Privacy Policy
Version: 2026-08-31 · Effective from: 31 Aug 2026
Privacy Policy
Last updated: 31 August 2026.
This Privacy Policy explains how Talyvro OÜ processes personal data through the AI Athlete application and related services (the “Service”). It should be read together with the Terms of Service and, where health-related data is processed, the Health Data Processing Consent.
1. Controller and Contact Details
The controller is:
- Talyvro OÜ
- Registry code: 17553163
- Address: Pihlaka tee 11-2, 75312 Peetri alevik, Rae vald, Harju County, Estonia
- General contact: support@ai-coach.ee
- Privacy and data-subject requests: privacy@ai-coach.ee
- Billing: billing@ai-coach.ee
The privacy contact handles data-protection questions and rights requests. If Talyvro OÜ appoints a data protection officer, the officer’s contact details will be published here and notified as required.
We assess privacy risks before introducing material new processing and carry out or update a data protection impact assessment where required by Article 35 of the GDPR.
2. Scope and Adult Users
This Policy applies to account registration, use of the Service, AI-assisted analysis, uploaded material, optional integrations, support, security and billing.
The Service is offered only to users aged 18 or older. The current invite-only onboarding does not support a parent or guardian accepting on behalf of a minor. If we learn that a minor’s data has been collected, we restrict the account and take the deletion or preservation steps required by law.
3. Personal Data We Process
Depending on the features you use, we may process the following categories.
3.1 Account and identity data
Name, email address, password hash, account identifier, role, language, date or year of birth, account status, login and security events, and authentication or recovery information.
3.2 Legacy guardian-authorisation data
The current adult-only flow does not collect new guardian authorisations. If a historical record exists from an earlier controlled flow, it may contain the guardian’s name, email address, relationship, authorisation choices, verification status, timestamps and document version and is restricted according to the applicable retention rule.
3.3 Athlete profile and preferences
Sport, goals, training background, equipment, schedule, planning preferences, competition information and other profile settings.
3.4 Training and performance data
Planned and completed sessions, exercise type, volume, intensity, pace, distance, duration, route, power, heart rate, workload, tests, personal bests, competition history, recovery and subjective feedback.
3.5 Health-related and special-category data
Information that may reveal physical or mental health, including injuries, symptoms, pain, discomfort, fatigue, sleep or recovery notes, wellbeing ratings, body weight, height, body composition, heart-rate zones, VO2max, test results, allergies and other information relevant to training readiness or safety.
3.6 Nutrition data
Food preferences, restrictions, allergies, meal information, nutrition goals, plans and shopping lists where you choose to use those features.
3.7 AI conversations, outputs and transparency records
Prompts, messages, requested analyses, relevant context supplied to an AI provider, generated replies, summaries, recommendations, source references, feedback and limited technical metadata.
To demonstrate AI-transparency compliance, we may also record whether content was generated or materially modified by AI, the relevant system or deployment version, generation time, visible-label or marking version, machine-readable provenance status, whether substantive human review took place, and the version and time of the first-interaction notice shown to the user. These records are not used for advertising.
3.8 Files, archives and videos
Training files, ZIP archives, images or videos, processing results, proxy files, extracted metrics and associated metadata.
3.9 Integration data
Data imported from Garmin, Strava or another integration you choose to connect, together with connection status, provider identifiers and access tokens.
3.10 Billing, payment and tax data
Plan, net price, VAT-inclusive total price, VAT rate and amount, currency and billing period; billing name, address, country and postal code; order, subscription, invoice, credit-note, payment and refund status; amount, payment time and references; Stripe customer, Checkout, subscription, invoice, PaymentIntent, Tax calculation and refund identifiers; payment-attempt and authentication status; and accounting or reconciliation records.
You enter full card numbers, CVC and other sensitive payment credentials directly into Stripe’s interface. Talyvro OÜ does not receive or store full card details. We may receive limited payment-method information such as card brand, last four digits, expiry month/year and the country associated with the payment method or issuer where Stripe makes this available for billing, fraud prevention or tax-location checks.
