Privacy Policy
CoachPulse
Effective date: June 3, 2026
Introduction
This Privacy Policy applies to CoachPulse ("the App"), developed and operated by Nioquant, obrt za usluge, vl. Fran Čudina, Zagreb, Štefanićeva ulica 1, Croatia ("we", "us", "our"). CoachPulse is an AI coaching data field available on the Garmin Connect IQ platform. It reads your biometric and activity data during a workout and sends it to a third-party AI provider of your choice to generate real-time coaching cues displayed on your Garmin watch.
This policy applies to all users of the App regardless of their country of residence. Where specific regional rights apply, they are described in the "Your Privacy Rights" section below.
Data Controller: Nioquant, obrt za usluge, vl. Fran Čudina, Zagreb, Štefanićeva ulica 1, Croatia. Contact: [email protected].
Data We Collect
The App reads the following data during use. All data stays on your device except for what is transmitted to the AI provider when a coaching cue is requested (see "Data Sent to AI Providers" below). We do not receive, store, or process any of this data on our own servers at any point.
Profile Data
- Age (derived from birth year stored in your Garmin user profile)
- Gender (from your Garmin user profile)
- Height (from your Garmin user profile)
- Weight (from your Garmin user profile)
- Resting heart rate (from your Garmin user profile)
- Average resting heart rate (from your Garmin user profile)
- VO2max estimate for running (from your Garmin user profile, if available)
- VO2max estimate for cycling (from your Garmin user profile, if available)
- Heart rate zones for the current sport (from your Garmin user profile)
Biometric Data
- Current, average, and maximum heart rate during the workout
- Body battery level (from Garmin SensorHistory)
- Stress level averaged over the past two hours (from Garmin SensorHistory)
Activity Data
- Sport type and sub-sport (for example: running, cycling, swimming)
- Elapsed time, distance, and calories burned
- Current and average speed or pace
- Cadence (steps per minute for running, revolutions per minute for cycling)
- Power output (cycling, if a power meter is connected)
- Swim stroke type, SWOLF score, and distance per stroke
- Altitude, total ascent, total descent, and climb rate
- Ambient temperature and barometric pressure (from Garmin SensorHistory)
- Training effect and energy expenditure rate
- Structured workout step name and intensity (if a structured workout is active)
Recovery and Load Data
- Acute training load (7-day rolling total workout minutes)
- Chronic training load (28-day weekly average workout minutes)
User Settings
- Session goal text (optional, entered by you in the app settings)
- Coaching style and recovery focus preferences
- AI provider selection, AI model selection, and your API key
- Unit preference (metric or imperial)
Note on health and biometric data: Heart rate, body battery, stress level, VO2max, resting heart rate, weight, and similar data points are classified as health or biometric data under applicable privacy laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, Brazil's LGPD, and various US state laws. This data is processed solely on your device and transmitted only to your chosen AI provider. We never receive it.
Data Sent to AI Providers
When the App detects a coaching trigger (such as a heart rate alert, pace drop, milestone, or periodic check-in), it assembles a text prompt from your current biometric and activity snapshot and transmits it directly from your device to the AI provider you have configured. The prompt contains no personally identifiable information such as your name, email address, or GPS coordinates.
The prompt includes a subset of the data listed above, for example: athlete profile (age, gender, height, weight, resting heart rate, VO2max), current heart rate and zone, pace, cadence, body battery, stress level, and training load. This data travels from your Garmin watch through the Garmin Connect app on your paired phone and over the internet to the AI provider API.
The following AI providers are supported. Your use of each provider is subject to their own privacy policy and terms of service:
- OpenAI via the OpenAI API. See OpenAI Privacy Policy.
- Anthropic (Claude) via the Anthropic API. See Anthropic Privacy Policy.
- Google (Gemini) via the Gemini API. See Google Privacy Policy.
We do not control how AI providers store or process the data included in API requests. All three providers listed above are based in the United States. See "International Data Transfers" below for more information. We recommend reviewing the privacy policy of your chosen provider before use.
