TRIPEAKBeta
Data & Trust

Your training data, treated like it matters

TriPeak holds some of the most personal data there is — your heart, your sleep, your body. Here is exactly what we collect, how each class is protected, and the rights you can exercise yourself, aligned with every US state privacy law (CCPA/CPRA, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Washington My Health My Data, and peers).

Data classification

ClassExamplesSensitivityHow it's protected
IdentityEmail, display namePersonalEncrypted at rest (AES-256) and in transit (TLS 1.2+). Used only to run your account. Never sold, never shared for advertising.
Health & biometricResting HR, HRV, sleep, VO₂max, weightSensitive — consumer health dataHighest tier. Your Apple Health export is parsed on your device — the raw file never reaches our servers; only daily summaries are stored, encrypted at rest, isolated per athlete by row-level security. Treated as consumer health data under state health-privacy laws (e.g. Washington My Health My Data).
Training activityWorkouts, distances, heart rate, power, plansPersonalEncrypted at rest, per-athlete row-level security — no account can query another's rows, enforced in the database itself, not just the app.
Third-party credentialsStrava OAuth tokensSecretDouble-encrypted: application-layer AES-256-GCM on top of database encryption. Never exposed to the browser, never included in exports. Deleted and revoked with Strava when you disconnect or delete.
PaymentCard details, billingFinancialWe never see or store card numbers — payment runs entirely on Stripe (PCI-DSS Level 1). We keep only your subscription status.

Security standards

  • • AES-256 encryption at rest for every table and backup
  • • TLS 1.2+ for all data in transit
  • • Row-level security: per-athlete isolation enforced in the database
  • • OAuth tokens double-encrypted (app-layer AES-256-GCM)
  • • On-device parsing for Apple Health — the raw export never leaves your machine
  • • Least-privilege service roles; admin functions locked to authenticated RPCs

Your rights, self-service

  • Access & portability. Download everything we hold about you as JSON — one click in Settings.
  • Deletion. Delete your data or your entire account from Settings, effective immediately. Strava access is revoked at the same time. Encrypted backups age out within 30 days.
  • No sale, no ads. We do not sell personal data or share it for targeted advertising. There is nothing to opt out of.
  • Correction. Your profile and plan are directly editable in the product.
  • Non-discrimination. Exercising your rights never changes your service.

Deletion, in plain language

Settings → Privacy & your data → Delete my data removes every activity, health record, and plan while keeping your login; Delete account removes everything including the login itself. Both take effect immediately, revoke our Strava access at Strava, and require no email, call, or waiting period — the same right in every US state, regardless of where you live. Questions or requests we can help with directly: privacy@journeytoironman.app