Privacy Policy
Last updated: September 2, 2026
Data Controller
PaceLab is operated by:
Hinson Ventures LLC is the data controller responsible for your personal data as described in this Privacy Policy.
1. Introduction
PaceLab("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered running coach service.
By using PaceLab, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
- Email address (required for account creation)
- Name (optional)
- Password (managed securely through AWS Cognito authentication - we do not store passwords directly)
- Timezone preference (for scheduling and notifications)
- Account timestamps (creation date, last login)
2.2 Fitness Data from Connected Services
When you connect a fitness service or device (Garmin or Apple Health), we access and store:
- Activity metrics: distance, duration, pace, heart rate (average and maximum), cadence, and calories
- GPS route data: coordinates, map polylines, and elevation profiles. Route coordinates are stored at the full precision your device recorded them — typically thousands of points per workout. We do not round, blur, or truncate them
- Activity details: timestamps, titles, descriptions, and workout type
- Lap and split information (if recorded by your device)
- Activity photos (if shared through your connected service)
- Basic athlete profile information from the connected service
- Heart-rate zone boundaries and the time you spend in each zone
- Wellness and recovery metrics, where your device or app records them: sleep duration and quality, heart-rate variability (HRV), resting heart rate, readiness or body-battery scores, and stress metrics
We store the complete activity data from your provider to ensure accurate training analysis. This includes the raw data as provided by the service.
2.3 Profile Information You Provide
- Training goals and target races (including race name, date, distance, and target time)
- Physical attributes (all optional):
- Date of birth or age
- Biological sex (used for physiologically-appropriate training recommendations)
- Height
- Weight (including historical entries if you choose to track changes over time)
- Running experience level
- Personal records and race history
- Training preferences (weekly schedule, preferred workout types, training philosophy)
- Coach communication style preference
- Self-assessment feedback on workouts (perceived effort, energy level, notes)
- Your location, for weather forecasts and optimal run-time suggestions. Only a city-level place name is used in your coaching, but the coordinates you or your device provide are stored at the precision they were reported — we do not round them before saving
- Strength training logs (exercises performed, loads, sets, and repetitions)
- Injury, pain, and discomfort reports, including the body area affected and the severity rating (1-5) you select
- Physiological context, if you choose to declare one in Coaching → Preferences: pregnant, returning from injury, recovering from illness, or coming back after an extended break. This is optional and defaults to none. We never infer this setting — it is set only when you select it, or when a member of our team sets it at your request. We use it to adjust how your heart-rate signals are interpreted, because these states shift your baseline
- Free-text you write in the app, including athlete notes, notes to your coach, and race reviews
2.4 Automatically Collected Information
- Weather data for your activities and location (from Open-Meteo weather service)
- Map images generated from your activity routes
- Derived metrics including elevation profiles, pace analysis, and plan-completion scores
- AI service usage metrics (to manage costs and improve recommendations)
- Activity sync status and history
- Product-interaction analytics: which screens you open, which controls you tap, and how you move through flows such as onboarding, connecting a device, and subscribing
- Crash and diagnostic data: error messages and stack traces when something goes wrong, plus records of whether your device is syncing as expected
- Performance data: page-load timings, API response times, and web-performance measurements
- Technical request context: an app session identifier, your app or browser version, user agent, and the page address where an event happened
- Device token for push notifications, if you enable them (used only to deliver notifications to your device)
This diagnostic and analytics data is linked to your account— each batch carries your internal account identifier, so we can tell whose session encountered a problem. It is therefore pseudonymous, not anonymous. Some of it is processed by Sentry, our error and performance monitoring provider (see Section 5). We do notuse any of it to track you across other companies' apps or websites: PaceLab contains no advertising SDK, no advertising identifier, and no cross-app tracking.
3. Apple Health (HealthKit)
On iPhone you can connect PaceLab to Apple Health. Health data deserves its own explanation, so this section sets out exactly what that connection does and does not do.
We only read. We never write.
PaceLab requests read-only access to Apple Health. Our authorization request asks for read permission and passes no write permission at all, so the app is technically unable to add, change, or delete anything in your Health app. iOS still shows a write-permission description for PaceLab because the Health framework we link includes writing APIs; we do not call them. If we ever want to save a completed session back to Health, we will ask you first.
What we read from Health
When you connect Apple Health, iOS shows you a permission sheet listing every category below and you choose which to allow. We receive only what you allow, and iOS enforces that independently of us.
- Workouts, including their routes and lap markers — the GPS route of an outdoor session is part of the workout record
- Heart rate, resting heart rate, and heart-rate variability
- Respiratory rate and VO₂ max
- Sleep — your sleep analysis records
- Steps, walking and running distance, and energy burned (active and resting)
- Running dynamics — running power, running speed, stride length, ground contact time, and vertical oscillation, where your Apple Watch records them on outdoor runs
That is the complete list. We do not request blood oxygen, body or wrist temperature, heart-rate recovery, mindfulness, nutrition, menstrual or reproductive health, clinical health records, or any other Health category.
