Privacy policy
1. Introduction
TriPaced (the "Service") is published by Vincent Delpeuch, a natural person acting as data controller within the meaning of Regulation (EU) 2016/679 of 27 April 2016 ("GDPR").
This privacy policy informs users of the Service about the personal data collected, the purposes of processing, the legal bases, the recipients, the retention periods and their rights.
TriPaced processes health data within the meaning of Article 9 GDPR. Explicit and separate consent is requested at sign-up for those specific processing operations.
The Service is currently a free, invite-only private beta with a very small number of accounts. This policy describes what the Service actually does today, not what it might do tomorrow.
2. Data controller
- Name: Vincent Delpeuch
- Status: natural person, personal project in beta phase
- Contact: vincent@tripaced.com
- Data Protection Officer (DPO): Vincent Delpeuch acts as de facto DPO. No formal appointment is required given the size of the project (Article 37 GDPR), but Vincent Delpeuch can be reached directly at vincent@tripaced.com for any data protection question.
3. Data collected
3.1 Identification data
- Email address (required to create an account)
- First and last name (optional, editable at any time)
- Password (bcrypt-hashed, never accessible in clear text)
3.2 Training data
- Athlete profile setup: hours available per week, target race type (Half Ironman 70.3 or Full Ironman 140.6), race date, current level
- Sessions planned by the engine (discipline, duration, prescribed intensity)
- Completed sessions (from Strava or manual validation)
- Weekly check-ins (perceived load, requested adjustments)
- Computed thresholds: FTP (Functional Threshold Power), VDOT (Jack Daniels), CSS (Critical Swim Speed)
3.3 Health data (Article 9 GDPR)
This data is only collected with your explicit and separate consent, given at sign-up.
- Declared injury episodes: injury type, severity, start and end dates, free-text notes
- Physiological training load: CTL (Chronic Training Load), ATL (Acute Training Load), TSB (Training Stress Balance) following the Banister/Coggan model
- Messages sent to the AI coach (feature currently hidden in the MVP), which may contain medical statements
3.4 Data from Strava (with your OAuth consent)
When you connect your Strava account:
- OAuth tokens (access token, refresh token, expiry): stored encrypted, refreshed automatically
- Synchronised activities: distance, duration, pace, power, average heart rate
- Detailed GPS and heart rate streams (for fine-grained analysis)
- Strava profile picture and name
GPS coordinates are used exclusively to compute elevation gain and session quality. They are never displayed publicly and never shared with third parties.
3.5 Behavioural data (audience measurement)
Through PostHog (processor, hosted in the European Union):
- Pages visited, session duration
- Key events: beta sign-up funnel, account creation, wizard completion, plan generation, weekly check-in
- Account identifier and email address: when you are signed in and have accepted audience measurement, your internal identifier and your email address are sent to PostHog so that events can be attached to your account
This data is pseudonymised, not anonymous. In legal terms "anonymisation" means an irreversible process; that is not the case here, since events are attached to your account and email address. However, no health data is ever sent to PostHog: no weight, no heart rate, no physiological threshold and no injury goes through audience measurement, and the threshold input fields are explicitly excluded from automatic capture.
This processing is based on your prior consent (opt-in): no audience measurement takes place until you have clicked "Accept" in the dedicated banner. You can grant or withdraw that consent at any time below.
Current status: audience measurement disabled
3.6 Beta application data
For users who applied through the beta form:
- Email, free-text motivation, target race, self-declared level
- Application status (pending / invited / rejected)
3.7 Data related to the optional Intervals.icu connection
If you connect an Intervals.icu account (see section 5.2), the Service stores:
- Your Intervals.icu OAuth token and athlete identifier, accessible server-side only
- The mapping between each TriPaced session and the event created on Intervals.icu (date, slot, event identifier, last synchronisation date)
3.8 Content you publish in the community space
- Discussion threads: title and body
- Replies posted in a thread
- Likes placed on a reply
- The first name attached to your account, displayed as the author
4. Purposes and legal bases
| Purpose | Legal basis (Article 6) | Health data (Article 9) |
|---|---|---|
| Account creation and management | Performance of the contract (Terms) | Not applicable |
| Generation of the personalised training plan | Performance of the contract | Separate explicit consent |
| Strava synchronisation | OAuth consent | OAuth consent |
| Export of planned sessions to Intervals.icu | OAuth consent (connection you establish) | Consent (exported targets derive from your thresholds) |
| MCP connector (your AI assistant accessing your TriPaced data) | Consent (named token issued on your request) | Consent (physiological load exposed) |
| Platform coach space: a human coach reviewing your plan | Consent (link you confirm, revocable) | Explicit consent (load, active injury) |
| Public share link for a session | Consent (per-session opt-in, revocable) | Not applicable (no health data is published) |
| Community leaderboards | Consent (opt-in, off by default) | Not applicable |
| Community space (forum between users) | Performance of the contract (Service feature) | Not applicable (free-text content published at your initiative) |
| AI coach (feature hidden in the MVP) | Consent | Separate consent |
| Pseudonymised audience measurement | Consent (opt-in banner, withdrawable at any time) | Not applicable |
| Project email updates (newsletter) | Opt-in consent | Not applicable |
| Beta application handling | Consent (form) | Not applicable |
5. Third-party connections you activate
None of these connections is active by default. Each one is triggered by an explicit action on your part and can be revoked at any time.
