Palena
/Privacy Policy

Privacy Policy

This notice explains how Palena handles personal data when you browse the site, create an account, publish endurance stories, connect an activity service, or contact the team. It describes the product as implemented; it is not a claim of compliance with every privacy law.

Data Palena handles

Account and profile

Email address, authentication identifiers, name, handle, avatar, location, sport preferences, account settings, and administrator status where applicable.

Stories, activity, and community content

Race reports, imported activity details, photos and other media, comments, messages, follows, saved items, club or challenge activity, and the metadata needed to publish or organise them.

Connected services

Provider account identifiers, OAuth tokens, and activity data from services you choose to connect, such as Strava, Garmin, RideWithGPS, TrainingPeaks, or Komoot.

Support and launch communications

Contact messages, early-access signups, feedback reports, email addresses, and any screenshots or files you deliberately attach.

Technical and usage information

Authentication cookies, device and browser information, IP-derived request information, feature usage, diagnostics, rate-limit records, and analytics events when the relevant services are enabled.

Why Palena uses it

Palena uses this information to authenticate accounts, provide profiles and community features, publish and organise stories and media, import activities you request, respond to support and feedback, protect the service, diagnose faults, and understand product performance.

Palena does not need to sell personal data to provide the service. Any materially different use should be disclosed here before it is enabled.

Services that may receive data

Core hosting and storage: Supabase is used for configured authentication, database, and file-storage features. Vercel hosts the web application and provides performance and usage measurement.

Features you choose: connected activity providers receive OAuth requests and return account or activity data; email, YouTube search, and AI-assisted report tools share the information needed for the feature only when that integration is configured and used.

Feedback and analytics: configured Google analytics tags may receive usage events. In-app feedback may create an issue in Palena's configured GitHub repository, and attached evidence may be stored in Supabase.

Public stories, profiles, and media are intentionally visible to other people and may be copied or indexed outside Palena's control. Avoid publishing sensitive information you do not want to make public.

Access, export, correction, and deletion

Palena does not currently provide a complete self-service privacy dashboard or account-deletion workflow. Requests are handled by support using the configured privacy email above.

Access or export

Ask for a copy or summary of the personal data associated with your account and identify any particular content, connection, or date range you need.

Correction

Describe the information that is inaccurate and the correction you want. Use in-product profile or content editing controls first when they are available.

Deletion or erasure

State whether you want specific content removed, a connected service disconnected, or the account and associated personal data deleted.

Objection or restriction

Explain the processing you want Palena to stop or limit. Palena will confirm what can be changed and any information that must still be retained.

Use the subject line Privacy request and include your account email or handle, the type and scope of request, and enough detail to locate the relevant records. Do not send passwords, access tokens, payment-card details, or unnecessary identity documents. Palena may ask for proportionate verification before disclosing or deleting account data and will confirm the outcome through the request channel.

Security and changes

Palena uses access controls and service-provider security features to protect account and content data, but no online service can guarantee absolute security. This notice should be updated when material data uses, integrations, retention practices, or request channels change.