1. Overview
Zone Training Log (“Zone Trainer,” “we,” “us”) is designed around a local-first training log. Your phone reads health data only with your permission, keeps detailed workout processing on the device, and syncs workout history to the Zone Trainer web backend only when you connect an account or use features that require a backend service.
Some features can still contact our backend before account linking, such as device registration, subscription verification, abuse prevention, optional AI workout suggestions, and rewarded ad verification. This policy explains those cases, what changes after account connection, and how the iOS app, Android app, and website at https://www.zonetraininglog.com handle data.
2. Who We Are
Controller: Code Marketer s.r.o.
Contact email: ondrej@sevcik.dev
Address: Na Nabrezi 231/6, Havirov, 736 01, Czech Republic
3. Platform Privacy Model
A) iOS Before Connecting to Web
The iOS app reads Apple Health data only after you grant HealthKit permission. It can read workouts, heart rate, workout routes when available, resting heart rate, energy, distance, effort metrics, running and cycling power, and date of birth where needed for zone calculations. It can write manual workouts and effort values back to Apple Health when you choose to create or update them.
Before you connect a Zone Trainer web account, your detailed workout history is not synced to the Zone Trainer account backend. Workout calculations, summaries, tags, zones, colors, and app settings are stored on the device. Some iOS metadata and settings may also sync through your private Apple iCloud account using CloudKit or iCloud key-value storage, governed by Apple's terms.
The iOS app may still register the device with our backend before account linking. Device registration uses an app install identifier stored in the Keychain, App Attest, app version, and token state so we can protect the service, check entitlement and AI availability, and prevent abuse. The backend stores a hashed form of the install identifier rather than the raw value.
B) iOS After Connecting to Web
When you connect the iOS app to a Zone Trainer web account, the app can sync a cross-platform training mirror so your log is available across iOS, Android, and web. Synced data can include zone profiles, tags, activity colors, planned workouts, workout titles and notes, workout type, start and end time, duration, effort, average and maximum heart rate, distance, pace, elevation, energy, zone metrics, and a compact heart-rate preview series.
Account sync does not upload every raw heart-rate sample and does not upload full HealthKit routes as part of the normal cross-platform workout mirror. HealthKit remains the iOS source for health records; the backend stores the account-linked mirror needed for web and cross-device use.
C) Android Before Connecting to Web
The Android app reads Health Connect data only after you grant Health Connect permission. It can read exercise sessions, heart rate, distance, elevation, and calories, including background health data when you allow it. It can write manual exercise sessions to Health Connect when you create them in the app.
Before you connect a Zone Trainer web account, your detailed workout history is not synced to the Zone Trainer account backend. The Android app keeps a local database and preferences for workouts, summaries, zones, tags, colors, metadata, planned workouts, sync state, account state, and subscription cache. Health records remain managed by Health Connect and the source apps that wrote them.
The Android app may still register the device with our backend before account linking. Device registration uses a generated backend install identifier, Play Integrity in production builds, app version, package information, and token state so we can protect the service, check entitlement and AI availability, and prevent abuse. The backend stores a hashed form of the install identifier rather than the raw value.
D) Android After Connecting to Web
When you connect the Android app to a Zone Trainer web account, the app can sync the same cross-platform training mirror used by iOS and web. Synced data can include zone profiles, tags, activity colors, planned workouts, workout titles and notes, workout type, start and end time, duration, effort, average and maximum heart rate, distance, pace, elevation, energy, zone metrics, and a compact heart-rate preview series.
Account sync does not upload every raw heart-rate sample. Health Connect remains the Android source for health records; the backend stores the account-linked mirror needed for web and cross-device use.
E) Web Account and Website
The web app stores account data needed to sign you in, link devices, show synced workouts, manage planned workouts, maintain entitlements, and operate account sync. This can include your email address, linked device records, subscription and entitlement state, training mirror data, planned workouts, metadata overrides, AI consent state, AI usage counters, and generated AI results.
The marketing website uses analytics and advertising pixels only after you accept analytics cookies. Lead signup forms store your email address, consent state, privacy-policy version accepted, page and campaign context, user agent, and a hashed IP address for abuse prevention and attribution.
4. Data We Collect
A) Health Data
With your permission, the iOS app reads and writes Apple HealthKit data and the Android app reads and writes Health Connect data such as:
- Workouts, exercise sessions, and activity details
- Heart rate samples
- Distance, pace, speed, elevation, energy, source app, device name, and related metrics where available
- Effort ratings and related metrics
- Route or location data from Apple Health or Health Connect when available, with the required permissions, and when route features are used
- Manual workouts you create in Zone Trainer and choose to write to HealthKit or Health Connect
We use this data to compute training zones, summaries, route displays, and your training log. We do not use HealthKit or Health Connect data for advertising or marketing.
