Privacy
Privacy Policy
Last updated: 15 August 2026
Montis.icu is designed to minimise the amount of personal data retained by the Service while still providing secure connected-account access, athlete analytics, notifications and coaching functionality.
This Privacy Policy explains what personal data Montis accesses, where that data comes from, why it is processed, what limited information is retained by Montis, which external services are involved and what rights you have.
This Policy should be read together with the Terms of Service.
01 · Who is responsible
Data controller
Montis.icu is operated from the Canton of Vaud, Switzerland.
For personal data processed directly by Montis in connection with the Service, the Montis operator acts as the data controller. For requests see the form below.
02 · Scope
Where this Policy applies
This Policy applies to personal data processed through:
- the Montis.icu website and application;
- Montis connected-account and OAuth services;
- Montis reporting and coaching tools;
- Cloudflare-based authentication and edge services;
- Railway-based analytics and reporting execution;
- Montis REST APIs;
- Montis MCP services;
- supported AI and LLM integrations;
- push-notification functionality; and
- subscription or supporter-access functionality.
03 · Athlete data
Intervals.icu remains the primary athlete-data source.
Athlete training and wellness information used by Montis is primarily retrieved from Intervals.icu after the athlete or an authorised coach connects the relevant account.
Depending on the tool or report requested, this can include:
- activities and activity metadata;
- intervals and workout information;
- power, heart-rate and pace data;
- FIT-derived and custom activity fields;
- training load and fitness-related fields;
- wellness information;
- HRV and resting-heart-rate information;
- sleep and recovery information;
- subjective wellness information;
- calendar and planned workouts;
- race and event information;
- athlete profile information made available by Intervals.icu; and
- other authorised Intervals.icu fields required by the selected Montis tool.
Where athletes add optional physiological information — for example lactate thresholds, AlphaHRV / DFA-α1 fields or other custom activity fields — those values may also be retrieved when explicitly available through the authorised Intervals.icu account.
04 · Health-related information
Training and wellness data can be sensitive personal data.
Training, wellness, recovery, HRV, sleep, heart-rate and related physiological information can reveal information concerning an athlete's health or physical condition.
Montis therefore treats these data as sensitive and limits processing to what is required to provide the requested athlete service.
Montis does not sell athlete health or training data and does not use those data for advertising.
05 · Authentication
OAuth and server-side credentials
Access to protected Intervals.icu data is authorised through supported account-connection and OAuth mechanisms.
- You explicitly authorise the relevant Intervals.icu connection.
- Montis does not receive your Intervals.icu password through OAuth.
- Intervals access and refresh credentials are held server-side and are not intentionally exposed to an AI model or browser client.
- Browser, GPT and MCP clients use separate authentication mechanisms which resolve to the authorised athlete connection.
- Access may be revoked or disconnected using available account controls.
Disconnecting the Intervals.icu account prevents Montis from continuing to retrieve protected athlete data through that connection.
06 · Data retained by Montis
Montis does not maintain a persistent athlete training-history database.
Athlete activity, wellness, physiological, calendar and report data retrieved from Intervals.icu is processed as required for the requested Montis tool, report or action and is not retained by Montis as a permanent copy of the athlete's training history.
Montis does retain a limited amount of operational and account-related information required to provide, secure and operate the Service.
This may include:
- Account identifiers, such as email address and Intervals.icu athlete ID.
- Subscription and supporter information, including membership status, level and entitlement dates.
- Notification settings and device registrations required to deliver notifications that the user has explicitly enabled.
- Temporary webhook and update-processing data, including athlete ID, event type, timestamps, resource identifiers, processing state and the relevant Intervals.icu activity or wellness webhook payload. This is stored only for eligible Montis Supporters and Subscribers to process new updates.
- Operational tool metadata, such as requested tool, client, request identifier, report type and execution status.
- User-configured Montis settings, such as personal directives where that feature is used.
Successfully processed Intervals.icu webhook payloads are automatically removed after a short operational retention period and are not maintained as an athlete-history archive.
