PactPact

Privacy Policy

Effective 2026-07-22 · Last updated 2026-07-22

1. Who we are

Pact is a personal training software platform operated by Evan Fitzjohn (“Pact,” “we,” “us”). This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices you have. It applies to the Pact mobile app, the Pact website at pactpt.com and app.pactpt.com, and any related services (collectively, the “Service”).

For questions or requests regarding this policy, contact us at privacy@pactpt.com.

2. Our core privacy principle

Clients own their training data. Pact is built around a simple inversion of how most personal-training platforms work: the athlete (client) is the primary account holder, and coaches are relationships that attach to and detach from that account. Your training history belongs to you and persists across coach changes. Coaches keep professional artifacts (notes, programs, observations) private to themselves, and organizations see coached activity within their own coaching operation.

3. Information we collect

3.1 Information you provide

  • Account information: name, email address, date of birth (used to verify you are 18 or older — see Section 11), password (stored hashed), and optionally a profile photo.
  • Profile information: athlete or coach role, optional body weight, training preferences, and goals you choose to enter.
  • Workout data: exercises, sets, reps, weights, session timestamps, durations, and notes you enter on yourself or that a coach enters with you on the floor.
  • Program data: training plans you create, are assigned, or save.
  • Coaching relationships: the link between a coach and a client, invite metadata, and (where applicable) organization membership.
  • Coach-authored content: client notes (e.g., assessment findings, injury limitations, goals) written by a coach about a client.
  • Communications: messages you send us (e.g., support email).

3.2 Information collected automatically

  • Device and diagnostic data: app version, operating system, device model, locale, and crash reports collected through Sentry. We use this to debug and improve reliability.
  • Authentication metadata: session tokens, sign-in timestamps, provider identifiers from Google or Apple if you sign in with those providers, passkey credential metadata (public keys and credential identifiers — never your biometrics, which stay on your device), and two-factor authentication settings if you enable them.
  • Usage signals: coarse, aggregate signals about feature usage to understand what is working and what is broken.

3.3 Information we do not collect

  • We do not collect health or medical records, biometric identifiers, heart rate, blood pressure, blood glucose, sleep data, or anything similar.
  • We do not collect precise location data.
  • We do not store payment card numbers, bank account numbers, or other financial credentials. When we begin processing subscription payments, billing is handled directly by Stripe, which receives card data on our behalf — we receive only non-sensitive transaction metadata.
  • We do not collect contacts, calendar entries, photos beyond a profile picture you choose, microphone audio, or social-graph information.

4. How we use your information

  • To operate and provide the Service (log workouts, deliver coaching features, sync data across devices).
  • To authenticate you and protect your account.
  • To communicate with you about your account, security, or service updates.
  • To debug crashes, diagnose errors, and improve reliability.
  • To detect and prevent fraud, abuse, or violations of our Terms of Service.
  • To comply with legal obligations.

We do not sell your personal information. We do not use your training data to serve advertising. We do not share your training data with third parties for their own marketing.

5. Who can see what

Visibility within the Service is enforced by server-side authorization checks evaluated on every request. The rules below describe what each role can see.

5.1 Athletes (clients)

Athletes can always see everything about themselves. This is true regardless of whether you have a coach, change coaches, or leave an organization. Your training history is yours permanently.

5.2 Independent coaches

A coach who is not part of an organization can see, for each of their active clients: the client’s full exercise-level history (all-time weights, reps, and progression for each exercise), and any sessions, programs, and notes created during their coaching relationship. They cannot see prior coaches’ sessions, programs, or notes.

5.3 Organization coaches

A coach who belongs to an organization sees the same baseline as an independent coach, plus full visibility into work performed by other coaches within the same organization for the same client. This enables continuity when coaches transition. Coaches do not see work performed by coaches outside their organization.

5.4 Organization admins

An organization admin sees coached sessions across the organization, coach performance metrics, and client packages and notes within the organization. Admins do not see personal (non-coached) workouts of any user, coach or client. Admin visibility ends immediately when the admin leaves the organization. After departure, the organization retains read-only access to coached data only from the period that admin or coach was active.

5.5 No cross-organization visibility

No one outside your organization sees your organization’s data. Independent coaching relationships and organization coaching relationships are completely separate.

6. How we share information

We share information only as described below.