B) App Content You Create
- Manual workouts
- Workout titles, descriptions, tags, notes, and labels
- Activity color preferences
- Zone definitions and settings
- Planned workouts and AI prompt inputs you choose to enter
C) Account, Device, Usage & Settings
- App preferences (e.g., appearance, configuration)
- Feature state and local settings
- Account-linking state, email address used for sign-in, and sync status
- Device identifiers and authentication state used for device registration, account sync, App Attest, Play Integrity, fraud prevention, and abuse prevention
- Device-linked AI consent status and accepted privacy-policy version
- Website cookie consent state, lead signup consent, campaign context, referrer, user agent, and hashed IP address when you submit website forms
D) Purchases
We use Apple StoreKit on iOS and Google Play Billing on Android to process purchases. We do not receive or store your payment card information. We may store subscription status, entitlement state, purchase source, expiration dates, and limited purchase verification identifiers returned by Apple or Google.
If you delete your Zone Trainer account through our self-service deletion page, we delete Zone Trainer purchase entitlement and server transaction rows tied to that account. Apple App Store and Google Play purchase records remain managed by Apple and Google for billing, tax, refund, dispute, and fraud handling. If you delete synced server data while keeping your account, we retain minimal purchase entitlement data so your account can still reflect paid access after you relink a device.
E) AI and Rewarded Ad Data
If you accept the current AI privacy terms and use AI workout suggestions, the app may send recent workout context, planned workouts, workout titles, workout descriptions, durations, heart rate summaries, pace, elevation, effort, tags, zone metrics, and the AI prompt text you enter to our backend and to OpenAI to generate a suggestion.
When you request workout photo transcription, the app sends a resized photo with embedded image metadata removed to our backend and OpenAI to extract an optional workout title and description. You review and edit the text before applying it to an activity or planned activity. We do not save transcription photos as workout attachments, put them in cloud media storage, or include them in diagnostic logs. Android camera capture uses a private temporary file that is deleted after preparation or cancellation; abandoned capture files are removed when the photo flow next opens. Photo transcription does not require rewarded ads. OpenAI processes API inputs under its API data controls.
For free-tier AI generations, we also use Google AdMob rewarded ads. AdMob may process ad request data, device and app identifiers, reward verification callback data, and related anti-fraud information to deliver and verify rewarded ads.
F) AI Coaching Data
If you accept the current AI terms and request AI coaching, we process the goals and plan preferences you submit, including selected activities, availability, schedule exceptions, desired frequency and duration, experience, equipment, and limitations. You may optionally provide age, sex, weight, and height. Coaching is limited to users who confirm that they are at least 18 years old.
When you choose to use workout history, up to the most recent three months may be supplied from your device or account mirror. Depending on the administrator-controlled processing mode, the coaching service sends either the bounded workout snapshot or a compact summary to OpenAI. Relevant fields can include title, description, activity type, effort, duration, heart-rate summaries, distance, elevation, pace, and speed. You can generate without sharing workout history.
Separately, when workout history is enabled before coaching setup recommendations, we may send coarse activity-type counts from the last three months, such as how many running or strength workouts you logged, so the recommendation can prefer activities the app already records for you. Those aggregate counts do not include workout dates, titles, descriptions, biometric metrics, routes, media, or tags. If you disable history before requesting recommendations, those counts are not sent. The bounded individual-workout snapshot or summary used for each later generation or adaptation is a separate choice.
We store coaching goals, plan setup, generated sessions, warnings, plan revisions, typed confirmed change proposals, completion associations, usage records, and durable generation state so an interrupted request can finish and devices can synchronize the result. A plan-specific question and its generated answer are returned for that request but are not retained as conversation history; only the typed proposed changes and audit metadata are stored for later confirmation. Raw history input is cleared after it is summarized or after a raw-mode plan is successfully published. Failed or cancelled requests may retain the bounded input long enough to support an explicit retry, and account deletion removes this coaching data. Push tokens may be stored to notify your active linked devices when a requested plan is ready or fails.
G) Workout Media
When cloud workout media is enabled, images and videos you attach to a workout can be stored in a private Cloudflare R2 bucket so they are available on iOS, Android, and web. The app creates an optimized original and a small thumbnail, removes embedded image metadata such as EXIF and GPS data, and stores technical information needed for synchronization, including opaque asset identifiers, media type, dimensions, duration, byte size, checksum, upload state, and workout association.
