Privacy Policy
Last updated: 2026-07-06
Introduction
MyNextRow (“we”, “us”, or “our”) is an AI-powered coaching service for Concept2 rowers. We are operated by an independent entity and are NOT affiliated with, endorsed by, or sponsored by Concept2 Inc. Concept2, Concept2 Logbook, PM5, and ErgData are trademarks of Concept2 Inc.
This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over your data. We have written it in plain English because legal jargon helps no one.
If you have questions, contact us at [email protected].
Information We Collect
We collect the minimum data needed to provide AI coaching, sync your Concept2 workout history, and bill subscriptions. The categories below cover everything we hold.
Account Data
When you sign in via Concept2 OAuth, we receive your Concept2 display name and email address (if available). We use this to identify your account and to communicate with you about service changes.
Profile Data
You may optionally provide training context such as goals (e.g. 2k PR, marathon), injuries, equipment availability, age range, and training preferences. This data is used solely by our AI coach to generate personalised workouts.
Workout Data
We sync your workout history from Concept2 Logbook (workouts, intervals, distances, paces, heart rate, stroke rate, drag factor). We also store AI-generated workouts and training-load metrics (TRIMP, acute:chronic ratios). When you program a Concept2 PM5 monitor, we send the workout to ErgData; we may receive raw payload data back for verification.
AI Coach Conversations
When you chat with the AI coach, we store the messages you send and the AI’s responses. Conversations are retained to provide continuity across sessions and to improve our prompts.
Credit and Transaction Data
We track your credit balance, the source of each credit grant (signup bonus, daily reset, subscription, rewarded ad), and every credit consumption (workout generation, chat). This is required to prevent abuse and to power the credit counter.
Payment Data
Payments are processed by Square. We never see or store your card number, CVV, or bank details. We store only a Square customer identifier and your subscription status.
Technical Data
Our servers (Cloudflare Workers and D1) log your IP address and User-Agent string for the duration of your session. These logs are used for rate limiting, security, and abuse detection. Logs are retained for up to 30 days.
How We Use Your Data
We use your data only for the following purposes:
- AI coaching: generating personalised workouts and chat responses based on your training history, goals, and context.
- Progress tracking: computing training-load metrics and visualising your trends over time.
- Payment processing: managing subscriptions, credit grants, and refunds via Square.
- Security and fraud prevention: detecting abusive credit-reset attempts, blocking automated scraping, and rate limiting.
- Service communication: notifying you of material policy changes, security incidents, or service outages.
We do not sell your personal information. We do not share it for cross-context behavioural advertising.
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under the following legal bases under the General Data Protection Regulation (GDPR):
- Consent (Art. 6(1)(a)): provided when you sign in via Concept2 OAuth and accept this policy. You may withdraw consent at any time by deleting your account.
- Contract (Art. 6(1)(b)): processing your workout history and chat messages is necessary to deliver the AI coaching service you signed up for.
- Legitimate interests (Art. 6(1)(f)): we process IP addresses, User-Agent strings, and credit-transaction history to protect the service from abuse (per GDPR Recital 47).
Automated decision-making (GDPR Art. 22): AI workout generation involves automated processing of your training data. You have the right to request human review of any AI-generated workout prescription. To request human review, contact us at [email protected] with the workout ID in question and a coach from our team will review and adjust it.
Third-Party Services
We use a small number of trusted third-party processors to deliver the service. Each has its own privacy practices, which we encourage you to review.
Concept2 (OAuth and Logbook API)
We use Concept2’s official OAuth flow to authenticate you and read your Logbook workout history. Concept2 receives your username and password when you sign in; we never see your password. We store an OAuth access token that allows us to sync new workouts while you remain connected.
Cloudflare (Workers, D1, Pages)
Our backend runs on Cloudflare Workers, our database is Cloudflare D1 (SQLite), and the frontend is hosted on Cloudflare Pages. Cloudflare processes all traffic to and from the service and is certified under the EU-US Data Privacy Framework. See Cloudflare’s subprocessor list.
Google (AdSense and Google Ad Manager)
When you accept cookies, Google AdSense and Google Ad Manager may serve ads. Google receives your IP address, User-Agent string, and the page URL where the ad was displayed. Google may use cookies or local storage to measure ad performance. See Google’s Privacy Policy.
Square (Payment Processing)
Subscription payments are processed by Square. Square receives your billing details directly; we never see your card number. Square may receive your IP address for fraud detection. See Square’s Privacy Policy.
AI Providers (LLM API)
To generate workout prescriptions and chat responses, we send structured workout context (your training history, goals, profile) to a large language model provider. We do not send your name, email, or raw Concept2 credentials. Providers may retain telemetry per their own policies.
Cookies
We use cookies sparingly. Below is a complete list.
Strictly Necessary Cookies (no consent required)
- ba-session — HTTP-only session cookie set by our backend to keep you signed in. Expires after 7 days. This cookie is essential for the service to function and cannot be disabled.