3.11 Tax-location and OSS evidence
To determine whether a paid transaction is a supported EU Consumer sale, identify the Member State of consumption, calculate VAT and maintain legally required OSS records, we may process:
- the country and Consumer status you declare;
- billing address, billing country and postal code;
- the country associated with the payment method, card issuer, bank account or other payment evidence;
- the transaction IP address and/or the country derived from it;
- the tax location selected by Stripe Tax, the location source and the evidence types used;
- product tax code, tax-registration status, Member State of consumption, VAT rate, taxable amount, VAT amount and currency;
- missing, invalid or conflicting location flags and the result of a manual review; and
- later adjustments, cancellations, credit notes and refunds relevant to the VAT record.
An IP-derived country is approximate. We do not use health, training or coaching data to determine tax location.
3.12 Consent and accountability data
The legal-document version presented, consent and acceptance choices, date and time, method, withdrawal event, guardian authorisation and limited evidence such as IP address and user-agent where proportionate. An IP address or user-agent is supporting evidence, not the only proof of consent.
3.13 Technical, support and security data
IP address, user-agent, session and device data, security and rate-limit logs, error reports, system metrics, deployment diagnostics, support communications and steps taken to resolve an incident or request.
3.14 Service-use country observations
When the authenticated Service is used, we may derive a country code from Railway's trusted client IP at most once every 24 hours. In the per-user aggregate record, we retain the user identifier, country code, first and last observation times, observation count and evidence source. The full IP address is not retained in this register.
We use this data for country-level reliability and usage statistics and human review of possible account or location risks. A country change is only a risk signal: it does not automatically change VAT, the subscription, the plan or access to the Service. Tax location is determined separately from the transaction-specific evidence described in section 3.11.
4. Sources of Data
We receive data:
- directly from you or your guardian;
- from files and content you submit;
- from Garmin, Strava or another service you connect;
- from Stripe, Stripe Tax, payment networks, card issuers or banks in connection with checkout, payment, subscription and tax events;
- from the billing address, payment-method information and transaction IP used in the purchase flow;
- from a bank, accounting system or accountant where a bank-transfer, OSS or reconciliation process is used;
- from administrators who manage invitations, billing review or support; and
- from the Service’s own analysis, security, tax-control and logging processes.
Do not submit another person’s data unless you have a lawful basis and any required permission.
5. Purposes and Legal Bases
For ordinary personal data we rely on one or more legal bases under Article 6 of the GDPR. For health-related or other special-category data, we also need a condition under Article 9.
5.1 Creating and operating the account
Purpose: registration, authentication, profile management, support and provision of requested features.
Legal basis: Article 6(1)(b), performance of the contract or steps requested before entering into it.
5.2 Providing personalised training and AI-assisted coaching
Purpose: training diary, planning, workload and recovery analysis, AI recommendations, summaries and related coaching features.
Legal basis: Article 6(1)(b); and, for health-related data, your explicit consent under Article 9(2)(a).
Health-data consent is limited to purposes objectively necessary for the requested health-personalised coaching. We do not rely on “contract necessity” to use health data for advertising, unrelated research or general model training.
5.3 Optional integrations
Purpose: importing and using data from an account that you choose to connect.
Legal basis: Article 6(1)(b) after you activate the integration; and Article 9(2)(a) where the imported data is health-related. Connecting an integration is a separate affirmative choice.
5.4 Payments, subscriptions and accounting
Purpose: pricing, checkout, recurring billing, payment retries, invoicing, reconciliation, refunds and statutory accounting.
Legal basis: Article 6(1)(b) for the contract and Article 6(1)(c) for accounting and other legal obligations.
5.5 Tax location, EU market eligibility and OSS compliance
Purpose: determining whether a purchase is a supported EU Consumer sale; determining the Member State of consumption; calculating and displaying destination-country VAT; creating, correcting and retaining OSS and VAT records; identifying contradictory tax-location evidence; and pausing, resuming, cancelling or refunding a transaction where needed for tax compliance or the supported-market rules.
