Privacy Policy
Endyr.AI LLC ("Endyr," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered coaching platform, mobile applications, websites, and related services (collectively, the "Services").
By using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Services.
1. Information We Collect
1.1 Information You Provide Directly
- Account registration information: name, email address, phone number, mailing address, date of birth, sex, and password
- Athlete profile data: height, weight, fitness goals, training history, and sport preferences
- Payment information: processed securely through third-party payment processors; Endyr does not store full card details
- Communications: messages, support requests, and feedback you submit to us
- Coach or affiliate organization details (Affiliate tier users)
1.2 Health and Fitness Data
To deliver personalized coaching, Endyr collects sensitive health and performance data, including:
- Wearable device data: heart rate, heart rate variability (HRV), blood oxygen saturation (SpO2), skin temperature, sleep stages, recovery scores, and activity data
- Workout data: training load, session duration, perceived exertion, and movement metrics
- Nutritional data: meal logs and macro/micronutrient estimates; meal photos are processed and immediately discarded — Endyr does not retain images
- Menstrual cycle data: may be imported via Apple Health, where you authorize it. Used solely to inform training and recovery recommendations
- Travel context (user-provided): If you choose to log a trip, we collect the destination and travel dates you enter, along with your home base location. Destination names are resolved to a time zone and approximate altitude using a third-party geocoding service; no account or identity information is shared with that service. We use this context so coaching and recovery recommendations can account for travel-related factors such as jet lag, sleep disruption, and altitude. Travel information is entered manually by you — Endyr does not access your device's location services or GPS and never requests location permission.
1.3 Data Collected Automatically
- Device identifiers, operating system, app version, and browser type
- Usage data: features accessed, session timestamps, and interaction patterns
- Server-side diagnostic logs
1.4 Data From Third-Party Integrations
If you connect a third-party wearable device or health platform, we receive data from those services subject to your authorization. We receive only the data types you explicitly authorize. Current integrations include WHOOP, Oura, and Eight Sleep (via authorized account connections) and Apple Health (iOS, read-only).
2. How We Use Your Information
We use your information to:
- Provide and personalize AI coaching, training recommendations, and recovery guidance
- Power our proprietary fitness algorithm, including discipline-agnostic capacity weighting and automated backfill analysis for new athletes
- Deliver readiness scores, strain assessments, sleep quality reports, and longitudinal performance tracking
- Process payments and manage your subscription tier
- Communicate with you about your account, updates, and service changes
- Improve and develop the Services through aggregate, de-identified analytics
- Comply with legal obligations and enforce our Terms of Service
- Provide customer support
Endyr does not use your health data to train general-purpose AI models that are shared with or sold to third parties.
To generate coaching analysis, readiness assessments, and recommendations, Endyr uses a third-party artificial intelligence provider that processes your data on our behalf. Details of this processing and the provider's data practices are described in Section 3.2 below.
3. How We Share Your Information
3.1 With Coaches and Coaching Organizations
If you connect with a coach on the platform — independently or through a coaching organization — your coach may access your performance data as configured in the platform, solely to provide coaching services. If your coach belongs to a coaching organization, that organization's administrators may also have access as configured. You may disable coach access to your performance data at any time through your account settings; while disabled, your performance data is not visible to any coach or coaching organization. Endyr maintains a competitive intelligence firewall — your performance data is not visible to, or shared with, other affiliated organizations.
3.2 Service Providers
We share data with trusted third-party vendors who assist in operating the Services, including cloud hosting providers, payment processors, and wearable data aggregators. These vendors are contractually obligated to protect your data and use it only for the services they provide to Endyr.
Artificial intelligence processing. A core function of the Services is AI-generated coaching analysis. To produce your readiness assessments, training recommendations, and other coaching outputs, Endyr transmits certain athlete data — including training and recovery metrics derived from your wearable and health data — to our third-party AI provider, Anthropic, PBC, which processes that data on Endyr's behalf to generate those outputs. Under our commercial agreement with Anthropic:
- Your data is not used to train Anthropic's AI models or any other AI models;
- Your data is not sold and is not used for advertising;
- Your data is retained by Anthropic only for a limited period (currently up to 30 days) for security and abuse-monitoring purposes and is then deleted, except where a longer period is required by law or to investigate suspected misuse.
