Privacy Policy

Effective date: July 15, 2026

This Privacy Policy ("Policy") describes how fuelant collects, uses, shares, and otherwise processes personal information when you use our websites, mobile applications, application programming interfaces (APIs), and related offerings available at getfuelant.com (collectively, the "Services"). It also describes your privacy rights and choices. We aim to be direct about what we collect and why—so you can make informed decisions.

Please also read our Terms of Service ("Terms"), which govern your access to and use of the Services.

As used in this Policy, "fuelant," "we," "us," or "our" means fuelant LLC, the company that provides the Services to you.

1. Introduction

About fuelant: fuelant helps endurance athletes build session-specific fueling plans—carbohydrate, fluid, and electrolyte guidance aligned to the workouts you actually do—and execute those plans with live cues on phone and watch during training and racing.

How to reach us: Questions about this Policy or your personal information may be sent to privacy@getfuelant.com.

A quick summary

We collect the information we need to operate the Services for you. We do not sell your personal information. We do not use health, fitness, or Activity Data (as described below) for advertising. For EU/UK and U.S. state-law details, see Section 7.

2. Information We Collect

We collect information you provide to us, information generated when you use the Services, and information from third-party sources you choose to connect (for example, wearable and training platforms).

Information you provide

  • Account information: Email address, name, and credentials. You may also sign in with supported third-party identity providers (for example, Google). Passwords are handled by our authentication provider and are not stored by fuelant in plain text.
  • Profile and athlete information:Details you enter such as date of birth, gender, weight and unit, height, primary sport, race or event goals, training structure, city/ZIP (or similar location fields), sweat and hydration preferences, allergen or dietary preferences, nutrition stack / "quiver" products, gut concerns, flavor or caffeine preferences, and a profile photo if you upload one.
  • Session and plan inputs: Manual session details, fuel logs, symptom or gut check-ins, calculator / plan inputs, and related notes.
  • Waitlist and marketing forms: Email address (and any optional fields) when you join our waitlist or submit coaching or store inquiry forms.
  • Support information: Information you send us when you contact support.
  • Payment information: If you subscribe or purchase, our payment processor (Stripe) collects and processes payment details. We do not receive or store full payment card numbers.

Activity, health, and integration data

Depending on how you use fuelant, we process workout-related information ("Activity Data") and related health or performance metrics to build and adjust your fueling plans and live guidance. Activity Data may include session type, duration, distance, intensity cues, heart rate where available, and training metrics (such as load or intensity scores) when supplied by a connected platform.

Connected apps and devices: When you connect a third-party service, we collect information from that integration as described in this Policy and only as permitted by your authorization. If we collect health or fitness information from these integrations, we will not sell it or use it for advertising; we will not disclose it to third parties except as needed to provide the Services or as otherwise described in this Policy; and we will use it only for the purposes described here.

Apple HealthKit (iOS)

With your permission on Apple devices, the fuelant app may read health and fitness data from HealthKit—such as workouts (including duration and related metrics), heart rate, resting heart rate, heart-rate variability, heart-rate recovery, active energy, steps, VO₂ max, respiratory rate, sleep analysis, and recent body weight where available. We use this data to personalize training and fueling features. We never use HealthKit data for advertising, never sell it, and do not share it with third parties except as needed to provide the Services (for example, syncing a snapshot to your fuelant account) or as otherwise described in this Policy.

Google Health Connect (Android)

With your permission on Android devices, the fuelant app may read comparable metrics through Health Connect—such as heart rate, resting heart rate, sleep sessions, weight, active calories, and exercise sessions—for the same fueling and training purposes described above.

Strava

When you connect Strava, we receive activity information you authorize (read access), such as activity type, duration, distance, elevation, heart rate when shared, and related summary fields. We use this data to power planning and hub features. We do not currently write fueling summaries back to Strava activities.

COROS

When you connect COROS, we receive workout and recovery information you authorize—such as activity type, duration, heart rate, training load, and recovery-related metrics (for example, HRV, resting heart rate, or sleep scores when made available)—to refine fuel targets and planning.

Terra and other wearables

You may connect additional wearables and platforms through our Terra integration (for example Garmin, WHOOP, Polar, Wahoo, or other providers Terra supports, depending on availability). When you do, Terra processes connection and sync on your behalf, and we receive activity, body, and/or sleep information you authorize so we can personalize the Services. Direct first-party OAuth for some brands (including Garmin Connect and TrainingPeaks) may be limited or rolling out; where a direct connection is not yet available, Terra or in-app export tools may be the supported path.

