Effective: August 12, 2026 · Contact: george@bristowbuilt.com
TriCoach ("we," "our," "the service") is a coaching platform operated by Bristow Built, owned and operated by George Bristow II (george@bristowbuilt.com). TriCoach allows coaches to design and deliver structured triathlon and strength training programs, and allows athletes to track their training and connect third-party fitness integrations.
Email address, display name, and role (athlete or coach). Passwords (if used) are hashed with Argon2id and never stored in plaintext.
When you connect your Strava account, we request read access to your activities, and write access so we can upload completed TriCoach workouts to Strava at your request. We collect and store:
We do NOT read your Strava profile photo, followers, following, kudos, comments, segments, gear, or payment information.
What we send to Strava: when you — or your coach, acting on your behalf — choose to push a completed workout, we upload it to your Strava account as an activity. That upload contains no more than the session's sport type, start time, duration, distance, calories, average and maximum heart rate, and any workout notes. No GPS route and no other TriCoach data is sent. Uploads are never automatic: each one is an explicit action you or your coach takes. The resulting activity is yours on Strava — we never edit or delete Strava activities, so removing one is done from Strava. If you connected before we added upload support, your existing connection stays read-only until you reconnect.
If you connect your Oura account (via Personal Access Token), we collect daily readiness and sleep scores. Tokens are encrypted at rest.
If you configure Garmin Connect, your credentials are encrypted using Fernet and used only to push structured workouts to your Garmin device. We do not pull activity data from Garmin.
Training plans, workout completions, strength logs, check-ins, and RPE ratings entered by you or your coach.
Goal race, training history, injury flags, and subjective wellness data you voluntarily provide during onboarding or daily check-ins.
When you or your coach describe a workout in your own words and ask us to build it, we store that request and what the model produced from it: the description verbatim (including anything dictated by voice, transcribed on your device), the training context we sent with it — threshold values, one-rep maxes, available equipment, and injury notes — and the generated workout, whether or not it came out usable. Failed generations are kept for the same reason as successful ones.
What we do with it: we use these records to measure and improve the quality of generated workouts — comparing versions of our instructions to the model, and building a regression set from real requests instead of invented ones. Anthropic, who provide the model, do not train on API traffic, so this is our own evaluation corpus and not a donation to a third party. See Section 4 for how long we keep it.
We use PostHog (see Section 5) for product analytics, session replay, and error tracking. This includes: pages and features you use, app performance and crash data, and a recording of your on-screen session for debugging and product-improvement purposes. Analytics events are tied to your account ID, not your name or email. Session replay masks all form input by default, and we additionally mask message content and sensitive metric values (heart rate, weight, readiness scores) so they never appear in a recording.
We do NOT sell your data. We do NOT use your data for advertising. We do NOT share your training or health data with third parties except the sub-processors listed in Section 5.
Strava data: In compliance with the Strava API Agreement §2.14.5 and §2.14.6, all Strava-derived data (activities, streams, tokens) is deleted within 48 hours of disconnecting your Strava account. Disconnection can be done from /settings. Deletion is synchronous — your data is purged at the moment you disconnect.
Account deletion: To delete your TriCoach account and all associated data, email george@bristowbuilt.com. We will complete deletion within 30 days and confirm via email.
Other data: Training plans, strength logs, and check-ins are retained for the life of your account and deleted on account deletion.
AI workout generation requests: The requests described in Section 2.7, and the workouts generated from them, are retained for 24 months from the date of the request and then automatically deleted by a scheduled job. Deleting your account deletes them immediately — both the requests made for you as an athlete and any you authored as a coach. Individual examples we select for our quality-regression set are kept beyond that window; those are held for evaluation purposes only and are not linked to your account.
Analytics and session data: Product analytics events are retained for up to 7 years. Session replay recordings are retained for 30–90 days, after which they are automatically deleted. Deleting your account also deletes your associated analytics profile and any linked recordings.
The following third parties may process your data as part of delivering TriCoach:
| Provider | Purpose | Data shared |
|---|---|---|
| Railway | Hosting (database + API server) | All stored data (encrypted at rest) |
| Strava | Fitness activity source + completed-workout upload | OAuth tokens (athlete-to-athlete), uploaded workout data |
| Resend | Transactional email delivery | Email address, message content |
| Oura | Sleep + readiness data (optional) | Personal Access Token (encrypted) |
| Garmin | Workout push (optional) | Credentials (encrypted), workout data |
| Anthropic (Claude) | AI coaching summaries; workout generation (Section 2.7) | Anonymized training metrics; for workout generation, the request text you write or dictate plus the training context it needs — threshold values, one-rep maxes, equipment, and injury notes. Not used to train their models. |
| PostHog Inc. | Product analytics, session replay, error tracking | User ID, usage events, replay recordings (PostHog Cloud, US region) |
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the GDPR:
To exercise any of these rights, email george@bristowbuilt.com with the subject line "GDPR Request — [right]". We will respond within 30 days.
TriCoach stores a JWT authentication token in your browser's localStorage. This token identifies your session and is used for all API requests.
We use PostHog for product analytics, session replay, and error tracking (see Section 5). PostHog sets its own cookies/local storage to recognize your browser across sessions. This is not third-party advertising tracking — analytics are tied to your TriCoach account ID, not sold, and not used to build an advertising profile. Because analytics only run for logged-in accounts, we do not show a cookie consent banner; using the app while logged in constitutes acceptance of this policy.
We may update this policy from time to time. Material changes will be communicated via email to your registered address. The "Effective" date at the top of this page indicates when the current version took effect.