Privacy policy.
The short version: we collect what the fueling maths needs, we never sell it, there are no ad networks or analytics trackers in the app, and you can delete the whole account yourself from inside it.
1. Who we are
CarbRate is a race-fueling app and website operated by Jeff Gaudette. In this policy “CarbRate”, “we” and “us” mean that operator, and “you” means the person using the app or the site. You can reach a human at [email protected].
This policy covers the CarbRate iOS app and the carbrate.com website. It does not cover RunnersConnect, which is a separate service with its own policy, or any third-party site you reach by following a link from ours.
2. What we collect, and why
CarbRate is a calculator with a memory. Almost everything below exists because the fueling engine needs it as an input — not because we wanted a profile of you.
| What | Why we need it |
|---|---|
| Email address and password | To create your account and sign you back in. Passwords are hashed by our authentication provider; we never see or store the plain text. |
| Body data — weight, height, age, sex | Direct inputs to the sweat-rate, carbohydrate and fluid models. Sex and body mass change the heat-balance calculation materially; without them the plan is guesswork. |
| Training and fueling inputs — recent race results, gut tolerance, fat-adaptation level, sweat-test results, sweat sodium concentration | These personalise the plan and let us re-compute your calibration factor when you run another test. |
| Your races, plans, products and course notes | So your plan is there on your phone when you come back to it, and so we can place feeds against a real course. |
| Course progress and saved lessons | To remember where you got to in the Learn tab. |
| Subscription status | To know whether to unlock Pro features. We store an entitlement flag, not your payment details. |
What we do not collect
- No analytics or advertising SDKs. There is no PostHog, Firebase, Amplitude, Mixpanel, Sentry or ad network in the app. We do not track you across other apps or websites, and we do not run an advertising identifier.
- No location tracking. The app never asks for your device location and has no GPS permission. When it fetches a race-day forecast, it geocodes the place name you typed — nothing about where your phone actually is.
- No card numbers. Payment is handled entirely by Stripe on their own hosted checkout page. Card details never touch our servers.
- No contacts, photos, microphone or camera access.
Using CarbRate without an account
You can go through the whole fueling interview as a guest. A guest session is a random identifier with no email attached to it. If you later create a real account, your guest data carries across to it rather than being duplicated.
3. Apple Health data
Apple Health is entirely optional. CarbRate is fully functional if you decline it, and nothing about the app degrades if you never grant it.
If you choose to connect Apple Health, CarbRate requests read-only access to four things:
- Workouts
- Heart rate
- Active energy burned
- Walking and running distance
We use these for one purpose: to pre-fill and sharpen your fueling inputs, so you don’t have to type in a run you already recorded, and so your carbohydrate and fluid targets reflect what you actually did rather than an estimate.
CarbRate never writes to Apple Health. Health data is read on your device and is never used for advertising or marketing, never sold, never shared with data brokers, and never disclosed to a third party for their own purposes. Where a value derived from a workout is saved to your CarbRate account (for example, a race result that feeds your fitness estimate), it is stored as an ordinary fueling input under your account and is deleted along with everything else when you delete your account.
You can withdraw Health access at any time in the iOS Settings app, under Privacy & Security › Health › CarbRate. Revoking it stops all further reads immediately.
4. Who else touches your data
We use a small number of service providers to run CarbRate. Each one gets only what it needs to do its job, and none of them is permitted to use your data for their own marketing.
| Provider | What it handles |
|---|---|
| Supabase | Our database and sign-in system. Your account and all the fueling data above live here, hosted in the United States. |
| Stripe | Subscription payments and billing. Stripe collects your payment details directly under their privacy policy; we receive only a customer reference and whether the subscription is active. |
| Superwall | Presents the upgrade screen inside the iOS app and tells us which subscription you hold. It receives an anonymous app-install identifier and standard device attributes, including your App Store storefront country — we use that last one to show the correct screen for your region. |
| Kit | Sends the emails you ask for, such as a plan sheet mailed to yourself, and any newsletter you opt into. Only used if you give us an email for that purpose, and every message has an unsubscribe link. |
| Open-Meteo | Race-day weather forecasts. Receives the place name you typed and its coordinates. No account identifier and nothing about your device is sent. |
| Cloudflare | Hosts and serves carbrate.com. |
We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. The only other circumstances in which we would disclose data are where the law requires it, or where a business transfer occurs — in which case we would tell you first and this policy would travel with the data.
Affiliate links
Some outbound product links are affiliate links, and clicking one records that the click happened so we can reconcile it later. Product rankings and Science Scores are computed from verified product data and are never influenced by affiliate relationships. Sponsored placements are always labelled as such.
5. Keeping, deleting, and getting your data
Deleting your account
You can delete your account and everything in it from inside the app: open the You tab and choose Delete account. This is permanent. It removes your profile, races, plans, sweat tests, saved products, course progress and sign-in credentials, and it cancels any active subscription immediately. We cannot undo it, and we cannot recover the data afterwards.
If you would rather we did it for you, email [email protected] from your account address and we will action it within 30 days.
How long we keep things
Your account data is kept for as long as your account exists. Once you delete it, it is removed from our live systems immediately and ages out of encrypted backups within 30 days. Records we are legally required to keep — payment and tax records, held by Stripe — are retained for as long as the law requires.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, object to how we use it, or ask us to send it somewhere else. You can exercise any of these by emailing [email protected]. We will not charge you for it, and we will not treat you differently for asking. If you are in California, note that we do not sell or share personal information as those terms are defined under the CCPA.
6. Security
Data is encrypted in transit and at rest. Access to the database is governed by row-level security, so one account cannot read another’s rows even if a client were compromised. No system is perfectly secure, but we keep the number of places your data lives deliberately small.
7. Children
CarbRate is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us data, email us and we will delete it.
8. Changes to this policy
If we change how we handle your data, we will update this page and move the effective date at the top. Material changes get an email to account holders as well — we will not quietly broaden what we collect.
See also our terms of service and support page.