Loading…
Loading…
Last updated: 3 August 2026
BioMotion is a training and readiness platform for track and field athletes. It has four parts:
This policy covers all four. It describes what the software actually does, not what it might do one day.
Your daily check-in is the core of the product. When you complete one you give us:
If you report pain or illness you can add a symptom: what type, how severe, and where on your body it is. After a session you can log how hard it felt, how difficult it was, and any symptoms during it.
Every revision of a check-in is kept. If you correct an answer, the previous answer is retained rather than overwritten, so a record of what was said when is always reconstructible.
To have an account we hold your name, your preferred name, your date of birth, your nationality, your email address, your timezone, your primary events, and which squad you belong to. If you registered yourself and were under 16 at the time, we also hold a parent’s or guardian’s email address.
Sign-in is by a one-time code sent to your email. There is no password.
For each device you sign in on we record the platform, the app version, a device name and an installation identifier. That is what lets you see your signed-in devices and revoke one you no longer have. Our server sees the IP address your app or watch connects from and uses it to rate-limit sign-in attempts and watch pairing, so nobody can guess their way in.
The BioMotion Connect IQ app runs on your watch. It reads your watch’s own sensor history. It does not use Garmin’s cloud, and Garmin’s servers are not part of this path.
Once you pair it, the watch wakes every fifteen minutes, takes a snapshot, and sends it over HTTPS. The request is relayed through your phone’s Bluetooth link to Garmin Connect; if your phone is not there, the send fails and the next wake tries again with fresher data.
Everything that leaves your watch, in full:
| What | Sent |
|---|---|
| The watch clock time for the snapshot | Always |
| Steps today | Always, if your watch has it |
| Calories today | Always, if your watch has it |
| Distance today | Always, if your watch has it |
| Active minutes today | Always, if your watch has it |
| Resting heart rate | Always, if your watch has it |
| VO₂ max — Garmin’s estimate, not a measurement | Always, if your watch has it |
| Your most recent heart rate reading | Always, if your watch has it |
| Body Battery | Only if you switch on “Share stress and Body Battery” |
| Garmin Stress score | Only if you switch on “Share stress and Body Battery” |
| Blood oxygen (SpO₂) | Only if you switch on “Share pulse oximetry” |
| Your watch’s part number | Always |
Both opt-in switches are off when you install the app. Connecting a watch is not agreement to share everything it records. You will find them in Garmin Connect, under the BioMotion app’s settings, alongside the pairing code field.
Of the list above, our server currently stores heart rate, resting heart rate, steps, active energy, blood oxygen, Body Battery and Garmin Stress. Distance, active minutes and VO₂ max are sent but discarded on arrival — nothing is done with them today.
A snapshot, not a history. The watch sends the most recent value of each thing, once every fifteen minutes. It does not upload your sensor history, your activity files, or anything from before you installed the app.
What the watch app cannot do. It asks for four permissions and no others: to make network requests, to run in the background, to read sensor history, and to read the resting heart rate and VO₂ max in your user profile. It does not ask for location and cannot read it. It cannot read your messages, contacts or calendar.
How the watch is authorised. You get a six-character code in BioMotion and type it into Garmin Connect once. The code is valid for fifteen minutes, works once, and is cleared from your watch as soon as it is spent. In exchange the watch receives a long-lived token, which it sends in a header — never in the body of a request, so it cannot land in a log that records payloads. On our side that token is stored only as a SHA-256 hash: a copy of our database cannot be replayed against the upload endpoint.
Connect IQ cannot provide sleep stages or sleep duration, workout files, or anything recorded before you installed the app. We say so on the pairing screen, before you connect, rather than letting you find out from a week of empty charts.
Apple has no server-to-server route for Health data. Your iPhone is the only thing that can move it, so the BioMotion app reads it on the device and uploads it.
If you connect Apple Health, BioMotion asks iOS for permission to read these fifteen types:
workouts · sleep analysis · heart rate · resting heart rate · heart rate variability (SDNN) · respiratory rate · blood oxygen · step count · walking and running distance · active energy · resting energy · Apple exercise time · body mass · height · wrist temperature
Nothing reproductive and nothing clinical is on that list.
Apple decides what you actually grant, in Apple’s own permission sheet, one type at a time. Apple deliberately does not tell apps whether a read was allowed — so if a type shows nothing in BioMotion, we genuinely cannot tell you whether you denied it or whether there is simply no data. We will never claim otherwise.
Sleep is re-read over a rolling fourteen-day window rather than only forwards, because a night is stored as many separate segments and reading it once can cut one in half.
BioMotion also writes to Apple Health. With your permission, a session you complete in the app is saved back as a workout, so your training appears alongside everything else you record. That is the only thing we write. A workout BioMotion wrote is marked as ours and is never read back in, so nothing round-trips.
WHOOP is the one provider we reach through the cloud. Connecting it uses OAuth: you sign in at WHOOP, and WHOOP gives us a token to read your recovery, cycles, workouts, sleep and body measurements. We never see your WHOOP password.
