Skip to content
TrackForge

Privacy policy.

Last updated August 26, 2026

TrackForge (“TrackForge,” “we,” “us,” or “our”) is a training platform for track & field athletes, coaches, and the schools and clubs they belong to. This policy explains what personal information we collect, why we collect it, who processes it on our behalf, the legal bases we rely on, and the choices and rights you have. It applies to the TrackForge web application and the pages on this site.

The data controller responsible for your information is TrackForge LLC, an Indiana limited liability company, located at 550 Congressional Blvd, Suite 390 #1059, Carmel, IN 46032, United States. That address is our business mailing address and is listed to identify us, as data protection law requires; for anything that needs an answer, email is the channel that reaches us. Where TrackForge is used by a school, club, or team, that organization and its coaches also act as controllers of the athlete data they manage, and we process that data on their behalf.

1. Information we collect

We collect only what we need to run the product. We do not buy personal information from data brokers or build advertising profiles. The categories we collect are:

  • Waitlist email address. When you join the waitlist on trackforge.fit, Netlify Forms stores the email address you submit for TrackForge. We use it to notify you when public access opens and to honor deletion requests. We do not use it for a newsletter, advertising, or sale.
  • Account and identity data. When you sign up, our authentication provider (Clerk) collects your name, email address, and — if you choose it — a profile image, and records whether your email has been verified. We use this to create and secure your account and to control who can join an organization.
  • Athlete profile data. Your event group, primary events, graduation year, training age, preferred training days, and — where captured during onboarding — your date of birth (see “Children’s privacy” below). A separate profile exists for each organization you belong to, so your personal training data is kept independent from the data a school or club manages.
  • Training and performance data. Workouts and sessions you log, training plans assigned to you, individual sets and running splits, personal records, competition and meet results and entries, attendance, and any timing or performance observations imported from equipment or files. This is the core of the service.
  • Health-adjacent data. Some information you enter relates to your body and recovery: daily wellness check-ins (sleep quality, soreness, stress, fatigue, motivation), a computed readiness score, and injuries you or a coach record (the condition, severity, status, and related notes). We treat this information with particular care, use it only to scale and personalize training, and never use it for advertising. It is not medical-record data, and TrackForge is not a medical service.
  • Technique video and images. If you use form or race analysis, you (or a coach or guardian acting for you) upload a short video or still images of a technique phase. The video itself is never uploaded to us unless you ask us to keep it. Your browser extracts a small number of still frames from the footage on your own device, and only those frames are sent to us and on to a vision-capable AI model, which returns written feedback we store with your training data. The frames are kept. Each upload records who consented, when, and whether the scope was frames only or video retained.
  • Body measurements taken from technique footage. Alongside the frames, your browser measures the athlete’s body position and derives body keypoints — the positions of shoulders, elbows, wrists, hips, knees, ankles, heels and toes — which we store with the analysis so the report can show measured joint angles and draw a skeleton over the frames. This measurement runs entirely on your own device; the model that performs it is served from our own site, and the footage is not sent anywhere in order to do it. The resulting joint positions and angles, detected gait events, and contact, flight, and step timing timeline travel with the analysis. We deliberately do not keep the face and hand points the underlying model also produces. It reports positions for the eyes, ears, mouth and individual fingers; TrackForge does not use any of them, so they are discarded at the moment of measurement and never reach our systems. Only the joint positions listed above are retained. Some laws describe measurements of the body as biometric data. Two commitments apply to these measurements wherever that is the case, and they hold regardless of whether any particular law reaches them: we never use them to identify anyone — they exist to grade technique against a coaching rubric, and nothing in TrackForge matches a person by their body proportions or the way they move — and we never sell, rent, trade, or otherwise profit from them, and we do not disclose them to anyone outside the processors listed in section 5. Stored body keypoints are deleted on the 90-day schedule in section 9; the derived joint angles, gait events, and timings follow the separate retention rule stated there.
  • AI coaching chat. When you use the AI coaching assistant or the coach-facing planning copilot, we process the messages you send together with the relevant training context needed to generate a response, and we retain the resulting conversation so you can revisit it. We display a disclosure at the chat surface explaining that your message and that context are sent to a third-party model provider.
  • Organization and role data. The organizations (personal, school, or club) and teams you belong to, your role within them, coach-athlete and guardian-athlete relationships, and coach notes about athletes. Invitations you send or accept are also recorded.
  • Product usage data. A record of how the product is used: which features are opened, which actions succeed or fail, how long something took, and which step of a set-up flow was reached. These are written on our servers as a by-product of actions you take in the app, and the fields they can contain are a fixed list enforced in our code. They cannot contain anything you typed. No note, no message, no search term, no measurement, and no result is recorded this way, because there is no field of that shape for one to go in. We do this to see which parts of TrackForge are worth building on and which are quietly failing, and you can switch it off in Settings.
  • Cookies and local preferences. We use a small number of strictly functional cookies and browser-storage values: an authentication/session cookie set by Clerk to keep you signed in, and interface preferences such as whether the sidebar is expanded, which calendar view you last used, and which organization you are currently working in. We do not use advertising, cross-site tracking, or analytics-profiling cookies, and we do not embed third-party ad or social-tracking pixels. See “Cookies” below for details.

2. Cookies and local storage

TrackForge keeps its cookie footprint deliberately small. This is the complete list, not a summary. The Cookie Policy covers the same ground in more detail, including the values stored only on your device and how we treat Do Not Track and Global Privacy Control signals. Three cookies:

  • Authentication (Clerk). Session cookies set by Clerk that keep you signed in and protect your account. These are strictly necessary — the app cannot function without them — so they are not subject to opt-in consent.
  • Sidebar state (sidebar_state). Remembers whether the app sidebar is expanded or collapsed, so the layout does not reset on every page load. First-party, expires after 7 days.
  • Sign-in destination (tf_post_auth_redirect). Set only when you follow a link that requires signing in first, such as a team invitation. It holds the page you were trying to reach so we can return you there afterward. First-party, expires after 30 minutes, and is cleared the moment it is used.

And eight values kept in your browser’s local storage, which stay on your device until you clear them:

  • Active organization (trackforge-active-org). Which organization — personal, school, or club — your view of the app is currently scoped to, so switching contexts survives a reload.
  • Appearance (trackforge-theme). Whether you asked for the light theme, the dark theme, or for TrackForge to follow your device. It holds one of those three words and nothing else, and it is written only if you use the theme control — following your device is the default and needs nothing stored.
  • Welcome tour (trackforge-welcome-tour-seen). Whether you have already finished the introductory tour, so it does not reappear.
  • Referral code (trackforge:referral-code). A referral code from a shared sign-up link, held only until your account exists and the discount can be attached to it. The code identifies the offer, not the person who shared it, and it is erased as soon as it is used.
  • Training style quiz (trackforge.style-quiz.v1). Your answers to the optional training-style quiz, the knowledge packs those answers matched, and when you completed it. Kept on your device so the quiz does not have to be retaken.
  • Calendar view (trackforge:calendar-view). Whether you last viewed the calendar by month, week, or agenda. One entry per signed-in user on that device.
  • Collapsed sections (trackforge:section-card: + the section id). Whether you collapsed a section of a page, so it stays that way the next time you open it. One entry per section you have collapsed or reopened, each holding only the word open or closed. Nothing is stored until you use one of these toggles.
  • Demo session draft (trackforge_live_strength_draft). An in-progress weight-room session, written only in the demo/preview version of TrackForge, which has no account and stores nothing on our servers. The signed-in app saves sessions to your account instead.

None of these are used to identify you across sites, build a profile, or serve advertising, and none are shared with third parties. You can clear them at any time through your browser’s site-data controls; doing so signs you out and resets those preferences, and nothing else is lost.

Because every item above is either strictly necessary to deliver something you asked for or a preference you set yourself inside the app, TrackForge does not display a cookie consent banner and does not set advertising, retargeting, cross-site tracking, or third-party analytics-profiling cookies. If that ever changes, we will put consent controls in place before the change takes effect.

