Quantified Self   10.15.0Home
Compare Files
Membership
Login
Preferences

Legal & Privacy

Transparency about how we handle your data, your rights, and our terms of service.

Connected Services, AI & Third-Party ProcessingDisclosures for connected fitness services, user-authorized MCP clients, the built-in Assistant, infrastructure, payments, and analytics.
Training workout delivery: Manual plans and standalone workouts are stored beneath your account. Workout delivery to Garmin, Suunto, and Wahoo is available to connected Pro users; new COROS plan sync and standalone Send actions are currently marked Coming soon in the app. Every available destination requires explicit opt-in. Delivery sends the workout recipe, title and scheduled date in your saved delivery time zone to the selected connected provider. Quantified Self retains delivery preferences, compatibility approvals and private operation/artifact records so edits, retries and removal can be reconciled safely. Use Stop sync before disconnecting to request eligible future-copy removal. Explicit disconnect invalidates delivery consent but may leave provider-held copies; Pro expiry preserves preferences and copies while pausing changes. Account deletion fences new delivery and recursively removes local delivery records and jobs, but cannot guarantee removal of copies already held by a provider after access is revoked.
Private Timeline notes: Notes you create about sickness, injury, vacation, travel, stress, or other context are stored beneath your account with calendar dates, the captured time zone, and revision timestamps. They appear only in your authenticated Health, Sleep, and Training views and do not change measurements or scores. Text is not sent to providers, analytics or public shares. Full titles/details, including chart-hidden notes, may be sent to an MCP client only with the separate Timeline notes grant, or to Gemini only when you enable Timeline notes for the active Assistant chat. A separate MCP change grant can authorize an external client to create, edit, or permanently delete notes through that client's approval controls. In the built-in Assistant, a separate default-off note-change choice gives Gemini only current-note lookup and prepare-only tools; the signed-in user must review and apply the proposal in Quantified Self. This may contain sensitive health or personal information. Chart visibility is display-only; revocation cannot erase copies already received by an external client. Deleting a note removes its content and retains only a content-free deletion receipt to prevent delayed retries from recreating it. Disconnecting a service retains notes; account deletion recursively removes notes and receipts.
What this section covers: This page explains what connected-service data Quantified Self collects, how it is used inside the product, what may be stored for exports, reprocessing, and sync tools, and which third parties process that data.
Storage location: Imported provider data, saved route metadata, source-file references, and related processing metadata are stored in Quantified Self infrastructure on Google Cloud in the EU region.
User-initiated sharing: When you use features such as history import, FIT/GPX uploads, sending routes, or activity sync to Suunto, Wahoo, or COROS, Quantified Self must send the activity, route, or related data needed by the destination provider.
Provider echo protection: Before sending an activity to a connected provider, Quantified Self stores server-only hashes of the exact file and selected semantic FIT fields, plus destination routing metadata. These records do not contain the activity file, are used to prevent a provider-returned copy from creating another event or fan-out, and expire after about 120 days.
Manual Health measurements: You can add, edit, and delete Weight, VO₂ max, body fat, blood pressure, muscle mass, body water percentage, bone mass, and blood oxygen (SpO₂) measurements in the authenticated Health workspace. Blood pressure stores systolic and diastolic together with any pulse you choose to include; editing or deleting it affects that complete measurement. They are stored in your owner-scoped Health history with Quantified Self as the source, the observed time and timezone offset, and—for VO₂ max—the context and method you select. Manual values remain separate from provider and workout series. Account deletion removes them with the rest of your Health history.
Workout context in Health: When you select Weight or VO₂ max in the authenticated Health workspace, Quantified Self can read those values on demand from workouts already imported into your account. Workout Weight is labelled as profile context rather than a weigh-in and appears only when the active provider-filtered view has no provider or manual Health Weight; it is never plotted as a weigh-in. Workout VO₂ max remains separate by provider, local account label, and discipline and is not merged with provider Health or manual values. These reads do not copy workout values into Health storage, and their bounded response excludes workout identifiers, names, locations, provider account IDs, and raw creator details.
AI scope: Connected-service data is not forwarded wholesale to AI providers. The built-in Assistant sends Gemini the message you submit, the browser's IANA timezone for local-day context, bounded recent conversation context, and bounded validated results selected through Quantified Self's MCP tools. The Assistant is coordinate-free by default. If you explicitly start a fresh chat with Precise activity locations enabled, selected activity-tool results may also send Gemini exact activity start/end and MTB jump coordinates, bounded activity-chart breadcrumbs, plus nearby activity results during that chat. Separately enabled Training, activity-tag, and Timeline-note changes expose only bounded prepare tools to Gemini; Gemini cannot apply them, and Quantified Self requires your app-owned confirmation. Changing access starts another fresh chat, and New chat returns optional access to off. Gemini may select only a server-advertised visual source and safe series keys; Quantified Self deterministically constructs any stored chart values, map coordinates, labels, and renderer settings from the validated result. Coordinate-free saved-route summaries may be selected for route questions; their route names can contain user- or provider-assigned place information. Direct in-app URLs are withheld from Gemini, and an answer that repeats an opaque reference or cursor is rejected. Saved-route bounds, route geometry, waypoints, direct write tools, dashboard settings, and original uploaded source files remain unavailable to the Assistant.

