Legal
Privacy Policy
What Tri-Train stores about you, what happens to data from Strava and Garmin, where AI requests go, and how to get rid of all of it.
Last updated: September 23, 2026
1. Controller and contact
Tri-Train is operated privately by Jonas Leuenberger, Switzerland. It is a personal, non-commercial project, not a company, and there is no paid plan.
Contact for any privacy request: [email protected]. The German-language versions of this notice and the provider details are at Datenschutzerklärung and Impressum.
Processing follows the revised Swiss Data Protection Act (revDSG) and, where it applies, the EU GDPR.
2. Scope
This notice covers the public pages (calculators, guides, blog), the signed-in application, the connected services you can link yourself, and the AI features.
Nothing here is shared with advertisers, and no data is sold. There is no advertising network and no third-party tracking or analytics script on the site.
3. Data you give us directly
Account data: name, email address and a password hash when you register with email, or the basic profile Google returns when you sign in with Google.
Athlete profile: optional details such as birth year, weight, threshold values (FTP, threshold pace, LTHR, CSS), heart-rate zones, time zone and training preferences.
Training data: activities, planned workouts, training plans, races, personal records, journal entries and notes — whether you enter them by hand or they arrive through an integration.
AI inputs: what you type into the chat, and the activity context that is assembled for an analysis. Generated insights are stored with the activity so they need not be produced twice.
4. Data from connected services
Strava. If you connect Strava, we import your activities including title, description, private notes, sport type, distance, duration, heart rate, power, cadence, GPS track and the underlying data streams. The connection uses Strava's official OAuth flow; the access and refresh tokens are stored encrypted. You can disconnect in the settings and revoke access in your Strava account at any time.
Garmin. If you connect Garmin, we import daily wellness values — sleep duration and sleep score, heart-rate variability, resting heart rate, stress level, Body Battery and training readiness — plus swim-length detail for pool sessions. We can also upload planned workouts to your watch and delete them again.
Health data has special protection. The Garmin wellness values are health data under both revDSG and GDPR. They are used only to display them back to you and to inform your own training analysis. They are never sold, never passed to advertisers, and never used to profile you for anyone else.
5. The Garmin sign-in, in plain terms
Garmin offers no OAuth flow for third-party applications. Connecting therefore requires your Garmin email and password, and there is no way around that.
Your Garmin password is never stored and never written to a log. It exists only for the duration of that one sign-in request. What we keep is the session token Garmin returns, encrypted at rest with AES-256-GCM. That token grants full access to your Garmin account, not read-only access — treat the connection accordingly.
Sign-in attempts are rate-limited, because Garmin locks accounts after repeated failures. Disconnecting in the settings deletes the stored token and stops further imports; values already imported stay part of your training history until you delete them or your account.
6. AI features and who sees your data
Activity insights, the structured activity analysis, the chat, the coach summary and plan comments are produced by a language model. The request goes to an Ollama instance on the operator's own hardware in Switzerland. Your data does not leave that infrastructure and is not sent to any cloud AI provider.
The operator chooses the model, not you; there is no way to enter your own AI configuration or API key. AI output is not used to train any model on our side.
7. Connected AI assistants (MCP)
You can connect an external AI assistant such as Claude to your account over an OAuth connection. Once connected, the assistant can read your activities, plans, notes, profile values and wellness data, and — if you granted the write permission — create, change and delete planned sessions and push workouts to your watch.
Everything that connection writes is journaled and can be undone. You can see every connected application and revoke it at any time in the settings; revoking takes effect immediately.
8. Calendar feed
The optional calendar subscription (iCal) is a URL containing a secret token, so that a calendar app can read it without signing in. Anyone who has that URL can read your planned sessions. Treat it like a password, and generate a new one in the settings if it leaks.
9. Technical data
The server writes operational logs (IP address, timestamp, requested path, user agent, error details) for operation, troubleshooting and abuse detection. They are deleted after 30 days.