3. Why we use your information

  • To create, provide, maintain, and secure your account.
  • To power core features — workout and session logging, training plans, personal records, competition and meet tracking, wellness and readiness scaling, attendance, and performance imports.
  • To generate AI coaching responses and planning suggestions based on the goals, events, constraints, and training context you provide.
  • To let coaches, schools, and clubs manage their athletes, teams, and rosters within their organization.
  • To detect, prevent, and respond to fraud, abuse, and security incidents, and to enforce rate limits and usage controls.
  • To communicate with you about your account and important service changes.
  • To comply with legal obligations and enforce our terms of service.

We do not sell your personal information, we do not share it with advertisers, and we do not use your training or health-adjacent data for advertising or to send it to a third party to train their AI models beyond what is needed to answer your own requests.

Improving TrackForge, including with machine learning

TrackForge may use data from the service to build and improve TrackForge itself, including training its own models, under the limits below:

  • It reaches forward, never back. It applies only to data recorded on or after August 17, 2026, the date this section took effect. Everything recorded before that was given to us under a policy that said we did not do this, and it stays outside permanently. Changing the terms later cannot reach back and collect it.
  • Five categories are excluded outright. Injury and health-adjacent records, wellness check-ins, technique video and images, the body measurements taken from that footage, and anything belonging to an athlete under 18 are never used for this, in identified or de-identified form. That exclusion is not something an organization can authorise away on an athlete’s behalf.
  • School data needs the school to agree first. Where data reaches us through a school, college, or club agreement, it is used this way only if that institution has authorised it in writing, and only within the limits of that authorisation. Student records carry a purpose limitation we do not treat as negotiable.
  • You can opt out, whatever anyone else decided. An individual athlete may opt out in Settings even where their institution has authorised the use, and we honour that. That is deliberately more than the law requires of us.
  • Nothing is published about a small group. No statistic derived from this work is produced or published from fewer than 25 athletes, or from fewer than 5 institutions, however many athletes are in the group. Track and field marks are published publicly under athletes’ names, so a small group can be re-identified by anyone willing to cross-reference; those floors exist because of that, and they are higher than the standard most US rules set.

Any future expansion is disclosed here before it takes effect and applies only from its stated effective date.

5. Service providers (processors)

We rely on a small set of trusted providers who process data on our behalf under contract, only to deliver TrackForge:

This section groups them by what they do for you. Our subprocessor list is the same set named one by one, with what each receives and whether it is processing data today, and it is the page our data processing agreement points at. The public subprocessor page names each provider, what it receives, and whether it is active.

