peaklab
PrivacyTerminiDocumentazione
Note legali

Privacy Notice

Ultimo aggiornamento 27 settembre 2026

This Privacy Notice explains how Peaklab (“Peaklab”, “we”, “us”) collects, uses, shares and protects personal data when you use the Peaklab web application and the related Telegram and MCP interfaces (together, the “Service”).

Peaklab is a training analytics workspace for endurance athletes. It brings together training and recovery data from services you already use, and offers an AI coach that discusses that data with you. Using the Service therefore involves health data, which European law treats as a special category of personal data deserving extra protection. This notice sets out exactly what that means in practice.

Peaklab is not a medical device and does not provide medical advice, diagnosis or treatment. Readiness scores, training load figures and coaching replies are decision aids that can be incomplete or wrong.

If you have questions about this notice or want to exercise your rights, contact us at filippo.dionizio@hotmail.com.

1. Who is responsible for your data

Peaklab is operated by Filippo Dionizio as an independent developer. For the purposes of the EU General Data Protection Regulation (GDPR), we are the controller of the personal data described in this notice, which means we decide why and how it is processed.

You can reach us for any privacy matter at filippo.dionizio@hotmail.com. We have not appointed a Data Protection Officer, as we are not required to.

2. What data we collect

Account data you give us

To create an account we collect your email address and a password. Passwords are handled by our authentication provider and stored only as a cryptographic hash; we never see or store your password in readable form. We do not offer social or third-party login, so we receive no profile data from social networks.

Subscription and billing data

If you subscribe, payment happens on a checkout page hosted by Stripe. You enter your card or other payment details there, not in Peaklab, and we never see or store them. From Stripe we receive and keep a customer identifier, your plan, the subscription status, its renewal or cancellation dates, and the list of your invoices with their amounts and status, so we can switch paid features on or off and show you your payment history.

Free trial record

Each person can use the free trial once. To enforce that, when you sign up we compute a one-way cryptographic fingerprint (a keyed HMAC-SHA256) of your email address after normalising it (lower case, without “+” tags, and without dots for Gmail addresses). We keep only that fingerprint, the date of the first signup, the date of the latest one and how many signups used it. It does not contain your email address and cannot be turned back into it without a secret key held separately. Unlike your other data, this record is kept after you delete your account, for the period stated below, so that deleting and re-creating an account does not grant a new trial. We also check whether the email domain belongs to a known temporary email service, in which case the account works normally but comes without a free trial.

Training and recovery data from services you connect

The core of the Service is data you choose to bring in from third-party platforms. Nothing is imported until you explicitly connect a provider and authorise the transfer. Depending on the provider and on the data categories you enable, this can include:

  • Activities and workouts: date, time, duration, sport, distance, elevation, calories and the device or app that recorded them.
  • Detailed activity streams: heart rate, power, cadence, speed, altitude, temperature and GPS position over the course of a session.
  • Recovery and wellness readings: sleep duration and stages, resting heart rate, heart rate variability, respiratory rate, body temperature deviation, blood oxygen and provider recovery or readiness scores, where the provider records them.
  • Body and threshold values: weight, functional threshold power, threshold pace or heart rate, and their history over time.
  • Strength training logs, and calendar entries where you connect a calendar.

Providers we currently support are: Intervals.icu, WHOOP, Oura, Wahoo, Polar, Hevy, Google Calendar. Each provider exposes a different set of metrics, and you control which data categories are enabled for each connection.

Data you enter yourself

This includes your goals, target races and race results, training availability and constraints, injuries or limitations you choose to describe, coaching conversations, notes you add to sessions, course files you upload to Race Analysis, and facts you ask the coach to remember.

Technical data

When you use the Service we process the data needed to run it securely: authentication session cookies, your IP address and standard request information in server logs, and records of errors and of AI requests made for your account, including token counts and cost, so we can monitor usage and reliability. On the sign in, sign up and password reset pages, a bot check by Cloudflare Turnstile processes technical signals from your browser and your IP address to tell people from automated scripts. We also measure aggregate page views with Vercel Web Analytics, which sets no cookies and does not identify you. We do not use advertising cookies and we do not run third-party advertising or cross-site tracking. The cookies and local storage we use are listed in full below.

