Back to Pelaris

Privacy Policy

Last updated:

Last updated: 4 July 2026 | Version 1.3

The Short Version

Pelaris is an AI-powered fitness coaching app. Here’s what you need to know:

  • We collect your profile, training data, and body measurements to generate personalised programs and coaching.
  • Your photos vanish. Body analysis photos are processed in memory and immediately discarded, never stored, never seen by a human.
  • Your identity is hidden from AI. We strip personal identifiers before AI processing. The AI never knows who you are.
  • Your data is stored in Sydney, Australia (australia-southeast1) during normal operation.
  • We never sell your data. We only share it with the service providers that run Pelaris, or with a third party (like an AI assistant or a fitness service) when you choose to connect one.
  • AI never trains on you. Your data is never used to train or improve any AI model, ours or Google’s.
  • You own the delete button. Delete your account and everything goes, profile, programs, measurements, conversations.
  • No ads. No data selling. We make money from subscriptions, not your data.

For the full details, read on.


1. Who We Are

Pelaris (“we”, “us”, “our”) is an AI-powered adaptive fitness coaching platform. We are the data controller responsible for your personal information.

Privacy Contact: Email: privacy@pelaris.io

If you have any questions about this policy or how we handle your data, please contact us at the email above.


2. Data We Collect

2.1 Information You Provide

DataExamplesWhy We Collect It
Account informationEmail address, display nameTo create and manage your account
Fitness profileGoals, experience level, available equipment, training preferences, injuriesTo personalise your training programs
Training dataWorkout sessions, exercise logs, sets, reps, weights, RPE ratings, completion statusTo track your progress and adapt your programs
Body measurementsShoulder, waist, hip circumferences, height, weight (from manual entry or AI analysis)To assess body composition and personalise training
Body photosPhotos you upload for AI body analysisTo estimate body measurements, photos are processed in memory and immediately discarded, never stored
Coach conversationsMessages you send to the AI Coach, preferences and health notes you shareTo provide personalised coaching responses
FeedbackSession feedback, RPE ratings, check-in responses, injury reportsTo adapt your programs based on how you feel
Strava activity dataSport type, date, duration, distance, heart rate, pace/speed, cadence, power, elevation gainTo understand training load and adapt your coaching program
Polar exercise dataSport type, duration, heart rate, pace, cadence, caloriesTo understand training load and adapt your coaching program
Wahoo workout dataSport type, duration, power, heart rate, cadence, distanceTo understand training load and adapt your coaching program
Subscription dataSubscription tier, status, purchase and renewal dates, the app store or platform usedTo manage paid subscriptions, if and when you purchase one. Card and bank details are handled by the payment platform (Apple App Store, Google Play, or Stripe via RevenueCat), not by Pelaris. We never see or store your full payment card number.

Pelaris is currently free to use and does not charge for any feature. Subscription billing is built but not yet enabled. The subscription and payment handling described in this policy applies only if and when paid subscriptions are switched on, at which point we will provide advance notice.

2.2 Information We Derive

DataHow It’s Created
AI-generated training programsGenerated by AI based on your profile, goals, methodology, and training history
Body composition estimatesDerived from your photos or manual measurements using AI analysis
Coach memoryPreferences, health notes, and context the AI Coach retains from your conversations
Training metrics and trendsCalculated from your workout logs (e.g., volume trends, RPE trajectory, streak data)
Completion analysisAI analysis of actual vs. target performance after each training week

2.3 Information Collected Automatically

DataPurpose
Device and browser informationTo optimise the app experience for your device
Usage analyticsScreen views, feature usage, funnel events (only if you consent)
Error and crash reportsTo identify and fix bugs (only if you consent)

3. How We Use Your Data

We use your data for these purposes only:

