Privacy Policy.

Last updated: 4th August 2026  ·  Policy version: v2.0

This policy is issued under French law and the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR” / “RGPD”). AUSPRÁ is the trading name of AUSPRA SAS, a French société par actions simplifiée registered with the RCS of Lyon under number 106 480 668, whose registered office is at 64 Rue Lucette et René Desgrand, 69100 Villeurbanne, France. AUSPRA SAS is the data controller for the processing described below. For any question about this policy or your data, contact us at hello@auspra.com.

Who we are

AUSPRÁ builds recovery-intelligence technology for athletes. Our system pairs a wearable biomechanics sensor with a mobile application and a cloud platform that calculates personalised running indices. This policy covers three groups: people who join our waitlist or newsletter; people who apply to join our test cohort through our application form; and people who are admitted to the test cohort (the “tester program”) and use the AUSPRÁ sensor and app.

Adults only. The AUSPRÁ test cohort and application process are open to adults aged 18 or over only. We do not knowingly collect data from anyone under 18 through the tester program or application form. If we learn that we have collected data from a person under 18 in this context, we will delete it.

A note on the tester program. The AUSPRÁ test cohort is a research tester program. People who join the cohort do so to generate research data that helps us develop and validate our technology. This is explained in the invitation to join the test, and it shapes how consent works for testers, as described in section 7 and section 9 below.

What data we collect

Waitlist and newsletter. When you join our waitlist or subscribe to our newsletter, we collect your name and email address. We also record the source through which you found us (for example, LinkedIn, Reddit, or Strava) using a tag attached to the form you submitted. For the waitlist and newsletter, we do not collect your location, payment information, or any other personal data.

Application to join the test. Before you are admitted to the test, we ask you to complete an application form. Through that form we collect: your first name, last name, phone number and email; and information about your running and training — how many days per week you run, whether you train in more than one sport, your average weekly distance, whether you are training for a specific event and which event and when, whether you currently use a wearable and how you track your heart rate, why you want to join, the country and city where you are based, your Strava handle if you have one, whether you run with your phone, and which phone you use. We also ask whether you have had a running-related injury in the past two years. This injury question is health information, which we treat as special-category data under Article 9 GDPR; we ask it to assess your suitability for the test, and we collect it only with your explicit consent given on the application form. You can decline to answer, though this may affect eligibility.

Tester program. If you are admitted to the test cohort and use the AUSPRÁ sensor and app, we additionally collect:

  • Profile details — your first name, last name, date of birth and gender.
  • Physiological details — your weight, height, maximum heart rate and resting heart rate.
  • Training profile — your primary sport, number of sessions per week, years of practice, hours of running per week, kilometres per week, and consecutive weeks of training.
  • Sensor data — accelerometer data from the AUSPRÁ sensor, namely vibration, cadence and acceleration, captured as CSV or in the proprietary .sbem format used by Movesense, the sensor's manufacturer.
  • Location data — GPS data from your phone, captured during a session.
  • A device identifier — an identifier associated with your sensor or app instance, which is linked to your user profile.
  • Connected Strava data (only if you connect Strava) — when you choose to connect your Strava account and share it, we ingest, per activity: GPX route data, pace/speed, heart rate, and date/time. These are the fields we receive from Strava.

How we treat this data. AUSPRÁ collects sensor and location data only during a recorded training session, and heart rate only where you have connected a heart-rate monitor for that session. We do not monitor you passively or continuously. From your sensor's vibration data recorded during a session we calculate a fatigue index and related training and recovery metrics. Because your physiological details (such as resting and maximum heart rate, weight and height) and the metrics we derive from your sensor data allow inferences to be drawn about your physical condition, we treat those physiological details, your sensor data, connected heart-rate data, and the indices derived from them as special-category data under Article 9 GDPR, and we process them only on the basis of your explicit consent (see section 7). We take this careful approach so that your data is properly protected; it does not mean AUSPRÁ is a medical product (see section 5).

