TriageFit
FeaturesAboutPricing
Sign inGet started

Product

  • Features
  • Pricing
  • Affiliates, earn 10%

Company

  • About
  • Team
  • Contact
  • Coaching

Legal

  • Privacy Policy
  • Terms of Service
  • Disclaimer
  • Cookie Policy

Connect

  • Twitter
  • Instagram
  • Email

© 2026 TriageMethod Ltd. All rights reserved.

TriageMethod

Privacy policy

Last updated: 14 September 2026

TriageFit ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the TriageFit Health Coaching platform ("Service").

1. Data controller

TriageMethod Ltd, a company registered in Ireland and trading as TriageFit, is the data controller responsible for your personal data. For our company registration details, any privacy matter, or to exercise your rights, contact us at info@triagemethod.com.

Our Data Protection Officer is Patrick Farrell.

2. What data we collect

Account data

  • Name, email address, date of birth, gender
  • If you ask about seats for your team, your name, role, work email address and phone number, the company's name, the number of seats you asked about and where the team is based, anything you wrote in the message, who introduced you, and the outcome of the enquiry
  • Password (hashed and salted, we never store plain text)
  • Profile photo (optional)

Health & fitness data

  • Training logs, exercise history, and programme data
  • Body composition measurements (weight, body fat, etc.)
  • Blood work results and medical markers
  • Medications and supplements you tell us about, including weight-loss (GLP-1) medication
  • Injuries, pain and physical restrictions we need to train around
  • What you tell us at intake about your health history, including any history of disordered eating or of mental-health conditions
  • Sleep data, stress levels, and recovery metrics
  • Nutrition logs and dietary preferences
  • Health scores and dimension assessments
  • Habit tracking data
  • Wearable data you upload

Usage data

  • Device information, browser type, and operating system
  • IP address and approximate location
  • Pages visited, features used, and interaction patterns
  • Session duration and frequency

Communication data

  • Messages sent to AI coaching assistant
  • Support tickets and correspondence
  • Community posts and comments

Organisation and partner data

  • If an organisation funds memberships, the names, work email addresses and roles of its admin and billing contacts, and the organisation's seat and billing details
  • If an organisation invites you to a funded seat, the email address and role its admin entered for you
  • If a partner registers an organisation as a sales prospect, the business contact details the partner gave us for a named person there
  • If you register a clinic with us, your name, role and work email address, the clinic's name and website, who referred you, the version of the clinic partner terms you accepted, and our decision on the registration

3. Lawful basis for processing

We process your personal data on the following legal bases:

  • Contract: Processing necessary to provide the Service you subscribed to (Article 6(1)(b) GDPR)
  • Consent: Where you have given explicit consent, such as for marketing communications or optional data sharing (Article 6(1)(a) GDPR)
  • Legitimate Interest: For service improvement, security, and fraud prevention (Article 6(1)(f) GDPR)
  • Legal Obligation: Where required by law, such as tax or regulatory compliance (Article 6(1)(c) GDPR)

Health and fitness data is classified as special category data under GDPR. We process this data based on your explicit consent (Article 9(2)(a) GDPR), which you give when you create your account. The tick names the categories, it is required, and no account is created without it.

Waitlist. If you join our pre-launch waitlist, we process your email address (and your name, if you give it) to send you a short series of emails about how our coaching method works, and to notify you when we open, based on your consent (Article 6(1)(a) GDPR). You can withdraw at any time using the unsubscribe link in any email. We keep waitlist details until launch or until you unsubscribe, after which they are deleted within 30 days.

Starting a subscription. If you begin the payment process and do not finish it, we keep a record of the attempt, including the email address you entered, so that we can recognise a repeated attempt, release you from a pending state if the session expires, and answer you if you contact us about a payment that did not go through. Our legitimate interest in operating a working checkout is the basis for this (Article 6(1)(f) GDPR). These records are deleted after 90 days, and sooner if you ask us to erase your data.

Employer-funded membership. If your employer or another organisation pays for your membership, we process the organisation’s details, its seats, and your seat’s enrolment status to run that arrangement (Article 6(1)(b) GDPR). You join a funded seat only by accepting an invitation while signed in, the acceptance screen tells you exactly what the organisation can and cannot see before you commit, and section 4 describes that boundary. You can leave the organisation at any time in Settings.

Organisation invitations. When an organisation invites you to a funded seat, we hold the email address and role its admin entered so we can deliver the invitation and connect your acceptance to the right seat, based on our legitimate interest in letting organisations offer seats to the people they chose (Article 6(1)(f) GDPR). The invitation email explains this at first contact. An invitation link works for 7 days, an invitation you never accept is deleted 90 days after it expires, and we never use an invitee’s address for marketing.