PurposeLegal Basis (GDPR)APP Reference
Provide the service (programs, coaching, tracking)Performance of contractAPP 3, 6
Personalise training based on your goals and feedbackPerformance of contractAPP 3, 6
AI processing of your data to generate recommendationsLegitimate interest + consent for health dataAPP 3, 6 (sensitive: explicit consent)
Body photo analysisExplicit consentAPP 3 (sensitive information)
Usage analytics to improve the appLegitimate interest (only if consented)APP 3, 6
Error reporting and crash diagnosticsLegitimate interest (only if consented)APP 3
Communicate with you about your accountPerformance of contractAPP 3
Comply with legal obligationsLegal obligationAPP 3, 6

We never use your data to:

  • Train or improve AI models
  • Sell to third parties
  • Serve advertising
  • Profile you for marketing purposes
  • Make automated decisions with legal or similarly significant effects without your ability to contest

4. How Our AI Works

Pelaris uses artificial intelligence (Google Gemini via Vertex AI) to power three core features:

4.1 Training Program Generation

The AI considers your goals, training history, fitness level, available equipment, chosen methodology, body measurements, and feedback to generate personalised, periodized training programs.

If you connect your Strava account, Pelaris imports a summary of your completed activities including sport type, date, duration, distance, and available performance metrics (heart rate, pace, cadence, power, elevation). GPS coordinates and route data are not imported. This data helps the AI understand your recent training load and adapt your programs accordingly.

4.2 AI Coaching

The AI Coach responds to your questions and requests, suggests exercise alternatives, logs health notes, and adapts your training. Coach conversations are processed in real time.

4.3 Coach Memory

The AI Coach remembers certain things you tell it across conversations to provide continuity:

  • What it remembers: Training preferences, health notes (e.g., “I have a shoulder injury”), equipment availability, and general coaching context you share.
  • Where it’s stored: Coach memory is stored in your account data in Firestore (australia-southeast1), the same way your training data is stored.
  • How long it remembers: Coach memory persists as long as your account is active.
  • Your control: You can ask the Coach to forget specific information at any time (say “forget my shoulder injury” or similar). You can also delete all coach memory by deleting your account.

Coach memory is subject to the same privacy protections as all your other data, it is never shared, never used for model training, and is permanently deleted when you delete your account.

4.4 Body Composition Analysis

When you upload a photo, AI estimates body measurements (shoulder, waist, hip circumferences) and classifies your body type. The photo is processed in memory only and immediately discarded.

What the AI Receives

Before your data reaches any AI model, we run it through our privacy scrubber. This strips out your name, email address, and other personal identifiers. The AI processes your fitness data without knowing who you are.

What the AI Does NOT Do

  • Does not store your photos. Photos exist in temporary server memory during processing only.
  • Does not train on your data. Pelaris uses Google’s pre-trained Gemini models via Vertex AI under enterprise terms. Google does not use your data to train or improve its AI models. Your prompts and responses are not retained by Google beyond the processing duration.
  • Does not diagnose medical conditions. AI outputs are fitness guidance, not medical advice.
  • Does not make decisions you can’t override. You can modify or reject any AI recommendation.

AI Transparency

All AI-generated content in Pelaris is clearly identified as AI-generated. Training programs, coaching responses, and body estimates are automated recommendations, no human reviews them before they reach you. If you believe an AI output is inaccurate or unsafe, you can contact us.


5. Body Analysis & Photo Processing

This section covers our highest-sensitivity data handling.

How Photos Are Handled

  1. You select a photo
  2. Photo is compressed (< 1MB) on your device
  3. Transmitted securely (HTTPS/TLS) to our processing server in Australia
  4. Server decodes photo in temporary memory (RAM only)
  5. AI extracts approximate body measurements
  6. Photo buffer is immediately released and garbage collected
  7. Only numerical measurements are returned and stored

Your photo is:

  • Held in temporary server memory for seconds only
  • Never written to any storage system, database, log file, or backup
  • Never viewed by any Pelaris employee, contractor, or third party
  • Never transmitted to any party other than the secure AI processing endpoint
  • Never used to train or improve any AI model

What IS stored: Numerical measurements only, shoulder circumference, waist circumference, hip circumference, weight estimate, height, body type classification, and training recommendations. These are stored as health information in your account.

