Koers

Koers is operated by Lintel Works LLC ("Lintel Works," "we," "us"). This policy explains what personal data Koers collects, why we collect it, who we share it with, and the choices you have.

Koers is a training platform for endurance cyclists. Most of what we hold about you is training data — rides, power numbers, heart rate, body weight, the plan you're following. We treat that as sensitive, because it is.

Contact: privacy@koers.app
Postal address: Lintel Works LLC, 901 Farnam St, Unit 441, Omaha, Nebraska 68102, United States

01

Who is responsible
for your data.

Lintel Works LLC is the data controller for information collected through Koers (koers.app and the Koers mobile applications).

02

What we
collect.

Information you give us

  • Account information — email address, display name, password (stored only as a salted hash), or the identifier returned by Google or Apple if you sign in with those services.
  • Athlete profile — date of birth or age, body weight, functional threshold power (FTP), training zones, weekly hours available, rest days, and similar training parameters.
  • Goals and events — target races, dates, and priority.
  • Messages you send the coach — free-text conversations with Mia, the Koers coaching assistant, including anything you volunteer about how you're feeling, sleeping, or training.
  • Weight and body-composition entries, where you choose to log them.

Information from your connected devices and accounts

When you authorize a connection, we retrieve:

  • Completed activity data — date, duration, distance, elevation, and the recorded data streams for the activity, including power, heart rate, cadence, speed, temperature, and GPS position where your device recorded it.
  • Lap and interval structure for the activity.
  • Device make and model — which head unit or watch recorded the activity. We store and display this because some device partners require us to attribute the source of the data we show you.
  • Athlete settings held by that service, such as threshold values and zones, where the service provides them.
  • Calendar availability — if you connect Google Calendar, we read free/busy times only. We do not read event titles, descriptions, locations, attendees, or any other event content.

We request the narrowest scope each service offers for the above. We do not request sleep, blood-oxygen, or daily health and wellness data from device partners.

Information collected automatically

  • Technical and log data — IP address, browser or app version, device type, timestamps, and error diagnostics.
  • Basic usage analytics — which screens are opened and which features are used, so we can find what's broken and what isn't working.

We do not use advertising cookies, cross-site tracking pixels, or third-party ad networks.

03

How we use
your data.

We use your data to:

  • Generate and maintain your training plan, and adjust it as your training progresses.
  • Compare completed rides against prescribed sessions and compute training load, fitness, and readiness.
  • Deliver written coaching from Mia — the daily briefing, ride analysis, and conversations you have with her.
  • Send Koers-generated structured workouts to your connected device, where you have enabled that.
  • Operate, secure, debug, and improve the service.
  • Contact you about your account, service changes, and — if you opt in — product updates.

We do not use your data to build advertising profiles. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

04

Automated processing
and AI.

This section matters, so we're being specific about it.

Koers uses large language models to write coaching text. When Koers prepares a briefing, analyzes a ride, or responds to a message you send Mia, we transmit relevant context to a third-party model provider (Anthropic) to generate that text. That context can include your training plan, recent ride metrics, your profile parameters such as FTP and weight, and the content of your coaching conversations.

Your data is sent to Anthropic as input at the time a response is generated. It is not used to train Anthropic's models.

We do not train any machine-learning model on your data, our own or anyone else's.

Training plans are generated by a rule-based engine, not by a language model. The model writes the explanation; deterministic logic makes the decision.

Coaching is not medical advice. Koers does not diagnose, treat, or make clinical judgments.

All insights, recommendations, and analysis produced by Koers — including anything generated from data supplied by a connected device — are for fitness and performance purposes only. They are not medical advice, clinical diagnosis, or health assessment. Consumer fitness devices are not medical devices, and the data they produce should not be treated as clinical measurement. If something in your training concerns you physically, talk to a doctor.

If you would rather not have your data processed this way, you cannot use the coaching features of Koers, because that processing is the service. You can delete your account at any time.

05

Who we share
data with.

We share personal data only with service providers who process it on our behalf, under contract, and only for the purposes above.

Provider Purpose Location
Supabase Database, authentication, file storage United States
Vercel Application hosting, delivery, and site analytics United States
Anthropic Language model inference for coaching text United States
Wahoo Fitness Activity sync and workout delivery, where you connect it United States
COROS Wearables Inc. Activity sync and workout delivery, where you connect it United States
Google Sign-in and calendar free/busy, where you connect it United States
Formspree Transactional email United States

We share data with a device or service partner only for accounts you have explicitly connected, and only to the extent needed to move data between Koers and that service.

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will tell you before your data is transferred.

We do not sell your personal information.

07

How long we
keep it.

  • Account and training data — for as long as your account is active.
  • When you disconnect a device or service — we revoke the access tokens immediately and permanently delete the data sourced from that connection within 24 hours, automatically. You don't have to ask us.
  • After you delete your account — we delete your personal data within 30 days. Data sourced from connected services is deleted within 24 hours.
  • Logs and diagnostics — up to 90 days.
  • Backups — deleted data may persist in encrypted backups for up to 30 days before those backups age out. It is not restored to the live service.

Some limited retention beyond these windows may be necessary where required by law, or for security, fraud prevention, or dispute resolution.

08

Your
rights.

Wherever you live, you can:

  • Access the data we hold about you.
  • Correct anything that's wrong.
  • Delete your account and your data.
  • Export your training data in a portable format.
  • Withdraw consent for any connected service, at any time, from account settings.

If you're in the EEA or UK, you also have the right to restrict or object to processing, and to complain to your local data protection authority.

If you're in California, you have the rights to know, delete, correct, and to limit the use of sensitive personal information under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so there is no opt-out to offer — but you can exercise the other rights below. We will not discriminate against you for exercising them.

To make a request, email privacy@koers.app. We will respond within 30 days. We may need to verify your identity before acting on a request.

09

Security.

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Data at rest is encrypted by our infrastructure providers.
  • Database access is governed by row-level security, enforced per athlete from the moment an account is created. One athlete's data is not reachable from another athlete's session.
  • OAuth tokens for connected services are encrypted at rest and are never exposed to the browser or mobile client.
  • Passwords are stored as salted hashes. We never see your plaintext password.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

10

International
transfers.

Koers is operated from the United States and your data is stored and processed there. If you are in the EEA or UK, transfers are made under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

11

Children.

Koers is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, email privacy@koers.app and we will delete it.

12

Changes to
this policy.

If we make a material change — new categories of data, a new purpose, a new class of recipient — we will notify you by email or in the app before it takes effect. The "last updated" date at the top always reflects the current version.

13

Contact.

Privacy questions, data requests, and general contact: privacy@koers.app
Lintel Works LLC, 901 Farnam St, Unit 441, Omaha, Nebraska 68102, United States