Privacy Policy
Effective date: October 1st, 2026 Entity: Complete Laboratories, Inc. Address: 650 W 42nd St., New York, NY 10036, USA Contact: support@completelabs.com
1) Scope & Who We Are
This Privacy Policy explains how Complete Laboratories, Inc. (“Complete,” “we,” “us,” or “our”) collects, uses, shares, and safeguards personal information when you use our mobile apps (iOS/Android), web app, APIs, and related services (the “Services”). This Policy applies worldwide. It is designed to comply with major privacy laws including the GDPR (EU/UK), CCPA/CPRA (California), and other U.S. state privacy laws (e.g., CO, CT, VA, UT), as well as other applicable laws in regions where we operate.
We provide Services to multiple user roles: Athletes, Coaches, Trainers, Guardians, and Organization Administrators (Org Admins).
2) Children & Minimum Age
The Services are intended for users aged 12 and above. For users under the age where parental consent is required (e.g., under 16 in the EU and under 13 in the U.S. (COPPA)), we obtain verifiable parental/guardian consent before collecting personal information. Guardians have visibility into the minor’s account as described in Section 11, and may manage consent and account controls. If we learn a child used the Services without required consent, we will delete the account and associated personal information as required by law.
3) Categories of Personal Information We Collect
Depending on role, features used, and permissions you grant, we may collect:
- Account & Identity Data: name, email, password hashes, phone number, profile photo; identity verification information (e.g., government ID snapshots or checks).
- Contact & Relationship Data: team affiliations, coach/athlete/guardian connections, organization membership.
- Device & Network Data: device identifiers, OS/browser type, IP address, app version, crash/diagnostic logs, and security telemetry.
- Usage & Activity Data: in-app actions, feature usage, preferences, and communications with support.
- Content You Provide: photos/videos (e.g., training, movement, or nutrition images), text notes, comments, uploaded files.
- Health, Fitness & Biometrics: with your permission, wearables and in-device sources (e.g., Apple Health, Google Fit, Whoop, Garmin, Catapult/other sensors) such as heart rate, sleep, steps, strain, training load, recovery indicators, and similar metrics.
- Location Data: approximate or precise location if you enable it (e.g., to tag workouts or for safety features).
- Contacts & Calendar (Optional): if you grant access, we may read selected contacts or calendar entries to facilitate invitations or scheduling.
- Financial & Transaction Data: billing details and limited payment metadata processed via Stripe (we do not store full card numbers).
- Communications: emails, push notifications, and in-app messages (content and metadata).
- Inferences: derived insights (e.g., performance trends) built from the data above.
We obtain data directly from you, from your devices/wearables (with permission), from organizations that provision accounts, and from service providers (e.g., analytics, security).
4) Purposes & Legal Bases (GDPR/UK GDPR)
We process personal information for:
- Service Delivery & Account Management (contract): create and manage accounts; pair athletes with coaches/guardians; enable features; provide customer support.
- Safety & Security (legitimate interests/legal obligation): authentication, fraud prevention, abuse detection, and system monitoring.
- Analytics & Product Improvement (legitimate interests/consent where required): usage analytics, quality assurance, and feature optimization.
- Personalization (legitimate interests/consent where required): customize content, recommendations, and UI.
- Research & Development (legitimate interests): de-identified or aggregated analysis to improve performance science and our Services.
- AI-Assisted Features (contract/consent where required): nutrition estimation, movement/form insights, and recommendations (see Section 7).
- Communications (legitimate interests/consent): service notices, security alerts, and—where permitted—marketing communications (you can opt out).
- Legal Compliance (legal obligation): fulfill statutory obligations, respond to lawful requests, enforce terms, and protect rights.
Where required, we ask for consent (e.g., for connecting wearables, accessing location, contacts, or calendar, and for certain analytics/marketing activities). You may withdraw consent at any time in-app or by contacting us.