Pseudonymised, not anonymised. In our cloud platform, your sensor, location and Strava data are held in pseudonymised form: they remain linked to your profile through the device identifier and internal keys, but are separated from directly identifying details. Pseudonymised data is still personal data under Article 4(5) GDPR and is protected as such. We do not describe this data as “anonymised,” because it is not irreversibly stripped of identity.

How sensor and location data flows

For testers, the data path is as follows:

  • Local capture.The sensor captures accelerometer data (vibration, cadence, acceleration) and streams it locally to the app. Your phone's GPS is captured and stored locally in the app.
  • Cloud calculation. Your local data is then sent to our cloud, hosted on Google Cloud Platform in the europe-west1 region (Brussels, Belgium, in the EU), where we calculate your running indices.
  • Pseudonymised storage. Your data persists in your cloud profile in pseudonymised form, associated with your device identifier.

Strava integration

The Strava integration is user-initiated: we only ingest Strava data if you connect your Strava account and choose to share it. When connected, we use your Strava data in two ways:

  • Session augmentation — adding data to a live AUSPRÁ session that our own sensor does not capture, such as heart rate or richer GPS.
  • Baseline — using your historical Strava data to help establish your personal performance and recovery baseline.

You can disconnect Strava at any time. Strava's own processing of your data is governed by Strava's privacy policy; when you connect Strava, some processing takes place on Strava's own infrastructure, which may be outside the EU. See Strava's privacy policy for details.

AUSPRÁ is not a medical device

AUSPRÁ provides training, performance and recovery information to help you manage your training. The fatigue index and other metrics AUSPRÁ produces are training and performance indicators. AUSPRÁ is not a medical device, does not provide medical diagnosis or treatment, and its indices are not a substitute for professional medical advice. Treating the underlying data carefully under Article 9 GDPR, as described in this policy, is a data-protection measure; it does not make AUSPRÁ a health or medical service, and nothing in AUSPRÁ should be relied on as such.

Research and model improvement

Separately from running the app for you, we retain your pseudonymised data and use it for research that AUSPRÁ may publish and to improve our algorithms and machine-learning (ML) models. This use is tied to a specific, separate consent (“Box 2” at onboarding; see section 7). It means your pseudonymised data is retained beyond each individual session and contributes to research and to model training.

Because the test cohort is a research tester program, this research use is intrinsic to taking part in the test. If you are a tester and you withdraw this consent, you leave the test program — this is explained honestly in section 9. It is not a case of continuing to use the app with research switched off.

Legal basis for processing

We rely on different legal bases for different processing:

  • Waitlist and newsletter (name, email, source tag). Your consent, under Article 6(1)(a) GDPR, given when you submit the form. You can withdraw it at any time.
  • Application form (screening). Your consent under Article 6(1)(a) GDPR for the ordinary details (name, contact and training answers). For the injury-history question, which is health information, your explicit consent under Article 9(2)(a) GDPR, given by a separate tick on the application form. You can withdraw either at any time.
  • Core sensor and app processing to deliver your indices (Box 1). Because your fatigue and recovery indices are derived from session sensor data and allow inferences about your physical condition, we treat this processing as involving special-category data and rely on your explicit consent under Article 9(2)(a) GDPR, together with Article 6(1)(a). This consent covers collecting your accelerometer and GPS data (and connected heart-rate data, where applicable) during a session and processing it in our cloud to calculate your indices.
  • Research, publication and algorithm/ML improvement (Box 2). A separate, independent explicit consent under Article 9(2)(a) GDPR, together with Article 6(1)(a). It is unbundled from Box 1 and is ticked separately.

The two tester consents are collected as two separate, independently tickable boxes at onboarding, neither pre-ticked. We record the date and time of each consent and the policy version in force at that moment.

Who processes your data

We use the following processors and sources. Each processor acts under a data processing agreement (Article 28 GDPR).

