Magic Training logo
Magic TrainingHome

Privacy Policy

This policy explains how we handle information when you use our platform. We value your privacy and are committed to transparency in how we process your data.

Data Collection and Storage

Data Collected and Stored

Magic Training collects and stores information necessary to provide our personalized training services. Data is securely stored in PostgreSQL databases managed by Supabase, with encryption in transit and at rest and per-user isolation enforced at the row level.

Account and Profile Data:

  • Name, email, and profile picture (via Google OAuth or manual registration)
  • Profile information (date of birth, gender, runner level)
  • Personal records (5K, 10K, half marathon, marathon)
  • Training preferences and account settings

Training Data:

  • Saved and personalized training plans
  • Activity history and progress
  • Performance statistics and metrics
  • Custom pace settings

Subscription Data:

  • Premium subscription information (status, dates, type)
  • Payment data processed via PIX (Efí Bank)
  • Transaction and invoice history
  • Purchases made through the stores (Google Play and the App Store): purchase identifier, product code and subscription status — card details never pass through us
Challenges, leagues and levels (gamification)

The platform has monthly challenges with rankings, a weekly league with divisions, XP levels and badges. Everything is computed from the completed activities already in your account; no new data is collected for it.

What other people see

Rankings exist only among logged-in people and show the minimum needed to compare results:

  • In the challenges you join: name, photo, level, the challenge metric value (for example, km in the month) and position, to the other enrolled people. In coaching-group challenges, only to the athletes and the coach of that group.
  • In your league group (up to 30 people in the same division): name, photo, level, the week's km and workouts, the week's XP and position.
  • Never visible: route, map, heart rate, times and other activity details, profile data, body measurements or training plan.

Automatic placement in the league

Opening the challenges or league page places you in this week's group of your division. Anyone who trained during the week and has not opened the page yet is placed the next day. You can leave the leagues at any time on the league page; from then on you are no longer placed in a group, and the XP from your activities keeps counting only toward your level. Challenges are always opt-in: you only appear in the rankings of the ones you chose to join.

History and retention

At the end of each challenge and each league week we keep a summary (value, position, outcome and XP) for your history and for computing your level and badges. These records are deleted together with the account.

The full rules are at How challenges, the league and levels work.

Aggregated public statistics

We publish an overview of amateur running at magic.training/dados, built from workouts logged on the platform. No individual data is disclosed: only percentages, medians and counts describing the group leave the database.

What is published

Aggregate figures such as the distribution of workouts by weekday, the share of plans still active in each week, the distance distribution of runs and the median pace by target distance.

What is never published

  • Your name, email, photo or any identifier.
  • Individual workouts, routes, maps, heart rate or any metric attributable to a person.
  • Groups that are too small: every published cut requires a minimum number of records, so no result can correspond to a handful of individuals.

Legal basis and your choice

This processing relies on the legitimate interest in producing statistical information about training, under art. 7, IX of Brazil's LGPD. Because the result is anonymised and irreversible, it cannot identify you. Even so, if you prefer your records to be left out of these aggregates, write to us and we will exclude your account from the computation.

magic.training/dados

Cookies and Similar Technologies

We use cookies and similar technologies to improve user experience and analyze platform usage. This includes:

  • Functional cookies to remember your preferences (such as dark/light theme)
  • Analytical cookies to understand how the platform is used

You can manage your cookie preferences through your browser settings.

Payment Processing and Integrations

Efí Bank (PIX)

To process premium subscription payments via PIX, we use Efí Bank. During the payment process, we collect and share with Efí Bank:

  • Personal data (name, email, CPF)
  • Contact information (phone, address)
  • Information required to generate the PIX QR Code

This data is processed in accordance with Efí Bank's privacy policies and is necessary for the security of PIX transactions.

Resend (Transactional Emails)

We use the Resend service for sending transactional emails such as subscription confirmations, account updates, and important communications. We only share your email address and name for message personalization.

Google Analytics

We use Google Analytics to analyze the usage of our platform. Google Analytics uses cookies to collect information about how you interact with Magic Training. This information is used to generate reports and help us improve the platform. Google Analytics collects information anonymously, without identifying individual users.

