Last updated August 3, 2026

MarathonOS Privacy Policy

How 42cal collects, protects, and uses your personal data in the MarathonOS app.

MarathonOS is a race-preparation app operated by 42cal ("we," "us," or "our") that helps runners prepare for a specific race: a countdown, travel and start-line logistics, checklists, pace and fueling plans, readiness analytics built from imported runs, and post-race results and reflections. This Privacy Policy explains how we collect, use, store, and protect your personal data across marathonos.app and the MarathonOS mobile application.

We process personal data in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), Apple App Store Review Guidelines, and the terms of the Strava and Garmin Connect developer programs. When you use our services, you agree to the practices described below.

Note: This privacy policy applies specifically to the MarathonOS app. For the 42cal race directory privacy policy, please visit /privacy-directory.

We collect the following categories of personal and activity data, depending on how you use MarathonOS and the third-party services you choose to connect:

  • Account information: Email address, name, profile image, and authentication identifiers provided via Sign in with Apple or email/password authentication.
  • Running activities: Workout data from Apple HealthKit, Strava, and Garmin Connect, including distance, duration, pace, cadence, cadence variability, calories, elevation, and heart rate.
  • Activity metadata: GPS route geometry, weather tags, perceived effort, notes, device identifiers, and workout type.
  • Race preparation content: Races you create, travel and start-line logistics, key dates, checklists, goal times, pace bands, and fueling plans.
  • Race history: Race names, dates, locations, placements, chip/gun times, race-day conditions, splits, post-race notes and reflections, and related performance data.
  • Workout photos: Photos you attach to workout logs, stored in Supabase Storage.
  • Training plans (legacy): Scheduled workouts, prescribed intensities, completion status, and user-entered notes. Training plans are no longer offered to new users; this data exists only for accounts that created a plan before the feature was withdrawn.
  • Profile and preference data: Time zone, units of measure, primary discipline, injury and fatigue flags, and integration settings.
  • Support communications: Emails or support tickets you send to us, including attachments you voluntarily provide.
  • Technical telemetry: We collect the following technical data to improve MarathonOS and diagnose issues:
    • Device type and iOS version
    • App version and build number
    • Crash reports via Apple's built-in crash reporting system
    • Feature usage analytics via PostHog (with IP anonymization)
    • Network connectivity status
    • Integration sync timestamps and error states

We do NOT collect:

  • Location data outside of workout routes from HealthKit, Strava, or Garmin
  • Microphone or camera access (except when you choose to take workout photos)
  • Contacts, or calendar data (except for accounts with a legacy training plan that enabled calendar sync)

When you sign in with Apple, we receive:

  • Your name (if you choose to share it)
  • Your email address (or Apple's private relay email if you use Hide My Email)
  • A unique user identifier from Apple

We use this information solely to create and authenticate your account. Apple's privacy policy applies to data Apple collects: https://www.apple.com/legal/privacy/

We only collect data from sources that you explicitly authorize:

  • Apple HealthKit: We read workout, heart-rate, and distance data after you grant permissions on your iOS device. We do not write data back to HealthKit without additional consent.
  • Strava API: We access your Strava activities via OAuth2 authorization. Strava tokens and scopes are limited to read operations necessary to sync run data into MarathonOS.
  • Garmin Connect API:We integrate through Garmin's OAuth2 platform to ingest workout files and activity summaries, in compliance with Garmin Developer Program policies.
  • User-entered data: You can manually log runs, create races, build checklists and pace and fueling plans, and record race results and reflections directly within the MarathonOS interface.

