Privacy

Effective 7 June 2026.

This text is a translation. The English version is authoritative and prevails in case of any discrepancy.

Trailwise is a running-coaching service, currently in private beta and available by invitation. This notice explains what personal data we process, why, and the rights you have over it.

Who is responsible: Trailwise (the operator and data controller) is responsible for the data described here. Full legal entity details will be listed here once registration completes. For any privacy question, or to exercise your rights, contact privacy@trailwise.coach.

What we store: your account details (email and profile); training and activity data you import or connect (for example from Strava); health and fitness metrics such as heart-rate variability, resting heart rate, sleep, body weight and composition, and training load; connection metadata for the providers you link; and a security audit log. Provider credentials (OAuth tokens) are encrypted at rest and are never shared, sold, or exported.

Health data and your consent: the fitness and health metrics above are special-category data under GDPR Article 9. We process them only on your explicit consent, given when you connect a provider or enter the data, and solely to produce your coaching and recovery insights. You can withdraw consent at any time by disconnecting the provider or deleting your account, which stops any further processing.

Apple Health: if you install our companion iOS app and grant it permission, it reads the Health categories you choose on your iPhone (such as sleep, heart-rate variability, resting heart rate, steps, blood oxygen, respiratory rate, VO2 max, weight, body composition, blood pressure and exercise minutes) and sends them to your Trailwise account over an encrypted connection. The app reads only the categories you allow, never writes to Apple Health, and does not read your workouts or your location. This is special-category health data processed on your explicit consent, granted per category on your device; you can withdraw it at any time in the iOS Health settings or by unlinking the app. It travels only to Trailwise's own EU infrastructure and is never shared with third parties or used for advertising.

Why we process your data: account and core service data is processed to provide the service you signed up for (performance of a contract); health and activity data is processed on your explicit consent as described above; limited security logging relies on our legitimate interest in keeping the service safe.

Who we share it with: we do not sell your data and we do not serve ads. We rely on a small set of processors to run the service: hosting in the EU (Hetzner, Germany), email delivery (Resend), and the AI coaching component (Anthropic's Claude API). To comply with Strava's API terms, data from Strava is never sent to the AI coach. Activities you choose to connect come from providers such as Strava under their own terms.

International transfers: some processors are based outside the EU/EEA (Resend and Anthropic are in the US). Where that is the case, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

How long we keep it: we keep your data while your account is active. When you delete your account it enters a 30-day grace period and is then permanently removed; residual copies in encrypted backups are purged on the next backup rotation.

Your rights: under the GDPR you can access, correct, delete, restrict, or object to the processing of your data, and request a portable copy. You can export everything or delete your account from your privacy and data settings, or contact us at the address above. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, gegevensbeschermingsautoriteit.be).

Cookies: Trailwise sets only strictly necessary cookies for sign-in and session security. We use no advertising or analytics cookies, so no consent banner is required.

Children: Trailwise is not intended for anyone under 16, and you should not use it if you are under 16.

Changes: if this notice changes materially we will update the effective date above and, where appropriate, notify you by email or in the app.

Your data is visible only to you. Each account's data is isolated at the database level (row-level security).