Tri.Me — Privacy Policy
Version 0.1 — 17 September 2026
This policy explains what personal data Tri.Me collects, why, where it is kept, who can see it, how long it is kept, and the choices and rights you have. It is written in plain language on purpose. If anything here is unclear, ask — the contact details are at the end.
Tri.Me is a self-hosted training application run by a single operator for a small group of athletes. It is not an advertising business. Your data is not sold, rented, or used to build profiles for anyone else.
1. Who is responsible for your data
The operator of this Tri.Me server is:
ERWIN ROMMEL ESPINOSA — support@adaptive-tri.me — Singapore
The operator decides why and how your personal data is processed and is the person to contact for any request under this policy.
2. What we collect
Account and profile. Email address, password (stored only as a salted hash), name or display name, birth date, sex, height, weight, an optional profile photo, and the training history, injury history, fuelling preferences and goals you enter during onboarding or later in Settings.
Training data. Your training plans and blocks, planned sessions, completed workouts, uploaded FIT and GPX files and the second-by-second streams they contain (heart rate, power, pace, cadence, GPS position), your ratings of effort and any notes you attach, and the load and readiness figures the training engine derives from them.
Recovery and health signals from wearables. If you connect a wearable or health platform, the measurements it provides — for example heart-rate variability, resting heart rate, sleep, and readiness or recovery scores — together with the date you connected it and the date it last synced.
Coach conversations. The text of your conversations with the in-app AI coach, and the references it cites, so that the conversation can continue where you left off.
Community (Crew) data. If you choose a public handle: your handle, display name, short bio and profile photo; who you follow, who follows you, follow requests and blocks; the workouts, posts and comments you choose to share and the audience you chose for each; and the privacy choices and consents you record. Section 6 explains what other athletes can and cannot see.
Technical data. Standard server logs (request time, path, response status, IP address) kept for operating and securing the service, and the device platform and app version sent by the app so that problems can be diagnosed.
We do not collect precise location beyond what is inside the workout files you choose to upload or sync, and the app does not track your location in the background.
3. Why we use it (purposes and legal basis)
- To provide the service you signed up for — building and adapting your training plan, analysing your workouts, showing your readiness, and running the coach. This is processing necessary to perform our agreement with you.
- To connect the services you ask us to connect — pulling activities and recovery data from a wearable platform you have authorised. This happens only with your consent, which you give when you connect the platform and can withdraw by disconnecting it.
- To let you share with other athletes — only what you choose, to the audience you choose, and only after you have accepted the sharing terms. This is consent-based and can be withdrawn at any time (Section 6).
- To keep the service secure and working — server logs, backups, rate limiting and error diagnosis. This is our legitimate interest in running a safe service, balanced against your interests; the data used is the minimum needed.
- To improve the training engine — the operator may look at how the engine's guidance compared with real outcomes in order to calibrate it. This uses your data inside this server only; it is never shared externally, and you will be made aware when it happens.
Health-related data (heart rate, HRV, sleep, injuries, and similar) is sensitive. We process it only for the purposes above, only on this server, and only because you have chosen to use a training application whose purpose is to work with exactly this data.
4. Where your data lives
Your data is stored on a single self-hosted server operated by the operator named above, located in Singapore. It is not stored with a third-party cloud provider, analytics service or content delivery network. The mobile app talks only to this server.
Access to the server is restricted to authenticated app sessions and to the operator. Passwords are stored as salted hashes. The credentials that let the server read your wearable data are stored with application-layer encryption. Encrypted backups are taken regularly and kept by the operator.
The AI coach is a self-hosted model that runs on this same server, under the operator's control. No health data leaves this server to a third-party AI provider.
5. Who can see your data
- You. Everything about you, through the app and through the data export.
- The operator. Can access your data when you report a problem and ask for help, to run backups and restores, to keep the service secure, and for engine calibration as described in Section 3. The operator does not browse athletes' data without a reason connected to running the service.
- Other athletes on this server — only what you share. See Section 6. By default, nothing.
- Wearable and activity platforms you connect (for example Strava, Garmin, Oura, WHOOP, Apple Health). Data flows FROM those platforms TO this server at your request. Their handling of your data is governed by their own privacy policies. We do not send your Tri.Me data back to them.
