Privacy notice
Effective 1 September 2026. Version 2026-09-01.
Trailwise is a running-coaching service with an AI coach, Trailly, and optional human coaches. Coaching only works with data about your body and your training, some of which is health data. This notice explains what personal data we process, why, who sees it, how long we keep it and what you can do about it. It is written to be read, not skimmed. If anything is unclear, write to us.
1. Who is responsible
The data controller is Trailwise BV, Wetteren, Belgium (see the legal notice for the registration details). We are responsible for all personal data described in this notice, including the data a human coach sees through Trailwise. For any privacy question or to exercise your rights, contact privacy@trailwise.coach.
2. What data we process
We process the following categories of personal data. You control most of them: you choose which sources to connect, what to log and what to share.
Account data. Your email address, name, language, time zone, account settings, and the security log of sign-ins and important account actions.
Profile data. What you tell us about yourself for coaching: date of birth, sex, height, weight, self-described fitness, maximum heart rate and zones, goals, availability, shoes and gear, personal records.
Training data. Activities you connect or import, including duration, distance, pace, power, heart rate, elevation, and the GPS track of an activity where the source provides one. A GPS track is location data and shows where you ran.
Health and body data. Heart-rate variability, resting heart rate, sleep and sleep stages, blood oxygen, respiratory rate, VO2 max, body weight and composition, blood pressure, and daily readiness and stress values, as delivered by your connected devices or entered by you.
Check-ins and symptoms. How you feel, soreness and pain on the body map, illness, injuries, declared breaks, menstrual cycle information if you choose to log it, and your answers to the nutrition screening questions.
Nutrition data. Food and hydration you log, calorie and macronutrient targets, weight trend, and race-day fuelling plans.
Conversations with Trailly. The messages you send to the AI coach, its replies, the daily call and weekly digest, and the coaching memory Trailly keeps about you so that it does not ask the same question twice.
Documents you upload. Training plans, medical clearance letters, race documents and other files you place in your document library, together with the text extracted from them so Trailly can read them.
Races and calendar. Races you add, race tasks and deadlines, and calendar events you choose to sync with Google Calendar or iCloud Calendar.
Approximate location. If you use the weather page, the place you choose or the approximate location your browser provides, used only to fetch a forecast and map tiles.
Billing data. Your plan, invoices, payment status and the last four digits and expiry of your payment method. Card numbers never reach Trailwise; they are handled by Stripe.
Support and feedback. Bug reports, feature requests and support conversations, and the technical context you attach to them.
Technical data. IP address, browser and device type, pages visited, error logs, and, if you accept analytics cookies, usage statistics.
Coaching relationship data. If you link to a human coach: the invitation, the categories of data you chose to share, the coach’s notes and actions about you, and the alerts the coach receives.
3. Health data and your explicit consent
Health and body data, check-ins and symptoms, nutrition data, menstrual cycle data and the health content of your conversations and documents are special-category data under Article 9 of the GDPR. We process them only with your explicit consent, which you give when you connect a source, upload a file, log a value or start using Trailly, and only to provide coaching, recovery and nutrition guidance to you. You can withdraw consent at any time by disconnecting a source, deleting a value, or deleting your account. Withdrawal stops further processing; it does not affect what happened before.
Health data of a person under the digital consent age of their country requires the consent of a parent or guardian. See the minimum age by country.
4. Why we process your data, and on what legal basis
To provide the service you signed up for (performance of a contract, GDPR Article 6(1)(b)): your account, your plan, syncing your sources, calculating your scores and plan, showing your data back to you, billing, and support.
With your explicit consent (Articles 6(1)(a) and 9(2)(a)): all health and body data, check-ins, nutrition, cycle data, the health content of documents and conversations, sharing data with a human coach, analytics cookies, and marketing email.
For our legitimate interests (Article 6(1)(f)): keeping the service secure, preventing abuse, security logging, fixing errors, and improving the product from aggregated, non-identifying statistics. We have weighed these interests against your rights and you can object at any time.
To comply with the law (Article 6(1)(c)): invoicing, accounting, tax and answering lawful requests from authorities.
5. How Trailly, the AI coach, uses your data
Trailly reads your data to reason about your training and produces its guidance with a large language model run by Anthropic on our behalf. Only the data needed for the question at hand is sent, and it is sent under a contract that forbids Anthropic from using it to train or improve its models. We do not train any model of our own on your data. Trailly’s guidance is general training and wellness guidance, not medical advice, and it is marked as written by AI wherever it appears. The How Trailly uses AI page describes this in full.
