Privacy policy of the GeneTrainer connector for Claude
Draft — to be validated by a DPO / legal counsel before publication (Projet — à valider par un DPO / juriste).
Version: 2026-10-01 (draft). This text describes the connector as it is designed and coded on 2026-10-01. Passages in square brackets
[…]must be completed or confirmed before publication. French version: privacy-policy.fr.md.
1. In short
- The connector lets a member of a team's staff query, from Claude (Anthropic), the data of their teams in GeneTrainer, in natural language. It is read-only: it does not create, change or delete any club data (it only writes its own audit log and acceptance records, described below).
- It processes athletes' health data. The club, which is the data controller, decides to switch it on team by team and category by category. The medical categories are off by default.
- The data that is consulted is sent to Anthropic, through the Claude account of the staff member who consults it.
- GeneTrainer does not keep the data returned to Claude. It keeps an audit log (who, when, which team, which athletes, which categories) for 12 months; the log never contains the data that was returned.
- GeneTrainer does not sell this data, does not use it for advertising or commercial profiling, and does not use it to train an AI model.
- Contact:
privacy@genetrainer.com[to be confirmed].
2. Who this concerns, and what this policy covers
The connector is operated by GeneTrainer [company name, legal form, registered office, registration number: to be completed] ("GeneTrainer"). It is a remote MCP (Model Context Protocol) server, reachable at https://mcp.genetrainer.com/mcp, which staff members add to Claude (claude.ai, Claude Desktop, the Claude mobile app, Claude Code).
This policy covers the data processed by this connector. It does not cover:
- Claude and Anthropic, which have their own terms and privacy policies;
- the GeneTrainer application itself: see GeneTrainer's privacy policy [link: to be completed].
It is addressed to the staff members who use the connector, to the athletes whose data can be consulted (and, for minors, to their legal representatives) and to clubs.
3. This processing involves health data
Yes. The connector can return data concerning athletes' health to Claude, and that data is then sent to Anthropic.
- The "Medical — injuries" and "Medical — notes" categories hold health data in the strict sense (diagnoses, injuries, return-to-play phases, medical notes). They are off by default. For a staff member to reach them, three agreements add up: the club's switch, a GeneTrainer permission on the team ("Medical" or "Medical notes") and the staff member's personal medical consent, given at each connection.
- Other categories can also reveal information about health: "Questions" (wellness answers, pain, pain zones), "Availability" (available, returning, unavailable) and "Performance" (weight, body measurements, physical tests, load). The legal kit given to clubs treats them as such.
- Decision support, not medical advice. The connector returns data recorded in GeneTrainer, and Claude, an AI assistant, summarises it. The answers are neither a diagnosis nor medical advice, and they can be incomplete or wrong. Decisions about an athlete's health remain with the club's qualified staff.
- It is for the club, as data controller, to have a legal basis (articles 6 and 9 of the GDPR), to inform the people concerned, to assess the risk (impact assessment) and to frame the use of Anthropic. GeneTrainer gives the club a kit for this (information notice, impact assessment template, activation text).
- The connector does not collect or check athletes' consent: the club must do so if its legal basis requires it.
4. Roles
| Party | Role | Details |
|---|---|---|
| The club | Data controller | It decides whether to switch sharing on, which categories are shared and who has access. It remains responsible for its athletes' data. |
| GeneTrainer | Processor for the club | For the team data read by the connector and for the audit log kept on the club's behalf. Switching sharing on in the team settings, after accepting the conditions in force, is the club's written instruction (its date, author and setting are kept in a history). |
| GeneTrainer | Controller for its own needs | User accounts and authentication, security and operation of its service [to be validated by the DPO]. |
| Anthropic | Recipient of the data | It receives the data through the staff member's Claude account. Its status (processor for the club or for the staff member's organisation, or controller) depends on the contract under which that Claude account is used: see section 7. GeneTrainer is not a party to that contract. |
| Amazon Web Services, Auth0, Sentry | GeneTrainer's sub-processors | Hosting, authentication, error monitoring: see section 7. |
5. Data collection practices
5.1 What the connector receives from Claude
With each call, the connector receives:
- the access token issued by Auth0: the person's Auth0 identifier (
sub), the Claude client used, the scope and the expiry; - the name of the tool requested and its arguments, chosen by Claude to answer the question (team, metric, period, group or list of athletes, an athlete identifier…);
- the ordinary technical metadata of an HTTPS request.
