PRIVACY / 守 / PROTECT

Privacy Policy

Your data stays with you. Shinobi is built client-side first — no accounts, no cloud storage, no tracking. This policy explains exactly what data exists, where it lives, and what you control.

EFFECTIVE: JUNE 24, 2026
§01
概要 · OVERVIEW
Who we are and what this covers.

Shinobi (shinobi.fit) is a free, open-source endurance race readiness tool operated by Shinobi ("we," "us," or "our"). This Privacy Policy describes how we collect, use, store, and protect information when you use our website and services.

By using Shinobi, you agree to the practices described in this policy. If you do not agree, please do not use the service.

§02
収集 · DATA COLLECTED
What data exists and where it comes from.
AData you provide directly

During the onboarding assessment and subsequent profile updates, you may enter the following information. All fields are optional unless marked otherwise:

CATEGORY
DATA
STORAGE / REFERENCE
Physical Profile
Age (required), weight, height, gender
Browser localStorage
Cardiovascular Metrics
VO2 Max, resting heart rate, HRV (RMSSD), max heart rate
Browser localStorage
Running Metrics
5K pace, weekly running distance, longest run, weekly training hours
Browser localStorage
Multi-sport Metrics
Swimming 100m pace, cycling FTP (watts/kg)
Browser localStorage
Strength & Body Composition
Grip strength, body fat percentage, pull-up count
Browser localStorage
Race Experience
Completed races (selected from catalogue)
Browser localStorage
Activity Logs
Training sessions: type, distance, duration, pace, elevation, power, exercises
Browser localStorage
All data listed above is stored exclusively in your browser's localStorage. It never leaves your device. It is not transmitted to any server, database, or third party. We cannot access, read, or recover this data.
BWaitlist data (Tally.so)

If you join the native app waitlist, the form is provided by Tally.so, a third-party form service. Any information you submit through the waitlist form (such as your email address) is collected and stored by Tally.so under their privacy policy. We access this data solely to notify you when the native app launches.

CAutomatically collected data

Shinobi does not use analytics services, tracking pixels, fingerprinting, or advertising networks. We do not collect:

IP addresses
Device or browser fingerprints
Usage patterns or behavioral analytics
Advertising identifiers
Location data

Our hosting provider (Vercel) may process standard server access logs (IP address, user agent, request path) as part of normal web hosting operations. These logs are managed by Vercel under their privacy policy and are not accessed or used by Shinobi.

§03
使用 · HOW WE USE DATA
Purpose of data collection.

We use the information described above for the following purposes only:

Computing your race readiness scores across the event catalogue
Generating personalized training recommendations based on your target race
Mapping your position on the 8-tier progression system
Displaying your 7-axis demand profile and metric breakdown
Notifying waitlist members when the native app launches
We do not sell, rent, trade, or share your personal data with any third party for marketing, advertising, or analytics purposes. Your data is used solely to provide the Shinobi service to you.
§04
健康 · HEALTH DATA
Special treatment for health and fitness data.

Shinobi collects health and fitness information including cardiovascular metrics (VO2 Max, heart rate, HRV), body composition data (weight, height, body fat percentage), and exercise performance data (pace, power, training volume). This data is classified as sensitive personal information under various privacy laws.

Our commitments regarding health data:

Health and fitness data is stored exclusively in your browser's localStorage — it is never transmitted to or stored on our servers.
We never use health data for advertising, profiling, or purposes unrelated to providing the Shinobi service.
We do not aggregate, de-identify, or analyze health data across users.
You maintain full control over your health data at all times (see Section 07: Your Rights).
Medical disclaimer: Shinobi is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Readiness scores and training recommendations are for informational and educational purposes only. Always consult a qualified healthcare professional before beginning or modifying any exercise program.
§05
保存 · COOKIES & STORAGE
Browser storage and cookies.

