Loam

Privacy at Loam.

How we handle your training data, in plain language.

What this covers

This policy describes how Loam Fitness (“Loam,” “we,” “us”) handles personal data in connection with the Loam training calendar service. It applies to your use of Loam’s website, web app, mobile apps, and authorized integrations.

Information we collect

Account information. When you create a Loam account we collect the email address and name associated with your sign-in, along with the identifiers issued by our authentication provider.

Workout data you provide directly. Workouts you log manually, workout files you upload, and any notes or planning content you write inside Loam.

Workout data you import from connected services. When you connect a third-party service — such as Suunto, Garmin, Coros, Apple Health, or Health Connect — Loamimports workout summaries and the related files (heart rate, distance, GPS, power, elevation, and similar measurements) through that service’s official API, with your explicit consent, and only to the extent needed to run the features you have enabled.

Apple Health (HealthKit). On iOS, Loam reads workout data from Apple Health only with your permission and only to import the workouts and measurements you choose to sync. This access is read-only — Loam never writes to Apple Health. HealthKit data never leaves your device except to send it to the first-party Loam API that operates the service; it is never shared with any third party, used for advertising, or used to train external models.

Operational data. Standard server logs, request metadata, and product telemetry needed to operate and secure the service.

How we use your information

We use the data above only to provide and operate Loam for you:

  • Render your unified training calendar across every sport you train.
  • Match imported workouts against the workouts you planned, and produce weekly summaries and compliance scores.
  • Provide the upload, export, and account-management tools described in the app.
  • Share read-only training context with AI agents you have explicitly authorized through Loam’s MCP (Model Context Protocol) server — only at your direction.
  • Secure the service, prevent abuse, and meet our legal obligations.

Payments & subscriptions

Loam is offered as a paid subscription. We use established payment processors to handle payments, and we never see or store your full card number. On the web, payments are processed by Stripe. In our iOS app, payments are processed by Apple through the App Store. Your card details are entered with the payment processor, not with Loam, and are handled under that processor’s own privacy policy — see Stripe’s privacy policy and Apple’s privacy policy.

Billing status and history. From our payment processors we receive and store your subscription status, the plan you chose, and billing-period metadata — such as trial and renewal dates and whether a subscription is active, canceled, or lapsed. We use this only to provide your subscription, decide what your account can access, and support you. We retain it for as long as your account exists and for as long afterward as we need to meet our tax, accounting, and legal obligations.

What we will not do

Loam does not sell your data, share it with advertisers, or use it to train external models. Workout data imported from connected services is used solely to operate Loam for you and is never re-sold or commercially redistributed. Your data remains your own and will not be used for any other purpose.

Your rights

You always retain ownership of your training data and may exercise the following rights at any time, from inside Loam:

  • Export. Download a complete copy of all of your training history and account data.
  • Delete. Permanently delete your account and the data associated with it.
  • Disconnect. Disconnect any third-party service you have linked. Loam will stop fetching new data from that service and revoke the access tokens it stored on your behalf.

Where local law gives you additional rights of access, correction, restriction, portability, or objection, those rights remain available to you.

Data security

Access tokens, refresh tokens, and provider API keys are encrypted at rest and are never exposed to client-side code. We follow industry-standard practices for transport security, access control, and operational hardening.

Children

Loam is not intended for, and we do not knowingly collect personal data from, individuals under 16.

Changes to this policy

We may update this policy from time to time as Loam evolves or as our legal obligations change. When we make material changes, we will notify users through the app and our website, and the updated policy takes effect when we post it.

Contact

Privacy questions and requests:
support@loamfitness.com
Codelous, LLC