Privacy Policy — TriCoach AI
Last updated: 2026-09-22. Version 2026-09-22.2.
TriCoach AI ("we", "the app") is an adaptive triathlon coaching app operated by 22.O1 L.L.C-FZ, a company registered in the United Arab Emirates. It handles health and fitness data, which we treat as sensitive personal data. This policy explains what we collect, why, and the rights you have.
What we collect
- Account data: your email address and authentication credentials.
- Training & health data: workouts, heart rate, HRV, sleep, recovery/readiness, and the coaching decisions computed from them — provided by you (manual FIT/CSV upload) or, only if you connect them, by third-party services you authorise (e.g. Strava, WHOOP).
- Menstrual cycle, if you tell us: two separate things, used for different purposes. First, a standing answer to "Do you menstruate?" on the Nutrition page. That answer sets your dietary iron target, and it decides whether the morning check-in asks you the daily question at all. Second — only if it does ask — a single yes/no per day recorded on the morning check-in. The daily entry is optional, and skipping it stores nothing at all: a day you did not answer is never recorded as a "no". The daily log is used for one thing only, drawing your own logged days on your own progress chart so you can read your training against your cycle; it does not feed your iron target. Neither the standing answer nor the daily log is ever sent to the AI coach (see the list below), and both are deleted with everything else when you delete your account. The daily log is its own consent, off until you turn it on. Turn it off in Settings and every day you logged is erased at once; your standing answer and your iron target are untouched.
- Injury reports, if you make one: when you tell us something is bothering you, we keep the body part (chosen from a list), the 0–10 severity you give it, the day you say it started, and when you mark it better. A current report is shown back to you in the app, and every report is in your data export. Injury reports are not sent to the AI coach and do not change your plan or any session. A report you mark better is kept, so your own history stays readable, until you delete your account.
- Connection tokens: when you connect a provider, we store the access tokens needed to sync your data, encrypted at rest.
How we use it
Solely to provide the coaching product to you: to generate and adapt your training plan, compute readiness, and explain adjustments. We do not sell your data and do not use it for advertising.
AI coaching — off unless you turn it on
You can let a large language model run by Anthropic read your recent training and recovery data. When it is on, the model both decides how today's session changes — within fixed safety limits it cannot exceed — and writes the explanations you read. This is the only feature that sends your training or health data to an AI company.
It is off by default and stays off until you switch it on in Settings → AI coaching. We did not turn it on for existing accounts when we built it. With it off, the app is fully functional: the same decisions are made by fixed rules and we write the explanations ourselves.
When it is on, these are sent. Each line is sent only by a part of the app that exists for you: where something here has not appeared in your copy yet, nothing about it is sent, and it will not start without this list changing first.
- Anything you type: word for word, alongside everything below. That means your messages to the coach chat, and the optional note on your morning check-in or on a session you have logged. Nothing filters any of it first, so if you write about an injury, an illness, medication or how you are feeling, that goes too. Please do not type anything you would not want sent.
- Recovery: HRV, resting heart rate, sleep duration, recovery and readiness scores, and how each compares with your own baseline. Your morning check-in goes too: the soreness, mood and motivation answers you give, each on its 1–5 scale, and the single 0–100 figure they average into. The three are sent separately because the average hides them — a bad soreness score next to a good mood and motivation averages out to something unremarkable, and the coach would never mention it.
- Training: seven days of planned and completed sessions — sport, title, duration, distance, moving time, average heart rate — plus your most recent strength session and how closely you followed the plan. The morning decision sees seven days; a question you ask can look back further.
- Intensity: how your recent weeks split between easy and hard work, as time in each zone, prescribed against what you actually did, measured from your power or your heart rate.
- Benchmarks: the test results you have recorded and how they have moved — FTP, critical swim speed, threshold pace, threshold heart rate, and your body weight over time.
- Load: fitness, fatigue, form, weekly ramp, how balanced your training is across sports, where your readiness is heading tomorrow, today's session and the days it could move to.
