API terms

Version 1.0 · 2 October 2026

These API Terms govern access to and use of the TrainerPlan API. They add to the Terms and Conditions and the Privacy Policy, which continue to apply to your account. Where they say something different about the API, these API Terms prevail.

1. Who we are and who these terms are for

In compliance with Article 10 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce, the provider of the API is:

Name: Bruno Felicio
Entity: TrainerPlan
Address: Colmenar Viejo, Madrid, Spain
Contact Email: info@trainerplan.co

The API is a professional tool. It is offered to coaches, clubs and businesses acting in the course of their trade, business or profession, not to consumers. "You" means the holder of the TrainerPlan account that requests access, and anyone who uses an API key of that account.

In these terms:

  • API means the TrainerPlan programming interface, its keys, its documentation and its OpenAPI description.
  • API Data means any data obtained through the API, including the personal data of your athletes.
  • Your Tools means the scripts, spreadsheets, applications, AI assistants and third-party services you connect to the API.

2. Access and approval

  • The API is included, at no extra charge, in the subscription plans that list it (currently the Elite plan).
  • Access is requested from Settings > API in your account. The information you give in the request must be true and complete, and you must tell us if your use changes materially, for example if you start using a new third-party service or start making changes through the API.
  • We review every request and may approve or refuse it. We reply by email. Approval is given to your account only and cannot be transferred.
  • Access ends when your subscription no longer includes the API or when your account is closed.

3. API keys

  • Keys can be created by the owner of the account and by its team administrators.
  • A key is confidential. Treat it as a password: do not publish it in code repositories, in applications that run on a user's device or in prompts or documents shared with others.
  • Use a separate key for each tool, and give it no more access than it needs: a key is read-only unless you decide otherwise.
  • You are responsible for everything done with your keys, including by Your Tools and by the people you give them to.
  • If a key has been exposed, or you suspect it has, revoke it at once in Settings > API and tell us without undue delay (see Section 6.4).

4. Permitted use

You may use the API to:

  • read and manage your own coaching account from Your Tools;
  • build reports, dashboards and analyses for your coaching;
  • plan workouts, notes and events for your athletes and comment on their sessions;
  • connect an AI assistant or a third-party service that acts on your behalf and under your responsibility.

5. Prohibited use

You may not, and may not allow anyone else to:

  • sell, rent, license or otherwise disclose API Data to third parties for their own purposes;
  • use API Data for advertising, for profiling unrelated to coaching, or for decisions about insurance, employment or credit;
  • train, fine-tune or evaluate artificial intelligence or machine-learning models with athletes' personal data, or allow a provider to do so;
  • build a product or service that competes with TrainerPlan, reproduce a substantial part of the platform's data, or resell or sublicense access to the API;
  • access accounts or athletes you are not authorised to access, get around rate limits, authentication or other technical restrictions, or test the API for vulnerabilities without our written permission;
  • misrepresent who you are or what your tool does, or suggest that TrainerPlan endorses it;
  • use the API against the law or the rights of others.

6. Personal data and the GDPR

6.1 What the API contains. API Data includes personal data of your athletes and, among it, data concerning health within the meaning of Article 9 of Regulation (EU) 2016/679 (GDPR): heart rate, heart rate variability, sleep, weight and similar metrics.

6.2 Roles. Inside the platform, personal data is processed as described in the Privacy Policy. When you take API Data out to Your Tools, you decide why and how it is processed there. For that processing you are the data controller, independently of TrainerPlan, and TrainerPlan is neither controller nor processor of it.

6.3 Your obligations. For the API Data you process in Your Tools, you undertake to:

  • Lawful basis. Have a legal basis under Article 6 GDPR and, for health data, a condition under Article 9(2) GDPR, normally the athlete's explicit consent, before their data reaches Your Tools or any third party, and be able to demonstrate it.
  • Information. Tell your athletes, as Articles 13 and 14 GDPR require, which tools and recipients receive their data (including any AI provider), for what purposes, for how long and how to exercise their rights.
  • Minimisation. Request and keep only the data you need for the purpose.
  • Security. Apply appropriate technical and organisational measures (Article 32 GDPR): store keys and API Data securely, encrypted where possible, and limit who can reach them.
  • Processors. Have a written data processing agreement (Article 28 GDPR) with every provider that processes API Data on your behalf, including AI assistant and cloud providers, and use services and settings under which that data is not used to train models.
  • International transfers. Send API Data outside the European Economic Area only to a country with an adequacy decision or with appropriate safeguards under Chapter V GDPR, such as the Standard Contractual Clauses or the EU–U.S. Data Privacy Framework.
  • Retention and erasure. Delete API Data when you no longer need it and, in any case, when the athlete stops training with you, withdraws consent or asks for erasure, unless the law requires you to keep it.
  • Athletes' rights. Answer your athletes' requests for access, rectification, erasure, restriction, portability and objection for the copies you hold.
  • Minors. If you coach minors, obtain the authorisation of their parents or guardians where the law requires it (in Spain, for those under 14).
  • Automated decisions and AI. Take no decision about an athlete based solely on automated processing that produces legal or similarly significant effects (Article 22 GDPR); have a qualified person review any AI-generated training before it is applied; and, where you use AI systems, meet your own obligations under Regulation (EU) 2024/1689 (AI Act), including telling athletes when content is generated by AI where that is required.

