EnduraX™ is in early access.

Privacy Policy

Effective date: April 18, 2026 · Last updated: September 2, 2026

Important: EnduraX collects sensitive health data including menstrual cycle information, biometric data, and health-derived readiness scores. Your computed scores — and, if you use the optional Fueling module, the meal descriptions and photos you log — may be processed by a third-party AI service (Anthropic) to generate suggestions and estimates (see Section 4.3). Please read this policy carefully.

1. Who we are

EnduraX ("we", "us", "our") operates the EnduraX DARS application at enduraxapp.com. DARS is a daily athlete readiness and coordination tool for athletes and the coaches and providers they choose to involve. We are headquartered in New York, USA.

EnduraX is not a HIPAA-covered entity. DARS data is not protected health information (PHI) under HIPAA. EnduraX is a wellness and performance tracking tool, not a medical device or healthcare provider.

2. What data we collect

We collect the following categories of data:

  • Account data: Your email address and password (stored securely via Supabase Auth).
  • Profile data: Biological sex, date of birth, training level, primary sport, display name, height, and body weight — used to personalise your readiness score.
  • Check-in data: Daily self-reported inputs including sleep hours, sleep quality, fatigue, mood, soreness, stress, training duration, intensity, and fueling scores.
  • Menstrual cycle and period data: Period start dates, cycle length, and cycle phase — used to personalise your readiness score and training guidance. This data is collected only with your explicit consent via an opt-in toggle during onboarding. You can enable or disable cycle tracking at any time. This is sensitive health data treated with heightened protection (see Section 5).
  • Supplement and recovery modifier flags: Optional disclosures about supplement use or recovery medications that affect biometric interpretation. Entirely user-initiated.
  • Wearable and connected-device data: If you connect an Oura Ring, we retrieve HRV, resting heart rate, sleep data, and SpO2. If you connect Strava, we retrieve training activity data. If you connect Whoop, we retrieve recovery score, HRV, resting heart rate, sleep data, strain, and workout data. If you connect a Withings device, we retrieve supported body measurements — body weight, body-fat ratio and fat mass, fat-free mass, muscle mass, bone mass, and hydration. In the iOS app, you can separately allow Apple Health reads for sleep analysis, resting heart rate, HRV measured as SDNN, workouts, active energy, and walking/running or cycling distance. In the Android app, you can separately allow Health Connect reads for sleep sessions, resting heart rate, HRV measured as RMSSD, and exercise sessions. Health Connect reads are optional, read-only, foreground-only, and limited to the four most recent days for sleep and the two most recent days for heart and exercise context. Raw Apple Health samples and raw Health Connect records, record IDs, and source metadata remain in memory on your device and are not uploaded; only fields you review and choose to save as part of a check-in are sent to EnduraX.
  • Fueling data (optional, opt-in): If you enable the Fueling module, we collect the meals you log — descriptions, optional meal photos, and AI-estimated nutrient values — plus hydration presence, optional recovery-journal notes, and (only if you turn them on) bone-pain check-ins. The module is off until you opt in, and you can turn it off or delete all fueling data at any time from Settings.
  • Private messages, safety reports, and attachments: If you use messaging, we collect the text, shared-record references, meal or case photos, and short voice recordings you choose to send to an explicitly selected connected profile. You can report a conversation to EnduraX safety operations or block another exact profile. A report records the selected reason and optional details you submit; a block stops direct messaging between those profiles and hides blocked-participant content in supported group views. Blocking changes messaging only and does not grant or revoke health-data permissions. Voice recording begins only after you choose the microphone control, remains in a local preview until you confirm sharing, and is limited to 60 seconds. Attachments are encrypted after security screening, are not public or discoverable, and can be made available for 7, 30, or 90 days or until withdrawn.
  • Payment data: Billing is handled by Stripe. We store your Stripe customer ID but never see or store full card details.
  • Usage data: Standard server logs (IP address, browser type, pages visited) for security and debugging. Where analytics is enabled, we also collect explicit, non-health events such as a page path or a named product interaction. Analytics is configured without analytics cookies, local storage, session storage, persistent browser identifiers, person profiles, automatic element capture, full query strings, referrer collection, or session replay. We do not send health data or form contents to analytics.

