Zone Two

Legal

Privacy Policy

Last updated: June 16, 2026

Who we are

Zone Two Log ("Zone Two", "we", "us") is a training log operated by Zone 2 Athletica LLC. This policy applies to our website at app.zonetwo.co and our mobile apps on iOS and Android.

Data we collect

  • Account information: email address and optional display name when you sign up.
  • Training data: activity type, session type, duration, heart rate, Zone 2 minutes, notes, and dates you log or import.
  • Profile settings: max heart rate, Zone 2 range, and weekly Zone 2 goal.
  • Health platform data (optional): if you connect Apple Health on iOS, we read workout and heart rate data you authorize. We do not write data back to Apple Health.
  • Device and app metadata: platform (iOS, Android, web), app version, and connection status for health integrations.

We do not collect precise location, contacts, photos, payment information, or advertising identifiers.

Apple Health (HealthKit)

On iPhone, you may optionally connect Apple Health. If you do, Zone Two reads workouts and heart rate samples to estimate Zone 2 minutes and import sessions into your log. Access is requested only when you tap "Connect Apple Health" or "Sync now" in Settings. You can revoke access anytime in the iOS Settings app under Privacy & Security → Health → Zone Two.

Health data imported from Apple Health is stored in your Zone Two account like manually logged workouts. We do not sell or share HealthKit data with third parties for advertising or marketing.

How we use data

We use your data to:

  • Provide the training log, dashboard, and weekly progress views
  • Calculate Zone 2 metrics based on your profile and heart rate data
  • Sync workouts from Apple Health when you request a sync
  • Operate and improve the service

We do not sell your personal data. We do not use your data for third-party advertising.

Third-party services

We use trusted infrastructure providers to run Zone Two:

  • Supabase — authentication and database (PostgreSQL). Data is encrypted in transit (TLS). Row-level security limits each user to their own profile and workouts.
  • Vercel — hosts the web application.
  • Expo / EAS — builds and distributes the mobile apps.

These providers process data on our behalf under their own privacy and security terms. We do not share your training data with analytics or ad networks.

Data retention

We retain your account data while your account is active. When you delete your account, we permanently delete your profile, workouts, and health connection records from our database. Backups may persist for a limited period before being overwritten.

Your rights and account deletion

You can delete your account at any time from Settings → Delete account in the web or mobile app. Deletion is permanent and removes your training data from our systems.

You may also request access, correction, or deletion by emailing support@zonetwo.co. We respond within a reasonable timeframe.

Children's privacy

Zone Two is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.

International users

Zone Two is operated from the United States. If you use the service from outside the U.S., your data may be processed in the U.S. where our providers host infrastructure.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use after changes means you accept the updated policy.

Contact

Zone 2 Athletica LLC · Miami, FL
Email: support@zonetwo.co
Support: app.zonetwo.co/support