Privacy Policy

Last updated: 1 June 2026

TriBoard ("TriBoard", "we", "us" or "our") is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, use, hold, disclose and protect your personal information when you use triboard.app and related services (the "Service").

1. Information we collect

We collect only what we need to deliver the Service:

  • Account data: name, email address and authentication identifiers (including Google or Apple sign-in tokens where used).
  • Training data: sessions you log (swim, bike, run), wellness check-ins, niggles, PBs, equipment, race plans and notes.
  • Connected services: activity data you authorise us to import from Strava, Wahoo or similar platforms.
  • Billing data: processed by our payment provider (Stripe). We do not store full card numbers.
  • Technical data: IP address, browser type, device identifiers and basic analytics required to operate the Service securely.

2. How we use your information

  • Provide, maintain and improve the Service.
  • Authenticate you and keep your account secure.
  • Send transactional messages (receipts, password resets, important service notices).
  • Send optional product updates, you can opt out at any time.
  • Comply with our legal obligations under Australian law.

We do not sell your personal information.

3. Disclosure to third parties

We disclose personal information only to service providers that help us run TriBoard, including cloud hosting, database, email delivery and payment processing partners. These providers may store data outside Australia (including in the United States and the European Union). We take reasonable steps to ensure overseas recipients handle your information consistently with the APPs.

4. Data security

Personal information is stored in encrypted form, in transit and at rest. Access is restricted to personnel who need it to operate the Service. In the unlikely event of an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

4a. Strava integration

When you connect Strava, TriBoard receives an OAuth access token and refresh token from Strava and imports your activities using the minimum scopes read and activity:read_all. We do not request any write scopes and cannot post, edit or delete anything on your Strava account.

What we store: per-activity summary metrics only (date, type, duration, distance, average heart rate, average/normalised power, average pace, calculated training load). We do not retain raw GPS streams, route polylines, or split-by-split sensor data.

How tokens are protected: Strava access and refresh tokens are encrypted at rest with AES-GCM before being written to our database, and all traffic with Strava and with your browser is over HTTPS. Tokens are refreshed automatically before they expire so you don't have to reconnect.

How to disconnect and delete: Settings → Connected apps → Disconnect. This calls Strava's deauthorize endpoint to revoke our access and permanently deletes every session we imported from Strava. If you revoke access directly from Strava, the deauthorize webhook triggers the same deletion on our side.

How your Strava data is used: every data point we ingest is tagged with its source (strava, wahoo, manual, or derived). Rows tagged strava are scoped to the athlete who owns them by row-level security and are shown only to that athlete; no other end user can read another athlete's Strava-sourced data. Wherever Strava data appears in the app it carries Strava attribution and a "View on Strava" link.

No model training on Strava data: we do not train, fine-tune or otherwise fit any machine-learning model on data sourced from Strava. Race predictions are computed deterministically by sports-science formulas (e.g. Riegel for run pace, power/CdA models for the bike) on the requesting athlete's own inputs, at request time, for that athlete only. The AI Coach reasons over the authenticated athlete's own metrics to generate guidance for that same athlete; athlete metrics are passed into a prompt at request time and are not retained as training data by us or by the model provider.

No third-party exposure: TriBoard does not expose an athlete's Strava-sourced data to any other end user. There is no coach-facing or team-facing view of another athlete's Strava data.

5. Data retention

We retain your information while your account is active and for as long as needed to comply with legal, tax and accounting obligations. You can request deletion at any time (see section 7).

6. Cookies

We use first-party cookies and similar technologies to keep you signed in and to measure how the Service is used. You can disable cookies in your browser, but parts of the Service may not work.

7. Your rights

Under the APPs you may request access to, correction of, or deletion of your personal information, and you may export your training data at any time from the Settings page. To make a request, email legal@triboard.app.

8. Complaints

If you believe we have breached the APPs, contact us first at legal@triboard.app and we will respond within 30 days. If you are not satisfied, you can lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or an in-app notice before they take effect.

10. Contact

TriBoard, Australia.
Email: legal@triboard.app