International Data Transfers
When you use the App, your biometric and activity data is transmitted from your Garmin device directly to the AI provider you have selected. All three supported AI providers (OpenAI, Anthropic, and Google) are headquartered in the United States and process data on infrastructure that may be located in the United States or other countries.
We do not ourselves transfer your data across borders, as we never receive it. The transfer occurs directly between your device and your chosen AI provider. By selecting an AI provider and entering your API key, you initiate and control this transfer.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please be aware that the AI providers you choose may transfer your data to countries that do not have an adequacy decision from the relevant authority. Each of the supported providers maintains Standard Contractual Clauses or equivalent transfer mechanisms under their API terms of service. We recommend reviewing each provider's data transfer documentation before use.
Legal Basis for Processing
This section applies to users in the European Economic Area, the United Kingdom, and Switzerland, where data protection law requires a legal basis for each type of processing.
General data (activity data, settings, recovery data)
We process this data on the basis of performance of a contract (Article 6(1)(b) GDPR and UK GDPR). You install and configure the App to provide real-time coaching, and this data is necessary to deliver that service.
Health and biometric data (heart rate, VO2max, body battery, stress, weight, resting heart rate)
Health and biometric data is classified as special category data under Article 9 GDPR. We process this data on the basis of your explicit consent (Article 9(2)(a) GDPR). By deliberately installing the App, entering your API key, and activating it during a workout, you provide explicit consent for your biometric data to be used to generate coaching cues via your chosen AI provider.
You may withdraw this consent at any time by removing the App from your Garmin device or by clearing your API key in the app settings. Withdrawal of consent does not affect the lawfulness of processing that took place before withdrawal.
Switzerland
For users in Switzerland, the same legal bases apply under the revised Federal Act on Data Protection (nFADP, in force since 1 September 2023).
How We Use Your Data
All data read by the App is used solely to provide its core functionality:
- Detecting workout conditions that warrant a coaching cue (heart rate alerts, pace drops, milestones, sustained effort, cadence issues, swim efficiency drops)
- Building context-aware prompts that allow the AI provider to generate relevant, data-driven coaching advice
- Displaying the AI response as a coaching cue on your Garmin watch
- Triggering a vibration alert for genuine safety emergencies signaled by the AI response
We do not use your data for advertising, profiling, sale to third parties, or any purpose other than those listed above.
Data Storage and Retention
On your Garmin device and phone: App settings, AI provider selection, and your API key are stored locally in Garmin Connect IQ app properties on your paired phone. No activity or biometric data is persisted by the App beyond the current workout session.
Our servers: We do not operate any servers that receive or store your data. The only outbound communication from the App is the API request sent directly from your device to your chosen AI provider. We hold no personal data and therefore have no data retention schedule to maintain on our end.
AI provider retention: Each AI provider may retain API request data according to their own retention policies. Please review the privacy policy of your chosen provider for details.
Your API Key
CoachPulse requires you to supply your own API key for the AI provider you choose. Your key is stored locally in Garmin Connect IQ app properties and is transmitted only to the corresponding AI provider endpoint when a coaching request is made. We never receive your API key.
You are responsible for keeping your API key secure. You can update or remove it at any time through the app settings in Garmin Connect.
Data Sharing
We do not sell, rent, trade, or share your data with any third parties beyond the AI provider API calls described above and initiated by you. Specifically:
- No analytics or crash reporting is sent to any external service by us
- No advertising networks receive your data
- We do not receive any data from your device or from AI provider responses
- We do not sell personal information, including health or biometric data, under any circumstances
Your Privacy Rights
Depending on your country or region of residence, you may have specific rights regarding your personal data. Because we do not store or receive your data, most rights relating to access, correction, or deletion of data held by an organisation do not apply to us directly. However, we describe your rights below and explain where to direct each type of request.
European Economic Area and United Kingdom (GDPR / UK GDPR)
If you are located in the EEA or UK, you have the following rights under the GDPR and UK GDPR:
- Right of access (Article 15): You may request confirmation of whether we process your personal data and, if so, a copy of it. Because we hold no personal data, we will confirm this in response to any access request sent to [email protected].
