T.E.A.M.
Executive Athlete
Back
Last updated · 29 August 2026

Privacy, in plain terms.

Read-only access to the sources you connect, encrypted credentials, data never sold, never processed by external AI, never used to train models. You can disconnect any source whenever you want.

1. Controller and contact

Dante Larroy. For enquiries and to exercise your rights: privacy@executiveathletesmethod.com.

2. Data we process

Account and identity; the metrics you authorise from Withings, Oura, WHOOP and Garmin; synchronisation status; consent records; audit logs and the reports your coach reviews. OAuth tokens are stored encrypted and kept separate from the metrics.

3. Purpose and legal basis

We use your data to import your history, show trends, and compute deterministic briefs that your coach reads before each review. We process health data only with your explicit consent (GDPR art. 6(1)(a) and 9(2)(a)), and operational data as necessary to provide the service (art. 6(1)(b)).

4. Artificial intelligence

We do not share your data with external artificial intelligence providers, and we do not allow any third-party AI service to process it. This expressly includes data obtained through the APIs of the device manufacturers you connect — among them Garmin, Withings, Oura and WHOOP — which is never sent to any external AI or data-processing service.

Nor is it used to train models. The reports and analysis you see are computed deterministically by our own platform and written by your coach: there is no automated generation of text about your data. No automated decisions with legal effects are made, and no medical diagnosis is offered.

5. Service providers

Supabase hosts authentication and PostgreSQL; Vercel may host the frontend. Withings, Oura, WHOOP and Garmin receive the OAuth authorisation you initiate and act under their own policies. No other third party has access to your metrics.

Separately, if you book an introductory call from our website, Cal.com handles that scheduling and receives only what you type into the booking form — your name, your email, and any notes. It never receives device or health data.

6. Security and retention

HTTPS in transit, encryption at rest, tokens under AES‑256‑GCM, role-based access control, row-level security, audit logging and least privilege. We retain data for the duration of the service relationship and any applicable legal period; a deletion request stops further synchronisation and starts the erasure process.

7. Your rights

You may request access, rectification, portability, restriction, objection or erasure, and withdraw consent by disconnecting a source. You may also lodge a complaint with the competent data protection authority.

8. Minors and changes

The service is for adults aged 18 and over only. Material changes will be communicated inside the platform before they take effect.