Privacy and data
AI Aero Coach handles information only to the extent needed to support your own training decisions. This policy takes effect when the service is provided.
Aero-photo duplicate checks
For aero photos uploaded after sign-in, the browser sends a SHA-256 equality value for the original file. Iris stores it privately with an equality value calculated from the server-checked uploaded JPEG, to avoid counting the same photo again as a retake. The original file, original filename and embedded metadata are not sent for this check. Private history returns only account-scoped equality identifiers. Equality values and identifiers are excluded from friend sharing, external-AI context and JSON exports, and are removed when photo deletion is accepted and when deletion processing completes. Iris does not recreate them for records whose photos were deleted. The original-file value is a client-supplied hint, and a different file does not prove a new capture; editing or re-encoding can evade matching. Your retake and capture-condition review applies only to the current comparison selection and is neither saved nor sent. Trial photos and equality values are not sent to or stored by the server.
Record-map data minimization
The athlete record map is computed on demand from the account holder's saved records; Iris does not store new record-model snapshots. When health context is explicitly enabled for an Iris answer, the map is recalculated for that answer and previously stored snapshots are not used in external-AI context. Previously stored snapshots are not silently deleted and remain covered by account export and full deletion.
Free text never authorizes a numeric claim
Numbers and dates inside exercise names, record names, labels, notes, guidance, and other free text are not accepted as evidence for an external-AI numeric claim. Iris authorizes only typed numeric and date fields, the correct evidence-category count, and a validated structured aero target range.
Numeric-notation checks on external-AI answers
For every quantity in external-AI answer text, Iris requires both the same retained value and an authorized unit, an explicit label for a unitless metric such as RPE, load, or IF, an exact retained range, or the correct evidence-count category. Iris normalizes full-width digits before checking. Non-rendering control formatting, unsupported numeral scripts, physical quantities without units, prose calculations, and ranges assembled from unrelated retained values cause the entire provider-written answer to be discarded in favor of the local rule-based answer from checked records.
Same-unit metric attribution
When external AI names average, maximum, normalized, or FTP power; average, maximum, or resting heart rate; body weight, exercise weight, or strength volume; any of the six recovery factors; or a duration, distance, environment, aero, or record-coverage metric, Iris checks the value and unit against that exact structured source field. The binding remains through explanatory wording and when an unambiguous metric name follows its value in the same sentence. The generic label aero score is fixed to overall aero score, and a bare-number overall, quality, or other named aero score is still checked against its exact component. An individual aero-posture metric reaches external AI only when its product-generated key and expected unit match one of 18 fixed definitions; Iris replaces its Japanese and English names with server-defined labels. Each measurement and named metric score is bound to that metric alone, while numeric deviations are excluded from external-AI context so they cannot substitute for measurements. Aero records are ordered newest first; a latest, previous, or dated number must match that exact record. Within one uninterrupted aero clause, the qualifier remains attached to every aero value whether it appears before or after the values, so a trailing date cannot bypass the check and a correct first value cannot conceal a later value borrowed from another record. Iris rejects a numeric claim that mixes multiple dates or both latest and previous. It also rejects ambiguous mappings of multiple same-unit labels and multiple values in either order, and a same-valued or same-unit field cannot substitute for the named metric. A mismatch discards the entire provider-written answer in favor of the local rule-based answer.
Unresolved aero time wording
Iris rejects an aero number attached to today, yesterday, a weekday, last analysis, recent, or another relative time that retained dates cannot resolve uniquely. The answer must use an exact retained date, latest, or previous; otherwise it must stay qualitative. A relative time in a separate non-aero clause does not change an independently grounded aero claim.
FIT activity chronology
FIT activities are fixed newest first. When an external-AI answer attaches latest, previous, or an exact retained date to duration, distance, average, maximum, or normalized power, average or maximum heart rate, cadence, speed, elevation gain, intensity factor, or training load, every metric in that uninterrupted activity clause must come from the same retained activity. Iris rejects mixed dates, latest-plus-previous wording, and activity numbers attached to today, yesterday, a weekday, recent, or another relative time that retained dates cannot resolve uniquely.