Vercel Analytics

Our platform is hosted on Vercel, which provides performance and usage analytics. Vercel may collect information such as IP addresses, browser type, and pages visited to provide these insights. This information is processed in aggregate and does not identify individual users.

Apple Health (HealthKit) and Apple Watch

The Magic Training app for iPhone and iPad can read data from Apple Health (HealthKit) to automatically log the workouts you recorded on your Apple Watch. Access is optional, requested explicitly the first time, and can be revoked at any moment.

The app never writes data to Apple Health: the authorization we request is read-only.

Data we read from Apple Health

With your authorization, the app reads only what it needs to recognize and log the workout in your plan:

  • Workouts (running, walking and strength training): type, date, time and duration
  • Heart rate during the workout
  • Distance covered while running and walking
  • Active energy (calories) burned in the workout
  • Workout route (GPS), used solely to compute elevation gain and per-kilometer splits

How we use this data

Data read from Apple Health is tied to your account and used exclusively to:

  • Automatically log the workout on the matching day of your plan
  • Show the workout metrics (pace, heart rate, elevation and splits)
  • Compute your progress, training volume and performance statistics
  • Send the synced-workout notification, when you keep it enabled

Our commitments regarding health data

In accordance with Apple's HealthKit guidelines and with applicable data protection law, we commit to:

  • Never use Apple Health data for advertising, marketing, or any form of use-based data mining
  • Never sell, rent or otherwise disclose Apple Health data to data brokers, advertisers or analytics platforms
  • Never share Apple Health data with third parties without your explicit consent. The only exception is your coach, when you use Coach Mode, and only for the workouts in the plan they supervise
  • Never use Apple Health data to train artificial intelligence systems
  • Use this data only for health, fitness and the management of your own training

Your control over access

You can revoke Magic Training's access to Apple Health at any time under Settings → Privacy & Security → Health → Magic Training on your iPhone, or turn off automatic import inside the app itself. Revoking access stops any further reads; to delete workouts already logged, use the rights described in the "Your Data Rights" section.

Android and Wear OS apps

Magic Training has apps for Android and for Wear OS watches. This section describes what those apps collect and send to our servers, in addition to what the other sections of this policy already describe.

Sensors and permissions on the watch

On a Wear OS watch, the app uses the permissions you grant to record the workout in progress:

  • Heart rate, from the watch sensor, during the workout
  • Location (GPS), used to calculate distance, pace and elevation during the run
  • Activity recognition and body sensors, required by Android to keep the workout recording alive in the background
  • Notifications, to show the ongoing workout and the alerts from the watch

GPS coordinates never leave your device: the watch turns them into distance, pace and altitude, and only those numbers are sent to your account. We do not record or store the route of your workout.

What is sent to your account

When you finish a workout on the watch or log it on your phone, we send the following to our servers:

  • Date, time, duration and distance of the workout
  • Average pace, speed and elevation calculated on the device
  • Average and maximum heart rate, and the heart rate series across the workout
  • Calories estimated by the watch
  • What you fill in yourself: perceived effort, workout notes and body measurements

Push notifications

To send notifications (today's workout, sync completed, coach alerts), we register a notification identifier generated by Firebase Cloud Messaging, along with your device model and app version. That identifier is tied to your account, used only to deliver notifications, and deleted when you sign out or uninstall the app.

Crash and diagnostic reports

We use Firebase Crashlytics (Google) to receive reports when the app crashes or misbehaves. It collects crash logs, diagnostic information (device model, Android version, memory and app state at the time of the failure) and an installation identifier generated by Firebase. This data is used solely to fix defects. The app uses no advertising ID, shows no ads, and contains no advertising or behavioural analytics SDK.

Subscribing through Google Play

When you subscribe from the Android app, billing is handled by Google Play. The app receives a purchase identifier and the product code from Google, which we send to our server only to validate the subscription and unlock premium access. Card details never pass through Magic Training.

