Privacy Policy
Last updated: July 30, 2026
1. Introduction
Beina ("we", "our", or "us") is operated by Veipha SAS, a French société par actions simplifiée registered under SIREN 993 855 154. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI coaching platform and websites at beina.ai and app.beina.ai.
2. Information We Collect
Account Information
- Email address
- Name (optional)
- Account preferences and settings
- Target event(s) you are training for
Strava Data (with your permission)
When you connect your Strava account, we access:
- Your Strava athlete profile (name, ID)
- Activity data (rides, runs, workouts)
- Activity metrics (distance, duration, elevation, heart rate, power)
- Activity timestamps and locations
Garmin Connect Data (with your permission)
When you connect your Garmin Connect account, we access:
- Activity data and metrics (workouts, rides, runs)
- Daily health metrics (resting heart rate, HRV, body battery, stress)
- Sleep data
- Recovery and fitness indicators
Wahoo Data (with your permission)
When you connect your Wahoo account, we access:
- Activity data (rides and workouts)
- Activity metrics (distance, duration, elevation, heart rate, power)
- Activity timestamps
Polar Data (with your permission)
When you connect your Polar Flow account, we access:
- Exercise data (training sessions)
- Exercise metrics (distance, duration, heart rate, power where recorded, calories)
- Exercise timestamps and the recording device
- Physical information (body weight, where you have recorded it)
Training Data
- Training plans and session completion
- Race goals and preferences
- AI coaching analysis results, predictions, and conversation history with the Beina Coach
- Race history and past results you choose to share
3. How We Use Your Information
We use your information to:
- Provide personalised, event-specific training plans
- Generate AI-powered race readiness predictions and coaching insights
- Analyse your training history to identify gaps, fatigue, and progression
- Send you updates about your training and race preparation (with your consent)
- Improve our services and develop new features
4. Third-Party Services
We use the following third-party services to deliver Beina:
Strava
We integrate with Strava's API to import your activity data. You can disconnect Strava at any time from your account settings. See Strava's Privacy Policy.
Garmin Connect
We integrate with the Garmin Connect Developer Program APIs to import your activity, health, and (where applicable) women's health data. Garmin data is collected via webhook push from Garmin's servers (Activity API, Health API, Women's Health API, plus User Deregistration and User Permissions endpoints). It is used solely to deliver personalised coaching to the individual user who connected their account (race predictions, training-load metrics, readiness scoring, personalised plans — see Section 3 above). It is processed on our own infrastructure and, for AI-coaching analysis, by Anthropic's Claude API as a sub-processor (see the Anthropic subsection below) — Anthropic does not train models on user data via their API. It is stored in our Railway PostgreSQL database located in the Netherlands (European Union), with TLS in transit and access restricted to Beina application services and authorised Veipha SAS personnel (see Section 5). It is retained until you delete your Beina account, after which stored Garmin data is deleted within 30 days except where retention is required by law (see Section 6). Disconnecting Garmin, or deregistering Beina from within Garmin Connect, immediately revokes our access and deletes the Garmin tokens we hold, so no further data can be imported; activity and health data already imported remains on your Beina account so your training history and fitness trend stay intact, and you can have it removed by deleting your account or by asking us. We do not sell Garmin data, do not share it with third parties beyond the sub-processors named in this policy, and do not aggregate or anonymise it for resale. You can disconnect Garmin at any time from your account settings. See also Garmin's Privacy Policy.
Wahoo
We integrate with the Wahoo Cloud API to import your activity data and to push Beina-generated workouts to your Wahoo devices. Wahoo data is collected via webhook push from Wahoo's servers when you complete or sync an activity. It is used solely to deliver personalised coaching to the individual user who connected their account (race predictions, training-load metrics, readiness scoring, personalised plans, see Section 3 above). It is processed on our own infrastructure and, for AI-coaching analysis, by Anthropic's Claude API as a sub-processor (see the Anthropic subsection below). Anthropic does not train models on user data via their API. It is stored in our Railway PostgreSQL database located in the Netherlands (European Union), with TLS in transit and access restricted to Beina application services and authorised Veipha SAS personnel (see Section 5). It is retained until you delete your Beina account, after which stored Wahoo data is deleted within 30 days except where retention is required by law (see Section 6). Disconnecting Wahoo immediately revokes our access and deletes the Wahoo tokens we hold, so no further data can be imported; activity data already imported remains on your Beina account so your training history and fitness trend stay intact, and you can have it removed by deleting your account or by asking us. We do not sell Wahoo data, do not share it with third parties beyond the sub-processors named in this policy, and do not aggregate or anonymise it for resale. You can disconnect Wahoo at any time from your account settings. See also Wahoo's Privacy Policy.
Polar
We integrate with the Polar AccessLink API to import your training and body-weight data. Polar does not offer a way to send workouts to Polar devices, so this integration is read-only. Polar data is collected via webhook push from Polar's servers when you sync a session to Polar Flow, and on request when you press Sync. It is used solely to deliver personalised coaching to the individual user who connected their account (race predictions, training-load metrics, readiness scoring, personalised plans, see Section 3 above). It is processed on our own infrastructure and, for AI-coaching analysis, by Anthropic's Claude API as a sub-processor (see the Anthropic subsection below). Anthropic does not train models on user data via their API. It is stored in our Railway PostgreSQL database located in the Netherlands (European Union), with TLS in transit and access restricted to Beina application services and authorised Veipha SAS personnel (see Section 5). It is retained until you delete your Beina account, after which stored Polar data is deleted within 30 days except where retention is required by law (see Section 6). Disconnecting Polar immediately revokes our access and deletes the Polar tokens we hold, so no further data can be imported; exercise data already imported remains on your Beina account so your training history and fitness trend stay intact, and you can have it removed by deleting your account or by asking us. We do not sell Polar data, do not share it with third parties beyond the sub-processors named in this policy, and do not aggregate or anonymise it for resale. You can disconnect Polar at any time from your account settings. See also Polar's Privacy Policy.
Anthropic (Claude AI)
We use Anthropic's Claude AI to generate training analysis, race predictions, and coaching conversations. Your training and health data is processed by Claude to provide personalised coaching insights. Anthropic does not train models on your data when used via their API. See Anthropic's Privacy Policy.
Supabase
We use Supabase for user authentication. See Supabase's Privacy Policy.
Hosting (Railway and Vercel)
Our application is hosted on Railway (database and API) and Vercel (web app and marketing site). Both providers process your data only as required to deliver the service.
5. Data Storage and Security
Your data is stored securely on servers hosted by Railway (PostgreSQL database, Europe — Netherlands) and Vercel (web). We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal purposes (e.g., financial records under French and EU law).
7. Your Rights
Under the GDPR, you have the right to:
- Access — Request a copy of your personal data
- Correction — Request correction of inaccurate data
- Deletion — Delete your account and associated data
- Disconnect — Disconnect third-party services (like Strava, Garmin, Wahoo, or Polar) at any time
- Export — Request an export of your data
- Object — Object to processing or request restriction
- Lodge a complaint with the CNIL (French data protection authority) at cnil.fr
To exercise these rights, visit your account settings or contact us at the email below.
8. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or sell your data to advertisers.
9. Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect personal information from children under 16.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at: angus@veipha.com
Data Controller: Veipha SAS, 39 Chemin de l'Indiennerie, 69450 Saint-Cyr-au-Mont-d'Or, France. SIREN 993 855 154.