Dated saved-record chronology
Recovery, body-weight, strength, and race histories are fixed newest first by category. When an external-AI answer attaches latest, previous, or an exact retained date to recovery signals, body weight, strength duration, RPE, volume or exercise weight, or race distance, goal time, scenario temperature or humidity, every metric from that category in the uninterrupted clause must match the same retained record. A valid value from another date cannot be borrowed. Iris rejects mixed dates, latest-plus-previous wording, and numbers attached to today, yesterday, a weekday, last workout, last check-in, last weigh-in, last race, recent, or another relative time the retained dates cannot resolve uniquely.
Metric labels for temporal numbers
When external-AI answer text attaches latest, previous, an exact date, or an unresolved relative time to a quantity, the same claim must name the exact recognized metric, such as average power, sleep quality, strength volume, or race distance. Category-only wording such as activity, record, check-in, workout, event, analysis, output, value, score, or load does not identify a metric. Iris rejects a temporal bare number even when the same value exists in another retained field, discards the provider-written answer, and returns its checked local rule-based answer.
Structured-answer fail-closed boundary
Iris constrains every text item to 500 Unicode characters in the strict schema sent to external AI, then independently rechecks that the structured answer contains only the required observation, interpretation, next-action, evidence, missing-data, and safety keys; uses the declared types and array limits; cites only unique canonical evidence labels; contains no blank text; and meets the same length limit. An extra key, wrong type, excess item, duplicate evidence label, blank field, or overlong text causes the entire provider-written answer to be discarded. Iris does not silently delete, repair, or truncate the malformed part before showing the rest; it returns the checked local rule-based answer.
Information we handle
We handle the identifier supplied by ChatGPT sign-in; your profile and weight history; activity metrics extracted from FIT files; training plans you create; morning self-reported condition; strength training; race plans; AI Coach conversations; aero-analysis photos and results; your selected helmet and apparel categories; still-air calculation speed; a CdA and its self-reported measurement method when you enter them; news choices; friend requests; and sharing settings. Aero-equipment inputs are stored with the applicable analysis and are covered by your private history, portable JSON export, and deletion controls. Sweat-rate trial weights, fluid, urine and calculated results stay in the current browser and are not sent to or stored by Iris. The sign-in-free trial stores its trial profile and up to 20 extracted FIT activities only in this browser's local storage. Each save renews a 30-day expiry; expired data is removed the next time you open the trial, because Iris cannot delete local storage while the browser is not running. You can delete it immediately from the trial. Trial photos, conversations, original FIT files, and original FIT filenames are not stored in local storage or sent to Iris. Iris does not store original FIT files or filenames, original aero- or profile-photo filenames, card numbers, or card security codes. Aero and profile photos are regenerated as JPEGs in the browser and receive an application-generated name before upload. Before storage, the server also rejects photos that retain embedded personal metadata such as EXIF, XMP, IPTC, or JPEG comments. Standard colour space, image dimensions, and empty generated container information needed for display and browser compatibility are allowed only when they contain no personal metadata. Existing aero-photo names and retired meal-photo names are also anonymized or removed.
Aero-equipment inputs and physical conversion
Helmet and apparel categories are comparison context selected by you; they are not Iris identifications of a product, shape effect, or CdA from the photo. Iris does not infer CdA, equipment-specific ΔCdA, watt savings, or time savings from a photo or category. Only when you enter both a current-setup CdA—including the same rider, bike, position, helmet, and apparel—and the method used to obtain it does Iris assume still air (so ground speed equals relative air speed) and standard air density ρ=1.225 kg/m³, then use your still-air calculation speed as v to display approximate aerodynamic drag in N from F=0.5ρCdAv² and aerodynamic power in W from P=Fv. The method label is self-reported; Iris does not independently validate the instrument, protocol, environment, accuracy, or repeatability. Wind, yaw, gradient, rolling resistance, and drivetrain losses are excluded. These are totals for the CdA you supplied, not an effect of one item, a saving, total cycling power, or a predicted time. Legacy analyses without a method label remain visibly marked as such and are not presented with new provenance.
Authentication and private-response boundary
Every Japanese and English dashboard and API response managed by Iris is marked private, no-store, and no-cache, including a dashboard response that redirects an anonymous visitor to sign in. Iris also sends noindex, nofollow, and noarchive on those app-managed responses. ChatGPT sign-in initiation, sign-out, and authentication callback are owned by the Sites authentication dispatcher in front of the Iris Worker, so Iris does not claim to change their response headers. Iris excludes all three dispatcher paths from crawler access in robots rules and excludes authentication and private paths from its sitemap.