Sensitive data

Heart rate, heart rate variability, sleep, recovery, weight, injuries and similar readings are health data under Article 9 GDPR. We process them only on the basis of your explicit consent, which you give when you create your account, and which you can withdraw at any time.

We do not knowingly collect information about your race, political opinions, religion, sex life or sexual orientation, genetic or biometric identifiers, or criminal record. Please do not put such information into coaching conversations or notes.

3. Why we use your data, and on what legal basis

Under the GDPR we must have a valid legal basis for every use of your personal data. Ours are as follows.

  • To create and secure your account, authenticate you and keep the Service working. Basis: performance of our contract with you.
  • To import, combine and display your training and recovery data, compute readiness, training load, thresholds, zones and trends, and generate training plans and race analyses. Basis: performance of our contract, and your explicit consent for the health data involved.
  • To operate the AI coach, including sending the relevant parts of your training context to our AI provider so it can answer you. Basis: performance of our contract, when you choose to use the AI features.
  • To deliver coaching and plan notifications through Telegram, if you link a Telegram account. Basis: performance of our contract, at your request.
  • To make your Peaklab context available to an external AI client you choose to connect over MCP, using a key you generate. Basis: your explicit consent and your instruction.
  • To sell and manage subscriptions: enabling paid features, showing your payment history, and cancelling billing when you delete your account. Basis: performance of our contract with you, and legal obligation for the accounting records the law requires.
  • To offer the free trial once per person, through the trial record described above, and to protect sign in, sign up and password reset from automated abuse. Basis: our legitimate interest in preventing abuse of the free trial and of your account. The trial record contains no readable email address and we use it for nothing else.
  • To keep the Service secure, prevent abuse, diagnose faults, monitor AI usage and cost, and understand aggregate site usage. Basis: our legitimate interest in running a reliable, sustainable service.
  • To reply to your support requests and feedback. Basis: performance of our contract and our legitimate interest.
  • To comply with legal obligations, and to establish or defend legal claims where necessary. Basis: legal obligation and legitimate interest.

We do not sell your personal data, we do not share it with data brokers, and we do not use it for advertising or profiling for marketing purposes.

4. Artificial intelligence in the Service

The Peaklab coach, the training plan generator and parts of the analysis features are powered by a large language model. We do not host that model ourselves: we send the prompt to a third-party AI provider over an API and show you the reply.

Who the provider is

Our current AI provider is DeepSeek, and requests are sent to DeepSeek's API. DeepSeek is based in the People's Republic of China and processes API requests on infrastructure there. This is a transfer of personal data outside the European Economic Area to a country without an EU adequacy decision, and it can include health data. Several European regulators have raised concerns about DeepSeek's consumer service and its data protection practices.

We consider this transfer material enough that you should decide on it knowingly. If you are not comfortable with training and health context being sent to an AI provider operating in China, do not use the coach, the plan generator or the MCP connection. The rest of the Service, including your dashboard, analytics and race analysis, works without them.

What is actually sent

A coach request includes the training context relevant to your question: recent activities and their key metrics, recovery and readiness figures, thresholds, your plan, your goals and races, the coaching memory you have approved, and the conversation itself. It does not include your password. Your email address is not needed for coaching and is not part of the coaching context.

Training on your data and retention at the provider

We do not train any model on your data, and we do not grant anyone the right to do so on our behalf. What the AI provider retains, and for how long, is governed by that provider's own terms and privacy policy rather than by us. We cannot guarantee that an AI provider deletes a request immediately after answering it. Treat anything you send to the coach accordingly, and do not paste information you would not want processed abroad.

Automated decisions

Readiness scores, training recommendations and generated plans are produced automatically, but they have no legal or similarly significant effect on you: they are suggestions you are free to ignore, and no decision about your rights, access or money is made automatically. You can always ask us to review any output.

