This Privacy Policy explains what personal data TriHonu (“we”, “us”, “our”) collects, why we collect it, who we share it with, and the rights you have over it. TriHonu is an AI-assisted triathlon-coaching app. Because it works with your health and training data, we treat your privacy seriously.
1. Who we are
The controller responsible for your data is TriHonu GmbH, Winkelweg 5, CH-8127 Forch, Switzerland, registered in the commercial register of the canton of Zürich under CHE-219.470.047, reachable at hello@trihonu.com. TriHonu operates at trihonu.com.
2. What we collect
- Account — your email address and, if you set one, a password (stored only as a salted hash by our authentication provider; we never see it in plain text).
- Profile — name, sex, date of birth, height, weight, home location, language, your chosen AI coach, and your goals and races.
- Health & training data — activities and their metrics (heart rate, power, pace, distance, duration), recovery and wellness signals (HRV, sleep, resting HR, body battery), daily check-ins, injuries and niggles, performance thresholds, whether you have told us that something you take affects your heart rate (a yes/no only — we never ask for or store the name of any medication), and nutrition information (dietary preferences, targets, and any food you log). Some of this is health data: a special category of personal data under the GDPR, and sensitive personal data under the Swiss FADP (see “Legal bases”).
- Connected services — if you connect a device or training platform (Garmin, Polar, COROS, Suunto, Oura, Withings, Wahoo, Hammerhead, Concept2, Hevy, Fitbod, Strong, StrongLifts, CORE, Zwift, Rouvy, TrainerRoad, TrainingPeaks, Apple Health or Google Health, which also carries Fitbit devices), we import the activity, workout, and wellness data you authorize, and store the access tokens needed to keep syncing. CORE reports core body temperature, which is health data.
- Apple Health — if you install the TriHonu iPhone app and connect Apple Health, we read the workout, sleep, heart-rate and recovery data you grant, and write your planned sessions back so they appear on your Apple Watch. This is described in full under “Apple Health (HealthKit)” below.
- AI coaching — your conversations with the AI coach, and the training and health context we send to the AI model so it can generate your coaching.
- Media — photos or videos you choose to upload (e.g. meals, gear, or technique clips).
- Feedback & surveys — what you write to us in the in-app feedback form, including any screenshots you attach, and your answers to a survey we may send you during your trial. Stored with your account so we can reply and act on it.
- Technical — sign-in cookies and minimal usage records (including AI-usage counts we keep to manage costs). We do not use third-party advertising or cross-site tracking. Three features do load content into your browser from a third party (see “Embedded content”).
3. Legal bases (GDPR / Swiss FADP)
Where the EU GDPR or the Swiss FADP applies, we rely on:
- Performance of a contract — to provide the coaching service you signed up for.
- Your explicit consent — for health / special-category data (Art. 9(2)(a) GDPR), given when you accept the in-app disclaimer and this policy. You can withdraw consent at any time by deleting the relevant data or your account.
- Legitimate interests — to keep the service secure and within cost and fair-use limits, to prevent abuse (in particular taking a one-time trial more than once), and to understand and improve the service from the feedback you give us, balanced against your rights.
4. How we use your data
- Generate your plan, morning briefings, weekly reviews, and coaching replies.
- Read your feedback and survey answers to improve TriHonu and, where you have asked us to, reply to you.
- Adapt your training to your recovery, goals, and how you’re responding.
- Sync with your connected devices and provide nutrition guidance.
- Judge whether heart rate is a meaningful signal for you. This is the only thing your answer about heart-rate medication is used for: if you tell us something you take affects it, your coach stops reading heart-rate zones and recovery scores as fitness and works from pace, power and how you feel instead. Answering is optional and you can change or clear the answer at any time in your profile.
- Keep your account secure and within fair-use limits.
We do not sell your personal data.
Health data from Apple Health is never used for advertising or marketing, never sold, and never shared with anyone for those purposes. We use it only to coach you: to build and adapt your plan, to judge your recovery, and to write your planned sessions back to your watch. It is not used to build a profile of you for any other purpose, and it is not disclosed to third parties without your consent, except where the law requires it.
5. AI processing & service providers
AI transparency statement. TriHonu is an AI coaching service. Your coaching — plan changes, briefings, reviews and chat replies — is written by an AI model (Anthropic’s Claude) from your own training context: your plan, your recorded sessions, the daily health data of the devices you connect (including Garmin), and what you tell your coach. It is used only to coach you. It is never used to train or improve any AI model — neither ours nor Anthropic’s — and never shared with other users. This processing needs your explicit consent, which you give before your data is processed by AI. You can withdraw it at any time in Profile › Account; from that moment your data is no longer processed by AI, and you keep using TriHonu without AI. The providers involved are listed below. We update this statement when the law, our providers’ rules or our processing change.