Athletes provide explicit consent to this AI processing before any data is shared with our AI provider; this consent is recorded as a versioned consent event. You may withdraw consent as described in Section 5. Because AI analysis is a core function of the Services, withdrawing consent may limit or end your ability to use the Services.
We maintain a current list of the third-party subprocessors that handle personal data, available at https://endyr.ai/subprocessors.html or upon request.
Nutrition analysis. When you log a meal by photo, text description, or barcode, Endyr transmits that input to Passio Inc. ("Passio Nutrition-AI") to identify foods and estimate their nutritional composition. Free-text meal descriptions, and photos where needed, are also processed by our AI provider (Anthropic, described above) to interpret your input. These providers act as Endyr's subprocessors and process the input solely to return the nutritional estimate; they do not use it for their own purposes. Meal photos are not retained by Endyr — they are analyzed in real time and discarded, with only the resulting estimates saved to your log (see Section 4.1).
3.3 Legal Requirements
We may disclose your information when required by law, court order, or government authority, or when we believe disclosure is necessary to protect the rights, property, or safety of Endyr, our users, or the public.
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or in-app notice if such a transfer occurs and your data will remain subject to this Privacy Policy.
3.5 With Your Consent
We will share your information with other parties when you have given explicit consent, such as opting into research studies or community features.
We do not sell your personal information to third parties for advertising or marketing purposes.
4. Data Retention, Export, and Deletion
4.1 Retention During Active Use
We retain your personal data for as long as your account is active or as needed to provide the Services. Specific retention practices:
- Active account data is retained for the duration of your account
- Meal photos are processed in real time and immediately deleted — no photo is ever stored on Endyr servers
- Wearable backfill imports are retained as processed metric data only; raw export files are not stored
- De-identified, aggregated data derived from your usage may be retained indefinitely for product improvement and cannot be reverse-engineered to identify you
4.2 Data Export
You may request a full export of your personal data at any time through your account settings or by contacting [email protected]. Endyr will deliver your data export within 72 hours of the request. Exports are provided as a structured data package (ZIP archive) containing the following:
- Athlete profile and account information
- Wearable-derived biometric data (heart rate, HRV, SpO2, sleep stages, activity data) as daily CSV files per data type
- Training session logs, perceived exertion entries, and coaching notes
- AI-generated scores and recommendations as delivered to you (readiness scores, recovery scores, training recommendations) — dated log format
- Nutritional logs and meal composition estimates
- Menstrual cycle data, if applicable
- Consent history (timestamped record of consent events)
- Account activity log (subscription history, device connections)
- A README file explaining the contents of each file included in the export
Your data export includes all personal data, health data, and AI-generated scores and recommendations that were delivered to you. It does not include Endyr's proprietary algorithms, scoring methodology, model parameters, or population benchmarks, which constitute Endyr's trade secrets and are protected under applicable law. This exclusion is consistent with your rights under the California Consumer Privacy Act (CCPA), Washington My Health MY Data Act, and other applicable privacy laws, which expressly carve out trade secrets from data access obligations.
4.3 Data Deletion — 30-Day Process
You may request deletion of your personal data at any time through your account settings or by contacting [email protected]. Endyr processes deletion requests as follows:
Step 1 — Export delivery (Days 1–3). If you request deletion together with an export, your data export will be prepared and delivered within 72 hours. The deletion grace window begins upon confirmed export delivery, not upon the initial request.
Step 2 — Grace window (Days 1–7). Deletion is queued but not executed during the first 7 days. You will receive a confirmation email with a clearly visible link to cancel the deletion request. This window protects against accidental deletion and allows time to confirm receipt of your data export. After 7 days, deletion cannot be reversed.
