Privacy Policy
DRAFT — ATTORNEY REVIEW REQUIRED BEFORE PUBLICATION
This policy is a structured draft based on Pacecraft™’s planned health-app practices. It contains bracketed items that must be confirmed before publication. Health information is sensitive, and this document must match the app’s actual data flows, service providers, and store disclosures.
The short version
Pacecraft™ collects health information because it cannot run an exercise protocol without it. We use that information to run your program and build reports you choose to share. We do not sell it, use it for advertising, or share it except with service providers that help operate the app. You can see, export, and delete what we hold.
1. Who we are
Pacecraft™ is operated by [LEGAL ENTITY NAME], [ENTITY TYPE], located at [ADDRESS].
For users in the UK and EU, our data controller is [ENTITY]. Contact: [PRIVACY EMAIL].
2. Information we collect
Health information you give us may include safety and post-exertional malaise screening answers; symptom scores; hypermobility flags; medication information including beta-blocker use; clinician-prescribed targets; and session records.
With permission, we may receive heart-rate and workout data from [Apple Health / Google Health Connect / wearable — CONFIRM]. We may also collect account details, device and app diagnostics, and purchase confirmation from Apple or Google. We do not receive or store card details.
We do not collect precise location, contacts, photos, microphone or camera input, or advertising identifiers. [CONFIRM].
3. Why we use it
We use information to determine which protocol fits, track your week, set session targets, apply adherence rules, assess red flags and post-exertional malaise, produce clinician reports you choose to export, send reminders, generate a calendar feed, and diagnose crashes or errors.
For UK and EU users, health data is special category data. The lawful basis and consent mechanics require counsel confirmation.
4. What we never do
We do not sell your information. We do not use health information for advertising or permit anyone else to. We do not share it with employers, insurers, or data brokers. We do not use health information to train machine-learning models. [CONFIRM all statements before publication.]
5. Who we share it with
We share information only with service providers that help operate Pacecraft™, and only what they need: [CLOUD HOST] stores account data; [CRASH REPORTING] receives device and error information; [EMAIL PROVIDER] receives your email address; [PUSH SERVICE] receives device tokens and notification content; Apple and Google process purchases and deliver the app. Each provider must be confirmed and named before publication.
Anything you export and send to a clinician leaves our control. Once you share a report, its handling is between you and the recipient.
6. Your calendar feed and health integrations
If you subscribe to a Pacecraft™ calendar feed, your schedule is delivered through a private URL. Anyone who obtains that URL can see the schedule, so treat it like a password. You can regenerate it in settings, which invalidates the old one. Calendar providers may copy the feed to their own servers; use in-app reminders if you prefer session information not leave the app.
If you connect [Apple Health / Health Connect], Pacecraft™ reads only the data types you approve for the described purposes. You can revoke access in device settings.
7. Storage, retention, and security
Your data is stored [ON YOUR DEVICE ONLY / on servers located in REGION — CONFIRM]. We keep information while your account is active. If you delete your account, we delete your data within [30 days], except where recordkeeping requires longer retention. Backups are purged on a [X-day] cycle.
We use [encryption in transit and at rest, access controls, and audit logging — CONFIRM]. No system is perfectly secure; if a breach affects health information, we will notify users and regulators as required by law.
8. Your rights
You can ask us to show, correct, export, or delete what we hold. We do not charge for this or require a reason. Use [PRIVACY EMAIL] or controls in the app. We respond within 45 days and will tell you if we need longer.
Washington, California, UK, and EU residents may have additional rights. These rights and the relevant response procedures require legal confirmation before publication.
9. Children, changes, and contact
Pacecraft™ is not intended for children under 13. If we learn we collected information from a child under 13, we will delete it. If you are between 13 and 18, we ask that a parent or guardian take part in setup. [CONFIRM policy.]
If we change how we use health information, we will provide notice before the change takes effect and seek consent where required. Contact: [PRIVACY EMAIL] · [POSTAL ADDRESS].
Washington Consumer Health Data Privacy Policy — Draft
This standalone policy is provided under the Washington My Health My Data Act and applies to consumers in Washington State.
Pacecraft™ may collect symptoms and severity scores, PEM screening responses, medication information, diagnosed conditions including hypermobility, heart-rate and exertion data, session records, and bodily-function or vital-sign data. The purposes are screening for contraindications, matching to a protocol, tracking response, applying modifications, setting targets, and generating reports at the consumer’s request.
Sources are the consumer and, where permission is granted, the consumer’s device or connected health application. Categories of sharing, specific affiliates, appeal contact, and service providers must be completed before publication.
Washington consumers may request confirmation, access, consent withdrawal, and deletion through [PRIVACY EMAIL] or [WEB FORM]. If a request is denied, you may appeal through [APPEAL CONTACT]. We do not sell consumer health data. [CONFIRM.]