LEGAL
Privacy Policy
This Privacy Policy explains how GOAT MODE ("we," "us," "our") collects, uses, and protects information when you use our app.
1. Information We Collect
Account and profile information (first name, last name, date of birth, country, stroke/events, level, training frequency, competition details, goals, challenges, mental approach preference, coaching style); sensitive information (daily check-in ratings, journal entries including voice-journal audio, race-prep notes, and AI Coach conversations, including messages flagged by our automated safety system); consumer health data (check-ins, mood/stress ratings, and wellbeing-related coach conversations may qualify as consumer health data under state laws like Washington's My Health My Data Act — we do not sell this data or use it for targeted advertising, ever); account credentials; payment information (handled entirely by Apple for App Store in-app purchases — we don't store card numbers and take no payments ourselves); basic usage data; and parental-consent status for users under 18.
We collect your date of birth to verify you meet our 13+ eligibility requirement and to tailor which content and coaching tone we show you by age group (for example, college-recruiting content is only surfaced to older swimmers).
We do not knowingly collect information from anyone under 13.
1a. Apple HealthKit Data (iOS, opt-in)
On iOS, GOAT MODE can read a limited set of health metrics from Apple HealthKit to power the in-app Recovery indicator: sleep, heart rate variability (HRV), and resting heart rate. This is sensitive health data and we treat it accordingly:
- It is strictly opt-in — nothing is read unless you grant permission through the iOS Health permission prompt.
- We only read these metrics. GOAT MODE never writes any data back to HealthKit.
- The data stays associated with your own account and is used only to show you your Recovery indicator and related mental-training and sleep guidance.
- We never sell HealthKit data, never share it with advertisers or data brokers, and never use it for advertising, marketing or profiling.
- You can revoke access at any time in iOS Settings > Privacy & Security > Health. Revoking access stops all further reads; the Recovery indicator simply stops updating.
1a-ii. WHOOP Data (planned, optional, Pro tier — not yet available)
WHOOP syncing is not live yet and no WHOOP data is being collected today. It is a planned second, entirely optional source alongside Apple HealthKit, and it is pending WHOOP's approval of our integration on their developer platform. Until that approval lands, the WHOOP option in the app is shown as “coming soon” and cannot be connected. We are describing it here in advance so you know exactly what will happen when it does launch.
Once it launches, connecting your own WHOOP account will be your choice, and GOAT MODE will read a limited set of metrics from the WHOOP API: recovery score, day strain, sleep performance and sleep duration, heart rate variability (HRV), and resting heart rate. This is sensitive health data and the commitments below will apply to it exactly as they apply to HealthKit data today:
- It will be strictly opt-in — nothing will be read unless you complete the WHOOP authorization flow yourself and grant permission to WHOOP.
- We will only read these metrics. GOAT MODE will never write any data back to WHOOP.
- WHOOP authorization tokens will be stored encrypted, accessible only to our server, and never exposed to your browser or to any third party.
- The data will stay associated with your own account and be used for exactly three things: your Recovery trend (compared with your own rolling baseline), the burnout-risk pattern indicator, and context for your AI Coach replies. Nothing else.
- We will never sell WHOOP data, never share it with advertisers or data brokers, never share it with your coach, squad or team dashboard, and never use it for advertising, marketing or profiling.
- You will be able to disconnect WHOOP at any time in Settings. Disconnecting will revoke our access and delete the WHOOP-sourced data we had stored. You will also be able to revoke access from your WHOOP account.
- Neither source is or will be required. With no wearable connected — which is the situation for every user today — your recovery and burnout trends are derived from your own self-reported check-ins alone.
If this changes, the change is the launch of an opt-in feature: we will update this policy and nothing will be read from WHOOP for your account unless you connect it yourself.
1a-iii. Consumer Health Data (Washington My Health My Data Act and similar state laws)
The Apple HealthKit metrics described above (and the WHOOP metrics described above, once that integration launches), together with any check-in answers that touch on how you are feeling physically, may qualify as consumer health data under Washington's My Health My Data Act and comparable state laws (for example Nevada's SB 370). GOAT MODE is not a HIPAA-covered entity and this data is not medical-record data, but we handle this category with these specific commitments:
- Collection requires your opt-in consent. We collect no consumer health data until you separately opt in by connecting Apple Health (or WHOOP, if and when that integration becomes available). Declining changes nothing else about the App.
