Privacy policy
Last updated: 28 July 2026
1. Who we are (data controller)
Crux (cruxrace.com) is operated by Sweet Deal SL, a company registered in Spain (“we”, “us”). Sweet Deal SL is the data controller for the personal data described in this policy under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Privacy contact: langelk@gmail.com
2. What data we collect, why, and on what legal basis
a. Marketing list (legacy preview waitlist)
- Status: Crux is now open to everyone, so we no longer collect new waitlist sign-ups. We retain the addresses already collected (and honour every unsubscribe) until erasure or the retention limit below.
- Data: your email address, the consent choices you made (recorded verbatim, with timestamps), confirmation status.
- Purpose: contacting you about Crux; and — only if you separately opted in — sending occasional news, training insights and product updates.
- Legal basis: your consent (Art. 6(1)(a) GDPR), collected via double opt-in. You can withdraw consent at any time via the unsubscribe link in every email — withdrawal is as easy as signing up.
b. Your Crux account
- Data: username, password (stored only as a salted cryptographic hash), optional email and full name, your athlete profile (level, objectives, fitness notes, philosophy), race plans, fuelling plans, debrief notes, and feedback you submit in the app.
- Purpose: providing the Crux service — building and storing your race strategies.
- Legal basis: performance of a contract (Art. 6(1)(b)) — the data is needed to provide the service you signed up for.
c. Public race-results data
- Data: if you connect your runner profiles (UTMB Index, ITRA, DUV), we import your publicly available race history and performance indexes from those sources, always at your request and visible to you.
- Legal basis: performance of a contract (Art. 6(1)(b)); you initiate each import and can delete the data from your profile at any time.
d. Crux Beacon — live race tracking (location, microphone, camera)
Crux Beacon is our companion mobile app. Everything in this section happens only while you have started a live race broadcast, and only on a device where you granted the relevant permission. You can stop a broadcast at any time, and nothing here is collected when no broadcast is running.
- Precise location — including in the background. While a broadcast is active, Beacon collects your GPS position even when the app is closed or not in use, because a race phone lives locked in a vest. We record latitude, longitude, elevation, accuracy, a device timestamp, and your phone's battery percentage (so your crew knows whether the signal is about to stop). We do not collect location when you are not broadcasting, and we never use it for advertising or profiling.
- Microphone. Only when you deliberately record a voice note to send to your crew and followers. Beacon does not listen continuously and never records ambient audio.
- Camera and photos. Only when you deliberately attach a photo to your race feed.
- Purpose: showing your live position, your progress against your plan, and messages to the crew and followers you share a link with; generating the race narration; and building your post-race replay and debrief.
- Legal basis:performance of a contract (Art. 6(1)(b)) — you start each broadcast and it is the service you asked for. Where a device permission is involved we also rely on the consent you give in the operating-system prompt, which you can withdraw at any time in your phone's settings.
- Who sees it:anyone holding a crew or fan link you have shared, for as long as that link is active. Live share links are unlisted and excluded from search engines, but treat them as public — anyone you send one to can pass it on. You can revoke links, and you can hide your position mid-race at any time with the “go dark” switch, which stops your location being shown without ending the broadcast.
e. Connected training accounts
- Data: if you connect Strava, we store your Strava athlete id and name and the access and refresh tokens for the connection, so we can import the activities you ask us to import.
- Use: Strava-derived data is shown only to you — it never appears on crew, fan or public pages, is never used in race narration, and is never used to train AI models. You can disconnect at any time, which deletes the stored tokens.
- Legal basis: performance of a contract (Art. 6(1)(b)); you initiate the connection and every import.
f. Technical & diagnostic data
- Data: server logs and error records (which feature failed, technical error messages), and AI usage metering (tokens consumed per feature) tied to your account.
- Purpose: keeping the service reliable and managing costs.
- Legal basis: our legitimate interest (Art. 6(1)(f)) in operating a secure, functioning service.
3. AI processing
Crux generates race strategies using Anthropic's Claude models. To do that, relevant parts of your data (your athlete profile, goals, the race's course data, your fuelling plan) are sent to Anthropic's API for processing. Anthropic acts as a processor and does not train its models on this API data. We don't send more than the feature needs, and your password and email are never included in AI requests.
4. Who processes your data for us
- Vercel Inc. — hosting and content delivery.
- Neon Inc. — database hosting.
- Anthropic PBC — AI model processing (see section 3).
- Resend (Plus Five Five Inc.) — transactional and (if you consented) news emails.
- Stripe Payments Europe — subscription & payment processing.
- Cloudinary Ltd. — hosting the photos and voice notes you attach to a race feed.
- Google Ireland Ltd. — only if you choose to sign in with Google, which shares your email address and name with us.
These providers may process data in the United States. Transfers are safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR). We do not sell your personal data, and we don't share it with anyone beyond these processors.
Crux moments you explicitly choose to share appear at the community campfire and may be used to ground course strategies for other runners on the same race (any third parties named in your story are already anonymised when the moment is created). Moments you keep private are never shared or reused, and you can unshare a moment at any time.
5. Cookies
Crux uses a single strictly necessary session cookie (rp_session) to keep you signed in. It is essential for the service, so no consent banner is required (it is exempt under Art. 22.2 LSSI). We use no advertising, analytics or third-party tracking cookies.
6. How long we keep data
- Waitlist: until you unsubscribe or ask for erasure, or at most 12 months after the preview programme ends.
- Account data: for as long as your account exists. Ask us to delete your account and all associated data is erased.
- Race-day location traces: kept as part of the race record for that plan — they are what your replay and debrief are built from — and erased with the plan or the account.
- Photos and voice notes: kept with the race feed they belong to and erased with the plan or the account.
- Server logs / diagnostics: up to 12 months, then deleted or anonymised.
7. Your rights
Under the GDPR you can, at any time and free of charge:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased — “right to be forgotten” (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw any consent you gave, without affecting prior processing (Art. 7(3)).
To exercise any of these, email langelk@gmail.com. We respond within one month. If you believe we haven't handled your data properly, you can lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es.
8. Security
Data is encrypted in transit (TLS) and at rest, passwords are stored only as salted scrypt hashes, sessions expire server-side, and admin access is restricted. No internet service can promise perfect security, but we follow current good practice and log errors so we can react quickly.
9. Children
Crux is not directed at children under 14, and we do not knowingly process their data.
10. Changes to this policy
If we make material changes, we'll update this page and the date above, and — where the change affects how we use the email address you gave us — notify you by email before it takes effect.