Quantified Self   10.14.0Home
Compare Files
Membership
Login
Preferences

Privacy Policy

How Quantified Self handles your data, connected services, processors, security, and privacy rights.

Connected Services, AI & Third-Party ProcessingDisclosures for connected fitness services, user-authorized MCP clients, the built-in Assistant, infrastructure, payments, and analytics.
Training workout delivery: Manual plans and standalone workouts are stored beneath your account. Provider workout delivery is not enabled yet. When available and explicitly authorized, it sends the workout recipe, title and scheduled date in your saved delivery time zone to the selected connected provider. Quantified Self retains delivery preferences, compatibility approvals and private operation/artifact records so edits, retries and removal can be reconciled safely. Use Stop sync before disconnecting to request eligible future-copy removal. Explicit disconnect invalidates delivery consent but may leave provider-held copies; Pro expiry preserves preferences and copies while pausing changes. Account deletion fences new delivery and recursively removes local delivery records and jobs, but cannot guarantee removal of copies already held by a provider after access is revoked.
Private Timeline notes: Notes you create about sickness, injury, vacation, travel, stress, or other context are stored beneath your account with calendar dates, the captured time zone, and revision timestamps. They appear only in your authenticated Health, Sleep, and Training views and do not change measurements or scores. Text is not sent to providers, analytics or public shares. Full titles/details, including chart-hidden notes, may be sent to an MCP client only with the separate Timeline notes grant, or to Gemini only when you enable Timeline notes for the active Assistant chat. This may contain sensitive health or personal information. Chart visibility is display-only; revocation cannot erase copies already received by an external client. Deleting a note removes its content and retains only a content-free deletion receipt to prevent delayed retries from recreating it. Disconnecting a service retains notes; account deletion recursively removes notes and receipts.
What this section covers: This page explains what connected-service data Quantified Self collects, how it is used inside the product, what may be stored for exports, reprocessing, and sync tools, and which third parties process that data.
Storage location: Imported provider data, saved route metadata, source-file references, and related processing metadata are stored in Quantified Self infrastructure on Google Cloud in the EU region.
User-initiated sharing: When you use features such as history import, FIT/GPX uploads, sending routes, or activity sync to Suunto, Wahoo, or COROS, Quantified Self must send the activity, route, or related data needed by the destination provider.
Provider echo protection: Before sending an activity to a connected provider, Quantified Self stores server-only hashes of the exact file and selected semantic FIT fields, plus destination routing metadata. These records do not contain the activity file, are used to prevent a provider-returned copy from creating another event or fan-out, and expire after about 120 days.
Manual Health measurements: You can add, edit, and delete Weight, VO₂ max, body fat, blood pressure, muscle mass, body water percentage, bone mass, and blood oxygen (SpO₂) measurements in the authenticated Health workspace. Blood pressure stores systolic and diastolic together with any pulse you choose to include; editing or deleting it affects that complete measurement. They are stored in your owner-scoped Health history with Quantified Self as the source, the observed time and timezone offset, and—for VO₂ max—the context and method you select. Manual values remain separate from provider and workout series. Account deletion removes them with the rest of your Health history.
Workout context in Health: When you select Weight or VO₂ max in the authenticated Health workspace, Quantified Self can read those values on demand from workouts already imported into your account. Workout Weight is labelled as profile context rather than a weigh-in and appears only when the active provider-filtered view has no provider or manual Health Weight; it is never plotted as a weigh-in. Workout VO₂ max remains separate by provider, local account label, and discipline and is not merged with provider Health or manual values. These reads do not copy workout values into Health storage, and their bounded response excludes workout identifiers, names, locations, provider account IDs, and raw creator details.
AI scope: Connected-service data is not forwarded wholesale to AI providers. The built-in Assistant sends Gemini the message you submit, the browser's IANA timezone for local-day context, bounded recent conversation context, and bounded validated results selected through Quantified Self's read-only MCP tools. The Assistant is coordinate-free by default. If you explicitly start a fresh chat with Precise activity locations enabled, selected activity-tool results may also send Gemini exact activity start/end and MTB jump coordinates, bounded activity-chart breadcrumbs, plus nearby activity results during that chat. Changing this setting starts another fresh chat, and New chat returns it to off. Gemini may select only a server-advertised visual source and safe series keys; Quantified Self deterministically constructs any stored chart values, map coordinates, labels, and renderer settings from the validated result. Coordinate-free saved-route summaries may be selected for route questions; their route names can contain user- or provider-assigned place information. Direct in-app URLs are withheld from Gemini, and an answer that repeats an opaque reference or cursor is rejected. Saved-route bounds, route geometry, waypoints, write capabilities, dashboard settings, and original uploaded source files remain unavailable to the Assistant.

