Privacy Policy
Last Updated: February 28, 2026
At Combat Ready, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our fitness application.
1. Information We Collect
Account Information
| Data Type | Examples | Purpose |
|---|---|---|
| Account Data | Email, username, password (encrypted) | User authentication |
| Profile Data | Age, weight, height, fitness goals, equipment access | Workout personalization |
| Workout Data | Exercise history, sets, reps, weights, duration | Progress tracking |
| Fitbit Data (optional) | Heart rate, sleep, activity levels | Workout optimization |
| Location Data (optional) | GPS coordinates during run tracking, route paths, elevation data | Run tracking, route mapping, pace calculation |
Automatically Collected Data
- Usage Data: Pages visited, features used, session duration
- Device Data: Browser type, operating system, device type
- Log Data: IP address, access times, error logs (for debugging)
- Location Data (when granted): GPS coordinates collected during active run tracking sessions only. We do NOT track your location in the background or when the run tracker is not active.
1a. Location Data & GPS Tracking
What We Collect During Run Tracking:
- GPS coordinates (latitude, longitude) while the run tracker is active
- Timestamps associated with each GPS coordinate
- Altitude/elevation data (when available from your device)
- Route path derived from GPS coordinates
What We Do NOT Collect:
- We do NOT track your location in the background or when the run tracker is not active
- We do NOT share your location data with advertisers or third-party data brokers
- We do NOT build a location profile or track your movements outside of run sessions
How GPS Data Is Stored:
- GPS data is transmitted to our servers only when you save a completed run
- Data is stored in an encrypted database hosted on Google Cloud
- GPS data is retained until you choose to delete it or delete your account
Deleting Your GPS Data:
- Delete individual runs from your workout history at any time
- Delete your entire account to remove all GPS data
- Contact us at privacy@combatready.ai to request deletion
2. How We Use Your Data
We use your information to:
- Generate personalized AI-powered workouts based on your goals and equipment
- Track your fitness progress and provide analytics
- Record and display GPS-based running routes, distance, pace, and elevation data
- Send password reset emails and important account notifications
- Improve our AI algorithms and service quality
- Ensure security and prevent fraudulent use
- Measure app usage and conversion events via Google Analytics to improve our service
- Comply with legal obligations
- Sell your personal data to third parties
- Use your data for personalized advertising or ad targeting
- Share your workout data without your consent
3. Data Sharing
We share data with the following service providers who help us operate Combat Ready:
| Service Provider | Data Shared | Purpose |
|---|---|---|
| Google Cloud | All application data | Secure hosting and database storage |
| OpenAI | Anonymised profile data (age range, experience level, training goals), your chat messages, aggregated fitness metrics (if Fitbit connected). No personally identifiable information (name, email, exact age/weight) is sent. | AI Coach chat responses and AI-powered workout generation. Explicit user consent is obtained before first use. |
| Fitbit | OAuth tokens (with your consent) | Fitness data synchronization |
| SendGrid | Email address | Password reset and notifications |
| Google Analytics | Usage data, device data (anonymized) | App usage analytics and conversion measurement |
| OpenStreetMap (map tiles) | None — map tiles loaded client-side only | Displaying run route maps. No personal data is sent to OpenStreetMap servers. |
4. Data Security
We implement industry-standard security measures:
- Encryption: Passwords are hashed using bcrypt; Fitbit tokens are encrypted
- HTTPS: All data transmitted over secure connections
- Access Controls: Strict authentication required for data access
- Cloud Security: Data hosted on Google Cloud with enterprise-grade protection
- Regular Updates: Security patches and updates applied promptly
5. Data Retention
- Account Data: Retained until you delete your account
- Workout History: Retained until you delete your account
- Fitbit Tokens: Retained until you disconnect Fitbit or tokens expire
- Server Logs: Retained for 30-90 days for debugging purposes
- GPS/Run Data: Retained until you delete individual runs or your account
When you delete your account, we will remove your personal data within 30 days, except where we are required by law to retain it.
6. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Delete your account and associated data
- Export: Download your workout data
- Withdraw Consent: Disconnect third-party services like Fitbit
- Location Control: Enable or disable location permissions at any time through your device settings
- GPS Data Deletion: Delete individual run records or all GPS data from your account
- Object: Object to certain processing of your data
To exercise these rights, please contact us at privacy@combatready.ai
7. Cookies & Analytics
We use essential cookies for:
- Session Management: Keeping you logged in
- Security: Preventing unauthorized access
We also use Google Analytics (via Google Tag) to collect anonymized usage data such as pages visited, session duration, and device type. This helps us understand how our app is used and improve the experience. Google may set cookies to distinguish users and track sessions. You can learn more about how Google uses this data at Google's Privacy & Terms.
We do NOT use:
- Advertising cookies for personalized ads
- Cookies that build a personal advertising profile
8. Children's Privacy
Combat Ready is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child, please contact us immediately.
9. International Data Transfers
Your data may be processed in the United States (where Google Cloud servers are located). We ensure appropriate safeguards are in place to protect your data in accordance with applicable privacy laws.
10. Third-Party Links
Our service may contain links to third-party websites (e.g., Fitbit). We are not responsible for the privacy practices of these external sites. Please review their privacy policies before providing any personal information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this page
- Sending an email notification for significant changes
- Displaying a notice in the application
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: privacy@combatready.ai
Website: combatready.ai