Tortoise Privacy Policy

Effective date: July 28, 2026

Tortoise is a training app. This page says plainly what it does with your data, not what a lawyer wants it to sound like it does.

Who runs this

Tortoise is operated by Todd Diebold. If you have a question about your data, email tdiebold@gmail.com. It's a small, independently run tool, not a company with a data department, so a real person reads that inbox.

What gets collected

When you sign in. Tortoise uses Google to sign you in. We receive your name, email address, and profile picture from Google. We never see or store your Google password.

What you or your household enters. Training sessions, goals, injuries and clinical restrictions, wellness check-ins like sleep and how you're feeling, equipment you own, and anything else you type into the app.

What syncs from your watch. If you connect a COROS device through Intervals.icu, we pull in your workout history: duration, heart rate, pace, power, and similar metrics. If a session has GPS data, we also store your route, the actual coordinates you ran or rode through, along with elevation.

Cookies. One cookie keeps you signed in. That's it. No advertising cookies, no tracking pixels, no analytics that follow you around the internet.

What it's used for

To build your training plan and show you your own trends. That's the whole purpose. We do not use your data to serve you ads, we do not sell it, and we do not share it with anyone for marketing.

One part of the app uses Anthropic's Claude to write the prose explanation attached to a training session, the "why" behind a workout, and to answer questions you ask it directly in the Ask feature. Claude sees the relevant training data needed to answer, it does not have standing access to your account, and Anthropic does not use this data to advertise to you.

Who can actually see your data

Tortoise is built around households, not individual accounts floating in isolation. Your training and health data is visible only to people who are members of your own household, people who were specifically added, not anyone who happens to sign in. Nobody outside your household can see your data by default, and there is currently no feature that shares it publicly or with any other household without an explicit, separate grant.

Children's data

Tortoise is built to be used by families, which means it may hold data belonging to a minor. A child does not sign up or create their own account independently. A parent or guardian who already has their own account adds a child's profile and manages it. We do not knowingly allow a child under 13 to create an account on their own, and if we become aware that one exists without a parent's involvement, we'll remove it.

How your data is stored and protected

Data lives in a Postgres database hosted by Supabase. Sensitive credentials, like the key that connects your account to Intervals.icu, are encrypted at rest, not stored as plain text. Access to the app itself requires signing in with your own Google account; there is no shared password.

Other services this app relies on

Tortoise is built on top of a small number of other companies' infrastructure, each with their own privacy practices:

We don't control these companies' own data practices, only what we send them and what we do with what comes back.

Deleting your data

Email the address above and ask. We'll remove your account and the data tied to it. If your data is part of a shared household, we'll ask you to confirm what specifically you want removed, since some data may be relevant to other household members' own history (for example, a shared training block).

Changes to this policy

If what this app does with your data changes in a real way, this page will change to reflect it, dated at the top so you can tell.