ATHLIVIA LLC ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, including OptiRun BASE+ and related applications.
Third-Party Integrations
Our services may integrate with third-party fitness platforms including Apple HealthKit, Garmin Connect, Strava, Polar Flow, and COROS Training Hub. When you connect these services, we access certain data as described below (some integrations are not yet active — see Section 4 for the current status of each). You can disconnect any active integration at any time through your account settings.
1. Information We Collect
1.1 Account Information
- Name and email address
- Password (encrypted)
- Profile information (team affiliation, role)
1.2 Health and Fitness Data
When you connect your wearable device or fitness platform, we may collect:
| Data Type |
Examples |
Source |
Purpose |
| Activity Data |
Workouts, running distance, pace, steps |
Apple HealthKit, Garmin Connect, Strava, Polar Flow, COROS, manual entry |
Training load analysis |
| Heart Rate Data |
Resting HR, HR zones, HRV |
Apple HealthKit, Garmin Connect, Strava, Polar Flow, COROS |
Recovery and readiness assessment |
| Sleep Data |
Sleep duration, sleep stages, sleep score |
Apple HealthKit, Garmin Connect, Polar Flow, COROS |
Recovery monitoring |
| Body Metrics |
Weight, body composition (if available) |
Apple HealthKit, Garmin Connect, manual entry |
Athlete profile management |
| GPS / Route Data |
Route summary, elevation gain, distance (raw GPS coordinates are NOT collected by us) |
Garmin Connect, Strava, COROS |
Training analysis (summary level only) |
In addition, you may voluntarily enter the following health and medical information in the app: injury history, blood test results, body composition, menstrual cycle logs, self-medical check results, rehabilitation / reconditioning records, and daily condition logs (heart rate, HRV, sleep, fatigue, subjective condition, etc.).
1.2.1 Sensitive Personal Information
Some of the information above (such as injury history and blood test results) may constitute "special care-required personal information" under the Act on the Protection of Personal Information of Japan (APPI). We handle such information according to the following principles:
- It is collected only with your prior consent. Entry is always optional, and the core features of our services remain available without it.
- It is used solely to provide service features such as condition management, injury-prevention support, and training optimization.
- It is never provided to third parties without your consent, except where required by law.
- In the event of a data breach, we will report to the Personal Information Protection Commission and notify affected users as required by law.
1.3 Usage Information
- App usage patterns and feature interactions
- Device information (OS version, device model)
- Log data and error reports
2. How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery: To provide training analysis, condition monitoring, and performance insights
- Personalization: To customize recommendations based on your training data
- Communication: To send service-related notifications and updates
- Improvement: To analyze usage patterns and improve our services
- Support: To respond to your inquiries and provide customer support
3. Data Sharing and Disclosure
3.1 We Do NOT:
- Sell your personal data to third parties
- Share your health data with advertisers
- Use your data for purposes unrelated to our services
3.2 We May Share Data With:
- Team Coaches/Staff: When you join a team (for example, by entering a team invite code), your training, condition, and health data (including sensitive information you have entered, such as injury history) become visible to the coaches and staff of that team as an inherent part of the team feature. Joining a team constitutes your consent to this sharing. To stop sharing, leave the team or contact us at the address below. Data obtained from third-party APIs (Garmin, Strava, etc.) is shared with your team in the same way while you remain a member.
- Service Providers: Third-party services that help us operate our platform (e.g., cloud hosting, analytics) under strict confidentiality agreements
- Legal Requirements: When required by law or to protect our rights
For how data obtained from Garmin Connect is collected, used, processed, and stored — and whether it is shared with or processed by any third party, including AI services — see 4.2 Garmin Connect.
3.3 Aggregated Data
We may use anonymized, aggregated data for research and statistical purposes. This data cannot be used to identify individual users.
4. Third-Party Platform Integrations
4.1 Apple HealthKit
Our iOS apps (OptiRun BASE+, OptiRun PERSONAL) may read health data from Apple HealthKit with your explicit permission.
