Terms of Service & Privacy Policy
The legally authoritative text is currently provided in English.
Effective date: May 23, 2026
Last updated: August 28, 2026
Welcome to Paceback ("we," "our," or "us"). By creating an account or using our app and services (collectively, the "Service"), you agree to the following Terms of Service and Privacy Policy. If you do not agree, please do not use the Service.
This document contains both our Terms of Service and our Privacy Policy. Some features, such as analytics, are optional and require your explicit consent.
Terms of Service
1. Eligibility
- You must be at least 18 years old to use the Service.
- By signing up, you confirm that you are legally allowed to use the Service in your country.
- You are responsible for deciding whether an activity is appropriate for you, and for consulting a healthcare professional where that decision depends on a medical question.
2. Account registration
- You must provide accurate information when creating an account.
- You are responsible for maintaining the security of your account and password.
- You may sign in using your email and password, or through a supported third-party identity provider (such as Apple, Google, or Strava). When you sign in via a third-party provider, that provider processes basic account information (such as your name and email) to authenticate you. Your use of the third-party provider is also subject to their own terms and privacy policies.
3. Use of the service
- The Service allows you to log rehab activities, track progress, and receive AI-powered insights.
- You may not misuse the Service, upload harmful content, or attempt to disrupt it.
- You are solely responsible for verifying all information independently and consulting healthcare professionals before engaging in any exercise program.
- You must stop using the Service immediately if you experience any pain, injury, or adverse health effects.
- You must provide accurate information and not attempt to circumvent security measures.
3.1 Coach-Client Relationships
- Paceback enables connections between coaches and clients through explicit invitation and acceptance.
- Coaches may only access data of clients who have explicitly invited them or accepted their invitation.
- Coaches cannot access data of users who are not connected to them.
- Once connected, coaches can view client data within the app to provide coaching services. Where the client has granted full (non-view-only) access, the coach may also edit and analyze that data on the client's behalf. View-only coaches can see plans and progress but cannot modify them.
- Clients can revoke coach access, or change a coach's permission level, at any time through the app settings.
- Paceback is a platform that facilitates coach-client relationships but does not supervise, validate, or endorse coach decisions or interpretations of data.
- Coaches are responsible for how they interpret and act on client data.
- Physiotherapists and coaches are independently responsible for how they interpret and use data accessed through the Service, and for the clinical decisions they make. Paceback is responsible for providing the technical platform and for the data-sharing mechanism described in the Privacy Policy.
3.2 Account suspension and termination
We may remove content, restrict access, suspend, or terminate an account if we reasonably believe that the user has violated these Terms, misused the Service, created a security or safety risk, harmed other users, or used the Service for unlawful, fraudulent, abusive, or disruptive activity.
We may act without advance notice when prompt action is reasonably necessary. Where practical, we will tell the user why.
Personal data associated with a terminated account will be handled according to the Privacy Policy.
4. Medical disclaimer and AI limitations
Medical disclaimer
- Paceback is not intended for any medical purpose. It is not intended to diagnose, monitor, treat, alleviate, prevent, predict, or give a prognosis for any disease, injury, or disability.
- Paceback is not approved by the Swedish Medical Products Agency (Läkemedelsverket), FDA, CE-marked, or regulated as medical software in any jurisdiction.
- Paceback does not provide medical diagnosis, treatment, prescription, or professional medical advice.
- Paceback does not provide medical advice. Physiotherapists and coaches who use Paceback act independently: Paceback does not employ them, supervise them, or provide their services.
- This Service is purely software technology and is not a substitute for professional medical or fitness guidance.
- All content, including AI-generated content, is for informational and educational purposes only.
The Service does not replace medical guidance and does not replace Apple Health/HealthKit recommendations.
- You must consult qualified healthcare professionals (doctors, physiotherapists, certified trainers) before starting any exercise program.
- You must seek immediate medical attention if experiencing pain, injury, or health concerns.
- You must stop using the Service immediately if experiencing any adverse effects.
- We may use AI models to generate insights and suggestions based on your logged data.
- AI systems may analyze a user's data and, where applicable for coaches, data from connected clients to generate insights and suggestions.
- AI outputs are experimental, informational, and may contain errors or inaccuracies.
- There is no warranty or guarantee of accuracy, completeness, or reliability of AI-generated content.
- AI models may produce incorrect, incomplete, or inappropriate responses.