The connector does not receive the conversation (your messages and Claude's answers), nor Claude's memory or chat history, nor your files. None of its tools asks for them.
5.2 What the connector reads in GeneTrainer to answer
Only the categories the club has ticked, and that the person's GeneTrainer rights allow, are read and returned. The rights are read again at each call.
| Category | Content | Default | Conditions |
|---|---|---|---|
| Organisation | Teams, roster (athlete identifier and name), positions, position groups, training groups, calendar (including medical-type sessions, as in the application), session content | Always included when sharing is on | Staff, technical or management profile on the team |
| Contact details | Athletes' phone number and e-mail address | Off | Same, and the club's switch |
| Performance | GPS, training load, playing time, physical tests, weight and body measurements, strength training | On | Same |
| Questions | Wellness answers, RPE, session questions, pain zones | On | Same |
| Availability | Available, returning or unavailable, with no diagnosis | On | Same |
| Medical — injuries | Area, diagnosis, illness or injury, traumatism, frequent pathology, phases and their dates, staff comment | Off | Same, GeneTrainer permission "Medical" (Read or Full level) and personal medical consent |
| Medical — notes | Athletes' and team medical notes, as plain text cut at 1,500 characters | Off | Same, permission "Medical notes" (Read or Full level; restricted notes: Full level) and personal medical consent |
Answers cover the team's current roster: former players, staff and athletes of other teams are not in them. They contain athletes' names: the connector does not pseudonymise them.
5.3 What the connector never returns
- Red list (never, whatever the setting): identity documents (including health card and European firearms card), weapons, social security number, postal address, athletes' contacts (including their parents), menstrual-cycle question and tracking.
- Not exported in this version: date of birth, sex, nationality, licence number, contract type, maximum heart rate.
- Free text written by athletes (questionnaire comments, "free text" questions, free-form injury reports, session completion notes), questions reserved for staff, interviews and staff's private calendar notes.
- Training groups that are private to another user, archived, or "smart".
Labels written by staff (session titles, group names, question titles) are passed on as they are: they may contain information about health.
5.4 What the connector records
| Record | Content | Purpose |
|---|---|---|
| Audit log of calls | Date, user, team, tool, call parameters, result or error code, identifiers of the athletes concerned, categories returned, duration, Claude client, request identifier. Never the data returned. | Traceability of consultations, security, proof that the conditions are respected. |
| Attestation acceptances | User, version of the text, date, medical consent yes or no, fingerprint of the single-use link. | Proof of the personal attestation and of the medical consent. |
| Club setting and history | Team, activation, ticked categories, version of the conditions accepted, author, date of each change. | The club's written instruction, proof. |
| Technical logs | Metadata: tool name, result, request identifier. Never a token, an Authorization header or response content. No access log (IP address, URL) on the server or the load balancer. |
Operation, diagnosis. |
| Rate-limit counters | Number of calls per minute and per day, under a key that is a fingerprint of the Auth0 identifier. | Abuse protection. |
| Error events | Error type and technical trace, with no personal data by configuration (send_default_pii off, local variables excluded). |
Fixing faults. |
The /consent attestation page uses no cookie, no tracker and no script.
6. Usage and storage
Purposes. To answer, from Claude, a staff member's requests about the data of their teams; to trace consultations; to secure the service and prevent abuse; to operate and fix the service. The connector has no other use: no advertising, no resale, no building of datasets, no training of an AI model by GeneTrainer. The connector makes no automated decision about people: it reads data and returns it.