3. How we use your data

  • To calculate and display your daily DARS readiness score.
  • To show your score history, trends, and RED-S risk indicators.
  • To show the exact health-data categories you separately choose to share with a connected professional. Joining a roster, team, practice, workspace, or conversation does not grant health-data access. Your personal notes remain private unless you explicitly attach a reviewed record that includes them.
  • Coach alert emails: Only after you separately grant the required current readiness categories and keep alerts enabled, if your composite score enters the Rest zone or your D5 RED-S indicator flags concern, we may send an automated alert email to an authorized coach containing your computed readiness scores for that day. Alert emails contain only the categories you currently authorize — never raw wearable samples, cycle data, or personal notes. You can narrow or revoke data access and change alert settings at any time in Settings → People & permissions.
  • AI features (Anthropic Claude): Three features use Anthropic's Claude AI. (1) Athlete-side workout suggestions and (2) coach-side training-plan modification suggestions send only your anonymised computed readiness scores and planned workout details — no personally identifiable information. (3) The optional Fueling module's meal estimator sends the meal descriptions and photos you choose to log. See Section 4.3 for details on each.
  • To process subscription payments via Stripe.
  • To improve the app and fix bugs.
  • To understand which public pages and product actions are useful through limited, cookieless analytics.

4. Data sharing

We do not sell your personal data. We share data only with:

  • Supabase — database and authentication provider (US).
  • Vercel — application hosting.
  • Stripe — payment processing.
  • Resend — transactional email delivery (coach alerts, account verification, receipts).
  • Anthropic (Claude AI) — AI workout and training-plan suggestions (anonymised computed scores only, no PII) and, if you use the optional Fueling module, meal descriptions and photos for nutrient estimation. See Section 4.3.
  • Amazon Web Services — temporary KMS-encrypted quarantine storage and GuardDuty malware screening for a photo or voice note you explicitly choose to attach to a private conversation. A clean attachment is removed from quarantine and stored encrypted in EnduraX; rejected or failed uploads are removed and are never delivered.
  • Sentry — error monitoring and performance tracking. Collects limited technical data (such as scrubbed stack traces, device type, and browser version) to identify and fix bugs. EnduraX applies a health- and identifying-data scrubber before transmission, does not intentionally include health or form data, and has screen recording disabled.
  • PostHog — limited website and product analytics. EnduraX configures PostHog in cookieless mode and sends only page paths and explicit, non-health interaction events. We disable persistent browser identifiers, person profiles, automatic element capture, session replay, full query strings, referrer collection, and form-content capture.
  • Oura / Strava / Whoop / Withings — only if you connect these services; we receive data from them on your behalf.
  • A connected coach or professional — accepting an invitation or joining a roster establishes an operational relationship only. Health data becomes visible only after you approve the exact requested categories, purpose, and access period. You can narrow or revoke those permissions independently and can leave or end the relationship at any time.

4.3 AI Processing (Anthropic)

Workout and training-plan suggestions. When you request an AI workout suggestion, or your coach generates AI training-plan suggestions, only your anonymised computed DARS scores (composite and D1–D5 domain scores) and planned workout details are sent to Anthropic. No name, email, cycle data, raw biometrics, or any identifier is sent for these features, and Anthropic cannot identify you from this data. AI suggestions are reference tools only — you and your coach make all final decisions.

Fueling meal estimator (optional module). If you enable the Fueling module and log a meal, the meal description you type — or the meal photo you choose to upload — is sent to Anthropic to estimate nutrients. Before sending, we screen meal text for identifiers (email addresses, phone numbers, dates, ID-like number runs) and block the AI call if any are found, and we strip all photo metadata (GPS location, capture time, device info); if metadata can't be stripped, the photo is not sent. These safeguards cannot catch everything you might write or photograph, so avoid including names, faces, or other personal details in meal logs.