Browser-permission minimization
Same-origin camera access is allowed only in the Japanese and English dashboard documents. Public pages, the sign-in-free trial, and API responses deny camera access. This keeps user-initiated still-photo selection or capture available for photo analysis without extending camera permission to unrelated pages. Iris screens do not start a live video stream; they process one still image that you select or capture. Microphone, geolocation, browser payment, and USB access are denied on every route.
On-device data after full deletion
Only after full server deletion is confirmed, the current browser removes Iris-owned trial data, session keys used for updates and the launch screen, and app caches whose names begin with iris-, then starts sign-out. Other open same-origin Iris tabs receive an on-device signal containing no personal information; each clears its local Iris state and closes displayed personal data. A dashboard open under another Iris production hostname or on another device detects confirmed deletion when it starts, receives focus, and normally once per minute while the browser is running through a minimal deletion-state check, then clears and signs out. An HTTP 202 pending state is not treated as complete. Iris does not target ChatGPT authentication cookies or unrelated browser data. If browser settings or privacy mode block notification or local cleanup, close open Iris tabs and remove this site's data with the browser's site-data controls.
FIT import processing boundary
FIT format, CRC, messages, and metrics are decoded in the browser. The Iris server does not receive the FIT binary or original filename and does not recheck extracted metrics against the binary. A current record stores this client-decode boundary and whether load came from client-decoded FIT session TSS, a server recomputation from duration and IF, or no available load. Iris does not infer and backfill a source for legacy records. These loads do not validate ability, readiness, adaptation, or injury risk.
FIT values at the external-AI boundary
Activity records sent to AI Coach state that their metrics were browser-decoded and were not rechecked against the FIT binary by the server. Internal zero sentinels for missing heart rate, power, cadence, speed, normalized power, and intensity factor are omitted rather than sent as zero measurements. A numeric training load is sent only when the current provenance version confirms FIT session TSS or duration × IF as its source and a positive stored value exists. Unavailable and legacy loads are not represented as zero, and Iris does not infer their value or source.
Answer evidence and other numeric values at the external-AI boundary
AI Coach evidence counts and confidence use only records that remain after the external-AI boundary checks, not raw saved-row totals. Strength records require a real date, RPE from 1 to 10, and in-range exercise values; total volume is recomputed from the retained exercises, and a missing duration is not sent as zero minutes. Race inputs are rechecked against the save-form ranges and a real date; an unset zero target time is omitted. Temperature and humidity are the athlete's scenario, not live weather or WBGT. Aero values are sent only when the stored and analysis method, view, confidence, and overall score match. A retake-required result cannot serve as posture or fit evidence. Out-of-range, inconsistent, or uninterpretable records do not count as answer evidence. Iris also checks every number and date in external-AI answer text against the retained value and recognized unit. If the answer introduces a value that was not supplied, reuses a value with another unit, or creates a conversion, calculation, range, or numerical prescription, Iris discards the entire provider-written answer and returns its local rule-based answer from checked records.
