← TriTune

Privacy Policy

Last updated 8 October 2026

TriTune is built on a simple principle: your health and training data exists to power your coaching, and nothing else. You choose what to connect, you can see everything we hold, and you can take it with you or delete it at any time.

TriTune is currently in private beta. This policy sets out how we handle your data during beta and how we intend to operate at launch. Questions? info@tritune.co

Who we are

TriTune is a training readiness and coaching app operated by Frazer Consulting LLC, the data controller for the personal data described in this policy. You can reach us at info@tritune.co for anything data-related.

What data we collect — and why

We collect the minimum needed to run your personalised readiness engine. Here is what we hold and on what basis.

Health and training data

This is GDPR special-category data. We process it only on the basis of your explicit consent, given when you connect a device or service and begin using TriTune. Specifically:

  • HRV (overnight RMSSD), resting heart rate, sleep duration, stages and score
  • Daily activity summaries such as steps
  • Training readiness and stress scores (where your device provides them)
  • Training activities: type, duration, heart rate, pace, power
  • Morning check-ins you enter yourself: how you feel, soreness, illness flags, effort ratings, lifestyle tags
  • Your athlete profile: age, weight, fitness benchmarks (e.g. FTP), goals, notes on injuries or equipment
  • For pomme: the outcome of your safety check (whether you answered yes to any question and whether loaded tests are paused, not your answers), your capability check results including the weight you carried, your goals and stages including any goal you type, how you arrived each day, session feedback including any pain and where, when and where you plan your next session, classes you have booked, walks we detect from your step data, and your weight or body composition if you add them
  • AI-generated coaching narratives and your training plan cache (derived from the above)

Contact data

  • Email address — to manage your account and send training briefings if you opt in
  • Name — optional; only if you provided it via the waitlist or Strava

Technical data

  • Your IP address is used as a key for rate-limiting (preventing abuse) and held for between one minute and a day, depending on what you were doing, then discarded
  • A session authentication cookie — see the Cookies section below

How we use it

Solely to run your daily readiness engine, generate your coaching guidance, and maintain your training plan. Nothing else.

  • We do not sell your data.
  • We do not use it for advertising.
  • We do not train shared or cross-athlete AI models from it. Coaching narratives are generated by sending the facts that guidance needs (for example how you said you feel, your recent sleep or heart-rate trend, your readiness and your plan) to our AI provider (Anthropic), under their commercial no-training API terms.
  • When AI is disabled or unavailable, all guidance comes from our deterministic engine — no data leaves TriTune.
  • We may use your own data to calibrate the engine to you specifically — for example, tuning your personal HRV band over time. This is covered by your core product consent and is the opposite of cross-user training: it makes your engine more accurate for you, not for anyone else.
  • Improving TriTune for everyone — future, and opt-in only. We may in future offer you the option to contribute de-identified, aggregated data to improve the readiness engine for all athletes. This is not happening today. If we introduce it, it will be strictly opt-in via a separate consent — never bundled with these terms, never on by default — we will email you before anything changes, we will explain exactly what is used, and anything that could identify you will be removed first. If you never opt in, your data is never used this way.

A note on HIPAA

TriTune is not a HIPAA “covered entity” or “business associate”, and the health data you share is not HIPAA-protected health information — it is governed by this policy. Please do not use TriTune to store information you believe needs HIPAA-level protection.

AI and automated processing

TriTune uses AI to turn your data into plain-language coaching. We are deliberately transparent about this:

  • What it does — your readiness signals and check-in context are processed to generate your daily narrative, explanations, and plan adjustments.
  • What is sent — the facts that guidance needs, such as how you said you feel, your recent sleep or heart-rate figures or trend, your readiness and your plan. If you use the coach chat, we send what you type. We do not send your email address or your name. It goes only to Anthropic (in the US) under their commercial no-training terms.
  • AI is part of TriTune — AI-written guidance is part of how the product works, and there is not yet a separate switch to turn it off for your account. If you do not want your data used this way, email us and we will close your account and delete your data.
  • No automated decisions about you— TriTune's guidance is advisory, always explained, and override-able. We do not make decisions producing legal or similarly significant effects about you (GDPR Article 22).