- Right to rectification (Article 16): You may request correction of inaccurate data we hold. Profile data (age, weight, height, etc.) is stored in your Garmin profile and can be corrected directly in Garmin Connect.
- Right to erasure (Article 17): You may request deletion of personal data we hold. We hold none. To request deletion of data sent to an AI provider, contact that provider directly.
- Right to restriction of processing (Article 18): You may request that we restrict processing of your data. You can achieve this immediately by removing the App or clearing your API key.
- Right to data portability (Article 20): You may request a machine-readable copy of personal data you have provided to us. We hold no such data.
- Right to object (Article 21): You may object to processing based on legitimate interests. We do not rely on legitimate interests as a legal basis for processing health data.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time by removing the App or clearing your API key. Withdrawal does not affect prior processing.
- Right not to be subject to automated decision-making (Article 22): We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority (see "Supervisory Authorities" below).
Switzerland (nFADP)
If you are located in Switzerland, you have rights under the revised Federal Act on Data Protection (nFADP) equivalent to those described above for EEA users, including the right of access, rectification, erasure, and the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.
United States
Depending on the state in which you reside, you may have the following rights:
- California (CCPA/CPRA): California residents have the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information. To submit a request, contact [email protected]. For data held by AI providers, contact those providers directly.
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other state privacy laws: Residents of these states have rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising and the sale of personal data. We do not conduct targeted advertising or sell data. Requests can be submitted to [email protected].
- Health data: In states where biometric or health data receives heightened protection (including Washington, Illinois, and Texas), we note that health and biometric data processed by the App is transmitted directly from your device to your chosen AI provider and is never received or held by us.
Brazil (LGPD)
If you are located in Brazil, you have rights under the Lei Geral de Protecao de Dados (LGPD), including the right of access, correction, anonymisation or deletion, portability, information about sharing, and the right to revoke consent. Because we hold no personal data, most requests will need to be directed to your chosen AI provider. You may contact us at [email protected] for any questions. You also have the right to file a complaint with the Autoridade Nacional de Protecao de Dados (ANPD).
Canada (PIPEDA and Quebec Law 25)
If you are located in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, if you are in Quebec, under Law 25 (Act respecting the protection of personal information in the private sector). These include the right to access personal information we hold about you and to challenge its accuracy. Because we hold no personal data, requests should be directed to your AI provider. Contact us at [email protected] with any questions or to request our privacy practices documentation.
Australia (Privacy Act 1988)
If you are located in Australia, you have rights under the Privacy Act 1988 and the Australian Privacy Principles (APPs), including the right to access and correct personal information held about you. Because we hold no personal information, access and correction requests should be directed to your chosen AI provider. You may contact us at [email protected]. You also have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Japan (APPI)
If you are located in Japan, you have rights under the Act on the Protection of Personal Information (APPI), including the right to disclosure, correction, and suspension of use of retained personal data. We hold no retained personal data. Contact us at [email protected] for any questions.
South Korea (PIPA)
If you are located in South Korea, you have rights under the Personal Information Protection Act (PIPA), including the right to access, correct, delete, and suspend processing of personal information. We hold no personal information. Contact [email protected] for any questions or to reach our designated personal information protection officer.
India (DPDP Act 2023)
If you are located in India, you have rights under the Digital Personal Data Protection Act 2023, including the right to access information about personal data processed, the right to correction and erasure, and the right to grievance redressal. We hold no personal data. Contact us at [email protected] for any questions.
South Africa (POPIA)
If you are located in South Africa, you have rights under the Protection of Personal Information Act (POPIA), including the right to access, correct, and object to the processing of personal information. We hold no personal information. You may contact us at [email protected] or lodge a complaint with the Information Regulator at inforegulator.org.za.
Singapore (PDPA)
If you are located in Singapore, you have rights under the Personal Data Protection Act (PDPA), including the right to access and correct personal data held about you. We hold no personal data. Contact us at [email protected] for any questions.