We process personal data to deliver and improve MarathonOS:

  • Display dashboards, analytics, and historical trends about your training load and race performances.
  • Calculate personal records, freshness/fatigue scores, and race readiness insights.
  • Synchronize workouts across your connected services and ensure consistent data between devices.
  • Generate race-readiness insights, goal verdicts, pace bands, and fueling timelines from your goal and your imported runs.
  • Send the countdown and race-day notifications you opt into, and populate your Home Screen widget, Lock Screen widget, and pre-race Live Activity.
  • Export legacy training plan workouts to Apple Calendar via EventKit, for the accounts that still have a plan and request calendar sync.
  • Deliver product updates, system alerts, and transactional communications (e.g., integration notices) via Supabase Realtime.
  • Manage your subscription and entitlements through RevenueCat and Apple In-App Purchase.
  • Diagnose performance issues, monitor for abuse, and comply with legal obligations.

We do not use your activity data to train machine learning or artificial intelligence models, fulfilling Strava API requirements. We do not sell data or serve targeted advertising.

We use Supabase Realtime (WebSocket connections) to keep your data consistent across your devices as new runs are imported and as you update races, checklists, and plans. These connections are encrypted and require authentication. You can manage them by signing out or disconnecting integrations.

You can attach photos to workout logs. Photos are:

  • Stored in Supabase Storage (encrypted at rest)
  • Visible only to you
  • Included in data export requests
  • Deleted when you delete the associated workout log

MarathonOS uses Supabase (PostgreSQL) as our primary data store with infrastructure hosted in the United States. We apply the following safeguards:

  • Encryption: All data is encrypted in transit using HTTPS/TLS and at rest via cloud provider-managed keys.
  • Row-Level Security: Supabase Row-Level Security ensures each athlete can access only their own records unless they grant explicit sharing permissions.
  • Credential storage: OAuth tokens and refresh keys for Strava and Garmin are stored securely; iOS tokens are persisted in the Apple Keychain, and server-side tokens are stored encrypted with limited internal access.
  • Operational controls: Access to production systems is restricted to authorized 42cal personnel with role-based access controls and audit logging.
  • No data resale: We do not transfer personal data to data brokers or advertisers.

Despite our safeguards, no system is completely secure. We maintain an incident response plan and will notify affected users and regulators of data breaches as required by law.

We only share your data when necessary to deliver MarathonOS features or when you explicitly request it:

  • Content you choose to share: Race and workout share cards are generated on your device and shared only when you tap Share and pick a destination. We do not publish your races or results anywhere.
  • Service providers:Infrastructure and platform vendors — Supabase, Vercel, RevenueCat, and PostHog — process data on our behalf under data processing agreements and cannot use it for their own purposes.
  • Legal compliance: We may disclose data if required by law, subpoena, or to protect the rights, property, or safety of MarathonOS users.

We never sell personal data, rent contact lists, or share OAuth tokens with unauthorized third parties.

Depending on your location, you have the following rights over your personal data:

  • Access: Request a copy of your training data at any time. We provide exports in JSON or CSV within 30 days.
  • Portability: Transfer your data to another service by requesting a structured export.
  • Correction: Update profile details or submit a request for us to amend inaccurate records.
  • Deletion: Permanently delete your account and all associated data. We erase account data within 30 days of a verified request and revoke connected OAuth tokens.
  • Revocation: Disconnect Strava, Garmin, or Apple Health integrations at any time. When you disconnect, we stop receiving new data and can remove historical data on request.
  • Opt-out (CCPA):California residents can opt out of any data sharing that qualifies as a "sale" or "sharing." MarathonOS does not sell personal information, but you may still submit a request via support@42cal.com.
  • Complaint: EU users can lodge a complaint with their local supervisory authority if they believe our processing violates GDPR.

To exercise any of these rights, email support@42cal.com with the subject "Privacy Request." We may need to verify your identity before fulfilling requests.

In compliance with the Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares - LFPDPPP), users in Mexico have the following ARCO rights:

Your ARCO Rights:

  • Acceso (Access): Request copies of your personal data we hold
  • Rectificación (Rectification): Correct inaccurate or incomplete data
  • Cancelación (Cancellation): Request deletion of your personal data
  • Oposición (Opposition): Object to the processing of your personal data

How to Exercise Your Rights:

To exercise any of your ARCO rights, please contact us at:

We will respond to your request within 20 business days as required by Mexican law.