  • Clerk · authentication. Handles sign-up, sign-in, session management, and email verification. Clerk stores your account identity (name, email, optional image) and sets the session cookie described above.
  • Convex · database and hosting. Hosts our application backend and database and stores the profile, training, health-adjacent, competition, chat, and organization data described above.
  • AI model providers · Anthropic, Google, OpenAI. When you use an AI feature, the messages you send and the training context needed to answer them are sent to the model provider configured for that request to generate a response. We send only what is needed for your request. Technique frames go to Anthropic and to no one else. Form and race analysis is deliberately restricted to a single provider rather than falling back across several, because the images are of athletes’ bodies and most of our athletes are minors. For technique analysis, Anthropic receives the event and phase labels plus the athlete note supplied with the clip, the extracted frames, and the on-device pose angles and stride timing timeline included in the prompt. Anthropic also receives redacted coach material used to draft inactive Knowledge proposals; resource text used for Research evaluation; and Research discovery topics, target URLs, and page content fetched through its web tools. Google can receive Research discovery text only when Gemini grounding is configured. No current product path selects OpenAI. Anthropic’s commercial terms state that it may not train its models on customer content submitted through its API, and that we retain all rights to what we send and own what comes back. We do not authorize any provider to use your data to train their general models where an option to decline is available to us.
  • Stripe · payments (integrated, not yet live). The Stripe integration is built into TrackForge, but paid subscriptions have not launched, so no payment data is processed today. When they launch, Stripe will process payments and store billing details such as customer and subscription identifiers. TrackForge does not store full card numbers. Billing is attached to the paying adult or organization account. Guardian accounts and minor athletes are not billed.
  • Netlify · hosting and content delivery. Serves the TrackForge website and application. It receives request metadata such as IP address, browser user-agent, requested page, referrer, response status, and country. On this public site, Netlify Forms also receives and stores the waitlist email address you submit. Netlify is contractually barred from using this information for its own marketing or advertising.
  • Zoho · inbound email. Runs the mailboxes behind the addresses we publish, so mail you send to TrackForge arrives somewhere. It receives your email address and whatever you write, and nothing else. It receives nothing from the application itself. Mail going the other way, from TrackForge to you, goes through Resend instead.
  • Resend · transactional email. Delivers the email TrackForge sends on your behalf or about your account — team invitations, notifications you have turned on, and billing notices. Resend receives the recipient address and the contents of that message, and nothing else. This is active only on deployments where an email provider is configured; where it is not, those messages are simply not sent.
  • Sentry · crash, error, and performance monitoring. Receives technical crash and error reports plus sampled navigation and request timings so we can find faults and slow paths: the error and stack trace when one exists, page or route, timing, and browser and device type. It is not configured to attach your IP address or account identity, and it never receives your training, wellness, or chat content. Sentry is switched on per deployment; where no reporting endpoint is configured it is inert and no data leaves your browser.
  • Firecrawl · web search. Powers the “Discover” search in the Research Library. When you run a discovery search, the text you typed and the page addresses we fetch for you are sent to Firecrawl. Your profile, training, and health-adjacent data are not. This is active only on deployments where a search provider is configured.

6. International data transfers

Our providers may process and store data in the United States and other countries where they operate, which may be outside the country where you live. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or the UK equivalent) and our providers’ own transfer mechanisms. You can contact us for more information about these safeguards.

7. Your rights and choices

Depending on where you live, you may have some or all of the rights below. We honor requests as required by applicable law (including the GDPR and the CCPA/CPRA):

  • Access and export. You can download a copy of the data TrackForge stores about you at any time from Settings using the “Export My Data” control. This generates a readable JSON file covering your profile and preferences, wellness check-ins, injuries, personal records, competition and meet results, logged workouts and their sets and splits, plan assignments, readiness snapshots, AI coach chat messages, and your organization memberships and guardian links. Very large collections may be capped, and the export notes where that happens.
  • Deletion. You can permanently delete your account and associated data from Settings using the account-deletion control (a typed confirmation is required). Deletion takes effect after a 14-day grace period, during which you can cancel by signing back in; after that it cascades permanently across the records you own. If you own any shared or non-personal organization, you must first transfer ownership. Where we are required to retain certain records by law or to resolve disputes, we retain only the minimum necessary.
  • Correction. You can update your profile, preferences, and most of your data directly in the app at any time.
  • Objection and restriction. Depending on your location, you may object to or ask us to restrict certain processing, and you may withdraw consent where we rely on it. Contact us to exercise these rights.
  • Opt out of usage recording and model improvement. A single switch in Settings turns off product usage recording and removes your data from any use for improving TrackForge or training its models. It deletes what has already been recorded about you as well as stopping what comes next, and it works even where your school, college, or club has authorised the use. TrackForge does not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. Do Not Track and Global Privacy Control signals therefore do not change those practices.
  • Non-discrimination. We will not deny you service or provide a different level of service because you exercised your privacy rights. Switching off usage recording does not change what the product does for you.

If TrackForge is administered by your school or club, some requests (such as correcting roster data) may be routed through that organization as the controller of that data. We will help direct your request appropriately.

8. Children's privacy

TrackForge is used in school and club settings, so some athletes are minors. Our policy is designed around that reality.

  • No accounts for anyone under 13. During onboarding we ask for your date of birth. If it shows that you are under 13, we do not create an account, and there is no other way to get one. A parent, a guardian, a coach, a school and a club are all equally unable to open a TrackForge account for someone under 13, and there is no consent, approval or upgrade that unlocks one later. TrackForge is for athletes aged 13 and over.

