Privacy policy

Last updated: 26 August 2026

TriageFit ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the TriageFit Health Coaching platform ("Service").

1. Data controller

TriageMethod Ltd, a company registered in Ireland and trading as TriageFit, is the data controller responsible for your personal data. For our company registration details, any privacy matter, or to exercise your rights, contact us at info@triagemethod.com.

Our Data Protection Officer is Patrick Farrell.

2. What data we collect

Account data

  • Name, email address, date of birth, gender
  • Password (hashed and salted, we never store plain text)
  • Profile photo (optional)

Health & fitness data

  • Training logs, exercise history, and programme data
  • Body composition measurements (weight, body fat, etc.)
  • Blood work results and medical markers
  • Medications and supplements you tell us about, including weight-loss (GLP-1) medication
  • Injuries, pain and physical restrictions we need to train around
  • What you tell us at intake about your health history, including any history of disordered eating or of mental-health conditions
  • Sleep data, stress levels, and recovery metrics
  • Nutrition logs and dietary preferences
  • Health scores and dimension assessments
  • Habit tracking data
  • Wearable data you upload

Usage data

  • Device information, browser type, and operating system
  • IP address and approximate location
  • Pages visited, features used, and interaction patterns
  • Session duration and frequency

Communication data

  • Messages sent to AI coaching assistant
  • Support tickets and correspondence
  • Community posts and comments

3. Lawful basis for processing

We process your personal data on the following legal bases:

  • Contract: Processing necessary to provide the Service you subscribed to (Article 6(1)(b) GDPR)
  • Consent: Where you have given explicit consent, such as for marketing communications or optional data sharing (Article 6(1)(a) GDPR)
  • Legitimate Interest: For service improvement, security, and fraud prevention (Article 6(1)(f) GDPR)
  • Legal Obligation: Where required by law, such as tax or regulatory compliance (Article 6(1)(c) GDPR)

Health and fitness data is classified as special category data under GDPR. We process this data based on your explicit consent (Article 9(2)(a) GDPR), which you give when you create your account. The tick names the categories, it is required, and no account is created without it.

Waitlist. If you join our pre-launch waitlist, we process your email address (and your name, if you give it) to send you a short series of emails about how our coaching method works, and to notify you when we open, based on your consent (Article 6(1)(a) GDPR). You can withdraw at any time using the unsubscribe link in any email. We keep waitlist details until launch or until you unsubscribe, after which they are deleted within 30 days.

Starting a subscription. If you begin the payment process and do not finish it, we keep a record of the attempt, including the email address you entered, so that we can recognise a repeated attempt, release you from a pending state if the session expires, and answer you if you contact us about a payment that did not go through. Our legitimate interest in operating a working checkout is the basis for this (Article 6(1)(f) GDPR). These records are deleted after 90 days, and sooner if you ask us to erase your data.

4. How we use your data

  • To provide personalised coaching, training programmes, and health insights
  • To calculate and display health scores and progress tracking
  • To generate AI-powered recommendations and coaching responses
  • To process payments and manage subscriptions
  • To send transactional emails (check-in reminders, reviews, etc.)
  • To understand and improve the Service through consent-gated, pseudonymised product-usage analytics, including Google Analytics 4
  • To detect and prevent fraud or abuse

Product-usage analytics. We record first-party product-usage events under a pseudonymous identifier stored only in your browser, and only after you accept analytics cookies. With the same consent, Google Analytics 4 receives page views without query strings and with IP anonymisation. These events are retained for 13 months and are used to understand and improve how the Service is used.

Your coach can see your AI-coach conversations. If you are assigned a human coach, they can read your chats with the AI coaching assistant so they have the full context when supporting you and can step in on anything that needs a human. These conversations are visible to your assigned coach and to our safeguarding team; they are never shown to other members.