Before your first body analysis, we will ask for your explicit consent. You can use Pelaris without ever using the body analysis feature. You can withdraw consent and delete all stored measurements at any time.


6. Data Sharing

Third-Party Services

ServiceProviderPurposeData SharedModel Training
Firebase AuthenticationGoogleUser login and identityEmail, auth tokensNo
Cloud FirestoreGoogleData storageAll account data (encrypted)No
Vertex AI (Gemini)GoogleAI processingScrubbed fitness data (no PII)No
Firebase AnalyticsGoogleUsage analytics (if consented)Anonymised eventsNo
Firebase HostingGoogleApp deliveryNone (static hosting)No
Strava APIStrava, Inc.Training activity importSport type, date, duration, distance, heart rate, pace, cadence, power, elevation, no GPS or route dataNo
Polar AccessLink APIPolar ElectroTraining activity importExercise data, sport, duration, heart rate, pace, cadence, caloriesNo
Wahoo Cloud APIWahoo FitnessTraining activity importWorkout summaries, power, heart rate, cadence, distance, durationNo
RevenueCat + app storesRevenueCat, Apple, Google, StripeSubscription and payment processing (only if you purchase a subscription)Pseudonymous user ID, subscription tier and status, purchase and renewal events. Full card details go to the app store or Stripe, never to Pelaris.No

All Google services are used under Google Cloud Platform enterprise terms, which explicitly state: “Google will not use Customer Data to train or improve Google’s generalized AI/ML models.”

Pelaris uses the Strava API to import activity data for connected athletes. By using the Strava integration, you acknowledge that Strava may monitor and collect certain usage data related to how Pelaris accesses the Strava API, in accordance with Strava’s own privacy policy and API Agreement.

Pelaris uses the Polar AccessLink API and Wahoo Cloud API for the same purpose. Wahoo may use data sent to the Wahoo Platform for its own business purposes per the Wahoo API Agreement.

AI Platform Integrations (MCP)

Pelaris can optionally connect to third-party AI assistants (such as Claude and ChatGPT) via the Model Context Protocol (MCP), so you can view and manage your training through an assistant you already use. This connection is entirely optional. If you never connect an AI assistant, none of the sharing described here occurs.

How the connection works: Data is shared only after you explicitly connect Pelaris to an AI assistant through OAuth 2.0 authorisation. During authorisation you are shown exactly which permissions (scopes) the assistant is requesting, and you must approve before any data flows. Pelaris uses a pseudonymous account identifier for the connection and does not send your email address or Firebase user ID to the assistant.

Permissions (scopes) you can grant: Access is controlled by scopes, each of which you approve at connection time:

  • Read your profile (profile:read). Your basic training profile, such as experience level, equipment, and availability.
  • Read your training (training:read). Programs, planned and completed sessions, session details, benchmarks, goals, and progress.
  • Manage your training (training:write). Create, modify, or delete planned and completed sessions, log workouts, swap exercises, generate programs and weekly plans, complete intake, manage goals, and submit check-ins and feedback.
  • Read your health data (health:read). Body composition data (measurements such as weight, waist, hip, shoulder, chest, height and muscle mass, ratios, archetype, and assessments) and injuries.
  • Manage your health data (health:write). Record body benchmarks and injuries.
  • Read coaching insights (coach:read). Coaching context and insights.
  • Stay connected (offline_access). Lets the assistant refresh its access without you re-authorising each session.

If you grant a “manage” (write) scope, the connected assistant can add to, change, or delete the corresponding data in your account. Most AI assistants ask you to confirm before they run an action, but that confirmation happens inside the assistant, not inside Pelaris. You control what an assistant can do by choosing which scopes to grant, and you can revoke access at any time.