No copy of the answers. Answers are computed at each call from the GeneTrainer database and are not stored by the connector. A correction made in GeneTrainer is therefore reflected in the next request.
Location. The service and its database are hosted at Amazon Web Services in the Ireland region (European Union). Authentication is handled by an Auth0 tenant in the Europe region.
Security measures: see section 10.
7. Third-party sharing
7.1 Anthropic, through the staff member's Claude account
When a staff member queries GeneTrainer from Claude, the connector's answer is passed to Claude, hence to Anthropic, and becomes part of that account's conversation. Depending on the categories shared, this includes health data. GeneTrainer does not contract with Anthropic for this flow: the terms that apply are those of the staff member's Claude account (in practice, their organisation's subscription). What GeneTrainer knows, as of 2026-10-01 and from Anthropic's public information [to be re-checked before publication]:
- Team and Enterprise plans (commercial terms): a data processing addendum (GDPR article 28) is part of the commercial terms, Anthropic acts as processor, and transfers outside the European Union rely on standard contractual clauses. The schedule of the published addendum shows "None" on the line for special categories of data: the club must obtain written confirmation from Anthropic that health data is covered before ticking the medical categories. GeneTrainer recommends an Enterprise plan for health data (a recommendation, not checked by the connector).
- Free, Pro and Max plans (consumer terms): no data processing addendum; conversations may be used to improve models if the user agrees (de-identified retention for up to 5 years), and retention periods are those of the consumer service. These plans are not compatible with athletes' health data. This is why a professional plan (Team or Enterprise) is required for each staff member who connects Claude: the club's sharing conditions say so, and the confirmation page does not ask the staff member to attest it. GeneTrainer cannot check the plan: the access token does not state it.
7.2 GeneTrainer's sub-processors for this connector
| Sub-processor | Role | Data concerned | Location |
|---|---|---|---|
| Amazon Web Services | Hosting of the service and the database, secrets vault, technical logs, rate-limit counters | All data processed by the connector (hosted by GeneTrainer) | Ireland (EU) |
| Auth0 (Okta) | OAuth authentication, issuing of tokens | The staff member's sign-in identity, sign-in logs | Europe [to be confirmed] |
| Sentry | Error monitoring | Technical events with no personal data by configuration | [to be confirmed] |
GeneTrainer's official list of sub-processors prevails [link: to be completed].
7.3 No other recipient
GeneTrainer does not disclose the connector's data to any other third party, except under a legal obligation or an order from a competent authority.
8. Transfers outside the European Union
The service and its data are hosted in the European Union. The transfer to Anthropic, which may process data outside the European Union (notably in the United States), takes place at the level of the staff member's Claude account: for professional plans it is covered by the standard contractual clauses of Anthropic's data processing addendum [to be validated]. It is for the club to assess this transfer in its impact assessment. For Sentry and Auth0, the applicable safeguards are those of their contracts with GeneTrainer [to be completed].
9. Data retention
| Data | Period |
|---|---|
| Data returned to Claude | Not kept by GeneTrainer. |
| Audit log of calls | 12 months, then purged: a purge job removes the records older than that period, which is a configuration setting [the job is to be scheduled before launch]. The log remains if a user is deleted (the staff member's identifier is then erased from it). |
| Attestation acceptances | As long as the staff member's account exists [to be confirmed]. |
| Club setting and its history | As long as the team exists [to be confirmed]. |
| Technical logs (CloudWatch) | 30 days, metadata only. |
| Rate-limit counters | At most one day. |
| Tokens | Access token: 1 hour. Refresh token: rotated at each use, expires after 30 days of inactivity. The staff member or GeneTrainer can revoke them. |
| Error events (Sentry) | [period to be confirmed], with no personal data by configuration. |
| In Claude (Anthropic) | Depends on the plan and the organisation's settings: see section 7.1. Deleting a conversation, retention and conversation sharing are set in Claude, not in GeneTrainer. |
10. Security
- OAuth 2.1 authentication through Auth0: a signed (RS256) access token valid for one hour, and a refresh token with rotation. The server checks the signature, the issuer, the audience (the connector's exact URL), the expiry, the
gt:readscope and that the client is an authorised Claude client. It never relays a token. - A single, read-only scope (
gt:read): no medical scope. - Rights read again at each call: the person must be a member of the team's staff (staff, technical or management profile) and their GeneTrainer permissions apply. Removal from a team or of a permission takes effect on the next call.
