← Back to the homepage

Scope: This policy covers the PaceMate app on Android (Google Play). It is identical to the version shown inside the app under “Profile → Legal → Privacy Policy”. The separate website privacy policy covers pacemate.de.

Privacy Policy

Last updated: August 2026


1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Jan Koester

Neureutherstr. 16

80799 Munich

Germany

Email: info@pacemate.de


2. Overview and scope

PaceMate is an app for finding training partners for running, cycling, hiking and gym training. We process personal data to provide this service. This Privacy Policy explains what data we collect, why we use it and which rights you have.

Source of data: Personal data is collected directly from you through your entries, technical transmissions from your device or, with your explicit consent, workout data from Health Connect. We do not obtain personal data from third parties or public sources.

This Privacy Policy applies worldwide. Additional GDPR provisions apply to users in the European Economic Area (EEA).


3. Data and purposes of processing

3.1 Registration and profile

Data: Email address, first name, profile photo, sports, pace, availability, training goals, home city or region, search radius and, optionally, gender, age, an “about me” text and links to your own channels such as a website, Strava or Instagram. Gym profiles also contain the information listed in section 3.12.

Purpose and legal basis: Creating your account and showing your profile to other users; Art. 6(1)(b) GDPR. PaceMate uses one-time login codes instead of passwords. Your email address is sent to our email provider but is never visible to other users.

Retention: Until you delete your account. Accounts unused for more than six months are deleted automatically — see section 3.22.

3.2 Location data

Data and purpose: The coordinates of your search centre — either obtained by GPS with your permission while you use the app, or set by you on the map — together with the city or region derived from them and your search radius. They are used to show nearby partners and to calculate distance for matching; Art. 6(1)(b) GDPR.

Storage: These coordinates are stored in your profile, because a radius search cannot be calculated without them. We do not record a movement profile: only the most recent search centre is kept and it is overwritten on every update — not your route and not your whereabouts over time.

Visibility: Other users cannot retrieve your coordinates. The database denies access to these fields, and the discovery feed runs through a secured database function that returns only a position rounded to roughly one kilometre plus the distance. Others therefore see only your city or region and an approximate distance.

Retention: Until your next location update or until you delete your account. You can revoke location access in your device settings and may also set your search centre manually without granting GPS access.

3.3 Health and fitness data (Health Connect)

With your explicit consent, PaceMate reads running and cycling workouts from Health Connect. Raw Health Connect data is processed only on your device, is not uploaded to our servers and is not shared with third parties. Only the pace value derived from it may be saved to your profile.

Purpose and legal basis: Suggesting a realistic pace for better matching; Art. 9(2)(a) GDPR.

You can revoke access at any time in the Health Connect app or in PaceMate under Profile → Settings → Connections. Existing profile values remain until you change them or delete your account.

3.4 Camera and photos

Photos you take or select are used as your profile picture under Art. 6(1)(b) GDPR. They are retained until replaced or until you delete your account. Replaced profile pictures are deleted without undue delay.

3.5 Chat messages

Messages are processed to coordinate training under Art. 6(1)(b) GDPR. They remain while your account exists and are removed when you delete it. Messages submitted as part of a report are the one exception and are retained under section 3.15.

3.6 Push notifications

Your device push token is used, with your consent under Art. 6(1)(a) GDPR, to notify you about matches and messages. It is deleted after consent is withdrawn or the account is deleted, without undue delay and no later than seven business days. You can withdraw permission under Settings → Apps → PaceMate → Notifications.

3.7 Technical usage data

App version, operating system, device category and crash reports are processed for troubleshooting and service security under Art. 6(1)(f) GDPR. They do not directly identify you and are deleted automatically after 30 days.

3.8 Sign-ins and device data

For each sign-in and app launch we record the time, event type, platform, operating-system version, app and build version, IP address, approximate country, region, city and time zone derived from it, and network provider. We use this data to investigate abuse, support access issues and plan supported app versions under Art. 6(1)(f) GDPR.

The IP address is sent to the geolocation provider described in section 4.4. These records are deleted after 180 days or immediately when you delete your account.

