Eldridge Solutions Personal projects

Fitness Data Hub

Privacy policy

Last updated 11 October 2026

Fitness Data Hub is a personal application maintained by Dave Eldridge. This policy covers the local application and this public information website.

Information the application accesses

The owner grants Google Drive read-only access through Google OAuth. This scope technically permits reading files across the Google account. The collector restricts its requests to direct children of one owner-configured export folder; this restriction is implemented by the app and is not a folder-only Google permission.

The application reads file metadata such as identifiers, names, sizes, modification times and checksums, and downloads supported FIT files from that folder. Fitness files can contain activity times, sport types, duration, heart rate, distance, speed, cadence, calories and location data where present. Not every field is populated or promoted into the analytical database.

The application does not request the owner’s Google password and does not upload, edit or delete Google Drive files.

How information is used

File metadata supports download tracking, integrity checks and duplicate detection. Downloaded fitness files are archived and parsed into a local PostgreSQL database. A local dashboard shows available activity measurements and pipeline status for personal training and recovery reviews.

Sleep and other daily metrics are planned extensions. They will only be presented as measured facts after delivery and validation. No automated external AI analysis is currently enabled.

Storage and access

Downloaded files, archives, import receipts, database records, owner-managed backups and OAuth credentials are stored on the owner’s computer. Credentials and fitness files are kept outside the source repository in private directories. OAuth credentials are protected with local file permissions. Separate database roles restrict intake and dashboard access, and the dashboard listens only on the local computer’s loopback interface.

These measures do not constitute a claim that every local file or backup is encrypted. The owner remains responsible for the computer’s security and any backups.

Sharing and Google user data

The application does not sell Google user data, use it for advertising or send fitness data to the public website. It does not automatically transmit Google user data to an LLM provider. Google Drive stores the original exports; FitnessSyncer and Garmin handle the upstream collection under their own privacy policies.

Fitness Data Hub follows the Google API Services User Data Policy, including its Limited Use requirements. Any future feature that changes data access, use or sharing will require an updated disclosure and any necessary owner authorisation before activation.

Retention, deletion and revoking access

Local files and records are retained until the owner deliberately deletes them; there is no automatic retention expiry. Revoking Google access stops future authorised collection but does not erase files, records or backups already retained locally. The owner can delete the local archives, inbox, receipts, credentials, database records and backups separately.

Google access can be reviewed and removed through Google Account third-party connections. Questions about deletion or data handling can be sent to the contact below.

This public website

This site contains static information pages. It has no fitness-data upload form, public dashboard, analytics scripts, advertising or application cookies. The hosting provider, Cloudflare, may process normal web-request information, including IP addresses, for delivery and security under its privacy policy. Contacting the maintainer by email supplies the information included in that email.

Contact and updates

Maintainer: Dave Eldridge.
Email: david.j.eldridge@gmail.com.

Changes to this policy will appear on this page with an updated date.