Privacy Policy
Effective as of September 29, 2026.
- Publisher
- Purpose
- Data collected
- Purposes and legal basis
- Third-party services
- Sharing with third parties
- Health Connect (Android)
- Apple HealthKit (iOS)
- Strava (optional partner)
- COROS (optional partner)
- Your GDPR rights
- Account deletion
- Security
- Data retention
- Minors
- Cookies and advertising identifiers
- Changes
- Contact
1. Publisher
The Physio Pacing mobile application (hereafter "the App") is published by:
Gautier Maurickx — Sole proprietorship (micro-entreprise)
SIRET: 105 168 371 00018
Registered office: 01800 Saint Jean de Niost, France
Contact: contact@physiopacing.fr
2. Purpose
This policy describes the personal data collected by the App, how it is used, the rights you have, and the third parties with whom it may be shared. It applies to all users of the App, on iOS and Android.
3. Data collected
3.1 Data you provide
- Account: email address, first name, date of birth
- Sport profile: MAS (Maximal Aerobic Speed), recent race times, race distance and goal, recent declared injuries
- Body data: height, weight (optional)
- Heart data: resting heart rate, maximum heart rate (optional)
- Training log: completed sessions, rating of perceived exertion (RPE), personal notes
- Profile picture (optional)
3.2 Data collected automatically
- IP address and device technical identifiers (model, operating system, app version)
- Pseudonymized usage data (screens viewed, features used) tied to your Firebase identifier — not anonymous as linked to your account. Collected only if you accepted "Usage statistics" (off by default).
- Crash and error data (via Firebase Crashlytics) — technical traces + device model + OS version, no personal content. Collected only if you accepted "Crash reports" (off by default).
- Date and time of your usage sessions
The App does not collect your precise location and does not use artificial intelligence to process your data.
4. Purposes and legal basis
Your data is used to:
- Provide the service (account, plan generation, multi-device sync) — basis: performance of contract
- Process your health and training data (rating of perceived exertion RPE, heart rate, sleep, step count, activities imported from Health Connect, Apple Health or a connected partner) to compute and adapt your plan and training load — basis: your explicit consent (Article 9(2)(a) GDPR), collected at first launch of the App. This consent is required for the App to work.
- Measure App usage (Google Analytics for Firebase) — basis: your consent, optional, off by default
- Fix crashes (Firebase Crashlytics) — basis: your consent, optional, off by default
- Communicate with you (verification emails, important notifications) — basis: performance of contract
- Comply with legal obligations (accounting, response to legal requests)
- Prevent free-trial abuse (an irreversible fingerprint of your email address, see § 12) — basis: legitimate interest
4.1 Collecting and withdrawing consent
At first launch (or the first time you open the App after the update that introduces this screen), the App shows a "Your data, your choices" screen (« Tes données, tes choix »):
- Health and training data: mandatory checkbox to use the App;
- Usage statistics and Crash reports: optional checkboxes, unchecked by default. The "Accept all" and "Confirm my choices" buttons carry the same weight.
Your choice, its date and the version of the text are stored on your device and in your profile. You can change it at any time under Profile → Settings → Privacy and consents. Withdrawing usage statistics or crash reports takes effect immediately. Withdrawing consent to health data makes the App unusable: it is exercised by deleting your account (§ 12) or by writing to us. Withdrawal does not affect the lawfulness of processing carried out before it.
5. Third-party services used
The App uses the following services, each with its own privacy policy:
5.1 Google Firebase infrastructure
- Firebase Authentication — account creation and management
- Firebase Cloud Firestore — storage of your profile and plan (location
europe-west9, Paris, European Union) - Firebase Cloud Messaging — push notifications (new articles, reminders)
- Firebase Cloud Functions — server-side validation of your Premium purchases, sending verification emails via Brevo
- Firebase Crashlytics — pseudonymized crash reporting, only with your consent
- Firebase App Check — verifies that requests actually come from the App (anti-abuse protection)
- Google Analytics for Firebase — pseudonymized audience measurement, only with your consent; advertising ID collection is disabled
- Google Play Services — Android system dependency
Google's policy: policies.google.com/privacy
5.2 Payment providers
- Google Play Billing (Android) — subscription processing
- Apple App Store In-App Purchases (iOS) — subscription processing
These services handle your payment information — Physio Pacing never has access to your card number.
