Privacy

Who is responsible
Eightpace is operated by Harvey MSC Ltd, the controller of your information. Contact support@traineightpace.com for privacy questions, support or a data-rights request.

Information we use
We store your display name, email, password hash and account dates to provide and secure your account. Guest accounts use a random internal identifier until you choose to save a named account. We store a record of the version and time of your terms acceptance and fitness-data consent.
If you choose fitness-data storage, we use your race date and division, goal, age, running baseline, training history, available days, equipment and time to select authored session variants and organise your calendar. Optional running results, height and weight can be omitted. Body measurements do not calculate pace, calories or medical clearance. We store workout entries, timers, sets, repetitions, loads, distances, durations, effort, optional classes and calendar changes to provide your record and progress views. Fitness information may reveal health information, so we treat it as potentially special-category data.
We no longer ask for or store answers to medical screening or its follow-up status. Earlier versions recorded an acknowledgement that guidance was read; it does not record a screening outcome. New setup does not require a screening questionnaire or store a new acknowledgement. Do not add diagnoses, injury details, screening answers or other people's information in free-text notes or feedback.

Purposes and legal bases
Account administration and the functions you request use Article 6(1)(b), performance of our agreement to provide Eightpace. Security and abuse prevention use Article 6(1)(f), our legitimate interest in protecting accounts and keeping the service available; we limit and periodically remove security records. Fitness-record storage, plan selection using your fitness background and progress displays use your consent under Article 6(1)(a) and, where information reveals health, explicit consent under Article 9(2)(a). That choice is separate from accepting membership terms. You can inspect the read-only sample without consenting. If you decline fitness-data storage, personalised record storage is unavailable, but your account and the sample remain accessible. No fitness records are used for advertising.
Contact requests store the name you provide, reply email, topic, message and request date in our private support inbox for up to 90 days. We use them to answer your request and administer accounts under Article 6(1)(b), or our legitimate interest in responding to general enquiries under Article 6(1)(f). Do not include passwords, payment details or medical information. Support requests are not marketing subscriptions. Ask the operator to correct or delete a request using its reference.
Feedback is optional and used to answer your request and improve usability, under our legitimate interest in improving the service. Please use fictional examples rather than medical details. We do not sell information or train an external AI model on your workout records.

Control and withdrawal
You can export your account's information in Account, correct plan inputs through a reviewed preview, and ask support to correct records that cannot be edited in the app. Account also offers a separate fitness-consent withdrawal control: it stops fitness-data use and removes your profile, plan, workout records, classes, reviews and notes from the active database while keeping your login. You may instead delete the entire account. Withdrawal does not make earlier lawful processing unlawful. Restricted backup copies expire as described below and will not be used to restore deleted records; any emergency restoration must reapply recorded deletions before reopening access.

Storage, access and recipients
For this hosted service, Render Services, Inc. provides web hosting and persistent database storage. The service is configured in Frankfurt, Germany. Account and fitness records and the app’s daily recovery copies are stored on the service’s persistent disk. Render also provides infrastructure recovery snapshots. Choosing a server region does not restrict all service-operation processing to that region: Render and its subprocessors may process operational information in the United States and other countries. Render’s Data Processing Addendum describes its processing arrangements and standard contractual clauses, including its UK Addendum: https://render.com/dpa . Its privacy information is at https://render.com/privacy . Contact Harvey MSC Ltd for details of the arrangements applying to Eightpace. A retained local database, if any, is restricted to the operator and follows the same account-deletion requirements; source uploads contain no participant records.
Only authorised operators and support staff may access records for support, security and operation. The app has no coach-sharing function. Do not share passwords. Stripe processes membership checkout, card payments, subscriptions, cancellation and invoices. It receives your account email and an internal account identifier; Eightpace does not send fitness records or workout notes to Stripe and does not store full card details. Stripe’s privacy information is at https://stripe.com/privacy . Payment and accounting records may be retained as required by applicable law. There are no wearable, ChatGPT, marketing-email or advertising integrations. Opening a linked external screening or technique website is governed by that site's privacy notice; we do not receive its answers.

Cookies and local storage
The essential session cookie is HttpOnly and expires after seven days, with renewal during use up to a maximum of 30 days from sign-in. Remote HTTPS mode adds Secure. A temporary invitation cookie lasts up to 24 hours. Browser storage holds a recovery copy of an unsaved workout on that device; account deletion or fitness-consent withdrawal in that browser clears its Eightpace workout copies. Other devices may retain a copy until you clear their site data. Do not use shared devices for personal workout notes.
There are no advertising cookies. Local product events store only an allowlisted event name and timestamp, without an account identifier, body measurements, health information or note contents. These are aggregate usage records, not individual conversion attribution.

Retention
Named accounts and saved plans remain until you delete them or withdraw fitness consent. Ending membership does not automatically erase saved records. Before closing the service, we will provide notice and an export opportunity, then remove active training records within 30 days. Billing identifiers and subscription status are stored to administer access; Stripe retains its own payment records under its privacy terms and legal obligations. Blank guests without a saved profile are removed after 48 hours. Invitation links expire after seven days; expired or used invitation records are removed after 14 days. Security rate-limit records expire after one hour, or ten minutes for email login limits. Reset links expire after 30 minutes and are single use. When automated email is connected, reset-delivery queue records expire with the link; password-change notification records expire after 24 hours. All older reset links and sign-ins are invalidated after a successful reset. Programme and calendar previews expire after 30 or ten minutes respectively. Expired records are removed at startup and by the daily maintenance task.
The supplied remote runtime makes a consistent daily SQLite backup and retains daily files for 14 days. Account and fitness-data deletion records are retained for 30 days so a restoration cannot revive deleted data. Older local development copies are separate, restricted records that must be removed or sanitised before real beta data is introduced. Source downloads contain no databases or backups. Any future off-site backup requires a documented recipient and the same deletion and retention rules.
Request logs contain method, a recognised route name, status and time. They omit query strings, cookies, request bodies, IP addresses and error-message contents. Render has independent routing and service records governed by its processing and privacy terms. The app disables Gunicorn access logging and does not include invitation queries, workout contents or credentials in its own request logs. Abuse limits use a keyed hash of the client address rather than storing a raw IP address in the app database.

Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests, and may withdraw consent at any time. Contact the address above; we normally respond within one month, subject to lawful extensions and identity checks. You can complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or your relevant supervisory authority. We do not make decisions with legal or similarly significant effects through automatic plan selection. It selects draft session variants and does not give medical clearance.

Changes
We will identify material changes and request new consent if fitness-data purposes change. This notice describes the hosted service. We will identify material changes to the host or storage arrangements before they take effect.


Account emails
Resend provides transactional delivery for email verification, password-reset links and password-change notifications. It receives the recipient email and the message required for account recovery, not fitness records. See https://resend.com/legal/privacy-policy and https://resend.com/legal/dpa for its processing arrangements. When a contact request arrives, an operator notification contains only its reference; the sender and message stay in the private support inbox. These are service messages, not marketing emails. Contact the operator for applicable retention and transfer arrangements.

Email verification and membership records
Email verification uses a single-use link that expires after one hour. The database stores a hash of the credential. Verification emails contain the confirmation link and account-service text, not fitness information. Expired verification and queued email records are removed by maintenance. Stripe webhook event identifiers are retained for 90 days to prevent duplicate handling. Membership status uses server-verified Stripe information; opening a payment return link does not itself grant access.

Return to Eightpace