Your coach can also see a short health-risk summary. Your assigned coach, and our admin team, can open your member record in our coaching console. Alongside your programme, check-ins and health scores, that record shows a short risk summary drawn from what you have told us at intake and from your injury record as you keep it up to date: whether you have told us about a history of disordered eating, whether you are taking a weight-loss (GLP-1) medication, whether you have an injury we should train around, and whether you reported a high stress load. Your coach sees each of these as a simple flag (yes, no, or “we don’t know”), so they can coach you safely and not ask you to repeat yourself. They do not see the words you wrote about any of it. This is part of the personal coaching you signed up for (Article 6(1)(b) GDPR) and rests on the explicit consent to health-data processing you gave when you joined (Article 9(2)(a) GDPR). Your assigned coach can only open the records of members assigned to them, and every time a coach or an administrator opens your record we log who looked and when.

Keeping you safe. To help keep you safe, free text you enter, for example journal entries, symptom or recovery notes, or messages to the coach, is automatically screened for signs of a crisis, such as self-harm, a mental-health emergency, or an urgent medical or eating-disorder concern. Where such signs appear, we may create a limited safety record and share it with our safeguarding and coaching team so we can offer support or point you to help. We do this to protect your vital interests (Article 6(1)(d) and, where applicable, Article 9(2)(c) GDPR). This safety record can include the text that triggered it; we keep it for up to two years, and we retain it, with your account link removed, even if you delete your account.

5. Sub-processors

The table below records the third-party processors used by the production Service and the data each one processes on our behalf. Where the application does not pin a processing region, the table says so.

ProcessorData processedPurposeRegion and international transfers
Google Cloud (Vertex AI)Text sent for a coaching task, together with the relevant account, programme, training, nutrition, wellbeing, injury, medication, blood-work and other health context included in the prompt. Member queries and reference text are also processed to create embeddings.Generate coaching responses and other model-assisted content, and create embeddings for knowledge-base retrieval.EU only. Gemini requests use the EU multi-region and embeddings useeurope-west1. The application refuses non-EU Vertex regions.
NeonAll records stored by the Service, including account, authentication, contact, consent, health and fitness, coaching, communication, community, billing-reference and audit data.Host the Service's PostgreSQL database.The production database endpoint is in eu-central-1(Frankfurt). The application reads the deployed database endpoint and does not pin any separate account or support region.
VercelApplication requests and responses, which can contain any data a member submits to or receives from the Service; session data; and request metadata such as IP address, user agent, URL and timing.Host and run the application, including server-side routes and scheduled jobs.Application compute is pinned to fra1 (Frankfurt). The application does not pin a separate region for Vercel account, control-plane or support processing.
StripeEmail address, internal account identifier, selected plan, price and currency, promotion or referral details, billing name and address, subscription and transaction records, and withdrawal acknowledgement. Payment-card details are entered directly with Stripe and do not pass through our servers. We do not send coaching or health records to Stripe.Process payments, subscriptions, invoices, billing-portal actions, refunds, disputes and affiliate payouts.No processing region is pinned in the application code.
ResendRecipient email address, sender, subject, HTML and plain-text message body, unsubscribe link and provider message identifier. Message bodies can contain account, billing or coaching information.Deliver transactional, coaching and consented marketing email.No processing region is pinned in the application code.
UpstashIP addresses or account identifiers used as rate-limit keys, request counters and reset times, and Stripe webhook event identifiers used to prevent duplicate processing. It does not receive coaching or health-record content.Enforce distributed rate limits and keep short-lived Stripe webhook idempotency records.The production database is in eu-central-1 (Frankfurt) with no read regions. The Upstash account controls this setting; the application does not pin it.
SentryOpaque account identifier, error type and stack trace, request URL and headers, and device and request metadata. Request bodies, exception text and known health or identifying fields are redacted before transmission. Session replay is disabled.Error monitoring, diagnostics and operational alerting.Error ingestion uses Sentry's German endpoint in the EU. The deployed DSN selects that destination; the application does not hard-code a separate account or support region.
Cloudflare R2Uploaded files and object metadata, including progress photos, wearable exports, blood-work PDFs, form-check videos, community images and medical-clearance documents.Store and retrieve member uploads.The production upload bucket uses Cloudflare's EU jurisdiction. The deployed S3-compatible endpoint selects the vendor and jurisdiction; the application does not pin them.
Google (Google Analytics 4 and Search Console)Google Analytics receives consent-gated page views without query strings, together with configured analytics events and an anonymised IP address. Search Console supplies site-level search queries, pages, clicks, impressions, click-through rate and position.Measure consented website usage and provide search-performance reporting to the administrator.No processing region is pinned in the application code.

