Last updated 31 July 2026
Private beta privacy notice
How Effort Atlas handles account, activity, location, sensor, connector, and operational data during the invite-only beta.
Controller and contact
The controller is Andreas Kanz, operator of Effort Atlas, Germany. Privacy requests can be sent to privacy@effortatlas.com.
Data processed
- Access-request data such as name, email address, selected product interests, request status, and submission time.
- Account data such as username, display name, plan, and saved preferences.
- Activity data such as timestamps, GPS routes, distance, elevation, pace, power, heart rate, cadence, temperature, device metadata, and source metadata.
- User-created segments, routes, seasons, exclusions, and the analytics derived from activity data.
- Connector identifiers and credentials. Intervals.icu credentials are encrypted before database storage.
- Security and operational records such as login attempts, request identifiers, errors, and access logs. Request bodies, uploaded files, passwords, session cookies, and connector keys are not intentionally written to application logs.
Uploaded source files are parsed for import and are not retained after processing.
Purpose and legal basis
Access-request data is processed to review beta requests, communicate an approval, and provision an account where access is granted.
Account and activity data is processed to provide the requested private-beta service: importing and synchronizing activities, displaying maps, generating personal analytics, detecting duplicates, and supporting saved comparisons. This is necessary to provide the service requested by the invited user.
Heart-rate and related sensor readings may constitute health-related data. They are optional and are processed only after the user explicitly agrees. The app remains usable without heart-rate processing; imports and syncs then omit heart-rate measurements.
Limited security and operational processing is necessary to protect accounts, diagnose failures, and operate the service. Effort Atlas does not use activity data for advertising, public profiling, automated decisions with legal effects, or generated coaching.
Service providers and recipients
- Intervals.icu
- Receives authorization and API requests only when the user connects that service. Effort Atlas requests activity access and stores the returned activity data.
- Stadia Maps
- Supplies map styles and tiles. The browser contacts Stadia Maps when a map loads, so ordinary request metadata such as IP address and referrer may be processed.
- Hetzner
- Hosts the planned private-beta application, database, and initial infrastructure backups in Germany.
- Cloudflare
- Provides domain registration and authoritative DNS. The initial application records use DNS-only mode, so application HTTP traffic is not proxied through Cloudflare.
Effort Atlas does not sell personal data. Data is disclosed only to service providers needed to operate requested functionality or when legally required.
Retention and deletion
Access requests remain while they are pending or needed to record an invitation decision. A requester can ask for this information to be deleted through the privacy contact.
Account and activity data remains until the user deletes individual activities, deletes the account, or asks the administrator to do so. Deleting an activity creates a deletion record so later syncs do not silently restore it; the user can remove that record to permit re-import.
Account deletion removes live account data immediately. Backup copies are outside normal application access and may remain for up to 21 days before expiring. Deleting data in Effort Atlas does not delete the source data held by Intervals.icu or another provider.
Withdrawing heart-rate consent removes stored heart-rate measurements, saved HR zones, HR-specific exclusions, and derived HR analytics from the live service immediately. Other activity data remains. Future imports and syncs omit heart-rate data unless the user later agrees again.
Security
Effort Atlas uses authenticated sessions, CSRF protection, encrypted connector credentials, access controls, HTTPS in production, private application responses, and database ownership checks. No system can eliminate every risk; suspected account or data exposure should be reported through the privacy contact above.
Your choices and rights
Users can disconnect a connector, delete individual activities, and delete their account from Settings. Disconnecting stops future access but does not remove activities already imported. Heart-rate consent can be granted or withdrawn in Settings without deleting the account. Users can also request access, correction, restriction, deletion, or a portable copy of their data through the privacy contact. Withdrawing consent does not affect processing that was lawful before withdrawal.
Users may lodge a complaint with the competent data-protection authority. Questions or requests should first be sent to privacy@effortatlas.com.