Skip to content
Product Routes Equipment Learn FAQ Studio Beta
Account

Legal

Privacy Policy

Effective June 15, 2026. Last updated September 27, 2026

Contact privacy

Document details

Product
TerraFlo
Publisher
Hidden Mesa Labs, LLC
Privacy Contact
privacy@terraflo.fit
Effective Date
June 15, 2026
Last Updated
September 27, 2026

On this page

  1. 1. Introduction
  2. 2. Who This Policy Covers
  3. 3. Information We Collect
  4. 4. How We Collect Information
  5. 5. Why We Collect and Use Information (Purposes)
  6. 6. How Long We Retain Your Information
  7. 7. With Whom We Share Your Information
  8. 8. International Data Transfers
  9. 9. Your Privacy Rights
  10. 10. Security
  11. 11. Third-Party Links and Services
  12. 12. Age Requirement
  13. 13. Apple App Store and Google Play Store Disclosures
  14. 14. Contact
  15. 15. Changes to This Policy

1. Introduction

TerraFlo (“the App,” “we,” “us,” or “our”) is a fitness application published by Hidden Mesa Labs, LLC, a Colorado limited liability company. TerraFlo enables users to record and share workout sessions, analyze GPS-linked telemetry from motion-capable fitness equipment, and engage with a community of fitness creators.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over your data. It applies to TerraFlo for iOS, macOS, tvOS, watchOS, Android, Wear OS, Windows, the TerraFlo account portal, the TerraFlo marketing site, and any web-based administrative interfaces operated by Hidden Mesa Labs, LLC.

If you do not agree with this policy, do not use the App.


2. Who This Policy Covers

This policy applies to:

  • End users who create an account, record workouts, or engage with community content.
  • Creator users who upload workout videos or GPS-linked content.
  • Visitors who interact with any web interface operated by Hidden Mesa Labs, LLC in connection with TerraFlo.

TerraFlo is intended for users who are 18 years of age or older. See Section 12 for details.


3. Information We Collect

We collect only the information necessary to operate TerraFlo’s stated features. The categories below describe what we collect and how.

3.1 Account and Identity Information

When you create a TerraFlo account via Apple Sign-In, Google Sign-In, or email/password through Firebase Authentication, we receive and store:

  • Display name — provided by you or imported from your chosen identity provider (Apple or Google).
  • Email address — used for account identification, login, and service communications.
  • Profile photo URL — a reference to a photo hosted by your identity provider, if you choose to share one.
  • Firebase UID — a unique opaque identifier assigned by Firebase Authentication; it never contains your name or email in cleartext.
  • Account role — an internal designation (e.g., standard user, creator) that controls feature access.
  • Account status flags — whether your account is active, suspended, or subject to any restriction.

We do not receive your Apple ID password or Google account password. Authentication is handled entirely by Apple and Google’s identity services, respectively; we receive only a signed assertion token.

3.1a Sign-In and Cloud Service Providers

When you choose Google Sign-In on iOS or macOS, Google processes account identifiers and IP addresses; it may use an IP address to estimate general location for fraud prevention. Google's disclosures for its sign-in service also include name, email address, phone number, device identifiers, usage information, and other service data. Google identifies sign-in functionality and service analytics as purposes for these data categories. This describes Google's processing; it does not mean TerraFlo receives your Google-account phone number or all of those fields.

Firebase Authentication and Cloud Firestore also process technical diagnostic data for service analytics. These provider practices are distinct from the account fields TerraFlo receives and the support reports you send to TerraFlo. The store disclosures in Section 13 include both TerraFlo's collection and collection declared by these integrated service providers.

3.2 Activity and Workout Data

When you start or save a workout session in TerraFlo, we collect:

  • Route data — latitude, longitude, elevation, and relative timestamp points from the workout route or from GPS metadata embedded in creator-uploaded files. TerraFlo does not continuously track your device location in the background.
  • Telemetry data — heart rate, speed, cadence, power, grade, incline, resistance, and similar values transmitted from paired Bluetooth Low Energy (BLE), Apple Watch, Wear OS, or fitness-equipment sources during the active session.
  • Session metadata — start and end timestamps, duration, and any user-supplied title or notes.