Legal basis: Article 6(1)(b) for steps needed to conclude and perform the requested Consumer contract; Article 6(1)(c) for VAT, OSS, invoicing and record-keeping obligations; and Article 6(1)(f) for our legitimate interests in preventing tax misclassification, fraud and unsupported transactions and in resolving evidence conflicts fairly.
We use only billing, payment and technical location information needed for these purposes. Health, training and coaching data is not used for tax checks.
5.6 Security, reliability and misuse prevention
Purpose: authentication security, access control, fraud and abuse prevention, error diagnosis, country-level reliability and usage statistics, human review of possible location risks, service reliability, incident response and protection of legal rights.
Legal basis: Article 6(1)(f), our legitimate interests in securing and operating the Service, and Article 6(1)(c) where a legal obligation applies.
We design technical monitoring to avoid health data and full user content. If special-category data is exceptionally necessary for establishing, exercising or defending a legal claim, Article 9(2)(f) may apply.
5.7 Consent, guardian, AI-transparency and compliance records
Purpose: demonstrating what was presented and agreed, managing withdrawal, verifying guardian authorisation, demonstrating AI-transparency measures, responding to rights requests and establishing or defending legal claims.
Legal basis: Article 6(1)(c) where a binding legal obligation applies, including applicable AI-transparency and accountability obligations; otherwise Article 6(1)(f), based on our legitimate interest in demonstrating compliance and protecting legal rights.
5.8 Optional analytics or product research
Where optional analytics or research is offered, we request separate consent under Article 6(1)(a). It can be refused or withdrawn without losing the paid core service.
We do not use identifiable health data, private training history or AI conversations for advertising, broad product research, or training or fine-tuning a general AI model unless we first present a separate, specific and explicit choice that is genuinely optional.
5.9 Legal claims and authorities
Purpose: complying with lawful requests, resolving disputes and establishing, exercising or defending legal claims.
Legal basis: Article 6(1)(c) and/or Article 6(1)(f), and Article 9(2)(f) where a legal claim necessarily involves special-category data.
6. Health-Related Data and Explicit Consent
Health-related data is processed for personalised coaching only after the required explicit consent has been recorded. The separate Health Data Processing Consent states the purposes, data categories, AI processing, recipients and consequences of withdrawal.
Giving health-data consent is voluntary in the sense that you are free not to use health-personalised coaching. Because that processing is essential to those features, refusing or withdrawing consent means the affected coaching features cannot operate.
After withdrawal:
- new AI analysis is blocked and queued AI work is skipped;
- a response from an already running AI request is discarded if withdrawal is detected before the result is accepted;
- affected coaching features are disabled;
- account, billing, privacy, export and deletion-request functions remain available as far as reasonably possible;
- earlier lawful processing remains lawful; and
- data is not automatically erased, but you may separately request erasure.
Data retained solely for consent evidence, accounting, security or legal claims is not reused for coaching.
7. AI Processing and Automated Decisions
The Service sends relevant data to an AI provider to generate the analysis or output requested by you. We apply data minimisation and, where not needed, exclude direct identifiers such as name and email address. Stored explicit-health context is controlled per AI workflow by a fail-closed configuration matrix. If enabled for a workflow, the data is consolidated into one health-context block; each included health field is limited to 2,000 characters and is cut only at a natural text boundary. If the workflow is disabled or not mapped, those explicit-health fields are removed before the request is sent. The current user message in AI Coach chat is sent as the user’s direct request and is not part of this stored-context limit.
The current main AI provider is OpenAI. For EEA services, the relevant OpenAI entity acts as a processor under a data-processing agreement and may use approved subprocessors. Business/API data is not used to train or fine-tune OpenAI’s general models by default. Talyvro OÜ does not authorise such model training unless you have made a separate, specific and optional choice.
Provider-side security or abuse-monitoring logs may be retained for the provider’s configured contractual period, normally up to 30 days unless a shorter or zero-retention arrangement applies or a legal or security exception requires longer retention.
