Skip to main content

Privacy Policy

Last Updated: July 26, 2026

Effective Date: July 26, 2026

The short version

  • What we collect: your account details, the running/fitness data you record or connect (runs, GPS location, heart rate, cadence, pace, training plans, goals), and — if you use the nutrition features — your bodyweight, dietary preferences, and any foods you ask to avoid.
  • Why: to run PaceBrain, give you analytics and AI coaching, and improve the product.
  • Do we sell your data? No. We never sell your personal data, and we never use your health or fitness data for advertising.
  • Who we share it with: only the service providers we need to run the app (listed in Section 5), under contract.
  • Your control: you can export all your data or permanently delete your account at any time from your settings.

This summary is for convenience only. The full policy below governs.

1. Who We Are and Scope

This Privacy Policy ("Policy") describes how Nicholas Patterson, trading as Origae (ABN 21 237 258 402), a sole trader based in Victoria, Australia ("PaceBrain," "we," "us," or "our"), collects, uses, discloses, and otherwise handles personal information in connection with the PaceBrain website at pacebrain.app, our mobile applications, and related services (collectively, the "Platform"). PaceBrain is the entity responsible for (and, where applicable, the data controller of) the personal information handled through the Platform.

This Policy applies to everyone who accesses or uses the Platform. By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with our data practices, please do not use the Platform.

This Policy is incorporated by reference into our Terms of Service and should be read together with our Cookie Policy.

2. Personal Information We Collect

2.1 Information You Provide Directly

  • Account Data: name, email address, password (stored only in hashed/encrypted form by our authentication provider), and profile information.
  • Athletic and Health/Fitness Data: running activities, distance, pace, duration, heart rate, heart-rate variability (HRV), elevation, cadence, GPS routes and precise location, recovery and readiness metrics, mood logs, training goals, race plans, and performance metrics. This is sensitive information and we treat it accordingly (see Section 3).
  • Nutrition and Dietary Data: if you use our nutrition features, we collect the bodyweight, gender, and athlete type you enter, your dietary preferences (such as vegan, vegetarian, or pescatarian), whether you require dairy-free options, any calorie target you set, and the free-text list of foods you ask to exclude. Foods you exclude may reveal a food allergy, intolerance, or medical condition. Dietary and allergy information is health information and therefore "sensitive information" under the Privacy Act 1988 (Cth) and a special category of data under the GDPR. We collect it only to generate the plan you request, we do not use it to infer or record any diagnosis, and we do not use it for advertising or profiling. You can delete a saved plan at any time, and deleting your account deletes all of it.
  • Consent and Acknowledgement Records: when you tick (or decline) the acknowledgement required before generating a nutrition plan, we record your answer, the date and time, and the version of the wording shown to you. We keep this as a record that the acknowledgement was given, and it may be retained after account deletion where we need it to establish or defend a legal claim (see Section 7).
  • User-Generated Content: activity notes, personal records, goals, crew/community messages, and other content you submit.
  • Communications: information in your messages to us, including support requests and feedback.
  • Payment Information: for paid subscriptions purchased on the web, billing details and transaction history are collected and processed by our payment processor, Stripe. Purchases made in our iOS app are processed by Apple. We do not receive or store your full card number.

2.2 Information Collected Automatically

  • Device Information: device type, operating system, browser type and version, and identifiers.
  • Usage Data: pages visited, features used, and interaction data, collected through our analytics providers (see Section 5).
  • Log Data: IP address, access times, and system logs.
  • Location Data: approximate location from your IP address, and — only where you record or connect GPS-enabled activities — precise route/location data.

2.3 Information From Connected Services and Sign-In Providers

  • Sign in with Google (web) and Sign in with Apple (iOS): if you use these, we receive basic profile information (such as your name and email) from the provider to create or access your account.
  • Garmin Connect: if you connect Garmin, you provide your Garmin account credentials so we can sync your activities and, at your request, send planned workouts to your device. Your Garmin password is used only to establish the connection — it is not stored or logged — and the resulting access tokens are stored in encrypted form. You can disconnect at any time in your settings.
  • Strava (when available): if you connect Strava, we receive the activity and profile data you authorize. Strava access may be unavailable at times due to changes in Strava's API program. If you disconnect Strava or delete your account, we delete the Strava-sourced data we imported, and we do not use Strava-sourced data to train AI or machine-learning models.
  • File uploads: you may upload activity files (e.g., GPX/FIT/TCX) exported from other platforms such as Garmin, Polar, or COROS.

3. Sensitive Information and Consent

Health and fitness data (including heart rate, HRV, GPS location, and related metrics) and nutrition and dietary data (including bodyweight and the foods you ask to exclude, which may reveal an allergy, intolerance, or medical condition)is "sensitive information" under the Australian Privacy Act 1988 (Cth) and a "special category" of data under the GDPR. We collect and process this data for the purpose of providing the Platform's tracking, analytics, coaching, and nutrition features, and we rely on your consent to do so. You provide that consent by choosing to record, upload, or connect this data, or by entering it into the nutrition wizard. You can withdraw consent at any time by disconnecting integrations, deleting a saved plan, ceasing to add data, or deleting your account.

Sharing a plan by email. If you choose to email a nutrition plan, you supply the recipient's name and email address and we send the plan to them through our email provider (Resend) as PDF and spreadsheet attachments. That plan contains your dietary information. You choose the recipient and you are responsible for that choice— once sent, we cannot recall it. We use the recipient's address only to send that email and do not add it to any marketing list.

We do not sell your personal information, and we never use your health or fitness data for advertising or for any decision that produces legal or similarly significant effects about you.

4. Legal Bases for Processing (GDPR/UK GDPR)

For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions requiring a legal basis, we process personal data on these grounds:

  • Contractual Necessity (Art. 6(1)(b)): to provide the Platform, manage your account, and fulfil subscriptions.
  • Consent (Art. 6(1)(a); Art. 9(2)(a) for health data): for health/fitness data, marketing, non-essential cookies, and location tracking.
  • Legitimate Interests (Art. 6(1)(f)): product improvement, security, and fraud prevention, where not overridden by your rights.
  • Legal Obligation (Art. 6(1)(c)): to comply with applicable law.

5. How We Share Information — Service Providers

We do not sell your personal information. We share it only with the service providers (sub-processors) we use to operate the Platform, under contracts that require them to protect it and use it only as we instruct. These providers are located primarily in the United States, so using the Platform involves the international transfer of your data (see Section 6):

  • Supabase: database hosting, authentication, and storage
  • Vercel: website/app hosting, content delivery, and product analytics (Vercel Analytics & Speed Insights)
  • Stripe: payment processing (web subscriptions)
  • Apple: payment processing (iOS in-app purchases) and Sign in with Apple
  • Google: Sign in with Google (web)
  • Groq: AI/ML model inference for coaching and insight features
  • PostHog: product analytics and usage measurement
  • Resend: transactional and notification email delivery
  • Sentry: error monitoring and application stability
  • Garmin / Strava: where you connect them, for activity sync (as described in Section 2.3)

We may also disclose personal information: (a) to comply with law, legal process, or a valid government request; (b) to protect the rights, property, or safety of PaceBrain, our users, or the public; (c) to detect or prevent fraud or security issues; (d) to enforce our Terms; or (e) in connection with a business transfer (merger, acquisition, or sale of assets), in which case we will notify you.

6. International Data Transfers

Your personal data may be transferred to, and processed in, countries other than your own, including the United States. Where we transfer data from the EEA, UK, or Switzerland to a country not recognised as providing adequate protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), together with supplementary measures where needed. For Australian users, before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles (APP 8).

7. Data Retention and Deletion

We retain personal data only as long as needed to provide the Platform and to meet legal, accounting, or reporting obligations.

  • Active accounts: data is retained while your account exists.
  • Account deletion: when you delete your account, we permanently and immediately delete your activity, health, nutrition, profile, and related data from our systems and cancel any active subscription. Limited records (e.g., transaction/tax records) may be retained where required by law or to resolve disputes or prevent fraud.
  • Consent records: records that you acknowledged (or declined) the health and nutrition disclaimer, including the date, time, and version of the wording shown, may be retained after account deletion where we need them to establish, exercise, or defend a legal claim, or to comply with a legal obligation. These records are kept separately, are used only for that purpose, and contain no plan content.
  • Anonymised data: aggregated or de-identified data that cannot reasonably identify you may be retained for analytics and product improvement.

