PRIVACY POLICY
Last Calibrated: August 2026 · Sovereign Athlete Telemetry & Location Privacy
1. The Offline-First Directive & Local Storage (Rule 7 & Rule 8)
Trevak operates under a strict Offline-First Architecture. Mission-critical telemetry (GPS breadcrumbs, heart rate, step cadence, and safety pings) is written in parallel to secure local device storage (using Capacitor Preferences and localforage) before attempting any server upload.
If network connectivity drops during a run, your data safely buffers in an offline queue on your hardware and auto-flushes via the SyncEngine upon reconnect.
2. Athlete Location Privacy & Safety Protocol (Rule 22)
Your physical location and identity are protected under strict safety protocols:
- Mandatory Privacy Zones: All public map renders, exported GPX route previews, and challenge telemetry automatically obscure or strip coordinates within a 400-meter radius of an athlete's starting location or home base.
- Zero Precise Home Storage: Raw residential street addresses are never stored in public database tables or unencrypted server logs. Physical shipping addresses collected for gear order fulfillment are stored in isolated, RLS-protected tables accessible solely by the authenticated athlete and fulfillment services. The Vanguard Badge is a digital in-app reward and does not require a shipping address.
- Anonymized Handles: Public squad feeds and challenge leaderboards display anonymized athlete handles without exposing timestamped GPS breadcrumbs that could enable physical tracking.
3. Strict Row-Level Security (RLS) Isolation (Rule 9)
Trevak treats all client-side data queries as untrusted. All database fetches rely strictly on the authenticated user's JWT token and Row-Level Security (RLS) policies.
Other athletes cannot query or access your telemetry, run logs, or gear locker data without your explicit, cryptographically verified Squad Link authorization. We do NOT sell your personal, identifiable telemetry, location data, or biometrics to third-party data brokers, insurers, or advertising networks.
Anonymized Aggregate Commerce Intelligence: We may use anonymized, aggregated trends derived from platform-wide activity (never individual routes, biometrics, identities, or residential locations) to power Trevak commerce-intelligence products and improve gear-lifecycle modeling. Aggregate reports contain no information that can identify you or reconstruct your personal training history.
3A. Training Profile Data
During onboarding and in your HQ profile settings, you may provide optional training-profile information used solely to calibrate projections and improve product analytics:
- Primary training goal (e.g. 5K / 10K, Half Marathon, Marathon, Ultramarathon, Base Building, Active Recovery)
- Weekly mileage band (self-reported volume range)
- Experience level (Beginner, Intermediate, Advanced, or Competitive — optional)
These fields are ordinary personal data, not biometric or health measurements. You can edit or clear them anytime in HQ → Settings → Profile. They are deleted with your account under the Right to Erasure.
4. GDPR & CCPA/CPRA Rights & Explicit PII Consent (Item L-9 & L-12)
Under GDPR (EU) and CCPA/CPRA (California), you possess full sovereign rights over your personal data:
- Right to Opt-Out: Customize cookie and telemetry preferences anytime via our Cookie Consent Banner or settings.
- Right to Data Portability: Export your full GPX traces and run logs in standard formats.
- Right to Erasure (Forget Me): Request complete deletion of your account, biometric profiles, and physical address records. Data is purged within 30 days.
5. State Biometrics Privacy (BIPA/CUBI) & COPPA
Biomechanical stride metrics and heart rate telemetry are collected solely for performance modeling and gear wear estimation. We comply with Illinois BIPA, Texas CUBI, and Washington My Health My Data acts. We do not collect biometric data from children under 13.