Document details
- Product
- TerraFlo
- Publisher
- Hidden Mesa Labs, LLC
- Privacy Contact
- privacy@terraflo.fit
- Effective Date
- June 15, 2026
- Last Updated
- July 30, 2026
1. Introduction
TerraFlo (“the App,” “we,” “us,” or “our”) is a fitness application published by Hidden Mesa Labs, LLC, a Colorado limited liability company. TerraFlo enables users to record and share workout sessions, analyze GPS-linked telemetry from motion-capable fitness equipment, and engage with a community of fitness creators.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over your data. It applies to TerraFlo for iOS, macOS, tvOS, watchOS, Android, Wear OS, Windows, the TerraFlo account portal, the TerraFlo marketing site, and any web-based administrative interfaces operated by Hidden Mesa Labs, LLC.
If you do not agree with this policy, do not use the App.
2. Who This Policy Covers
This policy applies to:
- End users who create an account, record workouts, or engage with community content.
- Creator users who upload workout videos or GPS-linked content.
- Visitors who interact with any web interface operated by Hidden Mesa Labs, LLC in connection with TerraFlo.
TerraFlo is intended for users who are 18 years of age or older. See Section 12 for details.
3. Information We Collect
We collect only the information necessary to operate TerraFlo’s stated features. The categories below describe what we collect and how.
3.1 Account and Identity Information
When you create a TerraFlo account via Apple Sign-In, Google Sign-In, or email/password through Firebase Authentication, we receive and store:
- Display name — provided by you or imported from your chosen identity provider (Apple or Google).
- Email address — used for account identification, login, and service communications.
- Profile photo URL — a reference to a photo hosted by your identity provider, if you choose to share one.
- Firebase UID — a unique opaque identifier assigned by Firebase Authentication; it never contains your name or email in cleartext.
- Account role — an internal designation (e.g., standard user, creator) that controls feature access.
- Account status flags — whether your account is active, suspended, or subject to any restriction.
We do not receive your Apple ID password or Google account password. Authentication is handled entirely by Apple and Google’s identity services, respectively; we receive only a signed assertion token.
3.2 Activity and Workout Data
When you start or save a workout session in TerraFlo, we collect:
- Route data — latitude, longitude, elevation, and relative timestamp points from the workout route or from GPS metadata embedded in creator-uploaded files. TerraFlo does not continuously track your device location in the background.
- Telemetry data — heart rate, speed, cadence, power, grade, incline, resistance, and similar values transmitted from paired Bluetooth Low Energy (BLE), Apple Watch, Wear OS, or fitness-equipment sources during the active session.
- Session metadata — start and end timestamps, duration, and any user-supplied title or notes.
GPS and telemetry data are stored in Google Cloud Firestore (session metadata) and Google Cloud Storage (detailed telemetry JSON payloads), both within the Firebase project operated on behalf of Hidden Mesa Labs, LLC.
3.3 Creator-Uploaded Video Content
If you are a TerraFlo creator, you may upload workout videos. Uploaded videos:
- Are stored in Google Cloud Storage and may be processed through Bunny Stream / Bunny CDN for playback.
- May contain embedded GPS telemetry (e.g., GoPro GPMF metadata) that TerraFlo parses and indexes.
- Are associated with your account UID in Firestore metadata records.
The GPS data extracted from creator videos is treated as workout/location data under this policy. When a creator publishes a route, TerraFlo minimizes public route exposure by rounding public start locations and requiring sign-in before exact route telemetry is accessible.
3.4 Social and Engagement Data
TerraFlo supports community interaction. We record:
- Likes, favorites, and “gratz” reactions on sessions or videos, associated with your UID.
- Comments you post, including their text content and timestamp.
- Follow/follower relationships — which accounts you follow and which accounts follow you (stored as UID references, not email or name).
- Leaderboard entries — aggregate performance data used to compute relative rankings.