GPS and telemetry data are stored in Google Cloud Firestore (session metadata) and Google Cloud Storage (detailed telemetry JSON payloads), both within the Firebase project operated on behalf of Hidden Mesa Labs, LLC.

3.3 Creator-Uploaded Video Content

If you are a TerraFlo creator, you may upload workout videos. Uploaded videos:

  • Are stored in Google Cloud Storage and may be processed through Bunny Stream / Bunny CDN for playback.
  • May contain embedded GPS telemetry (e.g., GoPro GPMF metadata) that TerraFlo parses and indexes.
  • Are associated with your account UID in Firestore metadata records.

The GPS data extracted from creator videos is treated as workout/location data under this policy. When a creator deliberately publishes a catalog route, TerraFlo makes a geometry-only representation of that route public to catalog visitors, including signed-out visitors. The published geometry includes the first and last valid route points at the source coordinate precision and up to 200 ordered route points selected to preserve the route shape. It does not include telemetry timestamps, heart rate, power, cadence, private notes, or device or service identifiers. To let another person actually ride the published route, TerraFlo also makes a strictly validated route-only playback track available to signed-in activity participants. That track may include precise route points, relative elapsed timing, elevation, grade, and route speed; it may not include heart rate, cadence, power, device identity, service identity, private notes, or absolute recording time. Anonymous visitors cannot download that detailed track.

The deliberate publish action authorizes publication; a separate Route Publication consent receipt is not required. To withdraw a route published under this workflow, unpublish it. Withdrawing Route Publication consent in the privacy center applies only to older routes that still carry a legacy consent binding. It does not block new publication or automatically unpublish routes published under the current workflow. For those legacy-bound routes, withdrawal starts a background process to unpublish them and remove their public geometry and participant playback access. TerraFlo's service objective for this legacy process is 15 minutes, not a guaranteed completion deadline; access may remain while the process runs. The revocation job's audit evidence is retained for 30 days and is not readable by clients.

3.4 Social and Engagement Data

TerraFlo supports community interaction. We record:

  • Likes, favorites, and “gratz” reactions on sessions or videos, associated with your UID.
  • Comments you post, including their text content and timestamp.
  • Follow/follower relationships — which accounts you follow and which accounts follow you (stored as UID references, not email or name).
  • Leaderboard entries — aggregate performance data used to compute relative rankings.

3.5 Third-Party Integration Data (Strava)

If you connect your Strava account to TerraFlo:

  • We store OAuth tokens server-side in a private user record sufficient to upload workout summaries to Strava on your behalf.
  • We do not store your Strava password.
  • You can revoke this connection at any time from within the App or from Strava’s connected-apps settings. Upon revocation, we delete the stored tokens.

3.6 Apple HealthKit, Apple Watch, Health Connect, and Wear OS — Opt-In Only

TerraFlo requests HealthKit (iOS/macOS/watchOS), Apple Watch heart-rate bridge, Health Connect (Android), or Wear OS Health Services permission only when you explicitly enable a workout or save/sync workflow that needs it. If you enable it:

  • On iOS, macOS, and watchOS (HealthKit): We may read limited heart-rate or workout records when the platform requires that access for workout status, heart-rate display, duplicate detection, or a connected Apple Watch session. We may write completed TerraFlo workout summaries, distance, speed, and heart-rate samples back to your HealthKit store.
  • On Android (Health Connect and Wear OS): TerraFlo writes completed workout summaries, exercise records, heart rate, distance, and speed to Health Connect. TerraFlo does not read data from Health Connect.
  • Health platform data is processed on-device except when a workout session, diagnostic report, or explicit export/share action sends selected workout telemetry to TerraFlo servers.
  • We do not use HealthKit or Health Connect data for advertising or for sale to third parties, and we comply with Apple’s HealthKit data-use restrictions.

3.7 BLE Device Diagnostics

When TerraFlo performs Bluetooth device capability profiling, it may send device model, firmware, advertised-service, capability, control-range, and test-result data to our servers. Community device profiles are organized by device model/fingerprint so they can improve compatibility for everyone. Submissions and diagnostics may also be associated with your account for moderation, abuse prevention, and support follow-up.

3.8 AI Discovery Sessions

TerraFlo’s device-profiling feature may use an AI-assisted discovery flow. Conversation transcripts from this flow are intended to contain device capability data, not health data. They may be associated with your account for access control, rate limiting, troubleshooting, and audit logging. These transcripts are retained for a limited period under TerraFlo’s privacy-retention process.

