Privacy Policy
Last updated: 17 August 2026
Allure (“Allure”, “we”, “us”, or “our”) operates the Allure training platform and website (the “Service”). This Privacy Policy explains what personal data we collect, how we use it, and the rights you have. By using the Service, you agree to this Policy. When you create an account, you confirm you are at least 18 years old and consent to our processing and interpretation of your training and health-related data as described here.
1. Information we collect
- Account information — your name, email address, and a securely hashed password when you create an account.
- Training & activity data — the activity files you upload (such as .fit files) and the metrics we derive from them (duration, distance, power, heart rate, pace, elevation, GPS routes, training load, and related analytics).
- Connected services — if you connect a third-party account such as Strava, we access the activity and profile data you authorise, using tokens you can revoke at any time.
- Profile & preferences — settings such as thresholds (e.g. FTP), units, primary sport, and dashboard layout.
- Technical & usage data — IP address, browser and device type, and log data, used to operate and secure the Service.
- Local storage — a login token and interface preferences stored in your browser (see our Cookie Policy).
2. How we use your information
- To provide, maintain, and secure the Service and your account.
- To compute training metrics and analytics from your activities.
- To sync activities from services you choose to connect.
- To personalise your experience (saved layouts, thresholds, units).
- To communicate with you about your account, security, and updates.
- To improve the Service and develop new features.
- To comply with legal obligations and enforce our Terms.
3. Legal bases (EEA / UK users)
Where the GDPR applies, we process your data on the following bases: performance of our contract with you (to provide the Service), your consent (e.g. connecting Strava or opting into communications), our legitimate interests (security and improving the Service), and compliance with legal obligations. You may withdraw consent at any time.
4. How we share information
We do not sell your personal data. We share it only:
- With service providers who host and operate the Service on our behalf (e.g. cloud hosting and database providers), under contracts requiring them to protect your data.
- With third-party services you connect (e.g. Strava), only as needed to provide the integration you request.
- Where required by law, or to protect the rights, safety, and security of Allure, our users, or the public.
- In connection with a business transfer (merger, acquisition, or sale of assets), subject to this Policy.
5. Third-party services
If you connect Strava or use maps and routing, your use of those services is also governed by their own terms and privacy policies. We are not responsible for the practices of third parties.
6. Data retention
We keep your personal data for as long as your account is active or as needed to provide the Service. You can delete your account and associated data at any time; we may retain limited records where required by law or for legitimate business purposes.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Residents of the EEA/UK (GDPR) and California (CCPA/CPRA) have additional rights, including the right not to be discriminated against for exercising them. To exercise any right, contact privacy@allure.app. You may also lodge a complaint with your local data-protection authority.
8. Data security
Data security is our top priority. Protecting your account and your training data is something we take seriously at every layer of the Service, and it guides how we build and operate Allure. We use industry-standard technical and organisational measures, including:
- Encrypted connections (TLS/HTTPS) for all data in transit.
- Passwords stored only as salted, hashed values — never in plain text.
- Authenticated, access-controlled endpoints, so your data is only ever accessible to you.
- The principle of least privilege for internal and third-party access.
- Ongoing monitoring for, and prompt remediation of, security issues.
We continually review and strengthen these safeguards. That said, no method of transmission or storage is ever completely secure, and we cannot guarantee absolute security. If we ever become aware of a breach affecting your data, we will act promptly and notify you where required by law.
9. International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards for such transfers.
10. Children
The Service is intended for adults. It is not directed to, and is not intended for use by, anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us with data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. We will post the new version here and update the “Last updated” date. Material changes may be communicated to you directly.
12. Contact
Questions about this Policy or your data: privacy@allure.app.