How to avoid it

Using the AI features is optional. You can use the Service without opening Coach, without generating a plan, without linking Telegram and without creating an MCP key. You can delete an MCP key, unlink Telegram and delete your coaching conversations and memory at any time.

5. Who we share data with

We share personal data only with the service providers we need to run Peaklab, and only to the extent they need it. They act as our processors under contract, except where stated otherwise.

  • Supabase, for our database, authentication and file storage. Data is stored in the European Union region.
  • Vercel, for application hosting, serving the site and running our server-side functions and scheduled jobs.
  • DeepSeek, as our AI provider for the coach and plan generation, as described above. Transfers to China are involved.
  • Google (Gemini API), only for voice notes and photos you send to the Telegram coach: the audio or image is sent to Google to be converted into text, which the coach then reads. Transfers to the United States may be involved.
  • Stripe, if you subscribe. Payments are processed through Stripe Managed Payments: the purchase is sold to you through Link, Stripe's merchant of record, which handles checkout, taxes, receipts, payment support, refund requests and fraud prevention. For your payment details and the purchase itself Stripe and Link act as independent controllers under their own privacy policies; we receive only the billing data described above.
  • Cloudflare, which runs the Turnstile bot check on the sign in, sign up and password reset pages.
  • Open Food Facts and the USDA FoodData Central database, which receive the names or barcodes of foods you log so we can look up their nutrition values. No account data is sent with these lookups.
  • Telegram, only if you link a Telegram account, in order to deliver and receive coaching messages. Telegram acts as an independent controller for the messaging service itself.
  • The training and recovery providers you connect, in order to retrieve your data at your request. Each of them is an independent controller for the data it holds; their own privacy policies govern that.
  • Google, only if you connect Google Calendar, in order to write your planned sessions and races to the calendar you authorise.
  • Any external AI client you connect over MCP, using a key you generate. Whatever you connect receives the Peaklab context that client requests, and its operator's terms then apply.

We may also disclose personal data where we are legally required to, for example in response to a valid order from a competent authority, or where necessary to establish, exercise or defend legal claims. If Peaklab is ever transferred to another owner as part of a sale, merger or similar transaction, your data may be transferred with it; we will tell you before that happens and you will be able to delete your account first.

6. International transfers

Your account and training data are stored in the European Union. Some of our providers are established outside the EEA or process data outside it. Where that happens we rely on the European Commission's Standard Contractual Clauses or on an adequacy decision where one exists.

The transfer to our AI provider in China described above is the most significant of these. It happens only when you use the AI features, and you should be aware that the legal protections and remedies available there are not equivalent to those in the EEA. You can avoid this transfer entirely by not using the AI features.

Connections you initiate to third-party providers may involve transfers to wherever that provider operates. That is inherent in choosing to connect them.

7. How long we keep data

  • Account, training, recovery, plan, coaching and race data: for as long as your account exists.
  • Deleted items, such as a deleted conversation, race or MCP key: removed when you delete them, subject to short-lived backups.
  • Server and error logs, and AI usage records: typically retained for up to 12 months for security, debugging and cost monitoring.
  • Subscription and billing data we hold: for as long as your account exists. Stripe and Link keep their own transaction records for as long as the law requires them to.
  • Free trial record: 24 months after the most recent signup with the same email address, then deleted automatically. It is kept after account deletion, as explained above.
  • Data held after account deletion: your data is deleted with your account, as described below, except the free trial record. Encrypted backups may retain copies for a short period before rotating out.

Where we are required to keep certain records for longer, for example for accounting or to defend a legal claim, we keep only what is necessary for that purpose.

8. How we protect data

We use encryption in transit, encrypted storage at rest, hashed passwords, row-level access rules in the database so that each account can reach only its own rows, scoped credentials for provider connections, and revocable keys for MCP access. Administrative access is limited to what is needed to operate the Service.

No system is perfectly secure. Peaklab is operated by a single developer rather than a staffed security team, and you should weigh that when deciding what to entrust to it. If we become aware of a personal data breach affecting your rights, we will notify the competent supervisory authority and, where required, you, within the timeframes set by law.

