Last updated: 14 September 2026
TriageFit ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the TriageFit Health Coaching platform ("Service").
TriageMethod Ltd, a company registered in Ireland and trading as TriageFit, is the data controller responsible for your personal data. For our company registration details, any privacy matter, or to exercise your rights, contact us at info@triagemethod.com.
Our Data Protection Officer is Patrick Farrell.
We process your personal data on the following legal bases:
Health and fitness data is classified as special category data under GDPR. We process this data based on your explicit consent (Article 9(2)(a) GDPR), which you give when you create your account. The tick names the categories, it is required, and no account is created without it.
Waitlist. If you join our pre-launch waitlist, we process your email address (and your name, if you give it) to send you a short series of emails about how our coaching method works, and to notify you when we open, based on your consent (Article 6(1)(a) GDPR). You can withdraw at any time using the unsubscribe link in any email. We keep waitlist details until launch or until you unsubscribe, after which they are deleted within 30 days.
Starting a subscription. If you begin the payment process and do not finish it, we keep a record of the attempt, including the email address you entered, so that we can recognise a repeated attempt, release you from a pending state if the session expires, and answer you if you contact us about a payment that did not go through. Our legitimate interest in operating a working checkout is the basis for this (Article 6(1)(f) GDPR). These records are deleted after 90 days, and sooner if you ask us to erase your data.
Employer-funded membership. If your employer or another organisation pays for your membership, we process the organisation’s details, its seats, and your seat’s enrolment status to run that arrangement (Article 6(1)(b) GDPR). You join a funded seat only by accepting an invitation while signed in, the acceptance screen tells you exactly what the organisation can and cannot see before you commit, and section 4 describes that boundary. You can leave the organisation at any time in Settings.
Organisation invitations. When an organisation invites you to a funded seat, we hold the email address and role its admin entered so we can deliver the invitation and connect your acceptance to the right seat, based on our legitimate interest in letting organisations offer seats to the people they chose (Article 6(1)(f) GDPR). The invitation email explains this at first contact. An invitation link works for 7 days, an invitation you never accept is deleted 90 days after it expires, and we never use an invitee’s address for marketing.
Partner referrals of organisations. A partner who introduces an organisation to us can register that introduction, and the registration includes the business contact details of a named person at the organisation. Those details reach us from the partner rather than from the named person, and this paragraph is our information notice to that person (Article 14 GDPR). We hold the details so the first partner to register an introduction is the one credited for it, based on our legitimate interest in running the partner programme (Article 6(1)(f) GDPR). We never contact or market to the named person because of a registration, only our admin team and the registering partner can see the details, and we remove them 13 months after the deal settles, keeping a de-identified record of the outcome for commission accounting. If you are such a contact and you object, write to us at the address in section 1 and we will remove your details (Article 21 GDPR).
Sharing your progress with your clinic. If a healthcare organisation refers you to TriageFit, or invites you to a seat it funds, you choose whether the clinicians who hold a seat at that organisation can follow your progress. Nothing is shared unless you say so. We ask you on the checkout page, on the invitation screen or in Settings, with the full list of what they would see in front of you, and we rely on your explicit consent for this sharing (Article 6(1)(a) and Article 9(2)(a) GDPR). Section 4 describes exactly what a clinician can and cannot see. You can turn sharing off at any time in Settings, then Privacy: the organisation stops seeing you straight away, your membership and your coaching carry on unchanged, and we keep a record of each decision so we can show what you chose and when.
Registering a clinic. If you register a clinic with us, we process your details to set the clinic up and to perform the clinic partner terms you accept, and we verify the registration before any patient can be asked to share their progress, which is our legitimate interest in letting only real clinics ask. We keep the decision, and any reason for it, as the record of that check.
