bakken.run
bakken.run

Privacy Policy

Effective date: 9 July 2026

Thank you for using bakken.run. Your privacy is important to us. This Privacy Policy explains how we collect, use, store, share, and protect personal information in connection with bakken.run, including the bakken.run mobile application, supporting website, server-side backend, Garmin integration, Intervals.icu integration, workout synchronization, connected training data, recovery-related data, and digital endurance training services operated by Bakken Performance AS.

1. bakken.run app and connected training platforms

bakken.run is a native mobile running coaching application with a supporting website and secure server-side backend. The app provides individualized running plans, structured workouts, threshold-based intensity guidance, completed-workout analysis, recovery-aware recommendations, and adaptive training adjustments for runners training from 10 km to the marathon. The same user-facing functionality will later also be available through a small companion web portal, using the same backend and the same user accounts.

bakken.run is operated by Bakken Performance AS, a Norwegian company founded by Marius Bakken, MD, a physician, former Olympic 5000-meter runner, and endurance training author based in Norway.

bakken.run works alongside the training devices, wearable platforms, and workout-analysis tools that runners already use. This may include Garmin Connect, Intervals.icu, Strava, COROS, Apple Health, and similar services, but only when the user explicitly chooses to connect such a service. We do not access data from any connected platform unless the user has authorized that connection through the relevant authorization process.

Connected-platform data is used only to provide the bakken.run training service to the individual user. We do not sell connected-platform data, broker it, resell it, use it for advertising, or share it for third-party profiling.

2. Who we are

Bakken Performance AS operates bakken.run. Since 2009, Bakken Performance AS has operated online running and marathon training services, including the 100 Day Marathon Plan. bakken.run modernizes this training system into a native mobile running coaching application supported by a secure server-side backend.

3. Information we may collect

Depending on the service used and the permissions granted by the user, we may collect the following categories of information:

We only collect connected-service data when the user has explicitly authorized that connection through the relevant third-party authorization process.

4. Garmin Connect data

If a user chooses to connect Garmin Connect, bakken.run uses Garmin’s OAuth authorization flow to access only the Garmin data needed to provide training guidance, workout planning, recovery-aware recommendations, structured workout delivery, and completed-workout analysis.

Garmin data is linked only to the user’s own bakken.run account and is used only to provide user-facing training functionality inside bakken.run.

4.1 Garmin Activity API

Garmin activity data may include activity type, start time, duration, distance, pace, speed, heart rate, cadence, laps, intervals, workout-step execution, elevation, route or track data where needed, and activity summary statistics.

This data is used to compare planned versus completed training, assess threshold intensity, calculate training load, understand adherence, grade-adjust pace on hilly sessions, detect missed or unusually hard sessions, support progression decisions, and adapt future workouts for the individual user.

4.2 Garmin Health API

Garmin health summary data may include resting heart rate, sleep summaries, stress summaries, and overnight HRV summaries where the user has authorized Health API access.

This data is used for readiness assessment and recovery-aware training adjustment. Elevated resting heart rate, suppressed HRV, poor sleep, or high stress may lead bakken.run to recommend an easier session, reduced intensity, or additional recovery.

bakken.run does not request continuous raw health streams, respiration, blood-oxygen data, or all-day epoch data unless this Privacy Policy is updated and the user is informed where required.

4.3 Garmin Women’s Health API

Garmin menstrual-cycle data may be imported only where the user has separately and explicitly opted in to Women’s Health API access. This opt-in is separate from the general Garmin connection.

Menstrual-cycle data is used only as training context for the individual user, including interpretation of recovery status, readiness, training tolerance, workout selection, and progression. bakken.run does not use pregnancy data. Where a Women’s Health summary includes pregnancy-related information because the user tracks a pregnancy in Garmin Connect, the summary is discarded on receipt and is not stored or processed. bakken.run does not request or store symptom logs through this integration.

Menstrual-cycle data is treated as special category data under GDPR Article 9, with explicit consent as the lawful basis. The user may withdraw this consent without disconnecting the full Garmin integration.

4.4 Garmin Training API

bakken.run may use Garmin’s Training API to send structured workouts and training-plan items to the user’s Garmin calendar and compatible devices where the user has connected Garmin and authorized this functionality.

This is the only Garmin integration where bakken.run writes data outward to Garmin. bakken.run does not repost, modify, or delete user activities inside Garmin Connect.

When a user authorizes this functionality, workout and training-plan data is transferred to Garmin. Garmin processes this data under the Garmin Connect privacy notice, available at https://www.garmin.com/privacy/connect.

