Privacy notice
Draft — prepared by the engineering team, not yet reviewed by a data-protection practitioner or a lawyer (see docs/compliance-plan.md). Facts about what the app does were checked directly against the codebase, not only against docs describing planned or in-progress work. Every [bracketed placeholder] below must be filled in by Training Den’s operator before this notice is relied on by a club or a family.
If you’re a young swimmer reading this
This bit is written for you, not for grown-ups. The long version for grown-ups is further down this page.
What we keep about you
Your club keeps some information to run your training. That includes your name, which sessions you come to, and whether you were there.
If you choose to tell us, it also includes how hard a session felt (we call this “RPE”) and any notes you write. If you can’t make a session, you or your parent or guardian can tell us why — sometimes that’s something private, like being ill or hurt. Your coach might also write their own notes about your swimming.
Who can see it
Every coach at your club can see your training information, not just your own coach. So can the people who run your club, and a parent or guardian who has an account linked to you.
Your coach’s own notes about you are different, and there are three kinds. Some notes are just for the coach who wrote them — nobody else sees those, not even other coaches. Some notes can be seen by all your club’s coaches. And some notes — called “squad” notes — can also be seen by other swimmers and parents in your squad. If you want to know which kind a note is, ask your coach.
About the computer helper
Sometimes a coach uses a computer helper (an “AI”) — to chat about the club, or to turn what they wrote into a training session or a chart. Whenever a coach types something, your name is usually swapped for a code like [S7] first, so the computer helper doesn’t see who you really are. Your coach still sees your real name on their own screen — the code only exists on the way out.
Two things are different, and we’d rather tell you than let you assume. If a coach talks to it instead of typing, the computer helper is the thing that turns the sound into words — so if your name is said out loud, it hears it. And if a coach takes a photo of a whiteboard, we don’t hunt through the picture for names, so a name written on the board goes too.
Your training numbers — how far you swam, your totals — are never worked out by the computer helper. Our own code always does that maths, so it can’t get your metres wrong.
If something’s not right
If you don’t like something written about you, or want to know exactly what we’ve got, you can ask. Tell a coach or your parent/guardian — or ask us yourself, you don’t have to wait for a grown-up. We’ll help you see it, change it, or delete it.
Who is responsible for your data
This is the single most important thing on this page: your swimming club is the data controller.Training Den is the data processor.
Your club decides that swimmers’ names, dates of birth, attendance and absences are recorded, and why — it is the organisation you or your family have a relationship with, and it is responsible under UK GDPR for that decision. Training Den stores and processes that data only on the club’s instructions, under a data processing agreement, and does not use it for Training Den’s own purposes.
If you have a question about your own or your child’s data, your first point of contact is your club, not Training Den.
There is exactly one exception, and it is the whole of the payment relationship.
If you are a coach who pays for your own subscription (a “seat”), your club is not the controller of that data and cannot answer anything about it — in the ordinary case your club does not know your seat exists. For payment data, Freeboard LTD is the controller, not your club and not a processor for anyone. It is our contract with you. So for anything about your own subscription — what we hold, changing it, or deleting it — come to us directly rather than to your club. Everywhere below that says “your club is the controller”, “that is your club’s to decide” or “ask your club”, read it as being about swimmer and club data, and read this exception alongside it. The detail is under payment data below.
Training Den is operated by: Freeboard LTD, a company registered in Scotland (company number SC897840), registered office 8 Duntreath Place, Edinburgh EH16 4ZA.
ICO registration (if applicable): [ICO REGISTRATION NUMBER]
Data protection contact: our contact form or admin@trainingden.app. Both reach the same people and neither needs an account. The form is worth preferring if your request is about a particular club, because it records which club it concerns and so reaches that club rather than leaving us to work out where it belongs — but an emailed request counts exactly the same and starts the same clock, and you never have to use the form. Either way it is answered by a person rather than automatically — so it is not instant, and you should keep your own copy of anything you send.
What we hold
On behalf of your club, we hold:
- Swimmer records: first name, last name, and an optional date of birth. That’s deliberately all — no home address, no photo, no medical record and no emergency contact are held for a swimmer.