To run the service we use the following providers, and pass data to the following other recipients, each only to the extent needed:
- Anthropic (Claude) — receives the relevant training/health context and your chat messages to generate your coaching. Anthropic does not use data sent through its API to train its models, and retains it only for a limited period for safety and abuse monitoring.
- Your device or platform provider — whichever one you connect yourself (§2 lists the supported ones). Through Terra, the data you have shared flows from there to us and planned sessions flow back. Processing at the provider is governed by their own terms and privacy policy, not ours, and we are not responsible for it.
- Terra — the data platform that connects TriHonu to your watch provider. When you connect a supported service, Terra receives your authorization, relays your activity, workout, and wellness data from the provider to us, and delivers planned workouts back to your device. Apple Health is the exception: current versions of the TriHonu iPhone app send it to us directly (see “Apple Health”), and only older versions of the app still relay it through Terra. Terra does not receive your name or email address; the connection is keyed to a technical identifier.
- Garmin — when you connect Garmin through TriHonu’s own Garmin app, TriHonu receives your Garmin data directly from Garmin Connect, not through Terra: your activities and the daily health data you choose to share. When you switch it on, we send your planned sessions and routes to your Garmin account. Processing at Garmin is governed by Garmin’s own terms and privacy policy.
- Apple — Apple is not one of our processors and receives nothing from us. Apple Health data lives on your iPhone, and the TriHonu app reads it only after you grant permission in Apple’s own dialog. You can withdraw that permission at any time in Settings › Privacy & Security › Health, which stops the reading immediately without touching your TriHonu account.
- Voyage AI — receives text you or your coach have saved (coach memory, uploaded documents, and your search queries) to turn it into the numerical representation that lets the coach recall the right note later.
- Supabase — hosts the database, authentication, and file storage.
- Vercel — hosts the application.
- Resend — sends sign-in and notification emails.
- Open-Meteo — receives the coordinates or place name of a planned session to return its forecast. It is not told who is asking.
- Paddle — our payment provider and merchant of record (Paddle.com Market Ltd). When you buy a subscription or a top-up pack, Paddle processes your payment and billing data on its own secure checkout; your card details never reach our servers. From Paddle we receive only what running your membership needs: what you bought, the state of your subscription, and your billing country and currency.
6. Apple Health (HealthKit)
If you use the TriHonu iPhone app, you can connect Apple Health. Apple provides no server for us to query, so unlike every other connection this one happens on your own device: the app reads from Apple Health on your iPhone, and only after you grant permission in Apple’s own dialog.
- What we read — workouts and their metrics, sleep, heart rate and heart-rate variability, and resting heart rate. You choose what to grant, category by category, in Apple’s dialog; we receive nothing you do not tick.
- What we write — your planned sessions, so they appear on your Apple Watch. Nothing else is ever written to Apple Health.
- What we never touch — clinical health records. The app declares no entitlement for them and requests none.
- How it reaches us — the app sends what you granted directly to TriHonu, over an encrypted connection tied to your paired phone. Older versions of the app hand it to Terra instead, which relays it to TriHonu, until you update. Apple itself is not our processor and receives nothing from us.
- Turning it off — Settings › Privacy & Security › Health › TriHonu, on your iPhone. Revoking there stops the reading immediately and needs no action from us. You can also revoke the phone itself in TriHonu under Settings › Connections, which is the right move if you no longer have the device.
Data read from Apple Health is never used for advertising or marketing, never sold, and never shared with anyone for those purposes. It is used to coach you and for nothing else, and it is not disclosed to third parties without your consent except where the law requires it. Deleting your TriHonu account deletes it along with the rest of your data (see “How long we keep it”).
7. Embedded content
Three parts of the app load content into your browser directly from someone else’s server. When that happens, your browser contacts that provider itself, so it sees your IP address and browser details — the same as if you had opened the content in a new tab. We send it nothing about you: no name, no email, no account identifier, and no training data.
- Exercise demonstrations — expanding the How to panel on a strength or mobility exercise may load demonstration images from jsDelivr (a public host for open-source files) and, where one exists, a demonstration video from YouTube. Videos use YouTube’s privacy-enhanced player (youtube-nocookie.com), which sets no tracking cookies unless you actually press play; once you do, YouTube (Google) may set cookies and receives your IP address and device details as an independent controller, not as our processor, under Google’s own privacy policy. Nothing is requested until you open the panel.
- Activity route maps — opening an activity that was recorded with GPS draws its route on a map, using tiles from OpenStreetMap and styling from unpkg. A map is drawn by fetching the tiles that cover your route, so OpenStreetMap necessarily learns the approximate area you trained in. This is the one embed that reveals something about you rather than only about your device, and it currently loads automatically with the activity — there is no setting to turn it off.
