CorosLink is local-first: there is no CorosLink cloud backend, and the app does not run its own servers or upload your files.
This page describes the desktop app. The CorosLink website and documentation privacy notice, including hosting logs, optional analytics, cookies, international transfers, and data-protection rights, is available at coroslink.com/privacy.
| Data | Where it lives | Sent to |
|---|---|---|
| Music and downloads | Local SQLite database + MP3 files in the Electron user data directory | Nowhere |
| Spotify tokens | Local SQLite, after OAuth | Only Spotify |
| Google OAuth tokens | Local SQLite, after OAuth | Only the YouTube Data API (playlist reads) |
| YouTube Music / Apple Music headers | Local storage | Only the respective service, to read library metadata |
| Apple Podcasts | Not stored — public catalogue and RSS requests only | Apple's public podcast endpoints |
| Map cache | A local folder you choose | Copied to the watch over USB only |
| OpenRouteService | Your API key stored locally | OpenRouteService, when you generate a route |
| Training Hub | Not stored beyond session | Your COROS email and password authenticate with COROS servers |
Training Hub credentials:
Your COROS email and password are used to authenticate with COROS servers when you use Training Hub. Activity data is fetched on demand and not synced to any third-party service.
Rights to media:
Only download media you have the rights or permission to download.