Privacy Policy

Last updated: 2026-07-06

Introduction

MyNextRow (“we”, “us”, or “our”) is an AI-powered coaching service for Concept2 rowers. We are operated by an independent entity and are NOT affiliated with, endorsed by, or sponsored by Concept2 Inc. Concept2, Concept2 Logbook, PM5, and ErgData are trademarks of Concept2 Inc.

This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over your data. We have written it in plain English because legal jargon helps no one.

If you have questions, contact us at [email protected].

Information We Collect

We collect the minimum data needed to provide AI coaching, sync your Concept2 workout history, and bill subscriptions. The categories below cover everything we hold.

Account Data

When you sign in via Concept2 OAuth, we receive your Concept2 display name and email address (if available). We use this to identify your account and to communicate with you about service changes.

Profile Data

You may optionally provide training context such as goals (e.g. 2k PR, marathon), injuries, equipment availability, age range, and training preferences. This data is used solely by our AI coach to generate personalised workouts.

Workout Data

We sync your workout history from Concept2 Logbook (workouts, intervals, distances, paces, heart rate, stroke rate, drag factor). We also store AI-generated workouts and training-load metrics (TRIMP, acute:chronic ratios). When you program a Concept2 PM5 monitor, we send the workout to ErgData; we may receive raw payload data back for verification.

AI Coach Conversations

When you chat with the AI coach, we store the messages you send and the AI’s responses. Conversations are retained to provide continuity across sessions and to improve our prompts.

Credit and Transaction Data

We track your credit balance, the source of each credit grant (signup bonus, daily reset, subscription, rewarded ad), and every credit consumption (workout generation, chat). This is required to prevent abuse and to power the credit counter.

Payment Data

Payments are processed by Square. We never see or store your card number, CVV, or bank details. We store only a Square customer identifier and your subscription status.

Technical Data

Our servers (Cloudflare Workers and D1) log your IP address and User-Agent string for the duration of your session. These logs are used for rate limiting, security, and abuse detection. Logs are retained for up to 30 days.

How We Use Your Data

We use your data only for the following purposes:

We do not sell your personal information. We do not share it for cross-context behavioural advertising.

Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under the following legal bases under the General Data Protection Regulation (GDPR):

Automated decision-making (GDPR Art. 22): AI workout generation involves automated processing of your training data. You have the right to request human review of any AI-generated workout prescription. To request human review, contact us at [email protected] with the workout ID in question and a coach from our team will review and adjust it.

Third-Party Services

We use a small number of trusted third-party processors to deliver the service. Each has its own privacy practices, which we encourage you to review.

Concept2 (OAuth and Logbook API)

We use Concept2’s official OAuth flow to authenticate you and read your Logbook workout history. Concept2 receives your username and password when you sign in; we never see your password. We store an OAuth access token that allows us to sync new workouts while you remain connected.

Cloudflare (Workers, D1, Pages)

Our backend runs on Cloudflare Workers, our database is Cloudflare D1 (SQLite), and the frontend is hosted on Cloudflare Pages. Cloudflare processes all traffic to and from the service and is certified under the EU-US Data Privacy Framework. See Cloudflare’s subprocessor list.

Google (AdSense and Google Ad Manager)

When you accept cookies, Google AdSense and Google Ad Manager may serve ads. Google receives your IP address, User-Agent string, and the page URL where the ad was displayed. Google may use cookies or local storage to measure ad performance. See Google’s Privacy Policy.

Square (Payment Processing)

Subscription payments are processed by Square. Square receives your billing details directly; we never see your card number. Square may receive your IP address for fraud detection. See Square’s Privacy Policy.

AI Providers (LLM API)

To generate workout prescriptions and chat responses, we send structured workout context (your training history, goals, profile) to a large language model provider. We do not send your name, email, or raw Concept2 credentials. Providers may retain telemetry per their own policies.

Cookies

We use cookies sparingly. Below is a complete list.

Strictly Necessary Cookies (no consent required)

Analytics Cookies

We do not currently use any analytics cookies. If we add analytics in the future we will update this policy and obtain consent.

Advertising Cookies

When you accept cookies via the consent banner, Google AdSense and Google Ad Manager may set cookies for ad measurement, frequency capping, and personalisation. If you decline, no advertising cookies are set and no ad scripts are loaded.

Data Retention

Your Rights

Regardless of where you live, you have the right to:

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you additional rights:

To exercise your CCPA/CPRA rights, contact [email protected]. We will respond within 45 days.

Account Deletion

You can permanently delete your account at any time from Settings → Delete Account. The flow is:

  1. Click “Delete Account”.
  2. Type DELETE (uppercase) in the confirmation box.
  3. Click “Permanently Delete”.

Deletion is performed synchronously: the moment you confirm, your account and all associated data are permanently removed from our production database. The deletion cascades through every related table (workouts, conversations, credit transactions, sessions, and so on). The deleted account cannot be recovered.

Active subscriptions: if you have an active Pro subscription, it is cancelled with Square before deletion proceeds. If the cancellation fails, deletion is blocked and you will be asked to contact support.

Anti-abuse credit reservation: to prevent deleting and recreating accounts to re-claim the signup bonus, we store a one-way hash of your Concept2 username when an account is deleted. If you re-create an account with the same Concept2 username, the signup bonus will not be granted. A determined attacker could rotate usernames (e.g. add a suffix like “+1”) to bypass; this is a known limitation and we monitor for it.

Children's Privacy

MyNextRow is not intended for children under 13 (or under 16 in the European Economic Area, the UK, or Switzerland). We do not knowingly collect data from children. If you believe a child has created an account, contact [email protected] and we will delete the account.

International Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the United States. When we transfer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards:

Cloudflare’s data handling is governed by their published Data Processing Addendum, available at cloudflare.com/cloudflare-customer-subprocessors.

Security

We take the security of your data seriously. Our safeguards include:

No system is perfectly secure. If you discover a vulnerability, please email [email protected].

Changes to This Policy

We may update this policy from time to time. Material changes (changes that affect your rights or the categories of data we process) will be notified to you by email (if we have it) and shown in-product before they take effect. Non-material changes will be reflected in the “Last updated” date at the top of this page.

Contact

For any privacy question, request, or complaint, contact us at [email protected]. We aim to respond within 7 business days.