Your training. Your choice.

Privacy policy · October 6, 2026

mammoth is operated by David King personally. Questions about your data? Email privacy@trainhappy.coach.

Training you choose to share

mammoth offers an AI coaching conversation and tools to inspect your imported training. Apple Health is optional. You can instead import a supported FIT activity file. mammoth reads the Health records you authorize; it does not change your recordings in Apple Health.

Apple Health import can include your earlier workout history in Apple Health, not only new workouts. Available details vary by source and permission: workout type, dates and times, duration, distance, heart rate, pace, cadence, power, elevation, intervals, source/device information and recorded routes. Imported FIT files and their supported measurements are retained in your account, including the original file. A FIT file can contain additional metadata recorded by its originating device or app.

Recovery sharing is separately optional. You choose each category separately: sleep, heart rate variability measured as SDNN, heart rate variability measured as RMSSD where supported (iOS 27 or later), and resting heart rate. Your category choices and Apple Health read permissions control what is shared; agreeing to coaching does not itself enable recovery sharing. mammoth imports selected records within a rolling 35-day window. Missing or denied records are not treated as zero measurements.

Your account and private storage

Sign in with Apple supplies an account identifier and may supply an email address, including an Apple relay address. mammoth uses account and installation identifiers to keep your data separate and synchronize it. mammoth stores your conversation, coach notes, training preferences, imported files and measurements in your private account. For coaching continuity, it also stores short athlete-stated facts from chats and training: goals, availability, preferences, and six ordinary coaching topics—a current niggle, injury history, kit, strength experience, sleep and fueling. A niggle or past injury is training context, not a diagnosis. The saved-profile feature is limited to ordinary coaching topics; your coach is instructed not to save diagnoses or sensitive subjects, including pregnancy and disability, as profile facts. This restriction does not filter your conversation: sensitive information you choose to include in a message or photo, and your coach’s replies about it, can be retained and processed as part of your chat. Messages and replies remain until account deletion; photo deletion is described below.

Supabase provides authentication, database and private file storage. Vercel hosts mammoth’s service. They process information needed to operate the app. Service providers may also process network/request metadata for security and reliability. mammoth does not sell your health data or use it for advertising or cross-app tracking.

Workout maps use Apple MapKit to request map imagery for the area around the displayed route. mammoth draws the route over that imagery on your device.

Photos you choose to send

Photo sending is currently restricted to the owner’s account. If it is available to your account, a first-use explanation appears before you choose photos or screenshots. mammoth creates a resized JPEG with embedded photo metadata removed and stores that copy in your private account and the app’s protected local storage. The image’s visible contents are still included: crop out anything you do not want to share.

Sent photos can be shared with OpenAI to write coaching replies. mammoth also stores a short text reading of what your coach saw, together with the photo’s account/message association, dimensions, size and integrity hash. Sent photos and readings in your account remain until you delete the photo or your account. “Delete photo” removes the stored photo and its reading; the message, earlier replies and a deletion record with technical metadata remain until account deletion. Photos uploaded but never attached to a sent message become eligible for cleanup after 24 hours; cleanup failures or delays can extend that time.

AI coaching by OpenAI

mammoth asks for your explicit permission before cloud coaching starts. If you agree, mammoth sends OpenAI your messages, saved coach notes and athlete-stated profile facts, current training preferences and relevant workout details to generate coaching replies. If you separately enable recovery sharing, relevant selected sleep and heart readings can also inform those replies. If photo sending is available and you send a photo, its visible contents and stored reading can also inform coaching.

mammoth does not attach original FIT files or send the coordinate streams of imported routes in AI requests. A map screenshot you send can still reveal its visible location information. They do include what you type: location, food, symptoms or other personal information written in a message becomes part of the conversation sent for coaching. Avoid sharing information you do not want processed this way.

mammoth disables OpenAI response storage. This does not guarantee immediate deletion by OpenAI: safety logs and processing caches may retain data under its policies. Read OpenAI’s data controls. AI replies can be wrong; mammoth provides training guidance, not medical care.