Partner referrals of organisations. A partner who introduces an organisation to us can register that introduction, and the registration includes the business contact details of a named person at the organisation. Those details reach us from the partner rather than from the named person, and this paragraph is our information notice to that person (Article 14 GDPR). We hold the details so the first partner to register an introduction is the one credited for it, based on our legitimate interest in running the partner programme (Article 6(1)(f) GDPR). We never contact or market to the named person because of a registration, only our admin team and the registering partner can see the details, and we remove them 13 months after the deal settles, keeping a de-identified record of the outcome for commission accounting. If you are such a contact and you object, write to us at the address in section 1 and we will remove your details (Article 21 GDPR).

Sharing your progress with your clinic. If a healthcare organisation refers you to TriageFit, or invites you to a seat it funds, you choose whether the clinicians who hold a seat at that organisation can follow your progress. Nothing is shared unless you say so. We ask you on the checkout page, on the invitation screen or in Settings, with the full list of what they would see in front of you, and we rely on your explicit consent for this sharing (Article 6(1)(a) and Article 9(2)(a) GDPR). Section 4 describes exactly what a clinician can and cannot see. You can turn sharing off at any time in Settings, then Privacy: the organisation stops seeing you straight away, your membership and your coaching carry on unchanged, and we keep a record of each decision so we can show what you chose and when.

Registering a clinic. If you register a clinic with us, we process your details to set the clinic up and to perform the clinic partner terms you accept, and we verify the registration before any patient can be asked to share their progress, which is our legitimate interest in letting only real clinics ask. We keep the decision, and any reason for it, as the record of that check.

Asking about seats for your team. When you fill in the enquiry form on our business page, we use what you give us to reply with a quote and the rollout steps, and for nothing else: the address is never added to a marketing list. Where you are the person who would sign, this is a step taken at your request before a contract (Article 6(1)(b) GDPR); where you are asking on behalf of your employer, we rely on our legitimate interest in answering the enquiry you sent us (Article 6(1)(f) GDPR). If a partner of ours introduced your team, we keep a note of which partner so that they can be paid; that note names the partner, not you. We keep your contact details for 13 months after the enquiry closes, then remove them; the record that a company asked, and what came of it, stays without your details.

4. How we use your data

  • To provide personalised coaching, training programmes, and health insights
  • To calculate and display health scores and progress tracking
  • To generate AI-powered recommendations and coaching responses
  • To process payments and manage subscriptions
  • To send transactional emails (check-in reminders, reviews, etc.)
  • To understand and improve the Service through consent-gated, pseudonymised product-usage analytics, including Google Analytics 4
  • To detect and prevent fraud or abuse

Product-usage analytics. We record first-party product-usage events under a pseudonymous identifier stored only in your browser, and only after you accept analytics cookies. With the same consent, Google Analytics 4 receives page views without query strings and with IP anonymisation. These events are retained for 13 months and are used to understand and improve how the Service is used.

Your coach can see your AI-coach conversations. If you are assigned a human coach, they can read your chats with the AI coaching assistant so they have the full context when supporting you and can step in on anything that needs a human. These conversations are visible to your assigned coach and to our safeguarding team; they are never shown to other members.

Your coach can also see a short health-risk summary. Your assigned coach, and our admin team, can open your member record in our coaching console. Alongside your programme, check-ins and health scores, that record shows a short risk summary drawn from what you have told us at intake and from your injury record as you keep it up to date: whether you have told us about a history of disordered eating, whether you are taking a weight-loss (GLP-1) medication, whether you have an injury we should train around, and whether you reported a high stress load. Your coach sees each of these as a simple flag (yes, no, or “we don’t know”), so they can coach you safely and not ask you to repeat yourself. They do not see the words you wrote about any of it. This is part of the personal coaching you signed up for (Article 6(1)(b) GDPR) and rests on the explicit consent to health-data processing you gave when you joined (Article 9(2)(a) GDPR). Your assigned coach can only open the records of members assigned to them, and every time a coach or an administrator opens your record we log who looked and when.

What a funding organisation can see. If an organisation pays for your seat, it can see that you have enrolled, and it can see group numbers that never single anyone out; groups smaller than five are withheld. It can never see your training, your check-ins, your messages or anything about your health. That stays between you and your coach. The one exception is a healthcare organisation whose clinicians you have chosen to share your progress with, and the next paragraph describes it. The organisation funds the seat and nothing more: it cannot require you to use the Service or to enter any data, and you can leave it at any time in Settings.

