Privacy Policy

The legally authoritative text is currently provided in English.

Effective date: May 23, 2026

Last updated: August 28, 2026

1. Data controller

Paceback is the data controller for the Service.

Contact email: support@paceback.com

2. Data Protection Officer

We have not appointed a Data Protection Officer (DPO) as we are not required to do so under Article 37 GDPR.

3. Data we collect

We collect the following data to operate and improve the Service:

  • Account details: name, email, profile picture (if uploaded)
  • Activity data: rehab logs, training goals, running distances, exercise completions
  • Health data: activity metrics, biometrics, and workout data synced from the health services you choose to connect. Available integrations are listed in the Terms of Service and may change over time.
  • Wellbeing data: pain ratings, energy levels, sleep quality (if logged)
  • Journal entries: personal reflections and notes (if provided)
  • AI memory entries: short, structured facts (such as goals, constraints, or preferences) that our AI features may infer from your onboarding answers, chat messages, and journal entries in order to personalize the Service. Memory entries are stored as concise text values, not copies of the underlying conversation or journal content.
  • Device data: IP address, device type, and limited app usage data (such as feature interactions), if analytics is enabled
  • Analytics data (optional): pseudonymous usage patterns such as features used, navigation flow, and interaction frequency, linked to your account identifier. This data is only collected if you explicitly opt in to analytics, and never includes health, training, or journal content.
  • Technical and diagnostic data: error logs, crash reports, device type, app version, and limited technical identifiers collected to maintain service stability.
  • Support communications: messages sent through the Support and feedback feature, including the message content, account email, and timestamps.

We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.

4. How we use your data

Your data helps us:

  • Provide and personalize the app experience
  • Generate AI-based feedback, progress tracking, and adaptive training plan suggestions, including by storing short structured "memory" entries that the AI infers from your inputs (see section 6)
  • Sync and process health data from connected third-party services
  • Improve our services and app functionality
  • Send notifications, reminders, and motivational messages (if enabled)
  • Respond to support requests and feedback submitted through the Support and feedback feature
  • Analyze pseudonymous usage patterns to understand how the app is used and identify areas for improvement (only if you have opted in to analytics)

We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.

We process user-generated text (such as invite messages and plan notes) solely to provide the coaching features of the Service and do not use this content for advertising purposes.

Legal basis for processing (GDPR):

  • Account creation and core service delivery: performance of a contract (Article 6(1)(b) GDPR)
  • Security, fraud prevention, and service reliability: legitimate interests (Article 6(1)(f) GDPR)
  • Handling support requests and user feedback: legitimate interests (Article 6(1)(f) GDPR) to provide assistance, troubleshoot issues, and improve the Service.
  • Optional analytics: consent (Article 6(1)(a) GDPR). Analytics data is only collected if you explicitly opt in. You may withdraw consent at any time under "Analytics & data" in the app settings.
  • Health and wellbeing data (including activity metrics, pain ratings, sleep, energy levels, and data synced from health services you connect) constitute special category personal data under Article 9 GDPR. We process such data solely based on your explicit consent (Article 9(2)(a) GDPR in conjunction with Article 6(1)(a)). Consent is obtained through a clear affirmative action within the app before health data processing begins. You may withdraw your consent at any time through the app settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. If you withdraw consent to health data processing, certain features of the Service may no longer function as intended.

Sharing with a physiotherapist or coach: connecting with a professional gives them access to your rehabilitation data in order to support your recovery. That includes your training plans, your daily check-ins, your pain ratings, and activities synced from any health or training service you connect. You choose whether to accept an invitation, and you can end the connection at any time in the app settings.

Your written notes are shared with a professional you connect to. The notes you write in your journal check-in, and any note you add to a pain entry, are part of the record a connected physiotherapist or coach can read — the same as your pain ratings and how you felt. They describe how your training and recovery are going, which is what your professional needs in order to help you between appointments. Our AI features do not use the text of your notes in anything generated for a professional. Your conversations with Paceback’s AI, and anything it remembers about you, are never shared with a professional.

We process only the personal data necessary to provide and improve the Service in accordance with the principle of data minimization under Article 5(1)(c) GDPR.

