Product boundaries

Keep sensitive context optional, separated and visible.

This page explains product behavior. It is not the legal privacy notice and does not invent controller, retention or jurisdiction facts.

Client/server separation

Backend provider secrets and Concept2 tokens do not belong in browser clients. Authentication uses confirmation-first account flows, protected session handling, anti-forgery for state changes and local return URLs.

Cache boundary

Authenticated athlete pages use no-store behavior. This public commercial site remains cookie-free and serves fingerprinted static assets independently.

Sign-out isolation

The commercial site does not inspect athlete authentication state, proxy account forms, or create an athlete session.

Concept2 connection

  • Protected OAuth state is validated by the API.
  • Browser correlation is verified and return values are cleaned.
  • Unsafe return URLs are rejected.
  • Disconnect stops future sync and clears stored access credentials.
  • Already imported ErgCoach workouts remain.

Consent and optional context

Optional health, readiness and feedback data follows applicable consent and revocation behavior. Some features cannot store or use that context without consent.

Source provenance remains attached to supported evidence. Privacy-safe PM5 fingerprints are bounded identifiers, not public device identities.

Athlete-controlled reports

Private previews contain only selected sections. Health is off by default and separately consent-gated. Reports are not automatically sent.

Camera prototype

Transient on-device frame processing with no raw recording/upload by default is the intended design. The feature is experimental, blocked from general release, and not a production privacy-acceptance claim.

No invented deletion promise.

Account, data deletion and retention controls can be described only where a current API or UI proves them. ErgCoach does not claim one-click full deletion or that disconnecting Concept2 deletes imported workouts.