Commitments about health and fitness data

As on iOS, the health and fitness data collected by the Android and Wear OS apps:

  • Is never used for advertising or marketing
  • Is never sold or transferred to data brokers, advertisers or analytics platforms
  • Is only shared with your coach when you use Coach Mode, and only for the workouts they follow

Your control

You can revoke the watch permissions under Settings → Apps → Magic Training → Permissions, turn notifications off in the system settings or inside the app, and delete your account and all your data directly in the app, under Profile → Delete account.

Garmin Connect Integration

Required Consent

Before connecting your Garmin Connect account, you must provide explicit consent for the transfer and processing of your training data. Your data will only be synchronized after your specific authorization.

Data Collected from Garmin

When you connect your Garmin Connect account to Magic Training, we collect the following types of data:

  • Training and activity data (running, cycling, swimming, etc.)
  • Performance metrics (time, distance, pace, heart rate)
  • Garmin device data (device model, settings)
  • Training plans and exercise calendar
  • Health and wellness data (when authorized)

How We Use Garmin Data

Data obtained from your Garmin Connect account is used exclusively for:

  • Synchronizing your training plans with Garmin devices
  • Analyzing your progress and athletic performance
  • Personalizing training recommendations based on your history
  • Generating progress reports and statistics
  • Improving our training planning algorithms

Garmin Privacy Policy

For detailed information about how Garmin handles your data, please refer to theGarmin Connect Privacy Policy.

International Data Transfer

When you connect your Garmin Connect account, some of your data may be transferred to Garmin servers located in the United States and other countries. These transfers are protected by standard contractual clauses approved by the European Union and follow international data protection best practices.

Your Rights Over Garmin Data

You have the following rights regarding data collected from your Garmin account:

  • Access: View which data has been collected from your Garmin account
  • Rectification: Request correction of incorrect or incomplete data
  • Deletion: Request removal of your data from our platform
  • Portability: Export your data in a machine-readable format
  • Disconnection: Revoke access to your Garmin account at any time

To exercise these rights, go to the "Synchronizations" section in your profile or contact us.

Use of Artificial Intelligence

AI Transparency

This platform uses artificial intelligence systems to process and analyze training data, including data obtained from Garmin devices.

How We Use AI

Our AI systems process your training data (including Garmin data) to:

  • Generate personalized training recommendations based on your history
  • Analyze performance patterns and identify areas for improvement
  • Automatically adjust training intensity and volume
  • Detect potential signs of overtraining or fatigue
  • Improve our training planning algorithms

Consent for AI Processing

By using our platform and connecting Garmin devices, you explicitly consent to:

  • Your training data being processed by AI systems
  • Analysis results being used to improve the service
  • Aggregated and anonymized data being used to train our models

You may withdraw this consent at any time through your account settings or by contacting us. Withdrawing consent may affect the functionality of some platform features.

Protections and Limitations

  • All data is processed securely and encrypted
  • Personally identifiable data is not shared with third parties
  • You maintain full control over your original data
  • Our AI systems follow best practices in AI ethics
  • Data originating from Apple Health (HealthKit) is excluded from any model training, in accordance with Apple's guidelines
Security and Your Rights

Security Measures

We implement technical and organizational security measures to protect your data:

  • Encryption of data in transit and at rest
  • Secure authentication via Supabase Auth with JWT tokens
  • CSP (Content Security Policy) security headers
  • Sensitive tokens encrypted in the database
  • Security monitoring and audit logs
  • Regular data backups

However, please remember that no method of internet transmission or electronic storage is 100% secure.

Your Data Rights

In compliance with the LGPD, you have the following rights over your personal data:

  • Access: View all data we have collected about you
  • Correction: Request correction of incorrect or outdated data
  • Deletion: Request complete removal of your data
  • Portability: Export your data in a readable format
  • Opposition: Object to processing for specific purposes
  • Revocation: Withdraw consent at any time

To exercise these rights, go to your account settings or contact us.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy or as required by law. Data from accounts inactive for more than 2 years may be automatically deleted, except when necessary for compliance with legal obligations.

Contact

If you have questions about this privacy policy or how we handle your information, contact us at: contato@magic.training

Last updated: September 10, 2026