5.1 Strava
An OAuth connection you establish in order to import your completed activities. The data involved is described in section 3.4. You can revoke it from your TriPaced settings or from your Strava account.
5.2 Intervals.icu
If your watch is a Garmin, Wahoo, COROS or Hammerhead, you can connect an Intervals.icu account to receive your planned sessions directly in your watch calendar. This connection is optional.
What TriPaced sends to Intervals.icu, and nothing else:
- The session title and its discipline (swim, bike, run, strength)
- The date, indicative time and planned duration
- The detailed structure of the session: blocks, repetitions and intensity targets expressed as a percentage of FTP, as a pace (seconds per kilometre or per 100 metres) or in beats per minute. Those targets are computed from your physiological thresholds, so they indirectly reveal your level.
What TriPaced never sends to Intervals.icu: your email address, your declared injuries, your physiological load (CTL, ATL, TSB), your coach messages, your raw Strava data, your GPS tracks.
The permissions requested when connecting cover writing to your Intervals.icu calendar as well as reading your activities and wellness data held on Intervals.icu, for future tracking features. Intervals.icu is published by intervals.icu Ltd, a company incorporated in the United Kingdom, whose servers are located in Germany and Finland. Towards you, Intervals.icu acts as an independent data controller: its own privacy policy applies to the data you hold there. You can break the connection at any time from your TriPaced settings or from your Intervals.icu account.
5.3 MCP connector (AI assistant)
TriPaced exposes a connector using the MCP (Model Context Protocol) format, which allows an AI assistant you use elsewhere (for instance Claude) to read, and where applicable to propose changes to, your TriPaced data. This connector is not open: it works with a named token issued manually by the data controller, at your request, and it is currently limited to a very small number of private beta accounts.
What the connector exposes, when enabled for your account:
- Your plan and your planned sessions
- Your training profile and computed thresholds, along with their history
- Your daily physiological state (CTL, ATL, TSB) and your weekly check-ins
- A weekly aggregate of your completed load (totals and load per discipline)
- Plan change proposals, if you use a write token
What the connector never exposes: your raw Strava data (activity identifiers, GPS tracks, detailed heart rate streams) and any other user's data. A token is bound server-side to one account and one only, and is never logged. Read tokens grant no write access whatsoever.
Important consequence: data read through this connector travels to the publisher of the assistant you connect, which may be located outside the European Union, and becomes subject to that publisher's own policy. Choosing that assistant is up to you. If you do not request a token, no data leaves through this channel.
6. Voluntary sharing inside TriPaced
Your account is private by default. None of the three surfaces below publishes anything until you turn it on yourself.
6.1 Public share link for a session
You can generate, session by session, a link of the form /s/<token> that makes that session readable without authentication by anyone you send the link to, and potentially by a search engine if the link is published somewhere.
- What the public page shows: the discipline, type and title of the session, its duration, its estimated load (TSS), the structure of the blocks and the associated badges.
- What it does not show: your name, your first name, your email address, your thresholds, your physiological load, your injuries, your exchanges with the coach, your full plan.
- Revocation: from your account privacy settings. The link then stops working immediately. The token is a random 122-bit identifier and cannot be guessed.
6.2 Community leaderboards
Leaderboards are off by default. As long as you do not turn them on in your settings, you appear in no other user's leaderboard and you only see your own rank.