Before account linking, an authenticated device may receive a device-owned guest media workspace. Existing iOS workout media may be copied from private iCloud storage into that workspace without uploading unrelated health data. Older app versions may retain the iCloud originals during the compatibility transition. App versions with verified migration cleanup remove a legacy iCloud copy only after checking that its cloud-media replacement is available and intact. Deleting an R2 copy does not automatically delete an iCloud original that an older app version retained. When you later connect an account, the guest workspace is claimed by or merged into that account. A guest workspace cannot be recovered on another device until it is claimed by an account.
H) Technical Diagnostics
We store server-side API warnings and errors to investigate failures, maintain reliability, and protect the service. A record can include its time, severity, API route template, response status, request duration, error code or failure reason, sanitized error details or stack trace, and server environment and deployment version. Compatible app versions also provide platform, app version, build number, and release channel. Missing release information is recorded as unknown.
Each API request receives a new random diagnostic identifier. This identifier is not a persistent user or device identifier. The diagnostic metadata does not add advertising identifiers or a browsing or activity history, and we do not use these logs for advertising or cross-app tracking. Device authentication, account records, and purchase verification are separate service data described above.
The database logger is designed to exclude health records, request and response bodies, credentials, email addresses, and persistent account or device identifiers. Sensitive fields and recognizable secrets are redacted before storage. These API diagnostics do not collect mobile crash dumps, screen recordings, or individual screen taps.
Only authorized administrators can view or export the diagnostic records for troubleshooting. The database retains them for 30 days; expired records are excluded from the viewer and exports, and scheduled cleanup removes them hourly. Downloaded exports are separate copies and are not automatically erased by database cleanup; they remain subject to restricted access and our purpose-limited retention practices.
5. How We Use Data
- Sync and display workouts, summaries, and zones
- Calculate time-in-zone metrics
- Authenticate devices and linked accounts
- Mirror account-linked workouts, metadata, settings, and planned workouts across Android, iOS, and web
- Store, optimize, synchronize, display, reorder, and delete workout media across your devices
- Restore purchases and entitlements
- Generate AI workout suggestions when you explicitly use AI features
- Generate and adapt AI coaching plans, answer plan-specific questions, and associate completed workouts with scheduled coaching sessions when you request or schedule those features
- Verify rewarded ads required for free-tier AI generations
- Remember website cookie choices and process lead signup requests
- Provide customer support
- Improve app reliability and performance (diagnostics only)
6. Data Sharing
We do not sell your personal data. We only share data with:
- Apple platform services such as HealthKit, iCloud, StoreKit, App Store services, and App Attest
- Google platform services such as Health Connect, Google Play services, Google Play Billing, Play Integrity, and AdMob rewarded ads
- Vercel for application hosting, and Supabase for database storage and authentication, including the API diagnostic database
- Cloudflare, which stores private workout-media objects in the configured European R2 jurisdiction
- Resend, which delivers inactivity and media-retention warnings to account email addresses
- OpenAI, to transcribe workout photos and generate AI workout suggestions, coaching intake guidance, history summaries, plans, adaptations, and plan-specific answers that you request
- Analytics and advertising measurement providers only after you accept analytics cookies on the website
We may also share data if required by law or to protect our legal rights.
7. Data Storage, Security & Retention
- Detailed workout processing starts locally on your device.
- On iOS, some metadata and settings may be stored in your private iCloud account through CloudKit or iCloud key-value storage, governed by Apple's policies.
- On Android, Health Connect records remain in Health Connect and connected provider apps. Zone Trainer keeps a local app database and preferences for workouts, summaries, zones, tags, colors, metadata, sync state, planned workouts, account state, and subscription cache.
- If you link an account or use web sync, our backend stores the account-linked training mirror needed for cross-platform use: linked devices, account identifiers, zone profiles, workout mirrors, metadata overrides, tags, activity colors, planned workouts, subscription state, AI consent, AI usage, and generated workout results.
- Normal account sync does not upload every raw heart-rate sample and does not upload full HealthKit routes as part of the cross-platform workout mirror. It uses summarized workout metrics and a compact heart-rate preview.
- Cloud workout media uses short-lived, single-object upload and download links. The R2 bucket is not public, and object names use opaque identifiers rather than email addresses or workout titles.
- Under media profile v2, free accounts receive 1 GB (1,073,741,824 bytes) for new photos; new videos require Premium. Monthly, yearly, and Lifetime products receive 10 GB for photos and videos. Registered legacy iCloud photos and videos are permanently excluded from your quota, including later legacy additions while migration is enabled. They still occupy provider storage. Originals and thumbnails count together for ordinary media. If a limit is reduced, a subscription expires, or a guest workspace is merged into an account above its limit, existing media remains available for viewing, export, and deletion; only new uploads are restricted.
