Your data, in plain words
TrailGoat is one runner's project, not an ad-tech company. This page lists everything the site stores, everything that never leaves your device, and the button that erases your account completely. Effective August 18, 2026 — changes get edited into this page, not hidden in a changelog.
The short version
- We store what you create here — courses, plans, training plans — under your account, so it's there when you come back.
- No ads, no third-party analytics or tracking pixels, and your data is never sold or shared for marketing. Ever.
- Your precise location never touches our server — weather lookups go straight from your browser to the forecast service.
- Your athlete profile (weight, sweat rate and the like) stays on your device when you're signed out, and syncs to your account when you're signed in.
- Questions you ask Capra, the AI coach, go to Anthropic's Claude API along with your plan's numbers — and are never used to train their models.
- Uploaded watch/activity files are read in memory and thrown away; only weekly totals are kept.
- You can delete any single thing in-app, or delete your whole account — including every byte — at the bottom of this page.
When you sign in
Sign-in is Google-only — TrailGoat never sees or stores a password. From Google we keep exactly four things: your name, email address, profile picture URL, and Google's stable account ID (so your account survives an email change). Your email is used to identify your account and for nothing else — no newsletters, no marketing.
Signing in sets one signed, HttpOnly session cookie (tg_session). It
contains only your account number, cryptographically signed so it can't be forged.
What you create
- Courses you save in the Course Creator (the GPX route, name, aid stations, elevation profile).
- Run & race plans from the Run Planner — the course, your fueling inputs, food pack, gear & drop-bag checklists, and your crew & pacer list. Crew entries can include the names, phone numbers and email addresses of people you add — that contact info is stored as part of the plan (so a plan opened on your phone has the same crew as on your laptop), visible only to you, and deleted with the plan. Please add someone's contact details only if they're okay appearing on your plan and crew sheets.
- Crew sheets you share — the "Get live crew sheet" button stores a read-only copy of the plan (including the crew list and its contact details) behind a secret-token URL, so your crew can open it without signing in. Anyone with the link can read it. The link is stable: re-sharing — or updating a saved plan that has been shared — refreshes the same URL in place, so your crew always sees the latest version you shared. Only you can update it (your account, or the browser that created the link). Sheets shared while signed in are tied to your account and erased when you delete it; sheets shared signed-out aren't linked to any account (email Kris with the link if you need one taken down).
- Training plans — your wizard answers (race, fitness, weekly schedule, terrain, free-text notes) and the generated plan, plus which workouts you've checked off.
- Athlete profile — experience level, body weight, sweat rate, sweat saltiness and heat acclimation, so your fueling numbers are the same on every device you sign in on.
- Fitness profile — if you upload watch or Strava export files, the files themselves are parsed in memory and never stored. We keep only the aggregate result: weekly mileage and vert, run frequency, longest run, and typical run days.
All of it is owner-scoped: only you (signed in) can see or change your stuff. One exception to know about: a training plan's calendar feed is a secret-token URL so your phone's calendar app can subscribe without signing in — anyone you give that URL to can read that plan's workouts. Deleting the plan kills the feed.
What stays on your device
Display preferences live in your browser's local storage, not on our server: units (miles/km), temperature scale, theme, and which first-visit tips you've dismissed.
Your athlete profile (experience level, body weight, sweat rate, saltiness, heat acclimation — the inputs behind the fueling math) also lives in your browser. Signed out, it never leaves this device. Signed in, it syncs to your account so the same numbers follow you to any browser you sign in on, and it's erased when you delete your account.
Your working plan — the loaded course, fueling inputs, food pack, gear & drop bags, and crew list — also lives in your browser while you build it. If you use TrailGoat without an account, that's the only place it exists (so a cleared browser loses it, and other devices can't see it). Hitting Save plan while signed in copies all of it into your account so the plan opens complete on any device.
Your location: the "Add local weather" feature asks for your location only when you tap it — never automatically. The coordinates are rounded to roughly 100 m, saved only in your browser, and sent directly from your browser to the Open-Meteo forecast service when a forecast is fetched. Our server never receives them.
Asking Capra (the AI coach)
Capra is the chat in the Run Planner's Ask Capra card. When you send a question, it goes to Anthropic's Claude API together with the plan on your screen — the course name, distance and vert, your start time, the forecast, your fueling targets, your aid-station rows (their names and arrival times), your food pack, and the athlete profile behind the math (experience, weight, sweat rate, saltiness, heat acclimation). That's what makes the answer about your actual day instead of generic advice. Under Anthropic's API terms it isn't used to train their models.
Your conversation isn't saved to your account — it lives in the page and is gone when you close it. One thing our server does keep: to avoid paying for the same answer twice, a generated answer is held in the server's memory for up to 24 hours, filed under a fingerprint of the question and the plan numbers it was based on. An identical question about an identical plan gets served that saved answer instead of a fresh one. Nothing in that cache is tied to you or your account, it's never written to the database, and it's cleared whenever the server restarts.
Capra is general guidance from a language model, not medical advice — and like any such model it can be wrong. Your own judgment, and a doctor for anything medical, beat it every time.
Cookies
Three first-party cookies, zero trackers:
tg_session— keeps you signed in (only exists after you sign in).tg_vid+tg_vday— an anonymous random ID used to count unique visitors once per day. It isn't linked to your account, doesn't follow you across other sites, and exists because we count our own visitors instead of installing Google Analytics.
We also keep daily totals of how the site gets used — how many courses were loaded, plans printed and questions asked, which pages were viewed, and which sites sent us traffic. These are plain counters ("47 plans printed today"), not a log of who did what: they aren't linked to your account, your visitor ID, or each other.
Services we rely on
TrailGoat runs on a small set of infrastructure providers. What each one sees:
- Google — sign-in only (the standard "Sign in with Google" flow).
- Anthropic (Claude) — two features call the Claude API: building a training plan sends your wizard answers (including fitness aggregates, never your raw files), and asking Capra sends your question plus your plan's numbers (see the card above). Under Anthropic's API terms, neither is used to train their models.
- Open-Meteo — weather forecasts, called directly from your browser with your device-stored coordinates.
- Render — hosts the site and server (United States).
- Turso — the database where your account and creations live.
That's the whole list. No ad networks, no data brokers, no social-media pixels.
What we never do
- Sell, rent, or share your data for advertising or marketing.
- Run third-party analytics, ad trackers, or fingerprinting.
- Email you anything except replies to emails you send us.
- Pull data from your Strava or watch accounts behind your back — the only activity data we ever have is what you explicitly upload.
- Keep your data after you delete it. Deletes are real deletes, not "deactivations."
Delete your account
This erases your account and everything in it, immediately and permanently: your profile, saved courses, run & race plans (including their gear and crew lists), crew sheets you shared while signed in, training plans (and their calendar feeds), and fitness profile. There's no grace period and no way for us to undo it.
Any ongoing subscription is canceled automatically before deletion, and Pro access ends. If cancellation cannot be confirmed, your account stays available so you can retry. Refunds follow our existing policy.
One carve-out, in the open: if a course you saved has been linked into the public race catalog that other runners plan from, the course itself stays in the catalog but is fully disconnected from you — nothing about it points to your account, because your account no longer exists.
Sign in first (top-right of any page) and this section becomes the delete button. Prefer email? Write to Kris from your account's email address and it'll be done by hand.
Signed in as …. To confirm, type DELETE below.
Done. Your account and everything in it has been deleted. Thanks for running with the goat — the trails are always here if you come back.