5. Analytics and usage data

Paceback offers optional, pseudonymous usage analytics to help us understand how the app is used and where we can improve.

  • Analytics is disabled by default and is only collected if you explicitly opt in.
  • Analytics data includes feature usage patterns, navigation flow, and interaction frequency. It does not include health data, training logs, journal entries, or directly identifiable information such as your name or email address.
  • Analytics data is processed by third-party analytics providers (such as PostHog) and includes a pseudonymous identifier — your account identifier — so that we can honour your consent and opt-out choices at the account level. Because this identifier is tied to your account, analytics data is pseudonymous rather than anonymous, and it remains personal data under GDPR.
  • We do not collect your IP address or approximate location for analytics purposes.
  • You can enable or disable analytics at any time under "Analytics & data" in the app settings.
  • Disabling analytics stops further collection immediately. Analytics data already collected is retained by our analytics provider for that provider's retention period; because it is pseudonymous rather than anonymous, you can ask us to delete it, and we will.

6. AI memory

To personalize AI-generated feedback and training plan suggestions, our AI features may store short, structured "memory" entries about you. Each entry consists of a category (such as goal, constraint, or preference), a short label, and a brief value.

  • Memory entries are derived from sources you provide to the Service, such as onboarding answers, chat messages with the AI, and journal entries.
  • We do not store copies of the underlying conversation or journal content as part of a memory entry; only the concise, structured value the AI extracts.
  • Memory entries are only used to personalize the Service for you, including AI suggestions and reminders. They are not used for advertising, profiling for third parties, or sold to anyone.
  • You can review, edit, or delete your AI memory entries at any time under "Memory" in account settings. Deleting an entry stops it from being used in future AI personalization.
  • Where AI memory is derived from health, wellbeing, or journal content, it is processed on the same legal basis as the underlying data (explicit consent for special category data under Article 9(2)(a) GDPR; performance of contract or legitimate interests otherwise).

7. Data retention

  • We keep your personal data only as long as necessary to provide the Service, and for as long as your account remains active.
  • Deleting your account starts a 14-day recovery period, during which your account is deactivated and inaccessible but can still be restored if you change your mind or deleted it in error. After that period ends, your account and its personal data are permanently deleted from our primary systems.
  • If we terminate an account, we follow the same deletion and retention rules described in this section, except where limited information must be retained for security, legal obligations, or legal claims.
  • Some data necessarily persists for a limited time after deletion:
    • Encrypted backups are retained on a rolling schedule and are overwritten in the normal course of operation. We do not restore individual records from backups in order to fulfil a deletion request.
    • Billing and payment records are retained where Swedish accounting law requires it, even after account deletion.
    • Email delivery logs and technical error reports are retained for a limited period by our email and error-monitoring providers.
    • Analytics data, if you opted in, is retained by our analytics provider for its retention period. You may ask us to delete it.
  • We may also retain data where required by law or for the establishment or defence of legal claims.

8. Your rights and choices

You have the right to:

  • Access, correct, or delete your data
  • Request a copy of your data
  • Opt out of optional communications
  • Enable or disable optional analytics at any time
  • Review, edit, or delete individual AI memory entries under "Memory" in account settings
  • Turn off the use of synced device vitals for AI personalization at any time
  • End a connection with a physiotherapist or coach at any time

These settings can be managed within the app under "Analytics & data", "Health data", "Memory", "Download my data", and "Delete account" in the settings menu, or by contacting us. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).

9. Security

  • We take reasonable steps to protect your data using industry-standard security measures including encryption, secure storage, and access controls.
  • However, no system is 100% secure, and we cannot guarantee absolute security.
  • You acknowledge inherent security risks in using online services.
  • In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Swedish Data Protection Authority (Integritetsskyddsmyndigheten/IMY) within 72 hours and affected users without undue delay.
  • You are responsible for maintaining account security, using strong passwords, and logging out when using shared devices.
  • If you suspect a security breach, please contact us immediately.

10. Updates to this policy

  • We may update these terms and privacy policy from time to time.
  • You will be notified of significant changes and may be required to accept the new version to continue using the Service.