Privacy Policy
This policy describes how Traqeo processes your personal data when you use our service, and what rights you have under the General Data Protection Regulation (GDPR) and Swedish data protection law. We have written it to be easy to understand — get in touch if anything is unclear.
This is an English translation of our Swedish privacy policy. If the two versions differ, the Swedish version prevails.
1. Data controller
The controller of the processing is TRNX Venture AB, corporate identity number 559571-6019, Barfotsgatan 1, 442 39 Kungälv, Sweden (“Traqeo”, “we”, “us”). This means that we decide why and how your personal data is processed and are responsible for ensuring that it is done in accordance with the law.
Contact for data protection matters: hej@traqeo.se. We have not appointed a data protection officer, as we are not required to, but the address above is your direct channel for all questions and requests concerning your data.
2. What personal data we process
We collect as little as possible and only what is needed to run and personalise the training service. Depending on how you use the app, the following categories may be processed:
- Account data: email address, an optional name/display name, and a securely hashed version of your password (never in plain text). If you sign in through an external service (e.g. Google or Apple), we process the identifier and account details that service provides.
- Profile and onboarding data: target race and race date, training background, available equipment, number of sessions per week, and the physiological measurements you enter yourself — e.g. age, sex, height, weight, maximum heart rate, threshold heart rate and estimated VO₂max.
- Training and log data: completed and skipped sessions, rating of perceived exertion (RPE), your own notes, and generated training plans and block evaluations (perceived feeling, energy, motivation, sleep).
- Health and wellbeing data (see section 3): heart rate, heart rate variability (HRV), resting heart rate, sleep, and periods of illness and injury with severity, symptoms and notes. This is sensitive data and is processed only with your explicit consent.
- Data from connected services: if you connect Strava, we retrieve your training activities — sport type, time, distance, elevation gain, heart rate and power data, and heart rate curves — to match them against your plan and fine-tune your zones. If you instead connect intervals.icu, we retrieve the same data, plus recovery data (resting heart rate, HRV and sleep) from the watch you have linked there. If you connect Whoop or Oura, we retrieve only recovery data — resting heart rate, HRV and sleep — since those services do not carry training sessions. In these cases we also store encrypted access tokens for the connected service.
- Data from Apple Health:if you connect Apple Health in the iPhone app, we read workouts with heart rate curves as well as resting heart rate, heart rate variability (HRV) and sleep from the Health store on your own phone. This source differs from the others: the data goes from your device directly to us, no third party stands in between, and we store no access tokens for it. We only read — the app never writes anything to Health. You control access yourself in iOS under Settings → Privacy & Security → Health, and you can disconnect from within the app.
- Payment data: when you make a purchase, we process purchase and subscription status and identifiers from our payment provider — Stripe for purchases on the web, or the Apple App Store or Google Play for purchases in the app. We never store the card number itself — it is handled directly by the payment provider.
- Data in “Traqeo Group Training”: if you create or join a training group, we process group membership, proposals and responses to shared sessions. The group’s members can also see how a confirmed shared session fits into your plan and whether you have logged it as completed. The rest of your plan is not shown to the group; it is used only to work out which days suit everyone. If you invite someone, we process the email address or phone number you enter for the invitation.
- Technical data and communication: settings and notification preferences, coach letters we send you, and technical operations and security logs.
3. Sensitive data (health data)
Several of the data points above — heart rate, HRV, sleep, resting heart rate, and periods of illness and injury — are data concerning health and constitute a special category of personal data under Article 9 of the GDPR. We process them only in order to deliver and personalise your training plan, and the legal basis is your explicit consent (Article 9(2)(a)). You choose whether, and which, health data you provide, and you can withdraw your consent at any time by no longer providing such data, disconnecting connected services or deleting your account. Withdrawing consent does not affect the lawfulness of processing that has already taken place.
4. Purposes and legal basis
- Providing the service — creating your account, generating and personalising training plans, showing progress and forecasts. Legal basis: performance of the contract with you (Art. 6(1)(b)), and for health data explicit consent (Art. 9(2)(a)).
- Handling payment and subscriptions. Legal basis: performance of the contract (Art. 6(1)(b)) and legal obligation for bookkeeping (Art. 6(1)(c)).
- Improving and securing the service — troubleshooting, abuse prevention, and evaluating and improving our training engine. Legal basis: our legitimate interest (Art. 6(1)(f)) in running a secure and functioning service. Our quality evaluation of the engine runs against synthetic test profiles, not against your personal data.
- Communication — answering questions and sending service-related messages and coach letters. Legal basis: performance of the contract and legitimate interest respectively (Art. 6(1)(b)/(f)).
5. Automated processing
Your training plans are produced by our rule-based training engine, based on the information you provide and the training you complete. The engine suggests content; you decide yourself whether and how to follow the plan. The processing is therefore a decision-support tool and not a decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Article 22 of the GDPR. If you would like to speak with a human about how your plan is produced, you can always get in touch with us.
6. Recipients and processors
We never sell your personal data and do not share it for marketing. To run the service, we use a small number of carefully selected service providers that process data on our behalf (processors), each bound by a data processing agreement:
- Neon — database hosting (storage of all account data). Region: EU.
- Vercel — application and web hosting, and storage of any group pictures you upload.
- Anthropic — writes the explanatory texts for the sessions in an already finished plan; the plan itself is built by our engine. Under the provider’s terms, data sent through the API is not used to train their models.
- Stripe — payment for purchases on the web. For purchases in the app, payment is handled by Apple or Google respectively.
- Resend — sending transactional emails (sign-in and verification codes, notifications).
- Inngest — running background jobs (e.g. plan generation).
- Strava — retrieving your activities after you have explicitly connected it.
- intervals.icu — retrieving activities and recovery data (resting heart rate, HRV and sleep) from the watch you have linked to that service, after you have explicitly connected it. The connection is not yet available; see section 7.
- Whoop and Oura — retrieving recovery data (resting heart rate, HRV and sleep) from the strap or ring you wear, after you have explicitly connected it.
Apple Health is not a processor. That connection works the other way round from the others: the Health store sits on your own iPhone, the app reads from it locally and sends the data directly to us. Apple therefore does not process any data on our behalf in that chain and does not receive what we retrieve. There is thus no data processing agreement to sign for it, and no access tokens to store — the data ends up with the same providers as all other account data, i.e. those listed above.
We may also disclose data if we are required to do so by law or by a decision of a public authority. Should the business be transferred (e.g. in a business transfer), data may be transferred to the acquirer, who will then be bound by this policy.
7. Transfers to third countries
Some of the providers above (including Anthropic, Stripe, Resend, Vercel and Strava) may process data in countries outside the EU/EEA, mainly the United States. When this happens, we ensure a level of protection equivalent to the GDPR through appropriate safeguards — primarily the European Commission’s standard contractual clauses and, where applicable, the provider’s certification under the EU–US Data Privacy Framework. You can contact us for more information about these safeguards.
The connection to intervals.icu will be activated only once a data processing agreement and a documented transfer basis are in place for that service. Until then, no data is transferred there. Since the connection would involve health data (resting heart rate, HRV and sleep), we carry out that assessment before the feature is made available, not afterwards.
8. How long we keep your data
We keep your data for as long as you have an active account, in order to deliver the service and your training history. In addition:
- When you delete your account, your personal data is permanently removed from our production and backup environments within 30 days.
- Accounting records related to payments are kept for as long as the Swedish Bookkeeping Act requires (normally seven years), even after the account has been deleted.
- Limited security and operations logs may be kept for a shorter period to prevent abuse and errors.
9. Your rights
Under the GDPR, you have the right to:
- access the data we process about you,
- have inaccurate data rectified,
- have data erased (“the right to be forgotten”),
- request restriction of or object to certain processing,
- receive your data in a machine-readable format and move it (data portability), and
- withdraw any consent you have given, at any time.
You can export your data and delete your account directly in the app (see traqeo.se/radera for the steps, in Swedish), or contact us at hej@traqeo.se. We respond to your request without undue delay and within one month at the latest. If you believe that we are processing your data incorrectly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.
10. Security
We take technical and organisational measures to protect your data. Passwords are stored only as secure hashes, access tokens for connected services are encrypted at rest (AES-256-GCM), and all traffic runs over encrypted connections. Access to production data is restricted. No system is entirely free of risk, but we work continuously to maintain a high level of protection.
11. Cookies and local storage
We use only necessary, functional cookies and equivalent local storage in your browser — to keep you signed in and remember your settings. We use no third-party tracking cookies, no ad networks and no behavioural profiling for marketing.
12. Age limit
The service is aimed at adults and is not intended for children under 18. We do not knowingly collect data about children. If you are a parent or guardian and believe that a child has provided data to us, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the service develops or legal requirements change. In the event of material changes, we will inform you in the app or by email. The “Last updated” date at the top shows when the current version took effect.
14. Contact
For questions about how we process your personal data, or to exercise your rights: hej@traqeo.se.