    We do not knowingly collect personal information from children under 13, and we do not operate a verifiable parental consent programme under the U.S. Children’s Online Privacy Protection Act (COPPA), because we do not offer the accounts that would need one. If an account for someone under 13 exists because it was created before this rule, or with a date of birth that was not accurate, it cannot be used to record anything, and we delete it and its data once we know about it.
  • Minors aged 13–17. Athletes aged 13 to 17 may onboard and train while guardian confirmation is pending. We ask for a parent or guardian's email and send a seven-day invitation tied to that address. After the adult accepts, they can review the athlete's permissions from My Athletes. Sharing cards outside TrackForge and AI start off and stay off until a linked guardian approves them. Under the EU GDPR, the digital-consent age can be as high as 16 depending on the member state; where local law sets a higher age, guardian involvement is required accordingly.
  • We never store video of a minor. For any athlete under 18, form and race analysis keeps only the extracted frames, and the option to retain the original video is not available — whatever is requested at upload. This is enforced on our servers from the athlete’s date of birth rather than by the upload screen, so it cannot be worked around by the app or by anyone modifying it. An adult athlete may choose to retain their video; nobody may choose it on a minor’s behalf. An upload is refused outright if we do not hold a date of birth for the athlete, because we cannot apply the right rule without one.
  • Guardian and coach management. Guardian links let a linked parent or guardian review the eligible minor’s privacy choices. Coaches manage training only within their organization and do not become guardians or approve guardian-controlled permissions merely because they coach the athlete.

If you believe someone under 13 has an account, or that a child has given us information, contact us and we will delete it.

9. Data retention

We keep your information for as long as your account is active and as needed to provide the service. When you delete your account, we delete the personal data you own within a reasonable period, except where retention is required by law or to resolve disputes and enforce our agreements. AI coach chat messages are retained so you can revisit conversations and are removed when you delete your account.

Some derived data is pruned automatically: computed athlete intelligence/readiness snapshots are retained for 365 days by a daily cleanup job and then removed, so we do not keep historical derived metrics longer than needed for trend reporting.

Product usage data

Usage records are kept on a short clock, and the clock is shorter where the data came from a school: 90 days for anything originating in a K-12 organization and 180 days everywhere else, after which a daily job deletes them. The shorter K-12 window is not a storage decision. A behavioural profile is a product of detail multiplied by time, and capping the time is half of how we make it impossible to build one about a pupil.

Switching product usage recording off in Settings deletes what has already been recorded about you as well as stopping what comes next. We took that route rather than keeping the back catalogue and promising not to look at it, because the second thing is not what anyone means when they switch something off.

Technique footage and body measurements

Form and race analysis has its own schedule, and it is the shortest one we operate. The uploaded frames, any retained video, and the stored body keypoints are permanently deleted 90 days after upload by a daily cleanup job. This is automatic. It does not require you to ask, it applies to every athlete of every age, and there is no option — for you or for us — to extend it.

What survives is the written coaching feedback, rubric scores, measured joint angles, detected gait events, and contact, flight, and step timings, so you can compare technique across a season. These are derived movement measurements rather than stored footage or body keypoints, and they are removed when you delete your account.

You can delete any submission yourself at any time, which removes everything immediately rather than waiting for the schedule. You can also download a copy of any report to your own device while the frames still exist; downloading does not extend how long we keep them.

10. Security

We use reputable infrastructure providers and reasonable technical and organizational measures to protect your information — including authenticated, role-based access so athletes, coaches, and guardians see only the data they are permitted to, server-side security headers, and provider-managed encryption in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.

12. Contact us and complaints

Questions about this policy, or want to exercise a privacy right? Email us at hello@trackforge.fit, or write to us at TrackForge LLC, 550 Congressional Blvd, Suite 390 #1059, Carmel, IN 46032, United States. Email is the fastest route for a privacy request; postal mail is forwarded to us and takes longer.

If you are in the EEA or UK and believe we have not resolved your concern, you have the right to lodge a complaint with your local data protection authority. If you are in the United States, you may have additional rights under your state’s privacy law.