Connected data sources

TriTune only receives health and training data from the services you choose to connect, and only after you authorise the connection. You can disconnect any source at any time from your Profile.

  • Garmin— when you connect Garmin, you authorise TriTune to receive your wellness and activity data (HRV, sleep, resting heart rate, stress, daily summaries, and activities). Garmin is an independent data controller for the data it holds; its handling of your data is governed by Garmin's own privacy policy. Disconnecting Garmin stops all further data and deletes the Garmin-sourced data we hold for you.
  • Strava— if you connect it, supplies your activity history; governed by Strava's own privacy policy. Disconnect at any time.
  • Oura— if you connect it, supplies your sleep, HRV, resting heart rate, activity and workouts; governed by Oura's own privacy policy. Disconnect at any time and we delete what we sourced from it.
  • Whoop, if you connect it, supplies your recovery, HRV, resting heart rate, sleep and workouts. It is governed by Whoop's own privacy policy. Disconnect at any time and we delete what we sourced from it.
  • Google Health Connect— an alternative source for HRV, sleep, and resting heart rate on non-Garmin devices; governed by Google's own privacy policy.
  • Apple Health is where your iPhone, your Apple Watch and some other apps keep your health readings. TriTune cannot read it directly. If you connect it, you set up a Shortcut on your own iPhone that sends us one day of readings at a time: sleep, heart-rate variability, resting heart rate, heart rate through the day, steps, active energy, distance and workouts. Some of those readings were recorded by another device or app that wrote them into Apple Health, such as Garmin Connect, Whoop or Oura. Where that happens we name every step: the device maker recorded it, Apple Health holds it on your phone, and your Shortcut sends it to us. Readings from any other app are not stored. What Apple and the device maker hold is governed by their own privacy policies. Your Shortcut identifies itself with a private token. A token is a credential: it can only add Apple Health readings to your account, it is shown once, and we keep only a scrambled copy of it. You can replace it with a new one or revoke it from your Profile at any time. Disconnecting Apple Health stops all further data and deletes the Apple Health data we hold for you. Apple Health data is stored in the same places as the data from your other sources, described below.
  • intervals.icu relays wellness and activity data that another device, usually your Garmin watch, originally recorded, so we can receive it without a direct connection to that device maker. Where data reaches us this way we name both: the device maker is the original source, and intervals.icu is the service that passes it on to us. Each of them decides for itself how it uses the data it holds, under its own privacy policy. We have no data-processing contract with intervals.icu, because it is a source of data rather than a supplier working on our behalf. Before you connect it, we ask you to confirm that the sleep and heart-rate variability readings in your intervals.icu come from your Garmin watch, because those readings arrive without a label saying which device took them. Disconnecting it stops all further data and deletes what we hold from that route.
  • Zwift records your indoor rides, including your power data. If your Zwift account is connected to your intervals.icu account, we take those rides through intervals.icu and record Zwift as the source of each one. Zwift decides for itself how it uses the data it holds, under its own privacy policy.

These services are the sources of your data, not our processors — you authorise them directly and control them through your account with each provider.

Sharing with your coach (optional, planned)

We plan to let you share your training context with a coach. This is off by default and will happen only with your explicit consent:

  • What a consented coach sees — your readiness tier and trend, HRV and sleep summaries, recent training load, your workout history, and the check-in context relevant to programming your sessions safely. They see it inside TriTune; they do not receive exports of your raw data.
  • You can revoke at any time— withdrawing consent removes your coach's access immediately.
  • Coach use only — coaches may use your data solely to coach you, for nothing else. Coach guidance through TriTune is training guidance, not medical advice.
  • Not available yet— coach sharing is something we are building, not something running today, and no coach has access to any athlete's data. When it does arrive it will work exactly as described here, and nothing will be shared with any coach unless you explicitly agree first.