Shinobi does not set HTTP cookies. We use the following browser storage mechanisms:

CATEGORY
DATA
STORAGE / REFERENCE
localStorage: race_goals_user_data
Your metrics and assessment results (when entered)
Persistent until you clear it
localStorage: shinobi_activity_logs
Your logged training activities (when entered)
Persistent until you clear it
sessionStorage: shinobi_intro_seen
Flag to skip the landing page intro animation on revisits
Current browser session only

No third-party cookies or tracking technologies are set by Shinobi. The Tally.so waitlist embed may set its own cookies if you interact with the waitlist form — see Tally.so's cookie policy for details.

§06
保持 · RETENTION & DELETION
How long data is kept and how to delete it.

Client-side data (localStorage): Your metrics, assessments, and activity logs persist in your browser until you explicitly delete them. There is no server-side backup or recovery. To delete all client-side data:

Open your browser's Developer Tools (F12 or Cmd+Shift+I)
Navigate to Application > Local Storage > shinobi.fit
Delete the relevant keys, or clear all site data via your browser settings

Waitlist data: Waitlist submissions are stored by Tally.so. To remove your waitlist entry, contact us at the email provided in Section 11 or submit a deletion request directly to Tally.so.

§07
権利 · YOUR RIGHTS
Data rights under GDPR, CCPA, and other laws.

Depending on your jurisdiction, you may have the following rights regarding your personal data:

For all users
Right to access: Your client-side data is fully accessible to you in your browser at all times.
Right to deletion: Delete client-side data at any time via your browser settings.
Right to portability: Your localStorage data can be exported as JSON from your browser's developer tools.
Right to withdraw consent: Stop using the service at any time; clear your local data whenever you wish.
European Economic Area, United Kingdom, and Switzerland (GDPR)
Lawful basis: We process health data based on your explicit consent, given when you enter metrics in your browser. You may withdraw consent at any time.
Right to rectification: You may update any metric at any time in the app.
Right to object: You may object to processing by contacting us.
Right to lodge a complaint: You may file a complaint with your local supervisory authority.
California (CCPA/CPRA)
We do not "sell" or "share" your personal information as defined under the CCPA.
We do not use personal information for cross-context behavioral advertising.
You have the right to know, delete, and correct your personal information.
We will not discriminate against you for exercising your privacy rights.
Washington State (My Health My Data Act)
We collect consumer health data (fitness metrics) only with your voluntary input.
We do not sell or share consumer health data.
You may request deletion of any health data at any time.
We process health data solely to provide the race readiness service you requested.
§08
外部 · THIRD-PARTY SERVICES
Services that interact with your data.
CATEGORY
DATA
STORAGE / REFERENCE
Vercel
Web hosting
vercel.com/legal/privacy-policy
Tally.so
Waitlist form collection
tally.so/help/privacy-policy
Google Fonts
Font loading (preconnect)
policies.google.com/privacy

Each third-party service operates under its own privacy policy. We encourage you to review their respective policies linked above.

§09
安全 · SECURITY
How we protect your data.

We implement the following security measures:

All data transmission occurs over HTTPS (TLS encryption in transit).
Your metrics and activity data live only in your browser's localStorage; they are never transmitted to our servers.
The application source code is open-source and auditable on GitHub.

Because Shinobi stores no personal data on its servers, there is no server-side store of your metrics to breach. Waitlist emails are held by Tally.so under their own security program.

§10
未成年 · CHILDREN
Children’s privacy.

Shinobi is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us and we will take steps to delete such information.

§11
連絡 · CONTACT
How to reach us.

For privacy-related inquiries, data access requests, deletion requests, or complaints:

Email: privacy@shinobi.fit
GitHub: github.com/mugen-space-claude/shinobi (open an issue)

We aim to respond to all privacy requests within 30 days, and within 45 days for CCPA requests as required by law.

§12
変更 · CHANGES
Updates to this policy.

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective Date" at the top of this page and post a notice on the Shinobi homepage. Your continued use of Shinobi after any changes constitutes acceptance of the updated policy.

“Privacy is not a feature — it is a constraint. Your data never crosses the wire unless you say so. endures by keeping nothing.”
— Shinobi design principles
© Shinobi · v1.0Privacy Policy · June 24, 2026