- Data Collected: Steps, heart rate (resting & active), sleep analysis, active energy (calories burned), workout data, body weight
- Purpose: Training load analysis, condition monitoring, energy availability (EA) calculation
- Important: HealthKit data is never used for advertising or marketing. Data is only accessed with your explicit permission and is not stored in iCloud.
4.2 Garmin Connect
OptiRun BASE+ integrates with Garmin Connect through the Garmin Connect Developer Program. The integration takes place only when you explicitly authorize it; without your authorization we do not collect, store, or process any Garmin data. This section governs how Garmin-sourced data is collected, used, processed, and stored, and states whether Garmin data is shared with or processed by any third party, including third-party AI or data-processing services. The Japanese-language version of this section is published at privacy.html#garmin.
- Data We Collect: Activity data (Garmin activity ID, start time, activity type, distance, duration, pace, average and maximum heart rate, calories, heart-rate zones), daily summaries (steps, calories, resting heart rate, stress level, Body Battery score), sleep data (sleep stages, sleep score), heart-rate variability (HRV), and the user identifier issued by Garmin (Garmin API User ID) together with the authentication tokens. We do not collect or store raw GPS route coordinates.
- How We Collect It: Data primarily reaches us through notifications (PING/PUSH) sent from Garmin's servers to our server endpoint. In addition, only when you explicitly trigger a sync inside the app, our server may query the Garmin APIs for your own data. We never retrieve data from Garmin at our own discretion, without your authorization and action.
- Authentication and Token Handling: OAuth 2.0 (PKCE) consent-based access. You select which categories to share and explicitly authorize them on the official Garmin Connect authorization screen. Access and refresh tokens are held in a dedicated table on our servers (Supabase), protected by AES-256 storage encryption at rest and TLS 1.2 or higher in transit. That table is governed by Row Level Security so that no one other than the account owner can read it, and only permission-restricted server-side functions use the tokens.
- Purpose of Use: Calculating training load (ACWR, sRPE) and Energy Availability (EA), monitoring condition and recovery, preventing injury and overtraining, and delivering coach-created structured workouts to your Garmin device. We do not use Garmin data for any purpose other than providing these service features.
- How We Process It: All received data is processed automatically by our own server-side functions (Supabase Edge Functions). Processing consists of (1) validating the payload and normalizing units and local dates, (2) de-duplicating records using the Garmin activity ID, (3) computing derived values such as training load, Energy Availability, and condition metrics, and (4) aggregating the results for display to you and to your team. All processing is automated; our staff view individual Garmin-sourced records only at your request or with your consent, for example when responding to a support enquiry.
- Where and How Long We Store It: Garmin-sourced data is stored in a Supabase (PostgreSQL) database. The data resides in Japan, in the AWS Tokyo region (ap-northeast-1), and backups are kept in the same region. It is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, and access is restricted by Row Level Security. Garmin-sourced records are identified as
data_source: garmin. Data is retained while the integration remains connected and your account remains active.
- Data We Send to Garmin: When a coach sends a training session to your Garmin device, we transmit workout information (session name, sport, distance or duration, step structure, and scheduled date) from our servers to the Garmin APIs. This happens only when a coach performs the send action, and no health or medical information is transmitted.
- Who Can See It: Garmin-sourced data is visible only to you and to the coaches and staff of a team you have chosen to join.
- Disclosure to Third Parties: We never provide, sell, or lease data obtained from the Garmin APIs to any third party. We do not disclose it to data brokers, advertisers, insurers, or third-party analytics businesses, and we do not use Garmin data to train machine-learning models, for advertising or profiling, or to build competing fitness products.
- Third-Party AI and Data-Processing Services: We never send Garmin-sourced data to, or have it processed by, any external AI service (generative AI, large language models, image-analysis APIs, and the like) or any other third-party data-processing service. Our service includes a feature that estimates the nutritional content of a meal from a photo, and that feature alone sends photos you voluntarily upload to an external AI service (see 4.6 Use of AI Services); Garmin-sourced data is never included in that path. We also never send Garmin-sourced data to analytics services (PostHog, Google Analytics).
