← Back to About
Privacy & Security

Gains In
Motion

What we store

  • Account info — email, name, and role (athlete or coach).
  • Activities and recovery data (resting heart rate, HRV, VO2max, sleep) from whichever source(s) you connect: Strava (new connections are currently closed — Strava’s API access for GIM is capped at 10 athletes, already in use, though everything below still applies to anyone already connected), via the read-only activity:read (or activity:read_all, if you choose to share private activities) OAuth scope — we never request your segments, kudos, comments, gear, or social connections; or COROS, via COROS’s own OAuth flow, similarly read-only.
  • If you connect Garmin directly, GIM briefly receives your Garmin email and password to set up access via an open-source bridge (see the FAQ) — the password itself is never stored, only the resulting access token, which works the same way Strava/COROS’s tokens do below.
  • If you connect Apple Health or Google Health (via Health Connect) instead, your phone reads that data locally — with your explicit, per-data-type permission — and sends the results directly to GIM. Apple and Google are never involved as a data-sharing party in that flow; they don’t receive anything from GIM, and GIM only sees what your phone hands it.
  • Training data you or your coach create — workouts, goals, plans, and notes.
  • Push notification subscription details, only if you opt in to notifications.
  • Conversations with Gimo, our in-app AI assistant — stored so your conversation history persists across visits. You (or, for a conversation about you, your coach) can see it inside the chat panel any time.

How it's protected

All data lives in a Postgres database (Supabase) behind Row Level Security — every table enforces, at the database level, that an athlete can only ever read their own data, and a coach can only read the athletes they’re actually connected to. This isn’t just an app-level check that could be gotten wrong — it’s enforced on every query, including the ones we write ourselves.

Your Strava and COROS access and refresh tokens are encrypted at rest (AES-256-GCM) before they’re ever written to the database, and only decrypted server-side, momentarily, when an API call needs to be made on your behalf. Apple Health and Google Health don’t involve any token GIM stores at all — see above. The Garmin bridge’s access token is encrypted the same way; your Garmin password itself is held in memory only for the moment it takes to set up access, and is never written anywhere.

All traffic between your device and GIM is encrypted in transit (HTTPS/TLS).

Third parties involved

Stravais a source of your activity data, if you connect it — GIM only reads what you’ve authorized via Strava’s own OAuth flow. If you also grant write access, GIM updates the name and description of one of your Strava activities only when you ask it to, by tapping “Push to Strava” or renaming the activity in GIM. You can also connect Strava for that purpose alone: GIM then imports nothing from Strava and reads it only to find the Strava copy of an activity synced from Garmin or COROS, so it can add its analysis there. Strava may monitor and collect Usage Data and may use Usage Data for any business purpose, internal or external.

COROSis a source of your activity and recovery data, if you connect it — GIM only reads what you’ve authorized via COROS’s own OAuth flow (through their developer platform), and never writes anything back to your COROS account.

Garminis a source of your activity and recovery data via an open-source bridge GIM operates, not Garmin’s own developer platform — Garmin’s official program isn’t currently approving new integrations. This is why it needs your Garmin password directly, unlike every other source above; see the FAQ for the full explanation.

Apple Health and Google Health aren’t data-sharing partners in the usual sense — your phone reads data already stored there (put there by whatever watch or app you use, Strava’s or Garmin’s own apps included) and sends it to GIM directly, with your permission. Apple and Google never receive anything from GIM.

Anthropic (Claude)generates the AI coaching commentary — summaries, recaps, and training plans — and powers Gimo, our in-app chat assistant. Both receive the structured training data needed to do their job (paces, distances, recent activity, targets) — never your credentials or Strava tokens. Gimo additionally receives whatever you type into the chat itself. Consistent with Anthropic’s standard API terms, this data is not used to train their models and is retained only as long as needed to provide the service and meet legal/safety requirements.

Vercel and Supabase host the application and database, respectively.

We don’t sell your data, and don’t share it beyond what’s needed to run the features above.

Your controls

  • Disconnect Strava any time from Settings — this stops future syncing and permanently deletes your synced Strava activity history within 7 days.
  • Revoke access directly from Strava’s own settings instead, if you prefer — we’re notified automatically and delete your synced Strava data on the same 24-hour timeline, with no action needed on your end.
  • Disconnect COROS any time from Settings — this stops future syncing and revokes GIM’s access on COROS’s side. Unlike Strava, previously-synced COROS activities aren’t automatically deleted — email us if you’d like those removed too.
  • Disconnect the Garmin bridge any time from Settings — this stops future syncing and removes the stored access token. Previously-synced activities aren’t automatically deleted — email us if you’d like those removed too.
  • Revoke Apple Health or Google Health access any time from your phone’s own Settings app (iOS: Settings → Privacy & Security → Health; Android: the Health Connect app’s permissions) — GIM simply stops receiving new data, nothing further to do here.
  • Delete your account any time from Settings — this revokes any connected Strava, Garmin, or COROS authorization and permanently removes your account and its associated training data.
  • Push notifications are opt-in per device and can be revoked at any time.

Your rights

You can ask us to access, correct, export, or delete the personal data we hold about you at any time by emailing privacy@viara.tech. Most of this you can also do yourself directly from Settings or your Profile page. If you believe we haven’t handled your data properly, you also have the right to lodge a complaint with your local data protection authority.

Questions or concerns

Terms & Conditions →

© 2026 ViaraNexus Technologies Pvt Ltd. All rights reserved. Gains In Motion and its contents are proprietary and confidential.