These records support authentication, subscriptions, notifications, update processing, troubleshooting and operation of the Service. They are not intended to form a duplicate repository of the athlete's complete Intervals.icu training and wellness history.
07 · Analytics processing
Training and wellness data is processed on demand.
When a Montis tool, report or action is requested, the required athlete data is retrieved from Intervals.icu and processed within the Montis execution environment.
This may include activities, workouts, wellness information, HRV, sleep, power, heart rate, calendar data, athlete profile information and other authorised Intervals.icu fields.
Processing may generate derived metrics, forecasts, coaching states, performance-intelligence outputs and semantic report data.
Temporary working data exists only for the period required to execute the requested operation.
Montis does not retain complete athlete datasets, training-history datasets or generated report datasets as persistent athlete records after the requested processing has completed.
For eligible Supporters and Subscribers, Intervals.icu activity and wellness webhook payloads may remain temporarily in operational storage while update processing completes. Successfully processed webhook payloads are automatically cleaned up after the configured short retention period, normally within approximately 24–48 hours depending on the cleanup schedule.
08 · AI and LLM processing
AI clients receive only the data required for the requested interaction.
Montis can be used through AI systems such as ChatGPT, Claude, Gemini and other supported clients.
Depending on the tool you request, an AI client may receive:
- pre-computed Montis semantic report output;
- structured performance or wellness information;
- authorised activity information;
- calendar or event information;
- athlete profile context; or
- other tool-specific data needed to answer your request.
Montis does not intentionally disclose Intervals.icu OAuth access or refresh tokens to the language model.
Numerical metrics produced by the Montis reporting pipeline are computed server-side. The LLM may explain or interpret those outputs, but the LLM may itself produce inaccurate language or conclusions.
Your chosen AI provider may separately retain or process conversation content according to your account settings and that provider's own privacy policy.
09 · Notifications
Push notifications are optional.
Supported Montis applications may offer push notifications for events such as newly uploaded activities or wellness updates.
Notifications are enabled separately on each supported device.
When notifications are enabled, Montis may retain the technical subscription or device information necessary to deliver them.
Notification permission can be withdrawn using the Montis notification settings and/or the notification controls provided by your browser or operating system.
10 · Coaches and shared athletes
Only access athlete data you are authorised to view.
Some Montis functionality supports athletes whose Intervals.icu data has been legitimately shared with a coach or other authorised user.
The person using Montis is responsible for ensuring that they have permission to access the athlete information concerned.
Montis processes the selected athlete's information only within the permissions available through the connected Intervals.icu account.
11 · Cookies and browser storage
Essential session technology only.
The Montis web application uses an essential secure session mechanism to maintain authenticated application state.
-
Essential session cookie:
montis_sessionis used to maintain authenticated browser-session state. - Montis does not use this cookie for behavioural advertising.
- Montis does not use third-party advertising cookies.
- Montis does not create advertising profiles from athlete activity.
Technical browser storage may also be used where necessary for application functionality, interface preferences or push-notification support.
12 · Security and operational data
Limited technical data is processed to operate the Service.
Like most internet services, Montis infrastructure can process technical request information needed for security, reliability and troubleshooting.
This can include:
- request timestamps;
- requested endpoints;
- authentication outcome;
- service or error status;
- technical client information;
- IP/network information processed by infrastructure providers; and
- security and rate-limit events.
Such data is used for operation, debugging, security and abuse prevention rather than athlete profiling or advertising.
13 · Why data is processed
Processing is limited to defined service purposes.
Montis processes personal data where necessary to:
- connect authorised athlete accounts;
- retrieve requested athlete information;
- produce reports and analytics;
- provide coaching and planning functionality;
- perform authorised calendar or workout operations;
- provide notifications requested by the user;
- manage subscription eligibility;
- authenticate users and clients;
- secure the Service;
- prevent abuse;
- diagnose failures; and
- maintain service reliability.
Athlete data is not processed by Montis for targeted advertising.