Content is not in those logs. What you type into the AI chat is stored with your account in the database and is deleted together with the account – not in a log file. The logs only record that a chat happened, which provider and model ran it, and how long the answer was.
The application also records a small number of its own performance samples, such as how long a page took to respond. These are used to find slow pages, and there is no third-party analytics provider involved.
9a. What the operator can see
Tri-Train is run by one person, and that person has technical access to the database. That cannot be configured away, and we would rather say so than leave it out. In practice this access is used for operating the service and for troubleshooting, not for reading training data.
The operational overview inside the application deliberately shows no names, email addresses or free text of other users: per entry it shows a shortened account id, the sport and the timestamp. Until 11 Sep 2026 it showed the email address and the activity note; that was removed.
AI chats, journal entries and notes are not shown in that overview.
10. Legal bases
Providing the account and the training features rests on performance of a contract (Art. 6(1)(b) GDPR). Operating the platform securely and preventing abuse rests on legitimate interests (Art. 6(1)(f) GDPR).
Connecting Strava or Garmin, enabling a cloud AI provider, connecting an external AI assistant and subscribing to the calendar feed are optional and rest on your consent (Art. 6(1)(a) GDPR, and Art. 9(2)(a) for the health data from Garmin). You can withdraw that consent by disconnecting, with effect for the future.
11. Hosting, processors and backups
The application and the PostgreSQL database run on self-hosted infrastructure in Switzerland. Backups are written hourly to storage on the same infrastructure and are kept for 30 days.
Services you connect yourself: Google (sign-in), Strava, Garmin and any AI assistant you authorise. Each of those acts as an independent controller under its own terms; there is no processing agreement under Art. 28 GDPR with them, because each transfer rests on your own decision.
Services we use without you choosing them. These act as processors (Art. 28 GDPR, Art. 9 revDSG):
- Cloudflare Turnstile – the bot check on sign-up. Cloudflare receives your IP address and technical properties of your browser. Without it, sign-up would fill with throwaway accounts within days.
- The email provider – the only email Tri-Train sends is the password reset link, and the provider receives your email address for it.
No analytics or advertising network is embedded.
12. Cookies and local storage
We set technically necessary cookies for the login session, a cookie remembering your cookie choice, and one holding your language choice ("de" or "en") — solely so the page arrives in the right language. Nothing else is set without your consent, and there is no advertising or tracking cookie.
The application also uses your browser's local storage to cache pages you have already loaded and to keep settings such as language and theme. That data stays in your browser and is cleared when you clear site data.
13. Retention and deletion
Personal data is kept while your account exists. You can delete individual activities, notes and plans at any time, and you can delete the whole account in the settings.
Deleting the account removes your data from the live database immediately, including tokens for connected services and your AI chats. Copies in the rolling backups disappear at the latest 30 days later. Operational logs are deleted after 30 days, and they contain no content (see section 9).
14. Your rights
You have the right to access, correction, deletion, restriction, data portability and objection. Much of this you can do yourself in the settings; for anything else, an email to the address above is enough.
You can also lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), in the EU the authority for your country of residence.
15. Security
Traffic is TLS-encrypted, passwords are hashed, and tokens for connected services and AI providers are encrypted at rest with AES-256-GCM. Access to the underlying infrastructure is restricted to the operator.
Your free-text content is additionally encrypted in the database – AI chats, AI analyses, coach reports, journal entries and notes written by a connected AI assistant. A stolen copy of the database could not be read. Measurements are deliberately excluded: times, distances, heart rate, sleep and HRV are filtered, sorted and computed on, and encrypting them would make every analysis impossible. A dump would still show how much and how hard you trained, but no longer what you wrote about it.
No online service can promise absolute security. Use a unique password, and disconnect integrations you no longer need.
16. Changes
This notice is updated when features or legal requirements change; the current version is always on this page. Significant changes to how connected or health data is processed will be pointed out in the application.
German-language versions are at Datenschutzerklärung, AGB and Impressum.
You can also jump between the legal pages here: Privacy Policy and Terms of Service.