Short version: encrypted on the way, encrypted where it rests, and the credentials for your connected services sealed with a key that only the server holds.
- In transit – every connection between your phone or browser, TriHonu, your watch platform (Terra) and our providers uses TLS.
- At rest – the database and file storage are encrypted by the hosting provider (Supabase, on AWS). That covers your activities, recovery metrics, photos and conversations.
- Access credentials – the tokens that let TriHonu read your watch data (Garmin, Wahoo, calendar links) are additionally encrypted in the application with a separate server-side key before they are stored. Someone holding a copy of the database could not use them. We never hold your Garmin password: you sign in on Garmin's own page.
- Who can see it – accounts are separated at the database level. Beyond you, the only person with access is the operator running TriHonu, and only where needed to run the service or to help you when you ask. Your coach is software; the training and health context it needs is sent to the AI provider to generate your coaching and is not used to train models.
What we deliberately do not do: encrypt each individual metric (heart rate, HRV, sleep) with its own key inside the application. It would stop the database from computing your weekly load, your recovery trend and your plan compliance, and it would add little over the provider's encryption at rest – your coach needs those numbers in the clear on every request anyway. If that changes, this page changes.
Your controls: disconnect any platform in Settings › Connections – new data stops arriving immediately. Delete your account and everything in it under Profile › Account, any time, without asking us. The Privacy Policy is the full statement.
Some of these steps happen inside TriHonu, where this article cannot take you while you are signed out. Sign in
Where this lives in the app: Settings