Client/server separation
Backend provider secrets and Concept2 tokens do not belong in browser clients. Authentication uses confirmation-first account flows, protected session handling, anti-forgery for state changes and local return URLs.
Product boundaries
This page explains product behavior. It is not the legal privacy notice and does not invent controller, retention or jurisdiction facts.
Backend provider secrets and Concept2 tokens do not belong in browser clients. Authentication uses confirmation-first account flows, protected session handling, anti-forgery for state changes and local return URLs.
Authenticated athlete pages use no-store behavior. This public commercial site remains cookie-free and serves fingerprinted static assets independently.
The commercial site does not inspect athlete authentication state, proxy account forms, or create an athlete session.
Optional health, readiness and feedback data follows applicable consent and revocation behavior. Some features cannot store or use that context without consent.
Source provenance remains attached to supported evidence. Privacy-safe PM5 fingerprints are bounded identifiers, not public device identities.
Private previews contain only selected sections. Health is off by default and separately consent-gated. Reports are not automatically sent.
Transient on-device frame processing with no raw recording/upload by default is the intended design. The feature is experimental, blocked from general release, and not a production privacy-acceptance claim.
Account, data deletion and retention controls can be described only where a current API or UI proves them. ErgCoach does not claim one-click full deletion or that disconnecting Concept2 deletes imported workouts.