- Attendance: which sessions a swimmer was present, late, absent or excused for.
- Absence notices: a category — illness, injury, holiday, school or other — plus an optional short free-text note a family can add. We treat “illness” and “injury” attached to a named child as health data (UK GDPR’s “special category” data), and the free-text note is where more detail (a diagnosis, a specific injury) is most likely to end up if a family writes it there.
- Self-reported training data: if a swimmer chooses to record it, how a session felt (“RPE”, 1–10) and an optional note.
- Coach notes: notes a coach writes about a swimmer, in one of three visibility levels the coach picks each time — private (only the coach who wrote it — not even other coaches), coaches (any coach or admin at the club), or squad (also visible to swimmers and parents/guardians in that swimmer’s squad). Notes default to private.
- Session, dashboard and results data: sets, distances, times and totals — all calculated by our own code from structured data, never invented or estimated by an AI model.
- Voice recordings, if a coach creates a session by speaking: processed to build the session; see AI features and how long we keep it below.
- Account data for coaches, admins and parents/guardians: name and email address, used to sign in.
Payment data, if you pay for a seat
Some coaches pay for their own subscription (a “seat”) directly with us, rather than through their club — see our terms of use, section 7 (“Paying for a seat”), for what that agreement covers. That payment relationship is between you and us, not your club, so what we hold about it is separate from the swimmer and club data described above, and it is not held “on behalf of your club” in the way the rest of this list is.
Who is responsible for it: Freeboard LTD is the controller of this data, on its own account. Not your club, and not as anyone’s processor.
Why we are allowed to hold it: because we need it to give you the subscription you asked for and to take the payment for it — that is UK GDPR’s “performance of a contract” basis (Article 6(1)(b)) — and, for the records that have to survive the subscription itself, because the law requires a business to keep records of what it sold and to whom (Article 6(1)(c), a legal obligation). None of it is special category data, and none of it is used for marketing, profiling or anything else.
We never see, handle or store your card details. Payment is taken on a page hosted by Stripe, our payment provider — your card number never reaches our servers in any form. Nor do we hold your billing name or billing address: Stripe collects those on its own page and keeps them (see who it’s shared with below). We already hold your name and email as ordinary account data, listed further up this page; the seat adds nothing to that.
What we hold for a seat is one record per coach, and this is all of it:
- Stripe’s own identifiers for your customer and subscription record, and the identifier of the price you bought.
- Which tier you are on, and who is paying for it — today always you; the field exists so a club could take a coach’s seat over in future without a second, double-charging record, and it names that club when it does.
- Your subscription’s status, stored in Stripe’s own words (trialing, active, past due, unpaid, cancelled, paused, incomplete) plus our own “complimentary” for an account we do not charge.
- The monthly AI allowance your tier carries.
- Dates: when your trial ends, when the current billing period ends, and when your seat first lapsed if it has. Whether you have asked to cancel at the end of the current period is stored as a yes/no rather than a date — we do not hold a cancellation date.
- Two dates for a seasonal pause of collection. That feature is not built yet, so they are empty for everyone today; the fields exist ahead of it.
- Housekeeping: when we last applied an update from Stripe (so a delayed message cannot undo a newer one), and when the record was created and last changed.
How long we keep it: while you have a seat, and then for as long as the law requires a business to keep records of its sales. That is longer than the rest of this notice describes, and it is why deleting your account does not delete this record — deleting your account does cancel the subscription, so nothing further is charged, but the record that it existed stays. It carries no card details, and no name or email of its own — it points at your account row, and that row’s name and email are cleared by the deletion. [EXACT BILLING-RECORD RETENTION PERIOD — CONFIRM. The ordinary answer for UK company and tax records is six years from the end of the relevant accounting period, but this has not been confirmed for Freeboard LTD and no automatic deletion is implemented for it either way.]
