Privacy Policy
This Privacy Policy explains how Based Training ("Based Training", "we", "us"), operated by Jan Adamski (NIP PL5342201833), Poland — the data controller — collects, uses, and protects your personal data when you use the Based Training application at sport.bigapp.io (the "Service"), including your rights under the EU General Data Protection Regulation (GDPR).
1. Data we collect
- Account data — your email address, name, and a securely hashed password.
- Connected-provider data — when you connect a third-party account (e.g. Strava, Wahoo, Garmin), we access, with your explicit authorization, the data you permit: your activities and their metrics (duration, distance, heart rate, power, pace, cadence, GPS/route where applicable), planned workouts, and profile/threshold values (FTP, threshold pace or heart rate). We store provider access and refresh tokens that authorize the sync, encrypted at rest, and only request the access needed to provide the Service. When completed-activity import is enabled for a destination account, we also retain the original provider FIT recording (including its sensor and route data) so the requested import can be retried safely.
- Experimental Garmin connection data — Garmin does not provide Based Training with an official OAuth flow for this connection. If you choose the hosted Garmin connection, we temporarily process your Garmin email address, password, and any MFA verification code in server memory solely to complete that sign-in. We do not persist those credentials in our database, logs, cache, backups, or analytics. A password or verification code is discarded when its active sign-in step finishes. Retained MFA or token-result state expires after five minutes, and after successful connection we retain only the resulting encrypted access and refresh tokens.
- Data you enter — training thresholds, planned workouts, and preferences.
- Technical data — IP address, browser/user-agent, and essential session cookies, used to operate and secure the Service.
2. How we use your data
- To display, aggregate, and de-duplicate your training history across connected providers.
- According to each connected account's import preference, to send an original completed-activity recording that is missing from that provider.
- To generate structured workouts and training recommendations based on your recent activity and thresholds.
- To send transactional email (account confirmation, password reset, security notices).
- To secure the Service, prevent abuse, and comply with legal obligations.
We do not sell your personal data or use it for advertising.
3. Legal bases (GDPR)
We process your data on the basis of: your consent (connecting a provider account and any AI processing of that data); performance of a contract (providing the Service you sign up for); and our legitimate interests (securing and improving the Service), balanced against your rights.
4. Third parties and sub-processors
We share data only with providers that help us run the Service, under contract and only as needed:
- Connected fitness platforms (Strava, Wahoo, Garmin, and similar) — accessed under your authorization and governed by each platform's own terms and privacy policy.
- Email delivery — Resend, to send transactional email.
- AI processing — a large-language-model provider, used to generate workouts and recommendations. Data from providers whose terms prohibit third-party AI processing (including Strava) is excluded from these features.
- Hosting — our servers are located in the European Union.
5. Connecting and disconnecting accounts
Most providers connect through their official OAuth flow. The experimental Garmin connection instead signs in through Garmin Connect's private, unsupported interface as described in Section 1. You can disconnect at any time from your Based Training settings, which deletes our stored tokens for that connection. You may also revoke access directly in the provider's own settings where that option is available. Disconnecting stops further syncing; data already synced is handled per Section 6.
6. Data retention and deletion
We keep your data for as long as your account is active. To request a copy of your data (export) or deletion of your account and associated data, email privacy@bigapp.io from the address on your account. We will fulfil export and deletion requests within 30 days, except where we must retain limited records to meet a legal obligation. In-app self-serve export and deletion may be added later; until then, email is the supported path.
7. Security
We protect your data with encryption in transit (HTTPS), access controls, and encrypted storage of provider credentials. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a breach where required by law.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your data, and to data portability. You may withdraw consent at any time and lodge a complaint with your local data-protection authority. To exercise any right — including access/export and erasure — email privacy@bigapp.io from the address on your account.
9. International transfers
Some sub-processors (e.g. our AI provider) may process data outside the European Economic Area. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Cookies
We use only essential, first-party cookies required to keep you signed in and to secure the Service. We do not use advertising or third-party tracking cookies.
11. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy from time to time; we will post the new version here and update the "Last updated" date above.
13. Contact
Jan Adamski (NIP PL5342201833), Poland
Email: privacy@bigapp.io
Based Training is an independent product and is not affiliated with, endorsed by, or sponsored by Strava, Wahoo Fitness, or Garmin. All trademarks are the property of their respective owners.