heart rate, HRV, sleep, resting HR, weight, and subjective wellness check-ins. Processed only with your explicit, separately given consent (GDPR Art. 9(2)(a)).
  • Usage data — AI token usage (shown transparently to you), audit logs of security-relevant actions, feedback you submit, and subscription/billing status.

2. Why we process it (legal bases)

  • Providing the coaching service you signed up for (contract, GDPR Art. 6(1)(b)).
  • Health-data-driven coaching features (explicit consent, Art. 9(2)(a)) — withdrawable at any time in Settings.
  • Security, fraud prevention, and abuse protection (legitimate interest, Art. 6(1)(f)).

3. AI processing

Summaries of your training data are sent to our AI providers (Anthropic) to generate coaching insights. We send derived metrics and summaries — not raw files. Providers are contractually barred from training on your data. Most analysis runs deterministically on our servers with no AI involvement at all, and every AI call is metered and visible to you in Settings.

4. Where your data lives

Data is stored in Supabase (Postgres) with row-level security so only you — and coaches you explicitly authorize — can read your rows. Integration tokens are encrypted at rest with AES-256-GCM. Traffic is TLS-encrypted end to end.

5. Sharing

We never sell data. Sharing happens only: (a) with a coach you explicitly link and consent to, revocable anytime; (b) with processors needed to run the service (Supabase, Vercel, Anthropic, Stripe for web payments, Apple for in-app purchases, Resend, Strava/intervals.icu at your direction); (c) if required by law.

6. Your rights (GDPR / CCPA)

  • Access & portability — one-tap full JSON export in Settings.
  • Erasure — delete your account in Settings; all data, files, and AI memory are permanently removed immediately.
  • Rectification — edit your profile, thresholds, and AI memory anytime.
  • Withdraw consent — in Settings, withdraw health-data consent (deletes health snapshots and stops wellness/AI health processing) or disconnect integrations. Full erasure is available via Delete account.
  • Do not sell / share (CCPA) — we do not sell personal information and do not share it for cross-context behavioral advertising.
  • Complaint — you may lodge a complaint with your local supervisory authority.

7. Retention

Data is kept while your account is active. On deletion it is removed immediately from production systems (database and object storage). Encrypted backups are retained under our infrastructure provider's backup schedule and roll off within approximately 30 days (ops SLA — see launch compliance checklist). Provider webhook payloads are purged after 30 days. Audit logs of the deletion itself are retained (without personal content) for security compliance.

8. Children

Brick is not directed at children under 16 and we do not knowingly process their data.

9. Changes

Material changes bump this document's version and you'll be asked to review and re-accept on your next sign-in.

Contact

Privacy questions: privacy@brick.training.