Why we use it and AI data minimization
We use this information for aero analysis, training logs, conditioning views, AI Coach suggestions, and protection from abuse. Opening the training calendar retrieves only the display columns needed from the authenticated user's saved calendar summaries. Pro history is fetched in owner-scoped pages only when you ask to load more, and calendar records are not sent to external AI. Each time you send an AI Coach question, Iris sends the current question and only the needed non-heart-rate FIT, race, strength, aero, and other training context. Exact activity and aero-analysis times are reduced to calendar dates; profile time zone, event names and course notes, strength-session titles, and duplicate confirmation-card copy are not sent. Saved recovery, HRV, resting heart rate, body measurements and weight, prior question trends, and record-map coverage recalculated from current records are excluded by default. They are included only when you explicitly select the per-answer checkbox. Per-answer answer-only mode keeps that ordinary question, response, and response-context summary out of Iris chat history, so they disappear from the screen after reload. It still sends the current question and minimized context to external AI and counts against plan and abuse-prevention limits. Both choices reset to off after sending. Even when health context is selected, Iris excludes database and owner IDs, FIT filenames and hashes, private-storage keys, pose landmarks, free-text recovery, weight, and strength notes, and the original text of earlier questions from external-AI input context. For abuse-prevention metadata, Iris attaches only a stable, non-reversible pseudonymous identifier created under a separate production secret. It is distinct from Iris's internal owner ID; no email address or Sites user ID is attached. Detecting a possible body-weight, recovery, or strength record in Iris chat does not create that record until you press the confirmation card's save button. The server verifies a short-lived confirmation bound to your account, the exact candidate values, and a 30-minute expiry; changed, expired, or cross-account confirmations are rejected. The confirmation itself contains no candidate values or account identifier and is not stored in chat history. Repeating the same confirmation does not create a duplicate. If another body-weight or recovery record already exists for that date, Iris leaves its values, notes, and source unchanged and asks you to review or edit it in Conditioning. A recovery candidate is created only when all six subjective fields are explicit; Iris does not invent missing scores. Manual recovery check-ins and Iris recovery cards are stored only when you select the visible consent checkbox for that save; the checkbox resets afterward. A question matching urgent-warning phrases such as chest pain, fainting, or severe breathing difficulty is handled by a language-specific safety rule before plan and request limits. It does not use external AI or saved athlete records, and the question and response are not stored in chat history. A response escalated by the external AI structured-safety contract is also not stored. AI-answer ratings are linked to a saved response identifier and score; rating an answer does not create a separate copy of its text, and answer-only responses cannot be rated. Question patterns are not used to diagnose personality, psychology, or health. We do not use your photos or health-related entries to train models without separate consent.
Recovery values at the external-AI boundary
Even when you enable health context, Iris sends a recovery-history row only when all six subjective values use a recognized scale version and are complete within 1–10. It excludes partial or uninterpretable rows. Internal zero sentinels for missing sleep duration, HRV, resting heart rate, profile height, and profile body weight are omitted rather than sent as measurements. Weight-history rows with an invalid range or date are also excluded. When at least one valid dated weight record remains, Iris omits the rounded undated profile weight and sends only the dated history as the weight authority. It uses an in-range profile weight only when no valid dated weight record remains. If today’s six factors or caution summary are incomplete or inconsistent, Iris withholds the individual values and conclusion text, and instructs external AI to treat current recovery as missing or uninterpretable.
Urgent heat-safety boundary
A question describing confusion, disorientation, loss of coordination, or a seizure during or after heat exposure is handled before plan limits, external AI, or saved athlete records. Iris does not diagnose heat stroke. It gives a conservative stop-exercise and emergency-call instruction, rapid-cooling steps while help is coming, and a warning not to force drinks when mental status is altered. The question and response are not stored in chat history.
Safety boundary after a blow or jolt
After a cycling crash, fall, collision, or blow or jolt to the head, neck, or body, danger signs such as repeated vomiting, a worsening or persistent severe headache, altered consciousness or inability to wake, a seizure, weakness or numbness, poor coordination, slurred speech, abnormal answers, inability to recognize people or places, unusual restlessness, double vision or unequal pupils, or severe neck pain select the urgent route before plan limits, external AI, or saved records. Iris does not diagnose the cause. It tells the person to stop exercise, call local emergency services, avoid riding or driving, avoid unnecessary head and neck movement unless there is an immediate hazard, and have someone monitor responsiveness and breathing. Without a danger sign, post-trauma headache, nausea or vomiting not described as repeated, dizziness, balance difficulty, fogginess, visual, light or noise disturbance, memory gaps, neck pain, an explicit current concern about concussion, or a request for post-concussion return-to-sport steps selects a separate fixed support route: no return to riding, training, or competition that day, prompt assessment by a qualified healthcare professional, and no self-driving. It explains relative rather than strict rest for the first 24–48 hours and a medically supervised six-step progression, usually at least 24 hours per step, from regular activities through light, moderate, and heavy non-contact activity to cleared practice and competition. Early aerobic steps use walking or stationary cycling, not outdoor riding; fall- or head-impact-risk activity requires explicit medical clearance after symptoms, cognitive abnormalities, and examination findings resolve. New or worsening symptoms stop progression and require contact with the healthcare professional before a directed return to the previous step; students complete return to learning before unrestricted sport. Impact alone, a fully recovered past event, general education other than return-to-sport steps, or a clear denial of symptoms and current concern does not select either route. The question and response are not stored in chat history.
