Skip to main content
  1. Fitness AI Connector/

← Back to Fitness AI Connector

Privacy Policy
#

Last updated: August 25, 2026

(The August 25, 2026 update clarifies existing practice. Section 6 on subscriptions has been aligned with Section 7 of the Terms of Service, under which cancellation takes effect at the end of the billing period.)

This Privacy Policy explains how FMP (“we”, “us”, or “our”) handles personal information in connection with Fitness AI Connector (“the Service”).


Your data, in plain language
#

Before the legal text, here is how the Service handles your data in plain terms. See the sections below for details.

  • What we access — Your Garmin health and activity data (sleep, heart rate, stress, activities, body composition, and similar). Only data from the moment you connect your Garmin account onward is available.
  • What we never have — Your Garmin password. You sign in on Garmin’s own page (OAuth); the Service never sees or stores your password.
  • Your control — You can revoke the connection at any time from your Garmin Connect™ account settings. If you delete your account, your Garmin health data is automatically and permanently deleted after a recovery grace period.
  • Read-only — The Service can only read data from your Garmin account. It can never write to or change anything in your Garmin account.

1. AI Transparency Statement
#

Your Garmin data is provided to AI assistants (Anthropic Claude / OpenAI ChatGPT). AI assistants analyze and summarize your data to generate responses.

Our Service only relays and provides data. Interpretation and recommendations are generated by the respective AI assistant platforms (Anthropic / OpenAI). The handling of your data by AI assistants is governed by their respective privacy policies.

AI Model Training: The Service provides data via MCP protocol (API). How data sent to an AI platform is stored, whether it is used to improve models, and how it is otherwise handled depends on the platform you use, your subscription plan, your account settings, and that platform’s current terms and policies. We do not guarantee or control this handling. Please check each platform’s terms and your account settings for the current conditions.


2. Data We Collect
#

2.1 Garmin Health Data
#

We collect the following data through the Garmin Health API, the Garmin Activity API, and the Garmin Women’s Health API:

  • Heart rate (resting and active)
  • Sleep data (duration, score, sleep stages)
  • HRV (heart rate variability)
  • Stress levels
  • Activity data (running, walking, and other exercise records)
  • VO2max
  • Body Battery
  • Menstrual cycle tracking data (cycle phase, day in cycle, period start date, cycle length, and fertile window predictions) — via the Garmin Women’s Health API. This data is collected only if you track your menstrual cycle in Garmin Connect and have menstrual cycle data sharing enabled. If you use pregnancy tracking in Garmin Connect, pregnancy-related data may be included.
  • Other health-related data provided by these Garmin APIs

2.2 Account Information
#

  • Email address (obtained through Auth0 authentication)

2.3 Payment Information
#

  • Payment processing is handled by Stripe. We do not store credit card numbers or other payment details.

3. How We Use Your Data and Legal Basis #

We use your data solely for the following purposes:

Purpose Legal Basis
Providing data to AI assistants (core function) Your consent (granted when authorizing Garmin connection)
Account management and authentication Performance of service contract
Subscription management and billing Performance of service contract
Service improvement and troubleshooting Legitimate interest
Service notifications: To send service-related notices by email, such as guidance for completing your account setup (e.g., connecting your Garmin account) Legitimate interest

4. Data Storage
#

4.1 Storage Location and International Data Transfers
#

Your data is encrypted and stored on Supabase (AWS US East region, United States).

For users residing in the EU/EEA, your data is transferred to the United States. These transfers are conducted based on Standard Contractual Clauses (SCCs) established by the respective service providers.

4.2 Retention Period
#

Data retention periods vary by plan:

  • Free plan: 2 days
  • Basic plan: up to 5 years from the date of sync (while your subscription is active)

Data beyond the retention period is automatically deleted.

When a paid (Basic) subscription ends, we retain your previously stored data for 30 days so that your history is preserved if you resubscribe. After 30 days, the Free plan’s retention rules apply and data beyond that range is deleted. This grace period does not apply to accounts that have only used the Free plan.


