treni.no · privacy
Privacy policy
Last updated 11 September 2026. Replaces the policy of 4 September 2026. New: Intervals.icu and file upload as data sources, and the waiting list is gone, everyone gets their page right away. In case of doubt, the Norwegian version applies.
Who is responsible
PAULSEN UTVIKLING (Norwegian sole proprietorship, org. no. 938 158 614), represented by Odd Levi Paulsen, is the data controller for the Treni service. Contact: hei@treni.no.
What we process
- The interest form on the website: name, email, mobile number and Telegram contact if you give them, language, how you heard about us, and what you write about your running. The form notifies the coach and is stored in our sign-up list at Hostinger (see "Where data is stored"). Only the coaches Eirik Haugsnes and Odd Levi Paulsen can see it. Used to create your page and contact you. If you do not become a runner with us, the entry is anonymised after 12 months. If you ask, it is deleted at once.
- The questions about your training (form 2): goals, age, maximum heart rate if you know it, best times, kilometres per week, terrain, other sports, strength training and races you aim for. Used to build your plan.
- What you tell the coach in Telegram or on my page: goals, planned races, age, threshold values, and any health conditions or injuries you choose to share so the advice can take them into account.
- Training data from your watch, via Intervals.icu (Garmin, Polar, Suunto, Coros, Wahoo) or Strava, after your explicit consent in their login: activities, distance, time, heart rate, laps, elevation, gear (shoes) and activity descriptions. You can also upload training files (FIT, GPX, TCX) yourself on my page; they are treated the same way.
- Messages in your Telegram group that concern your training (for example "holiday next week", "felt my foot"). The whole conversation in the group is stored, because the coach and the engine use it to understand your week.
- What you do on "my page" (min.treni.no): events you report (injury, illness, holiday), replies to your plan, feedback and pictures you upload yourself, for example of shoes.
- Technical data when you use the websites: IP address, browser and time, in ordinary server logs at Hostinger and in Cloudflare's network in front of the sites. Used only for operation and security, not for tracking or marketing. We use no third-party analytics.
Health data
Heart rate, injuries, illness and anything else you tell us about your body are health data under GDPR Article 9. We process them only because you give a separate, explicit consent, at onboarding or on my page when we ask for it. You decide what to share. Our advice is training guidance, not healthcare. In case of injury or illness we always refer you to a professional.
What the data is used for
One purpose: to give you personal training guidance from your named coach, with injury prevention first. The analysis (load, volume development, intensity distribution) is done by a deterministic rule engine. No data is sold, shared with third parties for marketing, or used for anything other than your guidance. No other runner sees your data. The data is also used to answer you when you write to us, and to run and secure the service.
AI transparency
The analysis itself is rule-based, not AI. We use a language model (Anthropic's API) to phrase the engine's findings as readable text, to draft training plans that the coach approves, and to interpret training messages you send in the chat or on my page. What is sent to Anthropic is your training numbers, your goals, your health note (what you have shared about injuries and health), your plan and training-related messages. Your first name may appear in the text. We do not send your email, phone number or Strava access. The data is processed transiently, is not stored by the provider and is not used to train AI models (contractually fixed in the provider's commercial terms). You consent to this before starting, and you can withdraw the consent at any time. Processing then stops.
Where data is stored
- Hostinger (EU): the websites, the sign-up list, my page, the chat log, training plans, the coach dashboard and a copy of your training data live in a database at Hostinger. The coach dashboard is password protected.
- The operator's computer in Norway: the main database with all training history, analyses and messages. The bot and the engine run from here.
- Apple iCloud: daily backup of the main database, consent records and runner documents. The copies live in Apple's cloud under Apple's terms.
- GitHub: program code only, in private repositories. Personal data must not be there. We check this automatically.
Processors and other recipients
These companies process data on our behalf (processors) or are independently responsible for their own service. We sign data-processing agreements where the law requires it.
| Who | What | Where |
|---|---|---|
| Hostinger | Websites, database, mail server, coach dashboard | EU/EEA |
| Apple (iCloud) | Backup of the database and documents | EU and USA. Apple uses standard contractual clauses (SCC). |
| Cloudflare | Network and protection in front of the websites. Sees the traffic, including your IP address. | Global network, EU-U.S. Data Privacy Framework. |
| Telegram | The messaging platform for your group and the bot. Telegram is responsible for its own service and terms. Everything you write there is also held by Telegram. | Servers outside the EU (Dubai and others). |
| Anthropic | AI phrasing of advice text and plan drafts. Transient processing, no storage, no model training. | USA. EU-U.S. Data Privacy Framework / SCC. |
| Google (Gmail) | Sends email from hei@treni.no. If you reply by email, the reply is held by Google. | EU/USA, Data Privacy Framework. |
| Intervals.icu | Passes the training data from your watch to us (Garmin, Polar, Suunto, Coros, Wahoo), after your consent. Intervals.icu is responsible for its own service and storage, see the intervals.icu privacy policy. | Outside the EEA |
| Strava | The source of the training data for runners who connect via Strava. Strava is responsible for its own service. We follow Strava's API terms. | USA |
| Meta (Instagram, Facebook) | We publish our own posts about Treni. Runner data is never sent to Meta, and we use no Meta pixels on the sites. | Not relevant to your data. |
Your watch, Strava and disconnecting
You can disconnect Treni from Intervals.icu at any time under Settings and Apps at intervals.icu, or from Strava at strava.com/settings/apps. Fetching then stops immediately and the access token is deleted. Training data we have fetched from Strava is deleted within 48 hours, as Strava's terms require. Training data fetched via Intervals.icu and files you have uploaded are deleted when you ask, within 30 days at the latest. What you have written to us yourself, and your plans, are kept under the rules below unless you ask for deletion.
How long we keep the data
- Active runner: as long as you use the service.
- After you leave: we keep the data for 24 months so you can come back and continue where you left off. After that it is anonymised: name, email, phone number, Telegram ID and free text are removed. Anonymous training numbers may be kept to improve the methodology.
- Signed up without becoming a runner: anonymised after 12 months. Name, email, phone number, Telegram contact and free text are removed.
- Consent records: kept as long as we must be able to show that consent was given.
- If you ask for deletion, that overrides all the periods above.
Legal basis and your rights
- Basis: your consent (GDPR art. 6(1)(a); for health data you share yourself: explicit consent under art. 9(2)(a)). Consent can be withdrawn at any time. Running and securing the websites rests on our legitimate interest (art. 6(1)(f)).
- Storage and processors: see the table above.
- Who sees your data: the coaches Eirik Haugsnes and Odd Levi Paulsen, and Odd Levi Paulsen as operator. If you get a new coach, you will be told. All coaches are bound by confidentiality.
- Rights: you may request access, rectification, deletion, restriction and portability, and you may withdraw your consent. One email to hei@treni.no is enough. We reply within 30 days. You may also complain to the Norwegian Data Protection Authority (datatilsynet.no).
- Security: access to the data is protected by passwords and personal links, keys are stored encrypted, and we check daily that no personal data ends up in the code repositories. Should a breach occur that may affect you, we notify you and the Data Protection Authority within 72 hours.
- Changes: if we change this policy in a way that matters to you, for example a new processor, you will be told in your Telegram group before the change takes effect.