6. Data retention

  • Active accounts: Data is retained for the duration of your subscription plus 30 days after cancellation to allow for reactivation.
  • Deleted accounts: When you ask us to delete your account, your personal data is erased within 30 days. A few limited records are kept afterwards, with your account link removed where possible, where the law requires or allows it: a record of the consents you gave and withdrew (kept for up to 6 years, as proof of the lawful basis for processing your data), and any safety record created by the screening described in section 4 above (kept for up to 2 years). Anonymised aggregated data may also be retained for analytics.
  • Billing records: Retained for 7 years as required by tax regulations.
  • AI interaction records: Up to 2 years.
  • In-app notifications: The notifications in your notification centre, check-in reminders, plan updates and messages from your coach, are kept for 24 months and then automatically deleted, whether or not you have read them.
  • Consent records: Up to 6 years, to demonstrate the lawful basis for processing.
  • Marketing suppression: If you unsubscribe, we keep only your email address on a suppression list so we do not contact you again.
  • Support correspondence: Retained for 2 years after resolution.
  • Server logs: Automatically purged after 90 days.

7. Your rights

Under GDPR and applicable data protection laws, you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format (JSON export available in Settings)
  • Restriction: Request that we limit processing of your data
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at info@triagemethod.com or use the data management features in your Settings page. We will respond within 30 days.

Automated decision-making. We use automated processing to generate your health scores, coaching recommendations, adaptive training and nutrition plans, and the short health-risk summary your coach sees. This supports your coaching but does not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR, and the Service remains under human oversight: a person, not a machine, decides what to do about anything flagged. You can contact us to query or ask us to review any recommendation.

8. Cookie policy

We use the following categories of cookies and local storage:

  • Essential: Required for the Service to function (authentication, session management, CSRF protection), the record of the cookie choice you made, and the display preferences you set yourself (light or dark appearance, collapsed navigation). Cannot be disabled.
  • Functional: Save your progress through the longer forms and remember who is signed in on this device, so you can pick up where you left off. Can be managed in cookie settings.
  • Analytics: Help us understand how the Service is used through a first-party visitor and session identifier and Google Analytics 4. Opt-in only.
  • Marketing: Remember which partner or referral link brought you to us, so that a referral or affiliate credit is applied correctly. We set these on our own domain only: we run no advertising networks, no ad pixels and no cross-site tracking. Opt-in only.

You can manage or withdraw your cookie consent at any time using the "Manage cookie preferences" option on our Cookie Policy page, or (if signed in) in Settings > Privacy & Data. See that page for the full list of cookies.

9. International transfers

Section 5 states the production region we can verify for each processor. Where the repository does not establish whether data can be accessed or processed outside the EEA, or which transfer safeguard applies, the table marks that point for confirmation rather than making an unverified claim.

10. Data security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.3) and at rest, access controls, regular security reviews, and incident response procedures.

11. Children's privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect.

13. Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority. As an Irish company, our lead supervisory authority is the Data Protection Commission (DPC) at dataprotection.ie. If you are in the UK, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

14. Contact

For privacy-related enquiries, contact our Data Protection Officer, Patrick Farrell, at info@triagemethod.com.