14 · External providers
Who may process data
Montis relies on specialised external services to provide parts of the platform.
Depending on the features you use, recipients or processors may include:
- Intervals.icu — athlete-data source and connected calendar/training platform.
- Cloudflare — public web delivery, edge routing, authentication, security and related infrastructure.
- Railway — backend execution and Montis report processing.
- OpenAI — where Montis is used through ChatGPT or another OpenAI-powered client.
- Anthropic — where Montis is used through Claude.
- Google — where Google/Gemini or supported notification infrastructure is involved.
- Payment or membership providers — where required to validate paid or supporter access.
Each independent third-party service may also process information under its own privacy policy and contractual relationship with you.
15 · International processing
Data may be processed outside Switzerland.
Montis uses international cloud and AI providers. Depending on the service, account configuration and infrastructure location, personal data may therefore be processed outside Switzerland.
This may include countries in the European Economic Area and other jurisdictions in which the relevant infrastructure or AI provider operates.
Where required, international transfers are subject to the safeguards required by applicable Swiss data-protection law or other applicable data-protection legislation.
16 · Retention
Different service data has different lifetimes.
Montis aims to retain personal data only for as long as required for the purpose for which it is processed.
- Report working data is normally limited to the processing context required to execute the request.
- Session and authentication records are retained while needed to maintain or secure the connection.
- OAuth connection information is retained while the athlete connection remains active or until it is revoked or deleted.
- Notification subscriptions are retained while the relevant device subscription remains enabled or valid.
- Subscription/supporter state may be retained for the period necessary to administer the relevant entitlement and related records.
- Operational and security records may be retained for a limited period necessary for troubleshooting, security and abuse prevention.
Where an external service independently retains data, that provider's retention rules also apply.
17 · Security
Technical and organisational safeguards
Montis uses technical and organisational measures intended to protect personal information and connected-account credentials.
These include, where applicable:
- encrypted HTTPS transport;
- OAuth-based account authorisation;
- server-side credential handling;
- separation between client authentication and athlete credentials;
- restricted access to protected endpoints;
- encrypted platform secrets;
- security and abuse controls at the edge; and
- operational monitoring.
No internet-connected service can guarantee absolute security.
18 · Your privacy rights
Swiss FADP and GDPR where applicable
Depending on the law applicable to you and the processing concerned, you may have rights relating to your personal data, including rights to:
- request information about personal data Montis processes about you;
- request correction of inaccurate personal data;
- request deletion where applicable;
- object to or restrict certain processing where applicable;
- request data portability where a corresponding legal right applies;
- withdraw consent where processing depends on consent; and
- disconnect your Intervals.icu authorisation.
For personal data held directly by Intervals.icu, your AI provider or another independent platform, you may also need to exercise your rights directly with that provider.
A request concerning Montis-held data may be submitted using the privacy contact details below.
19 · Automated analysis
Montis computes coaching states, but the athlete remains the decision-maker.
Montis uses deterministic algorithms to derive performance metrics, forecasts, readiness context and coaching recommendations from athlete data.
These outputs support endurance-training decisions. They do not make legally binding or similarly significant decisions about employment, insurance, credit, healthcare entitlement or other legal rights.
The athlete or coach remains responsible for deciding whether to follow a training recommendation.
20 · Children and young athletes
Montis is primarily intended for adult endurance athletes.
Montis is not designed as a service directed specifically at children.
Where a minor's athlete data is accessed through a coaching or connected-account relationship, the person authorising that access is responsible for ensuring that they have the legal authority and any required consent to do so.
21 · Changes to this Policy
Privacy information will evolve with the Service.
This Policy may be updated when Montis functionality, data processing, integrations, infrastructure or legal obligations change.
The current version will be published on this page with its updated date.
Relevant architectural changes may also be described in the Changelog.
22 · Privacy contact
Questions or privacy requests
For questions concerning Montis data handling, privacy requests, data access or deletion enquiries, use the form below.
Montis.icu is operated by Clive King from the Canton of Vaud, Switzerland.