° 36T Health — Privacy Policy
Last updated 4 August 2026
The short version. 36T Health has no server of its own. It talks to a 36T Health backend that you — or whoever invited you — run, and your training and health data lives there. Whoever operates that server is responsible for it. 36T Solutions GmbH publishes the app and receives nothing, unless the server you use is the one we operate (section 7).
There is no advertising, no analytics or tracking SDK in the app, and nothing is sold or shared with data brokers.
1. Who is responsible for your data
| Controller of your data | Whoever operates the 36T Health server you connect to. If you set it up, that is you. If someone invited you, it is them. |
|---|---|
| Publisher of the app | 36T Solutions GmbH, Hungerbühlstraße 33, 73614 Schorndorf, Germany. We write and distribute the app. We do not receive your data by publishing it. |
The one exception is section 7: 36T Solutions GmbH also operates a server of its own, and for the people who use that server we are the controller in the ordinary sense.
If you do not know who runs your server, its address is shown in the app under Settings → Account → Server, and it is part of the invite link you were sent.
Contact for anything in this policy: info@36t.solutions
2. What the app keeps on your device
- Your login token, in Android Keystore-backed secure storage — not ordinary app storage.
- The address of the server you chose.
- A small number of preferences, such as whether logged reps are also sent to Garmin.
- A cached copy of your reminder schedule, so notifications work without a connection.
That is the complete list. The app contains no analytics, crash-reporting or advertising SDK, and collects no advertising identifier.
3. What the app sends, and where it goes
Everything the app sends goes to the server you configured, and nowhere else. The connection is HTTPS unless you deliberately point the app at a server on your own network over plain HTTP.
What travels there:
- Account details — your email address, display name and password.
- Your athlete profile — age, height, optionally biological sex, training background, goals, available days, equipment, sports, constraints, injuries, race goals and focuses.
- Health and fitness data — activities, heart rate, heart-rate variability, sleep and its stages, Body Battery, stress, steps, calories, training load and status, fitness age, endurance and hill scores, lactate threshold, FTP, intensity minutes, personal records and race predictions.
- Things you record yourself — body weight, blood pressure, pain and injury reports, perceived exertion and logged repetitions.
- Social activity — challenges you join, your scores in them, reactions, comments, and your conversations with the AI coach.
- Credentials for services you connect — your Garmin sign-in, an API key for an AI provider, and optionally a Mealie address and token.
4. Permissions the Android app asks for
| Notifications | Training reminders you have configured. You can decline; the rest of the app still works. |
|---|---|
| Internet | To reach the server you chose. |
5. Third parties the app itself involves
Only one: the app checks for over-the-air updates through Expo's update service, which reveals your IP address and basic device and app-version information. No account or health data is involved.
Garmin, your AI provider and Mealie are contacted by your server, not by the app — see the next section.
6. What a 36T Health server does with your data
This describes the software, and therefore applies to whichever server you use, including one you run yourself.
Storage and protection
Passwords are stored only as an Argon2 hash. Login tokens are stored only as a SHA-256 hash. The credentials you connect — your Garmin password and session, your AI key, any Mealie token — are encrypted at rest with Fernet (AES-128-CBC with HMAC-SHA256) and are never sent back to the app, the website or a watch; the interface only ever shows whether a service is connected.
Garmin
The server signs in as you to read your activity and wellness data, and to send planned workouts to your device if you ask it to. Your use of Garmin Connect remains subject to Garmin's own terms.
Your AI provider
Coaching, plans, briefings and chat replies are generated by a large language model. You choose the provider — Anthropic, OpenAI or OpenRouter — and supply your own API key, so the request is governed by your agreement with them.
The model is sent characteristics, never identity. Your name, your email address and your account identifier are never included in anything sent to an AI provider, and neither is any other person's. Email addresses are stripped from every request as a second line of defence. The provider receives the shape of an athlete — age, history, sleep, load, injuries — with nothing attached that says whose it is.
One honest limit: the free text you write yourself — your goals, your constraints and your messages to the coach — is sent as you wrote it, because that is where the meaning is. If you type your own name or address into those boxes, it goes with them. No automatic filter can reliably tell a person's name from a sport or a place without mangling the text, so we do not pretend to. The app says so next to those fields.
If you would rather no health data left your server at all, do not configure an AI key — everything else continues to work.
Mealie
If you connect one, recipe and meal-plan data is exchanged with the address you provide, typically a server you run yourself.
Menstrual cycle and pregnancy information
If your Garmin account records it, it may appear in the imported wellness data. It is visible only to you, and never to anyone else unless you explicitly grant a named person access — which you can withdraw at any time. Nothing is copied when you share, so revoking takes effect immediately.
Other members of a challenge
They see your display name and your score in that challenge. They cannot see your profile, your wellness data or your health records.
7. The server operated by 36T Solutions GmbH
36T Solutions GmbH runs one 36T Health server, at fit.36t.solutions.
If that is the server you connect to, 36T Solutions GmbH is the
controller of your data and everything below applies. If you use any
other server, it does not, and we hold nothing about you.
- Where it is. On infrastructure we operate ourselves, in the European Union. It is not hosted with a third-party cloud provider. All traffic is encrypted with HTTPS.
- Why we process it. To run your account and show you your own data (performance of a contract, Art. 6(1)(b)); to generate training guidance from your health data (your explicit consent, Art. 9(2)(a)); to keep the service secure (legitimate interests, Art. 6(1)(f)).
- Health data is a special category under GDPR. We process it only because you asked us to, by connecting Garmin or entering it yourself, and you may withdraw that consent at any time by disconnecting the service or deleting your account.
- How long. For as long as your account exists — the value of the app is in the long history. Deleting your account deletes it. Login sessions expire on their own.
- Transfers outside the EU happen only through services you choose to use: your AI provider, and Garmin.
8. Deleting your account
You can delete your account and everything in it at any time, from inside the app or from a browser, without asking anyone. It takes effect immediately and cannot be undone.
Full instructions, and exactly what is removed: Delete your account →
9. Your rights
Under GDPR you have the right to access the data held about you and receive a copy, to have inaccurate data corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, to withdraw consent at any time without affecting processing already carried out, and to complain to a data protection supervisory authority.
Exercise them with whoever operates your server. If that is 36T Solutions GmbH, write to info@36t.solutions and we will respond within 30 days.
10. Children
36T Health is not intended for anyone under 16, and we do not knowingly collect data from children.
11. Changes to this policy
If this policy changes, the date at the top of this page changes with it. Where a change materially affects how data is used, we will say so in the app before it takes effect.
12. Contact
36T Solutions GmbH, Hungerbühlstraße 33, 73614 Schorndorf, Germany — info@36t.solutions