1. Data controller
The controller of your personal data is:
Grzegorz Walencik
Correspondence address: Tuwima 2/5, 82-300 Elbląg, Poland
Email: kontakt@ultrasoul.pl
Website: https://ultrasoul.pl
The UltraSoulAI project is run on a sole-proprietor basis. We have not appointed a formal Data Protection Officer (DPO), because the scale of processing does not require one under Article 37 of the GDPR. Direct any data-protection matters straight to kontakt@ultrasoul.pl — we respond within 30 days. UltraSoulAI is operated from Poland. To the extent Article 27 of the UK GDPR requires a UK representative for users in the United Kingdom, we will appoint one and publish their contact details here before any general launch to UK users; until then you can raise any data-protection matter with us directly at the address above.
2. What data we collect
2.1 Data provided directly by the user
| Category | Examples | Legal basis |
|---|---|---|
| Analysis form data | Race type, distance, time, physical symptoms, nutrition plan, weight, sex, age | Art. 6(1)(b) GDPR (performance of a contract) + Art. 9(2)(a) GDPR (explicit consent for health data) |
| Email address | Provided when signing up for follow-up or the newsletter | Art. 6(1)(a) GDPR (consent) |
| Nutrition context | What you ate before training, the number of gels, electrolytes, supplements | Art. 6(1)(b) GDPR + Art. 9(2)(a) GDPR |
2.2 Data from sports integrations
| Source | Type of data | What we do NOT store |
|---|---|---|
| Strava | Heart rate (HR), pace, elevation, cadence, duration, distance, temperature (where available) | GPS coordinates are not stored |
| Garmin Connect (integration in rollout) | Once live: heart rate, pace, elevation, cadence, HRV, Body Battery, stress score, daily summaries | GPS coordinates will not be stored |
A note about GPS:
GPS coordinates are received from Strava (and, in future, Garmin Connect) while activity data is being fetched, but they are not saved in our database. We store only the aggregated numeric streams (heart rate, pace, elevation, cadence, distance) in JSONB format. We also do not store raw FIT/GPX files.
2.3 Health data (Art. 9 GDPR)
Some data may qualify as „health data” within the meaning of Art. 9(1) GDPR:
- Heart rate (HR), heart-rate variability (HRV), Body Battery
- Physical symptoms reported in the form (nausea, cramps, vomiting, dizziness)
- Biometric data: weight, sex, age
This data is processed solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), given by actively ticking a checkbox before the analysis begins. It is used only to generate the analysis and is not shared with third parties other than the entities listed in section 5.
2.4 Data collected automatically
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Protection against abuse (rate limiting) | Art. 6(1)(f) (legitimate interest) |
| Device and browser type | Ensuring the app works correctly | Art. 6(1)(f) (legitimate interest) |
We do not use tracking cookies, advertising pixels or third-party analytics tools.
Server technical logs (including the IP address and diagnostic messages) are retained for a maximum of 7 days at our hosting provider, after which they are automatically deleted. We do not store the raw content of analyses or GPS data in them.
3. Purpose and legal basis for processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| AI sports-nutrition analysis | Art. 6(1)(b) (performance of a contract) + Art. 9(2)(a) (explicit consent) | Until the account is deleted or consent is withdrawn |
| Personalising supplement recommendations | Art. 6(1)(b) (performance of a contract) | Until the account is deleted |
| Sending follow-up emails | Art. 6(1)(a) (consent) | Until you unsubscribe (link in every email) |
| Strava / Garmin Connect integration | Art. 6(1)(b) (performance of a contract) | Until the integration is disconnected |
| Protection against abuse | Art. 6(1)(f) (legitimate interest) | 7 days (technical-log retention at the hosting provider) |
4. Processing by AI (artificial intelligence)
Data from the forms and sports integrations is processed by the Claude AI model (provider: Anthropic, PBC) in order to generate the nutrition analysis.
How it works:
- Your data is sent to the Anthropic API as context for the query to the AI model
- The model generates an analysis, which is returned to the app and saved in the UltraSoulAI database
- We use the commercial Claude API — under the Anthropic policy in force from 14 September 2025, data sent to the API is retained by Anthropic for a maximum of 7 days and then deleted automatically
- Data sent to the Claude API is not used to train AI models — this is a separate regime from Anthropic’s consumer products (Claude.ai), which have a different policy
Legal basis: Art. 6(1)(b) GDPR (performance of a contract — the analysis is the essence of the service) + Art. 9(2)(a) GDPR (explicit consent for health data).