Who we share it with

We share the minimum necessary data with the following service providers, each acting as a data processor on our behalf:

  • Vercel — hosts the application and stores your data in private, encrypted storage. Servers are in the US.
  • Anthropic — receives the context needed to write your AI guidance, which can include recent sleep and heart-rate figures or trends, your readiness, your plan and anything you type into the coach chat. We do not send your email address or name. Operates under commercial no-training terms. Servers are in the US.
  • Supabase — the database holding your training records (check-ins, sessions, notes, plans, race entries). Hosted in the EU (Ireland), encrypted in transit and at rest, with per-athlete row-level access control.
  • Upstash — a short-term cache of your computed dashboard, which includes health data, kept for up to 6 hours, and rate-limit counters keyed by IP address or account id. Servers are in the US.
  • Resend — delivers account confirmation and (if opted in) training briefing emails. Holds your email address and name.
  • Sentry — error monitoring, so we can find and fix crashes. Error reports are scrubbed of personal data before they are sent; no health data or identifiers leave TriTune this way.

Our only analytics is Vercel Web Analytics — a cookieless, privacy-first visit counter that gives us aggregate page-view numbers. It sets no cookies, stores no identifiers, does not track you across sites, and never sees your health data.

No advertising networks, user-tracking analytics platforms, or data brokers receive your data. No third party receives your raw health data.

Where your data is stored

Your data currently lives in two places, and we are consolidating it over time:

  • Supabase, EU (Ireland) — the records you create in TriTune: check-ins, gym sessions, notes, plans, race entries and similar, with per-athlete row-level access control.
  • Vercel, US (us-east-1) — the application itself, plus the data we receive from your connected devices (daily wellness records and detailed heart-rate and stress series) and our caches, in private access-controlled storage.

All of it is encrypted in transit (TLS) and at rest, and access is limited to your authenticated session. Where data is transferred between the EU/UK and the US, that transfer is covered by our providers' Standard Contractual Clauses.

If TriTune changes hands

If TriTune is ever involved in a merger, acquisition, or sale of the business, your data may transfer to the new owner as part of that transaction. Any new owner must honour this Privacy Policy, or give you notice and a choice before your data is used under a different one.

How long we keep it

  • Your active data (health data, check-ins, plans, profile) — kept while your account is active.
  • AI coaching cache — automatically purged after 90 days as part of our routine cache eviction.
  • Waitlist email address — kept until you unsubscribe, then deleted within 30 days.
  • When you disconnect a data source (for example Garmin or Apple Health) — we stop receiving new data from it and delete the data we sourced from it.
  • After a deletion request — we aim to purge all your data within 30 days of receiving and verifying the request, and we instruct the service providers listed above to delete it from their systems too, including any backups and archives.

Your rights

Email info@tritune.co to exercise any of the following. We respond within 30 days.

  • Access and portability — download everything in one click from your Profile page at any time, in JSON (complete archive) or CSV (activity history) format.
  • Erasure — request complete deletion of all your data. We action this promptly. Deleting your data does not affect your right to export it first.
  • Rectification— correct or update your profile data from within the app's Profile page, or ask us to do it.
  • Withdraw consent — disconnect a data source (which also deletes the data we sourced from it) or close your account at any time. Withdrawal does not affect processing that was lawful before you withdrew.
  • Object to processing — if we ever use your data beyond providing the service (we currently do not), you have the right to object.
  • Lodge a complaint — if you believe we have mishandled your data, you can complain to your local data protection authority: the ICO in the UK (ico.org.uk), or your national supervisory authority in the EU.

