Privacy & Security
Last updated: 3 October 2026
GM Manager is a companion web app for your Speediance machine, built by GMVoice. Because you trust it with your Speediance login, here is exactly what happens to your password, your tokens, and your data - in plain language.
What data is processed & who sees it
Speediance sign-in. Your e-mail and password are sent to Speediance's servers to log in and sync your workouts, history and settings. Speediance is a third party with its own privacy policy.
Encrypted credential storage. So you - and any AI assistant you connect over MCP - can act on your account, your password is stored encrypted on our server. Logging out and revoking AI tokens removes that access.
Usage analytics (optional). Only if you opt in.
No selling. We never sell your data or use it for advertising. Unofficial tool - not affiliated with Speediance.
1. Who we are
GM Manager (by GMVoice) is operated by Tech Cloud s. r. o., a company registered in Slovakia (EU), which is the data controller for the personal data described here.
Registered operator: Tech Cloud s. r. o., Tomášikova 12573/50E, 831 04 Bratislava – Nové Mesto, Slovakia · Company ID (IČO): 56 483 970
Contact for any privacy question: contact@gmvoice.tech
2. Your password - and exactly how we protect it
Signing in is handled by Speediance, not by us. When you log in, your e-mail and password travel over an encrypted (HTTPS) connection to Speediance's own servers, which check them. We do not run a separate password system.
So that you - and any AI assistant you choose to connect - can keep acting on your account after Speediance's short-lived access token expires, we store your Speediance password encrypted on our server, using authenticated encryption (Fernet / AES).
Signing in from the GMVoice app sends no password at all: the app passes the Speediance session token it already holds. We check that token with Speediance and sign you in. Only once you agree on the consent screen do we store the token, encrypted (Fernet / AES), and every sign-in from the app stores the current token again in place of the old one; until you agree nothing is stored, and the coach, calendar sync and AI connections stay unavailable. Once stored, they work until the token expires. For such a sign-in, signing out or removing your profile here does not end the session of your Speediance machine.
Being straight with you about one detail: this is reversible encryption, not a one-way “hash”. It has to be - Speediance does not issue a refresh token, so when your session expires the server needs your password to sign in again on your behalf. To keep that safe:
- The key that decrypts it lives only in a protected server setting - never in the database and never in our source code. The locked password and the key to unlock it are kept apart.
- Your password is never written to disk in plain text, and never written to any log.
- You can revoke this stored access whenever you want, by removing your profile (see §7).
3. Session, AI & calendar tokens
- Your web session is held in a cookie that is signed (tamper-proof), sent only over HTTPS, and not readable by page scripts. A copy of the session token is also cached encrypted on our server.
- Tokens outlive the session that made them. An AI (MCP) token, an API token or a calendar-feed link you create stays valid until you revoke it, not until the sign-in you created it in ends - so keep each one like a password. A sign-in from the GMVoice app lasts 24 hours and cannot create any of them; sign in with your Speediance password on the website to do that.
- AI connections (MCP): the tokens an AI assistant uses are stored only as a one-way SHA-256 hash - the full token is shown to you once and never kept. You can revoke any connection at any time on the Connect AI page.
- Calendar subscriptions (.ics): optional, and off until you create one. A calendar app fetches your feed without signing in, so the link itself carries a secret token - which means anyone who has the link can read your training calendar. Treat it like a password and don't publish it. The token is stored only as a one-way SHA-256 hash and shown to you once; the feed is read-only and can't change anything in your account. Because the token travels in the link's address, it can appear in server request logs - another reason to treat the link like a password. Delete a link at any time in Settings → Calendar sync: we stop serving it at once, though a calendar app that already fetched it may show a cached copy for a few more minutes.
4. What we store
| Data | Why |
|---|---|
| Your e-mail | Identifies your account. |
| Encrypted Speediance password & session token | So we can sign in on your behalf when the short-lived token expires (see below). |
| Session token from the GMVoice app (no password) | If you sign in from the GMVoice app, it passes the Speediance session token it already holds instead of a password. We check it with Speediance and, only once you have agreed on the consent screen, store it encrypted - and each sign-in from the app stores the current token again, replacing the previous one - so the coach, calendar sync and AI connections work until it expires. Nothing is stored before you agree. No password is involved and none is stored for such a sign-in. |
| Your preferences & coaching notes | To personalise plans. These can include things you tell the AI assistant - goals, schedule, or injuries. |
| Minimal usage records | To see which features are used and to diagnose errors. No IP addresses and no full health data are stored. |
| Hashed AI access tokens | So the AI assistants you authorise can connect. Only a one-way hash is kept - never the token itself. |
| Hashed calendar-feed tokens | So a calendar app you subscribe from can read your training calendar. Only a one-way hash is kept - never the token itself. |
5. Analytics - optional, and off by default
Nothing analytics-related loads until you tick the box. If - and only if - you opt in, we use:
- Microsoft Clarity - session replay & heatmaps that show us where the app is confusing. Your session is tagged with your e-mail so we can find your recordings if you ask us for support.
- Vercel Web Analytics - aggregate traffic and performance numbers.
You can turn analytics off any time in Settings → Privacy. We never use it for advertising.