- Apple. If you install the app through TestFlight or the App Store, Apple may collect crash reports and installation data under its own policies. Tri.Me itself does not include any analytics or crash-reporting service. Banner notifications are delivered by Apple; they carry no health data or message text. What Apple sees for each banner is the app's identifier, your phone's notification address, a generic category title (for example "Announcements"), and a notification identifier; the full text is fetched from this server when you open it.
- Our public website.
adaptive-tri.meis two static pages hosted by Cloudflare, with no analytics, no cookies and no tracking. Like any web host, Cloudflare logs the technical details of each request (IP address, browser) for security and delivery; nothing from the website is linked to your Tri.Me account. - Nobody else. No advertisers, no data brokers, no resale.
We may disclose data if legally required to by a competent authority in Singapore. If that ever happens, the operator will tell you unless prohibited from doing so.
6. Sharing with other athletes (Crew)
Everything starts private. Specifically:
- Your profile is not discoverable until you switch that on. New workouts default to Only me; new posts default to Followers — and no one can be your follower until you accept them (or choose to allow anyone to follow you).
- Your heart rate, power, effort ratings, readiness, plan, training zones and thresholds are never shown to other athletes unless you switch on "Show my heart rate, power and effort to others" — and even then, readiness, plan and thresholds stay private, always.
- Your GPS routes are hidden from others unless you switch them on, and when a route is visible to anyone but you, its start and end are always trimmed by the server (200 m by default) so that your home or usual start point is not revealed. You cannot switch this trim off.
- The first time you widen anything beyond "Only me", the app asks you to read and accept the sharing terms. You can re-read them at any time under Settings → About → Sharing terms.
- Withdrawing: set any audience back to Only me, unshare an item, remove a follower, block an athlete, or switch discoverability off. Every change to these settings is recorded in a privacy log you can see in your data export.
- Messages (direct and squad chat) stay on this server. They are never shared with the coach, and nothing in them is read, summarised or analysed by the app. When a notification tells you about a message, it carries the sender's name only — never the text.
- Messages you send are stored in the other person's copy of the conversation as well as your own. Two things follow. If you delete your account, your name and profile are removed, but the messages you sent may still be visible to the people you sent them to. And those people can download their conversations — including your messages — as part of their own data export.
- Anything you share is visible only to athletes on this server — never to the public internet.
7. How long we keep it
- Your account data, training data and conversations: for as long as your account exists.
- In-app notifications: deleted automatically after 90 days.
- Messages (direct messages and squad chat): deleted automatically after 180 days.
- Server logs: deleted after 30 days.
- After you delete your account: deletion is immediate and permanent for the live database. Your name may remain for a short time inside notifications other athletes already received, until those expire (90 days at most). Your data also leaves the encrypted backups as they rotate, within 30 days of deletion.
8. Your rights and how to use them
Wherever you are, you can:
- See and export everything — Settings → Account Settings → Export Data produces one file with your profile, plans, workouts, metrics, coach conversations, messages, community data and the privacy log. Your direct messages are included in full (both what you sent and what you received); in a squad chat the file contains your own messages.
- Correct your profile and settings in the app at any time.
- Delete your account and all data — Settings → Account Settings → Delete My Account (permanent; export first if you want a copy).
- Withdraw consent — disconnect a wearable, set sharing back to Only me, or delete the account.
- Object or ask questions — contact the operator (Section 10). You can also complain to your local data-protection authority; in Singapore that is the Personal Data Protection Commission.
Requests are handled by the operator personally and answered within a reasonable time — we aim for 30 days at most.
9. Children
Tri.Me is intended for adult athletes. You must be at least 18 years old to create an account. If we learn that an account belongs to someone under 18, the account and its data will be deleted.
10. Contact
ERWIN ROMMEL ESPINOSA — support@adaptive-tri.me
11. Changes to this policy
If this policy changes materially, you will be told in the app before the change takes effect, and the version and date at the top will be updated. Changes to the consent documents you have accepted will ask for your acceptance again.
This policy describes how Tri.Me handles your data today. If that changes, the policy and the version above are updated.