Your data
Privacy policy
Triglog uses read-only Strava access to turn your own activity history into a private mountain logbook. Your data is shown to you and to nobody else. Triglog never posts to Strava.
Last updated: 14 September 2026
Who we are
Triglog is the data controller for the personal data described here. Contact us at support@triglog.com or via the support page.
What we collect, and why
Most account and activity data comes from Strava, with your permission. We request a single scope, activity:read_all, and no other. Your summit corrections and pack details are supplied directly by you.
- Your Strava athlete ID and name — to identify your account and greet you. Supplied by Strava when you connect.
- Your activities — name, description, sport type, dates, distance, duration, elevation, speed, heart-rate summary, and the activity’s own privacy and visibility flags. Used to build your logbook and statistics.
- GPS, altitude, distance, time and heart-rate streams — the detailed traces of each activity. Used to detect which summits you passed over and to calculate climb-by-climb performance.
- Derived data we generate — detected summit ascents, your corrections to them, fitness and training metrics, and import progress records.
- OAuth tokens — encrypted at rest with AES-256-GCM so Triglog can refresh your data without asking you to log in again.
We do not collect your email address, and Strava does not give it to us. We do not use analytics or advertising cookies. The only cookies set are a signed session cookie that keeps you logged in and a short-lived cookie protecting the login flow against cross-site request forgery.
Legal basis
We process this data to perform the service you asked for (UK GDPR Article 6(1)(b), contract). Health-adjacent data such as heart rate is processed on the basis of your explicit consent, given when you grant activity access on Strava’s permission screen and withdrawable at any time by disconnecting.
Who can see your data
Only you. Triglog has no public profiles, no leaderboards, no following, public exports, and no cross-user aggregation. Strava data from one athlete is never shown to another.
Where it is stored, and who processes it
- Vercel — application hosting (London region)
- Supabase — the PostgreSQL database holding everything above
- MapTiler and OpenFreeMap — map tiles. Your browser requests tiles directly; your activity data is not sent to them.
Strava may monitor and collect data about Triglog’s API use and may use that information for internal or external business purposes, including service improvements, developer support and compliance. Strava handles that information under Strava’s privacy policy. That is outside our control.
How long we keep it
Your data is retained while your account exists and your Strava connection is active, because the product is a permanent logbook of your climbing history. It is deleted immediately when you disconnect or delete your account — see below.
Triglog subscribes to Strava’s change notifications, so your copy here follows what you do there. If you delete an activity on Strava, or change it to “Only You”, it is removed from Triglog too; renames and sport-type changes are applied. If you revoke Triglog from Strava’s own settings, the deauthorisation notification causes everything we hold for you to be deleted automatically.
If Triglog is discontinued, or if our access to the Strava API ends, all Strava data will be deleted and users notified.
Deleting your data
You are in control, and neither option requires contacting us:
- Disconnect Strava (Settings) — revokes our access and permanently deletes every activity, stream, detected ascent and token we hold for you, together with the account identity supplied by Strava.
- Delete your account (Settings) — performs the same complete erasure, with an explicit typed confirmation.
Both happen immediately, not on a schedule, and both finish by showing you written confirmation of exactly what was removed. Neither touches anything on Strava: your activities stay there untouched.
You can also revoke Triglog from My Apps in your Strava settings. If you do, Strava notifies Triglog and your imported and derived data is deleted automatically.
Your rights
You have the right to access, correct, export, restrict and erase your personal data, and to withdraw consent. Your logbook already shows everything we hold in readable form, and the deletion options above exercise erasure directly. For anything else — including a machine-readable export — contact us via the support page. You can also obtain a free export of your original Strava data from Strava’s bulk export tool. You may also complain to the UK Information Commissioner’s Office.
Security
Strava tokens are encrypted at rest. Session cookies are signed, HTTP-only and, in production, secure and same-site. All traffic is served over HTTPS. No third party is given access to your activity data.
Changes
If this policy changes materially we will update the date above and note the change on the support page.