- AI technology is provided "as-is" without warranties.
- You must independently verify all AI-generated information.
- AI may not account for individual medical conditions, limitations, or contraindications.
- No automated decisions with legal or medical impact are made by AI systems.
- We do not perform automated decision-making under Article 22 GDPR.
- We are not liable for decisions made based on AI outputs.
- You acknowledge AI limitations and agree not to hold us liable for AI errors.
- To the maximum extent permitted by applicable law, we are not liable for injuries, health complications, or adverse effects resulting from use of the Service.
- You acknowledge you are using the Service at your own risk and assume all responsibility for your health and safety.
5. User content and data
- By using the Service, you grant us permission to process your content (such as logs, training plans, and user-generated content including images) in order to provide the Service.
- You may upload photos or images as part of your activities, training plans, or notes. These are user-generated content used only for displaying and organizing your activities or plans within the app.
- Photos and images are not used for advertising or tracking purposes.
- Photos and images are deleted when you delete the associated content or your account.
- You retain ownership of your content and can delete your account at any time. See more under "Data retention."
User-Generated Content
Paceback allows users to include limited free-text content in specific contexts, such as coach invite messages and notes attached to training plan updates ("User Content").
You are solely responsible for any User Content you create, submit, or share through the Service. You agree not to post content that is unlawful, abusive, harassing, threatening, misleading, or otherwise inappropriate.
Paceback does not pre-moderate User Content. However, we may remove User Content that violates these Terms or applicable laws and respond to reports of misuse. Account restrictions are described in section 3.2.
Users may end a coaching relationship at any time. Ending a relationship removes access to shared plans, notes, and future communications between the parties.
6. Third-party services
AI features may rely on third-party providers.
Where Paceback directly engages a service provider to process data on our behalf (such as hosting, infrastructure, or error monitoring providers), such providers act as data processors under our instructions and are bound by data processing agreements.
The providers we currently engage to process data on our behalf include: Supabase (database, authentication, file storage, and serverless functions), Netlify (web hosting and content delivery), Resend (transactional and authentication email delivery), Stripe (payment and subscription processing), OpenAI (AI-generated guidance), Sentry (error monitoring), PostHog (optional usage analytics), and Google Firebase (push notification delivery).
Using your own AI provider key
Some AI features can run on your own third-party API key (currently OpenAI). Connecting one is optional. If you choose to connect a key:
- We store your key encrypted in a dedicated secrets store and use it only to make AI requests for your own account.
- Our servers make those requests, and we decide what information from your account is included in each one — the same processing described in the Privacy Policy for AI features generally. Connecting your own key changes which account the request is billed to, not what we send or why.
- Because the request runs under your own account with the provider, that provider's handling and retention of the data in the request is governed by your agreement with them rather than by our data processing agreement with them. Their terms may differ from ours, including on how long they keep request content.
- Any associated costs are between you and the provider.
- You can remove your key at any time in the app settings. Removing it stops all further requests made with it.
Crash and error monitoring tools (such as Sentry) are used to detect and fix technical issues. These tools may process limited technical data such as device information, app version, error logs, and a pseudonymous user identifier (your account ID) to allow us to correlate errors with accounts for debugging and to fulfil data access requests. We configure such tools to minimize the collection of personal data and to avoid the intentional transmission of health or journal content in error logs. Error monitoring is a required part of the Service to maintain stability and reliability and does not require your consent (legal basis: legitimate interests under Article 6(1)(f) GDPR).
Analytics tools (such as PostHog) are used to collect limited, pseudonymous usage data such as feature interactions and navigation patterns. Analytics is optional and only enabled if you explicitly opt in. When enabled, a pseudonymous user identifier (your Supabase account ID) is included to support account-level consent management. You can manage this under "Analytics & data" in the app settings.
Analytics providers only process limited usage data and do not receive health, training, or journal data.
Push notifications are delivered through Firebase Cloud Messaging, a Google service. When you enable notifications, your device's push token and the content of any messages we send to you are processed by Firebase in order to deliver them to your device. You can disable notifications at any time in the app settings or in your device's system settings.
These services operate under their own terms and privacy policies. We are not responsible for how they handle your data.
Apple disclaimer: Apple is not responsible for the Service or its content. The Service is not affiliated with, endorsed by, or sponsored by Apple.
Not all listed third-party integrations are currently active or available in the Service. Availability may change over time.