- Race: race name and date, your thresholds (FTP, critical swim speed, threshold run pace), and projected splits. Fuelling amounts are not sent: they are removed from the payload before the model is called, and a reply that states one is rejected rather than shown to you.
- Nutrition: how many planned meals you hit, missed or logged.
- Past coach notes: the coach's own earlier notes and weekly reviews, so it can answer what it told you before. These are notes the app wrote about you; nothing you typed is kept among them.
Your name, email address, password and connected-account tokens are never included.
Three further things are never sent, whatever else grows on this list: your cycle log, the fuelling numbers worked out for your race, and the body-composition and aerodynamic figures behind your projections. The coach is never given those, and that is enforced in the code rather than promised in a prompt.
You can withdraw at any time from the same screen, and withdrawal is never blocked or delayed. Doing so stops all future sending and erases what the model already produced: the health snapshots we sent, the raw model output, and cached narratives. Three consequences are worth knowing before you do it.
- Two things go permanently. Your past weekly review summaries are blanked and cannot be rebuilt. And every reply the coach chat wrote to you is deleted — the conversation is not emptied out, those messages are removed. Your own messages are never touched: what you wrote stays, and so do any replies the app wrote itself without a model.
- Some things simply revert. Your Training Status text, your race brief and the coach's read on each session go back to the non-AI version, and return if you switch it back on.
- What the coach recalls is deleted. The notes it kept to answer "what did I tell you before" are built from model-written prose, so they go with it.
The record of what the coach changed in your plan is kept, because that is your training history.
Four things about sending your data to Anthropic, because they are the ones worth knowing before you turn this on:
- It is processed in the United States. Anthropic offers no EU region for this, so enabling AI coaching means your health data leaves the EU. We pin the request to the United States rather than leaving it unspecified, so that this sentence can name one country instead of saying "wherever it happened to route".
- It is not used to train their models. Anthropic's commercial terms state that retained data is never used for model training without express permission. We have not given any, and we will not.
- Your data and the model's replies are not kept afterwards. On the model we use, Anthropic does not retain conversation content once the response is returned. The exception: content flagged by their automated safety systems may be kept for up to two years. We would rather tell you that than describe the general case and let you discover the exception.
- The transfer runs under a data-processing agreement. Anthropic's commercial terms incorporate their Data Processing Addendum, which in turn incorporates the EU standard contractual clauses for transfers out of the EEA. That, together with your explicit consent, is the basis for the transfer.
We are asking Anthropic for a zero-retention arrangement, which would remove the flagged-content exception above. It is not in place yet. This page will say so when it is — we are telling you we are trying, not implying we have finished.
Readiness signals — off unless you turn it on
With this on, we compare your own recovery signals — heart-rate variability, resting heart rate and sleep — against your personal baseline each morning and keep a daily reading of typical, watch or ease, with the names of the signals outside their range, never the values. When two or more are outside their usual range, today's session is made at least one zone easier. The reading is computed and stored by us alone. Nothing about it is sent to anyone unless you have also turned AI coaching on, whose list above says what travels. Turn it off in Settings and every stored reading is deleted.
Who we share it with
We do not sell or rent your data. Every recipient is listed here.
| Recipient | What they receive | Basis |
|---|---|---|
| Anthropic (AI coaching) | The training and health data listed above | Your explicit consent — off by default |
| Vercel (application hosting) | Everything that passes through the app, as the infrastructure it runs on | Necessary to provide the service |
| Neon (database hosting) | Everything stored: your account, training, health and recovery records | Necessary to provide the service |
| Your browser's push service (Google, Mozilla or Apple, depending on your device) | Notification contents are encrypted so the relay cannot read them. It does see your device's push address, and when messages are sent. | Your device permission, per notification type |
| Clerk (sign-in and account security, United States) | Your email address, your name, and the identifiers that prove a sign-in is yours. No health or training data, and no access to anything stored in the app. | Necessary to provide the service |
| Cloudflare (bot check on the sign-up screen) | Your IP address and browser characteristics, sent by the Turnstile check Clerk runs to tell a person from an automated sign-up. No health or training data, and no account content. | Necessary to provide the service |
| Upstash (rate limiting, Frankfurt, EU) | An unreadable code computed from your account identifier or your IP address with a secret key only we hold — never the identifier or the address itself — and the times of your recent requests, so that too many requests in a short time can be refused. Each code expires within an hour of your last request. No health or training data. | Necessary to provide the service |
| Strava / WHOOP, if you connect them | Only credentials and requests for your data. We send them no health data — the flow is inbound only. | Your authorisation, revocable |
We do not currently use a separate error-reporting provider. When something breaks, the technical error is written to the application logs at Vercel, already listed above. If we add an error-reporting provider we will name it here, say which region it processes in, and raise the version of this policy.