3.5 Third-Party Integration Data (Strava)
If you connect your Strava account to TerraFlo:
- We store OAuth tokens server-side in a private user record sufficient to upload workout summaries to Strava on your behalf.
- We do not store your Strava password.
- You can revoke this connection at any time from within the App or from Strava’s connected-apps settings. Upon revocation, we delete the stored tokens.
3.6 Apple HealthKit, Apple Watch, Health Connect, and Wear OS — Opt-In Only
TerraFlo requests HealthKit (iOS/macOS/watchOS), Apple Watch heart-rate bridge, Health Connect (Android), or Wear OS Health Services permission only when you explicitly enable a workout or save/sync workflow that needs it. If you enable it:
- On iOS, macOS, and watchOS (HealthKit): We may read limited heart-rate or workout records when the platform requires that access for workout status, heart-rate display, duplicate detection, or a connected Apple Watch session. We may write completed TerraFlo workout summaries, distance, speed, and heart-rate samples back to your HealthKit store.
- On Android (Health Connect and Wear OS): TerraFlo writes completed workout summaries, exercise records, heart rate, distance, and speed to Health Connect. TerraFlo does not read data from Health Connect.
- Health platform data is processed on-device except when a workout session, diagnostic report, or explicit export/share action sends selected workout telemetry to TerraFlo servers.
- We do not use HealthKit or Health Connect data for advertising or for sale to third parties, and we comply with Apple’s HealthKit data-use restrictions.
3.7 BLE Device Diagnostics
When TerraFlo performs Bluetooth device capability profiling, it may send device model, firmware, advertised-service, capability, control-range, and test-result data to our servers. Community device profiles are organized by device model/fingerprint so they can improve compatibility for everyone. Submissions and diagnostics may also be associated with your account for moderation, abuse prevention, and support follow-up.
3.8 AI Discovery Sessions
TerraFlo’s device-profiling feature may use an AI-assisted discovery flow. Conversation transcripts from this flow are intended to contain device capability data, not health data. They may be associated with your account for access control, rate limiting, troubleshooting, and audit logging. These transcripts are retained for a limited period under TerraFlo’s privacy-retention process.
3.9 On-Device Logs
TerraFlo writes diagnostic logs to the app’s private local storage. These logs may include event descriptions, error codes, device state, playback state, and recent telemetry summaries. Logs are not automatically transmitted for normal app use. If you submit a diagnostic report, TerraFlo uploads selected logs, optional screenshots, report comments, app/device metadata, and recent telemetry after client/server redaction removes auth tokens, signed URLs, raw BLE identifiers where possible, local file paths, and exact route coordinates from diagnostic telemetry.
3.9a Push Notification Tokens (Android)
On Android devices, TerraFlo stores a Firebase Cloud Messaging (FCM) device token in your account record. This token is used to deliver service notifications to your device. It is not shared with advertisers or third-party marketers. If you uninstall the App or delete your account, this token is removed.
3.9b Marketing Website Analytics (Google Analytics)
Our marketing website (terraflo.fit) uses Google Analytics 4, a service of Google LLC, to help us understand which pages visitors find useful — for example, which routes, guides, and product pages are read most, and whether visitors complete beta registration. We configure Google Analytics with advertising features disabled: we do not use it for ad targeting or ad personalization, we do not sell personal information, and Google Analytics 4 does not log or store IP addresses.
If you visit from a region that requires consent for analytics cookies (including the EEA, the United Kingdom, and Switzerland), analytics is off by default and runs only if you choose “Allow analytics” in the notice shown on your first visit. You can decline without losing any site functionality. Your choice is stored on your device; clearing your browser storage resets it.
Analytics applies to the marketing website only. It is separate from the TerraFlo App’s account, workout, and health data practices described elsewhere in this policy.
3.10 Information We Do Not Collect
We do not collect or use:
- Advertising identifiers (IDFA or Android Advertising ID).
- Third-party analytics SDKs or trackers in the mobile applications (our marketing website uses Google Analytics as described in Section 3.9b).