New Zealand (Privacy Act 2020)
If you are located in New Zealand, you have rights under the Privacy Act 2020, including the right to access and correct personal information held about you. We hold no personal information. You may contact us at [email protected] or lodge a complaint with the Office of the Privacy Commissioner at www.privacy.org.nz.
Your Controls
You have full control over the App's behavior through the settings in Garmin Connect:
- AI Provider and Model: Choose between OpenAI, Anthropic Claude, and Google Gemini and select the specific model
- API Key: Enter, update, or clear your API key at any time. Clearing your key stops all data transmission to AI providers immediately.
- Session Goal: Optionally provide a free-text goal that is included in AI prompts
- Coaching Triggers: Enable or disable individual triggers such as workout start, milestones, heart rate alerts, pace drop, and sustained effort
- Periodic Check-in: Set the interval for proactive AI check-ins, or disable them entirely
- Coaching Style and Recovery Focus: Adjust how aggressively the AI coaches and how much weight it gives to recovery signals
- Cooldown Period: Set the minimum time between coaching cues
- Response Length: Choose between short, normal, and long coaching cues
- Session Memory: Enable or disable session history so the AI can avoid repeating recent cues
Uninstalling the App from your Garmin device removes all locally stored settings, including your API key, and stops all processing immediately.
Third-Party Services
CoachPulse runs on the Garmin Connect IQ platform. Your use of a Garmin device is subject to Garmin's Privacy Policy. We are not responsible for data collected by Garmin independently of the App.
All AI provider integrations are initiated by you through your own API keys. The data included in each AI request is described in the "Data Sent to AI Providers" section above. We act as a data processor only in the sense that we write the software that constructs the prompt; we never receive, store, or have access to the data itself.
Supervisory Authorities
If you believe your data protection rights have not been respected, you have the right to lodge a complaint with the relevant supervisory authority in your country. Key authorities include:
- Croatia (our home authority): Agencija za zastitu osobnih podataka (AZOP) - azop.hr
- European Union: The data protection authority in your EU member state of residence
- United Kingdom: Information Commissioner's Office (ICO) - ico.org.uk
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) - edoeb.admin.ch
- Brazil: Autoridade Nacional de Protecao de Dados (ANPD) - gov.br/anpd
- Australia: Office of the Australian Information Commissioner (OAIC) - oaic.gov.au
- South Africa: Information Regulator - inforegulator.org.za
- New Zealand: Office of the Privacy Commissioner - privacy.org.nz
- Canada: Office of the Privacy Commissioner of Canada - priv.gc.ca
- Singapore: Personal Data Protection Commission - pdpc.gov.sg
Children's Privacy
The App is not directed at children. The minimum age to use the App depends on your country of residence:
- European Economic Area and UK: You must be at least 16 years old, or have verifiable parental consent if you are between 13 and 16, in accordance with GDPR Article 8.
- United States: You must be at least 13 years old in accordance with the Children's Online Privacy Protection Act (COPPA). Some US states may set a higher threshold.
- All other countries: You must meet the minimum digital consent age established by your country's applicable law, which is typically between 13 and 16 years of age.
We do not knowingly collect or process personal information from children below the applicable minimum age. If you believe a child below the applicable age has used the App, please contact us at [email protected] and we will take appropriate steps, which may include notifying the relevant AI provider.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App, applicable law, or our practices. Changes will be reflected on this page with an updated effective date. For material changes, we will make reasonable efforts to notify users, for example by updating the App listing on the Garmin Connect IQ Store. We encourage you to review this page periodically. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a concern about how your data is handled, please contact us:
- Email: [email protected]
- Data Controller: Nioquant, obrt za usluge, vl. Fran Čudina
- Address: Zagreb, Štefanićeva ulica 1, Croatia
We aim to respond to all privacy-related enquiries within 30 days. If your request relates to data held by an AI provider (OpenAI, Anthropic, or Google), we will direct you to the appropriate contact at that provider.