Last updated: 21 August 2026
Translation. This document was drawn up in French; this English version is a translation provided for your convenience. In the event of any discrepancy, only the French version is authoritative.
This privacy policy describes how Stibia (https://www.stibia.com) collects, uses and protects the personal data of its users, in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679).
The data controller is the publisher of the Stibia application, available at https://www.stibia.com.
For any question regarding your personal data, you can contact us at: privacy@stibia.com.
We collect the following categories of data:
Each processing operation rests on a legal basis:
The statistics we produce to understand how the service is used and to improve it are aggregated: they cover groups of users and cannot identify you. In that form they may be published or shared. Your personal data itself is never sold or transferred to third parties for commercial purposes.
If you connect your Garmin account, Stibia accesses the following data via the Garmin API:
This data is used exclusively to display your activities and compute your performance statistics within Stibia. It is never resold or transmitted to third parties, except for the AI provider described in section 4 bis, and only when you yourself trigger a program generation.
In addition, if you explicitly request it, Stibia can send the structured workouts you created in the application to your Garmin Connect account. No data is transmitted to Garmin without an action on your part.
You can revoke access at any time from your profile (the “Garmin Connect” section) or directly from your Garmin Connect account.
If you use the optional program-generation feature (“Built-in AI Coach”), and only when you explicitly trigger it, Stibia sends a summary of your training data to an artificial-intelligence provider in order to produce a personalized program.
The data transmitted is limited to what is necessary for this purpose (recent activities and competition goals) and no identifying data (name, first name, email, phone) is sent to the AI provider.
This provider acts as a processor and may be located outside the European Union (in particular the United States); such transfers are then governed by appropriate safeguards under the GDPR (the European Commission's Standard Contractual Clauses). The data is used solely to generate your program, is not used for advertising, and is retained by the provider only for as long as necessary for processing and security, in accordance with its own terms.
This feature relies on your explicit consent: it is activated only by your action and is never used without your request. You may choose not to use it, with no impact on the rest of the service.
If you take out a paid subscription, payment is handled by our provider Stripe (Stripe Payments Europe Ltd). Stibia neither collects nor stores your card details: they go directly to Stripe, which acts as a processor.
Stripe may transfer data outside the European Union, in particular to the United States; such transfers are governed by appropriate safeguards under the GDPR (the European Commission's Standard Contractual Clauses). Stripe processes this data in accordance with its own privacy policy.
We keep billing data (amount, date, transaction identifier, subscription status) for the legal retention period applicable to accounting records, namely ten years.
Stibia never sells, rents or transfers your personal data to third parties for commercial purposes.
Data may be shared in the following cases:
Each category has its own retention period:
In accordance with the GDPR, you have the following rights:
To exercise these rights, contact us at privacy@stibia.com. We undertake to respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority: in France the CNIL (Commission Nationale de l'Informatique et des Libertés), https://www.cnil.fr, or the authority of the country where you habitually reside.
We implement appropriate technical and organisational measures to protect your data: HTTPS encryption, password hashing (bcrypt), restricted access to production data, regular backups.
Stibia uses no tracking or advertising cookies. An authentication token is stored in your browser's local storage (localStorage) to keep your session, and is removed when you sign out. A cookie also keeps the language you chose, so that pages are served to you in that language.
We reserve the right to amend this policy at any time. In the event of a substantial change, you will be notified by email or through the application.
Stibia — privacy@stibia.com — Hosted in France (European Union)