9. Your rights

If the GDPR applies to you, you have the right to access your personal data and receive a copy, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing that already took place. Withdrawing consent for health data means we can no longer operate most of the Service for you.

Exercising them in the app

  • Correct or update your profile, thresholds, goals and races directly in the app.
  • Disconnect any provider, or disable individual data categories, from Integrations.
  • Delete coaching conversations, coaching memory, races and saved race analyses from the relevant pages.
  • Revoke an MCP key from the MCP page, and unlink Telegram from Integrations.
  • Delete your entire account from your account settings. This first cancels any active subscription, then permanently deletes your authentication record and, by cascade, all rows belonging to it: activities, wellness data, plans, coaching history and memory, MCP keys, the Telegram link, subscription records and saved analyses. Only the free trial record described above remains. It cannot be undone.
  • Manage or cancel your subscription and download your invoices from the Billing page.

For anything you cannot do yourself, including a copy of your data in a portable format, write to filippo.dionizio@hotmail.com. We will respond within one month, and will tell you if we need longer, as the GDPR permits. We may ask you to confirm your identity before acting on a request.

You also have the right to complain to a data protection authority. In Italy this is the Garante per la protezione dei dati personali; if you are elsewhere in the EEA you may complain to your local authority. We would appreciate the chance to address your concern first.

10. Children

The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Cookies and local storage

We use only what is strictly necessary to deliver the Service you asked for. We do not use analytics, advertising, profiling or cross-site tracking cookies, we load no third-party advertising or tracking scripts, and we do not fingerprint your device to recognise or follow you. This section is our full cookie policy; there is nothing else to disclose.

Cookies we set

  • Authentication cookies, set by our authentication provider, which keep you signed in and let the server recognise your session. Without them you could not stay logged in. They are removed when you sign out, and otherwise expire according to the session lifetime.
  • Short-lived connection cookies, such as an OAuth state value, set only while you are connecting a training provider. They exist to verify that the authorisation response genuinely answers the request you started, which is a security measure. They cannot be read by scripts in the page, and expire after ten minutes.

Third-party scripts

  • Cloudflare Turnstile, loaded only on the sign in, sign up and password reset pages. It examines your browser to check that a person, not a script, is using the form, and exists only to protect your account and the Service. It is not used for advertising or to track you across sites.
  • Vercel Web Analytics, which counts page views in aggregate without cookies and without identifying individual visitors.

Local storage in your browser

  • Your light or dark theme preference, kept in local storage so the page does not flash the wrong theme when it loads.
  • The identifier of the coaching conversation you currently have open, kept in session storage so a refresh does not lose your place. It is cleared when you close the tab.

These stay in your browser, are not transmitted to us as tracking data and are not used to build a profile of you.

Why we do not show a cookie banner

Under Article 5(3) of the ePrivacy Directive, storage that is strictly necessary to provide a service the user has explicitly requested is exempt from prior consent. Everything listed above falls into that category: authentication, connection and sign in security, and remembering a preference you set yourself. Vercel Web Analytics stores nothing on your device. Consent would be required if we added analytics, advertising or profiling, and if we ever do, we will ask for it properly before anything is set.

You can delete or block this storage in your browser settings at any time. Blocking the authentication cookies will prevent you from signing in, as they are what keeps you logged in. Because we do not track you across sites, browser Do Not Track signals make no difference to what we do.

12. Changes to this notice

We may update this notice as the Service changes. The date at the top always reflects the current version. If a change materially affects how we use your data, in particular a change of AI provider or of the categories we process, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

13. Contact

For any question, request or complaint about this notice or your data, email filippo.dionizio@hotmail.com.

Domande su questo documento?filippo.dionizio@hotmail.comLeggi i Termini di servizio
Indice
  1. Who is responsible for your data
  2. What data we collect
  3. Why we use your data, and on what legal basis
  4. Artificial intelligence in the Service
  5. Who we share data with
  6. International transfers
  7. How long we keep data
  8. How we protect data
  9. Your rights
  10. Children
  11. Cookies and local storage
  12. Changes to this notice
  13. Contact