5.3 Transactional email
- Brevo — sending address-verification emails (dispatched via Firebase Cloud Functions)
Service information emails. If you have agreed to receive them, we may send you information emails about the service (new features, important changes, the end of a testing phase). They are sent through our provider Brevo (European Union). You can unsubscribe at any time via the link included in every email or by writing to contact@physiopacing.fr.
5.4 Health data (on your device)
- Health Connect (Android) — reads your running sessions, writes manually validated sessions back
- Apple HealthKit (iOS) — same, on iOS
These connections are optional. Details in sections 7 and 8.
5.5 Third-party authentication
- Google Sign-In (Android + iOS) — sign in via your Google account
- Sign in with Apple (iOS) — sign in via your Apple ID
5.6 Partner services connected at your request
- Strava — import of your running activities (OAuth 2.0 PKCE,
activity:readscope only, no write access) - Polar — import of your activities from your Polar Flow account (OAuth 2.0, AccessLink API, read-only)
- intervals.icu — pushes your planned sessions to your watch (bidirectional relay for Garmin, Coros, Polar, Suunto, Wahoo) + imports your analyzed activities (OAuth 2.0)
- COROS — pushes your planned sessions and imports your completed activities from your COROS watch (OAuth 2.0, COROS Open Platform API V2.1.1)
For all these partners, access tokens (OAuth tokens) are stored exclusively on your device, in encrypted storage (Keychain on iOS / EncryptedSharedPreferences on Android) protected by an operating-system key. They are never transmitted to our Firebase servers.
6. Sharing with third parties
We do not sell and do not monetize your data. It may only be shared:
- With the providers listed in section 5, strictly within the scope of their mission
- Under judicial requisition (law, official procedure)
- To protect our rights or the safety of other users (fraud prevention)
7. Health Connect (Android) — Details
The App can connect to Health Connect, Android's built-in health-data platform. This connection is fully optional and is enabled only if you explicitly authorize it.
- Data read: running sessions from the last 7 days (duration, distance, elevation gain).
- Purpose: automatically fill in the details of your completed sessions (instead of manual entry), compute your training load (Foster method: RPE × duration) and your injury-risk index (ACWR — Acute-to-Chronic Workload Ratio).
- Data written: when you manually validate a session, it may be written to Health Connect so it appears in your health apps' global history. Sessions imported from Health Connect are never duplicated back.
- Storage: only the duration (min), distance (km) and elevation (m) of the selected session are stored in your plan. No raw Health Connect data is stored separately.
- Sharing: Health Connect data is never shared with third parties. It is synced to your Physio Pacing account (Firestore) only to keep continuity across your devices.
- Control: you can revoke access at any time from Settings → Apps → Health Connect → Permissions → Physio Pacing.
8. Apple HealthKit (iOS) — Details
The App can connect to Apple HealthKit, iOS's built-in health platform. This connection is fully optional.
- Data read: running sessions (duration, distance, elevation), heart rate.
- Purpose: same as Health Connect (auto-fill, Foster load computation, ACWR, precise training zones).
- Data written: sessions manually validated in the App, so they appear in the iOS Health app.
- Security: this data is never used for marketing, advertising profiling, nor sold to third parties.
- Control: Settings → Privacy & Security → Health → Physio Pacing.
9. Strava (optional partner) — Details
The App can connect to Strava to import your running activities. This connection is fully optional, enabled only at your request via the official "Connect with Strava" button, after displaying a dedicated consent screen.
- Data read: list of your running activities (Run / TrailRun / VirtualRun) — date, duration, distance, elevation gain. No social data (kudos, comments, follows), no detailed GPS trace, no photos, no segments.
- Method: read-only (OAuth 2.0 PKCE,
activity:readscope, never write). Other Strava users' data — even public — is never accessed nor displayed. - Storage: OAuth tokens are encrypted locally (Keychain iOS / EncryptedSharedPreferences Android), never sent to our Firebase servers. Metrics derived from your activities (date, duration, distance, elevation) are stored in your Physio Pacing journal under a neutral title ("Running"). The original activity name on the Strava side is not preserved.