Data from Strava is used only as input for your own coaching, in line with the Strava API agreement. It is never used to train or improve any model, never aggregated across users, and never shown to anyone but you and the coaches you choose.
6. Human coaches
If you accept an invitation from a coach, you choose which categories of your data the coach may see (for example training, recovery, sleep, nutrition, body, check-ins). The coach sees only those categories, only while the link is active, and you can revoke the link at any moment from your settings. Trailwise remains the data controller; the coach acts under the coach terms and may use your data only to coach you. A coach cannot export your data or share it with third parties through Trailwise.
7. Who receives your data
We do not sell personal data and we do not show advertising. We share data only with the processors we need to run the service, each bound by a data-processing agreement, and only for the purpose stated. The current list, with locations and purposes, is kept on the subprocessors page. The main ones are: Google Cloud (hosting and storage in the European Union), Anthropic (the AI model behind Trailly), Stripe (payments), Resend (transactional email), Backblaze (encrypted off-site backups), Google Analytics (usage statistics, only if you accept analytics cookies), Linear (support and bug tracking), and the map, weather and geocoding services used by the weather and race pages.
The services you connect (Garmin, Strava, Polar, Whoop, Oura, Withings, Fitbit, Intervals.icu, Apple Health, Google Health Connect, Google Calendar, iCloud) send data to Trailwise on your instruction and under their own terms and privacy notices. Trailwise never sends your data back to them, with one exception: calendar events you ask us to create in your own calendar.
We may disclose data where the law requires it, to protect the rights and safety of a person, or in a merger or acquisition, in which case this notice continues to apply and you will be informed.
8. International transfers
Your data is stored in the European Union. Some processors are established in the United States (Anthropic, Stripe, Resend, Linear, Google for analytics). For these we rely on the EU-US Data Privacy Framework where the processor is certified and on the European Commission’s Standard Contractual Clauses in every other case, with additional safeguards such as encryption in transit and at rest. Details per processor are on the subprocessors page.
9. How long we keep your data
We keep your data, including the documents you upload, for as long as your account exists, because your training history is the point of the service: Trailly reasons over all of it and plans up to two years ahead. If you want to stop using Trailwise but keep your data, you can close your profile instead of deleting it: we then keep your data for at least two years from that request, you can reopen your account at any time in that period, and we ask you before anything is removed afterwards. When you delete your account, it enters a grace period of thirty days during which you can change your mind; after that it is permanently removed from the live database, and the encrypted backup copies that still contain it expire on their own rotation, the last of them within twelve months. Invoices and accounting records are kept for the period Belgian law requires (up to ten years for VAT records). The security log is kept for twelve months. Support conversations are kept for seven years after they close, so that we can answer any later question or claim about them. Aggregated statistics that no longer identify you may be kept indefinitely.
10. Your rights
Under the GDPR you can access your data, correct it, delete it, restrict or object to its processing, withdraw consent, and receive a portable copy. You can export everything and delete your account yourself from your privacy and data settings, without asking us. For anything else, write to privacy@trailwise.coach; we answer within one month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, gegevensbeschermingsautoriteit.be) or with the authority of your own country.
Trailwise does not take decisions with legal or similarly significant effects about you by automated means. Trailly’s guidance is a recommendation you are free to ignore, and no plan, price or access decision is made by an algorithm alone.
11. Security
All connections are encrypted. Provider credentials are encrypted at rest with keys held separately from the database. Each account’s data is isolated at the database level with row-level security, so one athlete’s data cannot be read through another’s account, including by our own application code. Access by our team is limited to what support requires and is logged. We test our defences, and we will inform you and the authority without undue delay if a breach ever affects your data.
12. Cookies and analytics
Trailwise uses strictly necessary cookies for sign-in and session security, which need no consent, and analytics cookies (Google Analytics) only if you accept them in the cookie banner. You can change your choice at any time. The cookie policy lists every cookie and its lifetime.
13. Children and minimum age
Trailwise is not intended for children. You may use it on your own from the digital consent age of your country of residence, and never below the age of thirteen; below that age a parent or guardian must create and hold the account. The minimum age by country page lists the age that applies to you. If we learn that we hold data of a person below the applicable age without the required consent, we delete it.
14. Changes to this notice
When we change this notice in a way that matters, we update the version and effective date above and tell you by email or in the app before the change applies. Earlier versions are available on request.
Your data is visible only to you and to the coaches you choose. That is the design, not a promise added afterwards.