Legal

Privacy Policy

Effective June 28, 2026

Ekiden (“Ekiden,” “we,” “us,” or “our”) operates a coaching marketplace and training-management platform at ekiden.app that connects runners with human coaches. This Privacy Policy explains what information we collect, how we use and share it, how we keep it safe, and the choices and rights you have. It applies to our website, applications, and related services (together, the “Service”).

A note on connected fitness services: Ekiden lets athletes link accounts from third-party providers such as Strava, Garmin, and COROS so that training and activity data can flow to their coach. We handle the data we receive from these providers as described throughout this policy, and in particular in “Data from connected fitness services.”

Who this policy covers

The Service has two main kinds of users: athletes (runners who train using Ekiden) and coaches (the people who build and monitor their training). This policy covers both, as well as visitors to our website and anyone who applies to join as a coach. Where a section applies only to one group, we say so.

Information we collect

We collect the following categories of information:

Information you provide directly

  • Account information — your name, email address, password, and (for coaches) profile details such as coaching experience, qualifications, specialties, location, and rates.
  • Coach applications — if you apply to coach, the information you submit in the application form, including your name, email, country, years coaching, specialties, roster size, a profile or portfolio link, qualifications, and your motivation for joining.
  • Training and profile inputs — information athletes enter during onboarding and use, such as goals, race targets, self-reported effort (RPE), notes, and manually logged workouts.
  • Communications — messages (text and voice) you send between coaches and athletes through the Service, and any messages you send to us for support.

Data from connected fitness services

If you choose to connect a third-party fitness account — such as Strava, Garmin, or COROS — you authorize that provider to share data with Ekiden through their API. The connection is optional, you control it, and you can disconnect it at any time. Depending on the provider and the permissions you grant, the data we receive may include:

  • Activity and workout data — date and time, sport type, duration, distance, pace and speed, splits and laps, elevation, and route or GPS-derived metrics.
  • Physiological and health-related metrics — heart rate (average and maximum) and similar performance measures provided by the activity.
  • Account identifiers and tokens — a provider-issued user identifier and the OAuth access and refresh tokens needed to keep the connection working. We store tokens only to maintain your connection and never ask for your provider password.

We request only the data needed to deliver coaching features, and we use data from a connected provider solely to provide and improve the Service for you as described below.

Information collected automatically

  • Usage and device data — basic technical information such as your IP address, browser and device type, and how you interact with the Service, collected to operate, secure, and improve it.
  • Derived data — values Ekiden computes from your activities, such as training load, training-stress scores, threshold estimates, and automatically detected session types. These are generated by our own engine to power coaching analytics.

How we use information

We use the information we collect to:

  • Provide, maintain, and operate the Service — including matching athletes with coaches, building and delivering training plans, and pushing structured workouts to devices.
  • Sync, display, and analyze your activities so your coach can review your training and so you can track your fitness and progress.
  • Compute training-load and performance metrics — and automatically flag unusual training patterns for a coach to review — that power the analytics both coaches and athletes rely on.
  • Enable messaging between coaches and athletes and send service-related communications.
  • Process payments and payouts (handled by our payment processor).
  • Provide AI-assisted features that suggest plan edits, draft plans, and tag sessions — always as suggestions a coach confirms, never autonomously.
  • Keep the Service secure, prevent fraud and abuse, and comply with legal obligations.

We do not sell your personal information, and we do not use data obtained from connected fitness services (including Garmin and COROS data) for advertising or to build advertising profiles.

How we share information

We share information only in the following circumstances:

  • Between coach and athlete. The core purpose of Ekiden is to let a coach see and work with their athlete’s training. When you enter a coaching relationship, the relevant profile, activity, and training data is shared with the coach (or athlete) on the other side of that relationship.
  • Service providers (sub-processors). We use trusted third parties to run the Service — for example, cloud hosting and database providers, Stripe for payments and coach payouts, and AI providers that power coach-assist features. They may process data only on our instructions and for the purposes of providing their service to us.
  • Legal and safety reasons. We may disclose information if required by law or to protect the rights, safety, and security of our users, the public, or Ekiden.
  • Business transfers. If Ekiden is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

We do not share data obtained from Garmin, COROS, Strava, or other connected providers with anyone except as needed to provide the Service to you (most importantly, your own coach) and the service providers listed above. We never sell it.

Data retention and deletion

We keep your information for as long as your account is active or as needed to provide the Service, and afterward only as long as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

  • Disconnecting a provider. When you disconnect a fitness account (Strava, Garmin, or COROS), we stop syncing new data from it and delete the stored access and refresh tokens for that connection.
  • Deleting your account. You can ask us to delete your account and associated personal data, including data we received from connected providers. On deletion we remove or de-identify that data from our active systems within a reasonable period, except where we are required to retain it by law.

To delete your account or data, use the in-product controls where available or contact us at privacy@ekiden.app.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:

  • Access and update your profile information from within the Service.
  • Connect or disconnect any fitness provider at any time — connections are always optional.
  • Request a copy of your data or its deletion by contacting us.

To exercise any of these rights, email us at privacy@ekiden.app. We will respond within the time required by applicable law. You may also have the right to lodge a complaint with your local data-protection authority.

How we protect information

We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and limiting access to data on a need-to-know basis. OAuth tokens for connected providers are stored to maintain your connections and are removed when you disconnect. No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly.

International data transfers

Ekiden may process and store information in countries other than where you live, including the United States. Where we transfer personal information across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.

Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

If you have questions about this policy or how we handle your information, contact us at:

privacy@ekiden.app