3.9 Matching algorithm

PaceMate compares sport, pace, distance, availability and goals to suggest suitable partners. For hiking, elevation gain and difficulty take the place of pace. Gym matching instead considers studios, chains, network providers, studio flexibility and recurring training times. Matching only creates suggestions; you decide whether to contact anyone. No automated decision with legal or similarly significant effects under Art. 22 GDPR takes place.

3.10 Optional newsletter

If you actively opt in, we process your email address and consent status to send product, city-launch and event news under Art. 6(1)(a) GDPR. The box is off by default and the app remains fully usable without consent. You can unsubscribe through any newsletter email or by contacting info@pacemate.de. Data is retained until withdrawal or account deletion.

3.11 Visibility of group participation

When you join a group session, your profile name and photo are visible to its host and confirmed participants. People with whom you have a mutual match may also see that you joined the session. Other users cannot see your participation unless they are confirmed for the same session.

This is processed to arrange shared training under Art. 6(1)(b) GDPR. Leaving the group removes the indication. Ending a match also removes this visibility for that person. Data remains until you leave, the match ends or your account is deleted.

After an event, the host may record who actually attended; that note is visible to the host and to you. Muting a group chat is stored as well so the setting applies on all your devices.

3.12 Gym information

If you enable Gym, we process your primary and optional additional studios, training types and goals, experience, optional competition experience, frequency, recurring weekday/time availability, optional duration, preferred partnership styles, optional gym-network providers and willingness to try another studio. For a proposed gym session, we also process the selected studio, focus, optional duration and whether you need a spotter.

These details are visible to Gym users within your radius and are used for matching and planning sessions under Art. 6(1)(b) GDPR. We do not collect strength values, body weight, body measurements, injuries or medical status for Gym matching. You can change all details at any time. Disabling Gym hides the profile and excludes it from matching while retaining the values for later reactivation. Account deletion removes them.

3.13 Ratings after training sessions

After a shared session you may rate your training partner from one to five stars and optionally leave a short comment. We store the stars, the comment, the session and who rated whom, under Art. 6(1)(b) GDPR.

A rating is readable only by the person rated and by you — it is never public, never shown in the discovery feed and never visible to third parties. The person rated can see who wrote it. Ratings are retained until either account is deleted.

3.14 Support requests in the app

If you write to us under Profile → Contact support, we store the topic, your messages, our replies and technical details about your request such as app version and platform, so we can make sense of it. Processing is based on Art. 6(1)(b) GDPR and on our legitimate interest in traceable support under Art. 6(1)(f) GDPR.

Only the operator reads and answers these requests, through an internal dashboard; they are not passed to third parties. Requests are deleted 24 months after the last message in the thread, or immediately when you delete your account.

3.15 Reports about users and content

If you report a person or a chat, we store the reason, your optional comment, the profile names of both people involved, the sport concerned and an excerpt of the reported messages. This is based on our legitimate interest in a safe service and in investigating violations, Art. 6(1)(f) GDPR.

A report necessarily contains statements and messages of the reported person. It also survives the deletion of either account — otherwise a suspension could be evaded by signing up again and an open case could no longer be investigated. This is the only exception to our commitment that deleting your account removes all associated data. Reports are deleted 12 months after they are submitted. You may object under Art. 21 GDPR: info@pacemate.de.

3.16 Inviting friends

We generate a six-character invite code for your account. If someone redeems it, we store the link between the inviting and the invited account and the time, based on our legitimate interest in understanding how people find PaceMate, Art. 6(1)(f) GDPR. There is no reward, and the app shows you only the number of people invited, never their names. The link is retained until either account is deleted.

3.17 Goal events and event participation

If you sign up for an event, we store the event, the chosen distance where applicable and whether your participation should be visible, under Art. 6(1)(b) GDPR. When visible, your profile name and photo appear at the event and as a goal event on your profile, so others training towards the same goal can find you. You can withdraw or hide your participation at any time. Data is retained until you withdraw or delete your account.