Garmin Data

Garmin activity, Sleep, Health, route delivery, and provider sync workflows.

Collected from Garmin: When you connect Garmin, Quantified Self can import Garmin activities, request activity, Sleep, and Health history, receive Garmin Sleep updates, and import available Daily, Stress Details, HRV, User Metrics, Body Composition, Pulse Ox, All-day Respiration, Blood Pressure, Skin Temperature, and Health Snapshot summaries when Garmin grants Health Export permission.
Stored and used in Quantified Self: Imported Garmin data is used for dashboard, event analysis, Sleep views, the authenticated Health workspace, and related summaries. Wellness measurements are stored as normalized source-attributed Health records and bounded sample chunks, separate from workout metrics and Sleep sessions; missing values remain missing and Garmin Body Battery remains provider-specific. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. Short-lived Garmin pull callback URLs are retained only on retryable live queue work, removed after every terminal queue outcome, and excluded from failed-job copies. Quantified Self may retain original activity files or equivalent source-file metadata when downloads, exports, reprocessing, or syncing past activities require them.
Disconnect and deletion: Disconnecting Garmin stops future activity, Sleep, and Health imports but retains data already imported into Quantified Self. Deleting your Quantified Self account removes the Garmin connection, imported user-scoped Sleep and Health records, sample chunks, sync state, and associated operational queue work.
Shared with Garmin: You can send a saved route or explicitly select a GPX/FIT route file in Garmin Services. Quantified Self parses the selected route and creates a Garmin Connect course. Direct selected-file delivery does not create or retain a Quantified Self route or Garmin delivery metadata.
Shared with connected destinations from Garmin: If you turn on an automatic Garmin activity route or choose to sync past activities, Quantified Self uses the original activity file already saved with the event to send it to the selected supported destination: Suunto, Wahoo, or COROS. Each direction is opt-in and a date-range backfill does not enable future delivery.

Suunto Data

Suunto activity, sleep, 24/7 Health, route import, FIT upload, and activity or route delivery workflows.

Collected from Suunto: When you connect Suunto, Quantified Self can import Suunto activities and history, sync recent sleep data, import sleep history, and automatically import new or updated Suunto routes into your saved Routes list. Connected accounts can also import available 24/7 Activity, daily-statistics, and Recovery measurements such as heart rate, HRV, SpO2, altitude, steps, energy, Body Energy Balance, and StressState.
Stored and used in Quantified Self: Imported Suunto data is used for event analysis, route detail views, dashboard summaries, sleep views, the authenticated Health workspace, and saved route management. 24/7 values are stored as normalized source-attributed Health records, separate from workout FIT metrics and Sleep sessions; raw Health webhook samples are not stored. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. Connection metadata and processing metadata are also stored so reconnect, dedupe, bounded refetch, and refresh workflows can work reliably.
Disconnect and deletion: Disconnecting Suunto stops future activity, Sleep, route, and Health imports but retains data already imported into Quantified Self. Deleting your Quantified Self account removes the Suunto connection, imported user-scoped Sleep and Health records, and associated top-level operational queue work.
Shared back to Suunto: When you upload FIT activities or send a saved or selected GPX/FIT route to Suunto, Quantified Self sends the file or generated GPX route needed for that upload. Suunto receives GPX routes, so selected FIT routes and saved routes are converted to a compatible GPX route in memory; saved routes use the Quantified Self route name. Direct selected-file route delivery does not create or retain a Quantified Self route.
Shared from Suunto to connected destinations: You can opt in to automatic activity delivery or select a past stored date range for Wahoo or COROS. You can separately opt in to new and updated saved Suunto route delivery, or send existing saved routes, to Garmin Connect or Wahoo. Eligible connected Pro users can also select COROS. Quantified Self sends only the retained activity file or saved-route representation required by the selected destination.
Account-scope note: Routes imported from one Suunto account are blocked from being sent back to that same account, but can still be sent to a different connected Suunto account when that workflow is available to you.

COROS Data

COROS activity, daily Health and sleep, activity sync, Training delivery, FIT upload, and GPX/FIT or saved-route delivery workflows.