Weather and approximate location

To estimate weather-aware hydration targets, we may use city/ZIP from your profile and/or approximate device location when you allow location access in the mobile app. fuelant is not a continuous location-tracking or route-recording product: we do not collect precise GPS tracks to follow where you go.

Manual entry

Information you enter manually—such as session notes, fuel logs, symptom check-ins, or adjustments you make inside fuelant.

Information we collect automatically

  • Device and log data: Technical information from the browser or device you use—such as device type, operating system, app or browser version, and similar identifiers needed to deliver and secure the Services.
  • Operational diagnostics: Error logs and related performance signals needed to keep the Services reliable. We may use third-party crash or error tooling (including Sentry when configured for a given surface) to diagnose failures.
  • Network data: IP address and related metadata used for security, fraud prevention, abuse detection, and (where enabled) approximate region preferences.
  • Local notifications: On mobile, we may schedule on-device fueling reminders and session notifications you authorize. We do not require a remote push-notification pipeline to deliver those local cues.

What we do not collect (or do not use for ads)

We do not sell personal information. We do not use health, fitness, or Activity Data for advertising. We do not use cross-app tracking for advertising across unrelated third-party apps or sites. We do not access your contacts or microphone to collect personal information. If you set a profile photo, we access your photo library (with permission) only to let you choose and upload that image.

3. How We Use Your Information

We use personal information for the purposes below. We limit use to what is relevant and proportionate for those purposes.

To provide the Services

  • Create and maintain your account; authenticate you; sync data when you connect integrations.
  • Generate, display, and update personalized fueling plans, live session cues, and hub insights based on your Activity Data and profile.
  • Power recommendation and coaching-assist features. When those AI-assisted features are enabled, limited profile or session context may be sent to model providers solely to generate the response you requested.
  • Process subscriptions and billing through our payment processor when you purchase.
  • Provide customer support and respond to your requests and waitlist / inquiry submissions.

To communicate with you

  • Send transactional and service-related messages (for example, account security, password reset, subscription receipts, and material changes to our terms or this Policy).
  • Send product tips or updates where permitted; you can opt out of non-transactional messages via unsubscribe links or in-app controls where available.

To analyze and improve the Services

  • Use operational logs, crash diagnostics, and aggregated or de-identified information to improve reliability and product experience.

To protect you, others, and the Services

  • Monitor for fraud, abuse, and security incidents; enforce our Terms; and protect the integrity of fuelant.

To meet legal and compliance obligations

  • Comply with applicable law, regulation, or lawful requests from public authorities.

Health, fitness, and advertising: We do not use your health, fitness, or Activity Data for advertising. We do not sell your personal information.

4. How We Share Information

We share personal information with categories of recipients below. We do not share your information with advertisers, data brokers, or marketing platforms for their independent advertising use.

Partner / serviceRoleCategories of information
SupabaseAuthentication, database, and file storageAccount credentials handling; profile and session data; uploaded avatar files
StripePayment processingContact and billing details; transaction records (not full card numbers on fuelant systems)
Apple HealthKitOn-device health metrics (read per your permission)Workouts, heart metrics, energy, steps, VO₂, sleep, and related fields described above
Google Health ConnectOn-device health metrics (read per your permission)Heart rate, sleep, weight, calories, exercise sessions, and related fields described above
Strava (via API)Activity sync you authorize (read)OAuth tokens; activity summaries and metrics you authorize
COROS (via API)Workout and recovery sync you authorizeOAuth tokens; workouts and recovery metrics made available to fuelant
TerraWearable / platform connection bridgeConnection identifiers; activity, body, and sleep data from providers you choose through Terra
ResendTransactional / inquiry email deliveryEmail address; name; message content for inquiries we send through Resend
AI model providersRecommendation / coaching-assist features when enabledLimited profile and session context needed to generate the requested output (for example via Anthropic)
Crash / error toolingDiagnostics when configuredDevice/OS and app context; crash or error traces; limited identifiers needed to group reports

Legal requests and safety: We may disclose information if required by law, regulation, legal process, or a valid governmental request, or when we believe disclosure is necessary to protect the rights, safety, or security of fuelant, our users, or others.

