Privacy Policy
Last updated 21 June 2026
Frankie is a personal running-coach app. This policy explains what data it collects, why, and the control you have over it. It's written in plain language for an early beta and isn't legal advice.
Who's responsible
Frankie is operated by Aurélien Hubert ("I", "me"), the data controller for the purposes of the GDPR. For any question or request about your data, contact privacy@frankie.run.
What I collect
- Account — your email address, and your name when Google provides it. You sign in with Google or a one-time email link; Frankie never sets or stores a password.
- Activity data from Strava — when you connect Strava, I read your activities from the last 12 weeks: runs (distance, time, pace, heart rate, GPS-derived splits and streams, elevation) and other activity types (used as cross-training context). Access is read-only — Frankie never writes to or posts on Strava.
- Goals you set — race targets, distances and dates.
- Injury & illness declarations (health data, optional) — only if you choose to declare a setback: the kind (injury or illness), whether you can run, an optional body area, dates, and an optional short note. This is special-category health data under the GDPR: it's collected with your explicit consent (asked the first time you declare), used solely to adapt your plan, goal verdicts and coaching, never used for analytics, and you can delete it at any time.
- Data I derive — training-load, fitness and race-time estimates, and the AI coaching commentary generated from the above.
- Weather — historical weather for the time and place of each run, to put efforts in context.
- Usage analytics — which pages and features you use, to understand how Frankie is used and improve it. Pseudonymous (an opaque identifier, never your name or email) and cookieless.
Why I use it, and the legal basis
I use this data only to provide the running analysis and coaching that is the product. The legal bases are your consent (for connecting Strava and processing your activity data) and legitimate interest (operating the app for you); any injury or illness you declare is processed only with your explicit consent (GDPR Art. 9). I do not sell your data or use it for advertising.
Sharing your verdict
Sharing is entirely optional. If you tap Share on a goal, Frankie creates a public link (frankie.run/v/…) with an unguessable address. The card shows only your verdict numbers — a projected or finish time, the distance, and how it compares to your goal — plus the Frankie name. It never includes your name, email, or the text you wrote for the goal. Anyone with the link can open it, but links are never listed or search-indexed. You can revoke a link at any time ("Stop sharing" on the goal); deleting the goal or your account removes it too. The page and its image are served by Frankie itself, so no third party receives it.
Who processes it
Your data is stored and processed by a small set of providers, each under their own privacy terms:
- Supabase — database and authentication, hosted in the EU. Privacy
- Vercel — web hosting (EU region). Privacy
- Modal — background compute for syncing and analysis (EU region). Privacy
- Anthropic — generates the AI coaching text and triages your feedback. For coaching, only numbers, your declared setback state (if any), and an opaque user identifier are sent (never your name or email); a feedback note is sent as you wrote it. Privacy
- Strava — the source of your activity data. Privacy
- Google — sign-in. Privacy
- Brevo — sends transactional email (the one-time sign-in link, and waitlist notifications). A French, EU-resident provider; it processes your email address and the send logs, kept in the EU. Privacy
- Cloudflare — DNS, plus a privacy-preserving Turnstile check on the email sign-in form to block automated abuse (no tracking cookies, no cross-site profiling). Privacy
- Sentry — error diagnostics, EU-hosted and PII-scrubbed (no name or email). Privacy
- PostHog — product analytics (which pages and features are used), EU-hosted, cookieless and PII-scrubbed (an opaque user identifier only — never your name or email). Privacy
- Linear — issue tracking. When you send feedback, an actionable note (the text you wrote) is filed as a ticket for the team to act on. Privacy
- AWS SES — sends transactional email (a waitlist "a seat opened" notice, and sign-in links if you use email sign-in), EU region. Only your email address and the message are processed. Privacy
- Web push services — if you turn on notifications, your browser registers with its push service (Google for Chrome / Android, Apple for Safari, Mozilla for Firefox) and notifications are delivered through it. The content is encrypted end-to-end, so the service relays it but can't read it.
Where it's stored
In the European Union (Supabase, Paris region). Background compute runs in EU regions.
How long I keep it
- Activities roll on a 12-week window — anything older than 84 days is deleted automatically.
- Goals, derived analysis, AI commentary and fitness history are kept until you delete them or your account.
- Setback declarations — resolved entries are deleted automatically after 12 months; open ones are kept until you resolve or delete them (or your account).
- Strava tokens are kept (encrypted) only while you're connected, and revoked when you disconnect or delete your account.
Cookies
Only the essential cookies needed to keep you signed in. No advertising or third-party tracking cookies, so there's no cookie banner to click through.
Your rights
At any time you can:
- Access and export your data — Settings → Download my data gives you a full JSON copy (GDPR Article 20).
- Delete everything — Settings → Delete account permanently erases your data and disconnects Strava (GDPR Article 17).
- Correct your data, withdraw consent (by disconnecting Strava or deleting your account), and object to processing.
- Complain to a supervisory authority — in France, the CNIL.
To exercise any right that isn't self-service, contact privacy@frankie.run.
Security
Strava tokens are encrypted at rest. Every database row is protected by row-level security, so you can only ever access your own data.
Changes
I'll update this page if the data practices change, and revise the "last updated" date above.
Contact
Aurélien Hubert — privacy@frankie.run.