Collected from COROS: When you connect COROS, Quantified Self can import recent COROS history, sync sleep summaries, and store available daily Health metrics: steps, COROS's provider calorie value, resting and sleep heart rate, overnight HRV, and detailed HRV samples with an interval mean heart rate when COROS supplies it. Missing or unsupported values remain unavailable rather than becoming zero.
Stored and used in Quantified Self: Imported COROS activities and normalized Sleep sessions support dashboard metrics, event analysis, the authenticated Health workspace, and provider-specific history tooling. Daily measurements are also stored as source-attributed Health records for the unified Health model. Aggregate sleep duration, resting or sleep heart rate, and overnight HRV remain in the Sleep session and are referenced from Health instead of copied. Detailed HRV samples from new COROS responses are stored in bounded server-written Health sample records and are not duplicated in Sleep; recoverable legacy Sleep copies can remain until the guarded migration completes. Health displays providers and connected accounts separately, replaces opaque account keys with local account ordinals, and does not save a preferred source or calculate a cross-provider average. COROS's calorie field remains provider-native because the API does not define a safe canonical conversion. Quantified Self may retain original activity files or equivalent source-file metadata when later downloads, exports, reprocessing, or sync tools depend on them. One provider account identifier is stored as the active COROS connection so imports and deliveries do not silently switch between accounts. Private Training delivery records retain collision-checked partner workout identities and batch outcomes; browser and MCP responses do not expose those identifiers. An exact returned COROS planWorkoutId can link an imported activity to one account-bound scheduled workout and protect that copy from later automatic removal.
Disconnect and deletion: Disconnecting COROS stops future daily Health and sleep imports but retains already imported records. Deleting your Quantified Self account recursively removes the COROS connection, Sleep sessions, Health records and sample chunks, and imported data under your user record; account-deletion cleanup also removes associated top-level operational queues.
Shared back to COROS: You can send a selected FIT activity, automatically send new Garmin/Suunto/Wahoo FIT activities, or send a selected past date range already stored in Quantified Self. Eligible connected Pro users can also send a selected GPX/FIT route, a saved route from Routes, or opt in to new/updated or existing saved Suunto route delivery. New COROS Training plan sync and standalone Send actions are currently labelled Coming soon in the app. Existing saved COROS delivery state may continue to send the workout recipe, title and scheduled date according to its consent; delivery records, copy status, retry, per-workout exclusion and Stop sync remain available. COROS app/watch synchronization is controlled by COROS and a provider acceptance is not a watch receipt. Selected route files are parsed and converted to GPX in memory and do not create a Quantified Self route; saved routes retain provider delivery metadata for deduplication and status.
Shared with Suunto or Wahoo from COROS: If you turn on a supported automatic COROS activity route or choose to sync past activities, Quantified Self uses the original activity file already saved with the imported event to send it to the selected destination. Each automatic direction is off by default.
Echo protection: Activity delivery writes short-lived, server-only exact-file and semantic FIT fingerprints before sending. If COROS later returns a matching activity, Quantified Self acknowledges the echo without storing a duplicate event or starting another provider fan-out. The fingerprint records contain hashes and routing metadata rather than the source file and expire after about 120 days.

Wahoo Data

Wahoo OAuth, webhook, FIT activity and GPX/FIT course/route delivery, Training workout delivery, and history-import workflows.

Collected from Wahoo: When you connect Wahoo, Quantified Self can receive completed workout-summary webhooks and request Wahoo workout history. Only workouts with an available FIT file are imported, and records identified by Wahoo as originating from third-party fitness applications are skipped.
Stored and used in Quantified Self: Imported Wahoo FIT activities, source identifiers, summary revision metadata, and original activity files are used for event analysis, dashboard metrics, exports, deduplication, and reprocessing. Wahoo does not currently supply daily wellness records for Health. If an imported Wahoo workout contains Weight profile context or an activity-level VO₂ max estimate, the authenticated Health workspace can read that value on demand under the workout-context boundary above; it is not stored as a Health record. OAuth credentials are stored server-side and are not readable by the browser.
Disconnect and retention: Disconnecting Wahoo revokes future provider access and stops new imports. Activities already imported into Quantified Self are retained until you delete those activities or delete your account. Account deletion removes Wahoo tokens, queue state, and imported account data under the normal deletion workflow.
Shared with Wahoo: You can explicitly send a selected FIT activity file or GPX/FIT course/route file directly to Wahoo, turn on/send a date range for Garmin, COROS, or Suunto activities already stored in Quantified Self, or opt in to automatic/backfill delivery of Suunto routes already saved in Quantified Self. Quantified Self converts selected GPX routes to FIT in memory before sending them to Wahoo, and converts saved Suunto routes to FIT in memory for the same destination. Saved-route delivery uses an opaque stable key so an updated saved route updates the same Wahoo route. Direct Wahoo activity delivery does not create or retain a Quantified Self activity; direct course/route delivery does not create or retain a Quantified Self route.
Training shared with Wahoo: Connected Pro users can explicitly enable plan sync or send a standalone workout. Quantified Self sends the authored workout recipe, title and scheduled date to Wahoo as an app-owned Plan and dated Workout. Provider identifiers and operation receipts are retained server-side for safe updates, duplicate recovery and removal. Cloud checks confirm the Plan, Workout and association, not receipt by a Wahoo app, ELEMNT computer or watch. This does not import Wahoo-owned plans or grant assistants permission to send workouts.
Shared from Wahoo: You can turn on or backfill Wahoo-to-Suunto or Wahoo-to-COROS activity sync. Quantified Self sends the retained original FIT file from a Wahoo-imported event only after you enable or start that route.
Outbound boundaries: Suunto-to-Wahoo saved-route delivery is a separate opt-in route workflow in Suunto Services; direct GPX/FIT course/route delivery is a separate Wahoo-only upload. Plans, sleep, and other non-activity data are not sent between Wahoo and another provider. Existing Wahoo connections may need to be reconnected to grant workout and route access for delivery to Wahoo.

MCP Client Access

Permission-scoped metric, body-measurement, activity-detail, sleep, saved-route, full private Timeline note text, location access, and focused note, tag, or Training changes approved by the account owner.