Garmin Data

Garmin activity, Sleep, Health, route delivery, and provider sync workflows.

Collected from Garmin: When you connect Garmin, Quantified Self can import Garmin activities, request activity, Sleep, and Health history, receive Garmin Sleep updates, and import available Daily, Stress Details, HRV, User Metrics, Body Composition, Pulse Ox, All-day Respiration, Blood Pressure, Skin Temperature, and Health Snapshot summaries when Garmin grants Health Export permission.
Stored and used in Quantified Self: Imported Garmin data is used for dashboard, event analysis, Sleep views, the authenticated Health workspace, and related summaries. Wellness measurements are stored as normalized source-attributed Health records and bounded sample chunks, separate from workout metrics and Sleep sessions; missing values remain missing and Garmin Body Battery remains provider-specific. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. Short-lived Garmin pull callback URLs are retained only on retryable live queue work, removed after every terminal queue outcome, and excluded from failed-job copies. Quantified Self may retain original activity files or equivalent source-file metadata when downloads, exports, reprocessing, or syncing past activities require them.
Disconnect and deletion: Disconnecting Garmin stops future activity, Sleep, and Health imports but retains data already imported into Quantified Self. Deleting your Quantified Self account removes the Garmin connection, imported user-scoped Sleep and Health records, sample chunks, sync state, and associated operational queue work.
Shared with Garmin: You can send a saved route or explicitly select a GPX/FIT route file in Garmin Services. Quantified Self parses the selected route and creates a Garmin Connect course. Direct selected-file delivery does not create or retain a Quantified Self route or Garmin delivery metadata.
Shared with connected destinations from Garmin: If you turn on an automatic Garmin activity route or choose to sync past activities, Quantified Self uses the original activity file already saved with the event to send it to the selected supported destination: Suunto, Wahoo, or COROS. Each direction is opt-in and a date-range backfill does not enable future delivery.

Suunto Data

Suunto activity, sleep, 24/7 Health, route import, FIT upload, and activity or route delivery workflows.

Collected from Suunto: When you connect Suunto, Quantified Self can import Suunto activities and history, sync recent sleep data, import sleep history, and automatically import new or updated Suunto routes into your saved Routes list. Connected accounts can also import available 24/7 Activity, daily-statistics, and Recovery measurements such as heart rate, HRV, SpO2, altitude, steps, energy, Body Energy Balance, and StressState.
Stored and used in Quantified Self: Imported Suunto data is used for event analysis, route detail views, dashboard summaries, sleep views, the authenticated Health workspace, and saved route management. 24/7 values are stored as normalized source-attributed Health records, separate from workout FIT metrics and Sleep sessions; raw Health webhook samples are not stored. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. Connection metadata and processing metadata are also stored so reconnect, dedupe, bounded refetch, and refresh workflows can work reliably.
Disconnect and deletion: Disconnecting Suunto stops future activity, Sleep, route, and Health imports but retains data already imported into Quantified Self. Deleting your Quantified Self account removes the Suunto connection, imported user-scoped Sleep and Health records, and associated top-level operational queue work.
Shared back to Suunto: When you upload FIT activities or send a saved or selected GPX/FIT route to Suunto, Quantified Self sends the file or generated GPX route needed for that upload. Suunto receives GPX routes, so selected FIT routes and saved routes are converted to a compatible GPX route in memory; saved routes use the Quantified Self route name. Direct selected-file route delivery does not create or retain a Quantified Self route.
Shared from Suunto to connected destinations: You can opt in to automatic activity delivery or select a past stored date range for Wahoo or COROS. You can separately opt in to new and updated saved Suunto route delivery, or send existing saved routes, to Garmin Connect or Wahoo. Eligible connected Pro users can also select COROS. Quantified Self sends only the retained activity file or saved-route representation required by the selected destination.
Account-scope note: Routes imported from one Suunto account are blocked from being sent back to that same account, but can still be sent to a different connected Suunto account when that workflow is available to you.

