← Back
Privacy Policy
Last Updated: March 5, 2026
Your Privacy Matters: This Privacy Policy explains how PIONEER ("we", "our", "us") collects, uses, protects, and shares your personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Information
Data Controller: PIONEER Fitness Ltd
Address: United Kingdom
Email: [email protected]
Data Protection Officer: [email protected]
2. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent (Art. 6(1)(a) UK GDPR): You have given explicit consent for processing your personal data and health data
- Contract (Art. 6(1)(b) UK GDPR): Processing is necessary to provide the Service you signed up for
- Legal Obligation (Art. 6(1)(c) UK GDPR): We must retain certain records for tax and legal compliance
- Legitimate Interests (Art. 6(1)(f) UK GDPR): Fraud prevention, security, and service improvement where balanced against your rights
Special Category Data: Your health and fitness data is classified as "special category data" under Article 9 UK GDPR. We only process this data with your explicit consent, which you can withdraw at any time.
3. Information We Collect
3.1 Personal Information You Provide
- Account Information: Email address, first name, last name, date of birth, password (hashed with bcrypt)
- Profile Information: Height, weight, gender, fitness goals, activity level, military background (optional)
3.2 Special Category Data (Health Data)
With your explicit consent, we collect and process:
- Fitness Data: Workout sessions, exercise types, duration, intensity, personal records
- Nutrition Data: Meal logs, calorie intake, macronutrients, dietary preferences
- Health Information: Injuries, rehabilitation progress, fitness assessments
- Biometric Data (from connected apps): Heart rate, steps, sleep data, GPS routes
3.3 Information Collected Automatically
- Device Information: Device type, operating system, browser type, IP address
- Usage Data: Pages visited, features used, session duration, interactions
- Security Data: Login attempts, IP addresses, timestamps (for fraud prevention)
- Cookies: Essential cookies for authentication, optional analytics cookies
3.4 Information from Third Parties
With your permission, we receive data from:
| Service |
Data Received |
Purpose |
| Strava |
Activities, routes, performance metrics |
Sync workouts |
| Google Fit |
Steps, heart rate, sleep data |
Track daily activity |
| Apple Health |
Workouts, health metrics, vitals |
Comprehensive tracking |
| Garmin |
Activities, biometric data |
Sync training data |
4. How We Use Your Information
4.1 Service Delivery (Legal Basis: Contract)
- Create and manage your account
- Provide personalized fitness and nutrition plans
- Track your progress and achievements
- Enable community features and social interactions
- Process payments and subscriptions (if applicable)
- Provide customer support
- Send essential service-related notifications
4.2 Health Data Processing (Legal Basis: Explicit Consent)
We use your health and fitness data to:
- Generate personalized workout recommendations
- Calculate nutrition targets based on your goals
- Provide progress tracking and analytics
- Identify training patterns and suggest improvements
- Enable challenge participation and leaderboards
You can withdraw consent at any time by emailing [email protected] or deleting your account.
4.3 AI-Powered Features (Legal Basis: Consent)
AI Processing Disclosure: We use OpenAI's API to provide AI-powered workout suggestions and nutrition advice. When you use AI features:
- Your data may be processed by OpenAI (a third-party AI provider)
- AI-generated advice is NOT medical advice and may be inaccurate
- You should consult a healthcare professional before following AI recommendations
- We do not use your data to train OpenAI's models (per our agreement with OpenAI)
4.4 Analytics and Improvement (Legal Basis: Legitimate Interest)
We use anonymized, aggregated data to:
- Analyze usage patterns and trends
- Improve app features and user experience
- Develop new features and products
- Create statistical reports (e.g., "35% of users prefer morning workouts")
- Conduct fitness and health research
What is Anonymized Data? Anonymized data has been permanently stripped of all identifiers (name, email, IP address, device ID). This data cannot be traced back to you and is not considered "personal data" under UK GDPR.
4.5 Marketing Communications (Legal Basis: Consent)
Only if you opt in, we may send you:
- Product updates and new feature announcements
- Fitness tips and training advice
- Promotional offers and discounts
You can unsubscribe at any time by clicking "unsubscribe" in any email or updating your preferences.
5. Data Sharing and Third Parties
5.1 Third-Party Service Providers
We share data with trusted processors who help operate the Service:
| Provider |
Purpose |
Data Shared |
Location |
| Self-Hosted Server |
Store data and host application |
All account and usage data |
UK |
| Cloudflare |
Security, DDoS protection, CDN |
IP addresses, request data |
EU/UK |
| OpenAI |
AI-powered features (optional) |
Anonymized fitness queries |
US (SCCs) |
| Pexels API |
Stock images for UI |
No personal data |
EU |
| USDA FoodData API |
Nutrition database |
No personal data |
US |
All processors are bound by data processing agreements (DPAs) and comply with UK GDPR.
5.2 Anonymized Data Sharing (Legal Basis: Legitimate Interest)
We may share anonymized, aggregated data with:
- Research Partners: For fitness and health research studies
- Industry Partners: For fitness technology development
- Business Partners: For market research and trend analysis
Examples of anonymized data: "Average workout duration is 45 minutes", "Users aged 25-34 prefer HIIT training"
5.3 What We DON'T Share
Your Personal Data is Protected: We will NEVER sell or share your personally identifiable information (name, email, date of birth, location, individual workout data, health data) with third parties for their marketing purposes.