- Persistent cross-site or cross-app tracking cookies in the mobile applications.
- Precise background location or continuous device-location tracking.
- Your contacts, calendar, microphone, or camera data.
4. How We Collect Information
| Source | Collection method |
|---|---|
| Apple Sign-In | You initiate; Apple passes a signed identity token to Firebase Authentication. |
| Google Sign-In | You initiate; Google passes a signed identity token to Firebase Authentication. |
| Email/password | You provide credentials directly; Firebase Authentication manages hashing and storage. |
| Workout recording | Active user-initiated session; GPS and BLE telemetry are captured only while the session is running. |
| Video upload | Creator action; you explicitly select and upload a file. |
| Strava OAuth | You initiate the connection; we receive tokens after you authorize on Strava’s website. |
| HealthKit / Apple Watch / Health Connect / Wear OS | You explicitly grant permission in the system prompt or start a connected-watch workout. |
| Social actions | Generated as you use the App (likes, comments, follows). |
| BLE device profiling | Occurs during device setup; device model/capability data and account-linked submission metadata may be sent. |
5. Why We Collect and Use Information (Purposes)
We use the information we collect for the following purposes only. We do not use your data for purposes not listed here.
| Purpose | Data used | Legal basis (GDPR reference) |
|---|---|---|
| Providing the App — account creation, login, session display | Account info, UID | Contract performance |
| Recording and storing your workouts | GPS route, telemetry, session metadata | Contract performance |
| Enabling creator video uploads and community sharing | Video files, extracted GPS, creator metadata | Contract performance |
| Social features — likes, comments, follows, leaderboards | Engagement data | Contract performance / Legitimate interest |
| Syncing workouts to Strava | OAuth tokens, workout summaries | Consent (user-initiated OAuth) |
| Syncing with HealthKit / Health Connect | Health store read/write | Consent (explicit system permission) |
| Improving BLE device compatibility | Device capability data (non-PII) | Legitimate interest |
| Responding to support requests and diagnostic reports | Report comments, logs, screenshots, redacted telemetry, device/app metadata | Legitimate interest |
| Legal compliance and fraud prevention | Account info as needed | Legal obligation / Legitimate interest |
We do not sell your personal information. We do not use your workout data, GPS data, or health data to serve advertisements.
6. How Long We Retain Your Information
| Data category | Retention period |
|---|---|
| Account profile | Retained while your account is active; deleted within 30 days of account deletion request processing (following a 7-day cancellation grace window). |
| Workout sessions and telemetry | Retained while your account is active; deleted with your account or upon explicit deletion request. |
| Creator video content | Retained while the video is published or until the creator deletes it. Deleted with the account if the creator deletes their account. |
| Social engagement data (likes, comments, follows) | Retained while the associated content and accounts exist. Deleted comments may be replaced with a generic deleted-account placeholder if the comment was part of a thread. |
| Strava OAuth tokens | Deleted promptly upon integration disconnect or account deletion. |
| BLE device diagnostic data | Retained for up to 90 days; subject to earlier deletion upon account deletion. |
| AI discovery transcripts | Deleted after 30 days unless retained longer for an active abuse or security investigation. |
| Problem reports and attached blobs | Retained for up to 90 days, with a minimum 30-day floor; retained longer if required for an active support or security investigation. |
| Support correspondence | Retained for up to 30 days after issue resolution, then deleted. |
| Android push notification token (FCM) | Retained while account is active; deleted upon account deletion or App uninstallation. |
| On-device logs | Stored locally on your device; not retained on our servers unless you submit a diagnostic report or otherwise transmit them to support. |
| Marketing-website analytics events (Google Analytics) | Retained by Google Analytics for 14 months, then deleted automatically. |
We do not retain personal information beyond the periods described above unless required by law.
7. With Whom We Share Your Information
We share your information only as described below. We do not sell personal information to data brokers or advertisers.