Health data integrations
Paceback may integrate with health and fitness services including:
- Strava (running activity tracking)
- Apple Health / HealthKit (iOS health data)
- Withings (biometrics and activity data)
Additional integrations may become available in the future. An integration only processes your data once you explicitly connect it, and you can disconnect it at any time in the app settings.
- Each integration operates under its own terms and privacy policies.
- Health data synced from third parties is subject to those providers' data handling practices.
- We process but do not control third-party health data accuracy.
- By connecting these services, you grant us permission to sync and process health data from connected services.
- You can disconnect integrations at any time through the app settings.
- We are not responsible for third-party health data accuracy or availability.
- Health data may be used for AI analysis and plan adaptation.
International data transfers
Some of our service providers (such as hosting, AI infrastructure, or error monitoring providers) may process personal data outside the European Union (EU) or European Economic Area (EEA).
Where transfers outside the EU/EEA occur, we ensure appropriate safeguards are implemented in accordance with Chapter V GDPR. Such safeguards may include European Commission Standard Contractual Clauses (SCCs) or equivalent legally approved mechanisms.
You may request further information about applicable safeguards by contacting us.
7. Notifications and communications
- The app may send motivational messages, reminders, and insights via push notifications, email, or in-app messages.
- You can manage or disable notifications in the app's settings.
- These communications are optional and do not replace professional medical guidance.
7.1 Support and feedback communications
If you contact us through the "Support and feedback" feature in the app, we may store the information you provide, including your message, account email, and related metadata such as timestamps.
These communications may be reviewed by our team in order to respond to your request, provide technical support, investigate issues, and improve the Service.
Support communications are used only for support, service improvement, and troubleshooting purposes and are not used for advertising or marketing.
8. Limitation of liability
- To the maximum extent permitted by applicable law, our liability is limited to direct damages only.
- We are not liable for any indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill.
- We are not liable for any injuries, health complications, medical issues, or adverse effects resulting from your use of the Service.
- We are not liable for any errors, inaccuracies, or failures of AI-generated content or third-party services.
- We are not liable for any loss or damage resulting from your failure to consult healthcare professionals or follow medical advice.
- Some jurisdictions do not allow the exclusion of certain warranties or limitations of liability, so some of the above limitations may not apply to you.
- To the extent permitted by applicable law, our total aggregate liability arising out of or in connection with the Service shall not exceed the total amount paid by you to Paceback for the Service during the twelve (12) months preceding the event giving rise to the claim.
- Nothing in these Terms limits or excludes liability that cannot be limited or excluded under mandatory Swedish law or EU consumer protection law, including liability for intent or gross negligence.
9. Disclaimer of warranties
- The Service is provided "as-is" and "as-available" without warranties of any kind, either express or implied.
- We disclaim all warranties, including but not limited to warranties of merchantability, fitness for a particular purpose, accuracy, completeness, or reliability.
- We do not warrant that the Service will be uninterrupted, error-free, secure, or free from viruses or other harmful components.
- You acknowledge that you use the Service at your own risk and that there are inherent risks in using technology and AI systems.
- Where applicable, Swedish Sale of Goods Act (Köplagen) applies.
- Nothing in these Terms limits or excludes liability that cannot be limited or excluded under mandatory Swedish law or EU consumer protection law, including liability for intent or gross negligence.
10. Indemnification
- You agree to indemnify, defend, and hold harmless Paceback, its operators, and affiliates from any claims, damages, losses, liabilities, and expenses (including legal fees) arising from:
- Your use of the Service
- Your violation of these Terms
- Your violation of any third-party rights
- Any injuries, health complications, or medical issues resulting from your use of the Service
- This indemnification obligation is subject to limitations under Swedish law.
- Nothing in these Terms limits or excludes liability that cannot be limited or excluded under mandatory Swedish law or EU consumer protection law, including liability for intent or gross negligence.
11. Force majeure
- We are not liable for any failure or delay in performance due to circumstances beyond our reasonable control, including but not limited to natural disasters, pandemics, acts of war, terrorism, cyber attacks, internet failures, third-party service failures, or government actions.
- Swedish force majeure principles apply.
12. Dispute resolution and governing law
- These Terms are governed by Swedish law (Svensk lag).
- Any disputes arising from these Terms or your use of the Service shall be subject to the exclusive jurisdiction of Swedish courts (Sveriges domstolar), specifically the courts of Stockholm.