Asking about seats for your team. When you fill in the enquiry form on our business page, we use what you give us to reply with a quote and the rollout steps, and for nothing else: the address is never added to a marketing list. Where you are the person who would sign, this is a step taken at your request before a contract (Article 6(1)(b) GDPR); where you are asking on behalf of your employer, we rely on our legitimate interest in answering the enquiry you sent us (Article 6(1)(f) GDPR). If a partner of ours introduced your team, we keep a note of which partner so that they can be paid; that note names the partner, not you. We keep your contact details for 13 months after the enquiry closes, then remove them; the record that a company asked, and what came of it, stays without your details.
Product-usage analytics. We record first-party product-usage events under a pseudonymous identifier stored only in your browser, and only after you accept analytics cookies. With the same consent, Google Analytics 4 receives page views without query strings and with IP anonymisation. These events are retained for 13 months and are used to understand and improve how the Service is used.
Your coach can see your AI-coach conversations. If you are assigned a human coach, they can read your chats with the AI coaching assistant so they have the full context when supporting you and can step in on anything that needs a human. These conversations are visible to your assigned coach and to our safeguarding team; they are never shown to other members.
Your coach can also see a short health-risk summary. Your assigned coach, and our admin team, can open your member record in our coaching console. Alongside your programme, check-ins and health scores, that record shows a short risk summary drawn from what you have told us at intake and from your injury record as you keep it up to date: whether you have told us about a history of disordered eating, whether you are taking a weight-loss (GLP-1) medication, whether you have an injury we should train around, and whether you reported a high stress load. Your coach sees each of these as a simple flag (yes, no, or “we don’t know”), so they can coach you safely and not ask you to repeat yourself. They do not see the words you wrote about any of it. This is part of the personal coaching you signed up for (Article 6(1)(b) GDPR) and rests on the explicit consent to health-data processing you gave when you joined (Article 9(2)(a) GDPR). Your assigned coach can only open the records of members assigned to them, and every time a coach or an administrator opens your record we log who looked and when.
What a funding organisation can see. If an organisation pays for your seat, it can see that you have enrolled, and it can see group numbers that never single anyone out; groups smaller than five are withheld. It can never see your training, your check-ins, your messages or anything about your health. That stays between you and your coach. The one exception is a healthcare organisation whose clinicians you have chosen to share your progress with, and the next paragraph describes it. The organisation funds the seat and nothing more: it cannot require you to use the Service or to enter any data, and you can leave it at any time in Settings.
What a clinician can see, if you choose to share. A healthcare organisation sees nothing about you until you turn sharing on. While it is on, the clinicians who hold a seat at that organisation can see your name, email address, date of birth and gender, the programme week you are on, when you last checked in, how closely you are following your plan as one figure, your health scores and which way they are heading, your blood work from the last year, your medications and injuries, the energy, stress and sleep from your last two weeks of check-ins, and how long it has been since you last used TriageFit. Go 14 days without using it and their patient list marks you as disengaged. They never see your journal, your messages with your coach or your day-to-day training and food logs. Each time a clinician views your summary or opens your report, we record it. Turn sharing off and the organisation stops seeing you straight away, with no notice to it and no change to your membership.
Keeping you safe. To help keep you safe, free text you enter, for example journal entries, symptom or recovery notes, or messages to the coach, is automatically screened for signs of a crisis, such as self-harm, a mental-health emergency, or an urgent medical or eating-disorder concern. Where such signs appear, we may create a limited safety record and share it with our safeguarding and coaching team so we can offer support or point you to help. We do this to protect your vital interests (Article 6(1)(d) and, where applicable, Article 9(2)(c) GDPR). This safety record can include the text that triggered it; we keep it for up to two years, and we retain it, with your account link removed, even if you delete your account.