6.1 Service providers (subprocessors)

We use the following providers to operate the Service. They process your information on our behalf, under contract, and are not permitted to use it for their own purposes.

  • Neon — managed Postgres database hosting. Hosted on AWS infrastructure in the United States.
  • Sentry — application error monitoring and crash reports. Diagnostic data only; we scrub identifiers where feasible.
  • Google — Sign in with Google (OAuth) if you choose that option.
  • Apple — Sign in with Apple if you choose that option.
  • Vercel — web hosting and edge delivery.
  • Stripe — subscription billing for paid plans when those launch. Stripe handles all card data; we receive only non-sensitive transaction metadata.
  • Resend — transactional email (account verification, password reset, coach invites).

6.2 Within your coaching relationships

We share information between athletes, coaches, and organization admins as described in Section 5. This sharing is intrinsic to how the Service works — for example, your coach must be able to see the workout you logged together.

6.3 Legal and safety

We may disclose information if we believe in good faith that disclosure is required to comply with a valid legal process, protect the rights, property, or safety of Pact, our users, or the public, or investigate fraud or violations of our Terms.

6.4 Business transfers

If Pact is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

7. Where your data is stored

Pact data is stored in the United States on Neon’s managed Postgres infrastructure (AWS). Connections to and from the Service are encrypted in transit using TLS. Data access is enforced by application-layer authorization checks evaluated on every request based on the authenticated user.

If you access the Service from outside the United States, you understand and consent to your information being transferred to and processed in the United States.

8. Data retention

We retain your information for as long as your account is active and as needed to provide the Service. You can delete your account yourself at any time from the app’s settings. Deletion takes effect after a 24-hour grace window during which you can cancel; you can also request deletion by emailing privacy@pactpt.com, and we honor verified emailed requests within 30 days.

Some data is retained after account deletion for legitimate operational reasons:

  • When you delete your account, your personal training detail (exercise weights, reps, notes, body metrics) is permanently deleted.
  • The fact that a coached session occurred — its date, duration, and the coach involved — may be retained in anonymized form so that the coach’s and organization’s aggregate performance and billing records remain accurate.
  • Backups and logs may persist for up to 30 days after deletion before being overwritten through routine retention cycles.
  • We may retain limited information as required by law (e.g., tax records related to billing).

9. Your rights and choices

Depending on where you live, you may have rights regarding your personal information, including:

  • Access: request a copy of the personal information we hold about you.
  • Correction: ask us to correct inaccurate information. Most fields are directly editable in the app.
  • Deletion: ask us to delete your account and associated personal data, subject to the limits in Section 8.
  • Portability: export your training data in a machine-readable format directly from the app, or request an export by email.
  • Objection / withdrawal of consent: for users in jurisdictions where consent is the legal basis for processing, you may withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing prior to withdrawal.
  • Non-discrimination: we will not deny service, charge different prices, or provide a different level of service because you exercised a privacy right.

To exercise any of these rights, email privacy@pactpt.com. We will verify your request and respond within the timeframes required by applicable law.

10. Security

We use commercially reasonable safeguards to protect your information, including TLS in transit, encryption at rest by our hosting provider, server-side authorization checks on every request, short-lived access tokens, and support for passkeys and optional two-factor authentication. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

If we become aware of a security incident affecting your personal information, we will notify you and applicable authorities as required by law.

11. Age requirement and date of birth

Pact accounts are restricted to users 18 and older. We collect your date of birth at signup to verify eligibility, and we retain it while your account is active to support age-based fitness features (such as heart-rate zones and energy-expenditure estimates). You can view and correct your date of birth in your account settings at any time. We do not share raw date-of-birth data with coaches or organization admins — those parties see derived age information only. Your date of birth is deleted along with the rest of your personal data when your account is deleted.

The Service is not directed at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information to us, please contact privacy@pactpt.com and we will promptly delete the account.

12. Cookies and similar technologies

We use a small number of cookies and equivalent local-storage entries to keep you signed in, remember your theme preference, and protect against cross-site request forgery. We do not use third-party advertising cookies. We do not use cross-site tracking.

13. Third-party links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties; this Privacy Policy does not apply to them.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you in the app or by email. Continued use of the Service after a change becomes effective constitutes your acceptance of the revised policy.

15. Contact us

Questions, requests, or complaints about this policy should be directed to:

Pact (Evan Fitzjohn)
privacy@pactpt.com

← Back to home