COROS Data

COROS activity, daily Health and sleep, activity sync, FIT upload, and GPX/FIT or saved-route delivery workflows.

Collected from COROS: When you connect COROS, Quantified Self can import recent COROS history, sync sleep summaries, and store available daily Health metrics: steps, COROS's provider calorie value, resting and sleep heart rate, overnight HRV, and detailed HRV samples with an interval mean heart rate when COROS supplies it. Missing or unsupported values remain unavailable rather than becoming zero.
Stored and used in Quantified Self: Imported COROS activities and normalized Sleep sessions support dashboard metrics, event analysis, the authenticated Health workspace, and provider-specific history tooling. Daily measurements are also stored as source-attributed Health records for the unified Health model. Aggregate sleep duration, resting or sleep heart rate, and overnight HRV remain in the Sleep session and are referenced from Health instead of copied. Detailed HRV samples from new COROS responses are stored in bounded server-written Health sample records and are not duplicated in Sleep; recoverable legacy Sleep copies can remain until the guarded migration completes. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. COROS's calorie field remains provider-native because the API does not define a safe canonical conversion. Quantified Self may retain original activity files or equivalent source-file metadata when later downloads, exports, reprocessing, or sync tools depend on them. One provider account identifier is stored as the active COROS connection so imports and deliveries do not silently switch between accounts.
Disconnect and deletion: Disconnecting COROS stops future daily Health and sleep imports but retains already imported records. Deleting your Quantified Self account recursively removes the COROS connection, Sleep sessions, Health records and sample chunks, and imported data under your user record; account-deletion cleanup also removes associated top-level operational queues.
Shared back to COROS: You can send a selected FIT activity, automatically send new Garmin/Suunto/Wahoo FIT activities, or send a selected past date range already stored in Quantified Self. Eligible connected Pro users can also send a selected GPX/FIT route, a saved route from Routes, or opt in to new/updated or existing saved Suunto route delivery. Selected route files are parsed and converted to GPX in memory and do not create a Quantified Self route; saved routes retain provider delivery metadata for deduplication and status.
Shared with Suunto or Wahoo from COROS: If you turn on a supported automatic COROS activity route or choose to sync past activities, Quantified Self uses the original activity file already saved with the imported event to send it to the selected destination. Each automatic direction is off by default.
Echo protection: Activity delivery writes short-lived, server-only exact-file and semantic FIT fingerprints before sending. If COROS later returns a matching activity, Quantified Self acknowledges the echo without storing a duplicate event or starting another provider fan-out. The fingerprint records contain hashes and routing metadata rather than the source file and expire after about 120 days.

Wahoo Data

Wahoo OAuth, webhook, FIT activity and GPX/FIT course/route delivery, and history-import workflows.

Collected from Wahoo: When you connect Wahoo, Quantified Self can receive completed workout-summary webhooks and request Wahoo workout history. Only workouts with an available FIT file are imported, and records identified by Wahoo as originating from third-party fitness applications are skipped.
Stored and used in Quantified Self: Imported Wahoo FIT activities, source identifiers, summary revision metadata, and original activity files are used for event analysis, dashboard metrics, exports, deduplication, and reprocessing. Wahoo does not currently supply daily wellness records for Health. If an imported Wahoo workout contains Weight profile context or an activity-level VO₂ max estimate, the authenticated Health workspace can read that value on demand under the workout-context boundary above; it is not stored as a Health record. OAuth credentials are stored server-side and are not readable by the browser.
Disconnect and retention: Disconnecting Wahoo revokes future provider access and stops new imports. Activities already imported into Quantified Self are retained until you delete those activities or delete your account. Account deletion removes Wahoo tokens, queue state, and imported account data under the normal deletion workflow.
Shared with Wahoo: You can explicitly send a selected FIT activity file or GPX/FIT course/route file directly to Wahoo, turn on/send a date range for Garmin, COROS, or Suunto activities already stored in Quantified Self, or opt in to automatic/backfill delivery of Suunto routes already saved in Quantified Self. Quantified Self converts selected GPX routes to FIT in memory before sending them to Wahoo, and converts saved Suunto routes to FIT in memory for the same destination. Saved-route delivery uses an opaque stable key so an updated saved route updates the same Wahoo route. Direct Wahoo activity delivery does not create or retain a Quantified Self activity; direct course/route delivery does not create or retain a Quantified Self route.
Shared from Wahoo: You can turn on or backfill Wahoo-to-Suunto or Wahoo-to-COROS activity sync. Quantified Self sends the retained original FIT file from a Wahoo-imported event only after you enable or start that route.
Outbound boundaries: Suunto-to-Wahoo saved-route delivery is a separate opt-in route workflow in Suunto Services; direct GPX/FIT course/route delivery is a separate Wahoo-only upload. Plans, sleep, and other non-activity data are not sent between Wahoo and another provider. Existing Wahoo connections may need to be reconnected to grant workout and route access for delivery to Wahoo.

