val

Privacy

Last updated 17 August 2026. This describes the app as it is built today, not as it is planned.

The short version

Who this covers

Oval is a workout timer for running coaches. The coach is the user. Athletes never sign in and never have an Oval account.

Coaches enter details about their athletes, and those athletes are often under 18. Everything below is written with that in mind. If you are a coach at a school, read Schools and districts as well.

What is on your device

Your roster and your training history are stored on the device you use Oval on. Oval does not upload them and has no way to read them. The one time they move is if you invite an assistant coach and pair your devices; that is described further down, and it is still scrambled so that we cannot read it. This covers:

On the iPhone and Android apps, Oval also writes a second copy into the app's own storage, so a browser storage clear cannot wipe a season's work. That copy is eligible for the device backup you may already have switched on — iCloud on an iPhone, Google on an Android phone. The backup goes to your own Apple or Google account, never to Oval, and each company encrypts it with your device passcode, so neither they nor we can read it. Turn off backup for Oval in your phone's settings if you would rather it did not.

Deleting the app deletes this data from the phone. A backup copy can outlive the app. If you had backup switched on, the last backup stays in your Apple or Google account after you uninstall, and reinstalling Oval can bring your roster back. To remove that copy as well, delete Oval's backup in your account settings, or turn backup off for Oval before you uninstall.

That copy is yours, not ours. There is no copy for us to return, and none for us to delete on your behalf.

When you send a workout to an athlete

After a session you can send each athlete a link to their own results, which they can upload to Strava. Two things happen.

The link

Oval stores that athlete's lap times, plus the outline of the track you timed on, under a random eight-character code on a Cloudflare server. The athlete's name is not included — the field is deliberately sent empty. Anyone holding the code can read the times, which is why the code is random and why the link is not listed anywhere. Oval deletes the stored workout after 180 days.

The server also counts how many times you emailed each link, to stop one link being used to send unlimited mail.

The email

Oval passes the athlete's email address, the link code and your team name to Brevo, the company that delivers the mail. Oval does not store the address. Brevo holds it in its delivery logs for a limited period, as any mail provider does.

If an address permanently fails, or a recipient reports the mail as spam, Oval records a one-way scrambled form of that address so it never mails it again. That record cannot be turned back into an email address without a secret key, and it is kept until you ask us to remove it.

If you have no signal, Oval falls back to opening your own mail app instead. In that case the message never touches Oval's servers at all.

When you sign in

A coach account is optional and the app works fully without one. If you create one, Oval uses Supabase to hold your email address and to sign you in by emailed link. No password is ever typed into Oval or stored by it.

Signed in, Oval also syncs, tied to your account:

An assistant coach on your staff can see your name and your team details, because that is the team they have joined. Nobody else can, and it stops the moment you remove them.

Which season you are in, and which athletes and workouts belong to it, stay on your own device. That is filing, and filing an athlete would mean naming one.

Signing in does not upload your roster. No athlete name, address, record or result is sent because you have an account. The only thing that moves roster data is pairing with an assistant coach, below, and you have to set that up yourself.

Coaching with someone else

A head coach can invite an assistant coach. The invitation is an email with a link; Oval holds the assistant's name and address to send it, and forgets the address once they accept. The record that the two of you coach together stays on Oval's server, so that a head coach can end it at any time and have that stick.

Athletes and workouts are not kept on Oval's server. When you pair two devices, the data is scrambled on the sending device and only unscrambled on the receiving one. The key is passed between the two devices — by a code you read out, or a square you scan — and never reaches us. What passes through our server is therefore a block of characters we cannot read, and it is deleted as soon as the other device has collected it.

We can still see that two coaches are linked, and how large and how frequent the messages between them are. We cannot see what is in them.

Nothing moves without both sides acting: after the first handover, each of you reviews the other's changes athlete by athlete and workout by workout before anything lands.

Removing an assistant coach stops any further sync — our server refuses it from that moment, whether or not their phone is switched on. It cannot reach back and erase what they already received, and we will not pretend otherwise. Their app offers to delete what came from you; that is their choice to make.

Finding a track

When you search for the track you are standing on, Oval asks your device for its location and sends those coordinates to public map services — OpenStreetMap and Overpass for the track's shape and name, and Carto and Esri for the map and satellite images you see. Those companies receive your approximate location as part of serving the request. Oval asks for your location only when you use this feature, and you can refuse.

This is your location as the coach. Athletes' locations are never involved.

Product analytics

On the web version, Oval may record which screens are used and how long they are open, using PostHog. Only named events with simple values are sent. Automatic capture, page recording and session replay are all switched off, so no athlete name, address or workout text can be picked up. Analytics are switched off entirely in the iPhone and Android apps.

Strava

Uploading to Strava happens on the athlete's own device, in the athlete's own Strava account, after they approve it. The coach never sees the athlete's Strava login, and Oval does not keep it. Oval passes the workout file through to Strava and keeps no copy.

Companies that handle data for Oval

CompanyWhat it handles
CloudflareStores workout links: lap times and a track outline, under a random code. No names.
BrevoDelivers workout emails. Receives the athlete's address.
SupabaseCoach sign-in, saved tracks and track corrections. No athlete data.
VercelServes the website and the app.
PostHogScreen-usage statistics on the web version only.
OpenStreetMap, Overpass, Carto, EsriMap data and imagery. Receive the coach's approximate location during a track search.
StravaReceives a workout file, on the athlete's own instruction, into the athlete's own account.

What Oval never does

Schools and districts

Where a school is the party responsible for its students' records, Oval acts on the coach's instruction and holds no student records of its own. The design reason is above: the roster does not leave the device, and the workout link carries no name.

The one place a student's own detail reaches a third party is the email address, when a coach chooses to send a workout by email. A coach who cannot share addresses with a mail provider should send the link another way, using the share option instead of the email option.

Oval does not knowingly let anyone under 18 create an account, because athletes have no accounts at all.

How to remove data

Changes

If what Oval collects changes, this page changes with it and the date at the top moves. The date is the honest record of when this was last checked against the code.

Contact

Questions, or a request to delete something: ggg@ovaltimer.com.