RowRoutine Privacy Policy
Last updated: July 26, 2026
RowRoutine is a personal Concept2 PM5 rowing-ergometer coaching app. This policy explains what data the app stores and how it is used.
Data Stored
RowRoutine may store the following data for the authorized athlete account:
- Workout summaries, splits, and detailed PM5 time-series samples such as pace, watts, stroke rate, heart rate, elapsed time, and distance.
- Training plans, planned workouts, completion status, skipped workouts, and coaching cues.
- Health profile values entered by the user, such as body mass, birth year, heart-rate zones, max heart rate, resting heart rate, and lactate-threshold heart rate.
- Coaching preferences, athlete context, coach state, and durable coaching memories used to personalize coaching.
- Helper-device pairing tokens and access tokens needed to connect the local helper app and the web app.
Where Data Is Stored
Application data is stored in Cloudflare services, primarily Cloudflare D1. The web app is hosted on Cloudflare Pages and the API runs on Cloudflare Workers.
AI Providers
RowRoutine can send relevant workout data, health profile data, plan data, memory context, and user messages to OpenAI to generate coaching responses and training plans. When text-to-speech is enabled, short coaching messages may be sent to OpenAI or ElevenLabs to generate audio. These providers process the data according to their own terms and privacy policies.
Custom GPT Actions
If a Custom GPT is connected to RowRoutine, it can access the authorized athlete data through the RowRoutine OAuth-protected Actions API. The Custom GPT should only use this data for coaching, training analysis, planning, and maintaining coaching memory.
Data Sharing
RowRoutine does not sell personal data. Data is shared only with service providers needed to run the app, host the data, authenticate access, or provide AI and text-to-speech functionality.
Access and Deletion
The current version is configured for one authorized athlete account, accessible through configured authorized email addresses. To request data export, correction, or deletion, contact the project owner at nlspek04@hotmail.com.
Security
Access to private data requires an OAuth bearer token issued by the RowRoutine API. The site currently uses a magic-link sign-in flow for configured authorized email addresses.
Changes
This policy may be updated as RowRoutine evolves. The latest version will be published at this URL.