Your browser contacts two third parties: Clerk, which handles signing in, and Cloudflare, whose Turnstile check Clerk uses on the sign-up screen to tell a person from an automated sign-up. A Content-Security-Policy restricts it to those two and this app's own servers, and nothing else — there are no analytics, trackers, advertising pixels or external fonts anywhere in the app.
Where it is processed, and on what basis
The app runs on Vercel, in its Frankfurt (EU) region, and its database is Neon, also in Frankfurt (EU). Your account and your training history stay there.
AI coaching is the one exception, and it only applies if you turn it on. It sends the data listed above to Anthropic, which processes it in the United States — a transfer out of the EU, made on the basis of your explicit consent and the standard contractual clauses in Anthropic's data-processing agreement. Leave AI coaching off and nothing about you leaves Frankfurt. Depending on your location, this policy is intended to meet the EU GDPR and the UAE PDPL.
Governing law. 22.O1 L.L.C-FZ is established in the United Arab Emirates, and this policy is governed by UAE federal law. Where the EU GDPR applies to you, the rights set out below are honoured under it as well.
Our legal bases:
- Performance of our contract with you — for building and adapting your plan, and for account security.
- Your explicit consent (GDPR Art. 9(2)(a)) — for AI coaching, for readiness signals and for cycle tracking, each of which involves health data. Each is recorded separately, with a timestamp and the version of the words you agreed to, and each is withdrawable at any time on its own.
- Your consent — for connecting a wearable service, and for notifications.
Security
The app is served over HTTPS and instructs your browser never to connect over plain HTTP again. Session cookies are restricted to the app and inaccessible to scripts. Signing in is handled by Clerk, listed above: if you use a password, Clerk holds it, not us. The one exception is an account created before sign-in moved to Clerk, which may still have its old password stored here, hashed and never in readable form, until the account is deleted.
The access tokens for any wearable service you connect are encrypted at rest with AES-256-GCM under a key held outside the database. To be precise about scope: that encryption covers those tokens. Your training and health records are stored in ordinary database columns, protected by access control rather than by application-level encryption — whether the underlying storage is encrypted is a property of Neon, our database host.
Every request is scoped to your own account, and a session stops working the moment the account it belongs to is deleted.
Your rights
- Withdraw consent: turn AI coaching, readiness signals or cycle tracking off at any time in Settings. Each takes effect immediately and is never harder than turning it on. Turning readiness signals off deletes the daily readings we stored; turning cycle tracking off erases every day you logged.
- Access & export: download everything we hold about you from Settings → Export my data, as a JSON file generated at the moment you ask.
- Deletion: delete your account from Settings. See below for exactly what that does.
- Disconnect: revoke any wearable connection at any time from Settings.
- Depending on your jurisdiction, you may also have rights to rectification, restriction, and to lodge a complaint with a supervisory authority.
Most of those you exercise yourself, from Settings, and they take effect immediately — no request, no queue, no waiting on us. If you would rather ask us, or you want something there is no button for, write to contact@tricoachai.ai. We answer within one month. If a request turns out to be genuinely complicated we may need longer than that, and if so we will tell you inside the first month — with what we are doing and when to expect it — rather than let it run on in silence.
Data retention
We keep your training and health data for as long as your account exists. We do not age it out, because a coaching history is only useful whole — your fitness two years ago is what makes this year's numbers mean anything.
