The short version
Summit Line is a training almanac for runners. We hold your account, the runs that sync from your connected watch account, the metrics we derive from them, and the notes you write. We use that data to draw your charts, project your races, and feed the AI coach you ask to read your training. We do not sell your data, do not run ads, and do not load third-party trackers. You can export everything you have here and delete it on demand.
Who we are
Summit Line is operated by Jared Furubotten (“we,” “us”). The product is in private beta. Reach the privacy desk at privacy@runsummitline.com. Postal contact is at the foot of this page.
What we collect
Summit Line is built around your training data. The categories below are everything we hold, nothing is gathered silently in the background.
- Account. Email address, password (hashed by Supabase , we never see the cleartext), display name, account creation date.
- Profile. Birth year, sex, weight, resting heart rate, max heart rate, timezone. You enter these; you can edit them; you can clear them.
- Watch connection. Your connected watch account ID and the OAuth access + refresh tokens we need to read your activities. In production, those tokens are encrypted at the column level.
- Activities and streams. Distance, moving time, elevation, pace, GPS path, per-second heart rate, plus the activity name and any notes that come in from your connected watch account or that you write here. Your watch provider may itself aggregate data you recorded on your own GPS watch or device.
- Billing. Your subscription status (trialing, active, past due, canceled) and the Stripe customer and subscription identifiers tied to your account. We do not store raw card numbers; Stripe holds those.
- Derived metrics. TRIMP per run, CTL/ATL/TSB curves, vertical load, training plans, race goals, everything we compute on top of the raw activity data.
- Operational. Feedback messages you submit, server-captured client errors (route + error digest + user-agent string, no body payload), AI usage counters used to enforce the daily cap.
- Trial-abuse prevention. At signup, a hashed device identifier (from a first-party cookie) and a hashed copy of your IP address, kept in a separate fraud ledger so we can tell whether a device or network has already claimed a free trial. We never store the raw device identifier or raw IP, only the one-way hash. This ledger is not used for tracking or advertising, and it is separate from the 90-day audit log described below.
What we do not collect. No raw card numbers (Stripe processes and holds your card details; we only see your billing status and Stripe identifiers). No location outside the GPS that rides on synced runs. No address book, no social graph, no ad identifiers, no cross-site tracking pixels.
Why we collect it
- Account + profile to authenticate you and personalize pace and HR-zone math.
- Watch activity data + derived metrics to draw your charts, build your plan, and project race outcomes.
- Billing status + Stripe identifiers to run your subscription, start and end your trial, and give you access to paid features.
- Activity names and your notes to give the AI coach enough texture to write a useful summary when you ask for one. When you generate a Coach Note or race brief, summary fields derived from your synced activities (activity names, notes, distance/elevation/HR aggregates, training-load metrics) are sent to Anthropic for a one-shot AI brief. Anthropic does not train models on this data per their commercial API terms.
- Feedback + client errors to fix the product when it breaks.
- AI usage counters to keep one person from burning through the shared daily quota.
Who we share it with
We use a short list of subprocessors to run the product. None of them receive your data for their own marketing. In summary:
- Vercel: hosts the app and runs the edge runtime.
- Supabase: database, authentication, transactional auth email.
- Your watch provider (Garmin, Coros, or Suunto): the source of your activity data, via your OAuth grant. Your provider may itself aggregate data you recorded on your device.
- Stripe: our payment processor. Stripe processes your payment card details and billing metadata on our behalf to run your subscription. We store only your billing status and Stripe customer and subscription identifiers; raw card numbers stay with Stripe.
- Anthropic (Claude): processes activity names, your notes, and aggregate metric summaries (CTL/ATL/TSB, weekly mileage, recent splits) to produce the AI coach’s written observations. Per Anthropic’s Commercial Terms of Service and privacy commitments, API content is NOT used to train their models by default. Data residency: Anthropic’s primary serving region for this account is the United States. We send only already-sanitized data, raw GPS tracks, your email, and device identifiers never leave Summit Line for the AI path.
- Resend: sends operator-only digest emails (feedback, error counts). Not used for marketing to you.
Coaching: data you share with a coach
Summit Line lets you connect with a coach. When you accept a coaching invite, a human coach (a real person, not just the AI) can see your data. The coach sees only what each consent scope you grant authorizes, and nothing outside those scopes:
- Activities: your runs and their streams, including per-second heart rate, pace, and elevation.
- Fitness metrics: your derived load and fitness curves (CTL, ATL, TSB).
- Plan and races: your training plan and your goal races, including crew and pacer names you have entered.