3.9 On-Device Logs

TerraFlo writes diagnostic logs to the app’s private local storage. These logs may include event descriptions, error codes, device state, playback state, and recent telemetry summaries. If you submit a diagnostic report, TerraFlo uploads selected logs, optional screenshots, report comments, app/device metadata, and recent telemetry after client/server redaction removes auth tokens, signed URLs, raw BLE identifiers where possible, local file paths, and exact route coordinates from diagnostic telemetry.

If you turn on Send equipment diagnostics automatically (off unless you turn it on), TerraFlo also uploads equipment diagnostics without prompting you each time: automatic device-test results, and a crash report on the next launch after a crash. These uploads include the raw Bluetooth messages exchanged between TerraFlo and your fitness equipment — the commands sent, the equipment’s replies, and their timing — which is what makes it possible to diagnose why a particular machine misbehaves. Heart-rate readings are excluded from this capture by construction: heart-rate measurements are never buffered, and where equipment reports heart rate inside its own data messages that value is masked before the message is stored. Evidence waiting to upload is held in the app’s private storage, excluded from device backups, and discarded once uploaded. You can turn this off at any time; doing so stops future automatic uploads.

Diagnostic reports may include identifiers assigned to paired Bluetooth equipment, such as a peripheral identifier, together with your account association and app performance measurements such as playback stalls and timing delays. These help us attribute and investigate equipment and playback problems. Redaction does not make every report anonymous.

3.9a Push Notification Tokens (Android)

On Android devices, TerraFlo stores a Firebase Cloud Messaging (FCM) device token in your account record. This token is used to deliver service notifications to your device. It is not shared with advertisers or third-party marketers. If you uninstall the App or delete your account, this token is removed.

3.9b Marketing Website Analytics (Google Analytics)

Our marketing website (terraflo.fit) uses Google Analytics 4, a service of Google LLC, to help us understand which pages visitors find useful — for example, which routes, guides, and product pages are read most, and whether visitors complete beta registration. We configure Google Analytics with advertising features disabled: we do not use it for ad targeting or ad personalization, we do not sell personal information, and Google Analytics 4 does not log or store IP addresses.

If you visit from a region that requires consent for analytics cookies (including the EEA, the United Kingdom, and Switzerland), analytics is off by default and runs only if you choose “Allow analytics” in the notice shown on your first visit. You can decline without losing any site functionality. Your choice is stored on your device; clearing your browser storage resets it.

Analytics applies to the marketing website only. It is separate from the TerraFlo App’s account, workout, and health data practices described elsewhere in this policy.

3.9c Subscription Records

If you purchase a subscription, TerraFlo stores account-linked subscription records such as the product, transaction references, subscription status, renewal status, and paid-through dates to provide access, restore purchases, and prevent fraud. Apple and Google process payments; TerraFlo does not directly receive payment card or bank-account details.

3.10 Information We Do Not Collect

We do not collect or use:

  • Advertising identifiers (IDFA or Android Advertising ID).
  • Advertising trackers or a general-purpose behavioural analytics service in the mobile applications. Sign-in and cloud providers process the service analytics described in Section 3.1a; the marketing website uses Google Analytics as described in Section 3.9b.
  • Persistent cross-site or cross-app tracking cookies in the mobile applications.
  • Precise background location or continuous device-location tracking.
  • Your contacts, calendar, microphone, or camera data.

4. How We Collect Information

SourceCollection method
Apple Sign-InYou initiate; Apple passes a signed identity token to Firebase Authentication.
Google Sign-InYou initiate; Google passes a signed identity token to Firebase Authentication.
Email/passwordYou provide credentials directly; Firebase Authentication manages hashing and storage.
Workout recordingActive user-initiated session; GPS and BLE telemetry are captured only while the session is running.
Video uploadCreator action; you explicitly select and upload a file.
Strava OAuthYou initiate the connection; we receive tokens after you authorize on Strava’s website.
HealthKit / Apple Watch / Health Connect / Wear OSYou explicitly grant permission in the system prompt or start a connected-watch workout.
Social actionsGenerated as you use the App (likes, comments, follows).
BLE device profilingOccurs during device setup; device model/capability data and account-linked submission metadata may be sent.