7.1 Google (Firebase / Google Cloud)
We use Google Firebase services — Firebase Authentication, Cloud Firestore, and Cloud Storage — as our primary data infrastructure. Google processes data on our behalf as a data processor under Google’s Cloud Data Processing Addendum. Data is stored in the United States by default. For Firebase’s current data residency options, see Google’s Firebase documentation. Our marketing website also uses Google Analytics 4 as described in Section 3.9b; Google processes that data on our behalf under the Google Ads Data Processing Terms, which we have accepted.
7.2 Apple
If you sign in with Apple Sign-In, Apple’s identity services process your login credential. Apple’s handling of your Apple ID is governed by Apple’s Privacy Policy, not this policy.
7.3 Strava
If you connect Strava, we transmit your workout summary data (distance, duration, route, activity type, and optional heart-rate samples when included in your export) to Strava via their API using your authorized OAuth token. Strava’s handling of received data is governed by Strava’s Privacy Policy.
7.4 Apple HealthKit (iOS/macOS) and Health Connect (Android)
If you enable the HealthKit, Apple Watch, Health Connect, or Wear OS integration, data is exchanged with your device’s health platform per your permissions. These platform providers have their own privacy policies governing health data.
7.5 Legal Process
We will disclose your information if required to do so by a valid court order, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to prevent imminent harm, fraud, or illegal activity. We will attempt to notify you of such requests where legally permitted.
7.6 Business Transfers
If Hidden Mesa Labs, LLC is acquired, merges with another company, or transfers substantially all of its assets, your information may be transferred as part of that transaction. We will notify you via the App or your registered email address before such a transfer, and we will require any successor to honor the commitments in this policy or provide you an opportunity to delete your account.
7.7 Aggregated, Non-Identifiable Data
We may share aggregate, de-identified statistics (e.g., “average workout duration by activity type”) that cannot reasonably be linked to any individual. This does not constitute sharing personal information.
8. International Data Transfers
TerraFlo is operated from the United States and currently targets users in the United States. If you access TerraFlo from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
EU / EEA users: TerraFlo is not currently marketed in the European Union or European Economic Area. If Hidden Mesa Labs, LLC makes TerraFlo available in the EU in the future, it will implement appropriate transfer mechanisms (such as Standard Contractual Clauses) before processing EU residents’ data, and will appoint a Data Protection Officer or EU representative as required by GDPR Articles 27 and 37–39. This section will be updated before any EU launch.
9. Your Privacy Rights
9.1 General Rights (All Users)
You may, at any time:
- Access the personal information we hold about you by submitting a request to privacy@terraflo.fit.
- Correct inaccurate profile information directly within the App settings, or by contacting privacy@terraflo.fit.
- Delete your account and associated personal data. Account deletion is initiated from within the App or from the account portal at terraflo.fit/account/privacy. We will process the deletion within 30 days. Some aggregated or anonymized data derived from your account may not be deletable if it has been incorporated into aggregate statistics.
- Export / Portability — you may request a copy of your workout data in a portable format by contacting privacy@terraflo.fit.
- Opt out of optional integrations (Strava, HealthKit, Health Connect) at any time from within the App.
9.2 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for which it was collected, and the categories of third parties with whom it has been shared.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions permitted by law.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. No opt-out mechanism is required for this activity at this time because we do not engage in it.
- Right to Limit Use of Sensitive Personal Information: Location data collected during workouts and health-related telemetry (heart rate, cadence) may constitute “sensitive personal information” under CPRA. We use this data only to provide the features you explicitly activate. You may disable GPS recording or BLE telemetry within the App at any time.
- Right to Non-Discrimination: We will not discriminate against you for exercising your California privacy rights.
To exercise any of these rights, contact us at privacy@terraflo.fit or at the mailing address in Section 14. We will respond within 45 days, or notify you if we require an extension.
We do not knowingly sell the personal information of any user.
9.3 Colorado Residents (Colorado Privacy Act — CPA)
If you are a Colorado resident, you have rights under the Colorado Privacy Act, including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of the sale of personal data and of targeted advertising. TerraFlo does not sell personal data or conduct targeted advertising. To exercise your rights, contact privacy@terraflo.fit. We will respond within 45 days.