Personal HRV range: When both Health metrics and Sleep summaries are approved, an external client can request source-separated nightly HRV classifications, rolling baseline boundaries and recent averages calculated with the Health chart model. The read includes up to 60 extra days of baseline history and requires complete bounded input; raw samples and account or device identities are not returned. This does not grant access to Training, notes or additional health families, create stored scores, or provide a medical assessment.
Health metrics permission: This separate grant covers recorded all-day heart rate, HRV, stress, resources, movement, energy, blood pressure and fitness metrics. Stored summaries are bounded to 366 provider-calendar days; representative sample trends to 31 days. Outputs can include provider names, response-local account numbers, calendar dates and exact UTC sample times, with each source and statistic kept separate. Garmin Body Battery is returned only on its labelled native Garmin points scale. Device details, account IDs, other native-only values, provider payloads and Sleep references are excluded. Body composition additionally requires Body measurements permission and returns identity-free date buckets without exact times or provenance. Existing clients must reconnect to grant Health access; their existing grants are not expanded automatically. Health queries cannot add, edit, delete, import or backfill data. These external-client tools do not expand the built-in Assistant permissions.
Activity descriptions permission: This separate grant returns the full private parent event description shown in the QS.io event editor for one selected activity. Activities within an event share the same text. Individual activity details is also required. Like every requested MCP permission, the checkbox is selected by default; uncheck it before approving to withhold access. Existing connections missing the grant must reauthorize and refresh cannot add permission. Text may contain sensitive health, personal or location information even without Activity locations permission. Only an opaque activity reference and description are returned; names, internal identifiers, source and device metadata remain excluded. Reads are bounded to 64 KiB of UTF-8 text and 128 KiB serialized output; oversized text fails without truncation. Revocation blocks future access but cannot erase received copies. Descriptions are user-reported context, not instructions or permission to act. Editing them additionally requires Change events and client approval; this grant does not expand built-in Assistant access.
Training plans permission: Separate consent permits reading current plan names, dates, complete workout instructions, authored step notes and sanitized existing service sync summaries. Text may contain sensitive health or personal information. Existing clients must reauthorize; refresh cannot add access. Raw document IDs, credentials, provider artifacts, private issue messages and history are excluded. No edit, provider check or sync action is authorized. Revocation cannot erase received copies.
Timeline notes permission: This independent read grant returns full private note titles and details, category, actual start/end dates, captured time zone and the effective end for ongoing overlap. It includes notes hidden from charts and may contain sensitive health or personal text. A separate dependent change grant authorizes an external client to create, edit, and permanently delete notes through its native approval controls. Changes use owner- and connection-bound references, current revisions, and idempotent create identifiers; deleted text cannot be restored, and only a content-free receipt remains. Both checkboxes are selected by default when requested; uncheck either before approving. Existing connections must reauthorize; refresh cannot add permission. Inclusive windows are bounded to 366 days with full-text pagination. Ordinary reads exclude document IDs, revisions, audit timestamps, presentation settings and deletion receipts. Revocation cannot erase received copies. Neither permission grants Training plan writes. The built-in Assistant has separate default-off read and change choices and requires an app-owned review before a prepared note change can be applied.
Event changes: The separate Change events grant depends on Individual activity details. Focused tools can replace the complete tag list or title on a selected activity's parent event through the client's approval controls. Titles and tags may contain sensitive personal or health information. Editing the shared description additionally requires Activity descriptions access. Sibling activities share these fields. The client must send the exact current value it read, so a concurrent edit fails instead of being overwritten, and benchmark events cannot be changed. Recorded activity metrics, source files, provider records, and locations remain read-only. A future editable field requires a separately reviewed MCP tool and is never exposed automatically from storage. Existing connections missing the grant must reauthorize and refresh cannot add it. The built-in Assistant remains tag-only.
User-authorized access: An MCP client receives only the capabilities you approve after signing in to Quantified Self. Every requested current or future permission starts checked; uncheck anything you do not want to grant. Activity locations and event changes depend on activity details, Timeline-note changes depend on Timeline notes, saved-route locations depend on saved-route summaries, and either Training write permission depends on Training plans read access. Removing a parent removes its dependent permissions. MCP cannot write recorded activity data, routes, dashboard settings, body measurements, Health, or sleep records. Timeline-note and event changes require separate grants and the MCP host's native approval controls. Training plan/workout and delivery changes additionally require a bounded preview and separate apply tool.
Training planning changes: Training plans and planned workouts read access can return authored names, dates, notes, complete recipes, exact stored completion links, and sanitized service status. Training plan and workout changes separately allow a bounded lifecycle including explicit plan deletion. Plan deletion is reviewed alone, requires choosing whether its workouts become standalone or are permanently deleted, and permanently removes the plan and its history. Permanent single-workout deletion and history restoration remain unavailable. Training provider delivery changes separately allow plan opt-in and workout send, resume, stop, retry, verification, or compatibility approval; provider delivery remains Pro, connection, compatibility, horizon, and rollout gated. A client can only preview up to 25 strict changes before invoking a separate write tool governed by the MCP host's approval controls. Proposals bind the owner, client connection, current permission grant, schedule revision, and short expiry. Provider results are independent, so a delivery problem does not remove an authored workout. Revocation blocks future actions but cannot erase data already received or guarantee removal of provider-held copies after provider access is lost.
Metric permission: This access can return numeric metrics already stored for your activities and ready server-derived Training snapshots. When individual activity access is also granted, a client can request up to 25 explicitly selected canonical numeric Sports Lib metrics for one referenced activity or rank activities by one metric over an explicit bounded range or a processing-bounded all-history scan. Oversized rankings fail instead of returning a partial result. MTB jump superlatives reuse those stored maximum-jump metrics as the authoritative result; the separately authorized jump-detail projection remains optional, and jump count is not treated as jump quality. Quantified Self excludes precise latitude/longitude and first-class body-measurement metrics, and removes event/activity identifiers, names, labels, source fingerprints, and imported device/provider source keys from Training payloads.