5. Third-Party Data Sharing
#

The Service shares data with the following third-party services:

Service Purpose Data Shared
Garmin (US) Data source Connection info via the Garmin Health API / Activity API / Women’s Health API
Auth0 (US) Authentication Email address, auth tokens
Stripe (US) Payment processing Payment-related information
Anthropic (US) AI assistant Garmin health data via MCP protocol
OpenAI (US) AI assistant Garmin health data via MCP protocol
Supabase (US) Database and data storage Garmin health data and account information (stored encrypted)
Render (US) Server hosting Data processed by the Service in general

We do not sell, share, or provide your data to any third parties other than those listed above. When we add or change a service provider (sub-processor), we will announce it by updating this Policy.


6. Data Deletion
#

You may request deletion of your account and data at any time through either of the following methods:

  • Via AI assistant: Tell your AI assistant “I want to delete my account”
  • Via email: Send a deletion request to contact@fmp.it.com

When we receive a deletion request, we handle it as follows:

  • Garmin health data: Deleted from our database within 30 days of the request.
  • Account: Deactivated so that you can no longer sign in or use the Service. To prevent misuse and to comply with legal obligations, account identifiers (including your email address, authentication ID, and payment customer ID) are retained after deletion.
  • Subscription: If a subscription is still billing, we will ask you to cancel it yourself. Where a deletion request is sent to us by email, we will carry out the cancellation on your behalf. In either case the cancellation takes effect at the end of the billing period and no further charges are made. Payment and transaction records are retained in accordance with statutory record-keeping obligations.

Disconnecting from Garmin Connect (stopping data from being sent) is something you do yourself in the Garmin Connect app. See the Account Management page for the steps.


7. Your Rights (Disclosure Requests / GDPR)
#

Under the Act on the Protection of Personal Information of Japan (APPI) and the GDPR, you have the following rights:

  • Notification of purpose of use: Request notification of the purposes for which your retained personal data is used
  • Right of access (disclosure): Request disclosure of your data and of records of provision to third parties
  • Correction, addition, and deletion: Request correction, addition, or deletion of your data when its content is inaccurate
  • Suspension of use, erasure, and suspension of third-party provision: Request these in the cases provided by law (see Section 6 for what is deleted and what is retained)
  • Right to data portability: Receive your data in a structured format
  • Restriction, objection, and withdrawal of consent: Request restriction of processing or object to processing under certain circumstances, and withdraw consent for processing based on consent

How to make a request:

  • Method: Contact us at contact@fmp.it.com.
  • Identity verification: We verify your identity by means such as receiving your request from your registered email address.
  • Response: We will respond without undue delay.
  • Fees: Free of charge (including requests for notification of purpose of use and for disclosure).

Complaints: You have the right to lodge a complaint regarding the handling of your personal information with the Personal Information Protection Commission of Japan (or, if you reside in the EU/EEA, with your local supervisory authority).


8. Cookies
#

The Service uses session cookies for authentication purposes only. We do not use advertising tracking or third-party tracking cookies.


9. Minors
#

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18.


10. Security
#

We implement the following security measures to protect your data:

  • Data encryption (in transit and at rest)
  • Access controls and authentication
  • Regular security reviews

However, no method of data transmission over the Internet or electronic storage is completely secure.


11. Data Breach Response
#

In the event of a personal data breach, we will work to assess the impact and prevent further harm, and, where required by applicable law (including the Act on the Protection of Personal Information of Japan and the GDPR), we will report to the competent supervisory authority and notify affected users within the time limits and in the manner prescribed by that law.


12. Business Succession and Service Termination
#

If we transfer the business to a third party or terminate the Service, we will endeavor to ensure that your personal data continues to receive protection equivalent to this Policy, and we will announce material changes in advance. Upon termination of the Service, we will delete your personal data except where retention is required by law.


13. Changes to This Policy
#

We reserve the right to modify this Privacy Policy. We will notify you of significant changes through the Service. The latest policy will always be available on this page.


14. Governing Law
#

This policy is governed by the laws of Japan.


15. Contact
#

For questions regarding this Privacy Policy, please contact us:

The name and address of the operator (a sole proprietor) with respect to retained personal data will be disclosed without undue delay upon request to contact@fmp.it.com (normally within 7 days — the same period as set out in the Commercial Disclosure page).