What a clinician can see, if you choose to share. A healthcare organisation sees nothing about you until you turn sharing on. While it is on, the clinicians who hold a seat at that organisation can see your name, email address, date of birth and gender, the programme week you are on, when you last checked in, how closely you are following your plan as one figure, your health scores and which way they are heading, your blood work from the last year, your medications and injuries, the energy, stress and sleep from your last two weeks of check-ins, and how long it has been since you last used TriageFit. Go 14 days without using it and their patient list marks you as disengaged. They never see your journal, your messages with your coach or your day-to-day training and food logs. Each time a clinician views your summary or opens your report, we record it. Turn sharing off and the organisation stops seeing you straight away, with no notice to it and no change to your membership.

Keeping you safe. To help keep you safe, free text you enter, for example journal entries, symptom or recovery notes, or messages to the coach, is automatically screened for signs of a crisis, such as self-harm, a mental-health emergency, or an urgent medical or eating-disorder concern. Where such signs appear, we may create a limited safety record and share it with our safeguarding and coaching team so we can offer support or point you to help. We do this to protect your vital interests (Article 6(1)(d) and, where applicable, Article 9(2)(c) GDPR). This safety record can include the text that triggered it; we keep it for up to two years, and we retain it, with your account link removed, even if you delete your account.

5. Sub-processors

The table below records the third-party processors used by the production Service and the data each one processes on our behalf. Where the application does not pin a processing region, the table says so.

ProcessorData processedPurposeRegion and international transfers
Google Cloud (Vertex AI)Text sent for a coaching task, together with the relevant account, programme, training, nutrition, wellbeing, injury, medication, blood-work and other health context included in the prompt. Member queries and reference text are also processed to create embeddings.Generate coaching responses and other model-assisted content, and create embeddings for knowledge-base retrieval.EU only. Gemini requests use the EU multi-region and embeddings useeurope-west1. The application refuses non-EU Vertex regions.
NeonAll records stored by the Service, including account, authentication, contact, consent, health and fitness, coaching, communication, community, billing-reference and audit data.Host the Service's PostgreSQL database.The production database endpoint is in eu-central-1(Frankfurt). The application reads the deployed database endpoint and does not pin any separate account or support region.
VercelApplication requests and responses, which can contain any data a member submits to or receives from the Service; session data; and request metadata such as IP address, user agent, URL and timing.Host and run the application, including server-side routes and scheduled jobs.Application compute is pinned to fra1 (Frankfurt). The application does not pin a separate region for Vercel account, control-plane or support processing.
StripeEmail address, internal account identifier, selected plan, price and currency, promotion or referral details, billing name and address, subscription and transaction records, and withdrawal acknowledgement. Payment-card details are entered directly with Stripe and do not pass through our servers. We do not send coaching or health records to Stripe.Process payments, subscriptions, invoices, billing-portal actions, refunds, disputes and affiliate payouts.No processing region is pinned in the application code.
ResendRecipient email address, sender, subject, HTML and plain-text message body, unsubscribe link and provider message identifier. Message bodies can contain account, billing or coaching information.Deliver transactional, coaching and consented marketing email.No processing region is pinned in the application code.
UpstashIP addresses or account identifiers used as rate-limit keys, request counters and reset times, and Stripe webhook event identifiers used to prevent duplicate processing. It does not receive coaching or health-record content.Enforce distributed rate limits and keep short-lived Stripe webhook idempotency records.The production database is in eu-central-1 (Frankfurt) with no read regions. The Upstash account controls this setting; the application does not pin it.
SentryOpaque account identifier, error type and stack trace, request URL and headers, and device and request metadata. Request bodies, exception text and known health or identifying fields are redacted before transmission. Session replay is disabled.Error monitoring, diagnostics and operational alerting.Error ingestion uses Sentry's German endpoint in the EU. The deployed DSN selects that destination; the application does not hard-code a separate account or support region.
Cloudflare R2Uploaded files and object metadata, including progress photos, wearable exports, blood-work PDFs, form-check videos, community images and medical-clearance documents.Store and retrieve member uploads.The production upload bucket uses Cloudflare's EU jurisdiction. The deployed S3-compatible endpoint selects the vendor and jurisdiction; the application does not pin them.
Google (Google Analytics 4 and Search Console)Google Analytics receives consent-gated page views without query strings, together with configured analytics events and an anonymised IP address. Search Console supplies site-level search queries, pages, clicks, impressions, click-through rate and position.Measure consented website usage and provide search-performance reporting to the administrator.No processing region is pinned in the application code.