5) Sensitive Data
Health/fitness metrics, biometrics, and identity-verification data are treated as sensitive. We collect and process such data only to deliver the requested features, ensure safety/security, comply with law, and—as further detailed below—improve our Services using de-identified/aggregated data. We do not use sensitive data for advertising or sell it.
6) Cookies, SDKs & Tracking
We use web cookies and mobile SDKs for core functionality, security, and analytics, including Firebase, Segment, Sentry, and Google Analytics. Where applicable, we seek consent before using non-essential tracking. We adopt a privacy-forward default:
- No sale of personal information and no cross-context behavioral advertising without required notice/consent.
- If we ever use advertising technologies (e.g., Meta/Facebook, Google Ads, TikTok), we will implement regional consent and opt-out mechanisms as required and will not use sensitive health data for targeted ads.
You can control cookies via your browser settings and manage app permissions for mobile SDKs via your device OS.
7) AI Features & Human Review
We provide AI-assisted features (e.g., nutrition estimation, movement analysis, recommendations). Key safeguards:
- Advisory Only: AI outputs are informational and not medical advice. Always consult a qualified professional for medical or training decisions.
- Human-in-the-Loop: Trained reviewers may spot-check or label limited user content to improve quality and safety. Reviewers are bound by confidentiality, least-privilege access, and auditing.
- Model Improvement: We may use de-identified or aggregated data to improve models and Services. We do not use your identifiable photos/videos/text to train third-party models without a separate, explicit consent. You may opt out of model-improvement use of your data (Settings or by emailing support@completelabs.com). Opt-out will apply prospectively and will not undo prior processing of already de-identified data.
- Data Deletion & Training Copies: If you delete account content, we will delete the original copies according to Section 12. De-identified data already used for model improvement may be retained (cannot reasonably be linked back to you).
8) Wearables & Integrations
If you choose to connect services like Apple Health, Google Fit, Strava, Catapult, Whoop, or Garmin, we will receive data consistent with your permissions. You may disconnect integrations at any time in-app or via the integration provider. We do not share wearables data with advertisers.
9) Payments
We use Stripe to process payments. Stripe may collect and process payment information as an independent controller. We receive limited payment metadata (e.g., status, last 4 digits, expiration month/year). For details, see Stripe’s privacy documentation.
10) Sharing of Personal Information
We do not sell personal information. We share data only as described below:
- Service Providers / Processors: cloud hosting and infrastructure (AWS), payments (Stripe), authentication (Auth0), communications (Twilio, SendGrid), analytics/monitoring (Firebase, Segment, Sentry, Google Analytics), and similar vendors under contracts that limit use to providing services to us.
- Organization-Directed Sharing: At the request or configuration of an organization (e.g., school, club, team, employer), we share data with that organization and its designated admins/coaches/trainers as described in Section 11 and in the applicable agreement. We apply contractual limits, confidentiality, and security requirements.
- Legal, Safety, and Rights Protection: As required by law, in response to valid legal processes, or to protect our rights, users, or the public.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to continuity of protections and notice where required.
- With Your Direction: When you choose to share, export, or connect to third-party services.
We do not engage in cross-context behavioral advertising using sensitive health/fitness data and do not allow vendors to use your data for their own advertising purposes.
11) Roles, Visibility & Team Features
- Org Admins & Coaches/Trainers may access an athlete’s data while paired or within that organization/team context, including training content, health/fitness metrics, videos, and performance insights—consistent with the organization’s configuration.
- Guardians have full visibility into a minor’s account and may manage consent and controls.
- User-Controlled Visibility: Where features include rosters, team views, leaderboards, or community elements, you can control profile visibility and sharing settings. Certain limited profile information (e.g., display name, team) may be visible to teammates/participants; you can adjust these settings or leave teams to restrict visibility.
12) Retention & Deletion
We keep personal information only as long as necessary for the purposes in this Policy or as required by law:
- Inactive accounts: deleted after 4 years of inactivity.