- Sub-Processors: The storage and processing described above take place on the infrastructure of the following providers, with whom we have data-protection agreements in place. Each handles the data only on our instructions and never uses Garmin data for its own purposes. These are the only sub-processors that handle Garmin-sourced data:
- Supabase, Inc. (US): database, authentication infrastructure, and server-side processing. The data itself is stored in the AWS Tokyo region (in Japan) used by Supabase.
- Vercel, Inc. (US): hosting for the web version. Garmin-sourced data may pass through this environment while a data export is being generated, but it is never stored on Vercel.
- Data Deletion: When you disconnect the integration, either in Garmin Connect or in our app, we immediately revoke and delete the authentication tokens upon receiving the deregistration notification, and we delete the data obtained from Garmin Connect (within 30 days at the latest). The same deletion applies when you delete your account. You may also request deletion directly using the contact details below.
- License Compliance: Our use of Garmin Connect data is governed by the Garmin Connect Developer Program license agreement and the Garmin brand guidelines.
- Attribution: Wherever Garmin-sourced data appears in our app, we display attribution in accordance with the Garmin brand guidelines: the Garmin logo together with the device model on activity screens, "This chart was created using data provided by Garmin." beneath health-metric charts, and "Insights derived in part from Garmin device-sourced data." beneath analyses that combine multiple data sources.
- Changes to This Section: We will not change this section, as it relates to the handling of Garmin data, without the prior written approval of Garmin Ltd.
This integration becomes active after Garmin Ltd. approves our production access. Until then, OptiRun BASE+ does not collect, store, or process any Garmin Connect data.
4.3 Strava
We access data through the Strava API (OAuth 2.0 authentication) with your explicit consent.
- Data Collected: Activity data (distance, pace, average and maximum heart rate, elevation, cadence, power in watts, calories burned, moving time), athlete profile information (name, profile image)
- Authentication: OAuth 2.0 consent-based access. You choose the scope of data to share via the Strava authentication screen. Authentication tokens are securely managed in the device's Keychain (encrypted storage) and in our encrypted server-side database.
- Purpose: Automatic training log import and storage, running data analysis, training load visualization, Energy Availability (EA) calculation
- Data Storage: Imported activity data is stored in the same database table as manually entered training records and is shared between coaches and athletes. Strava-sourced data is identified as "data_source: strava".
- Duplicate Prevention: We record Strava's unique activity ID to prevent duplicate imports of the same activity.
- Data Deletion: When you disconnect Strava, authentication tokens are immediately removed from your device. All data obtained from Strava is deleted from our servers within 30 days.
4.4 Other Fitness Platforms
- Polar Flow: We access training sessions, activity data, and recovery metrics through the Polar AccessLink API (OAuth 2.0, consent-based; rolling out via app updates).
- COROS Training Hub: COROS API integration is currently under review by COROS and will be provided after approval. Until then, the app supports importing GPX files exported from COROS.
4.5 Data Handling Principles
We adhere to the following principles for all data obtained from fitness platforms:
- We do not collect or use your data without your explicit consent
- Data is used only for the purposes described in this policy
- We never use fitness data for advertising or marketing purposes
- We never sell or share fitness data with third parties
- You can disconnect integrations and request data deletion at any time
- After disconnection, collected data is deleted from our servers within 30 days
You can revoke access to any active integration at any time through:
- Your OptiRun BASE+ account settings
- The respective platform's connected apps settings (e.g., the Strava app; and Garmin Connect, Polar Flow, or COROS once those integrations become active)
4.6 Use of AI Services
The only feature in our services that uses an external AI service is the estimation of nutritional content from a meal photo. For that feature, the photo you voluntarily capture or upload, together with any correction you type, is sent to an external AI service (an image-analysis API provided by OpenAI or Anthropic) for processing. The processing serves only that feature, and we use these services under terms and settings under which the submitted data is not used to train the provider's models.