After you agree to cloud and AI coaching, Good morning is enabled by default. The service can process your recent conversation, training and plan context, current goals, saved notes and previous morning message to generate a short daily morning message through OpenAI, even when you have not just sent a message. It may use last night’s sleep only when sleep sharing is enabled and usable data is available; recovery sharing is not required to receive a morning message. Eligibility and delivery conditions can mean no message is sent on a particular day. In Settings → Coaching → Good morning, you can turn these messages off or separately turn their notifications off. The morning notification preference defaults to on, but visible alerts also require notification permission and enabled app notifications. Turning only the notification off does not stop morning processing.

How we improve mammoth

Once you agree to it in the app, mammoth’s operator may review conversations, coach notes, athlete-stated profile facts, workout data and app usage to fix defects, tune the coach and decide what to build. Review covers only what you share after you agree; it is not retroactive. Reviews are limited to the operator, access-controlled and not shared.

Nothing is used to train AI models, mammoth’s or anyone else’s, and OpenAI response storage stays disabled. Deleting your account removes your data from future review. Review is done by the operator, a person, and is not automated profiling of you as an individual.

Your controls

Retention and account deletion

Account information, workouts and messages remain until you delete your mammoth account. For incomplete workout uploads inactive for seven days, a cleanup worker attempts to remove uploaded file parts. Upload manifests, request identifiers and sequence records remain until account deletion so retries cannot reuse an earlier request for different content. Those manifests can include workout source information, such as sport, times, distance and device details. Some unfinished uploads from older app builds have storage keys that routine cleanup does not match; their file parts may remain until account deletion. The seven-day threshold is not a guarantee that all abandoned upload data has been erased. Recovery imports use the bounded window described above; disconnecting recovery also removes the imported recovery records.

Choose Settings → Delete my mammoth account to request deletion of your account and associated server data. The app stops processing, removes its account cache and shows deletion progress. If the request cannot reach the service, the app asks you to reconnect and retry to confirm server deletion; stopping locally does not itself confirm deletion on the server. Deleting mammoth does not delete your original Apple Health recordings or files you keep elsewhere. A deletion receipt remains available for seven days after completion.

For account security, mammoth retains an encrypted Apple authorization token so it can remove Sign in with Apple access when you delete your account. This token is not used for coaching or sent to OpenAI. If Apple’s revocation service is unavailable, mammoth deletes your training, conversation and account data independently and retries revocation for up to seven days. Revocation material is removed on success or at the retention limit by the cleanup worker. If no usable token is available, or revocation cannot be completed, the app explains how to remove Apple access yourself. This does not prevent deletion of your mammoth data.

When notification registration is authorized, mammoth uses Apple’s notification service and a device token to send notifications after workouts, for your morning message, and when your coach replies, as well as silent sync or notification-security messages. A silent sync message can ask the app to retry a pending Apple Health read after unlock. Turning alerts off inside mammoth retains the token, so silent traffic can continue with the required sharing permission. Denying the initial iOS notification request prevents registration; if you later deny iOS permission, mammoth clears its registration when it observes that change. The service may not learn of that change immediately. Workout and morning alerts use generic text and opaque message identifiers rather than workout measurements or chat text. To reconnect notifications safely, minimal recovery records are scheduled for deletion after seven days; hashed rate-limit records after one hour. Cleanup delays may extend these periods. Account-linked notification recovery records are removed when your account is deleted.

Separate security hashes and replay-prevention markers are retained without an expiry, including after account deletion, to prevent old notification credentials from being reused. They contain no workouts or messages but may be linked to a notification registration. These records are not used for coaching or advertising.

Cleanup depends on the service being available. Provider logs and rotating backups are not necessarily erased immediately with the active account and remain subject to provider retention policies. Contact privacy@trainhappy.coach with questions about retained information or a deletion request.

Adults only

mammoth is for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided personal information to mammoth, contact privacy@trainhappy.coach so we can investigate and remove it.

Changes and questions

If the data-sharing scope or AI provider changes materially, mammoth will explain the change and request any required permission before the new sharing starts.