TriCoach

Privacy Policy — TriCoach AI

Last updated: 2026-09-22. Version 2026-09-22.2.

TriCoach AI ("we", "the app") is an adaptive triathlon coaching app operated by 22.O1 L.L.C-FZ, a company registered in the United Arab Emirates. It handles health and fitness data, which we treat as sensitive personal data. This policy explains what we collect, why, and the rights you have.

What we collect

How we use it

Solely to provide the coaching product to you: to generate and adapt your training plan, compute readiness, and explain adjustments. We do not sell your data and do not use it for advertising.

AI coaching — off unless you turn it on

You can let a large language model run by Anthropic read your recent training and recovery data. When it is on, the model both decides how today's session changes — within fixed safety limits it cannot exceed — and writes the explanations you read. This is the only feature that sends your training or health data to an AI company.

It is off by default and stays off until you switch it on in Settings → AI coaching. We did not turn it on for existing accounts when we built it. With it off, the app is fully functional: the same decisions are made by fixed rules and we write the explanations ourselves.

When it is on, these are sent. Each line is sent only by a part of the app that exists for you: where something here has not appeared in your copy yet, nothing about it is sent, and it will not start without this list changing first.

Your name, email address, password and connected-account tokens are never included.

Three further things are never sent, whatever else grows on this list: your cycle log, the fuelling numbers worked out for your race, and the body-composition and aerodynamic figures behind your projections. The coach is never given those, and that is enforced in the code rather than promised in a prompt.

You can withdraw at any time from the same screen, and withdrawal is never blocked or delayed. Doing so stops all future sending and erases what the model already produced: the health snapshots we sent, the raw model output, and cached narratives. Three consequences are worth knowing before you do it.

The record of what the coach changed in your plan is kept, because that is your training history.

Four things about sending your data to Anthropic, because they are the ones worth knowing before you turn this on:

We are asking Anthropic for a zero-retention arrangement, which would remove the flagged-content exception above. It is not in place yet. This page will say so when it is — we are telling you we are trying, not implying we have finished.

Readiness signals — off unless you turn it on

With this on, we compare your own recovery signals — heart-rate variability, resting heart rate and sleep — against your personal baseline each morning and keep a daily reading of typical, watch or ease, with the names of the signals outside their range, never the values. When two or more are outside their usual range, today's session is made at least one zone easier. The reading is computed and stored by us alone. Nothing about it is sent to anyone unless you have also turned AI coaching on, whose list above says what travels. Turn it off in Settings and every stored reading is deleted.

Who we share it with

We do not sell or rent your data. Every recipient is listed here.

RecipientWhat they receiveBasis
Anthropic (AI coaching)The training and health data listed aboveYour explicit consent — off by default
Vercel (application hosting)Everything that passes through the app, as the infrastructure it runs onNecessary to provide the service
Neon (database hosting)Everything stored: your account, training, health and recovery recordsNecessary to provide the service
Your browser's push service (Google, Mozilla or Apple, depending on your device)Notification contents are encrypted so the relay cannot read them. It does see your device's push address, and when messages are sent.Your device permission, per notification type
Clerk (sign-in and account security, United States)Your email address, your name, and the identifiers that prove a sign-in is yours. No health or training data, and no access to anything stored in the app.Necessary to provide the service
Cloudflare (bot check on the sign-up screen)Your IP address and browser characteristics, sent by the Turnstile check Clerk runs to tell a person from an automated sign-up. No health or training data, and no account content.Necessary to provide the service
Upstash (rate limiting, Frankfurt, EU)An unreadable code computed from your account identifier or your IP address with a secret key only we hold — never the identifier or the address itself — and the times of your recent requests, so that too many requests in a short time can be refused. Each code expires within an hour of your last request. No health or training data.Necessary to provide the service
Strava / WHOOP, if you connect themOnly credentials and requests for your data. We send them no health data — the flow is inbound only.Your authorisation, revocable

We do not currently use a separate error-reporting provider. When something breaks, the technical error is written to the application logs at Vercel, already listed above. If we add an error-reporting provider we will name it here, say which region it processes in, and raise the version of this policy.

Your browser contacts two third parties: Clerk, which handles signing in, and Cloudflare, whose Turnstile check Clerk uses on the sign-up screen to tell a person from an automated sign-up. A Content-Security-Policy restricts it to those two and this app's own servers, and nothing else — there are no analytics, trackers, advertising pixels or external fonts anywhere in the app.

Where it is processed, and on what basis

The app runs on Vercel, in its Frankfurt (EU) region, and its database is Neon, also in Frankfurt (EU). Your account and your training history stay there.

AI coaching is the one exception, and it only applies if you turn it on. It sends the data listed above to Anthropic, which processes it in the United States — a transfer out of the EU, made on the basis of your explicit consent and the standard contractual clauses in Anthropic's data-processing agreement. Leave AI coaching off and nothing about you leaves Frankfurt. Depending on your location, this policy is intended to meet the EU GDPR and the UAE PDPL.