Referral data
If you create or use a referral link, Freeboard LTD is the controller of that data just as it is for your own paid seat. We hold the random referral code, who created it, which new account used it, the signup and 90-day qualification dates, the qualifying Stripe invoice, eligibility and disqualification reasons, and the amount and processing state of each account-credit grant. An administrator’s user identifier, the action and its reason or prior failure details are also retained when they manually disqualify or retry a reward, so that intervention cannot erase its own audit trail. If Stripe delivers a paid invoice before its subscription update, we keep the minimum signed invoice facts needed to retry qualification when the update arrives. We also keep Stripe’s identifier for a credit once it has been applied. We use this to perform the referral offer you chose to take part in (Article 6(1)(b), fulfilling our referral agreement) and to prevent duplicate or abusive rewards and reconcile money records (our legitimate interests, Article 6(1)(f)). It is not used for profiling.
We do not collect your friend’s contact details. The product gives you a neutral link to copy. It does not ask for their email address or phone number and does not send or generate an incentivised email, SMS or WhatsApp message on your behalf. Public link validation and each participant’s referral summary never reveal the other person’s identity.
How long we keep it: deleting an account disables its public referral code and clears the deleted person’s name and email from the account row. The pseudonymised attribution and credit ledger remains with the subscription and sales record for the period the law requires. It contains no friend contact details or card details. The exact period is the same unresolved billing-record period stated immediately above; we will not invent a shorter referral period that would make the financial record impossible to explain or a longer one that has not been approved.
Where this comes from
Most of what we hold about a swimmer is entered by the club, not by the child: a coach or admin adds a swimmer’s name and records attendance. A swimmer’s own linked account can add a few things directly — how a session felt and an optional note — and a parent or guardian’s account can submit an absence notice on a swimmer’s behalf.
We do not run any advertising or analytics tracking (no Google Analytics, no Facebook pixel, nothing that builds an advertising or behavioural profile of you, and nothing that sells your data), and nothing here is shared, sold or used across clubs.
Why, and the legal basis
What we use it for
In general, this data is used to: plan and record swim and land-training sessions; take attendance; let a swimmer or parent/guardian tell the club about an upcoming absence and why; let a swimmer optionally record how a session felt; and give coaches, club admins and (where a club allows it) parents/guardians visibility of a swimmer’s own training history. It is not used for anything else.
The legal basis
Because your club is the controller, the decision about which UK GDPR Article 6 lawful basis applies (for example, that it’s necessary for club membership, or that a family has consented) is your club’s to make and document, not Training Den’s.
That is about swimmer and club data. It does not cover a coach’s own paid seat: we are the controller of that, so the lawful basis for it is ours to state rather than your club’s, and we state it under payment data above — performing our contract with you, and the legal obligation to keep records of a sale.
Absence reasons and their notes are health data about a child, which UK GDPR treats as a special category needing an extra legal condition (Article 9) on top of the ordinary one — for example, explicit consent from a parent or guardian, or a condition available to not-for-profit membership bodies. This is honestly unresolved today: Training Den does not yet enforce or record a specific Article 9 condition anywhere in the product, and this is tracked as an open item in our own compliance work. Your club should agree and record its own answer to this question, separately from this notice.
If your club is relying on your (or your parent/guardian’s) consent for anything here — for example, a health-related absence reason — you can withdraw that consent at any time by telling your club. Withdrawing does not make anything already done unlawful; it just means the club needs a different basis to continue, or must stop.
Do you have to provide it?
Providing this data is not a legal requirement — no law says you must give a swimming club this information. Whether it is needed to take part in your club’s training programme, and what happens if you would rather not provide something (an absence reason, for instance), is for your club to tell you, since the club decides how it runs its own programme.
Automated decision-making
We do not carry out any automated decision-making, including profiling, that produces legal or similarly significant effects on you. Where AI is involved (see AI features below), it only drafts a suggestion that a coach reviews and decides whether to save — nothing is decided about you automatically.
