Triple Peaks TriplePeaks Open App
Features Pricing Changelog

Privacy Policy

Last updated: February 2026

1. Overview

Triple Peaks ("we", "us", "our") respects your privacy. This policy explains what data we collect, how we use it, and your rights under applicable data protection law.

It applies to triplepeaks.coach, app.triplepeaks.coach, and our iOS and Android apps.

2. Data Controller

Lukas Carullo
Email: hello@triplepeaks.coach

3. Data We Collect

Account Data

Email address, name (optional), and authentication via Strava OAuth. We do not store your Strava password.

Training Data

When you connect Strava, we receive activity data (duration, distance, pace, heart rate, GPS, power, cadence) and your training history. This is health-related data processed based on your explicit consent.

AI-Generated Data

Our AI generates training plans, workout analyses, chat responses, and performance insights based on your data.

Payment Data

Payments are handled entirely by Apple or Google. We only receive subscription status and purchase confirmations — never your payment details.

Technical Data

Device type, OS, app version, anonymized IP address, and crash reports.

4. How We Use Your Data

  • Service delivery: Generating plans, analyzing workouts, adapting training, answering coaching questions.
  • Notifications: Weekly plan summaries and account-related emails. Configurable in settings.
  • Improvement: Anonymized, aggregated data to improve the product. Individual data is never shared or sold.

5. Legal Basis

  • Consent: Health-related training data (heart rate, GPS, activity data) — based on your explicit consent when connecting Strava.
  • Contract: Processing needed to provide the coaching service (plan generation, analysis, account management).
  • Legitimate interest: Anonymized analytics, security, fraud prevention.
  • Legal obligation: Tax and commercial law requirements.

6. AI Processing

To provide coaching, your training data is sent to a third-party large language model (LLM) provider for processing. Data is encrypted in transit. By using Triple Peaks, you consent to this processing.

AI recommendations are informational and not a substitute for professional medical or sports science advice. No automated decisions with legal effects are made.

7. Third-Party Services

  • Strava: Activity import via API. You can revoke access anytime in your Strava settings.
  • LLM Provider: Third-party AI processing for coaching recommendations. Data is encrypted in transit.
  • Apple & Google: Payment processing for subscriptions and in-app purchases.

8. International Data Transfers

Some providers are US-based (Google, GitHub, Apple). Transfers are conducted under the EU-US Data Privacy Framework or Standard Contractual Clauses.

9. Data Retention

  • Data is kept while your account is active.
  • Personal data is deleted within 30 days of account deletion.
  • Backups are purged within 90 days.
  • Longer retention may apply where required by tax or commercial law.

10. Your Rights

You can request access, correction, deletion, or export of your data. You can restrict or object to processing, and withdraw consent at any time.

Contact us at hello@triplepeaks.coach. We respond within 30 days.

You also have the right to lodge a complaint with the competent data protection authority.

11. Cookies

Our marketing website does not use cookies or tracking. The app uses only technically necessary cookies for authentication and preferences. No third-party tracking or advertising cookies.

12. Security

We use TLS encryption for all connections, encryption at rest for sensitive data, access controls, and regular backups. Our database is not publicly accessible.

13. Children

Triple Peaks is not intended for users under 16. We do not knowingly collect data from children. Contact us if you believe a child has provided personal data.

14. Changes

We may update this policy and will notify you of significant changes at least 14 days in advance.

15. Contact

Email: hello@triplepeaks.coach

© 2026 Triple Peaks
Features Pricing Changelog Imprint Terms Privacy