Body-measurement permission: This separate access can return bounded body-measurement history from provider or manual canonical Health Weight point measurements. Workout profile Weight is excluded because it is not a weigh-in. Body-weight history is returned only as identity-free day, week, or month values for a range of at most 366 days; exact source measurement timestamps, event/activity identity, names, provider/device metadata, and source provenance are excluded.
Activity-type catalog: Any authorized MCP client can discover canonical Sports Lib activity types for route and activity filters. This static catalog contains no account data. Activity-detail permission: Individual activity access can return non-location summaries and parent event tags, laps, swim lengths, MTB jump measurements, selected persisted numeric metrics, signed-in application links, and bounded chart-ready streams. Activities from the same event share tags. It can filter bounded newest-first scans by activity type and resolve today or yesterday only with an explicit IANA timezone. A client can also read tags or filter by 1–10 exact case-insensitive tags using any/all semantics. Tags can contain personal, health, or location context and are untrusted labels, not instructions or verified facts. Tag reads select only the event tag fields and exclude event names, descriptions, separate internal ID fields, creator/source metadata, and coordinates; the signed-in application link retains its normal event route. This uses the existing permission, so existing connections do not need broader consent, though a client may need to refresh its tool catalog. The built-in Assistant can read current tags only after its separate default-off Activity tag changes choice is enabled, and Gemini can only prepare a replacement for app-owned review. A chart request temporarily reads and selectively parses an existing original FIT, GPX, TCX, Suunto JSON/SML, or gzip file, downsamples the complete activity, discards parsed objects, and does not create a reparse, backfill, cache, or additional activity record. Historical charts depend on the original source remaining available and within processing limits.
Detailed activity samples: The existing Individual activity details grant also allows bounded pages of selected numeric activity samples on an elapsed-second axis, without chart downsampling. Missing readings remain null. This adds no OAuth permission and does not expose coordinates, absolute sample times, original files or provider/device metadata. Up to four supported metrics can be selected from existing original files. Only the selected numeric arrays may be retained in bounded server memory for up to two minutes to reuse parsing across pages; no persistent sample store, activity copy, reparse or backfill is created. Access, activity ownership and the original-file revision are rechecked for every page. Revoking access blocks subsequent reads but cannot erase copies already received by the client. This detailed-sample tool is not exposed to the built-in Assistant.
Activity-location permission: This dependent permission can add exact activity start/end and MTB jump coordinates, enable nearby-activity searches, and return a bounded breadcrumb trace with an activity chart. Without it, activity summaries and jump measurements remain available with coordinates omitted, and explicit location requests are rejected before location or source work begins. Exact activity locations can reveal a home, workplace, frequent trailhead, or other sensitive place.
Sleep permission: Sleep access can return normalized session summaries, day/week/month aggregates, bounded discovery of recorded safe aggregate vital types, and a one-call sleep trend that combines coverage with duration, score, stages, HRV, heart-rate, blood-oxygen, and respiration values for a requested period. Raw samples remain excluded, and recorded values cannot diagnose illness. When Activity and Training metrics are also approved, the client can request the same live UTC-day Readiness used by Dashboard Today. That result combines current Form/ramp with the latest eligible sleep score and can return the seven-day HRV average and same-source 60-day personal range, the latest nightly HRV, sleep-heart-rate values and their baseline medians, ratios, evidence counts, and explicit missing or insufficient-history states. Current readiness history uses the same calculation and additionally requires Health metrics permission because saved HRV evidence may include overnight Health readings. Registered legacy tools retain their earlier formula. The requested IANA timezone supplies local-day context; it does not change the UTC scoring boundary. The preferred daily report returns the latest completed non-nap sleep with recorded average/overnight HRV and average/minimum sleep heart rate, a same-provider duration comparison, live Readiness, and current-versus-usual equivalent 28-day Training totals and Running/Cycling/Swimming mix. The older compact briefing remains physiology-free for compatibility. These projections exclude provider identity, provider user and session identifiers, provider-specific payloads, raw sleep-stage intervals, score components, raw HRV samples, SpO2 and respiration samples, locations, activities, body measurements, workout plans, and medical advice.
Saved-route summary permission: Saved-route access can return route names, activity types, bounded metrics, route/waypoint/point counts, import/update times, and signed-in application links. It can filter a bounded newest-first scan by canonical Sports Lib activity type or a case-insensitive part of the route name. It omits exact bounds, preview geometry, and waypoint locations.
Saved-route location permission: This dependent permission can add exact geographic bounds, simplified polyline preview geometry and segment endpoints, nearby-route search, and waypoint coordinates, altitude, and distance. Existing clients retain non-location route summaries but must reconnect and approve this permission to regain coordinate-bearing route tools. Activity and saved-route location permissions are independent.
Projection exclusions: Original files, unbounded recordings, unrequested streams, separate internal identifiers, source keys, Storage paths, parser extensions, device identities, waypoint names/comments, links, and delivery metadata are not returned. Activity charts exclude full-resolution recordings and absolute per-sample timestamps. Separately approved Health trends can include UTC sample times and provider names with response-local account numbers; they never include account keys, device details, or provider payloads.
Place-name resolution: Nearby MCP searches can use direct latitude/longitude or a place name. Direct-coordinate searches are processed within Quantified Self. For a place-name search, Quantified Self sends only the location text to Mapbox for forward geocoding; activity data, route data, account identifiers, and unrelated client prompts are not sent to Mapbox for that lookup.
Credentials and retention: MCP bearer and refresh credentials are opaque, stored server-side only as hashes, expire automatically, and are bound to your account and the MCP resource. Approving a request creates pending authorization metadata, but a new connection becomes active and appears in Connections only after the client successfully exchanges its authorization code. Reauthorizing the same exact verified client identity leaves its current grant usable until that exchange succeeds, then replaces the previous permissions and credentials rather than creating another logical connection. Failed or abandoned reauthorization does not replace the current grant, and authorization codes expire automatically. Authorization metadata and active connection metadata are retained so the connection can operate and be audited.
Control and destination: Review or revoke MCP clients under Connections -> MCP. A client can use the standard server-to-server token-revocation endpoint, but it may not notify Quantified Self when removed or uninstalled. Disconnect in Connections remains the authoritative control and immediately invalidates the current grant and any older duplicate records for that exact verified client without affecting other MCP clients. Account deletion removes MCP connection and authorization state. A client may retain data it already received according to its own privacy and retention practices, so authorize only clients you trust.

