PRIVACY AT 2537M

Your data should help your running—not become the product.

2537M uses runner-authorized training, recovery and profile information to provide adaptive trail and ultrarunning guidance. We do not sell connected activity or health data, and we do not use it for advertising.

Effective August 27, 2026Private testing release
01

Runner controlled

You choose which providers to connect. You can disconnect a provider at any time.

02

Purpose limited

Data is used to operate 2537M, analyze training and improve your personal guidance.

03

Clear boundaries

2537M supports training decisions. It does not provide medical diagnosis or treatment.

INFORMATION WE COLLECT

Only what is needed to run the service.

Depending on the features and connections you choose, 2537M may process:

  • Account information: name, email address, account identifier and authentication status.
  • Training activities: workout type, date, duration, distance, pace or speed, elevation, route, GPS coordinates, laps, heart rate, cadence, power and other available workout samples.
  • Recovery context: sleep, resting heart rate, heart-rate variability, daily activity and similar metrics when you authorize a compatible source.
  • Profile information: age or birth year, height, weight, sex, training zones and fitness values when supplied by you or an authorized provider.
  • Runner-entered information: goals, planned races, availability, perceived effort, soreness or injury comments, terrain, footwear, fueling, fluid intake and GI response.
  • Technical information: app version, connection status, synchronization timestamps, error information and security records required to operate the service.
HOW INFORMATION IS USED

To explain the past and guide what comes next.

2537M uses the information above to maintain your training history, remove duplicate imports, calculate training and recovery trends, compare similar runs, prepare fueling guidance, adapt future training and provide account support. Aggregated or de-identified information may be used to test and improve product reliability, but not to target advertising.

WEARABLE & DATA CONNECTIONS

Authorization stays with the provider.

Connections to services such as Apple Health, COROS, Polar, Strava and Suunto use the provider’s approved authorization process wherever available. 2537M does not ask for or store your watch-account password. Provider access tokens are stored on the server and are not sent to the coaching model.

Disconnecting a provider stops future access and, where supported, revokes the authorization token. Previously imported records may remain in your 2537M account until you delete them or request account deletion.

SERVICE PROVIDERS & AI

Limited processing, not data brokerage.

2537M may use contracted infrastructure, authentication, storage, weather, mapping and AI-processing services to operate the product. Those services receive only the information required for their function and are not authorized by 2537M to sell it or use it for advertising.

When the coaching feature is used, 2537M prepares a minimized evidence packet containing the training context needed to explain an approved decision. Provider passwords and authorization tokens are excluded. Automated output is informational training guidance and is not a medical conclusion.

Information may also be disclosed when required by law, to protect users or the service, or as part of a business transaction subject to appropriate confidentiality and notice requirements.

CAMPAIGN MEASUREMENT

App-level measurement stays separate from runner evidence.

2537M may use Meta App Events and Google Firebase Analytics to count basic app installation, lifecycle and opening events and evaluate advertising campaigns. Advertising-identifier collection, cross-app advertiser tracking, Meta automatic event logging and Firebase automatic screen reporting are disabled by 2537M. Campaign events contain no name, email address, account identifier, HealthKit data, workout, route, location, race, injury, recovery, coaching, fueling or profile information.

Campaign measurement is not used to personalize training guidance and is not combined with connected health or fitness records. 2537M does not use HealthKit or fitness-context information for advertising or marketing.

RETENTION & DELETION

Kept only while it serves the runner.

Account and training information is retained while your account is active and as reasonably necessary to provide the service, maintain security, resolve disputes and meet legal obligations. Synchronization records and backups may persist for a limited period after deletion while secure backup systems cycle.

You may request deletion of your account and associated 2537M data by emailing the address below. We may need to verify that the request comes from the account owner.

SECURITY

Designed to reduce unnecessary exposure.

2537M uses access controls, encrypted network connections, server-side credential storage and separation between provider tokens and coaching data. No system can guarantee absolute security; suspected unauthorized access should be reported promptly.

YOUR CHOICES

Access, correct, disconnect or delete.

You can choose which sources to connect, review connection status, disconnect providers and correct runner-entered information. You may also request access to or deletion of the personal information associated with your account, subject to identity verification and applicable legal exceptions.

2537M is not directed to children under 13, or to a higher minimum age where local law requires it, without appropriate parental authorization.

PRIVACY QUESTIONS

Talk to a person.

For privacy questions, access requests or deletion requests, email support@myomesh.ca. Please do not include passwords, API secrets or detailed medical records in your message.