Ultra Readiness

Privacy Policy

Last updated: 12 July 2026

Who we are

This service is operated by Stone Bled Dry ("we", "us"). This policy covers the Stone Bled Dry readiness platform ("the Service"), which provides training readiness insights to runners using their Garmin device data. It does not currently cover any other Stone Bled Dry products or services.

If you have questions about this policy or how your data is handled, contact us at privacy@stonebleddry.com.

What data we collect

We collect the following categories of data:

Account information

  • Email address, used to create and secure your account.

Activity data, from Garmin

If you connect a Garmin account, we receive data for your running activities, including distance, duration, pace, heart rate, elevation, running dynamics (such as cadence and ground contact time), and Garmin's own derived training metrics (such as Training Load and VO2 max estimates).

Activity data, from FIT files you upload

If you upload activity (.FIT) files from your device, we store the running data they contain: distance, duration, pace, elevation, and heart rate, plus the file's session summary (which may include additional device-derived metrics such as training effect, calories, and temperature), retained in raw form so your history can benefit as the readiness model improves. Uploading is always at your initiative — you choose exactly which files to provide.

Activity and health data, from intervals.icu

If you connect an intervals.icu account (by providing your intervals.icu API key), we retrieve your running activities from it — distance, duration, pace, heart rate and time in heart rate zones, and elevation — together with daily health data: sleep duration and quality, heart rate variability (HRV), resting heart rate, and step count. The full activity and wellness records as returned by intervals.icu are retained in raw form so your history can benefit as the readiness model improves — these may include additional metrics you track there (for example weight, SpO2, or respiration rate). Your API key is stored server-side only and is used solely to read this data from intervals.icu on your behalf; disconnecting deletes the stored key, and we keep a record of when consent was given and withdrawn.

Health data, from Garmin

If you connect a Garmin account, we also receive daily health data, including sleep duration and quality, heart rate variability (HRV), Body Battery, resting heart rate, stress score, and step count.

Health data — whether it arrives from Garmin or from intervals.icu — is "special category data" under UK GDPR, meaning it is treated as more sensitive and requires your explicit consent before we collect or process it. We ask for this consent separately, before connecting the account it comes from, and you can withdraw it at any time by disconnecting that account in your settings.

Information you enter directly

For runs you tag as a "simulation", we store the details you select (terrain, walking, fuelling, heat, conditions, fatigue) and any free-text notes you choose to add.

Why we collect it, and our legal basis

We use your data to:

  • Provide the Service itself — calculating your training readiness, displaying your activity history, and generating insights.
  • Maintain and secure your account.
  • Improve the underlying readiness model, using aggregated or de-identified data where possible.

Our legal bases for processing are:

  • Contract — processing your account and activity data is necessary to provide the Service you've signed up for.
  • Explicit consent — for the special category health data described above, which we only collect once you've actively connected your Garmin or intervals.icu account and agreed to share it.

We do not use your data for advertising, and we do not sell your data to third parties.

Who we share data with

We share data with the following third parties, solely to operate the Service:

  • Garmin— to receive your activity and health data, via Garmin's Connect Developer Program. Garmin's own privacy policy governs how they handle your data on their side.
  • intervals.icu— to retrieve your activity and health data if you connect an intervals.icu account. We only read data from intervals.icu; we do not send your data to it. intervals.icu's own privacy policy governs how they handle your data on their side.
  • Google Firebase / Google Cloud— our infrastructure provider, used to store your account, activity, and health data securely, and to handle sign-in. Google Cloud may process data outside the UK (including in the United States); where it does, this is covered by Google's standard contractual clauses, a legally recognised safeguard for international data transfers.

We do not currently share your data with any analytics, advertising, or marketing services.

How long we keep your data

We keep your data for as long as your account is active, so that your training history remains available to you. If you'd like your account and data deleted, contact us at privacy@stonebleddry.com — an automated self-service deletion option is planned but not yet available, so for now this is handled manually on request.

Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Withdraw consent for health data processing at any time (this will disconnect the account the health data comes from — Garmin or intervals.icu — and stop further health data collection; it does not retroactively delete data already collected unless you also request deletion).
  • Lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe your data has been mishandled.

To exercise any of these rights, contact us at privacy@stonebleddry.com.

Security

We take reasonable technical and organisational steps to protect your data, including restricting access so that each account can only access its own data, and securing credentials used to connect to Garmin or intervals.icu on your behalf. No system is completely secure, and we cannot guarantee absolute security of data transmitted to or from the Service.

Children

The Service is not intended for, and should not be used by, anyone under the age of 18.

Changes to this policy

We may update this policy as the Service develops — for example, as we add new features or data sources. We'll update the "Last updated" date above when we do, and for material changes affecting how special category data is handled, we'll seek your consent again before continuing.