Data Transfer:

Your personal data may be transferred to and stored on servers located in the United States (Supabase - see Data Storage section). By using MarathonOS, you expressly consent to this international data transfer. Your data is protected by Standard Contractual Clauses (SCCs) and industry-standard security measures.

MarathonOS relies on trusted vendors to deliver the platform. Each provider is contractually bound to protect your data and use it only as instructed:

  • Strava API: Imports running activities and related metrics via OAuth2. We comply with Strava API Terms, including policies prohibiting AI/ML model training and virtual event creation.
  • Garmin Connect API: Syncs workouts and activity metadata. We adhere to Garmin data retention and security requirements.
  • Apple HealthKit: Reads fitness data after device permission. Health data is used solely to populate your training dashboard and is never shared with advertisers.
  • Supabase: Provides SOC 2 Type II compliant database hosting with row-level security and audited access logs.
  • Vercel: Hosts our web pages within ISO 27001 certified infrastructure.
  • RevenueCat: Manages subscription state and entitlements. It receives your user identifier and purchase history from Apple; it does not receive your health or training data.
  • PostHog: Supplies privacy-first product analytics with IP anonymization and respect for Do Not Track signals.
  • Apple Crash Reporting:Collects crash reports via Apple's built-in system to help us diagnose and fix issues.

MarathonOS uses essential cookies and similar technologies to operate the service:

  • Session cookies for authentication and account security.
  • Preference cookies to remember theme settings (light/dark) and unit selections.
  • PostHog analytics with IP truncation and no cross-site tracking.

We do not use advertising networks, third-party marketing pixels, or social sharing trackers. You can manage cookies through your browser settings, but disabling session cookies may limit functionality.

We retain data only as long as needed to provide MarathonOS:

  • Active accounts: Training data is retained indefinitely so long as your account remains active.
  • Deleted accounts: All personal data is permanently erased from our production systems within 30 days of deletion request confirmation.
  • Inactive accounts (no login for 3+ years): We will email you before deleting inactive account data.
  • Integration tokens: OAuth tokens are stored only while integrations remain connected and are revoked immediately upon disconnect.
  • Backups: Encrypted database backups are retained for up to 90 days for disaster recovery, then securely purged. Deleted data may remain in backups during this period.

42cal is based in the United States. If you access MarathonOS from the European Economic Area (EEA), United Kingdom, or other regions with laws governing data collection, we transfer personal data to the U.S. under standard contractual clauses (SCCs) and other appropriate safeguards. We ensure vendors receiving EU personal data maintain comparable levels of protection.

MarathonOS integrates with partner APIs and app distribution platforms under strict compliance obligations:

  • Strava: We use Strava data only to populate your MarathonOS account, do not train AI/ML models or simulate virtual events, and honor athlete privacy and data deletion lifecycle requirements.
  • Garmin Connect:We adhere to Garmin's developer terms, protect OAuth tokens, implement HTTPS and least privilege access, and delete data when accounts are removed.
  • Apple App Store:Our iOS app follows Apple's App Store Review Guidelines, including user consent flows for HealthKit data, respect for parental controls, and clear disclosure of data practices. HealthKit data is never used for advertising or shared for cross-company tracking.
  • Security practices: All data transmissions use HTTPS; integrations use OAuth2 with refresh token rotation and short-lived access tokens.

MarathonOS is intended for athletes aged 13 and older. We do not knowingly collect personal data from children under 13 or the applicable minimum age in your jurisdiction. If we learn that a child has provided us with personal data, we will delete it within 30 days. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@42cal.com and we will delete it within 30 days.

We may update this Privacy Policy to reflect changes in our products, legal requirements, or industry practices. When we make material changes, we will notify you via email and update the "Last updated" date at the top of this page. Continued use of MarathonOS after any changes constitutes acceptance of the revised policy.

For questions, requests, or concerns about this Privacy Policy, reach out to us: