peaklab
PrivacyTermsDocs
Legal

Privacy Notice

Last updated September 13, 2026

This Privacy Notice explains how Peaklab (“Peaklab”, “we”, “us”) collects, uses, shares and protects personal data when you use the Peaklab web application and the related Telegram and MCP interfaces (together, the “Service”).

Peaklab is a training analytics workspace for endurance athletes. It brings together training and recovery data from services you already use, and offers an AI coach that discusses that data with you. Using the Service therefore involves health data, which European law treats as a special category of personal data deserving extra protection. This notice sets out exactly what that means in practice.

Peaklab is not a medical device and does not provide medical advice, diagnosis or treatment. Readiness scores, training load figures and coaching replies are decision aids that can be incomplete or wrong.

If you have questions about this notice or want to exercise your rights, contact us at filippo.dionizio@hotmail.com.

1. Who is responsible for your data

Peaklab is operated by Filippo Dionizio as an independent developer. For the purposes of the EU General Data Protection Regulation (GDPR), we are the controller of the personal data described in this notice, which means we decide why and how it is processed.

You can reach us for any privacy matter at filippo.dionizio@hotmail.com. We have not appointed a Data Protection Officer, as we are not required to.

2. What data we collect

Account data you give us

To create an account we collect your email address and a password. Passwords are handled by our authentication provider and stored only as a cryptographic hash; we never see or store your password in readable form. We do not offer social or third-party login, so we receive no profile data from social networks.

Training and recovery data from services you connect

The core of the Service is data you choose to bring in from third-party platforms. Nothing is imported until you explicitly connect a provider and authorise the transfer. Depending on the provider and on the data categories you enable, this can include:

  • Activities and workouts: date, time, duration, sport, distance, elevation, calories and the device or app that recorded them.
  • Detailed activity streams: heart rate, power, cadence, speed, altitude, temperature and GPS position over the course of a session.
  • Recovery and wellness readings: sleep duration and stages, resting heart rate, heart rate variability, respiratory rate, body temperature deviation, blood oxygen and provider recovery or readiness scores, where the provider records them.
  • Body and threshold values: weight, functional threshold power, threshold pace or heart rate, and their history over time.
  • Strength training logs, and calendar entries where you connect a calendar.

Providers we currently support are: Intervals.icu, WHOOP, Oura, Wahoo, Polar, Hevy, Google Calendar. Each provider exposes a different set of metrics, and you control which data categories are enabled for each connection.

Data you enter yourself

This includes your goals, target races and race results, training availability and constraints, injuries or limitations you choose to describe, coaching conversations, notes you add to sessions, course files you upload to Race Analysis, and facts you ask the coach to remember.

Technical data

When you use the Service we process the data needed to run it securely: authentication session cookies, your IP address and standard request information in server logs, and records of errors and of AI requests made for your account, including token counts and cost, so we can monitor usage and reliability. We do not use advertising cookies and we do not run third-party advertising or cross-site tracking. The cookies and local storage we use are listed in full below.

Sensitive data

Heart rate, heart rate variability, sleep, recovery, weight, injuries and similar readings are health data under Article 9 GDPR. We process them only on the basis of your explicit consent, which you give when you connect a provider or enter the data, and which you can withdraw at any time.

We do not knowingly collect information about your race, political opinions, religion, sex life or sexual orientation, genetic or biometric identifiers, or criminal record. Please do not put such information into coaching conversations or notes.

3. Why we use your data, and on what legal basis

Under the GDPR we must have a valid legal basis for every use of your personal data. Ours are as follows.

  • To create and secure your account, authenticate you and keep the Service working. Basis: performance of our contract with you.
  • To import, combine and display your training and recovery data, compute readiness, training load, thresholds, zones and trends, and generate training plans and race analyses. Basis: performance of our contract, and your explicit consent for the health data involved.
  • To operate the AI coach, including sending the relevant parts of your training context to our AI provider so it can answer you. Basis: your explicit consent.
  • To deliver coaching and plan notifications through Telegram, if you link a Telegram account. Basis: performance of our contract, at your request.
  • To make your Peaklab context available to an external AI client you choose to connect over MCP, using a key you generate. Basis: your explicit consent and your instruction.
  • To keep the Service secure, prevent abuse, diagnose faults and monitor AI usage and cost. Basis: our legitimate interest in running a reliable, sustainable service.
  • To reply to your support requests and feedback. Basis: performance of our contract and our legitimate interest.
  • To comply with legal obligations, and to establish or defend legal claims where necessary. Basis: legal obligation and legitimate interest.

We do not sell your personal data, we do not share it with data brokers, and we do not use it for advertising or profiling for marketing purposes.

4. Artificial intelligence in the Service

The Peaklab coach, the training plan generator and parts of the analysis features are powered by a large language model. We do not host that model ourselves: we send the prompt to a third-party AI provider over an API and show you the reply.

Who the provider is

Our current AI provider is DeepSeek, and requests are sent to DeepSeek's API. DeepSeek is based in the People's Republic of China and processes API requests on infrastructure there. This is a transfer of personal data outside the European Economic Area to a country without an EU adequacy decision, and it can include health data. Several European regulators have raised concerns about DeepSeek's consumer service and its data protection practices.

We consider this transfer material enough that you should decide on it knowingly. If you are not comfortable with training and health context being sent to an AI provider operating in China, do not use the coach, the plan generator or the MCP connection. The rest of the Service, including your dashboard, analytics and race analysis, works without them.

What is actually sent

A coach request includes the training context relevant to your question: recent activities and their key metrics, recovery and readiness figures, thresholds, your plan, your goals and races, the coaching memory you have approved, and the conversation itself. It does not include your password. Your email address is not needed for coaching and is not part of the coaching context.

Training on your data and retention at the provider

We do not train any model on your data, and we do not grant anyone the right to do so on our behalf. What the AI provider retains, and for how long, is governed by that provider's own terms and privacy policy rather than by us. We cannot guarantee that an AI provider deletes a request immediately after answering it. Treat anything you send to the coach accordingly, and do not paste information you would not want processed abroad.

Automated decisions

Readiness scores, training recommendations and generated plans are produced automatically, but they have no legal or similarly significant effect on you: they are suggestions you are free to ignore, and no decision about your rights, access or money is made automatically. You can always ask us to review any output.

How to avoid it

Using the AI features is optional. You can use the Service without opening Coach, without generating a plan, without linking Telegram and without creating an MCP key. You can delete an MCP key, unlink Telegram and delete your coaching conversations and memory at any time.

5. Who we share data with

We share personal data only with the service providers we need to run Peaklab, and only to the extent they need it. They act as our processors under contract, except where stated otherwise.

  • Supabase, for our database, authentication and file storage. Data is stored in the European Union region.
  • Vercel, for application hosting, serving the site and running our server-side functions and scheduled jobs.
  • DeepSeek, as our AI provider for the coach and plan generation, as described above. Transfers to China are involved.
  • Telegram, only if you link a Telegram account, in order to deliver and receive coaching messages. Telegram acts as an independent controller for the messaging service itself.
  • The training and recovery providers you connect, in order to retrieve your data at your request. Each of them is an independent controller for the data it holds; their own privacy policies govern that.
  • Google, only if you connect Google Calendar, in order to write your planned sessions and races to the calendar you authorise.
  • Any external AI client you connect over MCP, using a key you generate. Whatever you connect receives the Peaklab context that client requests, and its operator's terms then apply.

We may also disclose personal data where we are legally required to, for example in response to a valid order from a competent authority, or where necessary to establish, exercise or defend legal claims. If Peaklab is ever transferred to another owner as part of a sale, merger or similar transaction, your data may be transferred with it; we will tell you before that happens and you will be able to delete your account first.

6. International transfers

Your account and training data are stored in the European Union. Some of our providers are established outside the EEA or process data outside it. Where that happens we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one exists, or on your explicit consent for a specific transfer.

The transfer to our AI provider in China described above is the most significant of these. It takes place on the basis of your explicit consent under Article 49(1)(a) GDPR, and you should be aware that the legal protections and remedies available there are not equivalent to those in the EEA. You can avoid this transfer entirely by not using the AI features.

Connections you initiate to third-party providers may involve transfers to wherever that provider operates. That is inherent in choosing to connect them.

7. How long we keep data

  • Account, training, recovery, plan, coaching and race data: for as long as your account exists.
  • Deleted items, such as a deleted conversation, race or MCP key: removed when you delete them, subject to short-lived backups.
  • Server and error logs, and AI usage records: typically retained for up to 12 months for security, debugging and cost monitoring.
  • Data held after account deletion: your data is deleted with your account, as described below. Encrypted backups may retain copies for a short period before rotating out.

Where we are required to keep certain records for longer, for example for accounting or to defend a legal claim, we keep only what is necessary for that purpose.

8. How we protect data

We use encryption in transit, encrypted storage at rest, hashed passwords, row-level access rules in the database so that each account can reach only its own rows, scoped credentials for provider connections, and revocable keys for MCP access. Administrative access is limited to what is needed to operate the Service.

No system is perfectly secure. Peaklab is operated by a single developer rather than a staffed security team, and you should weigh that when deciding what to entrust to it. If we become aware of a personal data breach affecting your rights, we will notify the competent supervisory authority and, where required, you, within the timeframes set by law.

9. Your rights

If the GDPR applies to you, you have the right to access your personal data and receive a copy, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing that already took place. Withdrawing consent for health data means we can no longer operate most of the Service for you.

Exercising them in the app

  • Correct or update your profile, thresholds, goals and races directly in the app.
  • Disconnect any provider, or disable individual data categories, from Integrations.
  • Delete coaching conversations, coaching memory, races and saved race analyses from the relevant pages.
  • Revoke an MCP key from the MCP page, and unlink Telegram from Integrations.
  • Delete your entire account from your account settings. This permanently deletes your authentication record and, by cascade, all rows belonging to it: activities, wellness data, plans, coaching history and memory, MCP keys, the Telegram link and saved analyses. It cannot be undone.

For anything you cannot do yourself, including a copy of your data in a portable format, write to filippo.dionizio@hotmail.com. We will respond within one month, and will tell you if we need longer, as the GDPR permits. We may ask you to confirm your identity before acting on a request.

You also have the right to complain to a data protection authority. In Italy this is the Garante per la protezione dei dati personali; if you are elsewhere in the EEA you may complain to your local authority. We would appreciate the chance to address your concern first.

10. Children

The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Cookies and local storage

We use only what is strictly necessary to deliver the Service you asked for. We do not use analytics, advertising, profiling or cross-site tracking cookies, we load no third-party tracking scripts, and we do not fingerprint your device. This section is our full cookie policy; there is nothing else to disclose.

Cookies we set

  • Authentication cookies, set by our authentication provider, which keep you signed in and let the server recognise your session. Without them you could not stay logged in. They are removed when you sign out, and otherwise expire according to the session lifetime.
  • Short-lived connection cookies, such as an OAuth state value, set only while you are connecting a training provider. They exist to verify that the authorisation response genuinely answers the request you started, which is a security measure. They cannot be read by scripts in the page, and expire after ten minutes.

Local storage in your browser

  • Your light or dark theme preference, kept in local storage so the page does not flash the wrong theme when it loads.
  • The identifier of the coaching conversation you currently have open, kept in session storage so a refresh does not lose your place. It is cleared when you close the tab.

These stay in your browser, are not transmitted to us as tracking data and are not used to build a profile of you.

Why we do not show a cookie banner

Under Article 5(3) of the ePrivacy Directive, storage that is strictly necessary to provide a service the user has explicitly requested is exempt from prior consent. Everything listed above falls into that category: authentication, connection security and remembering a preference you set yourself. Consent would be required if we added analytics, advertising or profiling, and if we ever do, we will ask for it properly before anything is set.

You can delete or block this storage in your browser settings at any time. Blocking the authentication cookies will prevent you from signing in, as they are what keeps you logged in. Because we do not track you across sites, browser Do Not Track signals make no difference to what we do.

12. Changes to this notice

We may update this notice as the Service changes. The date at the top always reflects the current version. If a change materially affects how we use your data, in particular a change of AI provider or of the categories we process, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

13. Contact

For any question, request or complaint about this notice or your data, email filippo.dionizio@hotmail.com.

Questions about this document?filippo.dionizio@hotmail.comRead the Terms of Service
Contents
  1. Who is responsible for your data
  2. What data we collect
  3. Why we use your data, and on what legal basis
  4. Artificial intelligence in the Service
  5. Who we share data with
  6. International transfers
  7. How long we keep data
  8. How we protect data
  9. Your rights
  10. Children
  11. Cookies and local storage
  12. Changes to this notice
  13. Contact