Legal
Privacy Policy
In short
- Triku reads workouts and heart rate from Apple Health, only after you allow it, and only to show you your own training.
- Your data is stored in the European Union and is never sold, never used for advertising, and never shared with data brokers.
- When you ask your coach to adjust a plan, the text or voice memo you send is processed by OpenAI to understand it. Your Health data is not sent to OpenAI.
- You can disconnect Apple Health, delete individual workouts, plans and routes in the app, and delete your whole account from the You tab at any time.
1. Who we are
Triku is operated by BV Froteq, established at Gasmeterstraat 36, 9100 Sint-Niklaas, Belgium (“Triku”, “we”, “us”). We are the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR).
You can reach us about privacy at privacy@triku.app. We have not appointed a data protection officer because we are not legally required to; the same address reaches the person responsible for data protection.
2. What this policy covers
This policy applies to:
- the Triku app for iPhone;
- the Triku API, the server the app talks to;
- this website.
It does not cover third-party services you connect to Triku or use alongside it, such as Apple Health, Apple’s App Store, or the app you use to record workouts on your watch. Those have their own policies.
3. Data we collect
We collect only what the features you use need. Nothing below is collected until you create an account, and health data is only read after you explicitly allow it in iOS.
3.1 Account data
| Data | Source | Why |
|---|---|---|
| Email address, and a display name and profile picture when your sign-in provider shares them | Sign in with Apple, Google Sign-In, or the email you enter for a magic link | To create and secure your account and address you by name |
| A random account identifier | Generated when you sign up | To link your data to your account without using your email as a key |
| Preferences: measurement units (km or miles), maximum heart rate, date of birth | Entered by you, all optional except units | Units for display; maximum heart rate and age to calculate heart-rate zones and strain |
| Sign-in tokens | Issued by our authentication provider | To keep you signed in; stored on your device and verified by the API |
If you use Sign in with Apple and choose Hide My Email, we only receive Apple’s private relay address. If you sign in with Google, Google shares your name, email and picture with us; we do not receive your Google password.
3.2 Workout and health data
When you connect Apple Health, the app reads your workouts and heart rate and sends them to the Triku API. For each workout that is: the activity type, start and end time, time zone, duration, distance, energy burned, elevation gain, average and maximum heart rate, time spent in each heart-rate zone, a heart-rate curve sampled over the workout (up to 600 points), the recording device and app name, and a source identifier so the same workout is not imported twice. Section 4 explains the rules we follow for this data.
From this data we compute and store derived values: a training load and a 0–21 strain score per workout, daily and weekly summaries, a running-fitness estimate and training paces.
3.3 Training plans and coach messages
- Plan answers: goal distance, target time, race date, days per week, days you cannot train, experience level and any notes you type in the plan quiz.
- The plan itself and its history: each session, whether you marked it done or skipped, and every adjustment with the reason.
- Messages to your coach: the text you write, or a voice memo you record, when you ask for a plan change. Voice memos are transcribed to text; the transcript and, briefly, the audio are handled as described in section 7.
3.4 Routes and location
- Routes you draw: the route name, the points you place on the map, and the path between them computed by a routing service. These are stored with your account so you can reopen and export them.
- Your device location: used only to centre the map on where you are while you draw. It is read on your device when you tap the locate button or open the route builder, shown as a dot, and is not sent to our servers or stored. You can decline the iOS location permission; the map still works.
3.5 Technical data
- Server logs: when the app calls our API we log the time, the endpoint, the response status and the request’s IP address, for security and debugging. Logs are kept for a short period (section 9).
- App and device information Apple provides to developers about crashes and installs through App Store Connect and TestFlight, in aggregated or pseudonymised form, according to your iOS analytics settings.
The app contains no advertising SDK, no third-party analytics SDK and no tracking pixels. We do not build advertising profiles.
4. Apple Health data
Health data is sensitive, and we treat it under stricter rules than the rest, in line with Apple’s HealthKit requirements and the GDPR rules for health data:
- We read Health data only with your explicit permission, requested through the standard iOS Health permission screen. You choose which categories to share and can change that anytime in Settings → Health → Data Access & Devices → Triku.
- We only read. Triku does not write anything to Apple Health. (Apple requires our app to declare a write purpose string because the Health library we use references the write API; we do not use it.)