9.4 EU / EEA Residents (GDPR)
TerraFlo is not currently available in the EU/EEA. If it becomes available:
- You will have rights of access, rectification, erasure, restriction of processing, portability, and objection.
- We will identify an appropriate legal basis for each processing activity (see Section 5).
- You will have the right to lodge a complaint with your local supervisory authority.
- We will appoint a Data Protection Officer or EU representative as required by GDPR.
This section is included to ensure that no design decision in the current policy precludes GDPR compliance at launch.
10. Security
We implement the following measures to protect your information:
- Encryption in transit: All communications between the App and Firebase/Google Cloud services use TLS.
- Encryption at rest: Firebase Cloud Firestore and Cloud Storage encrypt data at rest by default using Google-managed encryption keys.
- Authentication: Firebase Authentication manages credential storage and hashing. We do not store passwords in cleartext.
- Access controls: Firebase Security Rules restrict read/write access to user data. Only authenticated users may access their own account data.
- Diagnostic sanitization: Client and server redaction remove common secrets, signed URLs, local file paths, raw BLE identifiers, and exact diagnostic route coordinates before problem-report storage.
- Local data protection: Sensitive local caches, diagnostics, upload state, and route/video cache metadata are excluded from OS backup where supported.
We do not represent that our security measures are infallible. No system is completely secure. If you believe your account has been compromised, contact privacy@terraflo.fit immediately.
In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
11. Third-Party Links and Services
TerraFlo does not display third-party advertisements. The App may contain links to Strava or other third-party platforms. When you follow such a link or initiate a third-party integration, you are subject to that platform’s privacy policy. We are not responsible for the privacy practices of third parties.
12. Age Requirement
TerraFlo is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a user under 18, we will delete it promptly and terminate the associated account. If you believe someone under 18 has created a TerraFlo account, please contact privacy@terraflo.fit.
13. Apple App Store and Google Play Store Disclosures
The following categories of data are collected by TerraFlo, as required by App Store privacy nutrition label and Google Play data safety section disclosures:
| Data type | Collected? | Linked to identity? | Used for tracking? |
|---|---|---|---|
| Email address | Yes | Yes | No |
| Name / display name | Yes | Yes | No |
| Profile photo | Reference URL only | Yes | No |
| Precise location / route data | Yes, from workout routes and uploaded route videos | Yes | No |
| Health & fitness data (heart rate, cadence, power, speed, grade, workout summaries) | Yes, during active sessions and optional health-platform sync | Yes | No |
| User-generated content (comments, videos, report comments, optional screenshots) | Yes | Yes | No |
| Identifiers (Firebase UID) | Yes | Yes | No |
| Product interaction (likes, follows, ratings, leaderboard entries, subscription usage) | Yes | Yes | No |
| Crash / diagnostic data | Yes, only when you submit a report or crash prompt | Yes | No |
| Payment information | Not collected directly; handled by App Store / Play Store billing | N/A | No |
| Device identifiers / push tokens | Android FCM token only; no advertising identifiers | Yes | No |
TerraFlo does not use any data for tracking you across apps or websites owned by other companies.
14. Contact
For privacy-related questions, requests to exercise your rights, or data breach reports:
Hidden Mesa Labs, LLC Attn: Privacy
200 S Wilcox St
#606
Castle Rock, Colorado 80104
United States
We aim to acknowledge all privacy requests within 5 business days and to resolve them within 45 days.
15. Changes to This Policy
We will update this policy when our data practices change. For material changes, we will notify you via an in-app notice or by email to your registered address at least 30 days before the change takes effect (where required by law). The “Last Updated” date at the top of this document will always reflect the most recent revision. Continued use of TerraFlo after the effective date of a change constitutes acceptance of the revised policy.
© 2026 Hidden Mesa Labs, LLC. All rights reserved.