← OurPace

Privacy statement

OurPace is built privacy-first: we collect as little as possible, store it in the European Union, and never sell or share your data.

Who we are

OurPace is a trade name of G. van der Burg, a sole proprietorship registered with the Dutch Chamber of Commerce under number 61221856, VAT number NL001789720B25, at Vlondertuinen 11, 5247 MX Rosmalen, the Netherlands. OurPace is run as a sole proprietorship, so G. van der Burg is personally the controller for the data described here. You can reach us at info@ourpace.eu. There is no data protection officer; at this size the law does not require one.

What we store

Waitlist: your email address, preferred language and sign-up source, plus a confirmation timestamp.

App accounts (invite-only): your name, email address, password (hashed), language, height, and the health-related data in your account: weight entries, workouts, goals and your personal plan. You enter those yourself, or — if you switch it on — they come from your phone or watch; see the next paragraph. Your progress is visible only to you and the partner you are coupled with — never to other users.

From your phone or watch (optional, off by default): if you give permission, we read six things from Health Connect (Android) or Apple Health (iOS): your weight entries, your workouts (type, duration, distance), your steps, your body fat percentage, your lean mass and your resting heart rate. Nothing else — no continuous heart rate, no sleep, no location, no calories. We store the day, not the exact time, plus a reference to the entry on your device so the same workout is never added twice. Steps and resting heart rate are kept as one figure per day. Your phone records those in small intervals; we add them up on your phone and send only the daily figure. A daily total says you walked eight thousand steps — a series of quarter-hour readings would say when you got up, when you were at work and when you went to sleep. We do not fetch that and we do not store it. We never write anything back to your phone, and what you enter yourself always beats what your watch reports. You can refuse this and the app works fine without it; withdrawing it in the app stops the syncing and deletes everything that came in this way. Reading while the app is closed is a separate choice. By default we only read while you have the app open. You can turn on reading in the background as well — Health Connect asks you for that separately, on the device itself — and then your workouts arrive on their own, about once every two hours, without you opening the app. It reads the same six things and nothing more, it stops the moment you withdraw the sync, and you can also switch it off in Health Connect itself.

The app on your phone: when you log in from our app we store a sign-in token for that device, and the time zone your phone reports — so that “today” means your today and not the server’s. Both are gone when you log out or delete your account.

Your plan: if you choose to have a plan generated, we store your intake answers (goals, preferences, training days, food preferences) and the outcome of the safety check — "standard", "careful" or "movement plan" — plus the date. We never store the individual safety-check answers themselves.

Visitor statistics: we count page views, unique visitors, the language of the page, the referring domain, the campaign a visit came from, the country and whether a visit came from a phone, tablet or computer. Stored only as totals per day: no cookies, no IP addresses and no user agents. To count a visitor once a day rather than once per page, we derive a key from the IP address and the browser, using a secret that changes every day. That key exists for a maximum of 24 hours, is never stored alongside the figures, cannot be turned back into an IP address, and is a different one tomorrow — so even we cannot tell that today’s visitor is yesterday’s. It is what lets us do this without a cookie and therefore without a consent banner.

Feedback: if you report a bug or a wish, we store what you wrote, which page you were on, your language and your account, so we can get back to you. We ask you not to put health details in that field.

Access and billing: which access status your own account has (beta, founder, trial, paid), and the moments you accepted the privacy statement and the terms.

Cookies: only functional cookies (session, security, language preference) — no tracking or advertising cookies.

Why, and on what legal basis

Solely to provide OurPace: showing your own progress to you and your partner, and contacting you about your waitlist spot or account. No advertising, no sale of data, and nothing is used to train AI models.

The GDPR requires us to say not just what we do, but why we are allowed to. Per purpose:

Your account, your logging and your plan — because we have an agreement with you (Article 6(1)(b)): you want to use OurPace, and it cannot work without this data. Because weight, height and the outcome of the safety check are data concerning health, we also rely on your explicit consent (Article 9(2)(a)). You give that when you create an account, and again before the safety check. If you switch on syncing from your phone or watch, you give it a third time — in Health Connect or Apple Health, on the device itself — and you can withdraw that one in our app at any time, which also deletes what came in that way.