AI & Third-Party Processing

Infrastructure, billing, analytics, maps, and the current AI provider.

Google Cloud: Quantified Self stores application data, connected-service metadata, and processing state on Google Cloud in the EU region.
Optional Assistant Training planning: Training plans read access and the two child choices for authored changes and provider-delivery changes are default-off and independent of other permissions. Changing one creates a fresh server-owned chat while preserving other choices; New chat resets all optional access and removes a pending proposal. Gemini may receive relevant instructions and sensitive authored names/notes, treated as untrusted context, never authority. Gemini can create only a bounded preview. The proposal is stored with the conversation and only the signed-in user can apply or dismiss it in Quantified Self. Stale tabs, changed permissions, account switches, expiry, or a changed schedule invalidate it.
Optional Assistant tags and notes: Timeline notes, Timeline note changes, and Activity tag changes are off by default. Enabling or disabling one starts a fresh server-owned chat and preserves independently selected optional permissions; note changes require note reads. New chat resets all optional permissions. When relevant, Gemini may receive full private note titles/details, including notes hidden from charts, or the selected activity's current complete tag list. Notes and tags are untrusted user-reported context, not verified diagnoses, causal proof, model instructions, or authorization. Gemini receives only prepare tools for changes. A proposal expires after ten minutes and only the signed-in user can apply or dismiss it in Quantified Self; current references, revisions or tags and access are rechecked before mutation. A note deletion permanently removes its text. Raw tool responses are not stored; answers may quote relevant details, and compact evidence identifies note context and dates under the existing conversation retention policy.
Stripe: Stripe processes subscription and billing data needed to charge, renew, and manage your plan.
Google Analytics: If you consent to analytics cookies, Google Analytics receives anonymized usage analytics used to improve the service. Analytics is optional and can be withdrawn in Settings.
Mapbox: When an authorized MCP client searches by place name, Mapbox is used to resolve the supplied place text and geographic scope. Direct-coordinate MCP searches do not call Mapbox. The built-in Assistant can make the same bounded place-name lookup only after you explicitly enable Precise activity locations for that chat; Quantified Self sends Mapbox only the supplied location text, not the conversation, activity data, or account identity. Separately, when you open an Assistant map, it uses the map style saved specifically for Assistant maps and Mapbox receives the displayed geographic tile area needed to render that map, including when the underlying location came from a direct coordinate rather than place-name geocoding. Its saved-route access remains limited to coordinate-free summaries.
Google GenAI / Gemini: The built-in Assistant uses Google's Gemini models through Google GenAI. Quantified Self sends the message you submit, the browser's IANA timezone for local-day context, at most the latest six completed conversation turns, and bounded validated results selected through Quantified Self's MCP tools for the question. Results are coordinate-free by default. If you explicitly start a fresh chat with Precise activity locations enabled, selected activity-tool results may also send Gemini exact activity start/end and MTB jump coordinates, bounded activity-chart breadcrumbs, and nearby activity results during that chat. Optional Training, activity-tag, and Timeline-note change access gives Gemini only bounded prepare tools; it cannot apply a proposal or call a provider transport. Changing a setting starts a fresh chat; New chat returns optional access to off. Gemini may select only a server-advertised visual source and safe series keys; Quantified Self deterministically constructs any chart values, map coordinates, labels, and renderer settings from the validated result. Coordinate-free saved-route summaries may be selected for route questions, and their route names can contain user- or provider-assigned place information. Direct in-app URLs are withheld from Gemini, and an answer that repeats an opaque reference or cursor is rejected. Original FIT/GPX/TCX/JSON/SML files, saved-route bounds, route geometry, waypoints, direct write tools, and dashboard settings remain unavailable to the Assistant. Text, compact evidence, at most one current Training proposal and one current content proposal, and any bounded chart or map payload share the same server-owned active conversation. It becomes unavailable about seven days after its latest completed turn or reset; a response already in progress can protect an imminent expiry for at most four extra minutes. Firestore TTL then deletes it asynchronously. New chat clears it immediately; account deletion removes it directly.
No hidden provider forwarding: Connected Garmin, Suunto, COROS, and Wahoo data is only sent to destination providers when you explicitly use the related import, upload, delivery, or sync feature. Wahoo delivery is limited to the explicit QS-authored planned-workout, FIT activity, GPX/FIT course/route, opt-in Suunto saved-route, and Garmin/COROS/Suunto-to-Wahoo activity workflows described above.
Privacy PolicyData Security & Ownership
Encryption: Your data are stored and held encrypted by Google (Google Cloud).
Control: Profile and activity visibility is managed by platform policy and is not configurable in the app UI.
Default Privacy: Visibility defaults to private and is only seen by your account unless platform policy changes.
No Data Sales: We do not sell your data. Data is sent outside Quantified Self only when needed for a feature you explicitly use or authorize, such as connected-provider delivery, an approved MCP client, or the bounded Assistant context described below.
Legal Basis: We process your data based on: (a) your consent for optional features like analytics, (b) contractual necessity to provide the service you subscribed to, and (c) our legitimate interest in maintaining service security.
Third-Party Processors and Recipients: Your data may be processed by Google Cloud (hosting and storage in the EU region), Stripe (payments), Google Analytics (only with consent), Mapbox (place resolution for authorized MCP place-name searches and explicitly enabled built-in Assistant activity-place searches), Google GenAI / Gemini (the built-in Assistant using the submitted message, browser timezone, bounded recent conversation context, validated tool results, and—only with the respective per-chat opt-in—precise activity locations, full private Timeline note text, selected activity tags, or a prepare-only content or Training change that still requires app-owned confirmation), connected fitness services you explicitly use, and MCP clients you explicitly authorize. See Connected Services, AI & Third-Party Processing below for details.
Data AvailabilityBackups & Access
Best Effort: While we employ best endeavors, we don't promise to keep your files and data accessible at all times.
Backups: It's best advised to keep your own private copies of critical data.
Portability: You have the right to request an export of your personal data stored on our platform.
Retention: We retain your data while your account is active and has a valid subscription. After a 30-day grace period, plan limits and feature restrictions apply. Existing activities are not automatically deleted due to downgrade alone.
GDPR & Your RightsFor EU/EEA Users
Under the General Data Protection Regulation (GDPR), you have the following rights:
  • Right of Access: You can request a copy of your personal data.
  • Right to Rectification: You can correct inaccurate personal data in your profile settings.
  • Right to Erasure: You can request deletion of your account and all associated data ("Right to be Forgotten").
  • Right to Restrict Processing: You can ask us to limit how we use your data.
  • Right to Data Portability: You can request your data in a structured, machine-readable format.
  • Right to Object: You can object to data processing based on legitimate interests.
  • Right to Withdraw Consent: You can withdraw consent at any time for optional processing (e.g., analytics).