Step 3 — Deletion processing (Days 8–30). Confirmed deletion requests are executed across all Endyr systems within 30 days of the original request, including primary databases, backup systems, wearable sync caches, and analytics pipelines. You will receive a confirmation email when deletion is complete.
4.4 Data Retained After Deletion
The following limited data is retained after a deletion request is fulfilled, with the justification noted:
- Consent audit records: The fact that consent was given and subsequently revoked, including timestamps and document versions — not the content of your health data. Retained for legal defensibility.
- Transaction records: Payment history and invoice metadata, retained for 7 years as required by IRS regulations. All associated health data is stripped; only financial transaction metadata is retained.
- Aggregated, de-identified data: Where your data has already been incorporated into population-level analytics in a form that cannot be reverse-engineered to identify you, that aggregate data is not subject to deletion.
- Security and fraud-prevention records: logs of security-relevant events (such as suspicious sign-in activity or suspected misuse), including the associated IP address and device information — never health data. Retained to detect and prevent fraud, abuse, and unauthorized access, and for legal defensibility.
5. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to the retention exceptions in Section 4.4
- Portability: Request export of your data in a machine-readable format per Section 4.2
- Objection / Restriction: Object to or request restriction of certain processing activities
- Withdrawal of Consent: Where processing is based on consent, withdraw it at any time
- Sensitive Data Opt-Out (CPRA): You may request to limit the use of your sensitive personal information, including health and biometric data, to purposes strictly necessary to provide the Services
To exercise these rights, contact us at [email protected]. We will respond to verified requests within 30 days.
You may also manage connected device integrations, notification preferences, and data sharing settings directly in the Endyr app settings.
6. Data Security
Endyr implements industry-standard technical and organizational security measures to protect your data, including:
- Encryption of data in transit (TLS) and at rest
- Role-based access controls limiting internal access to personal data
- Regular security assessments and monitoring
- Incident response procedures
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
7. Children's Privacy
The Services are not directed to individuals under the age of 18 without verified parental consent. We do not knowingly collect personal information from children under 13. Athletes between 13 and 17 may access the Services only through Endyr's minor athlete onboarding process, which requires documented parental or legal guardian consent. If we become aware that a minor has provided personal data without required parental consent, we will delete that information promptly. If you believe a minor has submitted data to us without proper consent, please contact [email protected].
8. Third-Party Links and Integrations
The Services may link to or integrate with third-party websites, applications, or devices (e.g. WHOOP, Oura, Eight Sleep, Apple Health). This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party service you connect to Endyr.
9. International Data Transfers
Endyr is based in the United States. If you are accessing the Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Services, you consent to such transfers. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy wherever it is processed.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of the sale or sharing of personal information. Your health and biometric data constitutes sensitive personal information under CPRA, entitling you to request that Endyr limit its use to purposes necessary to provide the Services. Endyr does not sell personal information. To submit a California rights request, contact [email protected] or visit https://www.endyr.ai/privacy.html.
11. Health Data — Additional Disclosures
Endyr collects health and fitness data to provide coaching and performance services. This data is not shared with health insurers, employers, or marketers. Endyr does not use your health data to make decisions that produce legal or similarly significant effects on you. Where applicable law requires it, we comply with applicable health data regulations and will execute appropriate data processing agreements upon request.
Data obtained from Apple HealthKit is used solely to provide the Services, is never used for advertising or marketing, and is never sold or shared with data brokers.
As described in Section 3.2, Endyr uses a third-party AI provider to generate coaching analysis from your health data. This provider processes your data solely to deliver the Services to Endyr, does not use it to train AI models, and does not sell it. The list of third parties to whom your consumer health data is disclosed — which Washington residents have the right to request — includes this AI processing provider.
Washington State residents have additional rights under the Washington My Health MY Data Act, including the right to confirm whether Endyr collects your consumer health data, to access that data, to withdraw consent, to request deletion, and to obtain a list of third parties to whom your data has been disclosed. To exercise these rights, contact [email protected].
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or in-app notification at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
13. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
Endyr.AI LLC
Email: [email protected]
Website: endyr.ai
Mailing Address: PO Box 185, Plainfield, IN 46168