5. Data Storage and Security

We implement administrative, technical, and organizational safeguards designed to protect personal information commensurate with the risks involved. No method of transmission or storage is completely secure; we work to follow industry practices and periodically review our controls.

  • Hosting: Account data, profiles, and related content are stored using Supabase (cloud database, auth, and storage). The website and APIs run on cloud application hosting. Exact cloud regions depend on our project configuration and may be updated as we scale.
  • Encryption in transit: We require TLS for data transmitted between your device and our Services where supported.
  • Encryption at rest: We rely on encryption at rest provided by our cloud providers for databases and backups where supported.
  • Integration credentials: OAuth tokens and similar secrets for connected platforms are stored with safeguards appropriate to credential material (including encryption at rest where supported by our stack).
  • Passwords: Managed by our authentication provider using industry-standard one-way hashing—not stored in plain text by fuelant.
  • Access: Employee access to personal information is limited to personnel who need it to support the Services, subject to policies appropriate to their role.
  • Incident response: If we confirm a breach affecting your personal information where notification is required, we will notify affected users without undue delay and within applicable legal timelines (for example, where required, within seventy-two (72) hours of becoming aware), together with guidance on protective steps.

6. Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

  • Account information: Retained while your account remains open.
  • Activity and integration data: Retained while needed to operate features you use and while an integration stays connected, unless you delete it earlier or disconnect the integration.
  • Waitlist / inquiry emails: Retained as needed to manage early access, respond to you, and operate related communications, unless you ask us to delete them where we can.
  • Account deletion: When you delete your account, we delete or irreversibly de-identify personal information within thirty (30) days, except where we must retain specific records for legal, tax, accounting, or security purposes (for example, billing records held by our payment processor).
  • Aggregated / de-identified data: May be retained in a form that does not reasonably identify you.
  • Disconnecting integrations: When you disconnect a platform (for example Strava, COROS, or Terra), we stop new syncs and remove or de-identify provider-sourced workout data from production systems within a reasonable period (typically within seven (7) days), subject to standard backup rotation—unless needed longer for security, dispute, or legal retention.

7. Your Rights and Choices

Depending on where you live, you may have additional statutory rights. Regardless of location, we provide the following controls:

  • Access / portability: Request a copy or export of your information, including in a machine-readable form such as JSON where feasible.
  • Correction: Update profile and athlete information in the Services.
  • Deletion: Delete your account in settings, subject to lawful exceptions.
  • Marketing preferences: Opt out via links in emails or in-app settings where available; operational messages may continue.
  • Integrations: Disconnect Strava, COROS, Terra connections, and other linked services in settings at any time—this revokes our API access on our side and starts the retention clocks described above.
  • HealthKit: Manage permissions on your iPhone under Settings → Privacy & Security → Health.
  • Health Connect: Manage permissions in Android Health Connect / system privacy settings.
  • Location: Deny or revoke location permission in system settings; you can still use city/ZIP-based weather where you have provided it.

Submit privacy requests to privacy@getfuelant.com. We will respond within a reasonable period and, where applicable, within thirty (30) days.

EU / UK users

If you are in the European Economic Area, United Kingdom, or Switzerland, we process personal information under GDPR/UK GDPR as applicable. Legal bases may include contract (providing the Services), legitimate interests (for example, securing our platform, improving reliability—balanced against your rights), and consent where required. You may have rights to access, rectify, erase, restrict, object, and port your data, and to lodge a complaint with your supervisory authority. Contact gdpr@getfuelant.com.

U.S. state privacy notices (including California)

Residents of certain U.S. states may have rights to know, delete, and correct personal information, and to opt out of certain types of processing. fuelant does not "sell" personal information as that term is commonly defined in state privacy laws, and we do not use sensitive health information for targeted advertising. We will not discriminate against you for exercising privacy rights. Submit requests through privacy@getfuelant.com.

8. Children's Privacy

The Services are not directed to children under thirteen (13), and we do not knowingly collect personal information from children under thirteen. If you believe a child has provided us information, contact privacy@getfuelant.com and we will take steps to delete it.

9. Changes to This Policy

We may update this Policy from time to time to reflect changes to our practices or the law. If we make material changes, we will provide notice as required—such as by email, in-product notification, or by posting the updated Policy with a new effective date. Your continued use of the Services after the effective date of an update may constitute acceptance where permitted by law. Prior versions are available on request.

10. Contact Us