Data Controller: Dimitrios Kanellopoulos, operating Quantified Self
Address: Kaloudi 15
45500 Ioannina
Greece
Contact: privacy@quantified-self.io
Data Location: European Union (Google Cloud EU region)
For privacy inquiries or to exercise your rights, contact us at the email above.

Supervisory Authority: If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. For users in Greece, this is the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.

Cookies & TrackingAnalytics
Google Analytics: With your consent, we use Google Analytics cookies to collect anonymized usage data (e.g., visits by country, active users). Analytics cookies are only activated after you provide consent.
Purpose: This data helps us improve the service and is strictly for internal use. We do not use it for advertising or profiling.
No 3rd Party Access: We don't allow Google or other 3rd parties to access this data for their own purposes.
Essential Cookies: Session cookies used to keep you logged in are strictly necessary for the service to function and do not require consent.
Withdraw Consent: You can withdraw your analytics consent at any time in your account settings.
Terms of ServiceSubscription Policy
Subscriptions & Auto-Renewal: Your subscription will automatically renew at the end of each billing cycle (monthly or yearly) until you cancel. You authorize us to charge your payment method for the renewal term.
Cancellation: You may cancel your subscription at any time through your account settings. Cancellation will take effect at the end of the current billing period, and you will retain access to pro features until then.
Refunds & EU Withdrawal Right: Under EU law, you have a 14-day right of withdrawal for digital services. However, by accepting these terms and gaining immediate access to premium features, you acknowledge that you waive this right of withdrawal. Partial refunds for unused periods are not provided.
Changes to Pricing: We reserve the right to change our pricing. Any price changes will be communicated to you in advance and will take effect at the start of the next billing cycle.
Plan Changes After Cancellation: Upon expiration or cancellation of a subscription, your account moves to the applicable plan limits after any grace period. Stored activities are not automatically deleted due to plan expiration or cancellation. It is still your responsibility to keep your own backups of critical data.
Marketing & UpdatesOptional
Promotional Emails: With your optional opt-in, we may send occasional founder emails about new features, product updates, promotions, and offers. We use your email address and plan to choose relevant recipients.
Unsubscribe Anytime: Turn this off in account settings or use the unsubscribe link in any marketing email without signing in. The link opens a confirmation page; one-click email unsubscribe also works.
Sending Limit: Marketing messages are sent gradually under a daily global limit. Transactional account and subscription messages are separate.