SlopeReady privacy
Privacy Policy
This policy explains what SlopeReady collects, what leaves your device, and which data the app does not use. Raw health data stays on your iPhone. Optional AI requests use minimized context that you can inspect.
1. Scope
This Privacy Policy covers the SlopeReady iOS app and the public website at slopeready.app. SlopeReady analyzes Apple Health with read-only access and provides AI coaching for endurance and ski preparation. The app does not require a SlopeReady account.
2. Apple Health and fitness data
If you grant permission, SlopeReady reads selected Apple Health data to calculate readiness, training load, recovery signals, recent workout summaries, and training recommendations. Data may include workouts, heart-rate summaries, HRV, resting heart rate, sleep, active energy, distance, VO2 max, permitted body metrics, and related fitness signals.
- SlopeReady requests read access only and does not write data to Apple Health.
- It does not start or stop workouts, record live sensors, or provide real-time GPS tracking.
- Raw HealthKit samples and raw health history remain on your device.
- When data is missing, SlopeReady shows an insufficient-data state instead of inventing a value.
You can revoke access in iOS Settings → Privacy & Security → Health → SlopeReady. Revoking access stops future reads. Health-derived data already copied into SlopeReady remains locally until you clear or delete it.
3. Local on-device storage
SlopeReady uses SwiftData to store app data on your iPhone. This data may include derived readiness and training-load outputs, cached plans, settings, coach transcripts, and plan revision history. Local storage supports dashboards and coaching history without a SlopeReady account database.
You can clear chat and revision history in Settings → What the coach sees → On-device coach storage. You can wipe local SlopeReady app data with Settings → Data & Privacy → Delete App Data.
4. Subscriptions, purchases, and technical identifiers
SlopeReady offers an optional paid subscription called SlopeReady Pro through Apple in-app purchases. Apple processes payments, billing, refunds, and subscription management under its terms. RevenueCat helps SlopeReady receive and verify subscription-entitlement information.
For purchases and restores, SlopeReady creates a random RevenueCat App User ID in the device keychain. This ID contains no name, email address, Apple ID, Health data, or Apple transaction identifier. SlopeReady sends it to RevenueCat as the app's purchase identifier and to the SlopeReady proxy for entitlement lookup and verification. The proxy links it to another random device identifier for device attestation, usage limits, restore handling, and abuse prevention. The proxy verifies every submitted identifier against RevenueCat before granting entitlement.
The SlopeReady proxy stores the identifier link, subscription status and expiry, product and verification metadata, daily AI-use counters, new-user boost state, coach-message reservation outcomes, and minimal RevenueCat webhook audit data in the operator's AWS RDS database. This monetization ledger does not contain Health data, chat content, Apple transaction IDs, or payment-card information.
SlopeReady keeps monetization-ledger records for up to 24 months to administer subscriptions and restores, prevent fraud and abuse, provide support, meet accounting needs, and satisfy legal obligations. The operator then deletes or de-identifies them unless applicable law requires a longer period.
5. Device-bound free allowance
SlopeReady uses a random device-bound identifier to enforce the free AI-message allowance. The device keychain keeps this identifier after app deletion and reinstallation, which prevents a reinstall from resetting the allowance. The identifier does not sync to iCloud or enter device backups. It contains no workouts, readiness scores, chat messages, Apple Health samples, GPS coordinates, or AI prompts.
Delete App Data intentionally preserves this identifier so the free allowance remains in effect.
6. AI coaching
AI coaching is optional. When you use it, SlopeReady sends minimized context through the SlopeReady proxy to the configured AI provider. The context may include derived readiness scores, confidence and missing-data indicators, recent workout summaries, your training goal and phase, optional profile fields, and a note or chat message you choose to send. The app shows a “What was sent” view for each interaction.
The base AI context does not include your name, email address, Apple ID, phone number, raw full-resolution HealthKit sample streams, or GPS coordinates. Chat tools may send limited, downsampled workout details only when needed to answer your request, such as a heart-rate series for one workout or a coordinate-free elevation, grade, and speed profile.
The proxy protects the provider key, applies request guards and budget controls, and forwards the minimized request. SlopeReady does not use it for long-term health-data storage.
7. App analytics and crash reports
App analytics and crash reports require opt-in consent and start disabled. When you enable them, SlopeReady may send fixed-name product counters to the self-hosted proxy and crash diagnostics to Sentry. Diagnostics can include the app version, device model, iOS version, stack trace, and a random device UUID used for aggregate release-health metrics.
Product analytics may include a random analytics install ID created after consent. The server stores only an HMAC hash of that ID for 180-day cohort retention and funnel reporting. Analytics and crash reports do not include Apple Health data, readiness scores, workouts, chat content, free-form text, GPS location, name, email, Apple ID, phone number, Apple transaction ID, or RevenueCat App User ID.
8. Website data
The public website uses Google Analytics 4 to measure visits and site use. The Google tag uses Consent Mode with analytics and advertising storage denied by default. Before you choose, Google may receive cookieless consent-state signals. If you accept analytics, Google Analytics can use analytics cookies and receive standard web-use data, including the page URL, browser and device information, approximate location derived from network information, and website interactions.
AWS hosting and CloudFront necessarily process standard connection data, such as IP address, requested URL, browser metadata, and request time, to deliver and secure the website. The public website has no account forms or newsletter capture, and it does not send Google Analytics data from the SlopeReady app, Apple Health, or AI coaching. You can accept, decline, or later change your analytics choice with the Privacy settings link in the site footer.
9. Data sharing
SlopeReady shares data only to operate the features you choose:
- Apple processes optional purchases, billing, refunds, and subscription management.
- RevenueCat processes the random purchase identifier and subscription-entitlement information.
- The SlopeReady proxy and configured AI provider process minimized AI requests.
- The self-hosted proxy processes fixed-name app analytics counters only after consent.
- Sentry processes crash diagnostics and limited release-health data only after consent.
- Google Analytics 4 processes website-usage data under the analytics choice described above.
- AWS infrastructure hosts the proxy, monetization ledger, and public website.
SlopeReady does not sell health or personal data, use health data for advertising, or track you across other companies' apps or websites.
10. Your choices and deletion
- Revoke Apple Health permissions in iOS Settings.
- Do not start another AI interaction if you do not want to send a new request. You can inspect each AI payload in the app; previously sent requests cannot be recalled.
- Disable app analytics and crash reports at any time.
- Clear local chat and plan revision history.
- Use Settings → Data & Privacy → Delete App Data to wipe local SlopeReady data and return to onboarding.
- Delete the app to remove its local app container, subject to iOS backup behavior.
Delete App Data removes local SwiftData records, cached Health-derived summaries, plans, chat transcripts, coach audit logs, profile settings, routing flags, analytics consent, and other local SlopeReady identifiers. It also requests deletion of the self-hosted per-install analytics cohort rows when an analytics install ID exists. It does not delete original Apple Health records, the preserved device-bound allowance identifier, Apple or RevenueCat purchase records, or server-side monetization records that must be retained for the purposes above. Contact info@slopeready.app with questions about those records.
11. Health and safety
SlopeReady supports training and coaching. It does not diagnose or treat medical conditions and cannot replace professional medical advice. Readiness scores and AI recommendations may be incomplete or wrong when data is missing, stale, or misinterpreted. Stop exercising and seek professional help if you experience concerning symptoms. Contact emergency services in an emergency.
12. Changes and contact
SlopeReady will revise the “Last updated” date when this policy changes. Material changes should also appear in App Store privacy labels and in-app legal links. Send privacy questions or data requests to info@slopeready.app.