MCP Client Access

Read-only metric, body-measurement, activity-detail, sleep, saved-route, full private Timeline note text, and separately approved location access granted to an MCP client by the account owner.

Personal HRV range: When both Health metrics and Sleep summaries are approved, an external client can request source-separated nightly HRV classifications, rolling baseline boundaries and recent averages calculated with the Health chart model. The read includes up to 60 extra days of baseline history and requires complete bounded input; raw samples and account or device identities are not returned. This does not grant access to Training, notes or additional health families, create stored scores, or provide a medical assessment.
Health metrics permission: This separate grant covers recorded all-day heart rate, HRV, stress, resources, movement, energy, blood pressure and fitness metrics. Stored summaries are bounded to 366 provider-calendar days; representative sample trends to 31 days. Outputs can include provider names, response-local account numbers, calendar dates and exact UTC sample times, with each source and statistic kept separate. Garmin Body Battery is returned only on its labelled native Garmin points scale. Device details, account IDs, other native-only values, provider payloads and Sleep references are excluded. Body composition additionally requires Body measurements permission and returns identity-free date buckets without exact times or provenance. Existing clients must reconnect to grant Health access; their existing grants are not expanded automatically. Health queries cannot add, edit, delete, import or backfill data. These external-client tools do not expand the built-in Assistant permissions.
Activity descriptions permission: This separate grant returns the full private parent event description shown in the QS.io event editor for one selected activity. Activities within an event share the same text. Individual activity details is also required. Like every requested MCP permission, the checkbox is selected by default; uncheck it before approving to withhold access. Existing connections must reauthorize and refresh cannot add permission. Text may contain sensitive health, personal or location information even without Activity locations permission. Only an opaque activity reference and description are returned; names, internal identifiers, source and device metadata remain excluded. Reads are bounded to 64 KiB of UTF-8 text and 128 KiB serialized output; oversized text fails without truncation. Revocation blocks future access but cannot erase received copies. Descriptions are user-reported context, not instructions or permission to act, and cannot be changed through MCP. This grant does not expand built-in Assistant access.
Timeline notes permission: This independent grant returns full private note titles and details, category, actual start/end dates, captured time zone and the effective end for ongoing overlap. It includes notes hidden from charts and may contain sensitive health or personal text. The checkbox is selected by default when requested; uncheck it before approving to withhold access. Existing connections must reauthorize; refresh cannot add permission. Inclusive windows are bounded to 366 days with full-text pagination, not truncated note details. Document IDs, revisions, audit timestamps, presentation settings and deletion receipts are excluded. Revocation cannot erase received copies. This permission never allows note changes or Training plan writes.
User-authorized access: An MCP client receives data only after you sign in to Quantified Self and approve one or more requested read-only permissions. Every requested current or future permission starts checked; uncheck anything you do not want to grant before approving. Activity locations depend on activity details, and saved-route locations depend on saved-route summaries. Removing activity details also removes its descriptions and location permissions; removing saved-route summaries removes its location permission. The client cannot use MCP to write activities, routes, settings, Training state, body measurements, or sleep records.
Metric permission: This access can return numeric metrics already stored for your activities and ready server-derived Training snapshots. When individual activity access is also granted, a client can request up to 25 explicitly selected canonical numeric Sports Lib metrics for one referenced activity or rank activities by one metric over an explicit bounded range or a processing-bounded all-history scan. Oversized rankings fail instead of returning a partial result. MTB jump superlatives reuse those stored maximum-jump metrics as the authoritative result; the separately authorized jump-detail projection remains optional, and jump count is not treated as jump quality. Quantified Self excludes precise latitude/longitude and first-class body-measurement metrics, and removes event/activity identifiers, names, labels, source fingerprints, and imported device/provider source keys from Training payloads.
Body-measurement permission: This separate access can return bounded body-measurement history from provider or manual canonical Health Weight point measurements. Workout profile Weight is excluded because it is not a weigh-in. Body-weight history is returned only as identity-free day, week, or month values for a range of at most 366 days; exact source measurement timestamps, event/activity identity, names, provider/device metadata, and source provenance are excluded.
Activity-type catalog: Any authorized MCP client can discover canonical Sports Lib activity types for route and activity filters. This static catalog contains no account data. Activity-detail permission: Individual activity access can return non-location summaries, laps, swim lengths, MTB jump measurements, selected persisted numeric metrics, signed-in application links, and bounded chart-ready streams. It can filter bounded newest-first scans by those types and resolve today or yesterday only with an explicit IANA timezone. A chart request temporarily reads and selectively parses an existing original FIT, GPX, TCX, Suunto JSON/SML, or gzip file, downsamples the complete activity, discards parsed objects, and does not create a reparse, backfill, cache, or additional activity record. Historical charts depend on the original source remaining available and within processing limits.
