Privacy Policy
Suffer Well · Last updated 16 July 2026
This is a private, non-commercial application operated by an individual for their own personal training use. It is not a public product and does not have other users.
What this app is
Suffer Well is a personal web app that brings the owner's own fitness data from Strava and WHOOP into one private dashboard, and uses it to generate training insights. Access is restricted to the owner's authenticated account.
Data we access
Only after you explicitly authorize each connection, the app accesses your own data:
- Strava — your activities (type, date, duration, distance, elevation, average and maximum heart rate, and heart-rate zone summaries).
- WHOOP — your recovery data (recovery score, resting heart rate, heart-rate variability), sleep, and daily strain.
The app does not collect your contacts, browsing activity, precise location routes, or any data beyond the fitness metrics above.
How your data is used
- To display your training and recovery on your private dashboard.
- To compute training-load analytics (fitness, fatigue, form, load balance).
- To generate plain-language coaching insights. A compact summary of your metrics is sent to Anthropic (the Claude API) to produce the written coaching text; it is not used to train models.
Your data is never sold, rented, or used for advertising.
Where your data is stored
- Supabase — database and authentication. Your data is protected by row-level security so only your authenticated account can read it.
- Netlify — hosting of the app and its server functions.
- Connection tokens (Strava, WHOOP) are stored server-side only and are never exposed to the browser.
Service providers
The app relies on these processors solely to provide its functionality: Supabase (storage and auth), Netlify (hosting), and Anthropic (AI coaching). Strava and WHOOP are the sources of your data, accessed under their own terms.
Retention and deletion
Data is retained only as long as the app is in use. You can revoke the app's access at any time from your Strava or WHOOP account settings, which stops all future syncing. To have stored data deleted, use the contact below.
Security
All traffic is served over HTTPS. Access requires authentication, database access is restricted by row-level security, and third-party tokens are kept on the server only.
Contact
Questions or deletion requests: Tuckers@infonancial.com