Privacy Policy

Last Updated: February 17, 2026

1. Introduction

CardioCapture ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use the CardioCapture mobile application (the "App").

By using CardioCapture, you agree to the practices described in this policy. If you do not agree, please do not use our App. Your use of the App is also subject to our Terms of Service.

Privacy at a Glance

  • No account required — You remain anonymous
  • No data stored on our servers — Your fitness data stays on your device
  • You control sharing — Data is only shared when you explicitly choose to export or sync
  • Minimal analytics — Privacy-first, anonymous usage statistics only

2. Data We Do Not Collect

CardioCapture is designed with privacy as a core principle. We do not:

This commitment applies to all data we handle, including any data received from third-party APIs such as the Garmin Connect API.

3. Data Stored Locally on Your Device

Your fitness data is securely stored in a local private database on your device. This includes:

Your data never leaves your device unless you explicitly choose to share or export it.

Because your data is stored locally, if you delete the App or clear its data, your fitness information will be permanently removed from your device.

4. Anonymous Usage Analytics

To help improve CardioCapture, we may collect anonymous usage analytics using Matomo, a privacy-focused analytics platform. Our Matomo instance is hosted securely in the European Union on a dedicated and isolated server.

These analytics are:

This data helps us understand how the App is used so we can fix bugs and improve features. It cannot be used to identify you personally.

5. When You Choose to Sync or Share Data

CardioCapture allows you to both import data from fitness wearables and export your workout data to external platforms. In all cases, data only moves when you explicitly choose to do so — nothing happens automatically without your consent.

Your explicit consent is required for all data transfers — both importing data into CardioCapture and exporting data to external services. You are always in control.

5.1 Syncing External Data (Importing)

CardioCapture can sync and import data from fitness wearables and health platforms to enhance your workout records. With your explicit consent, you may import data such as heart rate, activity metrics, and other fitness information from:

When you authorize a connection, data is imported from these services and stored locally on your device. We do not store this imported data on our servers.

5.2 Sharing with Training Platforms (Exporting)

CardioCapture allows you to export and share your captured workout data with training and fitness platforms. With your explicit consent, you may export data to services such as:

Garmin Connect Notice: When you choose to upload data to Garmin Connect, your data will be transferred to and processed by Garmin International, Inc. and its affiliates in accordance with Garmin's Privacy Policy. You should not upload data to Garmin Connect if you are restricted from doing so under applicable law or any agreement with Garmin.

Important: Any data you import from or export to external services becomes subject to those services' privacy policies and any agreements you have with them. We encourage you to review their policies before connecting.

5.3 Consent and Authorization

All connections to external platforms require your explicit authorization through an OAuth consent flow. Each data transfer must be explicitly initiated by you. No data is transferred in the background without your knowledge.

You can withdraw your consent at any time by:

Withdrawing consent immediately stops any further data transfers to or from that service.

5.4 Manual File Exports

You can also export your workout data in standard formats (such as FIT, TCX, or GPX files) to use with any compatible service or for your own records. Once exported, that data is under your control.

6. Artificial Intelligence Processing

CardioCapture offers an optional AI-powered feature that allows you to describe a workout in natural language, which is then converted into a structured FIT file. This feature is entirely opt-in and requires your explicit consent before any data is processed.

How It Works

When you choose to use the AI workout builder, your workout description is sent to Anthropic's Claude API for analysis and conversion. This means your workout description is transmitted to Anthropic's servers for processing.

What You Should Know

7. Your Data Rights

You have the following rights regarding your personal data:

Local storage advantage: Because CardioCapture stores your fitness data locally on your device, most of your data is already entirely under your control. You can view, modify, export, or delete it at any time directly within the App.

To exercise any of these rights regarding data we may process (such as anonymous analytics), please contact us at rory.duffy@cardiocaptureapp.xyz. We will respond to your request within 30 days.

8. You Are in Control

You have full control over your data at all times:

Since we do not store your data on our servers, deleting the App or your local data removes it completely — there is nothing for us to delete on our end.

9. Data Security

We take reasonable measures to protect the App and your locally stored data:

10. Children's Privacy

CardioCapture is not intended for use by children under the age of 13. We do not knowingly collect any information from children. Since the App does not collect personal information, no such data can be inadvertently gathered.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

We encourage you to review this policy periodically.

12. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us:

CardioCapture

Email: rory.duffy@cardiocaptureapp.xyz

You may also use this contact information to report any misuse or abuse of the CardioCapture application.

13. Third-Party Privacy Policies

When you choose to connect CardioCapture with external platforms, your data is governed by their respective privacy policies:

Data Sources (Import)

Training Platforms (Export)

AI Processing