Privacy Policy

Version 1.3, effective 1 October 2026. These are the same terms shown in the app, plus a note about this website.

Summary

Pelt is built to keep your data on your phone. We only hold what is needed to run your optional account, subscription and encrypted backup, and we handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Because the app handles health information, we treat it with the extra care the Act requires for sensitive information.

Health information and consent

Heart rate, workouts, sleep, HRV, VO2 max, body mass, body fat, waist and other measurements are health information. We read them from Apple Health only with your permission, process them on your phone, and never use them for advertising, marketing or data mining. If you turn on cloud backup, your training data (including Health-derived data) is encrypted on your phone before upload; the server holds only ciphertext it cannot read. You can withdraw Health access in iOS Settings at any time. By turning on backup you consent to this handling.

What we collect

When you create an account we store: your email address, the name and profile picture your sign-in provider shares (Apple or Google), the provider you used, your unit preference, the app version and iOS version, when you last used the app, whether and when you accepted the Terms and Privacy Policy, your marketing choice, and if you back up, the time of your last backup and a fingerprint of your encryption key (not the key). If you subscribe to Pro, Apple processes the payment; we receive only an anonymous entitlement, never your card or Apple ID details.

What stays on your phone

Activities, GPS routes, heart rate and other Health data, progress photos and their analysis, body metrics, plans and coaching insights are stored only on your device unless you choose to back up. Photo analysis runs on the phone with Apple's Vision framework; photos are never uploaded for analysis.

How we use it

To sign you in, keep your customer record, provide your subscription, back up and restore your data at your request, honour your consent choices, respond to your requests and keep the service secure. We do not sell personal information, do not show advertising, and do not share data with data brokers.

Where it is stored (overseas disclosure)

Account, consent and backup data are stored with Supabase, Inc. on infrastructure in Tokyo, Japan (Amazon Web Services region ap-northeast-1). By creating an account you consent to your data being held there. Access is restricted by row-level security so each customer can only reach their own records; data is encrypted in transit (TLS) and at rest, and backups are additionally end-to-end encrypted.

Third parties

Sign in with Apple, Google Sign-In, Apple Health, Apple Maps and the App Store are provided by Apple and Google under their own privacy policies. Weather and elevation requests to Open-Meteo and surface lookups to OpenStreetMap's Overpass service include the approximate coordinates of the area you are looking at; no account information is sent with them. When you search for gear online or scan a barcode the built-in list does not recognise, the search words or barcode number are sent to KicksDB (kicks.dev) and, for barcodes, Open Products Facts; nothing else about you is sent. Supabase processes data on our behalf under its data processing terms.

Your choices and rights

You can use Pelt without an account. You can view and correct your profile in the app, export your data (GPX), turn backup off, and delete your account and all cloud data from Settings at any time. You may also ask us to access, correct or delete your personal information, or complain, by emailing hello@pelt.run; we respond within 30 days. If you are not satisfied you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). If you are in the United Kingdom or European Economic Area you also have the rights in the UK and EU GDPR, including access, rectification, erasure, portability and objection, and the right to complain to your supervisory authority; our legal bases are performance of our contract with you and your consent for health information.

Retention

Account records are kept while your account exists and are deleted when you delete it or after 24 months of inactivity, whichever comes first. Backups are replaced each time you back up. Consent records are kept for as long as your account exists so we can show what you agreed to.

Security

We use encryption in transit and at rest, end-to-end encryption for backups, row-level security on the database, hardware-backed key storage on your phone, an optional Face ID or Touch ID lock and a privacy screen in the app switcher. If a data breach is likely to cause serious harm we will notify you and the OAIC as the Notifiable Data Breaches scheme requires. No system is perfectly secure; keep your recovery key safe.

Problem reports, feedback and crash reports

If you send a problem report or feedback from Settings, we receive your message, any email address and rating you add, and (unless you switch it off) the app version, iOS version and iPhone model. If you have turned on Share With App Developers in iOS Settings, Apple gives Pelt crash and hang reports, which we send to ourselves with the app version, iOS version and iPhone model. Both use a random install number that is not linked to your account, and neither contains health data, routes or account details. They are stored with Cloudflare, Inc. (which may process them outside Australia, including in the United States), used only to fix problems and improve Pelt, and deleted after 24 months.

Children

Pelt is not intended for people under 16 and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will delete it.

Changes

We will update this Policy when our practices change and ask you to accept material changes in the app. The version and effective date are shown at the top.

Contact

Tanzim Islam Khan, hello@pelt.run.

This website and the early access list

pelt.run does not use cookies, analytics or advertising trackers. If you join the early access list we keep your email address, the time you joined and which link or advert brought you to the page, so we can email you once when Pelt launches and understand which adverts work. We do not sell or share the list. It is stored with Cloudflare, Inc. (which may process it outside Australia, including in the United States) and deleted after launch or when you ask. To stop abuse, the sign-up form keeps a one-way hash of your IP address for one hour. To be removed, email hello@pelt.run.