Training Dashboard
Privacy and Health Data Notice
Version 2026-09-06 ยท Effective September 6, 2026
This update adds optional shoe inventory and confirmed mileage, read-only sharing with currently authorized coaches, and optional full-text device notification previews. It does not expand which coaches may access your data or turn on device notifications automatically. Read the previous notice.
Training Dashboard is a private team beta offered through runtrainingdashboard.com ("Training Dashboard," "we," "us," or "our"). This notice explains what information the service collects, why it is used, who may receive it, how long it is kept, and how a beta participant may exercise privacy rights.
Scope and eligibility
This beta is limited to individually approved team participants. Access is personal and may be revoked by the application administrator.
Information we collect
- Account and access information: Supabase user ID, Google-authenticated email, display name, profile image when available, beta membership, access requests, legal acceptance records, and account status.
- Training and competition information: workouts, dates, mileage, sessions, splits, race plans, athlete notes, and coach session notes.
- Shoe information: shoe brand, model, nickname, first-use date, opening mileage, replacement milestones, status, and athlete-confirmed mileage allocations and usage dates.
- Athlete-reported health and wellness information: readiness scores and inputs, pain and injury concerns, body locations, illness responses, soreness, sleep, energy, stress, mood, nutrition adequacy, recovery responses, and free-form readiness notes.
- Coach and team information: coach applications and roles, head-coach and assistant-staff assignments, coach-athlete relationships, documented coach and program-staff authorizations, team groups, assignments, and Sheet mappings.
- Google integration information: connected-account identity, selected file and worksheet identifiers, mapping and sync status, server-held authorization tokens, and values in the managed A-D training range when an entitled coach enables the integration.
- Optional reminder information: whether readiness reminders are enabled, the selected reminder time, the device time zone, and encrypted browser push-subscription delivery information for each registered device.
- Technical and request information: account-scoped browser cache, authentication and synchronization events, rate-limit and security records, error diagnostics, data exports, and privacy-request status.
How health and training information is used
Training Dashboard uses athlete-entered information to show the athlete's own dashboard, organize training, calculate and display readiness summaries, identify reported concerns for review, support coach planning, and operate authorized Sheet synchronization. Readiness is a communication aid. It is not medical care, diagnosis, treatment, injury clearance, or emergency monitoring.
The service does not sell personal or health information, use it for targeted advertising, or use it to train generalized artificial-intelligence models.
Coach access and separate authorization
A coach does not receive athlete dashboard or health information merely because a button is visible. A head coach must be approved, the relationship must be accepted, both accounts must have active beta access, and a current documented authorization must exist. An assistant additionally requires an active Admin-assigned staff relationship to that head coach's program.
Existing accepted beta relationships may use a scoped grandfathered operator record after participants receive notice of the updated Terms and this Notice. Future relationships require a separate in-app authorization that identifies the head coach by account email, covers current or future Admin-assigned assistants in that program, and describes the information categories and coaching purpose. The authorization remains active until the athlete withdraws it or the head-coach relationship ends. The athlete may review the authorization source and history in a personal data export and may withdraw it from Settings. Withdrawal immediately ends the head-coach relationship, blocks the head coach and program assistants, removes the athlete from that program's team groups, and deactivates the related Sheet source. Withdrawal does not erase prior records; deletion may be requested separately.
Shoe inventory and athlete-confirmed shoe mileage are treated as training information. Each currently authorized coach may view this information read-only and may use independent coach-wide replacement milestones. Team-group membership changes filtering only and does not grant access.
Google user data
Google Sign-In supplies identity information used for authentication. The optional Google Sheets integration is available only to an approved, individually entitled coach and requests drive.file access to files that coach selects through Google Picker. It does not provide access to the coach's entire Drive.
For an activated worksheet, Training Dashboard may read and write managed dates, weekly mileage, workout sessions, and athlete-note cells. App saves may send supported changes to the Sheet; Sheet changes enter the app only through an authorized Refresh. The service does not delete the spreadsheet, worksheet, unrelated cells, or file-sharing permissions.
Google tokens remain server-side and are not returned to athletes or browser code. Training Dashboard's use and transfer of Google API information follows the Google API Services User Data Policy, including Limited Use.
