Your training data, treated like it matters
TriPeak holds some of the most personal data there is — your heart, your sleep, your body. Here is exactly what we collect, how each class is protected, and the rights you can exercise yourself, aligned with every US state privacy law (CCPA/CPRA, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Washington My Health My Data, and peers).
Data classification
| Class | Examples | Sensitivity | How it's protected |
|---|---|---|---|
| Identity | Email, display name | Personal | Encrypted at rest (AES-256) and in transit (TLS 1.2+). Used only to run your account. Never sold, never shared for advertising. |
| Health & biometric | Resting HR, HRV, sleep, VO₂max, weight | Sensitive — consumer health data | Highest tier. Your Apple Health export is parsed on your device — the raw file never reaches our servers; only daily summaries are stored, encrypted at rest, isolated per athlete by row-level security. Treated as consumer health data under state health-privacy laws (e.g. Washington My Health My Data). |
| Training activity | Workouts, distances, heart rate, power, plans | Personal | Encrypted at rest, per-athlete row-level security — no account can query another's rows, enforced in the database itself, not just the app. |
| Third-party credentials | Strava OAuth tokens | Secret | Double-encrypted: application-layer AES-256-GCM on top of database encryption. Never exposed to the browser, never included in exports. Deleted and revoked with Strava when you disconnect or delete. |
| Payment | Card details, billing | Financial | We never see or store card numbers — payment runs entirely on Stripe (PCI-DSS Level 1). We keep only your subscription status. |
Security standards
- • AES-256 encryption at rest for every table and backup
- • TLS 1.2+ for all data in transit
- • Row-level security: per-athlete isolation enforced in the database
- • OAuth tokens double-encrypted (app-layer AES-256-GCM)
- • On-device parsing for Apple Health — the raw export never leaves your machine
- • Least-privilege service roles; admin functions locked to authenticated RPCs
Your rights, self-service
- Access & portability. Download everything we hold about you as JSON — one click in Settings.
- Deletion. Delete your data or your entire account from Settings, effective immediately. Strava access is revoked at the same time. Encrypted backups age out within 30 days.
- No sale, no ads. We do not sell personal data or share it for targeted advertising. There is nothing to opt out of.
- Correction. Your profile and plan are directly editable in the product.
- Non-discrimination. Exercising your rights never changes your service.
Deletion, in plain language
Settings → Privacy & your data → Delete my data removes every activity, health record, and plan while keeping your login; Delete account removes everything including the login itself. Both take effect immediately, revoke our Strava access at Strava, and require no email, call, or waiting period — the same right in every US state, regardless of where you live. Questions or requests we can help with directly: privacy@journeytoironman.app