Anthropic processes this data under its Commercial Terms of Service and Data Processing Addendum, which prohibit Anthropic from training models on our data; under Anthropic's standard retention policy, API inputs and outputs are automatically deleted within 30 days (safety-flagged content may be retained longer per their published policy). This processing is disclosed at onboarding and at Fueling-module opt-in, and you can contact us to object. Full details: AI Disclosure.

5. Health data

EnduraX collects sensitive health-related information including HRV, sleep data, fatigue, mood, menstrual cycle data, and computed readiness scores derived from health inputs. We treat all such data with heightened care:

  • Health data is used solely to calculate your readiness score and provide the Service.
  • We do not use your health data for advertising, profiling, or any purpose beyond delivering the Service.
  • We do not sell your health data to any third party.
  • Coach alert emails contain only computed scores — no raw biometric values or sensitive health data categories.
  • The AI suggestion features use only anonymised computed scores — no sensitive health data categories are sent to Anthropic for those features. The optional Fueling module's AI estimator additionally processes the meal descriptions and photos you choose to log, with the safeguards described in Section 4.3.
  • Aggregated, de-identified data may be used for product research only in a form that cannot identify you.
  • Apple Health access is read-only and optional. EnduraX does not write to Apple Health, request Health Records, or use HealthKit background delivery. Apple Health data is not used for advertising or shared with data brokers.
  • Health Connect access is read-only, foreground-only, and optional. EnduraX does not write to Health Connect or request exercise routes, background reads, or unrestricted history. Denying or revoking a category does not lower readiness or block the rest of the app.
  • If you delete your account, health data is deleted within 30 days.

5a. Legal basis for processing health data (GDPR Article 9)

  • Article 9(2)(a) — Explicit consent: Captured via in-app modal, documented with timestamp, and withdrawable at any time without penalty.
  • Article 9(2)(b) — Coaching context: Score data shared with coaches who have a legitimate coaching relationship with the athlete.
  • AI processing of anonymised scores: GDPR Article 6(1)(b) (performance of contract) and Article 5(1)(c) (data minimisation) — only the minimum computed scores necessary are transmitted, with no PII.
  • Fueling module (including AI meal estimation): Article 9(2)(a) — explicit consent. The module and its AI estimation run only after you opt in, and you can turn the module off or delete its data at any time.

6. Data retention

  • Account and profile data: retained for the lifetime of your account.
  • Check-in and health data: retained for the lifetime of your account for historical trend analysis.
  • Training plan and workout data: retained for the lifetime of the coach account.
  • Coach notification records: retained for 12 months for deduplication, then deleted.
  • AI suggestion outputs: retained as part of your training plan records, subject to the same deletion rights.
  • Fueling data (meals, photos, AI nutrient estimates): retained while the module is enabled; you can delete all fueling data at any time from Settings — it is removed from your account immediately, and residual copies in encrypted backups age out automatically.
  • Private messages and attachments: message records are retained for the lifetime of the relevant account or relationship unless deleted under an applicable data-rights request. Attachment access follows the duration selected when it is shared — 7, 30, or 90 days, or until withdrawn. When access expires, is withdrawn, or the relationship ends, the keys required to decrypt the object are erased and the encrypted storage object is removed through the attachment-cleanup process. Temporary AWS quarantine objects are removed after scanning or terminal failure.
  • Raw Apple Health samples: not retained by EnduraX servers. The iOS app stores only account-scoped authorization/read timestamps and the dates of categories with recent readable data; it clears that local metadata when you sign out or switch accounts. Check-in fields you review and save follow the check-in retention period above.
  • Raw Health Connect records: not retained by EnduraX servers. The Android app reads the selected recent records into memory for athlete review and does not upload record IDs or source metadata. Check-in fields you review and save follow the check-in retention period above.
  • Upon account deletion: personal data deleted within 30 days.
  • Washington State residents: absolute right to deletion under the My Health My Data Act.

7. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (processed within 30 days).
  • Export your check-in history using the CSV Export feature on the History page.
  • Withdraw consent for cloud wearable access by disconnecting Oura, Strava, Whoop, or Withings in Settings. Disconnecting removes the saved connection and imported provider rows.
  • Change or revoke Apple Health read access in iOS Settings or Health → profile → Apps → EnduraX. Because Apple does not disclose whether individual read permissions were denied, EnduraX reports only whether access was requested and whether recent readable data was found.
  • Change or revoke Health Connect read access in Android Settings or Health Connect. You can grant all, some, or none of the requested categories without losing access to the rest of EnduraX.
  • End a connection without automatically changing unrelated permissions, or revoke a professional's exact data categories without leaving the roster, in Settings → People & permissions.
  • Turn off coach alert emails without leaving a roster in Settings → Notifications, and revoke the underlying readiness access independently in People & permissions (GDPR Article 21 right to object).
  • Object to AI processing of your scores by contacting us. Note: this does not affect scores already shared with your coach on the dashboard.
  • Stop AI meal estimation at any time by turning off the Fueling module in Settings (your data is kept), or delete all fueling data entirely.
  • Withdraw an active private attachment share or let its selected access period expire. Ending a relationship or revoking permissions also invalidates affected views immediately.
  • Report a private conversation for review, block an exact profile from direct messaging, or later unblock a profile from the conversation safety controls.

To exercise any of these rights, contact us at rose@enduraxapp.com.

7a. California residents (CCPA/CPRA)

If you are a California resident, DARS scores and health data constitute Sensitive Personal Information under CCPA/CPRA. You have the right to limit our use of this data to purposes necessary to provide the Service. You also have the right to: know what data we collect; request deletion; opt out of the sale of personal information (we do not sell personal information); and non-discrimination for exercising your rights. To submit a CCPA request, email rose@enduraxapp.com.

7b. Washington State (My Health My Data Act)

If you are located in Washington State, you have additional rights under the MHMDA, including the absolute right to request deletion of your consumer health data with no exceptions. Contact us at rose@enduraxapp.com to exercise these rights.

8. Security

All data is transmitted over HTTPS (TLS). Data at rest is encrypted within Supabase. Row-level security ensures users can only access data authorized for their exact active profile. Access tokens for Oura, Strava, Whoop, and Withings are stored encrypted. Private photo and voice-note attachments are security-screened before delivery, encrypted with per-object keys, and limited to the explicitly selected recipient profile. AI API calls to Anthropic use encrypted connections; the suggestion features transmit no PII, and Fueling meal logs are screened for identifiers and stripped of photo metadata before transmission (Section 4.3). Coach alert emails are sent via Resend over encrypted connections.

9. Cookies and cookieless analytics

We use essential authentication cookies when you sign in. Our analytics is configured to run cookieless: it does not set analytics cookies or store persistent analytics identifiers in your browser, build person profiles, use cross-site advertising trackers, or record your screen. We use limited page-path and explicit product-action events to understand which parts of EnduraX are useful. Dismissing the privacy notice saves only a device-local acknowledgement so the notice stays out of the way; that acknowledgement is not sent to analytics.

10. Children

EnduraX is intended for users 18 and older. Because we collect sensitive health data including menstrual cycle information, the Service is not appropriate for anyone under 18. We do not knowingly collect data from anyone under 18.

11. Anti-doping

EnduraX is not affiliated with and has no reporting obligations to WADA, USADA, UK Anti-Doping, or any other anti-doping organisation. No user data — including modifier flags, supplement disclosures, readiness scores, or AI suggestions — is reported to any anti-doping authority.

12. International data transfers

EnduraX operates primarily from the United States. If you access the Service from outside the US, your information may be transferred to and processed in the United States. Supabase and Vercel maintain EU data processing addenda for users who require them. For EU/UK users, data transfers to the US are made under Standard Contractual Clauses (SCCs) where required. Contact us at rose@enduraxapp.com to request applicable transfer documentation.

13. Changes to this policy

We may update this policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before changes take effect. Continued use after the effective date constitutes acceptance.

14. Contact

Questions about this policy? Email us at rose@enduraxapp.com. We aim to respond within 5 business days.