Privacy Notice
Last updated September 13, 2026
This Privacy Notice explains how Peaklab (“Peaklab”, “we”, “us”) collects, uses, shares and protects personal data when you use the Peaklab web application and the related Telegram and MCP interfaces (together, the “Service”).
Peaklab is a training analytics workspace for endurance athletes. It brings together training and recovery data from services you already use, and offers an AI coach that discusses that data with you. Using the Service therefore involves health data, which European law treats as a special category of personal data deserving extra protection. This notice sets out exactly what that means in practice.
If you have questions about this notice or want to exercise your rights, contact us at filippo.dionizio@hotmail.com.
1. Who is responsible for your data
Peaklab is operated by Filippo Dionizio as an independent developer. For the purposes of the EU General Data Protection Regulation (GDPR), we are the controller of the personal data described in this notice, which means we decide why and how it is processed.
You can reach us for any privacy matter at filippo.dionizio@hotmail.com. We have not appointed a Data Protection Officer, as we are not required to.
2. What data we collect
Account data you give us
To create an account we collect your email address and a password. Passwords are handled by our authentication provider and stored only as a cryptographic hash; we never see or store your password in readable form. We do not offer social or third-party login, so we receive no profile data from social networks.
Training and recovery data from services you connect
The core of the Service is data you choose to bring in from third-party platforms. Nothing is imported until you explicitly connect a provider and authorise the transfer. Depending on the provider and on the data categories you enable, this can include:
- Activities and workouts: date, time, duration, sport, distance, elevation, calories and the device or app that recorded them.
- Detailed activity streams: heart rate, power, cadence, speed, altitude, temperature and GPS position over the course of a session.
- Recovery and wellness readings: sleep duration and stages, resting heart rate, heart rate variability, respiratory rate, body temperature deviation, blood oxygen and provider recovery or readiness scores, where the provider records them.
- Body and threshold values: weight, functional threshold power, threshold pace or heart rate, and their history over time.
- Strength training logs, and calendar entries where you connect a calendar.
Providers we currently support are: Intervals.icu, WHOOP, Oura, Wahoo, Polar, Hevy, Google Calendar. Each provider exposes a different set of metrics, and you control which data categories are enabled for each connection.
Data you enter yourself
This includes your goals, target races and race results, training availability and constraints, injuries or limitations you choose to describe, coaching conversations, notes you add to sessions, course files you upload to Race Analysis, and facts you ask the coach to remember.
Technical data
When you use the Service we process the data needed to run it securely: authentication session cookies, your IP address and standard request information in server logs, and records of errors and of AI requests made for your account, including token counts and cost, so we can monitor usage and reliability. We do not use advertising cookies and we do not run third-party advertising or cross-site tracking. The cookies and local storage we use are listed in full below.
Sensitive data
Heart rate, heart rate variability, sleep, recovery, weight, injuries and similar readings are health data under Article 9 GDPR. We process them only on the basis of your explicit consent, which you give when you connect a provider or enter the data, and which you can withdraw at any time.
We do not knowingly collect information about your race, political opinions, religion, sex life or sexual orientation, genetic or biometric identifiers, or criminal record. Please do not put such information into coaching conversations or notes.
3. Why we use your data, and on what legal basis
Under the GDPR we must have a valid legal basis for every use of your personal data. Ours are as follows.
- To create and secure your account, authenticate you and keep the Service working. Basis: performance of our contract with you.
- To import, combine and display your training and recovery data, compute readiness, training load, thresholds, zones and trends, and generate training plans and race analyses. Basis: performance of our contract, and your explicit consent for the health data involved.
- To operate the AI coach, including sending the relevant parts of your training context to our AI provider so it can answer you. Basis: your explicit consent.
- To deliver coaching and plan notifications through Telegram, if you link a Telegram account. Basis: performance of our contract, at your request.
- To make your Peaklab context available to an external AI client you choose to connect over MCP, using a key you generate. Basis: your explicit consent and your instruction.
- To keep the Service secure, prevent abuse, diagnose faults and monitor AI usage and cost. Basis: our legitimate interest in running a reliable, sustainable service.
- To reply to your support requests and feedback. Basis: performance of our contract and our legitimate interest.
- To comply with legal obligations, and to establish or defend legal claims where necessary. Basis: legal obligation and legitimate interest.
We do not sell your personal data, we do not share it with data brokers, and we do not use it for advertising or profiling for marketing purposes.
4. Artificial intelligence in the Service
The Peaklab coach, the training plan generator and parts of the analysis features are powered by a large language model. We do not host that model ourselves: we send the prompt to a third-party AI provider over an API and show you the reply.
Who the provider is
Our current AI provider is DeepSeek, and requests are sent to DeepSeek's API. DeepSeek is based in the People's Republic of China and processes API requests on infrastructure there. This is a transfer of personal data outside the European Economic Area to a country without an EU adequacy decision, and it can include health data. Several European regulators have raised concerns about DeepSeek's consumer service and its data protection practices.
What is actually sent
A coach request includes the training context relevant to your question: recent activities and their key metrics, recovery and readiness figures, thresholds, your plan, your goals and races, the coaching memory you have approved, and the conversation itself. It does not include your password. Your email address is not needed for coaching and is not part of the coaching context.
Training on your data and retention at the provider
We do not train any model on your data, and we do not grant anyone the right to do so on our behalf. What the AI provider retains, and for how long, is governed by that provider's own terms and privacy policy rather than by us. We cannot guarantee that an AI provider deletes a request immediately after answering it. Treat anything you send to the coach accordingly, and do not paste information you would not want processed abroad.
Automated decisions
Readiness scores, training recommendations and generated plans are produced automatically, but they have no legal or similarly significant effect on you: they are suggestions you are free to ignore, and no decision about your rights, access or money is made automatically. You can always ask us to review any output.
How to avoid it
Using the AI features is optional. You can use the Service without opening Coach, without generating a plan, without linking Telegram and without creating an MCP key. You can delete an MCP key, unlink Telegram and delete your coaching conversations and memory at any time.
6. International transfers
Your account and training data are stored in the European Union. Some of our providers are established outside the EEA or process data outside it. Where that happens we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one exists, or on your explicit consent for a specific transfer.
The transfer to our AI provider in China described above is the most significant of these. It takes place on the basis of your explicit consent under Article 49(1)(a) GDPR, and you should be aware that the legal protections and remedies available there are not equivalent to those in the EEA. You can avoid this transfer entirely by not using the AI features.
Connections you initiate to third-party providers may involve transfers to wherever that provider operates. That is inherent in choosing to connect them.
7. How long we keep data
- Account, training, recovery, plan, coaching and race data: for as long as your account exists.
- Deleted items, such as a deleted conversation, race or MCP key: removed when you delete them, subject to short-lived backups.
- Server and error logs, and AI usage records: typically retained for up to 12 months for security, debugging and cost monitoring.
- Data held after account deletion: your data is deleted with your account, as described below. Encrypted backups may retain copies for a short period before rotating out.
Where we are required to keep certain records for longer, for example for accounting or to defend a legal claim, we keep only what is necessary for that purpose.
8. How we protect data
We use encryption in transit, encrypted storage at rest, hashed passwords, row-level access rules in the database so that each account can reach only its own rows, scoped credentials for provider connections, and revocable keys for MCP access. Administrative access is limited to what is needed to operate the Service.
No system is perfectly secure. Peaklab is operated by a single developer rather than a staffed security team, and you should weigh that when deciding what to entrust to it. If we become aware of a personal data breach affecting your rights, we will notify the competent supervisory authority and, where required, you, within the timeframes set by law.
9. Your rights
If the GDPR applies to you, you have the right to access your personal data and receive a copy, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing that already took place. Withdrawing consent for health data means we can no longer operate most of the Service for you.
Exercising them in the app
- Correct or update your profile, thresholds, goals and races directly in the app.
- Disconnect any provider, or disable individual data categories, from Integrations.
- Delete coaching conversations, coaching memory, races and saved race analyses from the relevant pages.
- Revoke an MCP key from the MCP page, and unlink Telegram from Integrations.
- Delete your entire account from your account settings. This permanently deletes your authentication record and, by cascade, all rows belonging to it: activities, wellness data, plans, coaching history and memory, MCP keys, the Telegram link and saved analyses. It cannot be undone.
For anything you cannot do yourself, including a copy of your data in a portable format, write to filippo.dionizio@hotmail.com. We will respond within one month, and will tell you if we need longer, as the GDPR permits. We may ask you to confirm your identity before acting on a request.
You also have the right to complain to a data protection authority. In Italy this is the Garante per la protezione dei dati personali; if you are elsewhere in the EEA you may complain to your local authority. We would appreciate the chance to address your concern first.
10. Children
The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
12. Changes to this notice
We may update this notice as the Service changes. The date at the top always reflects the current version. If a change materially affects how we use your data, in particular a change of AI provider or of the categories we process, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
13. Contact
For any question, request or complaint about this notice or your data, email filippo.dionizio@hotmail.com.