If you are established outside the European Economic Area, you commit to protect athletes' data to the standard of this section whenever the GDPR applies to them, and to comply with the data protection law that applies to you.

6.4 Security incidents. You must notify us at info@trainerplan.co without undue delay, and no later than 48 hours after becoming aware of it, of any exposure of a key and of any personal data breach affecting API Data, stating what happened, the data and athletes affected and the measures taken. You remain responsible for your own notifications to the supervisory authority and to the athletes (Articles 33 and 34 GDPR).

6.5 What we process. To operate, secure and limit the API we keep the information in your access request, the number of requests and changes made with each key per day, and standard server logs. The legal bases are the performance of the contract with you and our legitimate interest in the security of the service. The Privacy Policy describes your rights and how to exercise them.

6.6 Objections. If an athlete objects to their data being taken out through the API, or an authority requires it, we may ask you to stop accessing that athlete's data and to delete the copies you hold, and you must do so.

7. Changes you make through the API

  • A change made with a key has the same effect as one made by you in the app: the athlete is notified and it is sent to their devices.
  • You are responsible for the changes made with your keys. Test your tools with care; we may not be able to undo what they do.
  • Sections 11 (Sports Liability Disclaimer) and 12 (AI-Assisted Features) of the Terms and Conditions apply to everything planned through the API, including what an AI assistant plans on your behalf.

8. Limits, availability and changes to the API

  • The API has rate limits and other limits, published in its documentation. We may adjust them.
  • The API is provided as it is, without a guaranteed level of availability, and may be interrupted for maintenance or for reasons beyond our control. Do not make anything safety-critical depend on it.
  • We may add to, change or withdraw parts of the API. For a change that breaks a published version we will give at least 30 days' notice by email, unless a shorter period is needed for security, to protect personal data or to comply with the law.

9. Suspension and termination

You may stop using the API at any time by revoking your keys.

We may suspend or revoke your keys or your access, immediately where necessary, if:

  • you breach these terms or the Terms and Conditions;
  • a key has been exposed or there is another security risk;
  • there is a risk to athletes' personal data or rights;
  • your use puts an abnormal load on the service;
  • the law or an authority requires it.

We will tell you the reasons at the time or as soon as possible afterwards, and you will be able to respond. Where the cause can be remedied, we will restore access once it has been.

When access ends you must stop using the API, and your keys stop working. Sections 5, 6, 10 and 11 continue to apply to the API Data you still hold.

10. Intellectual property

  • The API, its documentation and its OpenAPI description belong to TrainerPlan. While you have access, we grant you a limited, non-exclusive, non-transferable and revocable licence to use them as these terms allow.
  • Your content and your data remain yours. Nothing in these terms transfers ownership of them to us, or of the API to you.
  • You may state truthfully that your tool works with TrainerPlan. You may not use our name or logo in a way that suggests a partnership or endorsement without our written permission.
  • If you send us suggestions about the API, we may use them without obligation to you.

11. Liability

To the extent the law allows:

  • we are not liable for Your Tools, for third-party services, for the output of AI systems, or for what happens to API Data once it has left the platform;
  • we are not liable for indirect damage, loss of profit, loss of business or loss of data in Your Tools;
  • our total liability for claims related to the API is limited to the amount you paid for your subscription in the 12 months before the event that gave rise to the claim.

Nothing in these terms limits liability for wilful misconduct or gross negligence, for death or personal injury, or any other liability that cannot be limited by law.

You will hold TrainerPlan harmless from claims, penalties and costs brought by third parties, including athletes and authorities, that arise from your breach of these terms or of data protection law in your use of API Data.

12. Changes to these terms

We may change these API Terms. We will notify you by email at least 30 days before a change takes effect, saying what changes. If you do not agree, you must stop using the API and revoke your keys before that date; continuing to use the API after it means you accept the new terms. Changes required by law or for security may apply sooner.

We keep a record of the version you accepted and the date.

13. Applicable law and jurisdiction

These API Terms are governed by Spanish law. For any dispute arising from them, the parties submit to the courts of the city of Madrid, Spain, expressly waiving any other jurisdiction that may apply.

These terms are available in several languages. If there is a discrepancy between versions, the Spanish version prevails.

14. Contact

For any question about these API Terms, write to info@trainerplan.co.