Privacy Policy

Last updated August 20, 2026.

Who is responsible for your data

Martin Ahlberger, a private individual resident in Sweden, is the data controller for ErgIntz. A controller does not have to be a company — GDPR Art. 4(7) defines one as “the natural or legal person” who decides why and how personal data is handled.

Contact: hello@tenelephants.app.

If ErgIntz is one day run by a company formed for the purpose, that company becomes the controller. We will say so here and on the site before it happens. The change does not by itself alter what we hold, why we hold it, or any of your rights over it.

The short version

  • You can use ErgIntz without an account. The app works with your erg and keeps everything on your phone. Nothing here applies until you sign in.
  • Your account is your email address, proved by a code we email you. There is no password anywhere in ErgIntz. A Concept2 Logbook is an optional connection you add afterwards, not your identity.
  • Results are shown next to names, by default. That is what the app is for. There are switches to turn it off, and one place — ErgIntz's own public workouts — where you are told before it happens and your agreement is recorded.
  • No advertising, no analytics SDK, no tracking. We do not sell your data and we never will.

What we hold, and why

If you have signed in

  • Your email address and the date it was verified. It is your account — there is no password and no other identifier.
  • Sign-in challenges. For each code you request: your address, the time, how many attempts — and hashes of the code and the link, never the code itself. Kept 24 hours.
  • Your Concept2 connection, only if you add one: your Concept2 user ID and username, and the tokens needed to sync.
  • Device tokens — one per signed-in device, stored only as a hash, with a label and when it was last used.
  • Your rowing profile — display name, a 5 km benchmark per erg, body weight, and gender if a Logbook is connected. The benchmark is what “% of 5k pace” targets resolve against; weight and gender derive your Logbook weight class.
  • Your preferences — pace or watts, appearance, and the four visibility switches.
  • Your workouts, and any you publish to share by link.
  • Your sessions — start and end time, the time zone you rowed in, distance, elapsed time, average and max heart rate, average power, calories, the effort you set, which erg, and the full stroke-by-stroke event stream from the PM5. That last one is most of what we store about you, and it is what makes splits, personal bests and FIT export work.
  • Logbook sync state — so we don't push a session twice and a failure can be retried.

If you are in a club

  • Which clubs you are in, your role, when you joined and when you left.
  • The message you wrote when asking to join.
  • Which club workouts you completed, and when you rowed them.
  • Entries in the club's admin log naming you — approved, declined, removed, promoted, left — so a member can ask “who removed me?” and get an answer.

If you run a club that is being billed

Billing contact name and email, the organisation's org.nr and invoice reference, and a Stripe customer id. No invoice has been issued — this is machinery, not history.

Data about people who do not have an account

A personal invite holds the name and email address a club admin addressed it to. A member's suggestion (“I think Calle should be in the club”) holds the suggested person's name, email address and a note about them, typed by somebody else. Both are deleted automatically after 30 days.

If you are that person and you did not ask to be here, email hello@tenelephants.app and we will remove the entry. You do not need an account to ask, and you should not have to make one.

The app's diagnostic log, if you switch it on

The app keeps a technical log of what it does with your erg — the Bluetooth connection, the workout it sends, what the PM5 answers. It is there because that is the only way anyone can work out why a workout would not load on a machine we cannot see.

It is off unless you turn it on, under Diagnostics in Settings — the exception is a test build handed out for testing on an erg, which starts with it on and says so on that same screen. Not every version of the app has that section; where it is absent, nothing is sent at all. Turning it off stops it immediately. While it is on, the log is sent to us with your account, an id for that installation of the app, and which build it is. It holds no heart rate, no e-mail address and no sign-in code: those are stripped on your phone before anything is sent, and stripped again when it reaches us. We keep it for 30 days.

What we do not collect

No advertising identifiers, no contacts, no location, no browsing activity, no third-party analytics or tracking SDKs, and no payment card details — a card is handled by Stripe and never reaches us.

Bluetooth

The app talks to your PM5 over Bluetooth to read your workout as you row it. That connection is between your phone and the erg. The data becomes ours only if you are signed in and the session syncs.

Why we are allowed to hold it

  • Performance of a contract — running your account, storing your workouts and sessions, and syncing to Concept2 when you ask. It is the service you asked for.
  • Consent — showing you on a club's boards (given by joining the club) and on ErgIntz's public boards (recorded the moment you first start one of our published workouts). Withdrawable in Settings.
  • Explicit consent — heart rate. Heart rate can say something about your health, so we treat it as special-category data (GDPR Article 9) and store it only after you have agreed in the app. Sessions synced before you agree carry no heart-rate data. Withdrawing is one switch: turn off Heart-rate data in Settings in the app, and that erases the heart rate already stored — here and on your phone — and stops new readings being recorded. Deleting a session or your account removes its heart rate too.
  • Legitimate interests — keeping an admin log, security, abuse handling, and keeping the service working.
  • Legal obligation — payment records, which Swedish bokföringslagen requires us to keep for seven years.