- The checkout — buying a subscription or a top-up pack opens our payment provider’s checkout, which loads Paddle.js from paddle.com in your browser. Paddle then sees your IP address and browser details, and sets the cookies it needs to run the payment securely — it acts as merchant of record and processes your payment under its own terms (see the processor list above). Nothing from paddle.com loads anywhere else in the app.
Apart from these, the app embeds no third-party content: no advertising, no analytics, no social widgets, no cross-site tracking. Fonts and every other asset are served from our own domain.
8. Cookies & local storage
We use no tracking cookies, no advertising cookies and no analytics. Everything this app stores in your browser is either needed to keep you signed in or a setting you chose yourself — which is why you are not asked to accept cookies when you arrive.
- Sign-in cookies — set when you sign in, by Supabase, the service that handles our authentication. They are what keeps you signed in as you move between pages, and they are refreshed as you browse so your session does not expire while you are using the app. Without them you would have to sign in again on every page. Clearing them signs you out.
- Your own settings, kept in your browser’s local storage — the light or dark appearance, whether the side navigation is collapsed, whether weights are shown in kilograms or pounds, whether the strength timer plays a sound, and when your watch last synced. They are written only when you change something, read only by the app on your own device, and never sent to us. Clearing them resets those preferences and nothing else.
- Choices you make on our website, kept as small first-party cookies: the language you picked with the EN / DE switch (one year), the coach you picked before signing up (seven days, so the signup can offer that coach), and whether you last used TriHonu as an athlete or as a coach (one year, so you land in the right place after signing in). Each holds only that choice. Clearing them resets the choice and nothing else.
- Connection and sign-in helpers — while you connect a service such as Garmin, a short-lived cookie (ten minutes) carries the security check that the connection was started by you, and is deleted when it completes. If you sign in through our iPhone app, a cookie remembers that for 180 days so the app can open your account directly.
Under EU and EEA rules, consent is required only for storage that is not strictly necessary for a service you actually asked for — which is why none of the above needs a banner. If we ever add something that does require consent, such as analytics, we will ask first, and refusing will be exactly as easy as agreeing. Two things noted above set their own cookies: pressing play on an embedded demonstration video lets YouTube do so, and opening the checkout lets Paddle set the cookies a secure payment needs (see Embedded content).
9. Where your data is stored & international transfers
Your data is stored with our hosting providers (Supabase and Vercel). Some providers process data in the European Union and/or the United States — for example, our AI provider (Anthropic) and our wearable-data platform (Terra) process in the United States. Where data is transferred outside Switzerland or the EEA, it is protected by appropriate safeguards such as the Standard Contractual Clauses.
10. How long we keep it
We keep your data while your account is active. When you delete your account (self-service in the app), your data is deleted, subject to short-lived rolling backups (currently up to 7 days) and any records we must retain by law. If your trial ends without a plan, your account and data are kept for 30 days — we tell you by e-mail before anything happens — and the account is then deleted the same way. Until subscriptions open (the checkout in §5 and §7 describes how payment will work once they do), a trial ending changes nothing and starts no deletion; we will tell you before that changes. What remains afterwards is a single minimal record that your e-mail address has already used its one trial, kept solely to prevent the trial being taken repeatedly.
11. Your rights
Subject to applicable law, you can request access to, correction of, deletion of, a portable copy of, restriction of, and objection to the processing of your data, and you can withdraw consent at any time with effect for the future. Withdrawing does not affect the lawfulness of processing carried out before it.
- Export — download your data yourself in-app under Profile → Your data.
- Delete — delete your account and its data in-app under Profile → Your data, or contact us.
- Other requests / complaints — contact hello@trihonu.com. You also have the right to lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local data-protection authority).
12. Security
We isolate every user’s data at the database level (row-level security keyed to your account) and encrypt data in transit (TLS). Our hosting provider encrypts the database and file storage at rest. Access tokens for connected services (for example Garmin or Wahoo) and calendar links are additionally encrypted in the application with a separate server-side key before they are stored, so a copy of the database alone cannot use them; we never hold your Garmin password. Passwords for TriHonu accounts are stored only as salted hashes, and your device tokens are never exposed to other users.
We do not encrypt individual training or health metrics inside the application: that would prevent the database from computing your training load, recovery trends and plan compliance, and it offers little beyond encryption at rest for data your coach must read on every request. Beyond you, only the operator of TriHonu can access your data, and only where needed to run the service or to help you at your request. No system is perfectly secure, but we work to protect your data.
13. Children
TriHonu is intended for adults only. It is not for anyone under 18, and we do not knowingly collect data from anyone under 18.
14. Changes to this policy
We may update this policy; material changes will be surfaced in-app. The version date above shows which version you are reading.
15. Contact
Questions or requests: hello@trihonu.com.