  • Google Cloud Platform (europe-west1, Brussels, EU) — cloud hosting and index calculation for tester data. Data is held on EU-based infrastructure. Google is a US-parent provider; any access from outside the EU is covered by Google's EU-US Data Privacy Framework certification and Standard Contractual Clauses in its data processing terms.
  • Customer.io (EU data centre) — our email and messaging platform for the waitlist and newsletter, replacing our previous provider. Your name and email are held on Customer.io's EU infrastructure. Customer.io is a US-parent provider certified under the EU-US Data Privacy Framework, with Standard Contractual Clauses in its data processing agreement covering any US access.
  • Vercel (US location) — website hosting. Vercel may collect standard server logs (IP address, browser type, pages visited) as part of normal hosting. See Vercel's privacy policy.
  • WhatsApp / Meta (tester community, optional) — we invite testers to an optional WhatsApp Community. If you join, your phone number and anything you post are processed through WhatsApp, operated by Meta, a US-parent provider; Meta relies on the EU-US Data Privacy Framework and Standard Contractual Clauses for such transfers. Joining is your choice, and WhatsApp's own terms and privacy policy govern the group. Please note that in a WhatsApp Community other members may be able to see your phone number and profile name.
  • Strava (source, when connected) — where you connect Strava, it is the source of the Strava data described in section 4, and processes your data under its own terms.

How long we keep your data

  • Waitlist and newsletter. We keep your name and email for as long as you remain subscribed. If you unsubscribe or request deletion, your data is removed within 30 days.
  • Application-form data. If you are admitted to the test, your application data is kept until the test closes, which we currently expect to be June 2027, after which it is deleted or merged into your tester record. If you are not admitted, your application data — including your injury-history answer — is deleted within three (3) months of the eligibility decision.
  • Tester data used to deliver your indices. Retained for as long as you are an active tester and your account is live.
  • Research data (Box 2 consent). Retained in pseudonymised form for up to ten (10) years from collection, for the purpose of longitudinal research and algorithm/ML development, which requires multi-year baselines to be scientifically meaningful. Because the research program is ongoing, this retention is reviewed at least every time this policy is updated, and in any event no later than five (5) years from collection, at which review the data is either re-justified against a live research purpose, further processed toward anonymisation, or deleted. Ten years from collection is a firm maximum. We never retain research data indefinitely.

Your rights, withdrawal and deletion

Under the GDPR you have the right to access the data we hold about you, to correct inaccurate data, to request deletion, to withdraw your consent, to receive a copy of your data in a portable format, and to object to processing. To exercise any of these, email hello@auspra.com. We respond within 30 days. These rights, and withdrawal and deletion, cover the sensor, location, device-identifier and connected Strava data described in this policy.

Withdrawing research consent (Box 2). You can withdraw at any time via My Account → Data & Privacy, or by emailing us. Withdrawing stops future research use of your data. Two honest points: first, because the test cohort is a research program, withdrawing research consent means leaving the test program. Second, data that has already been incorporated into trained models generally cannot be pulled back out of those models; withdrawal stops further use, but does not retroactively remove your past contribution from models already trained. We state this plainly rather than implying otherwise.

Cookies and tracking

Our website does not use cookies for advertising or tracking. If we add analytics in the future, this policy will be updated before any tracking is implemented.

How to unsubscribe

Every marketing email includes an unsubscribe link. You can also email hello@auspra.com and we will remove you manually within 48 hours.

Known future change

We record here, in advance, a change we already know we will make. The mandatory research consent (Box 2) described in sections 6, 7 and 9 applies only to the current test cohort, because participation in that cohort is defined by taking part in research. At public launch, research consent will become optional: public users will be able to use AUSPRÁ without consenting to research use of their data. This policy will be updated at that time.

Changes to this policy

If we make material changes to this policy, we will update the "last updated" date and the policy version at the top of this page. If the changes affect how we use your data, we will notify you by email before implementing them.