The table below records the third-party processors used by the production Service and the data each one processes on our behalf. Where the application does not pin a processing region, the table says so.
| Processor | Data processed | Purpose | Region and international transfers |
|---|---|---|---|
| Google Cloud (Vertex AI) | Text sent for a coaching task, together with the relevant account, programme, training, nutrition, wellbeing, injury, medication, blood-work and other health context included in the prompt. Member queries and reference text are also processed to create embeddings. | Generate coaching responses and other model-assisted content, and create embeddings for knowledge-base retrieval. | EU only. Gemini requests use the EU multi-region and embeddings useeurope-west1. The application refuses non-EU Vertex regions. |
| Neon | All records stored by the Service, including account, authentication, contact, consent, health and fitness, coaching, communication, community, billing-reference and audit data. | Host the Service's PostgreSQL database. | The production database endpoint is in eu-central-1(Frankfurt). The application reads the deployed database endpoint and does not pin any separate account or support region. |
| Vercel | Application requests and responses, which can contain any data a member submits to or receives from the Service; session data; and request metadata such as IP address, user agent, URL and timing. | Host and run the application, including server-side routes and scheduled jobs. | Application compute is pinned to fra1 (Frankfurt). The application does not pin a separate region for Vercel account, control-plane or support processing. |
| Stripe | Email address, internal account identifier, selected plan, price and currency, promotion or referral details, billing name and address, subscription and transaction records, and withdrawal acknowledgement. Payment-card details are entered directly with Stripe and do not pass through our servers. We do not send coaching or health records to Stripe. | Process payments, subscriptions, invoices, billing-portal actions, refunds, disputes and affiliate payouts. | No processing region is pinned in the application code. |
| Resend | Recipient email address, sender, subject, HTML and plain-text message body, unsubscribe link and provider message identifier. Message bodies can contain account, billing or coaching information. | Deliver transactional, coaching and consented marketing email. | No processing region is pinned in the application code. |
| Upstash | IP addresses or account identifiers used as rate-limit keys, request counters and reset times, and Stripe webhook event identifiers used to prevent duplicate processing. It does not receive coaching or health-record content. | Enforce distributed rate limits and keep short-lived Stripe webhook idempotency records. | The production database is in eu-central-1 (Frankfurt) with no read regions. The Upstash account controls this setting; the application does not pin it. |
| Sentry | Opaque account identifier, error type and stack trace, request URL and headers, and device and request metadata. Request bodies, exception text and known health or identifying fields are redacted before transmission. Session replay is disabled. | Error monitoring, diagnostics and operational alerting. | Error ingestion uses Sentry's German endpoint in the EU. The deployed DSN selects that destination; the application does not hard-code a separate account or support region. |
| Cloudflare R2 | Uploaded files and object metadata, including progress photos, wearable exports, blood-work PDFs, form-check videos, community images and medical-clearance documents. | Store and retrieve member uploads. | The production upload bucket uses Cloudflare's EU jurisdiction. The deployed S3-compatible endpoint selects the vendor and jurisdiction; the application does not pin them. |
| Google (Google Analytics 4 and Search Console) | Google Analytics receives consent-gated page views without query strings, together with configured analytics events and an anonymised IP address. Search Console supplies site-level search queries, pages, clicks, impressions, click-through rate and position. | Measure consented website usage and provide search-performance reporting to the administrator. | No processing region is pinned in the application code. |
Under GDPR and applicable data protection laws, you have the right to:
To exercise any of these rights, contact us at info@triagemethod.com or use the data management features in your Settings page. We will respond within 30 days.
Automated decision-making. We use automated processing to generate your health scores, coaching recommendations, adaptive training and nutrition plans, and the short health-risk summary your coach sees. This supports your coaching but does not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR, and the Service remains under human oversight: a person, not a machine, decides what to do about anything flagged. You can contact us to query or ask us to review any recommendation.
We use the following categories of cookies and local storage:
You can manage or withdraw your cookie consent at any time using the "Manage cookie preferences" option on our Cookie Policy page, or (if signed in) in Settings > Privacy & Data. See that page for the full list of cookies.
Section 5 states the production region we can verify for each processor. Where the repository does not establish whether data can be accessed or processed outside the EEA, or which transfer safeguard applies, the table marks that point for confirmation rather than making an unverified claim.
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, access controls, regular security reviews, and incident response procedures.
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority. As an Irish company, our lead supervisory authority is the Data Protection Commission (DPC) at dataprotection.ie. If you are in the UK, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.
For privacy-related enquiries, contact our Data Protection Officer, Patrick Farrell, at info@triagemethod.com.