SFSMARTFIT
Sign in
PRIVACY

Privacy & connected athlete accounts

SmartFIT separates data by signed-in user and athlete profile. Provider connections are stored only for providers enabled by the site operator in config.php.

Passkeys and biometrics

SmartFIT stores a public passkey credential and signed authentication metadata. Fingerprint, face recognition, Windows Hello or device PIN verification is performed by your device/authenticator; SmartFIT does not receive biometric templates.

Strava

Strava is handled in a restricted display-only mode. SmartFIT stores encrypted OAuth credentials plus a privacy-minimized keyed identifier for connection ownership/deauthorization matching. Recent activity summaries requested by the signed-in athlete are not inserted into SmartFIT learning. Strava-sourced rows are excluded from Athlete Twin, Route Twin, Personal Heatmap, trajectory learning and model training.

Disconnecting Strava attempts provider-side revocation and removes the local connection.

Optional Google Analytics

When enabled by the site operator, SmartFIT uses Google Analytics 4 only after the visitor explicitly allows analytics. The analytics layer measures page and feature usage without sending athlete names, email addresses, passkey identifiers, provider account IDs, route coordinates, activity-file contents or physiological sensor values.

Disconnect and deletion

Disconnecting an enabled provider removes that athlete's local connection tokens. Users can delete activities from Activity Library and delete athlete profiles from Account.

Support

Contact mitragoyani@gmail.com for privacy or deletion requests.

Back to SmartFIT