- Withdrawing consent: "Disconnect" button in Profile → Settings → Connected apps → Strava. Revocation is also possible directly from your Strava account settings (Settings → My Apps).
- Anonymization on disconnect: upon revocation (from Physio Pacing or from Strava), Strava identifiers associated with your imported activities are removed from the Physio Pacing journal (internal id reset, "strava" source marker cleared). Your session metrics (duration, distance, elevation, rated perceived exertion, notes) are retained as your own training data, indistinguishable from a manual entry. This approach fulfills the "Strava Data" erasure obligation of art. 7.4 of the Strava API Agreement while preserving your training memory. For a definitive erasure, you can then delete each session individually, or delete your entire account.
- Reflecting Strava deletions: if you delete an activity on Strava, the corresponding entry in Physio Pacing will follow at the next sync (within 48 hours, per art. 6.3 of the Strava API Agreement).
- Retention: Strava-sourced data is not retained beyond seven (7) days as Strava Data in the strict sense; after that period, only derived metrics remain, without reference to the source, as Physio Pacing's own data.
- No resale: Strava data is never sold, transferred to any third party, used for advertising profiling, nor combined with other data for aggregated analysis purposes.
- No AI training: Strava data and any derived data are never used to train, fine-tune, evaluate, ground, or operate any artificial intelligence model.
- Usage data collected by Strava: Strava may, on its side, collect usage data related to Physio Pacing's access to its API (call volumes, endpoints used, timestamps) for tracking, compliance and improvement purposes. This data is processed by Strava as an independent controller, in accordance with its Privacy Policy.
- Contact and incident reporting: in the event of a security incident affecting your Strava data, you can contact us at contact@physiopacing.fr. Physio Pacing undertakes to notify Strava (legal@strava.com) within twenty-four (24) hours, in accordance with art. 8.3 of the Strava API Agreement.
- Attribution: screens displaying activities imported from Strava carry the "Powered by Strava" attribution, in accordance with Strava's brand guidelines.
This policy complies with the Strava API Agreement (effective June 1, 2026) and the Strava API Policy (effective June 1, 2026). In case of conflict with Strava's own Privacy Policy, the latter prevails for Strava-side processing.
10. COROS (optional partner) — Details
The App can connect to the COROS Open Platform to push your planned sessions to your COROS watch and import your completed activities. This connection is fully optional, enabled only at your request via the dedicated button in Profile → Connected apps → COROS.
- Data read: running activities (Run / TrailRun / VirtualRun) completed on your watch — date, duration, distance, elevation gain, average pace, average heart rate. No social data, no detailed GPS trace stored, no nutrition, sleep or biometric data (weight, HRV).
- Data written: sessions planned by the Physio Pacing algorithm (warm-up / intervals / cool-down structure with pace targets), pushed via the
/coros/tp/workout/push(§6.3) and/coros/tp/list/push(§6.1) endpoints of the COROS API V2.1.1. No other writes — Physio Pacing never modifies your existing data on COROS. - Method: classic OAuth 2.0 (the protocol requires presenting the partner
client_secretat the authorization-code exchange step). Requested scope:workout profile. Data belonging to other COROS users is never accessed. - Storage: OAuth tokens and your unique COROS identifier (
openId) are encrypted locally (Keychain on iOS / EncryptedSharedPreferences on Android) and never sent to our Firebase servers — with the sole exception of theopenId, which is saved on your Firestore profile so COROS can notify us when you complete an activity (webhook §5.3 "Workout Summary Push"). Metrics derived from your imported activities (date, duration, distance, elevation) are stored in your Physio Pacing journal under a neutral title ("Running"). - §5.3 Webhook (end-of-activity notification): COROS pushes an activity summary to our Firebase Functions backend (
corosWorkoutWebhook, hosted in Europe —europe-west1region) every time you complete a run on your watch. This data triggers a push notification prompting you to confirm your perceived effort in the App. Each payload is authenticated via an HMAC-SHA1 signature computed with the partnerclient_secret. - Withdrawing consent: "Disconnect" button in Profile → Connected apps → COROS. Revocation is also possible from your COROS account (coros.com → account → connected apps). On disconnect, tokens are wiped from local encrypted storage and the
openIdfield remains on your profile so a fast reconnection is possible, but no further API call is made. - Retention: metrics of imported activities become your own training data (indistinguishable from a manual entry) once stored in your journal. Raw webhook logs are kept for 30 days for technical diagnostics, then automatically purged.