- Sharing would require a separate opt-in consent. We do not share or sell this category today. We never will without first obtaining your separate, specific opt-in consent for that sharing, described in plain language before you agree. We do not and will not sell consumer health data.
- You can access and delete this category on its own. Settings contains a dedicated Withdraw health data & delete it action that disconnects any connected health source, revokes any WHOOP access and deletes the stored health data — without deleting your account. You can also email us to request a copy of it.
- 45-day response. Requests to access, withdraw consent for, or delete consumer health data are honoured within 45 days of receipt (and we will tell you if we need the one permitted extension). In-app withdrawal is immediate.
- This data is used only for wellness insight — your own recovery trend, the early-warning burnout nudge and AI Coach context. It is never used for advertising, profiling, or any diagnostic or clinical purpose, and nothing in GOAT MODE is healthcare advice.
1b. Self-Reported Screen Time
The daily check-in includes an optional, self-reported estimate of your leisure screen-time hours. This is a number you type or select yourself — we do not monitor your device, apps, or usage in any way. It is stored alongside your other check-in data and used only to personalize your insights and sleep guidance. It is never shared with third parties.
1c. Face ID / Touch ID App Lock
If you enable the biometric app lock, authentication happens entirely on your device through Apple's Secure Enclave. GOAT MODE never receives, stores, or has any access to your biometric data — we only receive a pass/fail unlock result.
2. How We Use Your Information
To provide the App's features; personalize AI Coach responses using your swimmer profile; process payments; run our server-side crisis-safety screening (which checks messages for language indicating possible self-harm before any AI response is generated); maintain security; communicate with you about your account; and comply with legal obligations. We do not sell your personal information, share it with advertisers, or use it to train third-party advertising profiles.
3. Who We Share Information With
We share data only with the specific service providers below, and only what is needed to run that part of GOAT MODE:
- Google Gemini, through our AI provider — receives your chat messages and swimmer-profile context (name, stroke, goals, recent check-ins, journal entries, etc.) to power Kai's coaching answers. A separate Google Gemini model screens each message for crisis-risk language before Kai responds. Your email address is never sent to an AI model.
- OpenAI, through our AI provider — receives the text of content you choose to have read aloud and generates the voice-narration audio. If you dictate a message, your device or browser's speech-recognition facility converts your speech to text on the device; GOAT MODE sends the resulting text to Kai, not the raw dictation audio.
- Lovable Cloud / Supabase — our backend database, authentication, and file storage; this is where your account and app data lives.
- RevenueCat — receives your account ID and subscription/entitlement status to manage your Plus/Pro plan through Apple's In-App Purchase system.
- Mailchimp — receives your email address (and first name, if given) only if you sign up for our newsletter.
- WHOOP (only if you choose to connect it) — recovery, sleep, and strain data from WHOOP's API, to display alongside your training.
- Apple Health (only if you enable it) — read on-device; synced to our database only if you turn this on.
- PostHog — a fixed, named list of product-usage events only (e.g. "completed check-in"); no session recording or automatic data capture.
We do not use Stripe, Google Analytics, Meta/Facebook tracking, or any third-party advertising or crash-reporting tool. Notifications are generated locally on your device — we do not use a remote push-notification service.
Your team's coach (only if you opt in): if you turn on the team consent toggle, your team's coach can see aggregated, team-level performance trend data that includes your activity. Coaches never see your name alongside a score, your individual scores, your journal entries, or your coach conversations, and aggregates are only shown once enough teammates have opted in. You can turn this off at any time in Settings, and sharing stops immediately.
4. Data Retention
We retain your check-in, journal, and chat data while your account is active. If you delete your account, we permanently delete this data, including all Kai chat messages and messages flagged by our crisis-safety system. Records we are legally required to retain may be kept only for the required period. You can delete your account anytime from Account & Legal.
5. Crisis-Safety Data Handling
Messages are screened by our automated crisis-detection system while your account exists. Flagged messages are logged internally so flagged volume can be reviewed for safety, are excluded from later Kai conversation context, and are never used for marketing or profiling. All chat messages, including flagged messages, are deleted when you delete your account.