- Club switches: per team and per category, off by default, editable by the team's Management profile and GeneTrainer administrators, with immediate effect.
- Medical: three locks (GeneTrainer permission, the club's switch, personal consent given at each connection).
- Field-by-field privacy grid: a field with no declared category is never returned; the red list never is.
- Limits: 60 calls per minute and 2,000 per day per user, 10 seconds per query, 30 athletes per list, 365 days, 60 rows and 50 KB per answer.
- Audit log: if the log cannot be written, the answer is refused.
- Attestation: a page with signed, single-use, short-lived (15 minutes) tokens, protected against cross-site request forgery (CSRF), with no script and no cookie.
- Read-only: the connector writes nothing into the club's data.
- Operation: encrypted access (HTTPS), secrets kept in a vault, a container image with no key file, logs limited to metadata.
11. Your rights
Athletes and legal representatives. The data controller is your club: contact it [details of the club and its DPO, given in the information notice the club gave you]. Depending on the legal basis the club relies on, you have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw your consent where it is the basis of the processing. You can also lodge a complaint with the supervisory authority (in France, the CNIL: www.cnil.fr).
What GeneTrainer does for the club. GeneTrainer assists the club in answering these requests and passes on to the club any request it receives directly.
- Rectification and erasure are done at the source, in GeneTrainer: the connector reads the data live and keeps no copy.
- At the club's request, GeneTrainer extracts from the audit log the consultations that concern a team or an athlete [procedure to be confirmed].
- The club can switch off a category, or all sharing for a team, with effect on the next call.
- In this version it is not possible to exclude one particular athlete (right to object). That exclusion is planned for a later version. Meanwhile the club handles an objection by an organisational measure or by switching off the categories concerned for the team.
- GeneTrainer cannot erase the conversations Anthropic keeps in a staff member's Claude account: that is a matter for that account and the club's Claude organisation.
Staff members. Your data (account, acceptances, audit log of your consultations) is processed for the security of the service and so that the club can show that the attestation is respected. You can exercise your rights with your club or with GeneTrainer (section 14).
12. Minors
Athletes may be minors. Their data is processed like adults' data, with the same limits and the same control; it falls under the club, which informs their legal representatives. The connector is intended for staff members and is not offered to athletes or minors.
13. Staff members' commitments
At each connection from Claude, the staff member confirms on the "Use of GeneTrainer data" page: that the data they consult is sent to Anthropic, including athletes' health data; that they use it only for the sports follow-up of their teams; that they keep it confidential; that they do not copy it into other tools; and that their consultations are logged. This attestation does not transfer responsibility for the processing: the club remains responsible. Separately, the club's sharing conditions require a professional Claude plan (Team or Enterprise) for each staff member who connects Claude; the page does not ask the staff member to attest it and GeneTrainer does not check it (section 7.1).
14. Contact information
- Personal data and exercise of rights:
privacy@genetrainer.com[to be confirmed]. - Data protection officer: [name or function and address: to be completed].
- Help with the connector: [support address: to be confirmed].
- Reporting a vulnerability: [security address: to be confirmed].
- Postal address: [to be completed].
15. Changes to this policy
The version in force is dated at the top of this document. In case of an important change, clubs and staff members are informed; a change to the text of the attestation or of the club's conditions means a new acceptance at the next connection or in the club's panel.