← Back to Triku

Legal

Privacy Policy

Effective date: 24 September 2026 · Version 1.1 · Applies to the Triku iOS app, the Triku API and this website.

In short

1. Who we are

Triku is operated by BV Froteq, established at Gasmeterstraat 36, 9100 Sint-Niklaas, Belgium (“Triku”, “we”, “us”). We are the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR).

You can reach us about privacy at privacy@triku.app. We have not appointed a data protection officer because we are not legally required to; the same address reaches the person responsible for data protection.

2. What this policy covers

This policy applies to:

It does not cover third-party services you connect to Triku or use alongside it, such as Apple Health, Apple’s App Store, or the app you use to record workouts on your watch. Those have their own policies.

3. Data we collect

We collect only what the features you use need. Nothing below is collected until you create an account, and health data is only read after you explicitly allow it in iOS.

3.1 Account data

DataSourceWhy
Email address, and a display name and profile picture when your sign-in provider shares them Sign in with Apple, Google Sign-In, or the email you enter for a magic link To create and secure your account and address you by name
A random account identifier Generated when you sign up To link your data to your account without using your email as a key
Preferences: measurement units (km or miles), maximum heart rate, date of birth Entered by you, all optional except units Units for display; maximum heart rate and age to calculate heart-rate zones and strain
Sign-in tokens Issued by our authentication provider To keep you signed in; stored on your device and verified by the API

If you use Sign in with Apple and choose Hide My Email, we only receive Apple’s private relay address. If you sign in with Google, Google shares your name, email and picture with us; we do not receive your Google password.

3.2 Workout and health data

When you connect Apple Health, the app reads your workouts and heart rate and sends them to the Triku API. For each workout that is: the activity type, start and end time, time zone, duration, distance, energy burned, elevation gain, average and maximum heart rate, time spent in each heart-rate zone, a heart-rate curve sampled over the workout (up to 600 points), the recording device and app name, and a source identifier so the same workout is not imported twice. Section 4 explains the rules we follow for this data.

From this data we compute and store derived values: a training load and a 0–21 strain score per workout, daily and weekly summaries, a running-fitness estimate and training paces.

3.3 Training plans and coach messages

3.4 Routes and location

3.5 Technical data

The app contains no advertising SDK, no third-party analytics SDK and no tracking pixels. We do not build advertising profiles.

4. Apple Health data

Health data is sensitive, and we treat it under stricter rules than the rest, in line with Apple’s HealthKit requirements and the GDPR rules for health data:

5. How we use your data

PurposeData used
Create, secure and let you sign in to your accountAccount data, sign-in tokens, server logs
Show your activity: workouts, strain, heart-rate zones, weekly trends, streaksWorkout and health data, preferences
Estimate your running fitness and training pacesRunning workouts (distance, duration, dates)
Build and adapt a training planPlan answers, fitness estimate, workout history, coach messages and transcripts
Draw, save and export routes as GPX filesRoute points and computed path
Keep the service reliable and secure, detect abuse, debug problemsServer logs, technical data
Answer your support and privacy requestsWhatever you send us, and account data to verify you
Comply with legal obligationsOnly what the law requires in a specific case

We do not use your data to train machine-learning models, and our contracts with providers forbid them from doing so with your data (section 7).

7. Who we share data with

We share data only with providers that process it on our behalf and under our instructions, with data-processing agreements in place. We do not sell personal data.

ProviderWhat they doDataLocation
Supabase Authentication and database hosting All account, workout, plan and route data EU (Ireland)
Railway Hosts the Triku API Data passes through the API; server logs EU West (Amsterdam)
PostHog Cookieless analytics for this website Pages viewed, clicks, referring site, campaign tags, browser, device, language and time zone. The IP address only to count unique visitors; it is not stored. EU (Frankfurt, Germany)
OpenAI Writes the coaching text for plans; understands your written messages; transcribes voice memos Your plan answers and notes, session descriptions, derived paces, coach messages, voice memo audio and transcript. No workouts or heart-rate data. United States, under the EU Standard Contractual Clauses. OpenAI’s API terms state that data sent via the API is not used to train their models.
FOSSGIS e.V. (Valhalla routing) and OpenStreetMap Computes the road-following path between the points of a route; serves map tiles on the web version The coordinates of the route points you place (not your live location); your IP address as with any web request Germany / EU
Apple Sign in with Apple, App Store and TestFlight distribution, Apple Maps in the app Sign-in identity; App Store analytics per your iOS settings; map tiles requested by the app Per Apple’s privacy policy
Google Google Sign-In (only if you choose it) Sign-in identity Per Google’s privacy policy
Expo (EAS) Builds and distributes the app binary No user data United States

We may also disclose data if required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition, in which case this policy continues to apply and you will be told.

8. Where data is stored and transferred

Your account, workouts, plans and routes are stored in the European Union. Some providers listed above process data outside the EU, notably OpenAI in the United States. For those transfers we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards.

9. How long we keep data

DataRetention
Account, workouts, plans, routes, coach conversationsFor as long as your account exists. Deleted immediately when you delete your account in the app (or within 30 days of an emailed request); backups expire within a further 30 days.
Individual workouts, plans or routes you delete in the appRemoved immediately from your account; gone from backups within 30 days.
Voice memos (audio)Sent for transcription and not stored by us afterwards. The transcript is kept as part of the plan’s adjustment history.
Server logs30 days.
Website analyticsAs long as our PostHog plan keeps events, currently 12 months. The events contain no cookie, stored IP address or identifier that links visits across days.
Support and privacy correspondenceUp to 2 years, so we can show we handled your request.
Data we must keep by lawFor the period the law requires.

10. Your rights and choices

In the app and in iOS

Under the GDPR

You have the right to:

To exercise any of these, email privacy@triku.app from the address linked to your account, or tell us which sign-in you use so we can verify it is you. We respond within one month; for complex requests we may extend by two further months and will tell you why. Requests are free unless they are clearly unfounded or excessive.

Account deletion. Open You → Delete account in the app. Your account and every record linked to it (profile, workouts, plans, routes, coach conversations) are deleted immediately; copies in backups expire within 30 days. You can also email us with the subject “Delete my account” and we will do it for you within 30 days. Deletion is permanent; we cannot restore a deleted account.

If you are outside the EU

We give everyone the rights above regardless of where they live. If you are a California resident, they correspond to your rights to know, delete, correct and to non-discrimination under the CCPA/CPRA; we do not “sell” or “share” personal information as those terms are defined there. If you are in the United Kingdom, the UK GDPR gives you equivalent rights and you may complain to the ICO.

11. Security

No system is perfectly secure. Keep your Apple ID and Google account protected, and tell us immediately at the address below if you suspect unauthorised access.

12. Children

Triku is not directed at children. You must be at least 16 years old to create an account (or the lower age of digital consent in your EU country, but never under 13). We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

13. This website

This website uses PostHog to measure how visitors use it, so we can see which pages and features help and which don’t. It runs in cookieless mode: it sets no cookies and stores nothing in your browser.

Fonts and images are loaded from the website’s own server. The hosting provider keeps a standard request log, which includes your IP address and browser type, for a short period for security.

14. Changes to this policy

We will update this policy when the app changes in ways that affect your data, for example when a new data source such as Garmin or Strava is added. Material changes are announced in the app before they take effect, and the effective date at the top is always the date of the current version. Earlier versions are available on request.

15. Contact

BV Froteq
Gasmeterstraat 36, 9100 Sint-Niklaas
Belgium
privacy@triku.app