- If you are a consumer, you may refer a dispute to the Swedish National Board for Consumer Disputes (Allmänna reklamationsnämnden, ARN — arn.se). You may also contact the Swedish Consumer Agency (Konsumentverket) for guidance, or, if you live in another EU country, your local European Consumer Centre (ECC).
- We encourage resolving disputes through direct communication before pursuing legal action.
13. Contact
If you have any questions about these terms or your data, please contact us at: support@paceback.com
For data protection inquiries, you may also contact the Swedish Data Protection Authority (Integritetsskyddsmyndigheten/IMY) or your local EU supervisory authority.
Privacy Policy
1. Data controller
Paceback is the data controller for the Service.
Contact email: support@paceback.com
2. Data Protection Officer
We have not appointed a Data Protection Officer (DPO) as we are not required to do so under Article 37 GDPR.
3. Data we collect
We collect the following data to operate and improve the Service:
- Account details: name, email, profile picture (if uploaded)
- Activity data: rehab logs, training goals, running distances, exercise completions
- Health data: activity metrics, biometrics, and workout data synced from the health services you choose to connect. Available integrations are listed in the Terms of Service and may change over time.
- Wellbeing data: pain ratings, energy levels, sleep quality (if logged)
- Journal entries: personal reflections and notes (if provided)
- AI memory entries: short, structured facts (such as goals, constraints, or preferences) that our AI features may infer from your onboarding answers, chat messages, and journal entries in order to personalize the Service. Memory entries are stored as concise text values, not copies of the underlying conversation or journal content.
- Device data: IP address, device type, and limited app usage data (such as feature interactions), if analytics is enabled
- Analytics data (optional): pseudonymous usage patterns such as features used, navigation flow, and interaction frequency, linked to your account identifier. This data is only collected if you explicitly opt in to analytics, and never includes health, training, or journal content.
- Technical and diagnostic data: error logs, crash reports, device type, app version, and limited technical identifiers collected to maintain service stability.
- Support communications: messages sent through the Support and feedback feature, including the message content, account email, and timestamps.
We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.
4. How we use your data
Your data helps us:
- Provide and personalize the app experience
- Generate AI-based feedback, progress tracking, and adaptive training plan suggestions, including by storing short structured "memory" entries that the AI infers from your inputs (see section 6)
- Sync and process health data from connected third-party services
- Improve our services and app functionality
- Send notifications, reminders, and motivational messages (if enabled)
- Respond to support requests and feedback submitted through the Support and feedback feature
- Analyze pseudonymous usage patterns to understand how the app is used and identify areas for improvement (only if you have opted in to analytics)
We do not use health or fitness data for advertising, marketing, ad profiling, data brokerage, or selling personal data.
We process user-generated text (such as invite messages and plan notes) solely to provide the coaching features of the Service and do not use this content for advertising purposes.
Legal basis for processing (GDPR):
- Account creation and core service delivery: performance of a contract (Article 6(1)(b) GDPR)
- Security, fraud prevention, and service reliability: legitimate interests (Article 6(1)(f) GDPR)
- Handling support requests and user feedback: legitimate interests (Article 6(1)(f) GDPR) to provide assistance, troubleshoot issues, and improve the Service.
- Optional analytics: consent (Article 6(1)(a) GDPR). Analytics data is only collected if you explicitly opt in. You may withdraw consent at any time under "Analytics & data" in the app settings.
- Health and wellbeing data (including activity metrics, pain ratings, sleep, energy levels, and data synced from health services you connect) constitute special category personal data under Article 9 GDPR. We process such data solely based on your explicit consent (Article 9(2)(a) GDPR in conjunction with Article 6(1)(a)). Consent is obtained through a clear affirmative action within the app before health data processing begins. You may withdraw your consent at any time through the app settings or by contacting us. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. If you withdraw consent to health data processing, certain features of the Service may no longer function as intended.
Sharing with a physiotherapist or coach: connecting with a professional gives them access to your rehabilitation data in order to support your recovery. That includes your training plans, your daily check-ins, your pain ratings, and activities synced from any health or training service you connect. You choose whether to accept an invitation, and you can end the connection at any time in the app settings.