- We use Health data solely to provide Triku’s features to you: showing your workouts, computing strain, zones and trends, and building or adapting your training plan.
- We never use Health data for advertising, marketing, or any purpose other than the features you use; never sell it; never share it with data brokers, insurers, employers or advertisers; and never use it to make decisions with legal or similarly significant effects.
- Health data is not sent to OpenAI. The plan generator sends only your goal answers, the paces derived from your best recent run, and a description of the planned sessions, so the coach can write the plan’s wording. Raw workouts and heart-rate samples stay on our servers.
- Disconnecting Apple Health stops new imports immediately. Workouts already imported stay in your account until you delete them individually or ask us to delete your account.
5. How we use your data
| Purpose | Data used |
|---|---|
| Create, secure and let you sign in to your account | Account data, sign-in tokens, server logs |
| Show your activity: workouts, strain, heart-rate zones, weekly trends, streaks | Workout and health data, preferences |
| Estimate your running fitness and training paces | Running workouts (distance, duration, dates) |
| Build and adapt a training plan | Plan answers, fitness estimate, workout history, coach messages and transcripts |
| Draw, save and export routes as GPX files | Route points and computed path |
| Keep the service reliable and secure, detect abuse, debug problems | Server logs, technical data |
| Answer your support and privacy requests | Whatever you send us, and account data to verify you |
| Comply with legal obligations | Only what the law requires in a specific case |
We do not use your data to train machine-learning models, and our contracts with providers forbid them from doing so with your data (section 7).
6. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)): account, workouts, plans, routes and everything needed to deliver the app you asked for.
- Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) for health data, given through the iOS Health permission screen, and for location through the iOS location prompt. You can withdraw either at any time in iOS Settings; withdrawing does not affect processing that already happened.
- Legitimate interests (Art. 6(1)(f)): security logging, abuse prevention, debugging and cookieless analytics of this website (section 13). We have balanced these against your interests and keep the data minimal and short-lived.
- Legal obligation (Art. 6(1)(c)): where we must keep or disclose data by law.
7. Who we share data with
We share data only with providers that process it on our behalf and under our instructions, with data-processing agreements in place. We do not sell personal data.
| Provider | What they do | Data | Location |
|---|---|---|---|
| Supabase | Authentication and database hosting | All account, workout, plan and route data | EU (Ireland) |
| Railway | Hosts the Triku API | Data passes through the API; server logs | EU West (Amsterdam) |
| PostHog | Cookieless analytics for this website | Pages viewed, clicks, referring site, campaign tags, browser, device, language and time zone. The IP address only to count unique visitors; it is not stored. | EU (Frankfurt, Germany) |
| OpenAI | Writes the coaching text for plans; understands your written messages; transcribes voice memos | Your plan answers and notes, session descriptions, derived paces, coach messages, voice memo audio and transcript. No workouts or heart-rate data. | United States, under the EU Standard Contractual Clauses. OpenAI’s API terms state that data sent via the API is not used to train their models. |
| FOSSGIS e.V. (Valhalla routing) and OpenStreetMap | Computes the road-following path between the points of a route; serves map tiles on the web version | The coordinates of the route points you place (not your live location); your IP address as with any web request | Germany / EU |
| Apple | Sign in with Apple, App Store and TestFlight distribution, Apple Maps in the app | Sign-in identity; App Store analytics per your iOS settings; map tiles requested by the app | Per Apple’s privacy policy |
| Google Sign-In (only if you choose it) | Sign-in identity | Per Google’s privacy policy | |
| Expo (EAS) | Builds and distributes the app binary | No user data | United States |
We may also disclose data if required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition, in which case this policy continues to apply and you will be told.
8. Where data is stored and transferred
Your account, workouts, plans and routes are stored in the European Union. Some providers listed above process data outside the EU, notably OpenAI in the United States. For those transfers we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards.