6. Who else touches your data
We keep the list of providers short, and we never sell your data.
| Provider | Role | Location |
|---|---|---|
| Speediance | The upstream service that holds your account and training data, and that verifies your login. A separate company with its own privacy policy. | - |
| Render | Runs our backend servers and hosts our database - stores the encrypted credentials, your preferences and notes. | United States (Oregon) |
| Vercel | Delivers the web app and routes its API calls. | Global |
| Comgate (Comgate, a.s.) | Takes payment for a paid subscription from a card issued in the European Economic Area, or by a bank payment button. It receives your e-mail address and the amount, and you enter your card details on its own page, so we never see or store your full card number. | Czech Republic (EU) |
| Link (Stripe) | Sells a paid subscription to buyers outside the European Economic Area, or paying with a card issued outside it, as the seller of record ("Sold through Link"). It is not our processor: it is an independent controller of what it collects at its own checkout, such as your e-mail address, billing address and card details, under its own privacy policy, and you can ask it to delete that data. We never see or store your full card number. From it we receive the status of the subscription, the amount and your billing country, which is what we need to give you access. | See its privacy policy |
| Microsoft Clarity | Usage analytics - only ever loaded if you opt in. | United States |
| YouTube (Google) | Hosts our demo video. The player loads only when you press play - never on page load - and we use the no-cookie version. | Global |
| AI assistants you connect | Receive your training data to plan workouts - at your request, and only what you connect them to. | - |
International transfers: some of these providers process data outside the EU, including in the United States. Your data is always protected in transit (HTTPS/TLS) and, for credentials, encrypted at rest; transfers rely on those providers' standard data-protection safeguards.
7. Deleting your data
Open Settings → Privacy → Remove my profile. This permanently deletes everything we store about you - your encrypted credentials, preferences, coaching notes, AI tokens, calendar links and usage records - and logs you out. It cannot be undone.
Two things worth knowing: simply logging out does not delete your stored credentials - only “Remove my profile” does. And your Speediance account itself (your workouts and history) is not affected; we never delete anything on Speediance's side.
8. Your rights (GDPR)
As an EU operator we follow the principles of the GDPR and respect your rights: to access, correct, delete or export your data, to object to or restrict processing, and to withdraw consent (such as analytics) at any time. Most of this you can do yourself in Settings; for anything else, e-mail contact@gmvoice.tech and we will help. You also have the right to lodge a complaint with a data-protection authority - your local one, or our supervisory authority in Slovakia, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky).
9. How long we keep it
We keep your data for as long as your account is active. When you remove your profile, it is deleted immediately (as above). We keep only minimal usage records to run the service reliably - never full health data, and never IP addresses.
10. Not affiliated with Speediance
GM Manager is an independent, unofficial tool built by GMVoice. It is not made or endorsed by, or affiliated with, Speediance. The name “Speediance” is used only to describe the machine this app works with.
11. Changes to this policy
If we change how we handle your data, we will update this page - and for anything material, we will ask you to review the updated terms the next time you sign in.
12. Trainers and athletes
A subscriber to the Trainer plan can act for athletes who have linked with them. This is a service you ask for, and it works like this:
- You decide. A link exists only after you ask a trainer and they accept, or after you ask us to link you. Nobody can link you on their own. You can end the link at any time from the Trainer page, and the trainer can remove you too.
- What a linked trainer can do. Through the MCP connector and the REST API, the trainer can read and change your workouts, calendar, history and health data, as the connector does for your own account. They use the Speediance session we already hold for you; we never sign in for you, and the trainer never sees your password or your token.
- On your instruction. The trainer handles that data on your instruction and for your training. The trainer is responsible for what they do with what they read, including anything they copy out of GM Manager. We are the controller of the data we store, and we do not give the trainer access to anything outside the link.
- What the trainer sees about you. Your name and e-mail address, whether your Speediance sign-in is still valid, and your latest workout. A trainer who lists themselves in the directory shows a display name and a short bio to other users, never an e-mail address.
- Notices. We e-mail the other side when a link is requested, accepted, declined or ended, and when an account that was linked is deleted. We keep a usage record of calls made for an athlete, under the trainer's account, with the athlete noted so that it can be traced.
- When it stops. The access stops when either of you ends the link, when the trainer's plan ends (the link pauses and the trainer cannot act until the plan is active again), or when either account is deleted. Removing your profile (§7) also removes your link.
Technical details (for the security-minded)
- Encryption at rest: Fernet (AES-128-CBC + HMAC-SHA-256). The key is held in a server environment variable, never in the database or the codebase.
- Passwords: reversibly encrypted by design (no refresh token upstream - see §2); never hashed, never logged; otherwise held in memory only for the duration of a login request.
- Session cookie: signed with a server secret, HttpOnly, Secure, SameSite=Lax. It renews while you use the app and ends at the latest 90 days after you signed in (sign-ins from the GMVoice app: 24 hours).
- AI tokens: SHA-256 hashed at rest; the raw token is shown once.
- Calendar-feed tokens: SHA-256 hashed at rest, in their own store separate from the AI tokens; the raw link is shown once. The feed is read-only and serves nothing but your own calendar; the URL is marked no-index and never cached by shared caches.
- Transport: HTTPS everywhere; database connections require SSL.
- Hardening: HSTS, a strict Content-Security-Policy, X-Frame-Options: DENY (no embedding), X-Content-Type-Options: nosniff, Referrer-Policy: no-referrer, brute-force login throttling, and CSRF origin checks.
Questions about your privacy? E-mail contact@gmvoice.tech.