Separately, worth naming plainly rather than leaving out: the app does work out two things about a swimmer automatically from stored training records — whether their recent logged effort has gone up or down compared with their own average, and whether they have missed a run of sessions. Both are worked out by our own fixed arithmetic, never a model, and both are written to describe only what was measured (“62% above their own average”) — never a risk, a prediction, or advice. Only coaches can see either figure; a swimmer or parent/guardian account cannot reach it, even by asking directly. Nothing is decided or changed automatically because of either one — a coach reads it and decides, or does not.
AI features
Four places in the app send data to an AI provider (OpenAI, or Anthropic as an automatic backup): the coach assistant (typed chat), session and land-training creation, dashboard creation, and reading a photographed whiteboard. Everything else — saved sessions, dashboards, attendance, results — loads with zero AI calls, and neither provider trains its models on data sent through this app.
The line that matters is not which screen a coach is on — it is whether they typed, spoke, or took a photo. Typed text is name-masked everywhere. Audio and photographs are not masked anywhere.
Wherever a coach types — the coach assistant, swim and land-training session creation, and dashboard creation — a swimmer’s or coach’s name and internal ID are replaced with a meaningless label (like [S7]) before anything reaches an AI provider. That covers what a coach types now, the conversation history the app replays on later turns, and anything the app looks up for the AI to answer with — an attendance list, a coaching note and who wrote it, a swimmer’s history or times. The label changes every conversation, so it can never become a standing pseudonym for a particular child. This is enforced in code and covered by automated tests, including one that captures everything sent to the provider and fails if a real name appears anywhere in it — it is not a prompt asking the AI to behave.
Your coach’s own screen is unaffected: the real name is put back before they see the reply or the draft, and the saved session or dashboard keeps real names. The label only ever exists in what travels to the provider. If the club’s roster cannot be loaded for any reason, the AI request is refused rather than sent unmasked.
What masking does not cover — we would rather disclose this plainly than round it up:
- Voice audio. A coach can create a swim session, a land-training session or a dashboard by speaking. The AI provider is the thing that turns speech into words, so that step happens before any of our code can act — a name said out loud reaches the provider as said. (This is exactly why the coach assistant can no longer be spoken to at all: naming an individual child is the ordinary thing to do there, so the spoken assistant was removed rather than disclosed around. Bringing it back would take a change to the software, not a setting.)
- What the app says back during a spoken session. The reply read aloud has real names put back into it, because that is the sentence the coach is meant to hear. Mostly this tells the provider nothing new — it just transcribed the coach saying the name — but it can read back a surname the coach never said. Making the spoken reply say less than the screen does is an identified change we have not yet made.
- Photographs. A photo of a whiteboard or printed plan is not scanned or redacted for names before it goes to the AI’s vision model. The caption a coach types alongside it is masked; the picture is not.
- Squad names. The AI is always told what your club’s squads are called, because it has to name them back exactly to put a session in the right one. Usually harmless — but a squad named after a person sends that name every time. Renaming the squad is a two-minute fix on the Club screen.
- The limits of matching a name in text. Masking compares against the names actually stored for that club, so a misspelling or a nickname isn’t caught; a bare surname is deliberately never masked; a first name that is also an everyday word (Max, Grace, Will, May…) is only masked when it’s capitalised; and a coach who has left the club is no longer on the staff list, so their name is not masked at all.
- One thing masking adds rather than removes. If a coach types just “Freya” and one Freya is on the roster, what comes back is her full name — so a coach can see a surname they didn’t type. If more than one Freya is on the roster nothing is guessed: it comes back as “a swimmer”.
- The full list, written for a club committee, is in
docs/privacy-disclosure.md§4.
A club can restrict the assistant further. In Club settings, a club admin can switch “Assistant privacy” from Standard to Strict for the whole club. On Strict, the assistant is no longer given any way to look up anything about a named individual — no attendance list, no coaching notes, no individual history, times or pace, no morning briefing, and no breakdown of a figure swimmer by swimmer or coach by coach — not even under a label. It keeps working for club-, squad- and session-level figures, sessions, dashboards and drafts, and coaches still see all of the detail on the ordinary screens; only the AI loses access. Three things to be precise about: Standard is the default, so a club has to choose this; it applies to the assistant only, and changes nothing on the session or dashboard creation screens; and it is not a promise that no label ever leaves — a coach can still type “how is Freya doing”, and that message still goes with her name replaced by a label.