- What becomes visible to other signed-in users if you turn the option on: your first name (or the label "Athlete" if you have not provided one) and the ranked value, namely your total experience points, your current day streak or your longest streak.
- What never becomes visible: your email address, your thresholds, your load, your sessions, your injuries.
- Revocation: turning the option off removes you from other users' leaderboards immediately.
6.3 Community space (forum)
The community space is an internal forum reserved for signed-in users of the Service. It is not accessible without an account and is not publicly indexed.
- What is visible to other signed-in users: the title and body of the threads you publish, your replies, your likes, and the first name attached to your account as a signature.
- The content you write there is free text: avoid publishing information you do not wish to share, in particular health information.
- Deleting your account erases your threads, your replies and your likes.
7. Platform coach space: sharing with a human coach
TriPaced lets you link your account to that of a human coach who is also a user of the Service, so that they can follow your training. This link only exists if both you and the coach wanted it: either the coach sends you a request that you accept, or you enter the coach's code and the coach confirms. No coach can access your data without that two-sided action.
This sharing involves health data within the meaning of Article 9 GDPR. It is therefore based on your explicit consent, expressed by accepting the link, and you can end it at any time.
What your coach sees once the link is active:
- Your first name
- Your target race (name and date) and your main goal
- Your current training load: form (TSB) and chronic load (CTL)
- Whether you have a declared active injury and its severity (without the free-text notes you attached to it)
- Your planned sessions: date, slot, discipline, type, title, duration, estimated load, primary zone, block structure, and any changes the coach made
- The notes the coach writes on your sessions
What your coach does not see: your email address, your exchanges with the AI coach, your raw Strava data, and the data of any other athlete not linked to them. Depending on the agreed access mode, the coach has read-only access or access allowing them to propose changes to your plan.
Ending the sharing: you can end the link at any time from your space. The coach then loses access to your data immediately.
8. Recipients and processors
Data is accessible to Vincent Delpeuch (data controller) and to the following recipients, selected for their level of GDPR guarantees:
| Recipient | Role | Purpose | Location | Safeguards |
|---|---|---|---|---|
| Supabase Inc. | Processor | Database hosting + auth | Frankfurt (eu-central-1), Germany | EU hosting |
| Vercel Inc. | Processor | Frontend + serverless hosting | European regions | EU hosting |
| Strava Inc. | Independent controller | Sports activity synchronisation, through your OAuth connection | United States | Standard Contractual Clauses (SCCs) + EU-US Data Privacy Framework |
| intervals.icu Ltd | Independent controller | Export of your planned sessions to your Intervals.icu calendar, through your OAuth connection (section 5.2) | UK company, servers in Germany and Finland | Transfer triggered by you, revocable at any time. The Intervals.icu privacy policy applies to the data you hold there. |
| Resend | Processor | Transactional email delivery | Europe | EU hosting |
| PostHog | Processor | Pseudonymised audience measurement (account identifier and email address, no health data) | EU Cloud | EU hosting, on your consent only |
| Anthropic | Processor | AI coach (hidden feature) | United States | SCCs + EU-US Data Privacy Framework |
| Publisher of the AI assistant you connect | Independent controller | MCP connector, if and only if you request its activation (section 5.3) | Variable, potentially outside the European Union | Choice and policy of the publisher you select; connection revocable |
Some of your data may also be seen by other users of the Service, but only in the cases described in sections 6 and 7, and only after an explicit action on your part.
No data is sold, rented or shared with third parties for commercial purposes.
9. Retention periods
The Service is a private beta and has no automatic account purge. The table below describes what is actually applied today, rather than a commitment the Service would not honour. You can at any time request the deletion of your account, or the erasure of your health data alone, from your settings or by email: those requests are honoured.
| Data type | Period |
|---|---|
| Account data (active or not) | Kept until you request deletion. During the private beta, inactivity does not trigger any automatic deletion. |
| Health data (Article 9) | Kept until you withdraw your consent, which erases it selectively without deleting the rest of the account, or until the account is deleted. |
| Technical logs (access, errors) | Kept by the hosting providers (Vercel, Supabase) according to their own periods. TriPaced keeps no application-level copy. |
| Anti-abuse counters (rate limiting) | 1 day |
| Automatic database backups | Managed by Supabase, according to the hosting plan in place |
| Strava data | Until the Strava account is disconnected or the TriPaced account is deleted |
| Strava and Intervals.icu OAuth tokens | Until revocation or account deletion |
| Beta applications (including rejected ones) | Kept for the duration of the private beta, or until you request deletion at vincent@tripaced.com |
When the Service opens to the public, these periods will be bounded by automatic deletions and this section will be updated accordingly.