Who can see what

Other members of your clubs see your display name, your position on the club's result boards, and whether you turned up on its participation boards. Club admins additionally see the club's admin log, which names members.

Everyone, including people with no account, can see the boards for ErgIntz's own published workouts, a workout you choose to share by link, and any club's picture and colour.

Leaving a club does not remove your past results from its boards. You are marked a former member. The switches in Settings are what take you off — and they cover every club you are in, not one.

Your own sessions, history and personal bests are yours alone. No club admin can see the detail of a session you rowed — only the result that landed on a board.

Who else we give it to

We do not sell your data and we do not share it with advertisers. It reaches these parties, and no others. We have a data-processing agreement in place with each company that processes data on our behalf — Resend, Fly.io, Cloudflare, and (once paid club plans go live) Stripe. Concept2 and Apple are different: they are independent controllers, handling what reaches them under their own privacy policies and their own legal basis, so there is no data-processing agreement with either.

  • Resend — your email address, each time you ask for a sign-in code, so the code can be delivered.
  • Fly.io — everything, as the host. ErgIntz runs in Stockholm.
  • Cloudflare R2 — a continuously replicated backup of the database, in a bucket restricted to the European Union, so it does not leave the EU.
  • Concept2 — only if you connect a Logbook: your connection, and any session you push. Governed by Concept2's own privacy policy — and if you have connected Garmin Connect or Strava on the Concept2 side, Concept2 forwards your results on to them as well.
  • Stripe — billing contact details for a paying club.
  • Apple — app distribution.

Where these companies are. Resend, Fly.io, Cloudflare and Stripe are US companies. Your data is stored in the EU — the app and database run in Stockholm, and the backup bucket is restricted to the EU — but sending a sign-in email through Resend routes your address through US infrastructure. Where personal data reaches the US like this, the transfer is covered by the company's certification under the EU–US Data Privacy Framework or by the European Commission's standard contractual clauses (and in several cases both), which are the safeguards EU law recognises for sending personal data to the US.

Where it is stored

On servers in Stockholm, Sweden, with a continuously replicated backup in Cloudflare R2.

How long we keep it

  • Your sessions, workouts and profile — until you delete them or ask us to erase your account. There is no automatic expiry.
  • Your results on a club's boards — for as long as the club exists, including after you leave, unless you use the switches in Settings.
  • Sign-in codes — 24 hours. The code itself expires in 15 minutes, and only its hash is ever stored.
  • Admin log entries — 400 days.
  • The app's diagnostic log — 30 days, if you switched it on at all.
  • Contact details on a personal invite — cleared when the invite expires (30 days) or is withdrawn.
  • A suggestion about someone with no account — 30 days.
  • Payment records — seven years, as Swedish bookkeeping law requires. An erasure request does not override this.
  • Concept2 connection tokens — until you disconnect, revoke the device, revoke ErgIntz from Concept2, or are erased.

Your rights

Under GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to someone else. You can withdraw consent at any time. Email hello@tenelephants.app.

Things you can do yourself, right now, without asking:

  • change your display name, 5 km benchmarks and weight, in Settings;
  • turn the four visibility switches on or off;
  • delete an individual session, from its own page;
  • revoke any device's access;
  • disconnect your Concept2 Logbook, here or from Concept2;
  • leave a club.

What an erasure actually does

Worth setting out, because it is not “everything vanishes”.

Destroyed: your sessions and their full stroke data, your workouts, your club memberships and completions, your join requests, suggestions you made about other people, workouts you published to share, invites you created, every token, and every sign-in code ever issued to your address — including from before you finished signing up. Also your contact details wherever somebody else typed them: a suggestion naming you, an invite addressed to you, a club billing contact that is you.

Kept, with you removed from them: admin log entries (the entry stays, your name comes out, and the sentence is rewritten to a general one — an audit trail that disappeared with its subject would evidence nothing); a workout you shared into a club (it is the club's — deleting it would delete every other member's results against it); and payment records, for seven years, by law.

Refused until you fix it first: if you still own a club, we will not erase you. A club holds other people's data. Transfer it or wind it up, then ask again.

It is irreversible. There is no undo and no backup we will restore you from.

Complaints

If you think we have handled your data wrongly, please tell us first. You also have the right to complain to Integritetsskyddsmyndigheten (IMY)imy.se — or to the equivalent authority in the EU country you live in.

Cookies

A handful, all strictly necessary, none shared with anyone: a session cookie that keeps you signed in, a theme cookie remembering light or dark, and three short-lived ones that carry a sign-in, a club invite, or the Concept2 handshake safely between pages. No analytics cookies, no advertising cookies, no third-party cookies.

Children

You must be at least 13 to have an ErgIntz account. ErgIntz is not directed at children under 13 and we do not knowingly hold data about them. If we learn that an account belongs to someone under 13, we will close it and delete what it holds.

Changes

We may update this policy. The date at the top says when it last changed; if a change is material we will say so on the site and email you.

Contact

hello@tenelephants.app

See also our Terms of Service.