Why we read it
We read it for one purpose: to coach you. It tells your AI coach how hard each session really was and how well you are recovering, and your weekly training plan is built from that — a hard run and a poor night's sleep will lower the intensity it prescribes the next day. Once it reaches us, health data from Apple Health is handled exactly like the training data described in Section 2: workout summaries and wellness metrics form part of the coaching context we send to OpenAI, our AI processor, under the terms in Section 5, and raw GPS route coordinates are never sent to an AI provider.
What we never do with your health data
To be explicit, because Apple requires apps that read Health data to be:
- We never use health data for advertising or marketing — ours or anyone else's
- We never use health data for use-based data mining. We do not analyze it to build audience profiles, to target you, or for any purpose other than delivering your coaching
- We never sell health data, and we never share it with data brokers
- We never write anything back to your Health app
- We never share health data with third parties for their own purposes. It reaches only the service providers who help us deliver your coaching, each named in Section 5 and each acting on our instructions — our AI processor (OpenAI), our infrastructure provider (Amazon Web Services), and Mapbox, which renders the map image of a route; a connected service you have asked us to post your workout summaries to; or where the law requires it, as described in Section 6
- Health data is never used, by us or by anyone we share it with, to determine eligibility for insurance, credit, or employment
Your control
- Turn it off in iOS: the Health app → Sharing → Apps → PaceLab lets you turn off any individual category, or all of them, at any time. This is the control that stops the sharing, and iOS enforces it independently of us — once you turn a category off, no new data of that kind reaches PaceLab
- Disconnect the account: you can also disconnect a fitness service from PaceLab under Settings → Connected Devices. Apple Health is granted and revoked in the Health app itself, as above
- Delete: deleting your account permanently deletes the health data we hold, within 30 days (Section 9). It removes nothing from your Health app — because we never put anything there
4. How We Use Your Information
Your data is used solely to provide the service to you. We do not mine, analyze, or monetize your personal data for any other purpose.
Specifically, we use your information to:
- Generate personalized AI-powered training plans
- Analyze your training patterns and provide feedback
- Track your progress toward your goals
- Send service-related communications
- Process payments and manage subscriptions
We do not routinely access your individual data. We may only view your account data when troubleshooting issues that you report to us, and only to the extent necessary to resolve your specific problem.
5. AI Processing and Third-Party Services
To provide AI-powered coaching, your training data is processed by large language models (LLMs) run by one third-party AI provider: OpenAI. This means:
- We ask for your explicit permission in the app, and we record it against your account
- Your training, wellness, and coaching data is sent to OpenAI so it can generate your plans, feedback, and coaching notes
- We do not send your name, email address, password, or payment details to AI providers
- OpenAI acts as our processor: it handles your data on our instructions and does not train its models on it
- Generated training plans, feedback, and coaching notes are stored in your account
Your Explicit Permission
PaceLab shows you a consent screen that names OpenAI, describes the categories of data listed below, and requires you to actively agree. Nothing is pre-selected. For a new account we ask before your first training plan is generated. If you already had an account before we introduced this screen, your data was already being processed to provide you with coaching, as described in this policy, and we ask for your permission the next time you open the app.
Because AI is how PaceLab generates your training plans and coaching feedback, this permission is required to use the coaching service. If we change the categories of data we send, or add a new AI provider, we will ask you again rather than relying on your earlier agreement.
Data Shared with AI Providers
When generating training plans, coaching notes, and workout feedback, we share the following categories of data with OpenAI:
- Activity summaries: distance, duration, pace, elevation, average and maximum heart rate, and cadence (not raw GPS data)
- Lap, split, and interval detail from your workouts
- Heart-rate zones and the time you spent in each zone
- Wellness and recovery data: sleep duration and quality, heart-rate variability (HRV), resting heart rate, readiness or body-battery scores, and stress metrics
- Body weight and weight history
- Injury, pain, and discomfort reports you log, including the body area affected and the severity rating (1-5) you select
- Free-text you write in your own words: athlete notes, notes to your coach, self-assessment ("how it felt") comments, and race reviews
- Strength training logs, including the exercises performed and their loads, sets, and repetitions
- Training goals and target races, including the race name, race date, distance, and target finish time
- Personal records and race history
- Current training phase, weekly volume, and how closely you followed your plan
- Weather conditions during and forecast for your activities (city-level)
- Athlete profile attributes: age or age bracket, biological sex, height, running experience level, and your training and coaching-style preferences
We do NOT share your email address, full name, password or account credentials, payment details, precise home location or street address, or raw GPS coordinates and route polylines with AI providers.