AI output may reveal or infer health-related information because it is generated from the information you provide. It is returned only within the requested Service workflow and is subject to the same access controls as other account data.
The Service does not make a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within Article 22 of the GDPR. Payment, tax-location and access events may trigger deterministic technical actions, such as activating, pausing, resuming or cancelling a plan or holding a transaction for review. You can contact billing@ai-coach.ee for human review of a disputed tax or access result.
8. Garmin, Strava and Other Integrations
An integration is inactive until you choose to connect it. We receive only the categories allowed by the permission scope you approve with the provider.
Imported data is combined with data you enter or upload for the requested analysis. An individual metric may originate from a file, an integration or both; the resulting analysis may not preserve the original source of every derived value.
You may disconnect an integration at any time. Disconnecting stops future access but does not automatically remove previously imported data. You can delete that data or request account deletion as described below.
Garmin, Strava and similar platforms act as independent controllers for their own platforms and authentication services under their own privacy notices.
9. Recipients, Processors and Their Roles
We disclose data only where needed for the purposes above. The following list reflects the production architecture reviewed on 4 August 2026. A provider’s inclusion in this notice describes the factual data flow; it does not replace the separate contractual, security and transfer safeguards that Talyvro OÜ must maintain.
- Railway — application, worker and AI-service hosting, managed PostgreSQL database, Redis, cron jobs, deployment infrastructure and production secrets; acting on our behalf as a processor for these services.
- Cloudflare R2 / Cloudflare — private primary S3-compatible object storage for user-uploaded training files, archives, videos, extracted frames and related private processing artefacts, and private off-site PostgreSQL backup storage. These objects and backups may contain health-related data. Cloudflare acts on our behalf as a processor for the configured storage services and, for limited security or compliance activities, potentially under its own legal responsibilities.
- Resend — transactional and notification email; processor. Health information, AI conversation content and health-related attachments are not intended to be included in email content.
- OpenAI — AI analysis and content generation requested through the Service; processor for Customer Data under the applicable data-processing terms. We minimise the context supplied and exclude direct identifiers where they are not needed.
- Sentry — error and reliability monitoring; processor. We configure the integration to remove or suppress health data, prompts, AI outputs, secrets, request bodies, query strings, unnecessary URLs and unnecessary direct identifiers. Session Replay is not enabled for production health-data flows.
- Stripe and Stripe Tax — checkout, payment-method collection, subscriptions, invoices, tax-location determination, VAT calculation, payment attempts, fraud prevention, credit notes and refunds.
- Accountants, accounting software, banks, OSS reporting tools and payment-reconciliation providers — billing, accounting, VAT, OSS reporting and reconciliation, acting as processors or independent controllers depending on their legal role.
- Garmin, Strava and other connected platforms — sources of data you elect to import and independent controllers for their own services.
- Professional advisers, courts, regulators, tax authorities and other public authorities — only where necessary for legal advice, a legal claim or a binding legal obligation.
Stripe and Stripe Tax roles
Stripe acts as a processor where it processes checkout, payment, subscription and configured Stripe Tax data on Talyvro OÜ’s documented instructions to provide the selected services.
Stripe also acts as an independent controller for certain purposes it determines itself, such as complying with financial, anti-money-laundering, sanctions, tax-facilitation and payment-network obligations, preventing fraud across its network, maintaining platform security and carrying out activities described in Stripe’s own privacy notice. Stripe’s own notice and retention rules apply to those independent activities.
Depending on the purchase flow, Talyvro OÜ or Stripe may collect and process the email address, declared country and Consumer status, billing name and address, billing country and postal code, plan, price, product tax code, subscription information, payment-method country or issuer country, transaction IP address or IP-derived country, VAT calculation, tax-location source, evidence-conflict flags and refund or correction information. Full card details are entered directly into Stripe and are not received by Talyvro OÜ.
Talyvro OÜ is responsible for ensuring that processors are used under appropriate Article 28 terms and that material subprocessors, service locations, retention and international transfers are reviewed. An up-to-date provider list, including the relevant service and transfer mechanism, may be requested from privacy@ai-coach.ee.