Data obtained via API from external fitness platforms — Garmin Connect, Strava, Polar Flow, COROS, and Apple HealthKit — is never shared with, or processed by, any external AI provider or other third-party AI service. Such data is never included in the AI processing path described above. For the handling of Garmin data, see 4.2 Garmin Connect.
5. Data Storage and Security
5.1 Storage
- Data is stored on secure cloud servers (Supabase / PostgreSQL) hosted on AWS infrastructure in the Tokyo region (ap-northeast-1)
- Servers are located in ISO 27001 / SOC 2-certified data centers with industry-standard physical and network protections
- Data is encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Backups are stored within the same Tokyo region and are subject to the same security controls
5.2 Security Measures
- SSL/TLS encryption for all data transmission
- Row Level Security (RLS) for database access control
- Encrypted storage for sensitive data
- Secure authentication via Supabase Auth
- Regular security audits
6. Data Retention
- Active Accounts: Data is retained while your account is active
- Deleted Accounts: Data is deleted within 30 days of account deletion, except where retention is required by law
- Backup Data: May be retained in backups for up to 90 days
7. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Restriction: Request suspension of use or of third-party provision of your data
- Portability: Request export of your data in a standard format
- Withdraw Consent: Disconnect active third-party integrations at any time
To exercise these rights, please contact us at t.kamikubo@athlivia26.com
8. Children's Privacy
Our services are not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you are under 18, please use our services only with parental consent; users under 16 must obtain the consent of a parent or legal guardian. For team-based use by schools and clubs, we ask the organization to inform parents/guardians and confirm their consent.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers. Specifically, we entrust the processing of personal data to the following service providers located outside Japan, and have confirmed through contractual data-protection terms that each provider implements safeguards equivalent to those required by the APPI:
- Supabase, Inc. (US): database and authentication infrastructure (data is stored in Japan, AWS Tokyo region)
- Vercel, Inc. (US): web application hosting
- Stripe, Inc. (US): payment processing
- Resend (Plus Five Five, Inc., US): email delivery
- PostHog, Inc. (US): product usage analytics
- Google LLC (US): website analytics and app distribution (Google Play)
- Apple Inc. (US): app distribution and in-app purchases (App Store)
10. Cookies and Tracking Technologies
On our website (athlivia26.com), we use only the minimum cookies and similar technologies required to operate the site:
- Strictly Necessary: Session cookies for authentication and form submission.
- Analytics: Aggregated, anonymized page-view analytics. No personally identifying tracking, cross-site tracking, or advertising IDs are used.
Our mobile apps (OptiRun BASE+ for iOS and Android) do not use third-party advertising SDKs, cross-app tracking, or IDFA/AAID-based profiling. Fitness data obtained from Apple HealthKit, Garmin Connect, Strava, Polar Flow, or COROS is never used for advertising or shared with any advertising network.
To improve our services, our mobile apps may collect app usage information (screen views and feature usage, associated with your account) using the product analytics tool PostHog. This information is never used for advertising and never shared with third parties for their own purposes.
11. Trademarks
The following are trademarks or registered trademarks of their respective owners and are used here for descriptive purposes only:
- Garmin® and Garmin Connect® are registered trademarks of Garmin Ltd. or its subsidiaries.
- Strava® is a registered trademark of Strava, Inc.
- Polar® and Polar Flow® are registered trademarks of Polar Electro Oy.
- COROS™ is a trademark of COROS Wearables, Inc.
- Apple®, Apple HealthKit®, HealthKit®, and Apple Watch® are registered trademarks of Apple Inc.
ATHLIVIA and OptiRun BASE+ are trademarks of ATHLIVIA LLC. All other trademarks are the property of their respective owners. No endorsement by, sponsorship of, or affiliation with any third-party trademark holder is implied.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last Updated" date.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
ATHLIVIA LLC
Representative: Toshinao Kamikubo
Omiya Marui 7F, 2-3 Sakuragi-cho, Omiya-ku, Saitama City, Saitama 330-0854, Japan
Email: t.kamikubo@athlivia26.com
Phone: +81-90-6280-1648