Detailed activity samples: The existing Individual activity details grant also allows bounded pages of selected numeric activity samples on an elapsed-second axis, without chart downsampling. Missing readings remain null. This adds no OAuth permission and does not expose coordinates, absolute sample times, original files or provider/device metadata. Up to four supported metrics can be selected from existing original files. Only the selected numeric arrays may be retained in bounded server memory for up to two minutes to reuse parsing across pages; no persistent sample store, activity copy, reparse or backfill is created. Access, activity ownership and the original-file revision are rechecked for every page. Revoking access blocks subsequent reads but cannot erase copies already received by the client. This detailed-sample tool is not exposed to the built-in Assistant.
Activity-location permission: This dependent permission can add exact activity start/end and MTB jump coordinates, enable nearby-activity searches, and return a bounded breadcrumb trace with an activity chart. Without it, activity summaries and jump measurements remain available with coordinates omitted, and explicit location requests are rejected before location or source work begins. Exact activity locations can reveal a home, workplace, frequent trailhead, or other sensitive place.
Sleep permission: Sleep access can return normalized session summaries, day/week/month aggregates, bounded discovery of recorded safe aggregate vital types, and a one-call sleep trend that combines coverage with duration, score, stages, HRV, heart-rate, blood-oxygen, and respiration values for a requested period. Raw samples remain excluded, and recorded values cannot diagnose illness. When Activity and Training metrics are also approved, the client can request the same live UTC-day Readiness used by Dashboard Today. That result combines current Form/ramp with the latest eligible sleep score and can return safe aggregate latest HRV and sleep-heart-rate values, same-provider baseline medians, ratios, evidence counts, and explicit missing or insufficient-baseline states. The requested IANA timezone supplies local-day context; it does not change the UTC scoring boundary. The preferred daily report returns the latest completed non-nap sleep with recorded average/overnight HRV and average/minimum sleep heart rate, a same-provider duration comparison, live Readiness, and current-versus-usual equivalent 28-day Training totals and Running/Cycling/Swimming mix. The older compact briefing remains physiology-free for compatibility. These projections exclude provider identity, provider user and session identifiers, provider-specific payloads, raw sleep-stage intervals, score components, raw HRV samples, SpO2 and respiration samples, locations, activities, body measurements, workout plans, and medical advice.
Saved-route summary permission: Saved-route access can return route names, activity types, bounded metrics, route/waypoint/point counts, import/update times, and signed-in application links. It can filter a bounded newest-first scan by canonical Sports Lib activity type or a case-insensitive part of the route name. It omits exact bounds, preview geometry, and waypoint locations.
Saved-route location permission: This dependent permission can add exact geographic bounds, simplified polyline preview geometry and segment endpoints, nearby-route search, and waypoint coordinates, altitude, and distance. Existing clients retain non-location route summaries but must reconnect and approve this permission to regain coordinate-bearing route tools. Activity and saved-route location permissions are independent.
Projection exclusions: Original files, unbounded recordings, unrequested streams, separate internal identifiers, source keys, Storage paths, parser extensions, device identities, waypoint names/comments, links, and delivery metadata are not returned. Activity charts exclude full-resolution recordings and absolute per-sample timestamps. Separately approved Health trends can include UTC sample times and provider names with response-local account numbers; they never include account keys, device details, or provider payloads.
Place-name resolution: Nearby MCP searches can use direct latitude/longitude or a place name. Direct-coordinate searches are processed within Quantified Self. For a place-name search, Quantified Self sends only the location text to Mapbox for forward geocoding; activity data, route data, account identifiers, and unrelated client prompts are not sent to Mapbox for that lookup.
Credentials and retention: MCP bearer and refresh credentials are opaque, stored server-side only as hashes, expire automatically, and are bound to your account and the MCP resource. Approving a request creates pending authorization metadata, but a new connection becomes active and appears in Connections only after the client successfully exchanges its authorization code. Reauthorizing the same exact verified client identity leaves its current grant usable until that exchange succeeds, then replaces the previous permissions and credentials rather than creating another logical connection. Failed or abandoned reauthorization does not replace the current grant, and authorization codes expire automatically. Authorization metadata and active connection metadata are retained so the connection can operate and be audited.
Control and destination: Review or revoke MCP clients under Connections -> MCP. A client can use the standard server-to-server token-revocation endpoint, but it may not notify Quantified Self when removed or uninstalled. Disconnect in Connections remains the authoritative control and immediately invalidates the current grant and any older duplicate records for that exact verified client without affecting other MCP clients. Account deletion removes MCP connection and authorization state. A client may retain data it already received according to its own privacy and retention practices, so authorize only clients you trust.

