Last updated 27 August 2026

Private beta privacy notice

How Effort Atlas handles account, activity, location, sensor, connector, and operational data during the invite-only beta.

PurposeData is used to provide personal activity analysis.
Optional HRHeart-rate processing requires explicit agreement.
UploadsActivity import files are discarded; optional photos are optimized.
User controlDelete activities, disconnect sources, or delete the account.

Controller and contact

Effort Atlas is a personal project operated by Andreas Kanz, Germany. Andreas Kanz is the controller. Privacy requests can be sent to privacy@effortatlas.com.

Data processed

  • Access-request data such as name, email address, selected product interests, optional message, request status, and submission time.
  • Account data such as username, display name, plan, and saved preferences.
  • Activity data such as timestamps, GPS routes, distance, elevation, pace, power, heart rate, cadence, temperature, device metadata, and source metadata.
  • Optional activity photos and descriptions. When a user chooses map placement during upload, capture time and GPS coordinates may be read transiently from the source photo; usable photo and activity-track location candidates, their capture time, and the user's selected location source are then stored with the optimized image.
  • User-created segments, routes, seasons, exclusions, and the analytics derived from activity data.
  • Connector identifiers and credentials. Intervals.icu credentials are encrypted before database storage.
  • Security and operational records such as login attempts, request identifiers, errors, and access logs. Request bodies, uploaded files, passwords, session cookies, and connector keys are not intentionally written to application logs.

Uploaded activity source files are parsed for import and are not retained after processing. Original photo files are also not retained: Effort Atlas keeps optimized image copies with embedded metadata removed.

Effort Atlas uses first-party session and CSRF cookies to sign in, maintain an authenticated session, and protect forms and account actions. Browser local storage and session storage remember display and filter preferences and temporary navigation state on the user's device. These technologies are not used for advertising, analytics, or cross-site tracking.

Purpose and legal basis

Access-request data is processed to review beta requests, communicate an approval, and provision an account where access is granted. The legal basis is Art. 6(1)(b) GDPR, including steps taken at the request of the applicant before access is provided.

Account and activity data is processed to provide the requested private-beta service: importing and synchronizing activities, displaying maps, generating personal analytics, detecting duplicates, and supporting saved comparisons. The legal basis is Art. 6(1)(b) GDPR because this processing is necessary to provide the service requested by the invited user.

Optional photos are processed to present the user's activity history and Highlights. Photo location processing is off by default and occurs only when the user selects that feature for an upload. It is a feature control under the same Art. 6(1)(b) service basis, not a condition for using photos or the rest of Effort Atlas.

Heart-rate and related sensor readings may constitute health-related data. They are optional and are processed only after the user explicitly agrees under Art. 6(1)(a) and Art. 9(2)(a) GDPR. The app remains usable without heart-rate processing; imports and syncs then omit heart-rate measurements.

Limited security and operational processing is necessary to protect accounts, diagnose failures, prevent abuse, and operate the service. The legal basis is the controller's legitimate interest in providing a secure and reliable service under Art. 6(1)(f) GDPR. Processing required to comply with a legal obligation relies on Art. 6(1)(c) GDPR.

Service providers and recipients

Intervals.icu
Receives authorization and API requests only when the user connects that service. Effort Atlas requests activity access and stores the returned activity data.
Stadia Maps
Supplies map styles and tiles. The browser contacts Stadia Maps when a map loads, so ordinary request metadata such as IP address and referrer may be processed. When location search is enabled, the browser also sends the entered search text and the current map centre used to rank nearby results. Search results are not saved, and Stadia Maps states that its API endpoints do not set cookies for end users.
Sentry
Processes technical error and performance telemetry used to diagnose failures and monitor reliability. This may include request metadata and technical identifiers. The configured project stores event data in Sentry's Germany region.
Hetzner
Hosts the private-beta application, database, and optimized activity photos in Germany.
Cloudflare
Provides domain registration and authoritative DNS.

Data is disclosed to these providers only as needed to operate the requested functionality, or when legally required.

Stadia Maps and Sentry are providers based in the United States. Location search uses Stadia Maps' EU endpoint, and Sentry event data is stored in Germany. Where their group companies or subprocessors process data outside the EEA, Effort Atlas relies on the providers' data-processing terms and applicable safeguards, including the EU–US Data Privacy Framework or European Commission Standard Contractual Clauses. Information about those safeguards is available through the privacy contact.

Retention and deletion

Access requests remain while they are pending or needed to record an invitation decision. A requester can ask for this information to be deleted through the privacy contact.

Account and activity data remains until the user deletes individual activities, deletes the account, or asks the administrator to do so. Deleting an activity creates a deletion record so later syncs do not silently restore it; the user can remove that record to permit re-import.

Deleting an activity or account removes its live optimized photos. A photo can also be deleted individually. Removing an activity from Highlights does not delete photos because photos belong to the activity. Removing a photo's map location clears its stored capture time and coordinates; because the original is not retained, that metadata can only be recovered by uploading the source photo again.

Account deletion removes the account and its associated data from the live database. The hosting provider retains up to seven rolling daily server backups for disaster recovery. Individual records cannot be removed from those backups; deleted data expires as the backups rotate and is not restored except during service recovery. Deleting data in Effort Atlas does not delete the source data held by Intervals.icu or another provider. Photo derivatives may remain in encrypted disaster-recovery backups until those backups expire under the same rotation.

Withdrawing heart-rate consent removes stored heart-rate measurements, saved HR zones, HR-specific exclusions, and derived HR analytics from the live service immediately. Other activity data remains. Future imports and syncs omit heart-rate data unless the user later agrees again.

Security and operational records are kept only for as long as needed to investigate failures, prevent abuse, and maintain the service. Provider-controlled logs and telemetry follow the configured or provider retention schedule and are removed when no longer needed for those purposes.

Security

Effort Atlas applies technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, or disclosure. No system can eliminate every risk; suspected account or data exposure should be reported through the privacy contact above.

Your choices and rights

Users can disconnect a connector, delete individual activities, and delete their account from Settings. Disconnecting stops future access but does not remove activities already imported. Heart-rate consent can be granted or withdrawn in Settings without deleting the account. Photo map placement is selected during upload and can be removed later for each photo without deleting the activity. Users can also request access, correction, restriction, deletion, or a portable copy of their data through the privacy contact. Where processing relies on legitimate interests, users may object to that processing. Withdrawing consent does not affect processing that was lawful before withdrawal.

Users may lodge a complaint with the competent data-protection authority. Questions or requests should first be sent to privacy@effortatlas.com.