openpacemaker

Privacy

Your data.
Your control.

Last updated: June 2026

What we collect

Depending on which sign-in method you use, we may store:

  • Email address — only if you sign up via Google. Used for sign-in, and for a receipt if you choose to make an optional contribution. Not stored if you sign in with Strava (Strava does not share email with third-party apps).
  • Google account ID — only if you sign in with Google.
  • Strava athlete ID and OAuth tokens — if you connect Strava.
  • Activity data (distance, pace, heart rate, splits, etc.) fetched via the Strava API. GPS route polylines are not stored.
  • Coaching notes, conversation history, wellness, and training plan data from your Telegram sessions.
  • Payment metadata — Stripe customer / subscription identifiers, only if you make an optional contribution or hold a legacy subscription from before OpenPacemaker became free for everyone. Card details are never visible to us; they live with Stripe.

How we use it

Your data is used exclusively to provide you with personalised coaching analysis and responses. We do not sell your data, and we never share it for any other party's own purposes. To run the service we do rely on the sub-processors listed below. We do not post to Strava on your behalf.

To generate coaching responses, your messages and training data are sent, per request, to third-party AI model providers. We route these requests through OpenRouter and restrict them to vetted inference providers, explicitly excluding China-based providers. Those providers are configured not to retain your data after the request and not to use it to train their models. The underlying AI model may change as the technology improves — it is always operated under these same no-retention, no-training terms.

Data storage & retention

Data is stored in a PostgreSQL database hosted on Google Cloud (europe-west2). Access is restricted to the application service account.

Two different retention windows, so the “remembers you” promise is honest:

  • Chat transcripts — raw messages between you and the bot — auto-purge after 180 days as data minimisation.
  • Durable coaching memory — preferences, injuries, patterns, race results, the structured profile the coach uses to answer you — is retained for the lifetime of your account so the bot can still recall a 4-month-old niggle.
  • Activities and training plans — retained for the lifetime of your account.

You can wipe all three at any time with /delete confirm or by revoking Strava access.

Your rights

Data export (Article 20) — send /mydata to the bot and tap Export to receive a complete JSON download of everything stored for your account.

Deletion (Article 17) — you can request full deletion of your data at any time by:

  • Sending /delete confirm to the Telegram bot — permanent and immediate
  • Revoking access in Strava → Settings → My Apps (triggers automatic deletion)

Third-party services

  • Strava — activity data source and an authentication option (Strava Privacy Policy)
  • Google — an authentication option (Google Privacy Policy)
  • OpenRouter — AI gateway that routes coaching requests to third-party model providers; we restrict it to vetted, non-China inference providers configured for no data retention and no training (OpenRouter Privacy Policy)
  • AI model providers (currently DeepSeek and Anthropic, via the gateway above) — generate the coaching responses; data sent per request, not retained, not used for model training
  • Stripe — payment processing for optional contributions / legacy subscriptions (Stripe Privacy Policy)
  • Telegram — messaging interface
  • Google Cloud — hosting infrastructure

Contact

Questions? Message the bot, or email hello@openpacemaker.com.

← Back to openpacemaker.com