5. Intervals.icu data

If a user chooses to connect Intervals.icu, bakken.run may receive training and performance data authorized by the user, such as completed workouts, activity summaries, training load, intensity distribution, workout calendar information, heart rate or power-related summaries where available, and related performance metrics.

Intervals.icu data is used only to support training analysis, plan adjustment, workout interpretation, and coaching recommendations for the individual user. It is not sold, brokered, resold, used for advertising, or shared for third-party profiling.

Users may disconnect Intervals.icu inside bakken.run where available or revoke access through Intervals.icu. When access is disconnected or revoked, further syncing stops.

6. Other connected training platforms

bakken.run may support other connected training platforms or health services, such as Strava, COROS, Apple Health, and similar services. These integrations are used only when the user explicitly chooses to connect them.

Data from other connected platforms may include completed activities, activity summaries, workout calendar data, distance, duration, pace, heart rate, cadence, elevation, training-load summaries, and similar training-related metrics, depending on the platform and the permissions granted by the user.

Data from connected platforms is used only to provide training analysis, workout planning, recovery-aware recommendations, and coaching functionality to the individual user. It is not sold, brokered, resold, used for advertising, or shared for third-party profiling.

7. Third-party integration summary

Platform Data accessed Direction Purpose
Garmin Connect Activity API Completed activity data including distance, pace, duration, heart rate, cadence, laps, intervals, elevation, route data where needed, and summary statistics Read Planned-versus-completed analysis, training-load evaluation, progression decisions, and workout adaptation
Garmin Connect Health API Limited daily recovery summaries including resting heart rate, sleep summaries, stress summaries, and overnight HRV summaries Read Readiness assessment and recovery-aware training adjustment
Garmin Connect Women’s Health API Menstrual-cycle tracking summaries, with separate explicit opt-in; summaries containing pregnancy-related information are discarded on receipt Read Cycle-aware training context for female runners
Garmin Connect Training API Structured workouts and training-plan items Write Delivery of planned workouts to Garmin calendars and compatible devices
Intervals.icu Completed workouts, activity summaries, training load, intensity distribution, calendar information, and related performance metrics where authorized Read, and only where authorized, limited write/synchronization features Training analysis, plan adjustment, workout interpretation, and coaching recommendations
Other connected training platforms Training and activity data authorized by the user Read, and only where authorized, limited write/synchronization features Training analysis, workout planning, and user-facing coaching functionality

8. What we do not do with connected-platform data

Bakken Performance AS does not sell Garmin data, Intervals.icu data, or other connected-platform data. We do not broker, resell, use, or disclose connected-platform data for advertising, third-party profiling, or commercial resale. We do not share connected-platform data with third parties for their own AI or machine-learning model training. Where connected-platform data is used to improve bakken.run’s own training logic, readiness models, or AI-assisted features, this is done only as permitted by the relevant platform rules, applicable law, and the user’s consent choices, as described in section 15.

bakken.run does not repost, modify, or delete activities inside Garmin Connect. The only planned outbound Garmin write is sending structured workouts or training-plan items to Garmin when the user has connected Garmin and authorized that functionality.

For other connected platforms, bakken.run will only perform write or synchronization actions where the user has clearly authorized that feature.

9. How we use personal information

We may use personal information to:

10. Legal basis for processing

For users located in the EU/EEA, personal information is processed under one or more of the following legal bases under the General Data Protection Regulation:

11. Sharing of personal information

We do not sell personal information. We may share personal information only where necessary and appropriate, including with:

Service providers may process data only for the purposes of providing services to bakken.run and are not permitted to use personal information for their own independent purposes unless separately disclosed or legally required.

12. Data storage and region

Garmin-related user data at rest is stored in a Supabase/Postgres database provisioned in an EU region. Other connected-platform data may also be stored in the same EU-region database where needed to provide the service.

Backend processing runs on managed cloud infrastructure where exact server locations are provider-controlled; EU/EEA regions are selected where the platform allows region configuration.

Bakken Performance AS operates from Norway, inside the EEA, and complies with GDPR as data controller, including user access, export, correction, restriction, disconnection, and deletion rights.

13. Data protection and security

We use technical and organizational measures designed to protect personal information, including:

No method of transmission or storage is completely secure, but reasonable steps are taken to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

14. Data retention, disconnection, and deletion

Personal information is retained only for as long as necessary to provide the service, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.

Users can disconnect Garmin, Intervals.icu, or other connected platforms inside bakken.run where available, or revoke access directly through the connected platform. When access is disconnected or revoked, further syncing stops.

Where technically possible, Garmin OAuth tokens and other connected-platform tokens are deleted or revoked when the user disconnects the relevant service. On account deletion or a deletion request, stored connection data, OAuth tokens, and connected-platform-derived training records are deleted in line with this Privacy Policy and GDPR.

