Privacy Policy
Last updated: 19 June 2026
This Privacy Policy explains what personal data No Limit Athletes collects, why we collect it, how we use and share it, and the rights you have over it. We aim to be clear and to collect only what the product needs to work.
1.Who we are
No Limit Athletes (“we”, “us”, the “Service”) is a training and coaching platform for athletes and coaches, available as a web app and as mobile apps. The Service is operated by Stavros Amanatidis, based in Greece, who is the data controller for the purposes of the EU General Data Protection Regulation (GDPR). You can reach us at hello@nolimitathletes.com.
2.Data we collect
Information you provide
- Account — your email address and name. If you sign in with Google, we receive your basic Google profile (name, email). Passwords are handled and stored in hashed form by our authentication provider; we never see them in plain text.
- Profile & preferences — sports, goals, training level, availability, equipment, body metrics you enter during onboarding, and (for coaches) your public bio, headline, and location.
- Training content & activity — the exercises, programs, drills, activities, goals, and completion records you create or log, including session results.
- Media you upload — exercise images or videos you add to your library (stored as publicly accessible files; do not upload anything you want kept private).
- Social & messaging — your public profile, follows, feed posts, kudos, comments, and direct/group messages.
- Teams — team membership, assignments, completions, and reviews.
Health & fitness data
When you use a workout, drill, or outdoor session, we collect the fitness metrics you choose to record: heart rate, cycling power, cadence, rowing data, GPS location and tracks, pace, movement and jump metrics, technique scores, and shot-timer data. This is sensitive data and we process it only to provide and improve the features you use.
Camera & on-device processing
The live AI-camera form analysis runs entirely on your device. Your camera video is processed locally to count reps, estimate range of motion, and score technique — the video is not uploaded to us and never leaves your device. Only the resulting metrics (e.g. rep counts, scores) are saved with your session if you keep them.
Device & technical data
- Push tokens — if you enable notifications, we store the push subscription token for your browser or device (Web Push, Google Firebase Cloud Messaging on Android, or Apple Push Notification service on iOS) so we can send the notifications you asked for.
- Bluetooth & GPS — used on-device to connect sensors (heart-rate straps, power meters, rowers, shot timers) and to record outdoor tracks. Sensor pairing happens on your device.
- Diagnostics & security logs — limited technical logs, including a record of failed sign-in attempts, kept to protect accounts and operate the Service.
3.How we use your data
We use your data to:
- provide the Service — your account, training content, sessions, social and coaching features (legal basis: performance of a contract);
- process your health & fitness and camera-derived metrics to deliver the features you actively use (legal basis: your consent, which you can withdraw at any time);
- send notifications you enable, and reminders related to your training (legal basis: consent);
- keep the Service secure, prevent abuse, and fix problems (legal basis: legitimate interests);
- comply with legal obligations.
4.AI features
When you use AI features (such as the AI assistant, AI program or route generation, speech cues, or AI image generation), the text you submit — and any image you explicitly send for analysis — is transmitted to our AI and speech processors (Microsoft Azure AI services) to generate a response, and search queries may be sent to a web-search provider. This is separate from the on-device camera analysis described above. We do not use your content to train third-party models.
5.How we share data
We do not sell your personal data. We share it only with service providers (“sub-processors”) that help us run the Service, and with other users where you choose to (e.g. public profile, feed posts, messages, or content you assign or share). Our main sub-processors are:
- Supabase — database and authentication (stores your account and app data).
- Microsoft Azure — application hosting, file/media storage, AI services, and speech.
- Strava and Spotify — only if you connect them; we exchange the data needed for those integrations (e.g. activity upload, playback control).
- Google (Firebase Cloud Messaging) and Apple (Push Notification service) — to deliver push notifications to your device.
- Google — if you choose Google sign-in.
- A web-search provider — to answer certain AI queries.
6.International transfers
We aim to keep your core account and app data within the European Economic Area (EEA). Some sub-processors (for example for push delivery, sign-in, or connected integrations) may process data outside the EEA; where they do, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7.Data retention
We keep your personal data for as long as your account is active. If you delete your account, we delete or anonymise your personal data, except where we must keep limited records to comply with legal obligations or to resolve disputes. Security logs are kept only as long as needed for their purpose.
8.Security
We use technical and organisational measures to protect your data, including encryption in transit, access controls, and row-level security on our database. No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly.
9.Your rights
Under the GDPR, you have the right to access, correct, delete, export (portability), restrict, and object to our processing of your personal data, and to withdraw consent at any time. To exercise any of these, contact hello@nolimitathletes.com. You also have the right to lodge a complaint with your data protection authority — in Greece, the Hellenic Data Protection Authority (HDPA, dpa.gr).
10.Children
The Service is not directed to children under 16, and we do not knowingly collect their data. (In Greece, the age of digital consent is 15.) If you believe a child has given us personal data, please contact us and we will delete it.
11.Deleting your account
You can delete your account and associated personal data from within the app, or by contacting hello@nolimitathletes.com. Deleting your account removes your personal data as described in “Data retention” above.
12.Changes to this policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, for significant changes, provide a more prominent notice.
13.Contact
Questions about this policy or your data? Email hello@nolimitathletes.com.
© 2026 No Limit Athletes