Privacy Policy
Effective 30 August 2026 · applies to the TriForge web app, the home-screen app, and the iOS/Android apps.
TriForge is a personal endurance-training planner. It is built to work without an account, and it collects only what is needed to run your training plan. There are no ads, no analytics trackers, and your data is never sold or shared for marketing.
What TriForge stores
- Training data you enter or record — race and goal, baseline test times, availability, athlete profile, thresholds (FTP, heart-rate threshold, weight), logged sessions (times, distances, effort, heart rate, power), readiness check-ins, equipment, and GPS activities (route points, splits) you record or import.
- Account data (only if you create an account) — your email address, a display name, and a salted hash of your password. Passwords are never stored in readable form. A one-time recovery code is shown at sign-up; only its hash is kept.
- Home location (optional) — if you set one, it is used for route suggestions and weather notes.
Where it lives
- Without an account, everything stays in your browser or device storage. Nothing is uploaded.
- With an account (or a device-sync key), your training data is stored as a private document on our hosting provider (Vercel, servers in the United States) so it can sync between your devices. Documents are stored at unguessable addresses derived from a server-side secret.
Location
TriForge uses your device's location only while you record an activity on the Record tab (in the native app, also in the background during a recording you started, so the screen can be off). Location is used to measure distance, pace and route for that activity and is stored as part of the activity. It is not used for advertising or shared with anyone.
If you set a home location or request a weather forecast or route, the coordinates are sent to the following services to answer that request: Open-Meteo (weather), OpenStreetMap Nominatim (address lookup) and FOSSGIS OSRM (routing). These are anonymous requests; no account information is sent with them.
Health data
Heart rate and power values you log, or that come from a Bluetooth strap or an imported GPX/FIT file, are used only to compute your training load and are stored with the session. TriForge does not read Apple Health / HealthKit.
Deleting your data
- Delete account in Settings removes the account and every plan, log and recording stored under it, on the server and on the device, immediately.
- Reset all data in Settings clears the device's local copy.
- Export a JSON backup any time from Settings → Data.
Children
TriForge is not directed at children under 13 and does not knowingly collect their data.
Changes and contact
Changes to this policy are posted on this page with a new effective date. Questions: use the support link on the app's store listing, or the support page.