5. Why We Collect and Use Information (Purposes)

We use the information we collect for the following purposes only. We do not use your data for purposes not listed here.

PurposeData usedLegal basis (GDPR reference)
Providing the App — account creation, login, session displayAccount info, UIDContract performance
Recording and storing your workoutsGPS route, telemetry, session metadataContract performance
Enabling creator video uploads and community sharingVideo files, extracted GPS, creator metadataContract performance
Social features — likes, comments, follows, leaderboardsEngagement dataContract performance / Legitimate interest
Syncing workouts to StravaOAuth tokens, workout summariesConsent (user-initiated OAuth)
Syncing with HealthKit / Health ConnectHealth store read/writeConsent (explicit system permission)
Improving BLE device compatibilityDevice capability data (non-PII)Legitimate interest
Responding to support requests and diagnostic reportsReport comments, logs, screenshots, redacted telemetry, equipment identifiers, performance measurements, and device/app metadataLegitimate interest
Providing and restoring subscription accessAccount-linked subscription and purchase recordsContract performance
Legal compliance and fraud preventionAccount info as neededLegal obligation / Legitimate interest

The sign-in and cloud service providers also process data for authentication, fraud prevention, and service analytics as described in Section 3.1a.

We do not sell your personal information. We do not use your workout data, GPS data, or health data to serve advertisements.


6. How Long We Retain Your Information

Data categoryRetention period
Account profileRetained while your account is active; deleted within 30 days of account deletion request processing (following a 7-day cancellation grace window).
Workout sessions and telemetryRetained while your account is active; deleted with your account or upon explicit deletion request.
Creator video contentRetained while the video is published or until the creator deletes it. Deleted with the account if the creator deletes their account.
Social engagement data (likes, comments, follows)Retained while the associated content and accounts exist. Deleted comments may be replaced with a generic deleted-account placeholder if the comment was part of a thread.
Strava OAuth tokensDeleted promptly upon integration disconnect or account deletion.
BLE device diagnostic dataRetained for up to 90 days; subject to earlier deletion upon account deletion.
AI discovery transcriptsDeleted after 30 days unless retained longer for an active abuse or security investigation.
Problem reports and attached blobsRetained for up to 90 days, with a minimum 30-day floor; retained longer if required for an active support or security investigation.
Support correspondenceRetained for up to 30 days after issue resolution, then deleted.
Android push notification token (FCM)Retained while account is active; deleted upon account deletion or App uninstallation.
On-device logsStored locally on your device; not retained on our servers unless you submit a diagnostic report or otherwise transmit them to support.
Marketing-website analytics events (Google Analytics)Retained by Google Analytics for 14 months, then deleted automatically.

We do not retain personal information beyond the periods described above unless required by law.


7. With Whom We Share Your Information

We share your information only as described below. We do not sell personal information to data brokers or advertisers.

7.1 Google (Firebase / Google Cloud)

We use Google Firebase services — Firebase Authentication, Cloud Firestore, and Cloud Storage — as our primary data infrastructure. Google processes data on our behalf as a data processor under Google’s Cloud Data Processing Addendum. Data is stored in the United States by default. For Firebase’s current data residency options, see Google’s Firebase documentation. Our marketing website also uses Google Analytics 4 as described in Section 3.9b; Google processes that data on our behalf under the Google Ads Data Processing Terms, which we have accepted.

When you choose Google Sign-In, Google also processes information for its sign-in service as described in Section 3.1a. Google’s privacy policy governs Google’s handling of that information: https://policies.google.com/privacy.

7.2 Apple

If you sign in with Apple Sign-In, Apple’s identity services process your login credential. Apple’s handling of your Apple ID is governed by Apple’s Privacy Policy, not this policy.

7.3 Strava

If you connect Strava, we transmit your workout summary data (distance, duration, route, activity type, and optional heart-rate samples when included in your export) to Strava via their API using your authorized OAuth token. Strava’s handling of received data is governed by Strava’s Privacy Policy.

7.4 Apple HealthKit (iOS/macOS) and Health Connect (Android)

If you enable the HealthKit, Apple Watch, Health Connect, or Wear OS integration, data is exchanged with your device’s health platform per your permissions. These platform providers have their own privacy policies governing health data.

