Privacy Policy
Last updated: April 28, 2026
This Privacy Policy describes how Metrica Fit LLC (“Metrica Fit,” “we,” “us,” or “our”) collects, uses, stores, and discloses information when you use Onda (“Onda,” the “Service”), including the Onda web application, mobile application, and any related services operated by Metrica Fit LLC at ondafit.app.
By using Onda, you agree to the collection and use of information in accordance with this Policy. If you do not agree with any part of this Policy, you should not use the Service.
1. Who We Are
Onda is operated by Metrica Fit LLC, a limited liability company. If you have any questions about this Privacy Policy or our data practices, you can contact us at:
Metrica Fit LLC
Email: privacy@ondafit.app
2. Information We Collect
We collect information in the following categories:
2.1 Information You Provide Directly
When you create an account or use Onda, you may provide:
- Account information: name, email address, password (stored as a cryptographic hash)
- Profile information: date of birth, gender, height, weight, resting heart rate, functional threshold power, training zones, and related athletic profile data you choose to enter
- Race goals, target events, and training preferences
2.2 Information From Connected Services
Onda allows you to connect third-party services — including Garmin Connect, Suunto Cloud API, Apple HealthKit, Zwift via email, and others — to import your activity and health data. When you authorize one of these connections, we receive information from that service on your behalf, which may include:
- Workout activities: date, time, duration, sport type, distance, pace, speed, heart rate, power, cadence, elevation, GPS routes, laps, and splits
- Wellness and health metrics: resting heart rate, heart rate variability, sleep duration and stages, daily steps, stress scores, body composition, and VO2 max estimates
- Training-related data: structured workouts, training plans, and device settings
For Garmin Connect specifically, we access data through the Garmin Connect Developer API only after you have completed the Garmin OAuth2 authorization flow and granted Onda permission to access your data. You can revoke this permission at any time from your Garmin Connect account settings or from within Onda. See Section 2.4 for how Garmin data flows through our systems. Section 2.5 covers the equivalent flow for Suunto. Section 2.6 covers email-based ingestion from Zwift and other indoor-cycling platforms.
2.4 Garmin Connect Integration Details
When you connect your Garmin account, Onda receives and stores the following categories of information from the Garmin Developer API:
- Activity data — each workout you complete on a Garmin device: start time, duration, distance, sport type, heart rate, power, pace, cadence, elevation, GPS track, laps, and device metadata.
- Your Garmin athlete identifier — an opaque numeric ID that Garmin uses to identify your account. Onda stores this only to route incoming activities to the right Onda user.
- OAuth access and refresh tokens — short- and long-lived credentials issued by Garmin that let Onda download your activity data. These tokens are stored on Onda’s backend database and are accessible only to Onda’s server-side services; the Onda iOS app never reads them.
New activities are delivered to Onda by Garmin’s Activity API ping service: when you finish and sync a workout on your device, Garmin notifies Onda’s servers, and Onda downloads the activity details for you. You can disconnect the integration at any time from Onda → Settings → Connected Devices, or from your Garmin Connect account settings → Connected Apps. Disconnecting stops all future data flow from Garmin; activities already imported remain in your Onda account until you delete them (or your account).
2.5 Suunto Cloud API Integration Details
When you connect your Suunto account, Onda receives and stores the following categories of information from the Suunto Cloud API:
- Workout data — each workout you complete on a Suunto device, delivered as the FIT file Suunto exports for that workout: start time, duration, distance, sport type, heart rate, power (where present), pace, cadence, elevation, GPS track, laps, and device metadata.
- Your Suunto username — the identifier Suunto includes in the JWT access token. Onda stores this only to route incoming workouts to the right Onda user.
- OAuth access and refresh tokens — credentials issued by Suunto that let Onda download your workout data. These tokens are stored on Onda’s backend database and are accessible only to Onda’s server-side services; the Onda iOS app never reads them.
We do not ingest 24/7 daily activity data from Suunto — daily steps, calories, sleep, and stress are not requested or stored. Onda is built for workouts, not step tracking.
New workouts are delivered to Onda by Suunto’s notification webhook: when you finish and sync a workout to the Suunto app, Suunto notifies Onda’s servers, and Onda downloads the FIT file for you. You can disconnect the integration at any time from Onda → Settings → Connected Devices, or from the Suunto app’s connected-apps settings. Disconnecting stops all future data flow from Suunto; workouts already imported remain in your Onda account until you delete them (or your account).
2.6 Email-based Activity Ingestion (Zwift)
When you connect Zwift in Onda, the app generates a unique inbox address for you of the form <token>@inbox.ondafit.app. You forward your Zwift FIT files (or any other FIT file) to that address from any email client; Onda’s servers receive the message, extract the FIT attachment, and import it into your account. Onda receives and stores the following from each email:
- FIT-attachment activity data — the workout data inside the FIT file: start time, duration, distance, sport type, heart rate, power, pace, cadence, elevation, GPS track, laps, and device metadata. Non-FIT attachments (PDFs, images, body text) are discarded; we never parse the email body.