3.18 Club accounts and memberships

Besides athlete accounts, PaceMate has club accounts. If you belong to a club team, we store the link between your account and the club profile and your role (owner, write or read access). For a team invitation we store the invited email address, who invited and when the invitation expires, under Art. 6(1)(b) GDPR.

Roles are retained until withdrawn or the account is deleted. Accepted and expired invitations are removed after 30 days, the club change log after 400 days. The separate privacy notice at club.pacemate.de applies additionally to the club portal.

3.19 Routes and GPX files

When you plan a route for a group session, we store the meeting point, the start point and the course, under Art. 6(1)(b) GDPR. From an uploaded GPX file we read the track points (latitude and longitude) only; timestamps, heart-rate, power and other measurements in the file are discarded.

Note that a recorded route often starts at your home address and is visible to everyone who can see the session. Routes are retained until the group session is deleted; a technical counter limiting uploads is deleted after two hours.

3.20 Onboarding measurement

While you set up your account we record a small number of steps against your account: account type chosen, sport selection opened and completed, the first view of each page of the questionnaire, profile completed, and the outcome of the location prompt (granted, denied or unanswered). If your location lies outside the launch area, we also record whether you joined the waiting list, chose Munich instead, or left the screen without answering. When you first open partner search after setup, we store whether any suggestions existed and how many. This rests on our legitimate interest in a working sign-up under Art. 6(1)(f) GDPR.

The measurement is deliberately narrow: no clicks, no screen times, no behavioural log and no transfer to an analytics provider. Records are deleted after 180 days, or immediately when you delete your account. You may object under Art. 21 GDPR: info@pacemate.de.

3.21 Protection against sign-in abuse

Around sign-in we log security-relevant events such as repeated requests for login codes, and whether a requested code was actually used to sign in. Your email address is not stored in clear text but only as a non-reversible hash, which is also what lets us count how many requested codes go unused. This rests on our legitimate interest in the security of the service, Art. 6(1)(f) GDPR. Entries are deleted after 90 days; they are not tied to an account and therefore remain after an account is deleted.

3.22 Automatic deletion of inactive accounts

Accounts unused for more than six months are deleted automatically, together with the profile, profile photo, messages, matches and all other associated data. What counts is the time of your last activity in the app. This follows the storage-limitation principle in Art. 5(1)(e) GDPR. Open the app occasionally if you wish to keep your profile; we currently send no separate warning before this deletion.

3.23 Optional translation of public descriptions

If you use the app in English and actively select “Translate to English” for a public club or event description, Google ML Kit translates the displayed text directly on your device. Neither the source text nor the translation leaves your device or is sent to PaceMate or Google. Before the required language models (about 30 MB in total) are downloaded for the first time, PaceMate asks for your confirmation.

Processing is necessary to provide the translation you requested under Art. 6(1)(b) GDPR. The feature is optional and the unchanged original always remains available.

The language models are downloaded from Google and managed on your device by the operating system. PaceMate stores neither the source text nor the translation in a translation backend. According to Google's technical data disclosures, ML Kit may process the configured source and target language codes for diagnostics and usage analytics; the text being translated and the result are not included. Technically necessary connection data such as the IP address is generated when a model is downloaded.

Public descriptions may be translated by other users. People and clubs publishing them should therefore not include health data, third-party contact details or other particularly sensitive information.


4. Providers and processors

4.1 Supabase

We use Supabase (Supabase Inc., Oakland, California, USA) as backend infrastructure in the EU West region (Dublin, Ireland). Data is stored there. We have concluded a data processing agreement under Art. 28 GDPR. Possible US transfers are covered by the EU Standard Contractual Clauses and Supabase's certification under the EU-U.S. Data Privacy Framework.

4.2 Push services (Expo / Google)

We use the Expo Push Notification Service (Expo Inc., San Francisco, USA), which delivers notifications through Firebase Cloud Messaging (FCM, Google LLC). Only the device token and notification content are transferred. Expo's US transfers rely on its EU-U.S. Data Privacy Framework certification. As a downstream provider, Google is subject to its own EU-compliant privacy rules and is also DPF-certified.