8. Your Rights Under GDPR/UK GDPR

If you are in the EEA, UK, or a similar jurisdiction, you have rights to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing (including profiling and direct marketing); data portability; and withdraw consent at any time (without affecting prior processing). You may also lodge a complaint with your local supervisory authority.

You can exercise the core rights yourself in-app: export all of your data from your settings, and permanently delete your account from Settings → Data & Privacy. For any other request, email support@pacebrain.app (subject line: "Privacy"). We will respond within the time required by applicable law (generally within 30 days).

9. California Privacy Rights (CCPA/CPRA)

California residents have rights to know, delete, and correct personal information, to opt out of the "sale" or "sharing" of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We collect the categories described in Section 2 for the purposes in this Policy. To exercise your rights, email support@pacebrain.app. We will verify your identity and respond within the time required by law.

10. Australian Privacy Rights (Privacy Act 1988)

We handle personal information in accordance with the Australian Privacy Principles (APPs), including open and transparent management (APP 1), use and disclosure limits (APP 6), direct-marketing opt-out (APP 7), cross-border disclosure safeguards (APP 8), reasonable security (APP 11), and access and correction rights (APP 12–13). Where practicable, you may deal with us anonymously or by pseudonym, though some features require an account.

Complaints: if you believe we have breached the APPs, contact us at support@pacebrain.app (subject line: "Privacy") and we will respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

11. Data Security and Breach Notification

We implement technical and organisational measures to protect personal data, including encryption in transit (TLS) and at rest, hashed passwords, row-level access controls in our database, restricted staff access, and monitoring and logging.

Breach notification: in the event of an eligible data breach likely to result in serious harm or a risk to your rights, we will notify affected users and any relevant regulator (including the OAIC under the Notifiable Data Breaches scheme) without undue delay after becoming aware of it.

Not a HIPAA covered entity:PaceBrain is not a healthcare provider and is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Your data is protected under this Policy and applicable privacy law, not HIPAA.

No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security and are not liable for unauthorised access arising from circumstances beyond our reasonable control.

12. Children's Privacy

The Platform is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact support@pacebrain.app and we will delete it.

13. AI, Automated Processing, and Profiling

We use automated processing, including AI and machine-learning models (via our provider Groq), to generate coaching suggestions, training plans, insights, race predictions, and nutrition and meal-suggestion plans from the athletic and dietary data you provide. This processing supports the features you request and does not produce legal or similarly significant effects about you. No qualified professional reviews this output before you receive it.

To generate a plan, the relevant inputs are sent to Groq for processing — your training volume and experience level, your goal, your bodyweight and gender, your dietary preferences and any foods you exclude, and the name and date of an upcoming race if you have saved one. We do not send your name, email address, or account identifiers.

We do not sell your data or use your health or fitness data for advertising or automated decisions with legal or similarly significant effects. AI-generated output is for informational purposes only, may be inaccurate, and is not medical, professional coaching, or other regulated advice — see the health disclaimer in our Terms of Service. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

14. Cookies and Analytics

We use cookies and similar technologies for essential functionality (authentication and security), and, subject to your choices, for analytics (via PostHog and Vercel Analytics). See our Cookie Policy for details and to manage your preferences.

15. Third-Party Links

The Platform may link to third-party websites or services we do not operate. This Policy does not apply to them, and we are not responsible for their practices. Please review their privacy policies.

16. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a revised "Last Updated" date, and for material changes affecting your rights we will provide additional notice by email or in-app. Your continued use after the effective date constitutes acceptance.

17. Contact Us

PaceBrain — Privacy Inquiries
Nicholas Patterson t/a Origae
ABN: 21 237 258 402 · Victoria, Australia
Email: support@pacebrain.app (subject line: "Privacy")

18. Governing Law

This Policy is governed by the laws of the State of Victoria, Australia. Nothing in this Policy limits any rights you have under applicable data-protection laws, including the Privacy Act 1988 (Cth), the GDPR/UK GDPR, or the CCPA/CPRA.