This is not switched on yet. WHOOP developer approval is outstanding, so the platform currently reports WHOOP as not configured and no WHOOP data can be imported by anyone.
We derive things. They are stored, and they are data about you too:
Two commitments about the derived numbers. Your original answers are kept as first-class records, not replaced by the score. And there are no injury-risk percentages, no diagnosis, and no automatic cancellation of your training.
BioMotion has a coaching feature that drafts sessions and answers questions. It does not send your data to any outside AI company. There is no external model-provider client in the app or the server. The only settings the software will accept run either a plain rule engine or a model on our own machine, reachable only over loopback — deliberately, so that no default can quietly start shipping athlete data to a third party.
Separately, there is a research toolchain that reads coaching and sports-science textbooks to build a knowledge base. It uses an external AI service to process those books. It is not part of the running product, is not deployed on the server, and never sees athlete data.
Your data is used to improve the model only if you switch on training-data consent in your coaching profile. It is off by default, and a coach cannot switch it on for you. Even then, training runs on our own machine and the data does not leave it.
No analytics. No crash reporting. No advertising or tracking SDK of any kind — there is not one in the phone app, the web console or the server. No location. No push notifications. We do not sell data, and there is nobody to sell it to.
Consent in BioMotion is not one checkbox. It is a list of separate decisions, each recorded as its own receipt with the date you made it.
| What you can decide | Starts as |
|---|---|
| Platform terms | Required to use BioMotion |
| Health data processing | Granted at sign-up |
| Menstrual tracking | Off |
| Guardian summary sharing | Off |
| Video analysis | Off |
| Connecting a wearable at all | Off until you turn it on |
| Sleep from your devices | Off until you turn it on |
| Heart rate, HRV and recovery scores | Off until you turn it on |
| Activity and energy | Off until you turn it on |
| Body measurements | Off until you turn it on |
| Temperature | Off until you turn it on |
| Women’s health from a device | Off until you turn it on |
| Sending workouts to a device | Off until you turn it on |
| Writing to Apple Health | Off until you turn it on |
Four things about how this works are worth knowing, because they are unusual.
Connecting a device and sharing what it measures are separate decisions. Connecting WHOOP is not agreement to share your temperature. Each category is its own switch.
Your watch’s readings are checked against your consent as they arrive. If you switch off heart rate and recovery in BioMotion while your watch still has its Body Battery toggle on, our server refuses the reading rather than storing it and hiding it. Hiding it would mean your withdrawal never really took effect — only its display did.
Consent can only ever take access away, never give it. Granting something cannot hand anyone a level of access their role does not permit. And the absence of a decision is a no, not a default yes.
A withdrawal takes effect immediately. Permissions are recomputed from the database on every single request, never read out of your sign-in token. There is no cache and no waiting for anything to expire.
Changing your mind: Privacy and access, in the app’s settings. Only you can answer your own consents — there is no route by which a coach or an administrator can record a consent decision on your behalf.
What withdrawal does not do: it stops new data arriving. It does not erase what is already there. Those are different requests, and the app says so rather than letting you assume.
Menstrual tracking is off until you turn it on, and it is protected at four independent points:
And a design commitment: menstrual-cycle phase has no effect on your readiness score. Symptoms you report raise a signal for a human to look at. They do not silently lower a number.
BioMotion has seven roles. What each can reach is fixed in code and enforced on our server, not in the app. Access is the overlap of three things: what your role permits, what specific grant someone has been given over you, and what you have consented to. All three must agree.
You can see everything about yourself.
A head coach — your readiness score and your individual check-in answers, your training, what you logged after sessions, your competitions, your school commitments, and sleep, heart rate, HRV and activity from your devices. Not your private notes. Not clinical detail. Not menstrual information. Not temperature or body measurements.
A strength coach — your readiness score but not the individual answers, your training, sessions, competitions, and sleep, heart rate and activity.
A physiotherapist — your readiness score and answers, training, sessions, clinical records, competitions, and the wider device set including temperature and body measurements. Not menstrual information.
A doctor — as a physiotherapist, and menstrual information as well.
A parent or guardian — competition schedule, school commitments, and whether a device is connected. Nothing that device measures. Not your check-in answers, not your private notes, not menstrual information, not clinical records. Confirming an account is a safeguarding step, not a window into it.
An administrator — operational access only: the roster, who has access to whom, training schedules, the audit trail, and the ability to attach or detach a device connection. An administrator cannot read a single measurement any of it produces.
Symptom detail is separate from readiness detail. A coach who can see your check-in answers still cannot see where on your body the pain is, or how severe — that needs clinical access, which coaches do not have.
The list in the app is computed, not written down. Privacy and access shows the actual answer to “who can see my check-in answers”, worked out per category from who currently holds access, and it names them. A category nobody can reach reads “Only you”, which is the truth for most of what you record.
If you registered yourself with no club, you are in an organisation of one. You and any club are mutually invisible.
We keep an append-only audit trail of who did what. It is enforced append-only by the database itself, not by convention, and it stores hashes and descriptors, never values — the trail proves a record changed without becoming a second, less-protected copy of your health data.