- No resale: COROS data is never sold, transferred to any third party, used for advertising profiling, nor combined with other data for aggregated analysis purposes.
- No AI training: COROS data and any derived data are never used to train, fine-tune, evaluate, ground, or operate any artificial intelligence model.
- Attribution: screens displaying activities imported from COROS carry the "Powered by COROS" attribution, in accordance with COROS's brand guidelines.
- Contact and incident reporting: in the event of a security incident affecting your COROS data, you can contact us at contact@physiopacing.fr.
This policy complies with the COROS Open Platform Terms of Service. In case of conflict with COROS Wearables, Inc.'s own Privacy Policy, the latter prevails for COROS-side processing.
11. Your GDPR rights
If you reside in the European Union, the EEA, the United Kingdom or Switzerland, you have the following rights under the GDPR:
- Right of access — obtain a copy of the data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your account and associated data
- Right to portability — receive your data in a structured, commonly used, machine-readable format
- Right to restriction — request restriction of some processing
- Right to object — refuse some processing (in particular, processing based on legitimate interest)
- Right to withdraw your consent at any time — under Profile → Settings → Privacy and consents (see § 4.1)
- Right to lodge a complaint — with a data-protection authority (in France: CNIL)
To exercise a right: contact@physiopacing.fr. Reply within 30 days (GDPR legal deadline).
12. Account deletion
You can delete your account and all its data directly from within the App:
Profile → Delete my account
Deletion is effective within a reasonable timeframe on our servers. Alternatively, send your request to contact@physiopacing.fr.
After deletion: no recovery is possible. To prevent circumvention of the one-free-trial-per-person limit, we only keep an irreversible fingerprint (SHA-256 hash) of your email address in an anti-abuse register for 12 months, after which it is deleted automatically. Your plain-text email address is not retained.
13. Security
- Authentication via Firebase Auth (industry-grade)
- HTTPS/TLS encrypted transmissions
- Firebase App Check (Play Integrity on Android / App Attest on iOS) — anti-abuse protection of backend endpoints
- Partner OAuth tokens stored encrypted locally (Keychain on iOS / EncryptedSharedPreferences on Android) — never transmitted to our servers
- Locked Firestore rules: each user can only read/write their own data
- Sensitive fields (Premium status, subscription entitlements) modified exclusively server-side via Cloud Functions, never from the client
14. Data retention
Your data is kept as long as your account is active, then for a reasonable period after deletion to comply with legal obligations and fraud prevention. The only exception beyond that: the fingerprint (SHA-256 hash) of your email address in the free-trial anti-abuse register, kept for 12 months (§ 12).
Firebase servers are located in the European Union (europe-west9 region, Paris).
15. Minors
The App is not intended for people under the age of 15 (French GDPR limit without parental consent). In the United States, this limit is 13 (COPPA).
We do not knowingly collect personal data from people below these ages. If you are a parent or legal guardian and you believe your child has provided us with data, write to contact@physiopacing.fr — we will delete it immediately.
16. Cookies and advertising identifiers
The App being native (iOS + Android), it does not use HTTP cookies.
Device advertising identifiers (IDFA on iOS, Google advertising ID / GAID on Android) are not collected by the App: the corresponding Android permission is removed from the App, advertising ID collection by Google Analytics for Firebase is disabled, and the App does not request tracking authorization (App Tracking Transparency) on iOS. The App shows no ads.
17. Changes
This policy may be updated. You will be notified via an in-app notice for substantial changes. The date at the top of the document reflects the last update.
18. Contact
For any question regarding the protection of your data: contact@physiopacing.fr
In case of persistent disagreement about the processing, you may lodge a complaint with the CNIL: www.cnil.fr