PaceWolf ("we", "our", or "us") is a social fitness accountability app that lets you set step and distance goals and run challenges with friends. This policy explains what data we collect, why we collect it, and how we protect it.
PaceWolf never collects, holds, processes, or transfers money. A "pledge" is an optional, private promise between friends — ₹0 works perfectly. Any settlement happens directly between users in their own UPI apps; PaceWolf only records what a user marks as paid, and takes no commission.
1. Data We Collect
Account information
- Mobile phone number — used solely for OTP-based sign-in via Firebase Authentication.
- Display name and profile photo — shown to other participants in your challenges.
Fitness data
- Step count and distance (and, for your end-of-challenge summary, exercise sessions and active calories) — read from Health Connect on Android or Apple Health on iOS, only with your explicit permission.
- On Android, with the background-access permission, we read these metrics periodically while the app is closed so your progress, reminders, and home-screen widget stay current. You can revoke this at any time.
- This data is used only to measure your progress in challenges you join. It is never used for advertising and is never sold to third parties.
Payment information
- UPI ID (payment address) — optional, stored only if you choose to enter it, so friends can pay you back directly. We never initiate, process, or hold payments; any pledge is settled directly between users.
Device data
- Push notification token (Firebase Cloud Messaging on Android, or Apple APNs on iOS) — used only to send you notifications about your challenges. Stored on our servers and never shared.
Usage data
- Challenge activity (km logged per day, challenge results) — necessary to run the app's core features.
2. How We Use Your Data
- Authenticate your account and keep it secure.
- Display your progress and leaderboard position to challenge participants.
- Calculate challenge results and settlement amounts.
- Send push notifications about challenge events (starts, completions, reminders).
- Show your UPI VPA to other participants so they can settle payments with you.
We do not use your data for advertising, profiling, or any purpose not listed above.
3. Health Connect & Apple Health
PaceWolf reads fitness data (steps, distance, and — for the end-of-challenge summary — exercise and active calories) from Health Connect (Android) or Apple Health (iOS) only to measure your challenge progress. In line with Google's Health Connect requirements, this data is never used for advertising or marketing, is never sold or shared with data brokers, and is transmitted only to our own servers to compute and show your progress to the other participants in your challenge. It is deleted when you delete your account.
You can revoke access at any time — on Android in the Health Connect app (Permissions → PaceWolf), or on iOS in Settings → Privacy & Security → Health → PaceWolf. Revoking stops all further reads immediately; it does not delete your account.
4. Data Sharing
We share the minimum data required to operate the app:
- Other challenge participants — your display name, profile photo, km progress, and UPI VPA are visible to people in the same challenge as you.
- Firebase (Google) — your phone number is sent to Firebase solely to verify OTP codes. See Firebase Privacy.
- Push services — your device token is sent to Firebase Cloud Messaging (Android) or Apple APNs (iOS) to deliver notifications to your device.
We do not sell, rent, or trade your personal data to any third party.
5. Data Retention
Your data is retained for as long as your account is active. Challenge history (results, km records) is kept after a challenge ends so participants can reference settlement details.
To request deletion of your account and all associated data, email us at privacy@pacewolf.run. We will process deletion requests within 30 days.
6. Security
All data is transmitted over HTTPS. Authentication tokens are stored in the platform's secure storage (Android Keystore / iOS Keychain). We use Railway's managed PostgreSQL with restricted network access for our database. We do not store OTP codes — they are verified and discarded by Firebase.
7. Children
PaceWolf is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.
8. Your Rights
- Access — you can view all your data in the app (profile, challenge history, stats).
- Correction — you can update your display name and UPI VPA in the app.
- Deletion — email privacy@pacewolf.run to delete your account and all data.
- Portability — contact us to request a copy of your data in JSON format.
9. Changes to This Policy
We may update this policy as the app evolves. We will notify you of material changes via an in-app notice. The "Last updated" date at the top always reflects the current version.
10. Contact
Questions or concerns about this policy? Email us at privacy@pacewolf.run.