Legal
Privacy Policy
Last updated: 5 September 2026 · Effective immediately
SPLIT / Get-Split ("we", "the platform") is operated as a sole proprietorship from Denmark and complies with the EU General Data Protection Regulation (GDPR). We are the data controller; reach us at [email protected]. This policy covers both the website and the SPLIT mobile app, and explains what data we collect, how we use it, and the rights you have over it.
1. Data we collect
Account data
- Email address, display name, password hash (salted PBKDF2-SHA256, 200,000 iterations; never stored in plaintext)
- Optional profile: tagline, avatar, height, weight, date of birth
- Account creation timestamp, last-login timestamp, IP address of last session
Training data
- Activities synced from Garmin / Polar / Suunto via OAuth — GPS traces, heart rate, pace, cadence, power, all metrics your device recorded
- Manual activities you log, including notes
- Planned workouts, goals, race dates, target times
- Body composition (weight, body fat, muscle mass, hydration) — if synced from Garmin scale or entered manually
Mobile app data
- Location: precise GPS while you record an activity, including in the background so recording continues with the screen locked. Location is used only to record your route and live-track a run you start — never collected when you are not recording.
- Messages: direct messages between friends are stored encrypted, never as plain text. The key belongs to your account rather than to one handset, so your conversations are readable on every device you sign in on. That also means we hold the key and are technically able to read message content; we do not, except where we are legally required to. If you need a conversation nobody but the two of you can ever open, use a dedicated end-to-end encrypted messenger instead of this one.
- Push token: a device notification token (via Apple/Expo) so we can notify you of likes, comments, follows, messages, and off-route alerts. You can disable notifications in your OS settings.
- Photos you attach (activity photos, avatar) — only images you explicitly pick.
Usage + technical data
- Session cookie to keep you logged in (
session, 30-day sliding expiry, HttpOnly, Secure) - Browser user-agent + version for compatibility debugging
- API request logs (IP, path, timestamp) — retained 14 days then deleted
2. How we use it
- Deliver the service: render your dashboard, calculate stats, generate training plans, push structured workouts to Garmin
- Improve training recommendations: the AI Coach reads your last 30 days of data to give contextual advice
- Social features (optional): share activities with friends you follow, participate in challenges, send encrypted direct messages
- Live tracking + safety: record your route and warn you when you drift off a planned route
- Billing (premium users): process subscription payments via Apple In-App Purchase (in the app) or LemonSqueezy (on the web)
We never sell your data, and we never use it to train AI models. Where an AI provider processes your data on our behalf, it is named in section 4.
3. Where it lives
- Primary server in Germany (netcup GmbH, Nuremberg). A standby server at Hetzner (Falkenstein, Germany) is kept for failover
- PostgreSQL database on that server. The disk is not currently encrypted at rest; access is limited to key-based SSH and the application service. Encryption at rest is on our roadmap, and this line changes when it ships
- Nightly database dumps kept on the same host for 14 days, then deleted. Until 5 September 2026 a compressed copy of the database was also pushed nightly to a private repository at GitHub (GitHub, Inc., USA); that transfer has been stopped and the historical copies are being deleted
- LemonSqueezy (merchant of record for web purchases) and Apple hold your payment details — we only see a subscription status
- Garmin Connect OAuth tokens stored server-side and never exposed to your browser
- Direct messages are stored as ciphertext only — never as plain text, and decrypted only in the app with your account's key
4. Third parties
- Garmin / Polar / Suunto: receives push requests when you schedule workouts; we send workout structure + target date, nothing else
- LemonSqueezy / Apple / RevenueCat: premium-tier billing — Apple In-App Purchase processes app subscriptions, RevenueCat records subscription status, LemonSqueezy (Lemon Squeezy, LLC, USA) is the merchant of record for web payments. None receive your training data
- Brevo: (Sendinblue SAS, France) delivers our transactional email — verification, password reset, account notices. Receives your email address and display name
- Apple / Expo: delivery of push notifications (device token only)
- AI features: the coaching chat runs on a language model hosted on our own EU server. Automated activity summaries and the “deep analysis” option are generated with Claude by Anthropic (Anthropic PBC, USA), which processes the data on our behalf. For those we send your recent activities (distance, pace, heart rate, training load, notes you wrote), body composition, VO2max, readiness and training-status metrics, goals, age and display name. We do not send your email address. Because Anthropic is outside the EU/EEA this is an international transfer; we are putting the formal data-processing terms and transfer safeguards for it in place and will name them here. You can object to AI processing of your data at any time (section 5)
- Open-Meteo: for forecast data on upcoming workout days; we send coordinates and date, not identity
- Map tiles: Esri (Esri Inc., USA) on the website and VersaTiles (OpenStreetMap data, hosted in Germany) in the app. Your browser or app requests tiles directly, so the provider sees your IP address and the map area you view, not your identity
- Route building and address search: OpenRouteService (HeiGIT, Germany) and Nominatim (OpenStreetMap Foundation) receive the coordinates or address text you enter, not your identity
No advertising networks, no tracking pixels, no Google Analytics.
5. Your rights under GDPR
- Access: export every byte of your data via Settings → Data & privacy → Export account data — available on every tier, never behind a paywall
- Deletion: request full account deletion from Settings; data is purged within 14 days (backups rotate out within 14)
- What deletion leaves behind: one row recording that your email address has already used its free trial. It holds a one-way cryptographic hash of the address — not the address itself — and two yes/no flags. It cannot be reversed to identify you, is never used to contact you or to rebuild your account, and exists only so a free trial cannot be claimed repeatedly by deleting and re-creating an account. We keep it under our legitimate interest in preventing abuse (GDPR Art. 17(3)); everything else about you is erased
- Correction: edit profile + metric overrides directly in Settings
- Portability: one-click archive with your full account as JSON, activities as CSV, and a GPX track per GPS activity
- Objection: email [email protected] to object to any processing
6. Cookies
We use these cookies:
session— required, keeps you logged insplit_ref— set only when you arrive through a referral link (?ref=); keeps the campaign code for 30 days so the referrer is credited if you sign up. It contains the campaign code only. Your dark/light preference is kept in your browser's local storage, not in a cookie
No advertising cookies and no cross-site tracking.
7. Children
SPLIT is not intended for users under 16. If you believe a child has created an account, email [email protected] and we will delete it immediately.
8. Changes to this policy
Material changes are announced on the home page 14 days before taking effect. The "Last updated" date above always reflects the current revision.
9. Contact
Data Protection questions: [email protected]
General support: [email protected]
Data Protection Authority (DK): Datatilsynet