Privacy Policy

The legally authoritative text is currently provided in English.

Effective date: May 23, 2026

Last updated: August 1, 2026

1. Data controller

Paceback is operated by Oscar Linger, an individual trader (enskild näringsverksamhet) registered in Sweden.

Registered address: Rålambsvägen 48, Stockholm, Sweden
Contact email: support@paceback.com

2. Data Protection Officer

We have not appointed a Data Protection Officer (DPO) as we are not required to do so under Article 37 GDPR.

3. Data we collect

We collect the following data to operate and improve the Service:

  • Account details: name, email, profile picture (if uploaded)
  • Activity data: rehab logs, training goals, running distances, exercise completions
  • Health data: activity metrics, biometrics, workout data synced from connected health services (Strava, Apple Health, Garmin, Withings)
  • Wellbeing data: pain ratings, energy levels, sleep quality (if logged)
  • Journal entries: personal reflections and notes (if provided)
  • AI memory entries: short, structured facts (such as goals, constraints, or preferences) that our AI features may infer from your onboarding answers, chat messages, and journal entries in order to personalize the Service. Memory entries are stored as concise text values, not copies of the underlying conversation or journal content.
  • Device data: IP address, device type, and limited app usage data (such as feature interactions), if analytics is enabled
  • Analytics data (optional): anonymous usage patterns such as features used, navigation flow, and interaction frequency. This data is only collected if you explicitly opt in to analytics.
  • Technical and diagnostic data: error logs, crash reports, device type, app version, and limited technical identifiers collected to maintain service stability.
  • Support communications: messages sent through the Support and feedback feature, including the message content, account email, and timestamps.

We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.

4. How we use your data

Your data helps us:

  • Provide and personalize the app experience
  • Generate AI-based feedback, progress tracking, and adaptive training plan suggestions, including by storing short structured "memory" entries that the AI infers from your inputs (see section 6)
  • Sync and process health data from connected third-party services
  • Improve our services and app functionality
  • Send notifications, reminders, and motivational messages (if enabled)
  • Respond to support requests and feedback submitted through the Support and feedback feature
  • Analyze anonymized usage patterns to understand how the app is used and identify areas for improvement (only if analytics is enabled)

We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.

We process user-generated text (such as invite messages and plan notes) solely to provide the coaching features of the Service and do not use this content for advertising purposes.

Legal basis for processing (GDPR):

  • Account creation and core service delivery: performance of a contract (Article 6(1)(b) GDPR)
  • Security, fraud prevention, and service reliability: legitimate interests (Article 6(1)(f) GDPR)
  • Handling support requests and user feedback: legitimate interests (Article 6(1)(f) GDPR) to provide assistance, troubleshoot issues, and improve the Service.
  • Optional analytics: consent (Article 6(1)(a) GDPR). Analytics data is only collected if you explicitly opt in. You may withdraw consent at any time under "Analytics & data" in the app settings.
  • Health and wellbeing data (including activity metrics, pain ratings, sleep, energy levels, and data synced from Apple Health, Strava, Garmin, Withings or similar services) constitute special category personal data under Article 9 GDPR. We process such data solely based on your explicit consent (Article 9(2)(a) GDPR in conjunction with Article 6(1)(a)). Consent is obtained through a clear affirmative action within the app before health data processing begins. You may withdraw your consent at any time through the app settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. If you withdraw consent to health data processing, certain features of the Service may no longer function as intended.

Coach-client data sharing: When you connect with a coach, you control what data is shared. This sharing is based on your explicit consent and is managed through the app settings.

We process only the personal data necessary to provide and improve the Service in accordance with the principle of data minimization under Article 5(1)(c) GDPR.

5. Analytics and usage data

Paceback offers optional, anonymous usage analytics to help us understand how the app is used and where we can improve.

  • Analytics is disabled by default and only enabled if you explicitly opt in.
  • Analytics data includes feature usage patterns, navigation flow, and interaction frequency. It does not include health data, training logs, journal entries, or any directly identifiable information such as name or email address.
  • Analytics data is processed by third-party analytics providers (such as PostHog). When enabled, a pseudonymous user identifier (your account ID) is included to support account-level consent and opt-out.
  • You can enable or disable analytics at any time under "Analytics & data" in the app settings.
  • Disabling analytics immediately stops data collection. Previously collected anonymous data cannot be linked back to you.

6. AI memory

To personalize AI-generated feedback and training plan suggestions, our AI features may store short, structured "memory" entries about you. Each entry consists of a category (such as goal, constraint, or preference), a short label, and a brief value.

  • Memory entries are derived from sources you provide to the Service, such as onboarding answers, chat messages with the AI, and journal entries.
  • We do not store copies of the underlying conversation or journal content as part of a memory entry; only the concise, structured value the AI extracts.
  • Memory entries are only used to personalize the Service for you, including AI suggestions and reminders. They are not used for advertising, profiling for third parties, or sold to anyone.
  • You can review, edit, or delete your AI memory entries at any time under "Memory" in account settings. Deleting an entry stops it from being used in future AI personalization.
  • Where AI memory is derived from health, wellbeing, or journal content, it is processed on the same legal basis as the underlying data (explicit consent for special category data under Article 9(2)(a) GDPR; performance of contract or legitimate interests otherwise).

7. Data retention

  • We store your data only as long as necessary to provide the Service.
  • If you delete your account, all personal data will be permanently removed within 30 days.
  • We may retain certain data where required by law or for legitimate business purposes (such as accounting or dispute resolution).

8. Your rights and choices

You have the right to:

  • Access, correct, or delete your data
  • Request a copy of your data
  • Opt out of optional communications
  • Enable or disable optional analytics at any time
  • Review, edit, or delete individual AI memory entries under "Memory" in account settings

These settings can be managed within the app, including under "Analytics & data" and "Memory" in the settings menu, or by contacting us.

9. Security

  • We take reasonable steps to protect your data using industry-standard security measures including encryption, secure storage, and access controls.
  • However, no system is 100% secure, and we cannot guarantee absolute security.
  • You acknowledge inherent security risks in using online services.
  • In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Swedish Data Protection Authority (Integritetsskyddsmyndigheten/IMY) within 72 hours and affected users without undue delay.
  • You are responsible for maintaining account security, using strong passwords, and logging out when using shared devices.
  • If you suspect a security breach, please contact us immediately.

10. Updates to this policy

  • We may update these terms and privacy policy from time to time.
  • You will be notified of significant changes and may be required to accept the new version to continue using the Service.
    Loading paceback