AI & Third-Party Processing

Infrastructure, billing, analytics, maps, and the current AI provider.

Google Cloud: Quantified Self stores application data, connected-service metadata, and processing state on Google Cloud in the EU region.
Optional Assistant note context: Timeline notes access is off by default. Enabling or disabling it starts a fresh server-owned chat and preserves the independently selected location permission. Changing location access likewise preserves the notes choice; New chat resets both. When relevant, Gemini may receive full private titles and details, including notes hidden from charts. Notes are user-reported context, not verified diagnoses, causal proof, model instructions or authorization to change plans. Raw tool responses are not stored; answers may quote relevant details, and compact evidence identifies note context and dates under the existing conversation retention policy.
Stripe: Stripe processes subscription and billing data needed to charge, renew, and manage your plan.
Google Analytics: If you consent to analytics cookies, Google Analytics receives anonymized usage analytics used to improve the service. Analytics is optional and can be withdrawn in Settings.
Mapbox: When an authorized MCP client searches by place name, Mapbox is used to resolve the supplied place text and geographic scope. Direct-coordinate MCP searches do not call Mapbox. The built-in Assistant can make the same bounded place-name lookup only after you explicitly enable Precise activity locations for that chat; Quantified Self sends Mapbox only the supplied location text, not the conversation, activity data, or account identity. Separately, when you open an Assistant map, it uses the map style saved specifically for Assistant maps and Mapbox receives the displayed geographic tile area needed to render that map, including when the underlying location came from a direct coordinate rather than place-name geocoding. Its saved-route access remains limited to coordinate-free summaries.
Google GenAI / Gemini: The built-in Assistant uses Google's Gemini models through Google GenAI. Quantified Self sends the message you submit, the browser's IANA timezone for local-day context, at most the latest six completed conversation turns, and bounded validated results from the read-only tools chosen for the question. Results are coordinate-free by default. If you explicitly start a fresh chat with Precise activity locations enabled, selected activity-tool results may also send Gemini exact activity start/end and MTB jump coordinates, bounded activity-chart breadcrumbs, and nearby activity results during that chat. Changing the setting starts a fresh chat so coordinate-bearing history does not cross into a coordinate-free conversation; New chat returns the setting to off. Gemini may select only a server-advertised visual source and safe series keys; Quantified Self deterministically constructs any chart values, map coordinates, labels, and renderer settings from the validated result. Coordinate-free saved-route summaries may be selected for route questions, and their route names can contain user- or provider-assigned place information. Direct in-app URLs are withheld from Gemini, and an answer that repeats an opaque reference or cursor is rejected. Original FIT/GPX/TCX/JSON/SML files, saved-route bounds, route geometry, waypoints, write capabilities, and dashboard settings remain unavailable to the Assistant. Text, compact evidence, and any bounded chart or map payload share the same server-owned active conversation. It becomes unavailable about seven days after its latest completed turn or reset; a response already in progress can protect an imminent expiry for at most four extra minutes. Firestore TTL then deletes it asynchronously. New chat clears it immediately; account deletion removes it directly.
No hidden provider forwarding: Connected Garmin, Suunto, COROS, and Wahoo data is only sent to destination providers when you explicitly use the related import, upload, delivery, or sync feature. Wahoo delivery is limited to the explicit FIT activity, GPX/FIT course/route, opt-in Suunto saved-route, and Garmin/COROS/Suunto-to-Wahoo activity workflows described above.
Privacy PolicyData Security & Ownership
