Legal
Privacy Policy
Effective June 28, 2026
Ekiden (“Ekiden,” “we,” “us,” or “our”) operates a coaching marketplace and training-management platform at ekiden.app that connects runners with human coaches. This Privacy Policy explains what information we collect, how we use and share it, how we keep it safe, and the choices and rights you have. It applies to our website, applications, and related services (together, the “Service”).
A note on connected fitness services: Ekiden lets athletes link accounts from third-party providers such as Strava, Garmin, and COROS so that training and activity data can flow to their coach. We handle the data we receive from these providers as described throughout this policy, and in particular in “Data from connected fitness services.”
Who this policy covers
The Service has two main kinds of users: athletes (runners who train using Ekiden) and coaches (the people who build and monitor their training). This policy covers both, as well as visitors to our website and anyone who applies to join as a coach. Where a section applies only to one group, we say so.
Information we collect
We collect the following categories of information:
Information you provide directly
- Account information — your name, email address, password, and (for coaches) profile details such as coaching experience, qualifications, specialties, location, and rates.
- Coach applications — if you apply to coach, the information you submit in the application form, including your name, email, country, years coaching, specialties, roster size, a profile or portfolio link, qualifications, and your motivation for joining.
- Training and profile inputs — information athletes enter during onboarding and use, such as goals, race targets, self-reported effort (RPE), notes, and manually logged workouts.
- Communications — messages (text and voice) you send between coaches and athletes through the Service, and any messages you send to us for support.
Data from connected fitness services
If you choose to connect a third-party fitness account — such as Strava, Garmin, or COROS — you authorize that provider to share data with Ekiden through their API. The connection is optional, you control it, and you can disconnect it at any time. Depending on the provider and the permissions you grant, the data we receive may include:
- Activity and workout data — date and time, sport type, duration, distance, pace and speed, splits and laps, elevation, and route or GPS-derived metrics.
- Physiological and health-related metrics — heart rate (average and maximum) and similar performance measures provided by the activity.
- Account identifiers and tokens — a provider-issued user identifier and the OAuth access and refresh tokens needed to keep the connection working. We store tokens only to maintain your connection and never ask for your provider password.
We request only the data needed to deliver coaching features, and we use data from a connected provider solely to provide and improve the Service for you as described below.
Information collected automatically
- Usage and device data — basic technical information such as your IP address, browser and device type, and how you interact with the Service, collected to operate, secure, and improve it.
- Derived data — values Ekiden computes from your activities, such as training load, training-stress scores, threshold estimates, and automatically detected session types. These are generated by our own engine to power coaching analytics.
How we use information
We use the information we collect to:
- Provide, maintain, and operate the Service — including matching athletes with coaches, building and delivering training plans, and pushing structured workouts to devices.
- Sync, display, and analyze your activities so your coach can review your training and so you can track your fitness and progress.
- Compute training-load and performance metrics — and automatically flag unusual training patterns for a coach to review — that power the analytics both coaches and athletes rely on.
- Enable messaging between coaches and athletes and send service-related communications.
- Process payments and payouts (handled by our payment processor).
- Provide AI-assisted features that suggest plan edits, draft plans, and tag sessions — always as suggestions a coach confirms, never autonomously.
- Keep the Service secure, prevent fraud and abuse, and comply with legal obligations.
We do not sell your personal information, and we do not use data obtained from connected fitness services (including Garmin and COROS data) for advertising or to build advertising profiles.
Data retention and deletion
We keep your information for as long as your account is active or as needed to provide the Service, and afterward only as long as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.
- Disconnecting a provider. When you disconnect a fitness account (Strava, Garmin, or COROS), we stop syncing new data from it and delete the stored access and refresh tokens for that connection.
- Deleting your account. You can ask us to delete your account and associated personal data, including data we received from connected providers. On deletion we remove or de-identify that data from our active systems within a reasonable period, except where we are required to retain it by law.
To delete your account or data, use the in-product controls where available or contact us at privacy@ekiden.app.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:
- Access and update your profile information from within the Service.
- Connect or disconnect any fitness provider at any time — connections are always optional.
- Request a copy of your data or its deletion by contacting us.
To exercise any of these rights, email us at privacy@ekiden.app. We will respond within the time required by applicable law. You may also have the right to lodge a complaint with your local data-protection authority.
How we protect information
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and limiting access to data on a need-to-know basis. OAuth tokens for connected providers are stored to maintain your connections and are removed when you disconnect. No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly.
International data transfers
Ekiden may process and store information in countries other than where you live, including the United States. Where we transfer personal information across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.
Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
Contact us
If you have questions about this policy or how we handle your information, contact us at: