TrekReady LLC operates TrekReady, a mountaineering training and objective-planning service. This policy explains what we collect, why we use it, where it goes, and your controls.
Effective 2026-08-26 · version 2026-08-26.v2
Fitness, recovery, and training information may be consumer health data. Read our separate Consumer Health Data Privacy Policy.
Use of the service is separately governed by the Terms of Use. Accepting those Terms is not health-data consent, and accepting this Privacy Policy does not accept the Terms for you.
Information comes from you, Garmin for the operator account, intervals.icu or Strava when you connect one, and calculations TrekReady makes from those records. We use it to authenticate you, import and display training, measure evidence and readiness, build and adapt plans, support objective teams, respond through the Coach, recommend relevant gear or guides, deliver opted-in notifications, secure and troubleshoot the service, review and respond to invitation interest, honor privacy requests, and meet legal obligations. TrekReady does not infer your home from activity GPS.
Authorized TrekReady operators and infrastructure providers can access information when needed to run, secure, support, or delete the service, even when it is not exposed in an ordinary app screen.
When you use the Coach, TrekReady sends Anthropic your prompt and the relevant account, objective, training, and recovery context needed for that response. Anthropic states that standard commercial API inputs and outputs are ordinarily retained for up to 30 days, subject to its terms, safety enforcement, legal obligations, and any different agreement. Coach drafts require confirmation where the interface presents a draft; an explicit command to a supported write tool can update TrekReady data.
Supabase provides authentication, database, and private file storage; Resend receives your login email address, authentication-message content (including the one-time sign-in link), and delivery metadata to deliver authentication email. TrekReady does not send training or health data to Resend through that integration. Cloudflare provides the Turnstile anti-abuse challenge on login and invitation requests and receives ordinary request, browser, and challenge-interaction information; the invitation form asks you not to submit health information. Vercel hosts and processes application requests; enabled browser push services deliver notifications. Open-Meteo receives a weather-location request when a weather card is loaded. Connected fitness providers receive the API/authentication requests needed to import your data. Providers may also process limited information for security, abuse prevention, legal compliance, and service operation under their terms.
TrekReady does not sell health data or share it with advertising networks. Current gear and guide recommendations are reviewed editorial inventory. Following a card creates a click record with the item, surface, time, and relationship type—but no member id, health value, or objective date. The destination still receives ordinary web-request information such as your IP address and browser. Any future paid or affiliate relationship will be disclosed without changing eligibility or editorial order.
Session cookies keep you signed in. Local browser storage remembers interface conveniences and installation state. A service worker caches only the public app shell and static assets—not member pages, API responses, or private data. Reusable connected-service credentials are encrypted before database storage, private application data is available only through session-checked server routes, and photos use short-lived signed URLs. Turnstile may use browser storage or similar signals to distinguish people from automated abuse. Encrypted operational backups include database records and private photo objects. No system can promise absolute security, but TrekReady also uses rate limits, restrictive browser headers, and deny-by-default database privileges to reduce unauthorized access and abuse.
Account data is retained while the account is active and as needed for the purposes above. A completed account deletion removes active database rows, stored photos, connected credentials, conversations, and the Auth identity. A durable deletion record tracks cross-system completion and retries an Auth-provider failure. Limited operational records may remain where required for security, legal compliance, or to document the request. Invitation-interest records are retained while access is being evaluated and for reasonable security/duplicate-request handling, and may be deleted on request. Provider backups age out on provider schedules; deleted data is not returned to normal use and deletion is reapplied if a backup must be restored. Previously issued photo links may remain usable until their roughly one-hour expiration.
A material change gets a new policy version and requires agreement again before optional processing resumes. Questions and privacy requests: privacy@trekready.ai.