← Back to home

Privacy Policy

1. Information We Collect

When you create an account, we collect your name, email address, and basic profile information. When you connect Garmin Connect, we access your workouts, activity history, and — where Garmin supplies it — wellness data such as sleep, HRV, resting heart rate, and body-composition readings, as authorized by you. If the optional Strava connection is available to you and you enable it, we access Strava activity data to add coverage for workouts Garmin did not supply.

If you choose to add local weather to your training week, the browser may provide a location for that purpose, or you may enter a city or postcode. PaceBeats does not use an IP-address fallback and does not store your exact coordinates.

We also collect data you provide directly: race goals, training preferences, athlete notes, workout feedback (RPE, comments), schedule availability, saved route start points and route geometry, and messages you exchange with your coach.

If you choose to enable cycle awareness (Women's health), we store the menstrual-cycle information you provide or that Garmin syncs. This is strictly opt-in, off by default, and used only to add context to your plan.

2. How We Use Your Data

Your data is used to:

  • Shape personalized weekly schedules with an AI planning pass, then materialize and validate workouts with deterministic code and an authored workout library
  • Build and maintain your athlete profile and memory
  • Run AI assessments of your fitness and training patterns
  • Calculate training metrics (fitness, fatigue, form) and track progress
  • Sync workouts between PaceBeats and connected platforms
  • Send transactional and product emails (which you can control)
  • Operate, secure, and improve the platform

3. Data Storage & Security

Your data is stored in a PostgreSQL database with encryption in transit and at rest. Third-party access tokens (e.g. Garmin and Strava) are additionally encrypted at the application layer. Authentication uses secure, HTTP-only session cookies.

We do not sell your personal data or training data. Your athlete memory, workout feedback, and wellness data are used only to run your training experience.

4. Garmin Connect Data

Connecting Garmin is optional. PaceBeats receives only the Garmin data categories you authorize and that Garmin makes available to the integration. These may include activities, activity details, health and wellness summaries, body composition, women's health, and the ability to deliver supported planned workouts and, where enabled, courses to Garmin Connect.

We use Garmin data to calculate training load and recovery metrics, build your training history, personalize plans and assessments, provide coaching features, and deliver supported workouts or, where available, saved routes that you choose to send to Garmin. Garmin connection tokens are encrypted at the application layer. Imported Garmin data is stored with your PaceBeats training record for as long as needed to provide these features.

Disconnecting Garmin stops future synchronization and removes the stored connection credentials. Garmin-sourced data already incorporated into your PaceBeats training history is retained until you delete your PaceBeats account or ask us to delete it by contacting privacy@pacebeats.com. Deleting your PaceBeats account deletes the associated Garmin-sourced data together with the rest of your live account data. Restricted-access backup copies expire within 30 days and are not used for ordinary service operations. If a backup is restored during that period, our external erasure ledger automatically reapplies the deletion before the restored service takes traffic.

When an AI-assisted feature needs Garmin-derived context, PaceBeats sends only the relevant data to OpenAI or Anthropic for processing. These providers process it solely to return the requested coaching output. PaceBeats does not permit them to train their models on Garmin data. We do not sell Garmin data or share it for advertising.

Any material change to how PaceBeats collects, uses, processes, stores, or shares Garmin data will be submitted to the Garmin Connect Developer Program for written approval before implementation.

5. Third-Party Processors

We share data with a small set of service providers only as needed to run PaceBeats:

  • Garmin Connect — to import activities and available wellness data, and to sync supported planned workouts. The optional Strava connection, where available, imports activity data to fill coverage gaps. You can disconnect either service in Settings.
  • OpenAI and Anthropic — the AI models that power weekly schedule proposals, assessments, and coaching replies. Data sent to the models is used only for those features and is not used to train third-party models.
  • Stripe — to process subscription payments. Card details are handled by Stripe; we never see or store them.
  • Brevo — to deliver transactional and product emails.
  • PostHog — before you choose, we send only a narrow set of anonymous aggregate events (such as a fresh signup), using a new one-event identifier and no person profile. Accepting enables account-linked product analytics; declining or withdrawing stops future product analytics. Historical anonymous aggregate counts may remain.
  • Honeybadger — EU-hosted technical error monitoring that helps us fix failures.
  • Tomorrow.io and OpenStreetMap Nominatim — to provide optional local forecasts and place-name lookup. Weather coordinates are rounded to two decimal places (approximately one kilometre) before either processor is contacted. Reverse-geocoding for a location you select is rounded to four decimal places (approximately 11 metres). Requests are sent by PaceBeats servers, not directly by your browser. PaceBeats keeps weather results in browser memory for at most 30 minutes and does not persist weather coordinates or manual weather searches; memory is also cleared on logout or account deletion. The geocoding route does not cache lookup requests; a route start that you deliberately save remains in your route preferences until you change it or delete your account.

6. Your Rights

You have the right to:

  • Access and export your data — download a full JSON copy from Settings → Account & Billing.
  • Delete your account and all associated data — self-serve from the same page. Live-service deletion is effective immediately. Restricted-access backup copies expire within 30 days; a keyed pseudonymous erasure marker is retained solely to prevent deleted data from reappearing after a restore.
  • Disconnect third-party integrations at any time
  • Opt out of analytics cookies and control which emails you receive
  • Correct inaccurate profile information

You can also exercise any of these rights by contacting us at the address below.

7. Cookies

We use essential cookies for authentication and session management. Before you choose, PostHog receives only the documented anonymous aggregate signup/link counts, with no analytics cookie, stable user or account identifier, email, name, or person profile. Product-analytics cookies and account-linked events start only after you accept. Declining or withdrawing in Settings stops future product analytics and resets the browser analytics identity; historical anonymous aggregate counts may remain. We do not use advertising cookies.

8. Contact

For privacy-related questions or to exercise your rights, contact us at privacy@pacebeats.com.