- Media belonging to guest, free, or expired-subscription owners may be deleted after 24 months without meaningful activity. We warn eligible account holders approximately 90, 30, and 7 days beforehand by available email, push, or in-app channels. Opening the app, using the training log, using media, or choosing Keep media cancels the pending deletion. Active monthly and yearly subscribers and Lifetime users are exempt. Users already beyond the threshold when this policy launches receive a new 90-day warning period rather than immediate deletion.
- Device install identifiers are hashed before backend storage where applicable. Device access tokens are short-lived, and refresh tokens are stored server-side as token hashes.
- We transmit personal and sensitive data using modern cryptography such as HTTPS and limit backend access to what is needed to operate and support the service.
- Short-lived AI request state and generated results may be retained briefly to finish reward verification, recover interrupted requests, and return the result to your device.
- Photo transcription keeps no photo bytes or photo URL in our backend storage. Final transcription text can be returned again for 24 hours so a lost response does not consume a second scan. Expired text is cleared on access or by daily maintenance, within approximately 48 hours for inactive accounts. Minimal account or device attribution, request identifiers, an image hash, request status, month, model, and token counts remain to enforce allowances and prevent duplicate charges. Only text you apply is added to your workout and follows its normal storage and sync settings.
- AI request events, daily usage counters, and generated result records may be retained as needed to enforce limits, provide the feature, debug failures, and prevent abuse.
- AI coaching uses a bounded three-month individual-workout history window only when enabled for that generation or adaptation. Coarse activity-type counts used for setup recommendations are a separate payload and are omitted when history is disabled before recommendations. Raw coaching history is cleared after summarization or successful raw-mode publication; failed and cancelled inputs can remain available for an explicit retry until the associated coaching data or account is deleted.
- The 30-day API diagnostic retention period applies to our diagnostic database. It does not describe the retention of account records, workout data, media, AI records, or separate infrastructure logs. Hosting and network providers also process connection information, such as IP addresses, to deliver and secure requests; their operational logs are separate from this database.
- We retain personal data only as long as needed to provide app functionality, meet legal obligations, resolve disputes, protect the service, and honor your choices.
- You can delete the app to remove local app data. iCloud data is managed by Apple. Health Connect data is managed in Health Connect or the source app. Deleting cloud media removes the corresponding R2 objects. Account-linked backend data and cloud media can be removed through the self-service Zone Trainer deletion page.
8. Your Choices
- HealthKit access: You can grant or revoke iOS access at any time in Settings > Health.
- Health Connect access: You can grant or revoke Android access in Android Settings or the Health Connect app.
- Account sync: You can use the app without linking an account. If you link an account, you can use /delete-account to delete your Zone Trainer account and account-linked backend data, or to delete synced server data while keeping your login account.
- Workout media: You can remove individual attachments at any time. When an inactivity warning is active, opening Zone Trainer or choosing Keep media retains your media. Local copies are controlled separately by each device.
- AI consent: You can accept or revoke AI access in the app. If you do not accept the current AI privacy terms, AI features stay disabled.
- Workout history for coaching: You can turn off history before setup recommendations so no coarse activity-type counts are sent, and you can independently omit bounded individual-workout history from a later generation or adaptation.
- Purchases: Manage iOS subscriptions in Settings > Apple ID > Subscriptions and Android subscriptions in Google Play.
- Website cookies: You can accept or decline analytics cookies on the website. Essential cookies needed for sign-in and consent storage may still be used.
- Data deletion: You can delete the app, use local reset tools where available, manage HealthKit or Health Connect data in system settings, or use /delete-account to remove Zone Trainer server-held account, sync, provider, device, cloud media, AI, and token data.
The onboarding privacy overview is an explanation of these practices. Continuing past it does not grant HealthKit or Health Connect access, enable AI, or replace separate consent where required. Contact us if you need help accessing or deleting server-held data, including data associated with use without a linked account.
9. Provider Connections
Apple Health and Health Connect data reaches Zone Trainer through the paired iOS and Android apps after you grant platform permissions. Strava and Garmin provider connections are not currently enabled in the public service. If we enable additional provider connections later, they will require explicit provider authorization and will be governed by the permissions and revocation controls shown during that connection flow.
10. International Users
If you use the app outside your country, your data may be processed in the countries where Apple, Google, our cloud providers, OpenAI, and other service providers operate.
11. Changes to This Policy
We may update this policy periodically. The latest version will always be posted on our website, and the “Last updated” date will reflect changes.
12. Contact
If you have questions or requests, contact us at:
ondrej@sevcik.dev
A question about this page?
Get in touch with the person behind Zone.