6. Children's Privacy
GOAT MODE is intended for users 13 and older. We do not knowingly collect information from children under 13; if we learn we have, we delete it promptly. For users 13-17, we rely on parental/guardian consent obtained at sign-up. We do not sell or share the personal information of any user we know to be under 16.
7. Your Rights and Choices
You may have the right to access, correct, delete, or export your data, or withdraw consent. Washington residents and residents of states with similar consumer health data laws can additionally confirm what consumer health data we hold, get a list of third parties it's shared with, and request its deletion. There is no in-app download tool. To request a machine-readable copy of your data, email hello@goatmode.app; we will fulfil the request by email within the response timeframe below. You can use the delete-account option in the App to erase your account.
7a. Legal Basis for Processing (UK/EU GDPR)
If you are in the UK or the European Economic Area, we rely on the following legal bases under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)) — for creating your account and processing your swimmer profile information (name, date of birth, country, events, level, goals, coaching preferences) so we can personalize the App. You may withdraw consent at any time by deleting your account.
- Performance of a contract (Art. 6(1)(b)) — for providing and billing your subscription, including plan status, renewals and refunds.
- Legitimate interests (Art. 6(1)(f)) — for keeping the App secure, preventing abuse, and basic aggregate usage diagnostics.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose records to comply with applicable law.
Some of what you share with us — daily check-in ratings, journal entries, AI Coach conversations about wellbeing, Apple Health metrics (and WHOOP metrics once that integration launches: sleep, HRV, resting heart rate, recovery score, strain), and messages flagged by our crisis-safety screening — is special category health data under Article 9. We process it only on the basis of your explicit consent (Art. 9(2)(a)), which you give when you enable those features (for example the iOS Health permission prompt, or choosing to write a journal entry or message the coach). You can withdraw that explicit consent at any time — revoke Health access in iOS Settings, disconnect WHOOP in the app's Settings once that integration is available, stop using the affected features, or delete your account. Withdrawal does not affect processing already carried out before withdrawal.
For users aged 13-17 we additionally rely on parental/guardian consent obtained at sign-up.
7b. Rights of UK/EEA Users
If you are in the UK or the EEA, you have the right to:
- Access your personal data and receive a copy of it (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure ("right to be forgotten") — Art. 17. We honour this through the delete-account option, subject only to records we must keep by law. Crisis-flagged Kai messages are deleted with the account.
- Restriction of processing (Art. 18).
- Data portability — request a machine-readable export of the data you provided by emailing hello@goatmode.app; there is no in-app export tool (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, including explicit consent for health data (Art. 7(3)).
- Lodge a complaint with a supervisory authority — your national data protection authority, or the UK Information Commissioner's Office (ICO) in the UK. You can complain to them directly without contacting us first, though we'd appreciate the chance to resolve it.
We do not use automated decision-making that produces legal or similarly significant effects about you. To exercise any of these rights, email hello@goatmode.app; we respond within one month, extendable where the law permits. We are an independent individual developer and have not appointed a formal EU Article 27 representative or a statutory Data Protection Officer — requests come directly to us at that address.
7c. International Data Transfers
We are based outside the UK/EEA and our infrastructure providers (including Supabase for database, authentication and storage, and our AI Gateway provider for coaching responses) may process and store data in the United States and other countries. Where personal data is transferred out of the UK/EEA, that transfer is covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or an equivalent safeguard, as applicable to the provider in question. You can ask us for more detail about the safeguards used for a specific provider.
8. Security Incident Notification
If a security incident compromises your personal information in a way that triggers a legal notice obligation, we'll notify affected users and regulators within the timeframe required by law.
9. Age Verification
We ask for your date of birth at sign-up and use it to confirm eligibility (13+) and to tailor content and coaching tone by age group. Users under 13 cannot create an account. We don't currently use enhanced age-verification (like ID checks).
10. Security
We use encryption in transit, database-level row security so users can only access their own data, and access controls on our infrastructure. No system is completely secure.
11. Changes to This Policy
We may update this policy; material changes will be announced in-App or by email before taking effect.
12. Contact
GOAT MODE is operated by Sarah Oerer, an independent individual developer based in Dubai, United Arab Emirates, not a registered company. Questions about this Privacy Policy, or requests to access, correct, delete or export your data, can be sent to hello@goatmode.app. See our Contact page for more.