7.5 Legal Process

We will disclose your information if required to do so by a valid court order, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to prevent imminent harm, fraud, or illegal activity. We will attempt to notify you of such requests where legally permitted.

7.6 Business Transfers

If Hidden Mesa Labs, LLC is acquired, merges with another company, or transfers substantially all of its assets, your information may be transferred as part of that transaction. We will notify you via the App or your registered email address before such a transfer, and we will require any successor to honor the commitments in this policy or provide you an opportunity to delete your account.

7.7 Aggregated, Non-Identifiable Data

We may share aggregate, de-identified statistics (e.g., “average workout duration by activity type”) that cannot reasonably be linked to any individual. This does not constitute sharing personal information.


8. International Data Transfers

TerraFlo is operated from the United States. Its planned App Store launch includes supported storefronts outside the European Union, European Economic Area, and United Kingdom; actual availability depends on the storefront and release status. If you access TerraFlo from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.

EU / EEA and UK availability: The App Store launch excludes EU member states, Iceland, Liechtenstein, Norway, and the United Kingdom. These storefront restrictions do not determine whether data-protection law applies to particular processing. Before expanding into these markets, Hidden Mesa Labs, LLC will review the applicable requirements and update this policy. The existing commitment for a future EU launch remains: implement appropriate transfer mechanisms (such as Standard Contractual Clauses) before processing EU residents’ data, and appoint a Data Protection Officer or EU representative as required by GDPR Articles 27 and 37–39.


9. Your Privacy Rights

9.1 General Rights (All Users)

You may, at any time:

  • Access the personal information we hold about you by submitting a request to privacy@terraflo.fit.
  • Correct inaccurate profile information directly within the App settings, or by contacting privacy@terraflo.fit.
  • Delete your account and associated personal data. Account deletion is initiated from within the App or from the account portal at terraflo.fit/account/privacy. We will process the deletion within 30 days. Some aggregated or anonymized data derived from your account may not be deletable if it has been incorporated into aggregate statistics.
  • Export / Portability — you may request a copy of your workout data in a portable format by contacting privacy@terraflo.fit.
  • Opt out of optional integrations (Strava, HealthKit, Health Connect) at any time from within the App.

9.2 California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for which it was collected, and the categories of third parties with whom it has been shared.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions permitted by law.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. No opt-out mechanism is required for this activity at this time because we do not engage in it.
  • Right to Limit Use of Sensitive Personal Information: Location data collected during workouts and health-related telemetry (heart rate, cadence) may constitute “sensitive personal information” under CPRA. We use this data only to provide the features you explicitly activate. You may disable GPS recording or BLE telemetry within the App at any time.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your California privacy rights.

To exercise any of these rights, contact us at privacy@terraflo.fit or at the mailing address in Section 14. We will respond within 45 days, or notify you if we require an extension.

We do not knowingly sell the personal information of any user.

9.3 Colorado Residents (Colorado Privacy Act — CPA)

If you are a Colorado resident, you have rights under the Colorado Privacy Act, including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of the sale of personal data and of targeted advertising. TerraFlo does not sell personal data or conduct targeted advertising. To exercise your rights, contact privacy@terraflo.fit. We will respond within 45 days.

9.4 EU / EEA Residents (GDPR)

TerraFlo is not currently available in the EU/EEA. If it becomes available:

  • You will have rights of access, rectification, erasure, restriction of processing, portability, and objection.
  • We will identify an appropriate legal basis for each processing activity (see Section 5).
  • You will have the right to lodge a complaint with your local supervisory authority.
  • We will appoint a Data Protection Officer or EU representative as required by GDPR.

This section is included to ensure that no design decision in the current policy precludes GDPR compliance at launch.


10. Security

We implement the following measures to protect your information:

  • Encryption in transit: All communications between the App and Firebase/Google Cloud services use TLS.
  • Encryption at rest: Firebase Cloud Firestore and Cloud Storage encrypt data at rest by default using Google-managed encryption keys.
  • Authentication: Firebase Authentication manages credential storage and hashing. We do not store passwords in cleartext.
  • Access controls: Firebase Security Rules restrict read/write access to user data. Only authenticated users may access their own account data.
  • Diagnostic sanitization: Client and server redaction remove common secrets, signed URLs, local file paths, and exact diagnostic route coordinates before problem-report storage. Diagnostic reports can retain paired-equipment identifiers as described in Section 3.9; they are not represented as anonymous.
  • Local data protection: Sensitive local caches, diagnostics, upload state, and route/video cache metadata are excluded from OS backup where supported.

