Privacy

Baseline (“Baseline”, “we”) is a pre-incorporation project by Tim Rudder; the operating entity will be a UK private limited company (Baseline Ltd). This page describes what we collect, how we use it and the choices you have. If anything here is unclear, email hello@getbaseline.fit.

The one thing to know

Raw fitness files never leave your browser. Baseline parses your upload locally, derives your Baseline from it, and then discards the file when the tab closes. If you sign in and save, only the derived Baseline — your metrics, PBs and badges — is stored on our servers. The original FIT / TCX / GPX / CSV / XML file is never uploaded.

What we collect

Anonymous mode. None. We do not collect any personal data server-side when you use Baseline without signing in. Your file is parsed in the browser tab and everything is discarded when you close the tab.

Signed-in mode. When you create an account we collect your email address and Supabase Auth stores a hashed password (magic-link sign-in still stores the email so we can send the link). You may optionally add profile fields — name, age, sex, weight, resting HR, max HR — that shape your Baseline bracket. When you save an upload, we store the derived Baseline (score, per-discipline benchmarks, badges, source-mix summary, narrative text) and the timestamps of each save. We never receive the raw file.

Usage data. Standard hosting logs from Vercel (request paths, error traces, aggregate performance). No analytics vendor. No ad networks. No third-party tracking pixels.

What we never collect

To be explicit, these things never reach our servers:

  • Raw fitness or health export files (FIT, TCX, GPX, CSV, XML).
  • Location traces or GPS routes from your rides, runs or rows.
  • Individual heart-rate samples or stream data.
  • Individual workout stroke, rep or set detail.

Special-category data notice

The derived Baseline (your score, PBs, benchmarks and body-metric summaries) may constitute health data under UK GDPR Article 9. We rely on explicit consent under Article 9(2)(a) — which is why saving requires an authenticated action, not a passive collection. If you don’t sign in, nothing is stored.

How the AI layer is used

Where AI is used to generate narrative summaries in your Baseline, the model receives only the derived Baseline JSON — numbers, labels and badges — not raw uploaded files. No LLM ever sees your original export. We do not use your data to train public models.

Where your data is stored

Baseline runs on Supabase (auth + database, EU-West-2 region) and Vercel (hosting, EU regions). Email delivery for magic links may process the email address outside the EU under standard contractual clauses.

Retention

Derived Baseline snapshots are retained until you delete your account. Account deletion is available on /account when you’re signed in; it removes your profile, saved Baseline snapshots and lifetime PBs. Anonymous uploads leave nothing behind because nothing was stored.

We honour UK GDPR data-subject requests (access, correction, deletion, portability) within the required timeframes — email us if you’d prefer to make the request that way.

Cookies

Baseline uses only the cookies needed to keep you signed in. No third-party advertising cookies, no analytics cookies.

Changes

If we change this policy in a way that materially affects you, we’ll email active users and update the date below.

Last updated: 16 September 2026.