Stored Garmin-derived and connected-platform-derived training records are deleted on account deletion within 30 days, unless retention is required or permitted by law. Backup copies are purged within 60 days where technically possible.

Historical connected-platform-derived activity records already imported into bakken.run remain in the user’s account unless the user deletes the account, requests deletion, disconnects the relevant service in a way that requires deletion, or this Privacy Policy states otherwise.

15. AI processing

bakken.run may use Anthropic’s Claude API to support user-facing training features, including completed-run interpretation, weekly coaching check-ins, recovery-aware training comments, and plan adjustments when a user logs missed training, injury feedback, unusually high fatigue, or “not feeling great” feedback.

Garmin-derived data is not processed by AI unless the user has given separate, explicit in-app consent for AI-assisted training interpretation. This AI consent is separate from the general Garmin connection. The user may withdraw AI consent at any time without disconnecting Garmin.

For each AI request, bakken.run sends only the data needed for the specific training feature. This may include structured training history, planned versus completed workouts, distance, duration, pace, heart rate summaries, cadence, elevation, workout execution, recent training load, readiness markers, subjective training notes, plan context, race goal, phase of training, and recent race results where relevant. If the user has separately opted in to Garmin Health API access, this may also include recovery-related summaries such as resting heart rate, sleep summaries, stress summaries, and overnight HRV summaries. Menstrual-cycle data is sent to AI only if the user has separately opted in to Women’s Health API access, separately opted in to AI processing, and the feature specifically requires cycle-aware training context.

bakken.run does not send Anthropic any Garmin OAuth tokens, Garmin client secrets, Intervals.icu access tokens, other connected-platform tokens, payment information, address, phone number, or unrelated personal identifiers.

Anthropic processes API request data according to Anthropic’s Privacy Policy and commercial API terms. Anthropic states that API request data from commercial products is not used to train its models by default.

bakken.run may use training data in de-identified or aggregated form to improve the service, including training logic, readiness models, workout recommendations, and product quality. Garmin-derived data is used for AI or machine-learning model development only where permitted by Garmin’s developer rules, applicable law, and the user’s explicit consent. Data that identifies an individual user is not used to train AI or machine-learning features without the user’s separate consent. Connected-platform data is never sold or shared with third parties for their own model training.

AI features are used only to support training guidance for the individual user. They are not medical diagnosis, medical treatment, emergency monitoring, or a substitute for professional medical advice.

16. User rights

Depending on location and applicable law, users may have the right to:

To exercise these rights, contact us using the details below.

17. Third-party services

bakken.run may integrate with or link to third-party services, including Garmin Connect, Intervals.icu, Strava, COROS, Apple Health, and other training-related platforms. Those third-party services have their own privacy policies and terms. Users should review those policies before authorizing any connection. Garmin’s privacy practices are described in the Garmin Connect privacy notice at https://www.garmin.com/privacy/connect.

When a user authorizes Garmin Connect, Garmin may show the data categories and permissions that the user can control from their Garmin Connect account.

18. Children’s privacy

bakken.run is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16 without appropriate consent. If such information is collected without appropriate consent, steps will be taken to delete it.

19. International transfers

Personal information may be processed in countries outside the user’s country of residence. Where required, appropriate safeguards are used for international transfers of personal information.

For EU/EEA users, we aim to use EU/EEA infrastructure where practical and available, especially for Garmin-related data storage and connected-platform-derived training data.

20. Medical and training disclaimer

bakken.run provides training guidance, readiness interpretation, workout planning, and running-performance support. It does not provide medical diagnosis, medical treatment, or emergency health monitoring.

Health, HRV, sleep, stress, menstrual-cycle, and recovery data are used only as training context. Users should consult a qualified healthcare professional for medical concerns, injuries, illness, pregnancy-related questions, or health symptoms.

21. Updates to this policy

This Privacy Policy may be updated from time to time. The updated version will be posted on this page with a revised effective date.

The Privacy Policy will be updated before any material change in Garmin data scope, additional Garmin summary types, new third-party integrations, AI processing providers, data-sharing practices, or new purposes for processing.

Material changes will be communicated through the app, website, or on first login after the update where required.

22. Contact

For questions about this Privacy Policy or how personal information is handled, contact:

Bakken Performance AS
Marius Bakken
Borghilds vei 15a
4633 Kristiansand
Norway
Email: marius@bakken.run
Website: https://bakken.run

This policy describes privacy practices for bakken.run and connected-service integrations, including Garmin Connect, Intervals.icu, and other connected training platforms where authorized by the user.