10. International Transfers
We prefer EEA processing where reasonably available, but some providers or their approved subprocessors may access or process data outside the European Economic Area.
Where Chapter V of the GDPR applies, we use an appropriate safeguard, such as:
- an adequacy decision;
- an applicable recognised transfer framework;
- the European Commission’s Standard Contractual Clauses; or
- another legally permitted mechanism.
Where necessary, we also assess the transfer and use supplementary contractual, organisational and technical measures, such as encryption, access controls, data minimisation and pseudonymisation.
You may request information about the applicable safeguard or a copy of relevant standard clauses, subject to lawful redactions, by contacting privacy@ai-coach.ee.
11. Cookies, Local Storage, Error Monitoring and Analytics
The Service uses cookies or similar browser storage that are strictly necessary for authentication, security, session continuity, language and privacy choices. These technologies are needed to provide the requested Service and are not used for advertising.
Sentry is used for error and reliability monitoring. We configure it without advertising tracking and without collecting health data, full user content or secrets. Session Replay or comparable recording is not enabled unless it has been separately assessed, clearly disclosed and, where required, activated only after valid consent.
Stripe-hosted checkout or another third-party page may use technologies governed by that provider’s own notice.
The country-level observation described in section 3.14 is performed server-side from the existing request and does not add a separate cookie or other browser storage for that purpose.
If we introduce non-essential analytics, marketing cookies, cross-site tracking or optional session recording, they will be disabled until the required consent is obtained. We will provide a separate cookie notice and consent control that makes refusal and withdrawal as easy as acceptance.
12. Retention
We retain data only for as long as necessary for the stated purpose, legal obligations, security and accountability.
- Account, athlete profile, training, health and nutrition data: while the account is active. Following account closure or an accepted erasure request, primary-system data is deleted or irreversibly anonymised, normally within 30 days, unless a lawful exception applies.
- Data after health-consent withdrawal: health data remains restricted in the account until you delete it, request erasure or the account-retention period ends. It is not used for new coaching analysis.
- AI conversations and outputs: while the account is active or until you delete the relevant conversation or account, subject to lawful exceptions.
- AI-transparency and provenance records: linked to the relevant output while that output is retained. A limited evidence record of the first-interaction notice, marking version and substantive human-review status may be kept for up to three years after the relevant account or publication relationship ends, and longer only for an active complaint, investigation or legal claim.
- AI-provider security logs: for the provider’s configured short security/abuse period, normally up to 30 days, unless a shorter arrangement or a documented exception applies.
- Integration tokens: until you disconnect the integration, the token expires or the account is deleted.
- Consent, document-version, withdrawal and guardian-authorisation records: in a limited form for up to three years after the account relationship ends, and longer only where reasonably needed for an active complaint, investigation or legal claim.
- IP address and user-agent stored as consent evidence: only where proportionate, with restricted access, and no longer than the related consent record unless an active claim requires it.
- Security, access, rate-limit and error logs: normally 30 to 180 days; longer only for an active incident, legal hold or investigation.
- Per-user aggregate Service-use country records: while the account is active; they are removed when the account is deleted or an accepted erasure request is completed unless a lawful exception requires retention of a limited record.
- Support and complaint records: normally up to three years after closure, and longer where needed for an unresolved claim or legal obligation.
- Editable billing profile: removed or anonymised with the account unless the information has been frozen into a legally retained accounting or tax record.
- EU VAT and OSS transaction and customer-location records: retained for 10 years from 31 December of the year in which the transaction was carried out. Depending on the transaction, this includes the Member State of consumption, service type and date, taxable amount and currency, later price reductions or increases, VAT rate and amount, payment date and amount, invoice or credit-note information, refunds, and the information used to determine customer location, such as the declared, billing, payment-method and IP-derived countries and the evidence source or review result.
- Underlying IP and payment evidence used for VAT location: to minimise data, Talyvro OÜ normally retains the country-level result and evidence type rather than full card, bank or device data. An exact transaction IP address or another underlying item may be retained for the 10-year VAT/OSS period only where it was actually used as necessary statutory location evidence, is required for an audit trail or remains in Stripe under Stripe’s applicable role and retention rules.