9. How long we keep data
| Data | Retention |
|---|---|
| Account, workouts, plans, routes, coach conversations | For as long as your account exists. Deleted immediately when you delete your account in the app (or within 30 days of an emailed request); backups expire within a further 30 days. |
| Individual workouts, plans or routes you delete in the app | Removed immediately from your account; gone from backups within 30 days. |
| Voice memos (audio) | Sent for transcription and not stored by us afterwards. The transcript is kept as part of the plan’s adjustment history. |
| Server logs | 30 days. |
| Website analytics | As long as our PostHog plan keeps events, currently 12 months. The events contain no cookie, stored IP address or identifier that links visits across days. |
| Support and privacy correspondence | Up to 2 years, so we can show we handled your request. |
| Data we must keep by law | For the period the law requires. |
10. Your rights and choices
In the app and in iOS
- Disconnect Apple Health on the You tab, or revoke access in iOS Settings → Health.
- Delete a workout from its detail screen, archive or delete a plan, and delete a route from its page.
- Export a route as a GPX file at any time.
- Sign out or delete your account on the You tab.
- Location is optional; decline or revoke it in iOS Settings → Privacy & Security → Location Services.
Under the GDPR
You have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data;
- erase your data (“right to be forgotten”), including deleting your whole account;
- restrict or object to processing based on legitimate interests;
- data portability: receive your data in a structured, machine-readable format;
- withdraw consent at any time for health and location data;
- lodge a complaint with a supervisory authority. In Belgium that is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels. You may also complain to the authority of the EU country where you live.
To exercise any of these, email privacy@triku.app from the address linked to your account, or tell us which sign-in you use so we can verify it is you. We respond within one month; for complex requests we may extend by two further months and will tell you why. Requests are free unless they are clearly unfounded or excessive.
Account deletion. Open You → Delete account in the app. Your account and every record linked to it (profile, workouts, plans, routes, coach conversations) are deleted immediately; copies in backups expire within 30 days. You can also email us with the subject “Delete my account” and we will do it for you within 30 days. Deletion is permanent; we cannot restore a deleted account.
If you are outside the EU
We give everyone the rights above regardless of where they live. If you are a California resident, they correspond to your rights to know, delete, correct and to non-discrimination under the CCPA/CPRA; we do not “sell” or “share” personal information as those terms are defined there. If you are in the United Kingdom, the UK GDPR gives you equivalent rights and you may complain to the ICO.
11. Security
- All traffic between the app, the API and our providers is encrypted with TLS. Data is encrypted at rest by our hosting providers.
- The API verifies a signed token on every request and only ever returns the data of the signed-in account. The database additionally enforces row-level access rules so one user’s rows cannot be read by another.
- Sign-in is delegated to Apple, Google or a one-time email link; we do not store passwords.
- Access to production systems is limited to the people who operate Triku, protected by multi-factor authentication.
- If a breach affecting your data ever occurs, we will notify the supervisory authority within 72 hours and inform you without undue delay when the law requires it.
No system is perfectly secure. Keep your Apple ID and Google account protected, and tell us immediately at the address below if you suspect unauthorised access.
12. Children
Triku is not directed at children. You must be at least 16 years old to create an account (or the lower age of digital consent in your EU country, but never under 13). We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
13. This website
This website uses PostHog to measure how visitors use it, so we can see which pages and features help and which don’t. It runs in cookieless mode: it sets no cookies and stores nothing in your browser.
- What is measured: the pages you view, the buttons, links and sample features you use, how far you scroll, the site that referred you and any campaign tags in the link, your browser, operating system, device type, screen size, language and time zone, and how quickly the page loaded.
- What is not: your answers in the starting-point finder, your name or email address, and anything from your Triku account. We do not use website analytics for advertising.
- Counting visitors: to count unique visitors without a cookie, PostHog briefly combines your IP address, browser details and the website’s name with a random value that is discarded every day, and keeps only the resulting code. Your IP address is not stored, and visits on different days cannot be linked to each other.
- Your choice: if your browser sends a Do Not Track or Global Privacy Control signal, the analytics script does not load. You can also object to this processing by emailing us.
Fonts and images are loaded from the website’s own server. The hosting provider keeps a standard request log, which includes your IP address and browser type, for a short period for security.
14. Changes to this policy
We will update this policy when the app changes in ways that affect your data, for example when a new data source such as Garmin or Strava is added. Material changes are announced in the app before they take effect, and the effective date at the top is always the date of the current version. Earlier versions are available on request.
15. Contact
BV Froteq
Gasmeterstraat 36, 9100 Sint-Niklaas
Belgium
privacy@triku.app