- oauth_state and oauth_next — short-lived cookies set during the Concept2 OAuth flow to prevent CSRF and to remember your intended destination after sign-in. Expire after 5 minutes.
Analytics Cookies
We do not currently use any analytics cookies. If we add analytics in the future we will update this policy and obtain consent.
Advertising Cookies
When you accept cookies via the consent banner, Google AdSense and Google Ad Manager may set cookies for ad measurement, frequency capping, and personalisation. If you decline, no advertising cookies are set and no ad scripts are loaded.
Data Retention
- Account data: while your account is active.
- Sessions: 7 days after last activity.
- OAuth tokens: while you remain connected to Concept2. Disconnecting or deleting your account revokes them.
- Workout history: permanent until you delete your account or request deletion.
- Credit transactions: permanent (audit trail for anti-abuse).
- AI conversations: permanent until you delete your account.
- Server logs (IP, User-Agent): up to 30 days.
Your Rights
Regardless of where you live, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate data.
- Deletion of your data (via the Delete Account button in Settings, or by emailing support).
- Data portability — request a structured, commonly used, machine-readable export of your data (GDPR Art. 20). Contact [email protected] to request an export.
- Restriction of processing in certain circumstances.
- Objection to processing based on legitimate interests.
- Withdraw consent at any time.
- Lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, a Datenschutzbehörde in Germany, or your national DPA in the EEA).
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give you additional rights:
- Right to know what personal information we collect, the categories of sources, the business or commercial purpose, and the categories of third parties with whom we share it.
- Right to delete personal information we have collected from you (subject to the exceptions in Cal. Civ. Code § 1798.105(d)).
- Right to opt out of sale or sharing — MyNextRow does not sell personal information and does not share it for cross-context behavioural advertising. Because no sale or sharing occurs, no opt-out mechanism is required.
- Right to non-discrimination — we will not deny service, charge different prices, or provide a different level of quality for exercising your CCPA rights.
- Right to limit the use of sensitive personal information — we do not collect sensitive personal information as defined by CPRA.
To exercise your CCPA/CPRA rights, contact [email protected]. We will respond within 45 days.
Account Deletion
You can permanently delete your account at any time from Settings → Delete Account. The flow is:
- Click “Delete Account”.
- Type
DELETE(uppercase) in the confirmation box. - Click “Permanently Delete”.
Deletion is performed synchronously: the moment you confirm, your account and all associated data are permanently removed from our production database. The deletion cascades through every related table (workouts, conversations, credit transactions, sessions, and so on). The deleted account cannot be recovered.
Active subscriptions: if you have an active Pro subscription, it is cancelled with Square before deletion proceeds. If the cancellation fails, deletion is blocked and you will be asked to contact support.
Anti-abuse credit reservation: to prevent deleting and recreating accounts to re-claim the signup bonus, we store a one-way hash of your Concept2 username when an account is deleted. If you re-create an account with the same Concept2 username, the signup bonus will not be granted. A determined attacker could rotate usernames (e.g. add a suffix like “+1”) to bypass; this is a known limitation and we monitor for it.
Children's Privacy
MyNextRow is not intended for children under 13 (or under 16 in the European Economic Area, the UK, or Switzerland). We do not knowingly collect data from children. If you believe a child has created an account, contact [email protected] and we will delete the account.
International Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States. When we transfer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards:
- EU-US Data Privacy Framework (DPF): Cloudflare is certified under the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework. The DPF provides adequate protection for transfers from the EEA, the UK, and Switzerland to certified US organisations.
- Standard Contractual Clauses (SCCs): for transfers to processors that are not DPF-certified, we use the European Commission’s 2021 Standard Contractual Clauses (Module 2: Controller-to-Processor) or the UK International Data Transfer Agreement, as applicable.
Cloudflare’s data handling is governed by their published Data Processing Addendum, available at cloudflare.com/cloudflare-customer-subprocessors.
Security
We take the security of your data seriously. Our safeguards include:
- Encryption in transit: all traffic is served over HTTPS with TLS 1.2 or higher.
- Encryption at rest: Cloudflare D1 encrypts all stored data at rest.
- Session tokens: stored as HTTP-only, Secure-flagged cookies. We do not store passwords — authentication is delegated to Concept2 OAuth.
- Principle of least privilege: staff access to production data is limited and audited.
- Zero-PII logging: we never log workout content, email addresses, or authentication tokens in application logs.
No system is perfectly secure. If you discover a vulnerability, please email [email protected].
Changes to This Policy
We may update this policy from time to time. Material changes (changes that affect your rights or the categories of data we process) will be notified to you by email (if we have it) and shown in-product before they take effect. Non-material changes will be reflected in the “Last updated” date at the top of this page.
Contact
For any privacy question, request, or complaint, contact us at [email protected]. We aim to respond within 7 business days.