- Body data: where a scope includes it, your sex, birth year, heart rate, and weight travel with the metrics and plan you share.
A coach is an independent third party, not Summit Line staff. You stay in control: you can change each scope individually or end coaching at any time from Settings. Ending coaching revokes the coach’s access, the relationship is dropped and the coach can no longer read or edit any of your data. Your private per-activity notes are never shared with a coach unless you explicitly opt that scope in.
How long we keep it
- Account, activities, derived metrics: for as long as your account exists. When you delete your account, we cascade-delete everything tied to your user ID.
- Client error logs: 30 days, then purged on a rolling basis.
- Feedback messages: 12 months from submission.
- AI cache: invalidated automatically when the inputs change; deleted entirely on account deletion.
- Watch tokens: revoked and dropped immediately when you disconnect your watch account on either side.
- Billing records: subscription status and Stripe identifiers are kept for as long as your account exists and as required for tax and accounting records, then removed.
- Backups: 30-day rolling. Deletions propagate as old backups age out.
- Audit log: 90 days. Holds your IP + user-agent for security-relevant events (sign-in, sign-out, account locked) so we can investigate any suspicious activity. Purged on a rolling basis.
- Share-link revocations: 37 days (the share-link’s 30-day TTL plus a 7-day buffer). Lets a revoked share-link stay revoked for as long as its underlying token would otherwise still validate.
- Trial-abuse fraud ledger: retained indefinitely. Holds a hashed device marker and a hashed signup IP, never the raw values, so we can tell whether a device or network has already claimed a free trial. Kept on a fraud-prevention basis rather than a fixed window.
If we have to notify you of a breach
Summit Line is not a HIPAA-covered entity, but the FTC’s Health Breach Notification Rule (effective July 2024) covers direct-to-consumer health apps that handle individually identifiable health information, which includes the heart-rate, weight, and training data we process. If a breach affecting your information ever occurs, we will:
- Notify affected users by email within 60 days of discovering the breach, with details of what data was involved and the steps you should take.
- Notify the U.S. Federal Trade Commission within the same window if 500 or more individuals are affected, or by year-end for smaller incidents.
- Publish a notice on this page describing what happened and what we’re doing about it.
Your rights
- Access. Pull a full export of your data from Settings → Export.
- Portability. The export is a machine-readable archive you can take elsewhere.
- Correction. Edit your profile in Settings.
- Erasure. Settings → Account → Delete my account cascades the delete and revokes your connected watch grant.
- Restriction, objection, withdrawal of consent. Email privacy@runsummitline.com and we will action it.
- Lodge a complaint with your local data protection authority. We will respond to rights requests within 30 days.
Cookies and tracking
Strictly-necessary, first-party cookies only. We do not use analytics cookies, advertising cookies, or third-party cookies of any kind.
sb-*: Supabase session cookies. Required to keep you logged in.sl_view_as: admin preview cookie. Set only when an admin uses the “view as user” tool; never set on regular accounts.oauth_state: 10-minute CSRF token used during the watch connect handshake.sl_device: strictly-necessary fraud-prevention cookie, a random identifier with no personal data in it. Used only to detect repeat free-trial signups from the same device. 400-day lifetime.
Security
The Postgres database is encrypted at rest by Supabase. Every request to Summit Line travels over HTTPS. Every user-data table has row-level security, the database itself enforces that you only see your own rows. Watch tokens are encrypted at the column level in production. Service-role keys are held only by the server. If a breach occurs, we will notify the relevant supervisory authorities within 72 hours and affected users without undue delay.
Children
Summit Line is not for anyone under 16. We require an age attestation at signup. If we learn we have collected data from someone under 16, we delete it.
California rights (CCPA / CPRA)
The categories of personal information we collect, the purposes, sources, and recipients are listed above. California residents have the right to know what we have collected, to delete it, to correct it, to limit our use of sensitive personal information, and to opt out of sale or sharing. Summit Line does not sell or share your personal information, including for cross-context behavioral advertising. To exercise any of these rights, email privacy@runsummitline.com.
Washington rights (MHMDA)
Heart rate, GPS, weight, and the metrics we derive from them are consumer health data under the Washington My Health My Data Act. The specifics of how we handle that category, what counts, who sees it, and how to revoke consent, live in our standalone Consumer Health Data Privacy Policy.
Changes to this policy
We version this policy. For material changes, new categories of data, new subprocessors, expanded use of existing data, we will email registered users at least 30 days before the change takes effect. Minor edits (typos, link fixes) ship without notice but are reflected in the version line at the top of the page.
Contact
privacy@runsummitline.com
10742 Caminito Cascara, San Diego, CA 92108