Privacy policy
This page says what pacing.tools holds about you and what happens to it. Questions go to hi@pacing.tools.
1. What we hold
Your account: email address, sign-in method (Google, or a link and code sent to your email) and the date you joined. If you sign in with Google, Google shares your email, name and profile picture; we use the email.
Your profile: your name if you add it, your units, training values such as zones and VDOT, your goal race, and anything else you choose to store there.
Your training and health data: activities, laps, heart rate, sleep, resting heart rate and similar wellness signals. They come from a watch account you connect (Garmin, COROS) or from files you upload (FIT, GPX, TCX, a Strava export). Your activity history from Strava is imported only from files you upload yourself; we do not connect to your Strava account or use its API.
Files you upload are kept as you sent them, so an import can be repeated. They may contain your GPS route.
For a connected watch account we hold the access tokens that provider issues, encrypted. We never hold your password for that account.
Your connectors: a label, the client it is for, when it was created and last used. The key itself is stored hashed, so we cannot read it back.
Usage counts, such as calls and imports per day, to enforce caps and spot abuse. Bug reports if you send one, with your text and the email you choose to give. Technical logs with the IP address and request line. The connector’s own log records which tool ran and any error, never your question or the data returned.
2. Why, and on what basis
We use this data to run the service, show you your training, let your own AI read it through a connector you create, keep the service safe and answer your requests.
Account, profile, connector and usage data are processed because they are needed to perform the service you asked for. Heart rate, sleep and the other wellness signals are health data, and we process them only with your explicit consent. You give it by connecting a source or uploading a file, after a line at that point that says what is shared. Disconnecting a source stops new data from arriving. You withdraw consent by deleting the data or your account, and withdrawing does not affect the lawfulness of what was processed before. Logs and usage counts rest on our legitimate interest in keeping the service safe.
None of it is a legal requirement. Without your training data the site has nothing to show you.
3. Where it is kept
On a server in Germany under our control, in a database and files. The hosting provider keeps a daily snapshot of the server, in the EU.
4. Who else sees it
Your own AI client reads your data over a connector you create. Connecting a client allows its provider to receive the training and health data the connector returns. Revoking the connector stops future reads; it does not erase copies the provider already holds. Which client you use is your choice, and its own terms apply to what it does with your data.
Providers that work for us, bound to our instructions by contract:
- Hetzner, Germany, hosts the server and its snapshots.
- Google, United States, signs you in if you choose Google.
- Resend, United States, delivers the sign-in emails.
Where a provider is outside the EU, the transfer rests on the EU-US Data Privacy Framework where the provider is certified, or on the standard contractual clauses in its terms.
We do not sell your data, we do not use it to train any model, and there is no advertising.
5. Cookies and analytics
Four technical cookies, for your session only. Your preferences stay in your browser. Analytics is self-hosted, sets no cookies and stores no IP address; visits are counted with a hash that changes every day, so nothing follows you from one day to the next. No cookie banner is shown.
6. How long
Until you delete it. Deletion is self-serve from your account and removes your account, data, files, connectors and sign-in at once. Server snapshots expire after seven days, so deleted data can survive in one for up to a week. Usage counts are kept for 400 days. Technical logs are kept for 30 days.
7. Your rights
You can ask for access to your data, a copy of it, a correction, deletion, a restriction of its use, or object to how it is used, and you can withdraw consent at any time. Email hi@pacing.tools from your sign-in address, which is how we check it is you, and you will have an answer within a month. Deletion needs no email, see section 6.
You can also complain to the Spanish data protection authority, the AEPD.
8. Automated decisions and age
Nothing here makes a decision about you with legal or similar effect. The service is not for anyone under 16.
9. Changes and contact
This page shows its last update date. A change that reduces your rights or widens how we use your data is announced on the site or by email 30 days before it applies, and where the law needs your consent we ask for it. Earlier versions on request. Contact: hi@pacing.tools. The controller of your data is David Ortiz Mayoral, operating pacing.tools from Spain, details on the legal notice.
Last updated 22 September 2026.