Pseudonymization and Data Minimization
We send AI providers only what the coaching actually needs, and we separate it from your identity. To be precise about what that does and does not mean:
- No name or contact details: Your name, email address, password, and payment details are never included in AI prompts
- Pseudonymous, not anonymous: You are represented to AI providers by a random internal account identifier. That identifier means nothing to OpenAI on its own, but it is stable and we can link it back to you — so your data is pseudonymized, not anonymized
- Location generalization: Only city-level location is used, for weather and run-time suggestions. Your precise location and home address are not sent
- No GPS data: Raw route coordinates and map polylines are never sent to AI providers
- Summaries, not raw streams: Activity data is summarized (e.g., "10K run at 8:30/mile pace") rather than sent as raw second-by-second device streams
We want to be straightforward about the limits of this. What we send is detailed training and health information about one person, and it includes text you have written in your own words. Someone who already knows you well could potentially recognize you from it, even though it carries no name, email address, or exact location. We therefore do not describe this data as anonymous, and we do not rely on pseudonymization alone — the contractual protections described next matter just as much.
AI Providers Act as Our Processors
OpenAI is a data processor acting on our behalf. It processes your data only to return a result to PaceLab, under their business API terms and our data processing agreements with them. Specifically:
- They do not train their models on your data. See OpenAI's How your data is used to improve model performance, which states that "by default, we do not train on any inputs or outputs from ... the API."
- They do not use your data for their own purposes, and they do not sell it
- We use business APIs with these protections in place — your data is not entered into a consumer chatbot product
How Long AI-Related Data Is Kept
- At OpenAI: API inputs and outputs may be retained for up to 30 days for abuse and misuse monitoring, and are then deleted
- At PaceLab: we keep our own copy of the prompts sent to AI providers and the responses returned for 30 days, so we can debug problems and check coaching quality. After 30 days those records are deleted
- Coaching output: your plans, feedback, and coaching notes stay in your account for as long as your account is active
Withdrawing Your Permission
You can withdraw your permission for AI processing at any time, in either of two ways:
- Contact us at support@pacelab.ai and we will stop sending your data to AI providers. Because coaching cannot be generated without AI processing, this also ends the coaching service on your account
- Delete your account from your Settings page, which permanently deletes all of your personal data within 30 days
Withdrawing your permission stops any future AI processing. It cannot recall data that has already been sent to a provider, although those records age out under the retention periods described above.
Other Third-Party Services
- Fitness device providers: Activity data synchronization (Garmin Connect, Apple Health)
- Amazon Web Services (AWS): Secure cloud hosting and data storage
- Stripe: Payment processing (we do not store your full credit card details)
- Open-Meteo: Weather data for activity analysis (receives the coordinates of your run or your set location to return the forecast for that place)
- OpenStreetMap (Nominatim): Reverse-geocoding — turns coordinates into a city name so your coaching can refer to where you ran
- Mapbox: Map rendering and route visualization (receives GPS coordinates to generate activity map images)
- Strava: If you connect Strava, we post your coaching feedback and workout summary into the description of the matching Strava activity. This is outbound only — we do not read your Strava data
- Sentry: Error and performance monitoring (receives crash reports, stack traces, and performance timings from the app)
- Apple: In-app purchases and subscription management for purchases made in our iOS app, and the Apple Push Notification service for delivering notifications you have enabled
6. Data Sharing and Disclosure
We do not sell your personal data.
We may share information only in these circumstances:
- To comply with legal obligations or respond to lawful requests
- To protect our rights, privacy, safety, or property
- In connection with a merger, acquisition, or sale of assets (with notice to you)
7. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Data encrypted in transit (TLS/HTTPS) and at rest (AES-256)
- Secure authentication through AWS Cognito
- Regular security assessments and updates
- Access controls limiting employee access to user data
8. Your Rights
You have the right to:
- Access: View all data we hold about you through your account
- Correction: Update your profile information at any time
- Deletion: Delete your account and all associated data through Settings
- Portability: Request an export of your data
- Disconnect: Revoke connected service access at any time
To exercise these rights, visit your Profile settings or contact us at support@pacelab.ai.
9. Data Retention
We retain your data as follows:
- Active accounts: Data retained while your account is active
- Deleted accounts: All personal data permanently deleted within 30 days
- Diagnostics and analytics: Crash, performance, and product-interaction records are pseudonymous, linked to your account — not anonymous. They may be retained indefinitely for service improvement
10. Children's Privacy
PaceLab is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
11. International Users
Your data is processed and stored in the United States using Amazon Web Services (AWS). By using PaceLab, you consent to the transfer and processing of your data in the US.
We comply with applicable data protection laws in your jurisdiction:
- European Union & United Kingdom: GDPR and UK GDPR rights including access, rectification, erasure, and data portability
- California, USA: CCPA rights including disclosure and deletion
- Canada: PIPEDA rights including access and correction
- Australia: Privacy Act (APPs) rights
- New Zealand: Privacy Act 2020 rights
To exercise your rights under these laws, visit your Profile settings or contact us at support@pacelab.ai.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on our service. Your continued use after such notice constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@pacelab.ai