Privacy policy

Last updated 17 September 2026. This page is for athletes and for Google's app review. It explains Sign-In, optional Calendar sync, and the training data you connect.

How DataFrame.fit uses Google Sign-In, optional Google Calendar sync, Garmin training data, and cookies. You can disconnect Calendar at any time.

Who we are

DataFrame.fit is a free, non-commercial training dashboard for endurance and hybrid athletes. The site is https://dataframe.fit. It is a personal project, not a company product, and it is not affiliated with Garmin, TrainingPeaks, Google, or other fitness brands.

This policy explains what we collect, how we use it, and how you can stop that use. It covers Google Sign-In, optional Google Calendar sync, and the training data you connect from Garmin, TrainingPeaks, and MyWhoosh.

Google Sign-In

You sign in with Google. Sign-In only requests identity scopes: openid, email, and profile. We use that to create or recognise your DataFrame account. We do not receive Calendar access from Sign-In, and we do not keep the Google access token from Sign-In.

We store your Google account identifier (subject), email, name, and profile picture so you can stay signed in. The app session is a signed cookie on dataframe.fit, not a Google token.

Optional Google Calendar sync

If you tap Connect Google Calendar on the Calendar page, we ask Google for a separate permission: calendar.app.created. That lets DataFrame create one secondary calendar named DataFrame.fit and write events only on calendars we created.

From the moment you opt in, we write upcoming planned sessions and races as all-day events, then update or add timed events when a Garmin activity syncs. We do not dump your history. We do not read your other calendars, meetings, or email.

To keep writing after you close the browser, we store a Google refresh token on the server in your athlete folder. We use it only to create, update, and delete DataFrame.fit calendar events.

Training and account data

If you connect Garmin, TrainingPeaks, or MyWhoosh, we store activities, wellness, plans, nutrition logs, races, and settings in your private athlete folder so the dashboard can work. That data stays behind sign-in unless you create a privacy-controlled public activity link or a share card.

Share cards are images you choose to download or post. A public activity link only shows what you selected, and you can turn it off.

Cookies and logs

We use a signed session cookie to keep you logged in, plus short-lived cookies during Google Sign-In and Calendar connect. We keep ordinary server logs (time, path, errors) to run the site. We do not run advertising cookies.

How long we keep data

Account and training data stay until you delete the account or we remove it at your request. Google Calendar tokens and the DataFrame.fit calendar are removed when you stop syncing. If a Calendar refresh token stops working, we stop writing until you connect again.

Your choices

You can disconnect Garmin, TrainingPeaks, MyWhoosh, or Google Calendar from the app without deleting your DataFrame account. You can sign out at any time. To delete your account and training data, use Send an idea on Support and ask, or message @dataframe.fit on Instagram.

Contact

Questions about this policy: open https://dataframe.fit/support, send an idea from the signed-in app, or message @dataframe.fit on Instagram. The Google OAuth consent screen lists the support email we read for Calendar verification.

More about DataFrame.fit

© 2026 DataFrame™. All rights reserved.

This project is currently fully supported by Scope (www.scope.mt).

DataFrame™ is a non-commercial personal project. It is not affiliated with, endorsed by, or connected to Garmin, TrainingPeaks, Peaksware, or other fitness brands.