- Invoices, credit notes, payment and refund records, accounting snapshots and necessary accounting audit trail: seven years from the end of the financial year in which the relevant accounting source document was recorded, or longer if another applicable law or proceeding requires it. Where the same record is also an OSS record, the longer 10-year period applies.
- Backups: operational backups are rotated according to the backup schedule, normally within about 30 days. A limited periodic archive may be retained for up to 12 months where required for resilience. Deleted data in a backup is not restored into active use and disappears when the backup is overwritten.
Immediate deletion from every immutable backup may not be technically feasible. We delete or anonymise primary systems first, restrict backup use and allow the rotation schedule to remove residual copies.
13. Your Rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- receive information about processing;
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- receive data you provided in a structured, commonly used and machine-readable format and transmit it to another controller where the portability conditions apply;
- object to processing based on legitimate interests;
- withdraw consent at any time without affecting prior lawful processing;
- obtain human review and the protections applicable to a qualifying automated decision; and
- lodge a complaint with a supervisory authority.
You can manage consent, disconnect integrations, export available data and start an account-deletion request in the Service where those controls are provided. You may also contact privacy@ai-coach.ee.
We may request information reasonably necessary to verify identity and protect the account. We respond without undue delay and normally within one month, subject to any extension permitted by law.
14. Erasure and Statutory Retention
The right to erasure is not absolute. We cannot delete data that we must retain to comply with accounting, VAT, OSS or another legal obligation, or that is necessary for establishing, exercising or defending a legal claim.
When an account is deleted:
- active profile, training and health data is deleted or anonymised under section 12;
- legally retained accounting, VAT and OSS records remain separated and locked against ordinary profile or coaching use;
- limited consent, security and claim records may remain for their stated period; and
- remaining data is no longer used for personalised coaching, advertising or unrelated analytics.
Where only part of a record must be retained, we minimise or separate it and restrict access.
15. Security
We use technical and organisational measures appropriate to the risk, including role-based access, least-privilege administration, password hashing, encrypted transport, protected integration tokens, file validation, rate limits, logging, backup and recovery controls, provider due diligence and incident procedures.
Administrator access to user data is restricted and logged where appropriate. Personnel and service providers are bound by confidentiality and access instructions.
No system is completely secure. If a personal-data breach is likely to result in a risk to individuals, we notify the competent supervisory authority without undue delay and, where required, within 72 hours. We notify affected individuals where the breach is likely to result in a high risk.
16. Complaints and Supervisory Authority
Please contact privacy@ai-coach.ee first so that we can investigate the concern.
You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with the supervisory authority of the EEA country where you habitually reside, work or consider that an infringement occurred.
This does not limit your right to seek a judicial remedy.
17. Changes to This Policy
We may update this Policy to reflect legal, technical or service changes. We provide notice of a material change in a suitable way before or when it takes effect, as required.
A Privacy Policy is primarily an information notice. We do not treat continued use as consent to a new purpose that legally requires consent. If a new or expanded health-data purpose requires explicit consent, we present a separate choice before that processing begins.
The Service assigns every published legal-document text a version and technical fingerprint. A changed fingerprint invalidates the previous current-document acknowledgement and causes the user to be asked to review the current legal bundle again before protected functions continue.
18. Language
The English and Estonian versions are intended to provide the same information.
For users receiving the Service through the Estonian-language interface and for Consumers habitually resident in Estonia, the Estonian version prevails to the extent of an inconsistency. For other users, the English version prevails to the extent of an inconsistency.
Mandatory transparency and language requirements remain unaffected.
19. Contact
For privacy questions and rights requests:
- Talyvro OÜ
- Registry code: 17553163
- Address: Pihlaka tee 11-2, 75312 Peetri alevik, Rae vald, Harju County, Estonia
- Privacy: privacy@ai-coach.ee
- General: support@ai-coach.ee
- Billing: billing@ai-coach.ee