Your control: You can see every connected AI assistant, the permissions it holds, and when it was last used, in the app (Profile > Connected Apps). You can disconnect any assistant at any time, which immediately revokes all of its access tokens so it can no longer read or modify your data. You can reconnect later with fresh consent. Data an assistant has already received is retained and handled under that assistant’s own privacy policy, not ours.

What Pelaris does NOT do:

  • We do not store your AI assistant conversation data.
  • We do not share your data with AI assistants without your explicit authorisation.
  • We do not sell your data to AI platform operators.
  • We do not grant an assistant any permission you did not approve.

Platform privacy policies: Each AI assistant has its own privacy policy governing how it handles data received from tools like Pelaris. We encourage you to review:

We Never Share Your Data With

  • Advertisers or ad networks
  • Data brokers
  • Social media platforms
  • Insurance companies
  • Employers
  • Any party for marketing purposes

Law Enforcement

We will only disclose personal data to law enforcement or government authorities if:

  • We are legally compelled to do so (court order, subpoena, or mandatory legal process)
  • We believe in good faith that disclosure is necessary to prevent imminent harm

If legally permitted, we will notify you before any disclosure.


7. Data Storage & Security

Where Your Data Lives

All data is stored on Google Cloud Platform servers in Sydney, Australia (region: australia-southeast1). Your data does not leave Australia during normal operation.

How Your Data Is Protected

MeasureImplementation
Encryption in transitAll data transmitted over TLS 1.2+ (HTTPS)
Encryption at restGoogle Cloud default encryption (AES-256) for all stored data
Access controlsFirestore security rules enforce per-user data isolation
PII scrubbingPersonal identifiers stripped before AI processing
No photo storageBody photos processed in memory only, never persisted
Rate limitingAPI rate limits prevent abuse
Input sanitisationPrompt injection detection and content length limits
AuthenticationFirebase Authentication with secure session management

Data Breach Response

In the event of a data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the Office of the Australian Information Commissioner (OAIC) within 72 hours of becoming aware of the breach, as required by the Notifiable Data Breaches (NDB) scheme.
  • We will notify affected users without undue delay, including a description of the breach, the data affected, and steps we are taking.
  • For users covered by GDPR, we will also notify the relevant supervisory authority within 72 hours per GDPR Article 33.

8. Your Rights

You have the following rights regarding your personal data:

RightWhat It MeansHow to Exercise It
AccessSee what data we hold about youContact privacy@pelaris.io
CorrectionFix inaccurate dataEdit in-app or contact us
DeletionDelete all your data permanentlyIn-app account deletion or contact us
Data portabilityReceive your data in a machine-readable formatContact privacy@pelaris.io (JSON export)
Withdraw consentStop optional data processing (analytics, body analysis)In-app settings or contact us
ObjectObject to processing based on legitimate interestContact privacy@pelaris.io
Restrict processingLimit how we use your data while a concern is resolvedContact privacy@pelaris.io
ComplaintLodge a complaint with a supervisory authoritySee “Complaints” section below

Account Deletion

You can delete your account from within the app (Profile > Settings > Delete Account). When you delete your account:

  • Your account is immediately disabled
  • All personal data is permanently deleted within 30 days, including your profile, all training programs, workout history, body measurements, goals, coaching conversations, and preferences
  • Firebase Authentication record is deleted
  • Anonymised, aggregated analytics data that cannot identify you may be retained

Automated Decision-Making

Pelaris uses AI to generate training programs, coaching responses, and body composition estimates. These are automated recommendations. Under GDPR Article 22, you have the right to:

  • Be informed that automated decision-making is used (this section serves that purpose)
  • Request human review of any AI-generated recommendation
  • Express your point of view and contest an AI decision
  • Contact us if you believe an AI output is inaccurate or unsafe