Figures shown to a coach — distances, durations, percentages — are always calculated by our own code from the club’s stored data, never by the AI, so the AI is never the source of a number. This applies everywhere in the app, regardless of masking.
This is a risk-reduction measure, not an exemption. The masked labels are pseudonymisation under UK GDPR, not anonymisation — the data is still personal data, because your club can still link a label back to a real child. Using this app’s AI features does not take your club outside the scope of its own data protection obligations.
Each provider keeps a copy of what it’s sent for a limited time, mainly for abuse and safety monitoring — generally up to 30 days by default at both OpenAI and Anthropic, longer only if a request is flagged for a genuine policy violation. Neither company’s free consumer chat product (ChatGPT.com, claude.ai signed in personally) is used by this app.
International transfers
- Supabase processes in London, UK — no international transfer.
- Heroku processes in an EU region. The EU has “adequacy” status under UK data protection law, so this does not generally need additional transfer safeguards.
- Vercel’s processing region has not yet been confirmed for this notice — [VERCEL REGION — CONFIRM].
- OpenAI and Anthropic process in the United States. Anthropic’s data processing agreement states that it already incorporates the UK’s International Data Transfer Addendum — per
docs/privacy-disclosure.md§6.3, checked against Anthropic’s own published DPA text on 26 July 2026. OpenAI’s own transfer safeguard mechanism has not been independently verified for this notice — check openai.com/policies/data-processing-addendum directly before relying on it. Neither provider currently offers UK/EU data residency on its standard API — seedocs/privacy-disclosure.md§7 for what that would take. - Stripe, if you pay for your own seat — processing region and legal entity not yet confirmed for this deployment: [STRIPE REGION — CONFIRM]. Stripe’s own Data Processing Agreement describes Standard Contractual Clauses, and the UK International Data Transfer Addendum for UK transfers, as its safeguard for data processed outside the UK/EEA — but, like OpenAI’s above, that has not been independently verified against Stripe’s current DPA text for this notice.
A transfer risk assessment covering each provider above now exists (docs/transfer-risk-assessments.md) — but producing it documented the open questions precisely rather than closing them: OpenAI’s own transfer mechanism is still unverified (as above), and Vercel’s and Sentry’s processing regions are still unconfirmed. Stripe was not part of that assessment at all — it predates the billing workstream — and has not been separately assessed here either.
How long we keep it
Honestly: most of the data above still has no automatic time-based deletion, and where a time limit now exists, it is something your club has to switch on — it is not a new default.
Swimmer records, attendance, session history, and self-reported training data (an effort rating and note a swimmer adds) are kept for as long as your club’s account is active, or until you or your club ask us to remove them — there is no automatic time-based deletion for these at all today.
Absence notices, your club’s coach notes, and the AI assistant’s conversation history are different: a club admin can now set a number of days to keep each of these for, in Club settings, after which they are deleted automatically. Until an admin sets one, though, the same “kept indefinitely” position above still applies — this is a control a club opts into, not something that started happening on its own. The AI conversation history is worth naming specifically even once a club sets a window for it: it is stored with real names, not the labels sent to the AI provider (see AI features above), so it can carry more detail than the session it was used to draft. Where a club has set a window, it is enforced automatically whenever a coach marks a session delivered, and — like the voice-transcript purge below — by a separate daily housekeeping job for a club that has otherwise gone quiet; that job had not yet been installed in production as of our last engineering review, so a quiet club’s expired data may sit a little longer than the number of days it chose.
A pending club invite link expires automatically. Voice transcripts (raw recordings and transcript text from a session or the assistant) are off by default: nothing is stored at all. A club admin can opt in and choose a number of days to retain them for, after which they are purged. That purge runs opportunistically whenever any voice session ends (as a side effect of ending the call), so it is not entirely unenforced even today — but the separate daily scheduled sweep that would also catch anything an opportunistic purge misses had not yet been installed in production as of our last engineering review, and we are treating that as a priority.
