Last updated 30 September 2026
What Gridlines collects, why we collect it, who else sees it, and what you can ask us to do with it. Training data is personal; this page is meant to be readable rather than exhaustive.
This policy explains how Unit Fitness Solutions, Inc. handles personal data across Gridlines — the website, the builder, and the mobile app. It covers coaches, organization staff, and athletes alike; where a difference matters, it is called out.
Account data. Your email address, name, and authentication details. If you sign in with Google, we receive your email and basic profile from Google — not your Google password.
Organization and roster data. Organization names and settings, team membership, staff roles, and invitations.
Training content and results. Programs, exercises, protocols, and the sessions athletes complete — sets, reps, loads, times, and notes. For athletes this is the substance of the service.
Health, readiness, and athlete intake. Depending on your team and the features you use, we process body and health information, daily check-in answers, and coach-configured intake responses. These can include free text, dates and minor status, and typed signature names and form-version records.
If you choose to connect WHOOP or Oura, we process provider/account identifiers, connection metadata, and the health/readiness data that provider supplies. WHOOP data can include recovery, overnight HRV, resting heart rate, and sleep timing; Oura daily readiness is supported. We use this information for training, readiness, and coaching features. Connected-account authorization is managed on our server, and access is subject to your account and team permissions.
Communications. Direct messages and community posts, including reports made about them.
Storefront and commerce data. Public seller profile fields, listings, purchases, subscriptions, and payout status. We do not receive or store your full card number. Card details go directly to Stripe; we see only what Stripe returns, such as the card brand and last four digits.
Technical data. IP address, device and browser information, and logs of requests to the service, kept for security and debugging.
Where the GDPR applies, our legal bases are: performing our contract with you, our legitimate interests in operating and securing the service, complying with legal obligations, and your consent where we ask for it.
We do not sell your personal data, and we do not use your training data to train AI models.
Other users, as the product requires. Your coach sees the sessions you complete for the programs they assign you. Organization administrators see their organization's roster. Your authorized team staff can see the health, readiness, and intake information you submit for coaching. Community posts are visible to that community. Buying a program does not put you on the seller's roster.
Service providers who process data on our behalf, under contract:
Connected wearable services. WHOOP and Oura connections are optional and operate under the provider's terms and privacy policy. Connecting authorizes Gridlines to receive the supported data from that provider. You can disconnect the connection from the app.
We may also disclose data where the law requires it, or to protect the rights and safety of our users. If the business is sold or merged, data may transfer as part of that transaction; we will say so before it happens.
When you use an AI feature, the content needed to answer — such as the structure of the program you are working on — is sent to a model provider to generate a response. If you connect a third-party assistant over our connector, that assistant is operated by whoever provides it, under their own privacy policy, and what it can reach is limited to what your own account permissions allow. Do not put information into an AI conversation that you would not want processed by that provider.
We keep your data while your account is active. When we erase your account at your request, we delete or anonymise personal data, except where we must keep records — payment and tax records in particular — for a legally required period. Backups are retained for a limited window and then cycle out. Account deletion removes identifying profile information, memberships, personal photos and attachments, health/intake answers, readiness data, and wearable connections. Authored messages, posts, and comments are scrubbed. Workout records may remain deidentified; organization-owned programs and assets remain with their organization. Payment, restricted moderation/security records, and erasure audits may remain where needed for legitimate legal, security, or compliance obligations.
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Residents of California and other US states with comparable laws have equivalent rights, including the right not to be discriminated against for exercising them.
Profile and security settings let you change your name, email, and password. To request account and associated data deletion without installing the app, use our account deletion page. For anything else, write to support@getgridlines.com and we will respond within the time the applicable law allows. If you are in the EEA or UK you may also complain to your local data protection authority.
Data is encrypted in transit, access to production systems is restricted, and access to your organization's data is enforced at the database level rather than only in the interface. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant regulator where the law requires it.
We and our service providers operate in the United States and elsewhere, so your data may be processed outside the country where you live. Where we transfer personal data out of the EEA or UK we rely on appropriate safeguards, such as the European Commission's standard contractual clauses.
Gridlines is not intended for children under 16, and we do not knowingly collect their personal data. Where a coach trains minors, the coach is responsible for obtaining any consent their jurisdiction requires. If you believe a child has given us personal data, write to support@getgridlines.com and we will delete it.
We may update this policy. If a change is material we will give notice before it takes effect. The date at the top of this page shows when it last changed.
Questions about privacy, or to exercise a right: kylewilcox.ts@gmail.com.