The waitlist — your consent (Article 6(1)(a)), confirmed by the link in the email. You can withdraw it at any time by emailing us, and we delete the entry.

Invitations — our legitimate interest (Article 6(1)(f)): letting you invite the partner whose address you gave us. If you were invited and do not want an account, reply to that email and we delete your address.

Feedback, security and keeping the service running — our legitimate interest (Article 6(1)(f)): a working, secure app. That covers rate limiting, error logs and backups.

Invoices, once we start charging — a legal obligation (Article 6(1)(c)): Dutch tax law requires us to keep them for seven years.

How your plan is put together

Your plan is assembled by our own calculation rules, not by a person. They read your intake answers, your height, weight, year of birth and sex, and the outcome of the safety check. From those they pick a calorie range, a week structure and the exercises.

The safety check gives you one of three profiles — standard, careful or movement plan — and that profile decides how cautiously the plan is built, which parts are switched off, and whether we ask you to talk to your doctor before you start. That is profiling in the sense of the GDPR, so we say so plainly. It is not a decision with legal consequences, and there is no automated decision-making about you beyond your plan: nobody is refused, ranked or scored.

If you disagree with the outcome, email us — a person will look at it.

Where

All data is stored and processed on servers in the European Union. Email delivery runs through a European processor (Scaleway, France). Hosting runs on servers in Amsterdam operated by Vultr — an American company. Your data stays inside the European Union; the provider is not European, and we say so rather than round it off. There is one exception, described under "AI" below. Apple and Google are not recipients of your data: if you switch on syncing, data travels only from your device to us, never the other way round.

AI

Your plan is put together by our own calculation rules. Those are not AI. A language model only writes the short explanatory paragraphs around it — it has no say in what the plan contains.

Our processor for this is OpenAI Ireland Ltd., an Irish company, under a processing agreement. The model itself runs outside the European Union: OpenAI Ireland passes the request on within its own group, and does so under the European Commission's standard contractual clauses. Your data is never used to train AI models, and we tell OpenAI not to store the request at all.

What the model is given: the language to write in, whether the tone should be calm or upbeat, your starting level, how many days a week you train, your goal, the shape of your week, the names of the building blocks your plan is made of, and whether your plan uses an eating window.

What it is never given: your name, your weight, your height, your age, your calorie target, your answers to the safety check, or the reason your plan is calm. It is told that the tone should be calm — never why. Nothing in what we send identifies you, but it is not anonymous either: on our side it stays linked to your account. We do not store what is sent; we keep only the model name, the outcome and a token count.

Those two things sit next to each other, so to be precise: what we switch off is the log inside our own OpenAI account. Separately from that, OpenAI keeps requests for up to thirty days to check for misuse, and deletes them after that — that is their policy for every customer, not something we can turn off. We have asked them for processing inside the European Union and will move to it once that is arranged.

How long

Account data until you delete your account. Deletion is immediate: everything is gone from the live database at once, including all logged data. Backups are the one exception — they exist so we can recover from a failure, and they are overwritten within fourteen days. After that your data is gone from those too. Data that came from your phone or watch follows the same rule, and disappears immediately if you withdraw that permission in the app.

Waitlist entries: until you are invited or ask us to remove you, and at the latest two years after you confirmed. Invitations: half a year after they expire. Feedback: two years after we have dealt with it. Technical logs about the AI layer (model, outcome, token count — never the text): one year. Server logs: fourteen days.

Your plan is kept in versions so you can go back to an earlier one. We keep the current version plus the five most recent older ones, and we never keep an older version longer than twelve months. Anything beyond either limit is deleted automatically.

Your rights

You can delete your account, and everything in it, yourself under Profile. You can correct your name, goals, language and the details about you there as well. And under Profile you can download everything we hold about you in one file — your weigh-ins, workouts, plans, meal-prep weeks and profile. No request needed, and it works even if your subscription has ended.

Beyond that you have the following rights, and you exercise all of them by emailing us. We answer within a month.

If you think we are handling your data badly, we would rather hear it from you first. But you always have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your own country.

Contact

info@ourpace.eu

Last updated: 11 August 2026