Your written notes are shared with a professional you connect to. The notes you write in your journal check-in, and any note you add to a pain entry, are part of the record a connected physiotherapist or coach can read — the same as your pain ratings and how you felt. They describe how your training and recovery are going, which is what your professional needs in order to help you between appointments. Our AI features do not use the text of your notes in anything generated for a professional. Your conversations with Paceback’s AI, and anything it remembers about you, are never shared with a professional.
We process only the personal data necessary to provide and improve the Service in accordance with the principle of data minimization under Article 5(1)(c) GDPR.
5. Analytics and usage data
Paceback offers optional, pseudonymous usage analytics to help us understand how the app is used and where we can improve.
- Analytics is disabled by default and is only collected if you explicitly opt in.
- Analytics data includes feature usage patterns, navigation flow, and interaction frequency. It does not include health data, training logs, journal entries, or directly identifiable information such as your name or email address.
- Analytics data is processed by third-party analytics providers (such as PostHog) and includes a pseudonymous identifier — your account identifier — so that we can honour your consent and opt-out choices at the account level. Because this identifier is tied to your account, analytics data is pseudonymous rather than anonymous, and it remains personal data under GDPR.
- We do not collect your IP address or approximate location for analytics purposes.
- You can enable or disable analytics at any time under "Analytics & data" in the app settings.
- Disabling analytics stops further collection immediately. Analytics data already collected is retained by our analytics provider for that provider's retention period; because it is pseudonymous rather than anonymous, you can ask us to delete it, and we will.
6. AI memory
To personalize AI-generated feedback and training plan suggestions, our AI features may store short, structured "memory" entries about you. Each entry consists of a category (such as goal, constraint, or preference), a short label, and a brief value.
- Memory entries are derived from sources you provide to the Service, such as onboarding answers, chat messages with the AI, and journal entries.
- We do not store copies of the underlying conversation or journal content as part of a memory entry; only the concise, structured value the AI extracts.
- Memory entries are only used to personalize the Service for you, including AI suggestions and reminders. They are not used for advertising, profiling for third parties, or sold to anyone.
- You can review, edit, or delete your AI memory entries at any time under "Memory" in account settings. Deleting an entry stops it from being used in future AI personalization.
- Where AI memory is derived from health, wellbeing, or journal content, it is processed on the same legal basis as the underlying data (explicit consent for special category data under Article 9(2)(a) GDPR; performance of contract or legitimate interests otherwise).
7. Data retention
- We keep your personal data only as long as necessary to provide the Service, and for as long as your account remains active.
- Deleting your account starts a 14-day recovery period, during which your account is deactivated and inaccessible but can still be restored if you change your mind or deleted it in error. After that period ends, your account and its personal data are permanently deleted from our primary systems.
- If we terminate an account, we follow the same deletion and retention rules described in this section, except where limited information must be retained for security, legal obligations, or legal claims.
- Some data necessarily persists for a limited time after deletion:
- Encrypted backups are retained on a rolling schedule and are overwritten in the normal course of operation. We do not restore individual records from backups in order to fulfil a deletion request.
- Billing and payment records are retained where Swedish accounting law requires it, even after account deletion.
- Email delivery logs and technical error reports are retained for a limited period by our email and error-monitoring providers.
- Analytics data, if you opted in, is retained by our analytics provider for its retention period. You may ask us to delete it.
- We may also retain data where required by law or for the establishment or defence of legal claims.
8. Your rights and choices
You have the right to:
- Access, correct, or delete your data
- Request a copy of your data
- Opt out of optional communications
- Enable or disable optional analytics at any time
- Review, edit, or delete individual AI memory entries under "Memory" in account settings
- Turn off the use of synced device vitals for AI personalization at any time
- End a connection with a physiotherapist or coach at any time
These settings can be managed within the app under "Analytics & data", "Health data", "Memory", "Download my data", and "Delete account" in the settings menu, or by contacting us. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
9. Security
- We take reasonable steps to protect your data using industry-standard security measures including encryption, secure storage, and access controls.
- However, no system is 100% secure, and we cannot guarantee absolute security.
- You acknowledge inherent security risks in using online services.
- In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Swedish Data Protection Authority (Integritetsskyddsmyndigheten/IMY) within 72 hours and affected users without undue delay.
- You are responsible for maintaining account security, using strong passwords, and logging out when using shared devices.
- If you suspect a security breach, please contact us immediately.
10. Updates to this policy
- We may update these terms and privacy policy from time to time.
- You will be notified of significant changes and may be required to accept the new version to continue using the Service.