5.4 Legal Disclosures (Legal Basis: Legal Obligation)
We may disclose your information if required by law or to:
- Comply with court orders, subpoenas, or legal obligations
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Respond to lawful requests from UK authorities (police, ICO, etc.)
6. International Data Transfers
Your data is primarily stored in the UK. When data is transferred outside the UK/EEA (e.g., to OpenAI in the US), we ensure adequate protection through:
- Standard Contractual Clauses (SCCs): EU-approved contracts for international transfers
- Data Processing Agreements: Contracts requiring GDPR-equivalent protections
- Adequacy Decisions: Transfers only to countries with adequate data protection laws
7. Data Security
7.1 Security Measures
We implement industry-standard security measures:
- Encryption: TLS/SSL for data in transit, AES-256 for data at rest
- Password Security: Bcrypt hashing with cost factor 12
- Access Controls: Role-based access, multi-factor authentication for staff
- Security Monitoring: 24/7 monitoring for suspicious activity
- Regular Audits: Security audits and vulnerability assessments
- Incident Response: Procedures for handling data breaches
7.2 Data Breach Notification
In the event of a data breach affecting your personal data, we will:
- Notify the ICO (Information Commissioner's Office) within 72 hours if required
- Notify affected users without undue delay if the breach poses a high risk
- Provide details about the breach, its impact, and our response
- Offer support and guidance to affected users
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
8.1 Right to Access (Art. 15)
- Request a copy of all personal data we hold about you
- Receive information about how we use your data
- Free of charge (first request), subsequent requests may incur reasonable admin fees
- Response within 1 month of request
8.2 Right to Rectification (Art. 16)
- Correct inaccurate or incomplete personal data
- Update your profile information at any time via account settings
8.3 Right to Erasure / "Right to be Forgotten" (Art. 17)
- Delete your account instantly in the app: Profile → Settings → Delete account
- Or request deletion (no login needed) at pioneer-fitness.com/request-deletion.html
- Account and personal data deleted within 30 days
- Some data may be retained for legal compliance (e.g., financial records for 7 years)
- Anonymized data (no longer linked to you) may be retained indefinitely
8.4 Right to Restrict Processing (Art. 18)
- Request temporary restriction of data processing
- Useful while disputing data accuracy or processing legitimacy
8.5 Right to Data Portability (Art. 20)
- Receive your data in a structured, commonly used format (JSON, CSV)
- Transfer your data to another service provider
- Download your data via account settings or by requesting an export
8.6 Right to Object (Art. 21)
- Object to processing based on legitimate interests
- Object to direct marketing at any time (we must stop immediately)
8.7 Right to Withdraw Consent (Art. 7(3))
- Withdraw consent for health data processing at any time
- Withdraw consent for marketing emails at any time
- Note: Withdrawal does not affect lawfulness of processing before withdrawal
8.8 Right to Lodge a Complaint
If you believe we have violated your data protection rights, you can:
- Contact us first: [email protected]
- Lodge a complaint with the ICO:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk
8.9 How to Exercise Your Rights
To exercise any of these rights, contact us at:
Email: [email protected]
Subject Line: "Data Subject Request - [Your Right]"
Include: Your name, email, and specific request
We will respond within 1 month. If the request is complex, we may extend by 2 months and will inform you.
9. Data Retention
| Data Type |
Retention Period |
Legal Basis |
| Account Information |
Until account deletion + 30 days |
Contract |
| Health & Fitness Data |
Until account deletion + 30 days |
Consent |
| Payment Records |
7 years after last transaction |
Legal Obligation (tax law) |
| Consent Records |
7 years after withdrawal/deletion |
Legal Obligation (proof of consent) |
| Anonymized Analytics |
Indefinitely (no personal data) |
Legitimate Interest |
| Security Logs |
12 months |
Legitimate Interest |
| Support Tickets |
3 years after resolution |
Legitimate Interest |
10. Children's Privacy
Our Service is intended for users aged 16 and older. We do not knowingly collect data from individuals under 16. If we discover we have collected data from a person under 16, we will delete it immediately and notify the account holder.
See our Age Verification Policy for more details.
11. Cookies and Tracking
11.1 Essential Cookies (No Consent Required)
- Session Cookies: Keep you logged in
- Security Cookies: CSRF protection, bot detection (Cloudflare Turnstile)
11.2 Optional Cookies (Require Consent)
- Analytics Cookies: Understand usage patterns (anonymized)
- Preference Cookies: Remember your settings
11.3 Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies will affect Service functionality.
12. Automated Decision-Making and Profiling
We use limited automated processing for:
- Workout Recommendations: Based on your fitness level and goals
- Nutrition Suggestions: Based on your dietary preferences and targets
- Fraud Detection: Automated checks for suspicious account activity
You have the right to:
- Object to automated decision-making
- Request human review of automated decisions
- Express your point of view and contest the decision
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on the Service with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice in the app
Your continued use after changes constitutes acceptance of the updated policy. If you do not agree, you may delete your account.
14. Contact Us
For questions about this Privacy Policy, to exercise your rights, or to raise concerns:
Email: [email protected]
Data Protection Officer: [email protected]
Address: PIONEER Fitness Ltd, United Kingdom
15. Related Documents
16. Regulatory Compliance
This Privacy Policy complies with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR) 2003
- ICO (Information Commissioner's Office) Guidelines
Summary: We collect your data to provide the Service, use anonymized data for development, protect your health data with explicit consent, and give you full control over your information. Your privacy and trust are our top priorities.