4.3 Health Connect

Data from Health Connect is processed only locally on your device and is not shared with third parties.

4.4 IP geolocation (ip-api.com)

We send only your IP address to ip-api.com (Nucleus Software Ltd.) to obtain an approximate country, region, city, time zone and network provider. The request is server-side; your device does not connect to this provider. Results are cached for 30 days to avoid repeated requests for the same address.

4.5 Maps and place search

When you plan a group session, third-party map data is loaded and locations are resolved. The map is provided by Google Ireland Limited or Google LLC (Google Maps SDK). Technically required information such as your IP address and the visible map area is transmitted; account and profile data is not.

The app first uses your device geocoder. If it has no result, we query Nominatim, provided by the OpenStreetMap Foundation, Cambridge, United Kingdom. Only coordinates or your search text and the technically necessary IP address are sent. Results are cached only on your device. Processing is necessary to set a meeting point under Art. 6(1)(b) GDPR. Google LLC is based in the United States and is certified under the EU-U.S. Data Privacy Framework.

4.6 Email delivery (Resend)

We use Resend (Plus Five Five, Inc., San Francisco, USA) for login and system emails. We send your email address and the message sender, subject and content. Technical delivery logs include time, delivery state and mail-server errors.

Processing is necessary for passwordless sign-in under Art. 6(1)(b) GDPR. Resend generally retains email data for 30 days. We do not use open or click tracking for these transactional emails. Our sender domain uses the EU West region, while Resend stores account data, metadata, logs and API data in the United States. Transfers are covered by a data processing agreement, the EU-U.S. Data Privacy Framework and supplementary Standard Contractual Clauses.

Privacy: https://resend.com/legal/privacy-policy · DPA: https://resend.com/legal/dpa · Subprocessors: https://resend.com/legal/subprocessors

4.7 On-device translation (Google ML Kit)

For the optional translation described in section 3.23, PaceMate uses Google ML Kit, provided to users in the EEA and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Translation takes place entirely on your device. Google does not receive the description, the translation, your PaceMate user ID or other PaceMate account data.

A connection to Google is required only to download language models and for the technical diagnostic and usage information described by Google. This may include the selected language codes, device and app information and the technically necessary IP address. The model download you initiate is based on Art. 6(1)(b) GDPR; our legitimate interest in stability and error diagnostics is additionally based on Art. 6(1)(f) GDPR. Once downloaded, the models enable translation without an internet connection.

Privacy: https://policies.google.com/privacy · ML Kit privacy: https://developers.google.com/ml-kit/terms


5. No advertising disclosure

We do not sell, rent or share your personal data with third parties for advertising.


6. Your rights

All users may request access and correction, delete their account in the app under Profile → Delete account, and withdraw consent at any time. You may also contact info@pacemate.de. Two records outlive account deletion because they would otherwise lose their purpose: reports about violations (section 3.15, 12 months) and the account-independent sign-in security events (section 3.21, 90 days).

EEA users additionally have the rights to restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR).

California residents may request information about data collected, used, disclosed or sold in the preceding 12 months; request deletion subject to legal exceptions; opt out of sale or sharing; and exercise these rights without discrimination. We do not sell or share personal data for advertising. Contact info@pacemate.de. We answer within two business days; the statutory response period is 45 days.


7. Right to complain

In Germany you may contact the Bavarian State Office for Data Protection Supervision (BayLDA). EEA users may also contact the supervisory authority in their country of residence under Art. 77 GDPR.


8. Data security

Communication uses TLS/HTTPS and real-time connections use WSS. Database, storage and backups are hosted by Supabase in Ireland on encrypted storage. Row Level Security restricts access at database level.

We do not store passwords. Sessions are stored in the iOS Keychain or Android Keystore. Chats are encrypted in transit and at rest but are not end-to-end encrypted, so reported content can be reviewed. Profile images use non-guessable addresses, but anyone who obtains such an address may access the image outside the app.


9. Minimum age

PaceMate is intended for users aged 16 or older. Processing younger users' data requires parental consent.


10. Changes

We will notify you of material changes by push notification or when you next open the app.