A DUAA complaint you submit through this page (see Complaints below) is kept while it is open, and for 3 years after it is resolved — but, unlike voice transcripts, that 3-year clearance has no opportunistic fallback: it runs only from the same daily scheduled job that, as noted above, had not yet been installed in production as of our last engineering review. Until it is, a resolved complaint’s record is kept for longer than the 3 years we intend.
Payment records are the one thing here we would keep even if you asked us not to, and they are also the one thing on this page your club has no say over. If you have paid for a seat, the subscription record described under payment data above outlives both your subscription and your account: the law requires a business to keep records of what it sold, and a request to erase your data does not override that for this category. Deleting your account cancels the subscription and strips the name and email from the account it pointed at, so what remains is a record of a sale rather than a record about you — but it remains, and no automatic deletion runs against it. The exact period is the placeholder above.
Your rights
Under UK GDPR you have the right to access, correct (rectify), erase, restrict, receive a copy of (portability), and object to the processing of, your personal data. Because your club is the controller, the right way to exercise most of these is to ask your club directly — but you can also come to us and we will help.
Not for your own paid seat, though. If you are a coach paying for a subscription, we are the controller of that data and your club is not: it cannot see your seat, cannot act on it, and in the ordinary case does not know it exists. So for anything about your subscription — seeing what we hold, correcting it, or having it erased — come to us through our contact form, and see payment data for what we hold and how long we have to keep it.
- Access: ask your club, who can see your records directly, or ask your club admin for an export of your club’s data (they can already request this themselves, from Club settings). Worth stating plainly: this export is not everything we hold. It does not currently include absence-notice detail — the most sensitive category we hold, and the one a club would most need for a request about a child’s health or wellbeing — nor self-reported completion notes, land-training records, coach-timed training times, the AI assistant’s conversation history, voice transcripts, the audit log, or DUAA complaint records. A club using this export alone to answer a request about a specific child should know that gap exists before relying on it.
- Rectification: a coach or admin can correct a swimmer record directly in the app — ask your coach or admin.
- Erasure: a club admin can permanently erase a single swimmer’s record on request. This replaces the swimmer’s name with a non-identifying marker, clears their date of birth, and archives them so they no longer appear on the active roster; any health-related absence-notice detail is deleted outright rather than anonymised; free text on the attendance, adjustment, completion and training-time records that names them is cleared (on both the swim and land side); and the family’s guardian link is removed. If this child has their own sign-in, it is scrubbed too — unless it is shared with something else (another club, another child they guard), in which case it is left alone and the club is told to handle it separately. Attendance history and training totals for the squad are kept, against the anonymised record, so a squad’s own history stays accurate. This does not reach everything that might name a child, and we’d rather say so than let a club assume otherwise: a coach’s notes or a transcript written about a whole session, rather than about this one child, are not touched — nothing on those records says which child they concern — and neither is the AI assistant’s conversation history, which keeps real names rather than the labels sent to the AI provider (see how long we keep it below for how that is governed instead). This does not remove the swimmer entirely from the database — it is a thorough scrub, not a hard delete — and it is a step only a club admin can take, not something a swimmer or parent/guardian can trigger themselves from this app yet. If you want a swimmer’s record erased, ask your club admin, or tell us through our contact form and we will help make sure it happens.
- Deleting your own account — another current limit. A coach or admin can already delete and scrub their own account (including their private notes) at any time from within the app, in Settings. A parent/guardian or swimmer-only account cannot yet do this from the athlete surface — the underlying deletion exists on our server, but there is no button for it there today. We are treating that deliberately rather than rushing it: a one-tap, irreversible account deletion on a screen used by children is a safeguarding decision the product owner needs to make on purpose, not a quick fix. If you are a parent, guardian or swimmer and want your account deleted now, ask through our contact form and we will do it for you. If you pay for your own seat, deleting your account cancels that subscription too, so you are not left being charged for an account that no longer exists — the record that the subscription existed is kept, for the reason given under payment data, but nothing further is taken from your card.