5. Data recipients (processors)
| Recipient | Role | Location | Legal safeguards |
|---|---|---|---|
| Anthropic, PBC | AI processing (Claude API) | USA | Commercial API Terms + SCC. 7-day retention, no use for model training. |
| Supabase, Inc. | Database hosting (PostgreSQL) | Frankfurt, Germany (eu-central-1) | GDPR-compliant, data in the EU |
| Vercel, Inc. | Web application hosting | Global CDN, data in the EU | SOC 2 Type II, DPA + SCC |
| Railway Corp. | API backend hosting | USA / EU | Standard Contractual Clauses |
| Resend, Inc. | Sending transactional emails | USA | EU-US Data Privacy Framework + SCC |
| Strava, Inc. | Sports data provider | USA | OAuth2 authorisation, data fetched at the user's request |
| Garmin Ltd. | Sports data provider (Garmin Connect) | USA / globally | OAuth2 under the Garmin Connect Developer Program |
| Google Ireland Ltd. | Company email handling | EU | GDPR-compliant, data in the EU |
We do not share data with: advertising agencies, data brokers, social media platforms or any third parties for commercial purposes.
5.1 Your data and Garmin Connect
If you connect a Garmin Connect account to UltraSoulAI (once the integration is live):
- OAuth2 authorisation means selected data from your Garmin account is transferred to UltraSoulAI
- Once transferred, processing of that data is governed solely by this UltraSoulAI Privacy Policy — not by Garmin’s policy
- Garmin is not responsible for the processing of data by UltraSoulAI after it has been transferred
- You can disconnect the integration at any time in the app or by writing to kontakt@ultrasoul.pl
- Disconnecting immediately deletes the authorisation tokens and the data synced from Garmin Connect
6. Transfers of data outside the EEA
Some data may be transferred to the USA (Anthropic, Resend, Railway, Vercel). For users in the United Kingdom, transfers of personal data to the United States and other countries outside the UK are made under the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and — for transfers to certified US recipients — the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”). For users in the EEA, transfers rely on the EU Standard Contractual Clauses (Decision 2021/914) and the EU-US Data Privacy Framework. In both cases we apply technical safeguards: AES-256 encryption at rest and TLS 1.3 in transit.
7. Data security
| Measure | Description |
|---|---|
| Token encryption | OAuth tokens (Strava, Garmin) encrypted with AES-256 |
| Transport encryption | HTTPS / TLS 1.3 |
| User authorisation | JWT Bearer tokens (HS256) |
| Rate limiting | Request limits globally + on AI endpoints |
| Data isolation | Each user can access only their own data (JWT user_id) |
| No GPS | Geographic coordinates are not stored in the database |
| No raw files | FIT/GPX files parsed in RAM, deleted after processing |
8. Your rights (Art. 15–22 GDPR)
For users in the United Kingdom, the rights and obligations in this policy apply under the UK GDPR (the retained EU General Data Protection Regulation as it forms part of UK law) and the Data Protection Act 2018; for users in the EU they apply under the EU GDPR. The article numbering used in this policy is the same under both regimes.
You have the right to:
- Access your data (Art. 15)
- Rectification of your data (Art. 16)
- Erasure of your data (Art. 17, the „right to be forgotten”)
- Restriction of processing (Art. 18)
- Portability of your data in JSON format (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3))
How to exercise your rights
- Email: kontakt@ultrasoul.pl
- In the app: disconnecting the Strava/Garmin integration immediately deletes the tokens + synced data
- Unsubscribing from emails: the „Unsubscribe” link in the footer of every email
We respond to requests within 30 days (Art. 12(3) GDPR).
9. Right to lodge a complaint
You have the right to lodge a complaint with the data-protection supervisory authority in your country of residence. If you are in the United Kingdom, this is the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk. If you are in Poland or another EU country, it is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw — uodo.gov.pl, or your local supervisory authority.
11. Data of minors
UltraSoulAI is intended for adults (18+). The reason: the nutrition analysis may suggest supplementation strategies, calorie intake and effort intensity that require mature health judgement and full legal capacity.
We do not knowingly collect data from anyone under 18. If you learn that a minor has provided us with data, please get in touch — we will delete it without delay.
12. Changes to this privacy policy
We will notify you of material changes:
- By a notice in the app
- By email (if you provided an address)
A change to the policy’s content does not change its URL (ultrasoul.pl/polityka-prywatnosci) — if a URL change is technically necessary we will use a 301 redirect.
13. Contact
Email: kontakt@ultrasoul.pl
Website: ultrasoul.pl
This policy is effective from 21.04.2026 and is available at the stable address ultrasoul.pl/polityka-prywatnosci.