- Raw videos: retained for up to 24 months (or shorter where you delete them earlier).
- Logs/diagnostics: retained for up to 12 months.
- Aggregated/De-identified data: may be retained indefinitely for analytics, safety, and R&D.
You can download/export your data and delete your account or specific content (including photos/videos) in-app. De-identified data already created will not be re-identified or deleted because it cannot reasonably be linked to you.
13) Your Rights & Choices
Depending on your location, you may have the right to:
- Access and port your data.
- Correct inaccurate data.
- Delete data (subject to lawful exceptions).
- Object to or restrict certain processing (e.g., analytics or personalization).
- Withdraw consent at any time (e.g., wearables, location, contacts/calendar, marketing).
- Opt out of targeted advertising, data “sharing” (as defined by CPRA), and profiling where applicable.
- Appeal a decision if we decline to act on a request (where required by law).
Submit requests via in-app settings or email support@completelabs.com. We will verify your identity and respond within applicable timelines.
14) International Data Transfers
We operate globally and may transfer personal information to the United States and other countries that may not provide the same level of data protection as your home jurisdiction. For EU/UK users, we use Standard Contractual Clauses (SCCs) and conduct transfer impact assessments as appropriate. We maintain technical and organizational measures to safeguard data during and after transfer.
15) Security
We use industry-standard safeguards, including encryption in transit and at rest, role-based access control, least-privilege permissions, network segmentation/VPC, audit logging, secure key management, regular security testing, vendor due diligence, and an incident response program. No method of transmission or storage is 100% secure; we will notify you of a breach as required by law.
16) Communications & Marketing
We may send you service and transactional messages (e.g., security alerts, invoices). Where permitted, we may send marketing communications; you can opt out via the message itself or in-app settings. We do not use sensitive health or biometrics data for marketing.
17) Dispute Resolution
If you have a concern, contact support@completelabs.com. We will work with you to resolve the issue. If unresolved, disputes will be handled under local law in your jurisdiction unless otherwise required by applicable law.
18) Data Controller, Processor & DPA Terms (Embedded)
- For direct-to-consumer users, Complete is the data controller of personal information processed through the Services.
- For organization-provisioned users (e.g., schools, clubs, employers, teams), the organization is the controller and Complete acts as a processor (or service provider under CPRA). By using the Services under an organization, you acknowledge that your data may be accessible to that organization’s authorized personnel as described in Section 11.
- Processor Terms: Where we act as a processor/service provider, we will: (a) process personal information only on documented instructions; (b) maintain confidentiality and security; (c) assist with data subject requests and impact assessments; (d) use sub-processors (e.g., AWS, Stripe, Auth0, Twilio, SendGrid, Sentry, Firebase/Segment/Google Analytics) under written contracts with equivalent protections; (e) enable audits as legally required; and (f) delete or return personal information at termination, subject to legal retention and de-identification practices in Section 12. Our SCCs and jurisdiction-specific addenda apply where required for international transfers.
19) State-Specific Disclosures (U.S.)
Residents of certain U.S. states (e.g., CA, CO, CT, VA, UT) have additional rights, including the right to opt out of “sharing” (CPRA) for cross-context behavioral advertising. We do not sell personal information and do not use sensitive personal information for cross-context behavioral advertising. You may exercise applicable rights as described in Section 13.
20) Third-Party Links & Services
The Services may link to third-party sites or integrate with third-party services. We are not responsible for their privacy practices. Review their policies before use (e.g., Stripe, Apple Health, Google Fit, Strava, Catapult, Whoop, Garmin).
21) Changes to This Policy
We may update this Policy to reflect changes in our practices, legal requirements, or features. We will notify you via email and/or in-app notice and indicate the “Effective date” at the top. Material changes will take effect no sooner than the date stated in the notice unless otherwise required by law.
22) Contact Us
Questions or requests? Email support@completelabs.com.