Skip to main content

Last updated 2026-07-23.

Privacy Policy

Last updated: 2026-07-23

This Privacy Policy describes how MyThreshold (“MyThreshold”, “we”, “us”, “our”), established in Bulgaria, European Union, processes personal data in connection with the MyThreshold service (the “Service”). It is written to satisfy the transparency requirements of Articles 13 and 14 of the GDPR and UK GDPR and of comparable laws in other jurisdictions. It forms part of, and is incorporated by reference into, our Terms of Service.

1. Who we are

MyThreshold, established in Bulgaria, European Union, is the data controller for the personal data described in this policy. As a controller established in an EU member state, we are subject to the GDPR directly, and the Bulgarian Commission for Personal Data Protection (CPDP) is our lead supervisory authority. Contact details for privacy matters are in Section 11.

2. Categories of data we process

  • Account data. Email address, username, and authentication identifiers (via our authentication provider, Supabase) needed to create and secure your account.
  • Biometric and training data (data concerning health). Heart rate (HR), heart-rate variability (HRV), pace, power, cadence, GPS/route data, sleep, and other workout- and physiology-related signals synced from your connected device or provider (currently Garmin), and every metric we compute from that raw data — training load (CTL/ATL/TSB), TSS, Normalized Power, readiness scores, and similar derived values. We treat this entire category, both the raw signals and the metrics we derive from them, as data concerning health under Article 9 GDPR (see Section 4).
  • Chat and coaching-interaction data. Messages you send to the in-app coaching-assistant chat, and the assistant’s replies, which are generated by an AI system (see Section 5) and may reference your training and biometric data. Because your chat messages may reveal health information, we handle this category with the same protections as data concerning health.
  • Usage data. Standard technical logs (IP address, request metadata, error logs) generated by your use of the Service, for security and reliability purposes.

3. Why we process it (purposes)

  • To provide the Service: sync your training data, compute training-load and readiness metrics, and surface them to you.
  • To power the in-app coaching-assistant chat, which analyzes your computed metrics and responds to your questions, and the automated consistency check described in Section 6 of the Terms of Service.
  • To operate, secure, and improve the Service (fraud prevention, debugging, capacity planning).
  • To communicate with you about your account and about material changes to this policy or the Terms of Service.

We do not use your personal data for third-party advertising, and we do not sell or share it for cross-context behavioral advertising.

4. Legal basis for processing (EU/UK/EEA users)

Where the GDPR or UK GDPR applies, our legal bases are:

  • Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — for all processing of your biometric and training data and health-related chat content described in Section 2. We treat this data as special-category data concerning health under Article 9, because inferring fitness, readiness, and physiological-load status from raw biometric signals reveals information about your health. We therefore collect your explicit, separate consent through a dedicated, unbundled checkbox at signup — distinct from your acceptance of the Terms of Service — which names the HR/HRV/training-load data categories this policy describes. This consent is the sole legal basis for the health-data processing; if you do not give it, or if you withdraw it (Section 8), we will not process this category of data, and the features that depend on it will be unavailable.
  • Contract (Art. 6(1)(b)) — processing your account data is necessary to provide the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — security logging, fraud prevention, and service reliability, based on our legitimate interest in keeping the Service secure and functioning. You may object to this processing as described in Section 8.
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with a legal obligation that applies to us.

5. AI processing and automated decisions

The coaching-assistant chat and the automated consistency check described in Section 6 of the Terms of Service are powered by AI models accessed through our own internal, provider-abstracted service; every AI call is routed through that internal service under our control, not sent to a third-party hosted AI API directly from client code. When you use the chat, you are interacting with an AI system, not a human. We do not use the Service’s AI features to make any decision about you that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR: every AI output is informational, and every training decision remains yours. We do not use your personal data to train AI models.

6. Third parties / processors

We share personal data only with the following categories of recipients, only as needed to provide the Service:

  • Garmin (or another connected fitness device/provider you authorize) — the source of your raw training/biometric data, under your own agreement with that provider. Your provider’s own privacy policy governs its processing.
  • Supabase — authentication and session management.
  • Hosting provider — infrastructure hosting for the Service (details available on request).
  • Successors — if we undergo a merger, acquisition, or sale of assets, personal data may be transferred to the successor, which will remain bound by this policy or one at least as protective.
  • Authorities — where disclosure is required by law, legal process, or to protect the rights, safety, or property of you, us, or others.

Each processor acts under a data-processing agreement consistent with Article 28 GDPR where the GDPR applies. We do not sell your personal data.

7. Retention

  • Account and biometric/training data: retained for as long as your account is active, so the Service can compute historical training-load trends. If you delete your account or withdraw your health-data consent, we delete or irreversibly anonymize this data within 30 days, except where a longer retention is required by law.
  • Chat and coaching-interaction data: retained on the same schedule as your account.
  • Security and usage logs: retained for up to 12 months, then deleted, unless a specific log must be kept longer for an ongoing security investigation or a legal obligation.
  • Anonymized/aggregated data: data that can no longer identify you may be retained for service-improvement and statistical purposes.

8. Your rights

Depending on your jurisdiction, you have the right to access, correct, delete, restrict, or port your personal data; to object to processing based on legitimate interests; and to withdraw consent (including the explicit health-data consent described in Section 4) at any time, via your account settings or by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and will limit or disable the features that depend on that data. We respond to rights requests within the time limits of applicable law (one month under the GDPR, extendable as the GDPR permits). You will not be discriminated against for exercising any of these rights.

If you are in the EU, UK, or EEA, you also have the right to lodge a complaint with your national supervisory authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to address your concern first, but you may contact your authority at any time.

9. International transfers

We are established in Bulgaria, inside the EU/EEA, and your data is controlled from there. Some of our processors and service providers (for example, our hosting provider or the provider behind a connected fitness platform such as Garmin) may be established, or may process data, outside the EU/EEA, including in the United States. Any transfer of your personal data from us to a recipient outside the EU/EEA is made only under appropriate safeguards — the European Commission’s Standard Contractual Clauses, an adequacy decision covering the recipient country or framework, or (for UK data) the UK Addendum or International Data Transfer Agreement — together with supplementary technical measures (encryption in transit and at rest) where appropriate. You may request a copy of the applicable safeguard via the contact details in Section 11.

10. Security and changes to this policy

We apply technical and organizational measures appropriate to the sensitivity of health data, including encryption in transit, access controls, and isolation of biometric data stores. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the competent authority where applicable law requires it. We may update this policy as the Service or applicable law changes; material changes will be reflected in the “Last updated” date above and, where required by law, notified to you in advance. Where a change materially expands our processing of your health data, we will seek fresh consent rather than rely on continued use.

11. Contact

Privacy questions and rights requests: MyThreshold, Bulgaria, European Union, or the contact details published on the MyThreshold site.

© 2026 MyThreshold

How it works Metrics reference
Terms of Service Privacy Policy