- Sender address and email subject— stored alongside each incoming email for up to 30 days for debugging and surfaced to you in the “Recent emails” section of the Zwift settings screen. The email subject may also be used as the activity title when the FIT file doesn’t carry one.
- Your inbox token — a random 8-character string that routes incoming emails to your Onda account. The token is your credential for this channel; anyone who knows it can post FIT files to your account (rate-limited to 20 per hour). You can rotate it at any time from the Zwift settings screen.
Email delivery is handled by Resend, our email infrastructure provider. Resend processes inbound messages on our behalf; their handling of in-transit email is governed by Resend’s privacy policy. Onda only stores the FIT bytes + the forensic fields listed above; the email body, headers, and non-FIT attachments are never persisted.
You can disconnect the integration at any time from Onda → Settings → Connected Devices → Zwift → Disconnect. Disconnecting silently drops any future emails sent to your inbox address; activities already imported remain in your Onda account until you delete them (or your account). If you only want to invalidate the address (for example, because you accidentally shared it publicly), use the “Rotate address” button on the same screen — that mints a fresh token and the old address goes silent.
2.3 Information Collected Automatically
When you use Onda, we automatically collect limited technical information:
- Device and browser type, operating system version, and screen size
- IP address (used for security and regional routing; not used for advertising)
- Service usage events such as page views and feature interactions, for the purpose of debugging and improving the Service
- Crash and error logs
We do not use third-party advertising trackers, cross-site tracking pixels, or data broker integrations.
3. How We Use Your Information
We use the information we collect exclusively to operate, maintain, and improve Onda for you as an individual user. Specifically:
- To compute training load metrics (Training Stress Score, Intensity Factor, Chronic Training Load, Acute Training Load, Training Stress Balance) across swim, bike, and run disciplines
- To display detailed workout analysis including power, heart rate, pace, and GPS data
- To identify your best efforts and personal records across time and distance intervals
- To visualize long-term training consistency, volume, and fitness progression
- To project race-day readiness for target race events based on your recent training and historical performance
- To authenticate your account and secure your session
- To communicate with you about your account, important Service updates, and, if you opt in, product announcements
- To debug, monitor, and improve the Service
- To comply with legal obligations and enforce our Terms of Service
We do not use your activity or health data for advertising, profiling for advertising purposes, or automated decision-making that produces legal or similarly significant effects.
5. Data Retention
We retain your account and activity data for as long as your Onda account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain specific records for legal, tax, or security reasons.
You can delete your account at any time from within the Service, or by contacting privacy@ondafit.app.
6. Your Rights and Choices
You have the following rights regarding your information:
- Access: You can view most of your data directly within Onda. You may also request a copy of the personal data we hold about you.
- Correction: You can update your profile information at any time within the Service.
- Deletion: You can delete your account and associated data at any time.
- Revocation of third-party connections: You can disconnect Garmin Connect, Apple HealthKit, or any other connected service at any time, either from within Onda or directly from the third party. Revoking a connection stops future data flow; it does not automatically delete historical data already imported — for that, delete your Onda account or contact us.
- Portability: You can export your workout data in common formats (FIT, GPX, CSV) from within the Service.
- Objection and restriction: Where applicable under local law, you can object to or request restriction of certain processing.
To exercise any of these rights, contact privacy@ondafit.app. We will respond within 30 days.
Depending on where you live, you may have additional rights under laws such as the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), or similar laws. We honor these rights for all users regardless of location.
7. Data Security
We use industry-standard security measures to protect your information, including:
- Encryption in transit (TLS 1.2 or higher) for all network communication
- Encryption at rest for stored data
- Cryptographic hashing of passwords (bcrypt or equivalent)
- Principle of least privilege for internal access to production systems
- Regular security review of infrastructure and dependencies
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you in accordance with applicable law.
8. International Data Transfers
Onda is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and in the regions of our service providers. Where required, we use appropriate safeguards such as Standard Contractual Clauses to protect data transferred internationally.
9. Children's Privacy
Onda is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us and we will promptly delete it.
10. Third-Party Services and Links
Onda integrates with third-party services such as Garmin Connect. When you authorize such a connection, the third party's own privacy policy governs their handling of your data before it is transmitted to us. We encourage you to review the privacy policies of any service you connect.
- Garmin privacy policy: garmin.com/en-US/privacy/connect
- Apple privacy policy: apple.com/legal/privacy
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by posting a notice in the Service before the changes take effect. The “Last updated” date at the top of this Policy indicates when it was last revised.
12. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:
Metrica Fit LLC
Email: privacy@ondafit.app
Website: ondafit.app
This Privacy Policy is provided for the Onda service operated by Metrica Fit LLC. It does not constitute legal advice. Metrica Fit LLC recommends that users consult their own legal counsel if they have specific legal questions.