10. Your rights
Under Articles 15 to 22 GDPR, you have the following rights:
- Right of access (Article 15): obtain a copy of all your data
- Right to rectification (Article 16): correct any inaccurate data
- Right to erasure (Article 17, "right to be forgotten"): delete your account and all associated data
- Right to data portability (Article 20): receive your data in a structured format (JSON for the whole set, FIT for Garmin-compatible sessions)
- Right to object (Article 21): refuse a specific processing operation (audience measurement in particular)
- Right to restriction (Article 18): temporarily freeze a processing operation
- Right to withdraw Article 9 consent: selectively erase health data without deleting the rest of the account
- Right to give post-mortem instructions (French law): can be sent by email
How to exercise your rights
Send an email to vincent@tripaced.com stating:
- Your identity (the account email address)
- The right you wish to exercise
- Where applicable, proof of identity (if there is any doubt about your identity)
Response time: 1 month maximum (extendable to 3 months for complex requests, in accordance with Article 12 GDPR).
Complaint to the CNIL
If you consider that your rights are not respected, you may lodge a complaint with the French data protection authority (CNIL):
- Website: www.cnil.fr
- Address: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France
- Phone: +33 1 53 73 22 22
11. Security
Vincent Delpeuch implements the following technical and organisational measures:
- HTTPS across the whole site (Let's Encrypt certificate via Vercel)
- Passwords hashed with bcrypt (Supabase Auth, never accessible in clear text)
- PostgreSQL Row Level Security (RLS) enabled on every table holding user data
- Server secrets isolated: no secret is exposed to the client (regularly audited)
- OAuth tokens encrypted at rest (Supabase managed encryption)
- Automatic database backups managed by the hosting provider
- Rate limiting on sensitive entry points (invitations, forum, MCP connector)
- Access logging provided by the hosting providers for anomaly detection
12. Specific commitment on health data (Article 9 GDPR)
Vincent Delpeuch undertakes to:
- Never sell or share health data with commercial third parties
- Never use health data for advertising or marketing profiling
- Never use health data to discriminate access to features
- Never send health data to the audience measurement tool
- Only share health data with another user or a third-party service in the cases described in sections 5 and 7, and only after an explicit action on your part
- Respect your right to withdraw consent at any time, which triggers the selective erasure of health data without deleting the rest of your account
13. Cookies
TriPaced only uses strictly necessary cookies:
- Authentication session cookie (Supabase Auth)
- Interface preference cookie (language, theme)
No advertising cookie, no third-party tracking cookie. Audience measurement (PostHog) is only enabled after your explicit consent (opt-in banner) and uses no tracking cookie (local storage, EU region). You can withdraw that consent at any time from the "Behavioural data" section above.
14. Minors
Use of TriPaced is restricted to people aged 16 or over. At sign-up you certify that you are at least 16 years old.
If you are under 16, you must obtain the prior explicit consent of a parent or legal guardian and contact vincent@tripaced.com before signing up.
15. Transfers outside the European Union
Some recipients (Strava, Anthropic, and where applicable the publisher of the AI assistant you connect to the MCP connector) are located outside the European Union. Transfers to those recipients are framed by:
- The Standard Contractual Clauses approved by the European Commission (Decision 2021/914)
- The EU-US Data Privacy Framework in force since July 2023
Intervals.icu is published by a UK company, a country covered by a European Commission adequacy decision, and its servers are located inside the European Union.
Vincent Delpeuch follows regulatory developments (in particular ongoing challenges such as Schrems III) and will adapt transfers if necessary.
16. Changes to this policy
This privacy policy may be updated to reflect changes to the Service or to the regulation. The date of the last update is shown at the top of the document.
In the event of a substantial change (new purpose, new recipient processing health data, new sharing surface), you will be informed by email with reasonable notice before it takes effect.
17. Contact
For any question about this policy or your personal data:
- Email: vincent@tripaced.com
- Response time: 1 month maximum
18. Language
This English text is a translation provided for convenience. The French version is the reference version and prevails in the event of a discrepancy of interpretation.
End of the privacy policy.