Your US state privacy rights

If you live in a US state with a comprehensive privacy law (such as California, Colorado, Connecticut, Virginia, Texas, Oregon, and others), you also have the right to:

  • Know and access the personal information we hold about you
  • Delete it, and correct any inaccuracies
  • Opt outof any “sale” or “sharing” of your personal information, and of targeted advertising or profiling — though we do none of these
  • Appeal if we decline a request

We do not sell your personal information, and we have not done so — so there is nothing to opt out of, but the right stands. We honour the Global Privacy Control (GPC) browser signal as an opt-out of sale or sharing. To exercise any of these rights, email info@tritune.co; we respond within 45 days and will never treat you differently for asking. You may use an authorised agent to make a request on your behalf; we may ask you to verify that you authorised them.

Consumer health data (Washington, Nevada and Connecticut)

Some US states, notably Washington (My Health My Data Act), Nevada and Connecticut, give you specific rights over consumer health data. Almost everything TriTune holds is consumer health data, so this sets out, in one place, exactly how we treat it. These rights are in addition to the other rights in our Privacy Policy.

  • What we collect — HRV, resting heart rate, sleep duration, stages and score, daily activity summaries such as steps, stress and readiness scores, training activities and their heart rate, pace and power, your morning check-ins (how you feel, soreness, illness flags, effort, lifestyle tags), your athlete profile (age, weight, benchmarks, goals, injury and equipment notes), for pomme your safety-check outcome, capability check results, goals and stages, session feedback (including any pain) and booked classes, and coaching narratives derived from all of this.
  • Where it comes from — the services you choose to connect (Garmin, Strava, Oura, Whoop, Google Health Connect, Apple Health, intervals.icu, Zwift) and what you enter yourself in the app. Where one of those services passes on data that another device originally recorded, we name both. For Apple Health we also name the device maker that recorded a reading when it was not Apple. We do not buy health data, and we do not collect it from any other source.
  • Why we collect it — solely to run your readiness engine, generate your coaching guidance, and maintain your training plan. Nothing else.
  • Who we share it with — only the service providers named in our Privacy Policy, each acting on our behalf under contract, and a coach only if you explicitly consent. We have no affiliates. We never sell consumer health data. Under Washington law, selling it would require your separate written authorisation, and we neither seek nor accept one.
  • Your rights — you can confirm what consumer health data we hold, access it, get the list of third parties we have shared it with, withdraw your consent to its collection and sharing, and have it deleted. Deletion extends to our service providers, including backups and archives.

To exercise any of these, email info@tritune.co. We respond within 45 days. If we decline your request you can appeal by replying to our decision, and if we deny the appeal you may contact the Attorney General of your state — for Washington residents, the Washington State Attorney General's Office.

If there is a data breach

We use commercially reasonable measures to protect your data, though no system is ever perfectly secure. If a breach affects your personal data, we will notify you — by email to your account address — and the relevant supervisory authority, within the timeframe the law requires.

Cookies

We use two cookies, and neither one tracks you:

  • tritune_session — a signed, httpOnly, Secure session cookie that identifies your authenticated session. It contains only a session token — no personal or health data. It lasts up to 180 days with weekly renewal while you are active.
  • tt_skin— remembers whether you chose the Nightfall or Daylight appearance, so the app opens in the look you picked instead of flashing the wrong one. It holds a single word ("night" or "light"), set only when you use the appearance switch. No identifier, nothing personal, nothing that links back to you. It lasts one year and lives on that device only.

No advertising cookies. No tracking pixels. Our page analytics (Vercel Web Analytics) is cookieless and aggregate-only — it cannot identify or follow you. Our cookies do only two things: sign you in, and remember a display preference you chose yourself. Neither purpose requires consent under UK PECR or EU ePrivacy rules, which exempt strictly necessary cookies and user-interface customisation you asked for, so no consent banner is required.

Children

TriTune is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18 — and in particular do not knowingly collect personal information from children under 13 (or the minimum age in your country). If we learn we have, we delete it promptly. If you believe a minor has created an account, please contact us and we will delete it promptly.

Policy updates

If we make material changes to this policy, we will notify registered users by email before the changes take effect. Continuing to use TriTune after that date means you accept the updated policy.

Contact

Privacy questions and rights requests: info@tritune.co