Mosaic ("we", "us") is a personal training plan application for iOS. This policy explains what data we collect, how we use it, who we share it with, and your rights over it. Mosaic is operated by Tristan Louveaux, based in the United Kingdom.
Mosaic collects data from the following sources, only with your explicit authorisation:
All data is used exclusively to provide Mosaic's training plan and fitness tracking features to you. Specifically:
Mosaic includes code for an optional AI Coach feature. In this release the AI Coach is available only to a limited set of users on an internal access list while the subscription path is being built. If you are not on the access list, no AI Coach data flows to any third party from your device.
When the AI Coach is enabled for your account, the following is sent each session to Anthropic's Claude API (the Haiku model) for the sole purpose of generating coaching responses:
The following is never sent to Anthropic: your name, email, GPS coordinates, raw routes, Strava or Garmin credentials, payment information.
Anthropic retains messages for up to 30 days under their Commercial Terms, after which they are deleted. Anthropic does not use these messages to train their models. See the Anthropic Privacy Policy for full detail.
When the AI Coach becomes generally available you will be asked to consent to this data flow the first time you open the feature. You can decline at any time, and you can use the rest of Mosaic without the AI Coach enabled.
Your activity data is stored in a secured Supabase database hosted on AWS infrastructure in the EU. Data is encrypted in transit (HTTPS) and at rest. Row-level security policies enforce that you can only read and write your own data. Apple Health data is processed on-device and is not transmitted to our servers unless you also have the same metric synced via Strava or Garmin.
Mosaic uses the following third-party services to operate. Each is contracted as a data processor and is governed by their own privacy policy.
We retain your data for as long as your account is active. If you disconnect Strava, syncing stops and Mosaic's access is removed immediately; to erase Strava-sourced data already stored, delete your account or email us and we will remove it. If you delete your account from inside the app, your data is marked for deletion immediately and permanently purged within 30 days. The 30-day window lets you sign back in and cancel the deletion if you change your mind.
Under the UK GDPR, the EU GDPR, and applicable data protection law, you have the right to:
To exercise any right that is not available in-app, email tristan@mosaicrunning.run.
To disconnect Strava, open Mosaic, go to Account, and tap Disconnect on the Strava row. You can also revoke from your Strava app settings directly.
To disconnect Garmin, open Mosaic, go to Account, and tap Disconnect on the Garmin row.
To disconnect Apple Health, open iOS Settings, Health, Apps, Mosaic, and turn off the relevant permissions.
To delete your account and all data Mosaic holds about you, open Mosaic, go to Account, and tap Delete account. You can also email tristan@mosaicrunning.run with the subject "Delete my data".
Mosaic is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us with personal data, email us and we will delete it.
Material changes will be flagged in-app and noted at the top of this page. The "Last updated" date above always reflects the most recent revision.
Questions about this policy: tristan@mosaicrunning.run