CompeteCue Privacy

Privacy Policy

Last updated: 11 August 2026

The short version: the CompeteCue app stores your data on your device, not on our servers. We do not run accounts, we do not track you, and we cannot see your information — including anything medical you choose to declare. The one thing the app does send is a diagnostic report when it crashes, and that report carries nothing you entered — see section 6.

1. Who we are

CompeteCue is built and operated by Kourosh Sadr Momtaz ("we", "us"), based in the United Kingdom and the data controller for the little we process. For anything in this policy, contact kourosh@kourosh.design.

2. The app: local-first by design

Everything you enter in the CompeteCue app — your name, photo, date of birth, measurements, activity level, dietary requirements, allergies, medical declarations, medications, equipment, races and checklist progress — is stored in a database on your device only. It is not uploaded to us, synchronised to a cloud, or shared with anyone. The app works fully offline and requires no account.

Health information (medical conditions and medications) is special category data under UK and EU data-protection law. CompeteCue asks for it solely so the app can remove guidance that would not be safe for you. It never leaves your phone. We have no access to it, it appears in no backup we operate, and it is deliberately excluded from the crash reports described in section 6. Because none of it ever reaches us, we do not process it at all — the app on your device does, at your instruction, and you can delete it there at any time. That is why this policy asks for no consent to it: there is no processing by us to consent to.

Apple Health — with your permission, the app can read your date of birth, height, weight and biological sex from Apple Health to pre-fill your profile and to tell you when the weight there differs from the one your plan uses; your workouts, so recent runs can suggest an expected finish time, a race-day workout can be offered as your result, today's logged training can suggest the session on the Meals tab, and your recent months can suggest an activity level — every one of these is a suggestion you can take or ignore, and nothing is saved without you; your sleep, so recent nights can be shown alongside the rest targets in your plan; and — behind a separate, explicit opt-in — your logged period dates and flow, which it uses to estimate where race day falls in your cycle and show supportive sleep, heat, fuelling and hydration notes. Everything read from Apple Health is processed on your device only: it is never sent to a server, never shared, and reproductive-health data is additionally never written to any cloud backup we control. You can revoke access at any time in the Health app's sharing settings, and turn cycle cues off in the app.

Because your data lives with you, it is also deleted by you: removing the app (or using your phone's app-data controls) permanently deletes everything. Standard device backups you run (e.g. iCloud) are governed by Apple's terms, not ours.

3. What the app requests over the network

CompeteCue operates a small service that maintains a public catalogue of fitness events, and the app makes one further request to a third party. Three features involve a network request:

Our servers keep no user accounts and no databases of personal data. Where a legal basis is required for the transient processing above, we rely on legitimate interests (Article 6(1)(f) UK GDPR): providing the feature you asked for, in the least data-hungry way we can.

4. Notifications

Reminder notifications (carb-loading windows, packing checks, travel bookings) are scheduled locally on your device by the app. They are not sent from our servers, and we do not know whether or when they fire.

5. This website

This site sets no cookies. To understand which pages are read, it uses Vercel Web Analytics — a cookieless service that reports aggregate page views and referrers. It stores nothing on your device, builds no personal profile, and does not track you across sites; see Vercel's Web Analytics privacy statement.

The site is hosted on Vercel, whose infrastructure records short-lived server logs (such as IP address and requested page) for security and operations; see Vercel's privacy policy. We do not combine or enrich these logs.

6. Crash reports

When the app crashes or hits an unexpected error, it sends a diagnostic report so the fault can be found and fixed. This is the only thing CompeteCue sends about how you use the app, and it is the reason a crash on your phone can be repaired rather than guessed at.

What a report contains: the error and where in our code it happened, the app version and build number, the iOS version, and the device model (for example "iPhone 15 Pro"). A report sent after a crash that closed the app is assembled by the reporting library itself, and carries a little more: your device's language and region setting, and its screen size and memory. The reporting service also adds a rough location at its end — described below.

What it never contains: your name, email, photo, date of birth, measurements, activity level, dietary requirements, allergies, medical conditions, medications, equipment, races, results or checklist progress. The app is configured not to attach personal data to reports, and the values you type are stripped before a report leaves the device rather than filtered afterwards.

The code we removed: crash reports used to carry a code the reporting library derives from your device and this app — the same code each time, so in principle it distinguished one phone's crashes from another's. An earlier version of this policy said we could not remove it without losing the reports; we have since found the way, and the app now clears it before a crash can be recorded. One narrow gap remains, and we would rather say so than claim otherwise: a crash in the first moments of launch, before the app has finished starting, can still carry it.

A rough location we never ask for: every request sent over the internet carries the IP address your connection is using — the ordinary network metadata described in section 3. The reporting service turns that address into a rough area: your country, region and nearest town or city, never a street and never a precise position. It stores that alongside the report. The app does not have location access and never asks for it, and nothing read from Apple Health is involved — this is worked out at the service's end, from the connection itself. We have told them not to store the IP address and they no longer do, but the rough area derived from it stays, and no setting available to us removes it.

Reports are processed on our behalf by Sentry under a data-processing agreement. We keep them only while they are useful for diagnosing the fault: Sentry deletes each report automatically at the end of the error-event retention period for our plan, and we neither extend that period nor copy reports anywhere else. Our lawful basis is legitimate interests — keeping the app working for the people using it — which we consider proportionate because a report carries nothing you entered and nothing that identifies you as a person. You can object to this at any time by emailing us, and we will exclude your device.

7. Where processing happens, and what leaves the UK

What you enter does not travel at all: it stays in the database on your phone, so there is no transfer of it to disclose. This section covers the three services that do receive something.

8. Your rights

Under UK GDPR and EU GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Because we hold no account and no copy of what you enter, most of these are exercised directly on your device — your data is already in your hands, and deleting the app erases it. The crash reports in section 6 are the only thing we receive; they carry nothing that identifies you as a person, so we cannot look yours up from your name or email, but you can object to them and we will exclude your device. If you believe we hold anything else about you (for example, an email you sent us), contact us and we will resolve it.

You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

We make no automated decisions that produce legal or similarly significant effects about you. The app tailors a plan to what you tell it, but that happens on your phone, to guidance you are free to ignore, and no profile of you is built anywhere.

If you are a resident of a US state with a consumer-privacy law (such as the CCPA/CPRA in California), the same picture applies: we do not sell or share personal information, and the only thing the app sends us is the crash diagnostic described in section 6.

9. Children

CompeteCue is not directed at children and is intended for users aged 16 and over. We do not knowingly process children's data — by design, we process almost no data at all.

10. Changes

If the app ever gains features that change this picture (for example, optional cloud backup or a community service), this policy will be updated first and the change will be dated. Where a feature would send anything you have entered — anything in the section 2 list — the app will ask you first. Crash reports are the one exception, and they are described in section 6 precisely because they carry none of it.