- Restriction and objection: no dedicated in-app control yet — contact your club or us directly and we will act on the request.
- Portability: the club data export gives your club’s data in a portable form — ask your club admin, and see the note under “Access” above for what it doesn’t currently include.
Complaints
Complaining to your club: your club is the controller, so you can complain to it at any time, and since 19 June 2026 the UK’s Data (Use and Access) Act 2025 requires a controller — your club — to acknowledge a complaint within 30 days and respond without undue delay.
Complaining to Training Den directly: use our complaints form and we will acknowledge and respond promptly.
Complaining to the regulator: you also have the right to complain to the Information Commissioner’s Office (the ICO), the UK’s data protection regulator, at any time — you do not have to complain to us or your club first: ico.org.uk, or by phone on 0303 123 1113.
Keeping it safe
Every club-owned table in our database is scoped to that club, so one club cannot see another’s data. That’s enforced by our own server checking your club membership on every request it handles — which is most of what the app does — and, additionally, by the database’s own row-level security on the smaller number of screens where your browser reads data directly rather than through our server. Coach notes default to private. Signed-in access is logged. We do not have a paid database plan with confirmed point-in-time backup recovery in place yet — this is a tracked item, not something we want to claim before it’s true.
Cookies & your device
We don’t use tracking or advertising cookies, and we don’t run any third-party analytics — so we don’t show a cookie-consent banner, because there is nothing here that needs your consent under the rules that cover it. What we do store on your device is used only to make the app work: your sign-in session, an offline copy of your club’s data so a coach can keep working poolside without signal, and the app’s own mechanism for fetching an updated version. None of it is used to track you elsewhere.
Contact
For anything about your own or your child’s data, start with your club. To reach Training Den directly, use our contact form or email admin@trainingden.app. Either takes questions, requests to see, correct or delete data, objections and complaints, and neither needs an account.
The form is the better of the two for anything about a specific club, because it records which club the request concerns rather than leaving us to work it out — but a request counts however it reaches us, so an email is no weaker. You can always complain to the ICO instead, and you never have to go through us first — see your rights.
Changes to this notice
Last reviewed 23 August 2026. Referral data was added that date: the random code and attribution, qualification and account-credit ledger; who controls it and why it is used; the absence of friend-contact collection or electronic-message generation; and what account deletion does and does not remove.
Payment data was added on 23 August 2026, because coaches will be able to pay for their own subscription and nothing on this page mentioned it. That addition also corrected three sections that had quietly become wrong against it — “Who is responsible for your data”, “the legal basis” and “Your rights” all sent every question to the club, which is right for swimmer data and wrong for a coach’s own card, since we are the controller of that and a club usually does not know the seat exists. Retention gained a paragraph on billing records, which outlive an account deletion. And the Stripe row in the sub-processor table was put back into the conditional tense the Sentry row already used: it is listed in advance of being switched on, not describing something happening now.
Before that, this page was last reviewed 31 July 2026. Several changes were made that date: the AI features section was corrected, because name-masking had been extended to the session, land-training and dashboard creation screens and this page still said it hadn’t been; and, later the same day, the erasure section under “Your rights” was corrected because a single swimmer’s record can now genuinely be erased on a club admin’s request, and this page still said it couldn’t be. The “nothing that profiles” wording earlier on this page was also narrowed the same day, to be accurate about deterministic training-load and attendance flags that a coach can see (see “Automated decision-making” above) without overclaiming that nothing here evaluates a swimmer’s data at all. Later still the same day, three further corrections: the erasure bullet was tightened again, because it still overclaimed what erasure reaches (it said free text was “cleared” everywhere, when a coach’s notes or a session transcript, and the AI assistant’s conversation history, are structurally out of reach); the retention section was corrected because absence notices, coach notes and AI conversation history are now covered by a club-configurable retention setting this page had not caught up with (still off by default); and the international-transfers section and the data export description were corrected to match a transfer risk assessment and the data processing agreement’s own account of what the club export does and does not contain.