PRIVACY NOTICE
Last updated 30 July 2026
Who is responsible for your data
Paggered is operated by Turbo Shandy Labs. [TO BE COMPLETED BEFORE LAUNCH: registered legal entity name, company number, registered address, and ICO registration number if applicable.] A privacy notice has to identify the controller, and that detail is deliberately left blank here rather than guessed.
For anything about your data, contact support@paggered.app.
What we collect
Everything below is data you enter or that the app records as you use it. The complete, authoritative list is whatever your own data export returns — see Getting your data out below.
Account and identity
- Email address, and a password hash or passkey credential.
- Username, display name, avatar, and profile visibility setting.
- Communication preferences, timezone, and unit preferences.
Health and fitness data
This is the sensitive category. It includes workouts and individual sets, personal records, bodyweight and body measurements, injuries and limitations you tell the coach about, recovery check-ins, nutrition logs, goals, and form-check videos.
Under UK GDPR this is special-category data about your health, which requires a specific condition for processing in addition to a lawful basis. [TO BE COMPLETED BEFORE LAUNCH: the Article 9 condition relied on — most likely explicit consent — and how that consent is obtained and recorded.]
Coach conversations
The messages you send the Pags coach, and the training context the app includes with them so the coach can answer usefully.
Social activity
Follows, posts, likes, comments, challenge participation, blocks, and any reports you file. What other users can see depends on your profile visibility setting.
Billing
Subscription status and tier. Card details are entered directly with Stripe and are never seen or stored by Paggered.
Technical
Standard request data such as IP address and browser user agent, held by our host. Error diagnostics, with identifiers and request contents stripped before they are sent — see Error monitoring below.
Why we use it, and our lawful basis
[TO BE REVIEWED BEFORE LAUNCH: the mapping below is our honest description of purpose and basis, but the basis assigned to each purpose needs confirming.]
- Running the app — logging workouts, showing your history and progress, generating coaching. Performance of our contract with you.
- Health and fitness data specifically — the app cannot function without it, and it is the reason you are here. Requires an Article 9 condition as above.
- Payments — taking subscription payments and meeting tax obligations. Contract, and legal obligation for records.
- Transactional and lifecycle email — account emails, and weekly summaries or nudges you can turn off in Settings. Contract, and legitimate interests for optional messages.
- Keeping the service working and safe — error monitoring, abuse and spend limits, moderating reported content. Legitimate interests.
Who we share it with
We do not sell your data and we do not use it for advertising. It is shared only with the service providers below:
All of them act on our instructions, with one exception worth calling out. Stripe is the seller of record for your purchase, not Turbo Shandy Labs — so for payment data Stripe decides how it is handled under its own terms rather than only following ours. Your receipt may show the purchase as sold through Stripe. See Refunds & cancellation. [TO BE REVIEWED BEFORE LAUNCH: whether Stripe is a joint controller or an independent controller for payment data under this arrangement changes what this section must say.]
| Provider | What they do | What they receive |
|---|---|---|
| Supabase | Database, authentication, and file storage | Account details and all training, nutrition, recovery, and social data |
| Vercel | Application hosting and delivery | Request metadata such as IP address and user agent |
| Stripe | Payments, subscriptions, and tax — as seller of record, not only as our processor | Email address, billing and payment details, subscription status |
| OpenRouter | AI model routing for the Pags coach and workout generation | The messages you send the coach, plus the training context included in the prompt |
| Resend | Transactional and lifecycle email | Email address and the content of emails sent to you |
| Sentry | Error monitoring | Error diagnostics with identifiers and request payloads stripped before sending |
Some of these providers operate outside the UK. [TO BE COMPLETED BEFORE LAUNCH: the transfer mechanism relied on for each provider — typically the UK International Data Transfer Addendum to the EU Standard Contractual Clauses — and confirmation that a data processing agreement is in place with each.]
We may also disclose data where the law requires it, or to establish or defend legal claims.
How the AI coach handles your data
Coach messages and the training context sent with them are processed by AI models routed through OpenRouter. Two things are enforced in our code on every single request, not configured per-feature:
- Zero data retention is requested, so the model provider does not store the request.
- Provider data collection is denied, so your data is not used to train models.
Only an approved list of models can be used; a request naming any other model is rejected rather than sent. These controls sit at a single point every AI request passes through, so no feature can bypass them.
Coaching is generated by an AI model. It is guidance, not medical advice, and it can be wrong. See the Terms.
Error monitoring
When something breaks we receive a diagnostic report. Before any report leaves the app it is stripped: request bodies are removed entirely, headers are dropped unless specifically allowed, query strings are reduced, and email addresses and access tokens are redacted from any remaining text. No user identifier is attached, so reports are not linked to you.
Cookies and local storage
Paggered sets no advertising or analytics cookies. What it does set:
- Authentication cookies — these keep you signed in. The app cannot work without them.
- Local storage on your device — unsent workout drafts so you do not lose a session offline, and whether you have dismissed certain prompts. This stays on your device.
Because these are strictly necessary or things you asked for by using the feature, no consent banner is required. [TO BE CONFIRMED BEFORE LAUNCH by the reviewer.]
How long we keep it
Your data is kept for as long as your account exists. Delete your account and it is removed, other than records we must keep by law — principally billing records for tax purposes. [TO BE COMPLETED BEFORE LAUNCH: specific retention periods, including how long billing records are kept.]
Getting your data out, and deleting it
Both are self-service in Settings, and neither requires you to ask us:
- Export gives you a machine-readable file containing everything we hold about you.
- Delete account permanently removes your account and its data.
Your rights
You have the right to access your data, correct it, have it deleted, restrict or object to how it is used, and receive it in a portable format. Where we rely on consent you can withdraw it at any time. Export and deletion are self-service above; for anything else email support@paggered.app.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
Children
Paggered is not intended for under-18s and we do not knowingly collect their data. [TO BE CONFIRMED BEFORE LAUNCH: the minimum age, and whether it is enforced at signup.]
Changes to this notice
If we change this notice we will update the date at the top, and tell you directly if the change materially affects you.