Governing law. 22.O1 L.L.C-FZ is established in the United Arab Emirates, and this policy is governed by UAE federal law. Where the EU GDPR applies to you, the rights set out below are honoured under it as well.

Our legal bases:

Security

The app is served over HTTPS and instructs your browser never to connect over plain HTTP again. Session cookies are restricted to the app and inaccessible to scripts. Signing in is handled by Clerk, listed above: if you use a password, Clerk holds it, not us. The one exception is an account created before sign-in moved to Clerk, which may still have its old password stored here, hashed and never in readable form, until the account is deleted.

The access tokens for any wearable service you connect are encrypted at rest with AES-256-GCM under a key held outside the database. To be precise about scope: that encryption covers those tokens. Your training and health records are stored in ordinary database columns, protected by access control rather than by application-level encryption — whether the underlying storage is encrypted is a property of Neon, our database host.

Every request is scoped to your own account, and a session stops working the moment the account it belongs to is deleted.

Your rights

Most of those you exercise yourself, from Settings, and they take effect immediately — no request, no queue, no waiting on us. If you would rather ask us, or you want something there is no button for, write to contact@tricoachai.ai. We answer within one month. If a request turns out to be genuinely complicated we may need longer than that, and if so we will tell you inside the first month — with what we are doing and when to expect it — rather than let it run on in silence.

Data retention

We keep your training and health data for as long as your account exists. We do not age it out, because a coaching history is only useful whole — your fitness two years ago is what makes this year's numbers mean anything.

Three exceptions run automatically: the detailed health snapshot attached to each daily coaching decision is erased after 90 days (the decision itself is kept), the daily readings kept for readiness signals, if you turned them on, are deleted after 90 days, and raw records from connected services are deleted after 30 days, or 90 if they failed to process.

What deleting your account actually does

It happens immediately: your records are removed from the live database, with no grace period and no soft-delete. One qualification, because we would rather be precise than reassuring. Our database provider keeps a short rolling change history — currently six hours — so that an operational failure such as a bad deployment can be undone. Within that window, a restore would technically bring deleted rows back with everything else. We do not use it to reverse account deletions, and once the window has passed your data is unrecoverable by anyone, including us. Your profile, races, plans, sessions and the record of changes to them, activities, recovery records (including any cycle days you logged), injury reports, test results, body measurements, training load, readiness readings, coaching decisions, suggested changes, weekly reviews, the coach's notes, coach chat conversations, nutrition, strength logs, connected services with their tokens and the raw records they sent us that we had matched to your account, notification subscriptions, any authentication credentials we still held, and consent records are all destroyed together.

Your sign-in record at Clerk — your email address, your name, and the identifiers that prove a sign-in is yours — is deleted by the same action. If Clerk cannot be reached at that moment, we keep one thing and one thing only: the identifier Clerk uses for you, so that we can finish the job. We retry until it succeeds, and that identifier is deleted the moment it does. It is the only thing that outlives your account, it is useless to anyone who is not us, and it cannot be used to reach any of the data we have just destroyed.

We ask you to type the word DELETE first, because a live session on an unlocked phone should not be one tap away from erasing your training history.

Three things to know:

Age

TriCoach AI is for adults. You must be 18 or over to have an account, and our Terms of Service say the same thing.

The bar is 18 rather than something lower because of what the app actually does: it works out caffeine and sodium-bicarbonate doses in milligrams from your body weight, prescribes barbell loads in kilograms, and checks your energy intake against a figure established in adult athletes. None of that has a version written for a body that is still growing.

We should be straightforward that this is a rule rather than a control. Setting up your profile asks your age, but it is a number you type in and nothing checks it. We do not ask for your date of birth and we do not ask for proof, because verifying age properly would mean collecting identity documents from everyone — more data about you, not less, to enforce a rule most people were never going to break.

If you believe someone under 18 has created an account, write to contact@tricoachai.ai. If we find out ourselves, we will get in touch, explain why, and give them a way to download their data before the account is deleted.

Changes

We will update this page and the "last updated" date when this policy changes.

6 September 2026 — Readiness signals and cycle tracking are now named beside AI coaching as explicit-consent processing, with what withdrawing each one deletes. The AI coaching consent card now says on the card itself that processing happens in the United States, which this page already said. Nothing new is sent, and nothing new is collected.

22 September 2026 — The line about anything you type now names the optional note on your morning check-in and on a logged session by what it is, instead of quoting the wording one of those two screens happens to print. The same change is on the AI coaching consent card. Nothing new is sent, and nothing new is collected.

22 September 2026 — A second revision the same day. The retention section now names the third automatic deletion: the daily readings kept for readiness signals, after 90 days. Upstash, which counts requests so that too many in a short time can be refused, is added to the list of recipients. What we collect now includes injury reports, which are not sent to the AI coach. The list of what deleting your account destroys is now complete, and the security section now says who holds your password. Each of these describes something the app already did: nothing new is sent, and nothing new is collected.

Contact

Questions or requests: contact@tricoachai.ai.