Category-specific safety handling
The safety rule handles chest pain, fainting or severe breathing difficulty; stroke warnings; danger signs after head, neck, or body trauma; suspected-concussion support; overdose; immediate danger of self-harm; and eating-disorder language as separate categories, showing only fixed references relevant to that route. Suspected concussion and eating-disorder support do not by themselves assert an emergency: Iris stops ordinary exercise advice and points to qualified or specialist support. Every category runs before external AI, saved records, and plan limits, and the question and response are not stored. If external AI flags another safety concern, Iris discards its normal advice and returns general server-defined safety guidance without guessing references.
Private by default
Records are separated by authenticated user. Friend connections require a request and mutual approval. Aero analyses and training logs are private by default and are shown to approved friends only if you choose to share them. Weight, recovery, photos, conversations with Iris, helmet or apparel categories, still-air calculation speed, CdA measurement method, measured CdA, and derived aerodynamic drag N or aerodynamic power W are never shared with friends.
Retention, export, and deletion
We keep records for the period needed to provide the service, or until you delete them. Aero photos are stored privately. From aero history, you can delete only the private photo while retaining its analysis, metrics, and history. This account-holder privacy control is available on Free as well as Pro. Iris stops photo retrieval as soon as the request is accepted. If storage deletion temporarily fails, Iris returns HTTP 202, retries from a durable queue, and does not report completion early. Your portable JSON export includes the photo-storage state but excludes internal user IDs, FIT fingerprints, original FIT and photo filenames, private-storage keys, processing tokens, Stripe identifiers, and image binaries. History rows created after export starts are excluded, but updates or deletions to records not yet read can be reflected while it runs. It is not a point-in-time snapshot, so pause changes while exporting when you need a stable result. Records and photos previously saved through the retired nutrition feature are no longer used for new analysis or suggestions. Meal records and non-name photo metadata such as format and size are included in your export; image binaries are removed during full deletion. You can export or delete Iris records, conversations, photos, and friend connections from settings. Starting full deletion immediately blocks new saves and friend sharing, and Iris confirms immediate cancellation of any tracked Stripe subscription before erasing records and private objects. Billing reconciliation, an ambiguous upload, or failed object deletion remains HTTP 202 and is never reported as complete. To prevent the same account from recreating records after deletion, Iris retains only a one-way deleted-account identifier derived from the Sites-stable ID and processing timestamps as a deletion-prevention record. It contains no email, display name, health entry, FIT value, conversation, photo, or Stripe identifier.
Minimal retention of payment-processing metadata
Stripe webhook event IDs, types, modes, event times, and processing times used to prevent duplicate processing are deleted after 90 days. Short-lived reconciliation leases are deleted after expiry. Iris does not store card numbers, security codes, or webhook bodies.
Estimates and external services
Aero posture is an estimate and does not establish information that is not visible or directly measured. Its score is alignment with product-configured comparison bands plus capture quality; the bands are not validated elite norms, a personal optimum, measured CdA, or a bike-fit prescription. Selected helmet and apparel categories do not add to or subtract from the posture score, and Iris does not infer CdA, equipment-specific watt savings, or time savings from the photo or category. The N and W display available when you provide both a current-setup CdA and its self-reported measurement method is an approximate conversion of your supplied value under the stated still-air, standard-density assumption. It is not an Iris estimate of CdA, validation of the selected method, or a prediction of equipment benefit. Wind, yaw, gradient, rolling resistance, and drivetrain losses are excluded. The record map only counts whether existing records are present; it does not estimate ability, talent, recovery state, aero performance, injury, or adaptation. Weekly-time comparison is arithmetic calendar time, not a prediction of training load or performance. Iris uses external services for authentication, hosting, AI responses, image analysis, and news. Their infrastructure may be outside Japan. Stripe hosts payment screens; Iris stores only customer or subscription identifiers, subscription status, scheduled cancellation information, and the current subscription-period end. Iris uses that date to show the account holder the next scheduled renewal or the scheduled end of Pro access, and includes it in the portable JSON export.
Health and security
Displayed information is not medical diagnosis. Stop exercising and contact a qualified professional or local emergency services if pain, abnormal symptoms, or an emergency occurs. We combine encrypted transport, authentication, private storage, same-site request checks, signed webhook verification, rate limits, and input validation, but no Internet service can be absolutely secure. For a privacy request or concern, use Settings after signing in or email akira2940tri@gmail.com without signing in.