9. Data Retention

Data TypeRetention Period
Account and profile dataRetained while your account is active
Training data and workout historyRetained while your account is active
Body measurementsRetained while your account is active
Coach conversation historyRetained while your account is active
Body photosNever retained, processed and immediately discarded
Analytics data (if consented)Event-level analytics retained for up to 14 months, then deleted or aggregated. Aggregated statistics that cannot identify you may be kept longer.
Error/crash reports (if consented)Retained for up to 90 days
Subscription and payment recordsRetained while your account is active and for up to 7 years after a transaction where required for tax, accounting, or legal obligations
Deleted accountsAll data permanently deleted within 30 days of deletion request

10. Children’s Privacy

Pelaris is not intended for use by anyone under 16 years of age. We do not knowingly collect personal data from children under 16. If we discover that we have collected data from a child under 16, we will delete that data promptly.

If you are a parent or guardian and believe your child has provided personal data to Pelaris, please contact us at privacy@pelaris.io.


11. Cookies & Tracking

Pelaris is a web application. We use the following technologies:

TechnologyTypeConsent Required?Purpose
Firebase Auth tokensStrictly necessaryNoLogin and session management
Firestore local persistenceStrictly necessaryNoOffline functionality
Session cookiesStrictly necessaryNoApp functionality
Firebase AnalyticsOptional (analytics)YesUnderstanding feature usage

Your Choices

  • Essential technologies are required for the app to function and cannot be disabled.
  • Analytics are only enabled if you consent. You can withdraw consent at any time through your account settings.
  • We do not use any third-party advertising cookies or tracking pixels.

12. International Data Transfers

Your data is primarily stored and processed in Australia (Sydney, australia-southeast1). Google Cloud processes AI requests within its infrastructure under enterprise data processing terms.

For users in the European Economic Area (EEA) or United Kingdom:

  • Data transfers to Google Cloud are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission.
  • Google Cloud’s Data Processing Addendum addresses GDPR transfer requirements.

13. Changes to This Policy

We may update this privacy policy from time to time. When we make changes:

  • Minor changes (clarifications, formatting): Updated on this page with a new “Last updated” date.
  • Material changes (new data collection, new third parties, changes to your rights): We will notify you via email and/or an in-app notice at least 14 days before the changes take effect.

If a material change requires your renewed consent, we will ask for it explicitly. Continued use of Pelaris after being notified of changes constitutes acceptance of the updated policy.

We maintain a version history of this policy. Previous versions are available on request.

When you create your account or accept an updated policy, we record which version of this privacy policy you consented to (the version number shown at the top of this policy) on your account profile. This allows us to:

  • Track which users have accepted which policy version
  • Identify users who need to re-consent after a material change
  • Maintain an audit trail for legal compliance

If you have not accepted the current policy version, we may prompt you to review and accept it before continuing to use certain features.


14. Contact & Complaints

Privacy Inquiries

For any questions about this privacy policy or your personal data:

Email: privacy@pelaris.io

We aim to respond to all privacy inquiries within 14 days.

Complaints

Australia: If you believe we have breached the Australian Privacy Principles, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

European Union / United Kingdom: If you are in the EEA or UK and believe we have breached GDPR, you can lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en


For users covered by GDPR, here is a summary of our legal bases for processing:

Processing ActivityLegal Basis
Account creation and managementPerformance of contract (Art. 6(1)(b))
AI training program generationPerformance of contract (Art. 6(1)(b))
AI coaching responsesPerformance of contract (Art. 6(1)(b))
Processing health/fitness dataExplicit consent (Art. 9(2)(a))
Body photo analysisExplicit consent (Art. 9(2)(a))
Usage analyticsConsent (Art. 6(1)(a))
Error reportingLegitimate interest (Art. 6(1)(f))
Security and fraud preventionLegitimate interest (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))

16. United States: Consumer Health Data (Washington & California)

This section applies if you are a resident of the United States. It supplements the rest of this policy and, for the data it covers, controls if there is any conflict.