6. Data retention

  • Your account and its history: Your account, your programme, your training history and your check-ins are kept for as long as you have an account with us. Cancelling a subscription does not delete any of it, which is what lets your programme pick up where you left off if you come back. It is erased when you ask us to delete your account, which you can do at any time under Settings, Privacy & data.
  • Deleted accounts: When you ask us to delete your account, your personal data is erased within 30 days. A few limited records are kept afterwards, with your account link removed where possible, where the law requires or allows it: a record of the consents you gave and withdrew (kept for up to 6 years, as proof of the lawful basis for processing your data), any safety record created by the screening described in section 4 above (kept for up to 2 years), and, if we closed an affiliate partner account of yours for cause, your email address on the partner exclusion list described below. Anonymised aggregated data may also be retained for analytics.
  • Billing records: Retained for 7 years as required by tax regulations.
  • AI interaction records: Up to 2 years.
  • In-app notifications: The notifications in your notification centre, check-in reminders, plan updates and messages from your coach, are kept for 24 months and then automatically deleted, whether or not you have read them.
  • Consent records: Up to 6 years, to demonstrate the lawful basis for processing.
  • Clinic sharing: Each time you turn sharing with a healthcare organisation on or off is kept as a consent record on the same 6-year window, and each clinician view of your summary or report is kept for 2 years as a security record.
  • Marketing suppression: If you unsubscribe, we keep only your email address on a suppression list so we do not contact you again.
  • Partner exclusion: Anyone can join our affiliate programme, and we close an account afterwards if it breaks the programme terms. Where we do, we keep the email address on an exclusion list so the same person cannot simply open another one. Our legitimate interest in protecting the programme from fraud is the basis for this (Article 6(1)(f) GDPR). If you then delete your account we remove the link to it, and the note explaining the decision, and keep the address alone.
  • Support correspondence: Retained for 2 years after resolution.
  • Organisation invitations: An invitation you accept becomes part of the record of your membership. An invitation that is never accepted is deleted 90 days after it expires.
  • Partner deal registrations: The contact details in a registration are removed 13 months after the deal settles; a de-identified record of the outcome is kept for commission accounting.
  • Corporate enquiries: The contact details in an enquiry about seats for your team are removed 13 months after the enquiry closes, or 13 months after it arrived if it was never answered; a de-identified record of the enquiry and its outcome is kept.
  • Server logs: Automatically purged after 90 days.
  • Operational records: The records our systems keep in order to run the service are cleared on their own schedules: payment provider events after 30 days, and email delivery jobs, scheduled job runs, unfinished checkouts and the record of which coaching material was retrieved for an answer after 90 days.

7. Your rights

Under GDPR and applicable data protection laws, you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format (JSON export available in Settings)
  • Restriction: Request that we limit processing of your data
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at info@triagemethod.com or use the data management features in your Settings page. We will respond within 30 days.

Automated decision-making. We use automated processing to generate your health scores, coaching recommendations, adaptive training and nutrition plans, and the short health-risk summary your coach sees. This supports your coaching but does not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR, and the Service remains under human oversight: a person, not a machine, decides what to do about anything flagged. You can contact us to query or ask us to review any recommendation.

8. Cookie policy

We use the following categories of cookies and local storage:

  • Essential: Required for the Service to function (authentication, session management, CSRF protection), the record of the cookie choice you made, and the display preferences you set yourself (light or dark appearance, collapsed navigation). Cannot be disabled.
  • Functional: Save your progress through the longer forms and remember who is signed in on this device, so you can pick up where you left off. Can be managed in cookie settings.
  • Analytics: Help us understand how the Service is used through a first-party visitor and session identifier and Google Analytics 4. Opt-in only.
  • Marketing: Remember which partner or referral link brought you to us, so that a referral or affiliate credit is applied correctly. We set these on our own domain only: we run no advertising networks, no ad pixels and no cross-site tracking. Opt-in only.

You can manage or withdraw your cookie consent at any time using the "Manage cookie preferences" option on our Cookie Policy page, or (if signed in) in Settings > Privacy & Data. See that page for the full list of cookies.

9. International transfers

Section 5 states the production region we can verify for each processor. Where the repository does not establish whether data can be accessed or processed outside the EEA, or which transfer safeguard applies, the table marks that point for confirmation rather than making an unverified claim.

10. Data security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, access controls, regular security reviews, and incident response procedures.

11. Children's privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.

13. Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority. As an Irish company, our lead supervisory authority is the Data Protection Commission (DPC) at dataprotection.ie. If you are in the UK, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

14. Contact

For privacy-related enquiries, contact our Data Protection Officer, Patrick Farrell, at info@triagemethod.com.