Legal

Security

How your data is protected. Only what is true today; nothing aspirational.

Last updated 6 October 2026 · Applies to lankfit.com and app.lankfit.com

1. Encryption in transit

All traffic to LankFit is served over HTTPS (TLS). Your browser and our servers talk over an encrypted connection.

2. Encryption at rest

Your data lives in a database on an encrypted Fly.io volume in Johannesburg. A continuous copy and daily snapshots go to a private off-site storage bucket that only LankFit can reach.

3. Per-user data separation

Every record is tied to one athlete, and every request checks that the logged-in athlete owns the data it asks for. One athlete cannot see another's data.

4. Strava and Garmin connections

Strava connects through its official authorisation page, so we never see your Strava password. Garmin asks you to sign in once with your Garmin details; we use them only to get an access token from Garmin and never store your password. The tokens are kept in our database, used only to read your data, and deleted when you delete your account. Disconnecting stops access, and you can also revoke it from Strava's or Garmin's own settings.

5. Passwords

Passwords are stored hashed with bcrypt, never in plain text. Repeated wrong passwords lock that login out for a while.

6. Backups

Your data is copied off-site continuously, with daily snapshots on top. Snapshots are kept for 30 days and restored only to recover from failure.

7. Access controls

Access to production systems is limited to the people who need it to run LankFit, and protected by strong passwords and a two-step login code. Operator sessions expire after 12 hours, and every action an operator takes on a member's account is logged.

8. Reporting a vulnerability

If you find a security problem, please email [email protected] with the details. We will acknowledge it, fix it, and credit you if you want. Please don't access other people's data while testing.

Questions

Write to [email protected] or use the contact form.