Raw provider payloads — 400 days. The original untouched payload from Apple Health or WHOOP is encrypted and kept for 400 days so a bug in our processing can be re-run rather than leaving a permanent hole in your history. After that a background job deletes it. The normalised readings survive; the original payload does not.
Everything else — until you delete it. Your check-ins, your readings, your derived scores and your training have no automatic expiry.
Backups — 30 days. The database is backed up nightly, encrypted, and backups older than 30 days are deleted. If you delete something, a copy may remain in a backup for up to 30 days before it ages out.
The audit trail is never deleted. It records that things happened, not what they said. And revising a check-in preserves the answer you replaced.
Signing out wipes your phone. It is a wipe, not a change of screen. Your tokens go, the encrypted local database file is deleted, the key that would decrypt it is destroyed, the upload queue is cancelled, and Apple Health monitoring is unregistered so nothing can wake the app afterwards. If an administrator revokes your device, the same wipe happens the next time the app contacts the server.
Disconnecting a device is not erasing its data, and BioMotion never pretends otherwise. Disconnecting revokes the credentials and stops the background jobs. Everything already imported stays, and the app tells you so in those words.
Erasing is a separate, explicit request. It deletes every measurement, every sleep record, every workout and every raw payload that came in through that connection, and tells you how many of each it removed. That deletion is recorded in the audit trail.
Removing a watch. Withdrawing the relevant consent stops your watch’s readings being accepted immediately — the server refuses them at the door. Deleting the BioMotion app from your watch stops it sending.
Anything not covered above — closing your account entirely, or getting a copy of everything we hold — is a request to a human today. There is no self-service button for it yet, and we would rather say that than imply there is.
What is actually built, without embellishment:
In transit. Everything travels over TLS 1.2 or 1.3, with HSTS. The configuration refuses to start in staging or production against a plain-HTTP address. The watch app cannot send in the clear even if asked to — Connect IQ hardware rejects a plaintext request outright, and the phone relaying it validates the certificate chain.
On your phone. The local database is SQLite encrypted with SQLCipher. The 256-bit key is generated on the device, stored in the platform keychain, marked as available only on this device when unlocked, and excluded from iCloud and Android backups. You can require Face ID, Touch ID or your passcode to open the app, and it re-locks after five minutes of inactivity.
On the server. Raw provider payloads and stored provider credentials are encrypted with AES-256-GCM. The key is derived separately for every combination of athlete, provider and purpose, and the context is bound into the ciphertext — so a leaked key for one connection decrypts nothing else, and a ciphertext moved to another athlete’s row fails loudly rather than decrypting into the wrong record. The database listens only on localhost. The application runs as an unprivileged user under a restricted sandbox.
Credentials. Your watch’s token is stored only as a SHA-256 hash. Refresh tokens are hashed and bound to the specific device. Sign-in codes are hashed with a separate secret and attempt-counted. Attaching or removing a data source requires a recently re-verified sign-in.
Logs. A single redaction policy is applied centrally by the logger and the error handler, so no individual piece of code can forget. It covers tokens and secrets, and it covers your readiness answers, pain detail, body locations, menstrual information, clinical notes, private coach comments and signed media URLs.
What we do not claim. We do not claim full-disk or column-level encryption of the whole database. We do not claim off-site backups — backups are encrypted and kept on the same machine as the database, which means they would not survive that machine’s disk failing. We are telling you this rather than describing an arrangement we do not have.
BioMotion is built for competing junior athletes, and many of our users are under 18. That is not an edge case here; it shapes the design.
Under 16, registering yourself: you must give a parent’s or guardian’s email address, and it must be different from your own. Your account exists and your email is verified, but it issues no sign-in at all until your guardian opens the confirmation link we email them. Until then, signing in tells you plainly that you are waiting on them — it is deliberately their act, not something you can do for yourself.
Sixteen and seventeen, registering yourself: no guardian confirmation is required. Many athletes that age train without a parent involved in the detail, and the product reflects that.
If a coach created your account, the adult in the loop is the coach, and a guardian relationship — if there is one — is set up like any other access grant.
A guardian’s access does not widen with your age or with confirmation. It is competition schedule, school commitments, and whether a device is connected. Never your check-in answers, never your private notes, never menstrual or clinical information. Where an athlete is a minor, a weekly recovery figure is a health metric, and no decision a guardian makes requires one.
Your consents are yours. A guardian cannot answer them for you, and neither can a coach or an administrator.
When this changes, the date at the top changes, and we will say what changed.
Consent wording works differently and is stricter. Consent definitions in BioMotion are versioned and immutable: re-wording a consent publishes a new version rather than editing the old one, and the scopes a consent unlocks are recorded on your receipt at the moment you signed it. A later change to the wording cannot retroactively widen what you agreed to.
Questions about this policy, requests for a copy of your data, or requests to close your account:
mohamed.ahsan.saleem@gmail.com
If you use BioMotion through a club, your administrator can also help with access and device questions.