Encryption: Your data are stored and held encrypted by Google (Google Cloud).
Control: Profile and activity visibility is managed by platform policy and is not configurable in the app UI.
Default Privacy: Visibility defaults to private and is only seen by your account unless platform policy changes.
No Data Sales: We do not sell your data. Data is sent outside Quantified Self only when needed for a feature you explicitly use or authorize, such as connected-provider delivery, an approved MCP client, or the bounded Assistant context described below.
Legal Basis: We process your data based on: (a) your consent for optional features like analytics, (b) contractual necessity to provide the service you subscribed to, and (c) our legitimate interest in maintaining service security.
Third-Party Processors and Recipients: Your data may be processed by Google Cloud (hosting and storage in the EU region), Stripe (payments), Google Analytics (only with consent), Mapbox (place resolution for authorized MCP place-name searches and explicitly enabled built-in Assistant activity-place searches), Google GenAI / Gemini (the built-in Assistant using the submitted message, browser timezone, bounded recent conversation context, validated read-only results, and—only with the respective per-chat opt-in—precise activity locations or full private Timeline note text), connected fitness services you explicitly use, and MCP clients you explicitly authorize. See Connected Services, AI & Third-Party Processing below for details.
Data AvailabilityBackups & Access
Best Effort: While we employ best endeavors, we don't promise to keep your files and data accessible at all times.
Backups: It's best advised to keep your own private copies of critical data.
Portability: You have the right to request an export of your personal data stored on our platform.
Retention: We retain your data while your account is active and has a valid subscription. After a 30-day grace period, plan limits and feature restrictions apply. Existing activities are not automatically deleted due to downgrade alone.
GDPR & Your RightsFor EU/EEA Users
Under the General Data Protection Regulation (GDPR), you have the following rights:
  • Right of Access: You can request a copy of your personal data.
  • Right to Rectification: You can correct inaccurate personal data in your profile settings.
  • Right to Erasure: You can request deletion of your account and all associated data ("Right to be Forgotten").
  • Right to Restrict Processing: You can ask us to limit how we use your data.
  • Right to Data Portability: You can request your data in a structured, machine-readable format.
  • Right to Object: You can object to data processing based on legitimate interests.
  • Right to Withdraw Consent: You can withdraw consent at any time for optional processing (e.g., analytics).

Data Controller: Dimitrios Kanellopoulos, operating Quantified Self
Address: Kaloudi 15
45500 Ioannina
Greece
Contact: privacy@quantified-self.io
Data Location: European Union (Google Cloud EU region)
For privacy inquiries or to exercise your rights, contact us at the email above.

Supervisory Authority: If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. For users in Greece, this is the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.

Cookies & TrackingAnalytics
Google Analytics: With your consent, we use Google Analytics cookies to collect anonymized usage data (e.g., visits by country, active users). Analytics cookies are only activated after you provide consent.
Purpose: This data helps us improve the service and is strictly for internal use. We do not use it for advertising or profiling.
No 3rd Party Access: We don't allow Google or other 3rd parties to access this data for their own purposes.
Essential Cookies: Session cookies used to keep you logged in are strictly necessary for the service to function and do not require consent.
Withdraw Consent: You can withdraw your analytics consent at any time in your account settings.
Marketing & UpdatesOptional
Promotional Emails: Receive occasional emails about new features, promotions, and special offers.
Unsubscribe Anytime: You can unsubscribe at any time from your account settings.
No Spam: We respect your inbox and only send relevant updates about the service.