Privacy first

Privacy Policy

This policy explains what data Wellmade handles, why we use it, who may receive it and how you can exercise your rights.

Last updatedAugust 21, 2026
Operational pilot version. Before the open commercial launch, the controller's full legal identity and legal review must be completed, including the legal basis under Article 11 of Brazil's LGPD for sensitive data and retention periods by category.

1. Scope and roles

This policy covers wellmade.fit, the professional portal, the Wellmade app and support channels.

Wellmade controls data needed to create and protect accounts, provide the platform, charge subscriptions and answer requests. Professionals and organizations may control their athletes' data; in that context, Wellmade processes data under their instructions and the applicable agreement.

2. Data we handle

We collect only what is needed for the stated purpose and restrict access by role and organization. The categories below distinguish current features from fields that are not yet fully enabled.

  • Current account and contact data: name, email, protected credentials and preferences provided through available flows. Normalized international phone number and country are not part of registration available in this version; if a future version enables them, this notice will be updated before collection.
  • Current professional and organization profile: role and memberships. CPF/CNPJ and other registration details are not part of registration available in this version; any enablement will require updated purpose, safeguards and notice.
  • Athlete profile: professional relationship, availability, goals and data needed to personalize the experience.
  • Current training and wellbeing data: intake, restrictions, reported injuries, check-ins and available execution records. Loads, repetitions and perceived effort are not part of the records available in this version; if a future version enables them, this notice will be updated before collection.
  • Security and usage: sessions, device/platform, protection events, technical failures and minimized performance measurements.
  • For enabled billing flows: status, plan, currency, provider references and billing events; Wellmade does not store the full card number.
  • Athlete-selected integrations: provider, consent, connection status, and minimized activity records — date, duration, distance, and type. If the person enables menstrual tracking, we handle only period days, start indicator, flow intensity, symptoms in closed categories, and the training impact they report.

3. Why we use data

We use data to authenticate users, deliver training and coaching, connect athletes and professionals, operate payments when enabled, prevent abuse, provide support and comply with law.

Legal grounds may include contract performance, legal obligations, legal claims, assessed legitimate interests and consent where required.

4. Health and wellbeing data

Intake answers, injuries, pain, measurements, check-ins and workout content may reveal sensitive data. They stay within the authorized relationship, are not used for advertising and are never sent as properties to third-party analytics.

When you connect Strava, Garmin Connect, Apple Health, or Health Connect, Wellmade requests only the read access shown by the provider. For activities, we store only date, duration, distance, and type; routes, GPS coordinates, heart rate, free-form titles, and raw provider payloads are not stored. In Apple Health and Health Connect, sleep duration stays on the device and only suggests an editable check-in answer; it is not sent to the server.

Data you authorize from Apple Health, Health Connect, or Garmin Connect can be processed by Wellmade AI to personalize daily, weekly, and monthly training only after an explicit authorization on that source's card. This authorization is recorded separately, can be withdrawn by disconnecting, and does not replace the specific menstrual consent.

Menstrual tracking starts disabled and is never inferred from name, sex, or gender. If the person enables it, a separate system permission reads only menstrual flow records. We do not handle fertile windows, ovulation, sexual activity, pregnancy, contraception, free text, or raw payloads for this purpose.

Clue and Flo do not offer Wellmade a public API for reading an account's cycle. Clue can send new records to Apple Health after the person enables this in Clue, with no historical backfill; Flo states that its menstruation data is not sent to Apple Health. When the device repository has no records, the check-in shows optional questions.

Menstrual context is evaluated in daily, weekly, and monthly recommendations, but adjustments follow individually reported impact. Wellmade does not use a universal phase-based prescription table and does not predict fertility.

Connecting is optional. Athletes may disconnect a source at any time; Wellmade stops syncing, deletes Strava or Garmin tokens, asks Garmin to delete the access registration, and removes activities and menstrual observations imported from that source. Disabling menstrual tracking deletes its observations and withdraws that consent. Permissions can also be reviewed in device or provider settings.

Wellmade supports training follow-up; it does not replace medical evaluation, diagnosis or care.

The final legal basis for sensitive data, including qualification under Article 11 of Brazil's LGPD, remains a legal-review gate before the open commercial launch; this operational version does not replace that opinion.

5. Sharing and service providers

We may use hosting, database, email delivery, observability and payment providers, limited to what is necessary and subject to security and confidentiality obligations.

We do not sell personal data. We do not share an athlete's data with another organization or let a coach access another roster without authorization.

6. Cookies, analytics and marketing

Strictly necessary cookies and records maintain sessions, security and preferences. Analytics, diagnostics and marketing start disabled and require a specific choice where applicable.

Firebase/GA4 may receive only minimized app events after consent. GTM/GA4 and Meta are limited to the public website; Meta does not run in the portal, athlete area or authenticated WebViews.

7. Retention and deletion

We keep data only as long as needed to provide the service, protect accounts, meet legal periods and resolve disputes. We then securely delete or anonymize it.

A deletion request closes the account and revokes sessions, except for records that must be retained for law, fraud prevention or legal claims.

Specific periods by data category still require definition and legal validation; this version does not establish a final retention schedule.

8. Your rights

You may request confirmation, access, correction, applicable portability, sharing information, review of automated decisions, consent withdrawal, objection, anonymization or deletion.

To protect your account, we may verify your identity before acting. The proposed privacy address and its operational status appear at the end of this page.

9. Security and international transfers

We use tenant- and role-based access, revocable sessions, encryption in transit, minimization and operational records. No system is infallible; relevant incidents will be handled under applicable law.

Some providers may process data outside your country. We use contractual mechanisms and safeguards appropriate to the applicable law.

Some of what the app stores on your device so it works offline may be included in your operating system's backup: recorded sets and loads, pain markers, health questionnaire answers not yet submitted, the workout prescribed for the day, and your most recent Wellmade Score. On iOS this happens through iCloud Backup; on Android it does not, because the app asks the system not to include those files in the backup.

That backup belongs to your own account with the system provider: Wellmade does not receive it, access it, or control it. iCloud Backup is encrypted, but by default it is not end-to-end — Apple holds the keys and can be compelled to produce it under a court order. End-to-end protection exists only if you turn on Advanced Data Protection in your device settings.

10. Changes and contact

Material changes create a new version and an appropriate notice. The date above identifies the current version.

The proposed privacy address still requires activation and delivery verification. The controller's full legal identity and address will be published before the open commercial launch.

Proposed pilot address. Activation and email delivery still need verification before launch, so it is not presented as an operational channel.

Proposed privacy address: privacidade@wellmade.fit