Three exceptions run automatically: the detailed health snapshot attached to each daily coaching decision is erased after 90 days (the decision itself is kept), the daily readings kept for readiness signals, if you turned them on, are deleted after 90 days, and raw records from connected services are deleted after 30 days, or 90 if they failed to process.
What deleting your account actually does
It happens immediately: your records are removed from the live database, with no grace period and no soft-delete. One qualification, because we would rather be precise than reassuring. Our database provider keeps a short rolling change history — currently six hours — so that an operational failure such as a bad deployment can be undone. Within that window, a restore would technically bring deleted rows back with everything else. We do not use it to reverse account deletions, and once the window has passed your data is unrecoverable by anyone, including us. Your profile, races, plans, sessions and the record of changes to them, activities, recovery records (including any cycle days you logged), injury reports, test results, body measurements, training load, readiness readings, coaching decisions, suggested changes, weekly reviews, the coach's notes, coach chat conversations, nutrition, strength logs, connected services with their tokens and the raw records they sent us that we had matched to your account, notification subscriptions, any authentication credentials we still held, and consent records are all destroyed together.
Your sign-in record at Clerk — your email address, your name, and the identifiers that prove a sign-in is yours — is deleted by the same action. If Clerk cannot be reached at that moment, we keep one thing and one thing only: the identifier Clerk uses for you, so that we can finish the job. We retry until it succeeds, and that identifier is deleted the moment it does. It is the only thing that outlives your account, it is useless to anyone who is not us, and it cannot be used to reach any of the data we have just destroyed.
We ask you to type the word DELETE first, because a live session on an unlocked phone should not be one tap away from erasing your training history.
Three things to know:
- Your connection at Strava or WHOOP stays live. Deleting your account here destroys our copy of your tokens, which means we can no longer tell them to revoke it. If you want that access withdrawn, disconnect before deleting, or revoke it in that service's own settings afterwards.
- Your consent record is destroyed too. We keep an audit trail of every consent given and withdrawn while your account exists — but erasure means erasure, so it goes with everything else.
- Your device may keep a cached copy. The app clears its offline cache when you delete, and tells you if that fails. If it does fail, clear this site's data in your browser — particularly on a shared device.
Age
TriCoach AI is for adults. You must be 18 or over to have an account, and our Terms of Service say the same thing.
The bar is 18 rather than something lower because of what the app actually does: it works out caffeine and sodium-bicarbonate doses in milligrams from your body weight, prescribes barbell loads in kilograms, and checks your energy intake against a figure established in adult athletes. None of that has a version written for a body that is still growing.
We should be straightforward that this is a rule rather than a control. Setting up your profile asks your age, but it is a number you type in and nothing checks it. We do not ask for your date of birth and we do not ask for proof, because verifying age properly would mean collecting identity documents from everyone — more data about you, not less, to enforce a rule most people were never going to break.
If you believe someone under 18 has created an account, write to contact@tricoachai.ai. If we find out ourselves, we will get in touch, explain why, and give them a way to download their data before the account is deleted.
Changes
We will update this page and the "last updated" date when this policy changes.
6 September 2026 — Readiness signals and cycle tracking are now named beside AI coaching as explicit-consent processing, with what withdrawing each one deletes. The AI coaching consent card now says on the card itself that processing happens in the United States, which this page already said. Nothing new is sent, and nothing new is collected.
22 September 2026 — The line about anything you type now names the optional note on your morning check-in and on a logged session by what it is, instead of quoting the wording one of those two screens happens to print. The same change is on the AI coaching consent card. Nothing new is sent, and nothing new is collected.
22 September 2026 — A second revision the same day. The retention section now names the third automatic deletion: the daily readings kept for readiness signals, after 90 days. Upstash, which counts requests so that too many in a short time can be refused, is added to the list of recipients. What we collect now includes injury reports, which are not sent to the AI coach. The list of what deleting your account destroys is now complete, and the security section now says who holds your password. Each of these describes something the app already did: nothing new is sent, and nothing new is collected.
Contact
Questions or requests: contact@tricoachai.ai.