Who receives information
Information may be disclosed to the participant, the athlete-authorized head coach and current Admin-assigned assistants in that program, the active application administrator when needed to operate requests and access, and vendors that host or authenticate the service. Current vendor categories include Supabase for authentication and database services, Vercel for web hosting and delivery, and Google for sign-in and the optional selected-file integration. Information may also be disclosed when required by law or reasonably necessary to protect users and the service.
Device notifications and readiness reminders
General device notifications are optional and are not enabled merely because a device was previously registered for readiness reminders. When a signed-in user explicitly enables general notifications, new in-app bell notifications may also be delivered to that device. Push previews use the full bell title and message and may therefore appear in full on a device lock screen. Users should consider device privacy before enabling them.
Readiness reminders are optional and remain disabled until an athlete enables notifications on a device. When enabled, Training Dashboard may send one generic notification after the selected local reminder time only when that day's readiness check is still missing. Notification content does not include readiness answers, scores, pain information, notes, or other health details.
The selected time follows the stored IANA time zone, which the app refreshes from the signed-in device. Athletes may change the time or disable reminders in Settings. Coaches may set a team default for athletes assigned to them; a later team-default update replaces those athletes' reminder times, which athletes may subsequently edit again.
Stored push-subscription endpoints and delivery keys are encrypted and available only to server-side notification services. Normal sign-out pauses notifications for the signed-out account on that device; signing back into the same account resumes its registration. If the pause cannot be confirmed, the browser unsubscribes instead. Removing a device in Settings removes that account's registration without affecting its other devices or another account's registration on the same device. The physical subscription is removed when its final account registration is removed. Revoked application access stops notification delivery.
Storage and security
Training Dashboard uses database row-level access controls, server-side authorization checks, encrypted network transport, account-scoped browser storage, restricted Google tokens and encrypted push-delivery credentials, security headers, and operational logging. Google tokens and push-delivery credentials remain server-side and are not returned to browser clients. Explicit sign-out and account switching clear the signed-in account's private dashboard cache from that browser. No storage or transmission method can be guaranteed completely secure.
If you believe information was accessed or disclosed without authorization, stop entering new information and contact jpcuber8@gmail.com promptly. Training Dashboard maintains an incident-response process for containment, investigation, documentation, and legally required notice.
Retention
- Active account, training, shoe inventory and mileage, readiness, notes, races, and settings: retained while the account participates in the beta. After a verified deletion request or permanent beta closure, primary records are targeted for deletion within 45 days unless a specific legal, safety, fraud-prevention, or dispute-preservation need requires longer retention.
- Revoked accounts: private dashboard data is preserved for possible reinstatement for up to 90 days, then reviewed for deletion unless the participant requests earlier deletion or retention is required.
- Google connections: active while connected; server-held tokens are removed on disconnect. Inactive mapping and synchronization records are reviewed within 90 days.
- Legal acceptances, coach authorizations, privacy requests, and security records: retained for up to four years after account closure or the relevant authorization ends so Training Dashboard can document instructions, consent, requests, and security events.
- Rate-limit and routine diagnostic records: retained no longer than 90 days unless attached to a security investigation.
- Provider backups: deleted primary data may remain temporarily in restricted backups until the provider's configured recovery window expires. Backups are used only for disaster recovery; if deleted data is restored, it is deleted again from the restored primary system.
Your choices and requests
From Settings, an authenticated user may download a structured copy of dashboard data, withdraw a coach authorization, or submit an access, export, correction, deletion, or health-consent request. Requests may also be sent to jpcuber8@gmail.com. Do not email health details.
We may verify identity through the authenticated account and may request a limited additional confirmation before disclosing or deleting information. Requests are tracked and targeted for response within 45 days. If more time is reasonably necessary, the participant will be told why and given a revised date. A denied request will include a reason when legally permitted; the participant may ask for reconsideration by replying to the decision email.
Browser signals and third-party collection
Training Dashboard does not use cross-site advertising cookies or permit third parties to collect activity over time across unrelated websites for advertising. Because the service does not perform that tracking, it does not change behavior in response to a browser Do Not Track signal. Essential authentication, security, and hosting providers may receive ordinary request information needed to provide their services.
Changes to this notice
Material changes receive a new version. Newly approved participants must acknowledge the current version. Existing approved participants may receive an in-app update notice, and Training Dashboard may require renewed acceptance when a later change warrants it.
Contact
Service: Training Dashboard. Privacy, support, and data requests: jpcuber8@gmail.com.