We do not represent that our security measures are infallible. No system is completely secure. If you believe your account has been compromised, contact privacy@terraflo.fit immediately.

In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.


11. Third-Party Links and Services

TerraFlo does not display third-party advertisements. The App may contain links to Strava or other third-party platforms. When you follow such a link or initiate a third-party integration, you are subject to that platform’s privacy policy. We are not responsible for the privacy practices of third parties.


12. Age Requirement

TerraFlo is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a user under 18, we will delete it promptly and terminate the associated account. If you believe someone under 18 has created a TerraFlo account, please contact privacy@terraflo.fit.


13. Apple App Store and Google Play Store Disclosures

The following categories cover TerraFlo and integrated service-provider collection for store privacy disclosures. Collection varies by platform and the features or sign-in methods you use; the Google Sign-In entries below concern its iOS/macOS integration described in Section 3.1a.

Data typeCollected?Linked to identity?Used for tracking?
Email addressYesYesNo
Name / display nameYesYesNo
Profile photoReference URL onlyYesNo
Precise location / route dataYes, from workout routes and uploaded route videos; creator-authorized catalog geometry may be publicYesNo
Health & fitness data (heart rate, cadence, power, speed, grade, workout summaries)Yes, during active sessions and optional health-platform syncYesNo
User-generated content (comments, videos, report comments, optional screenshots)YesYesNo
Identifiers (Firebase UID and Google Sign-In user identifiers)Yes, for account functionality and provider-declared service analyticsYesNo
Product interaction (likes, follows, ratings, leaderboard entries, subscription usage)YesYesNo
Crash / diagnostic dataTerraFlo reports and consented automatic equipment diagnostics; Firebase also declares technical diagnostics for analyticsTerraFlo reports: Yes; Firebase service diagnostics: declared unlinkedNo
Performance dataYes, playback and timing diagnostics included in reportsYesNo
Customer supportYes, user-authored support requests and report commentsYesNo
Purchase historyYes, account-linked subscription records when you purchase or restore a subscriptionYesNo
Payment informationNot collected directly; handled by App Store / Play Store billingN/ANo
Device identifiers / push tokensPaired-equipment identifiers in diagnostics, Google Sign-In provider-declared device identifiers for analytics, and Android FCM tokens; no advertising identifiersYesNo
Coarse locationGoogle Sign-In may estimate general location from an IP address for fraud preventionYesNo
Phone numberDeclared by Google for its sign-in service; TerraFlo does not request a Google phone-number profile scopeYes, in Google’s declarationNo
Other usage dataDeclared by Google Sign-In for service analyticsYes, in Google’s declarationNo
Other data typesDeclared by Google Sign-In for functionality and service analyticsYes, in Google’s declarationNo

TerraFlo does not use any data for tracking you across apps or websites owned by other companies.


14. Contact

For privacy-related questions, requests to exercise your rights, or data breach reports:

Hidden Mesa Labs, LLC Attn: Privacy

200 S Wilcox St

#606

Castle Rock, Colorado 80104

United States

privacy@terraflo.fit

We aim to acknowledge all privacy requests within 5 business days and to resolve them within 45 days.


15. Changes to This Policy

We will update this policy when our data practices change. For material changes, we will notify you via an in-app notice or by email to your registered address at least 30 days before the change takes effect (where required by law). The “Last Updated” date at the top of this document will always reflect the most recent revision. Continued use of TerraFlo after the effective date of a change constitutes acceptance of the revised policy.


© 2026 Hidden Mesa Labs, LLC. All rights reserved.

TerraFlo

Real outdoor routes. Real indoor workouts.

Compatible with Strava

Explore

Product Routes Equipment Studio

Resources

Learn Compare FAQ Beta

Company

Account Privacy Terms Contact

TerraFlo is a Hidden Mesa Labs, LLC product. info@terraflo.fit

© 2026 Hidden Mesa Labs, LLC. All rights reserved.