Consumer Health Data

Some of the data Pelaris collects is consumer health data, defined broadly under laws such as Washington’s My Health My Data Act (MHMDA) as information that identifies your past, present, or future physical or mental health. For Pelaris, consumer health data includes:

  • Your fitness and training data (workouts, sessions, exercise logs, RPE, and completion status)
  • Your body-metric data (height, weight, body measurements such as shoulder, waist, hip, chest circumference, muscle mass, ratios, archetype, and body composition estimates)
  • Injuries, health notes, and check-in responses you share
  • Data imported from connected fitness services (for example heart rate and other physiological metrics)
  • Consent to collect. We collect your consumer health data only after you provide affirmative consent, which you give when you create your account, complete intake, or use a health-related feature (such as body analysis). You can decline health-related features and still use core parts of Pelaris.
  • Separate consent to share. We do not sell your consumer health data, and we do not share it with third parties except (a) with service providers and processors who help us operate Pelaris under contract (see Section 6), or (b) at your specific direction. Connecting a third-party AI assistant (see “AI Platform Integrations (MCP)” in Section 6) is a sharing action that requires your separate, affirmative authorisation at the time you connect, and you choose exactly which data the assistant may access.
  • No sale. We do not, and will not, sell your consumer health data. We do not use it for targeted advertising.

Your Rights

If you are a US resident, you may:

  • Withdraw consent to the collection or sharing of your consumer health data at any time. Withdrawing consent stops future processing but does not affect processing that already occurred.
  • Access and confirm what consumer health data we hold about you and with whom we have shared it.
  • Delete your consumer health data specifically, separate from deleting your whole account. On a valid deletion request we will delete the health data we hold and direct our processors to do the same, subject to narrow legal exceptions.
  • Not be discriminated against for exercising any of these rights.

California residents (CCPA/CPRA): In addition to the above, you have the right to know, access, correct, delete, and obtain a portable copy of your personal information, and to limit the use of sensitive personal information (which includes health data). We do not sell or “share” (as CCPA/CPRA defines those terms for cross-context behavioural advertising) your personal information. You may use an authorised agent to submit a request, and you will not be discriminated against for exercising your rights.

How to Exercise These Rights

To exercise any right in this section, or to appeal a decision we make about a request, contact our privacy contact at privacy@pelaris.io. We will verify your request and respond within the timeframes required by applicable law. Washington residents may also complain to the Washington State Attorney General, and California residents to the California Privacy Protection Agency or California Attorney General.


17. Australian Privacy Principles Compliance

Pelaris complies with the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988:

APPPrincipleHow We Comply
1Open and transparent managementThis privacy policy; privacy contact available
2Anonymity and pseudonymityUsers can use a display name; PII scrubbed for AI processing
3Collection of solicited personal informationWe only collect data necessary for the service; sensitive data (health, body) requires explicit consent
4Dealing with unsolicited personal informationWe do not seek or retain unsolicited personal information
5Notification of collectionThis policy and in-app notices inform you of collection
6Use or disclosureData used only for stated purposes; not disclosed without consent
7Direct marketingWe do not use personal data for direct marketing without consent
8Cross-border disclosureData stored in Australia; AI processing under Google Cloud enterprise terms with appropriate safeguards
9Adoption, use, or disclosure of government-related identifiersNot applicable, we do not collect government identifiers
10Quality of personal informationYou can correct your data in-app or by contacting us
11Security of personal informationEncryption, access controls, PII scrubbing, secure infrastructure (see Section 7)
12Access to personal informationYou can request access to all data we hold about you
13Correction of personal informationYou can correct inaccurate data in-app or by contacting us

This privacy policy is effective as of 4 July 2026.

Pelaris is committed to protecting your privacy. If anything in this policy is unclear, please contact us at privacy@pelaris.io, we’d rather explain than confuse.