Pacelytics

Privacy in the App

Information pursuant to Art. 13 GDPR on the processing of personal data in the iOS app Pacelytics.

Last updated: September 23, 2026 Courtesy translation – the German version is legally binding.

Controller and overview

Controller

Michael Descher, Julius-Wertheimer-Str. 41, 76437 Rastatt, Germany
Email: info@codewave.de
Phone: +49 152 33970021

The most important points first

Pacelytics does not operate a server of its own. There is no user account with the provider, no ads, no tracking, and no analytics or crash reporting tools. The app reads your running workouts from Apple's Health app, analyzes them on your device, and presents them as charts. Your health data does not leave your device in the process; the provider does not receive it and has no access to it.

The app has read-only access to Health and changes nothing there. Which types of data it may read is up to you, in Apple's permission dialog.

What data is processed where

Broken down by where the data comes from and where it resides: from Health, on the device, in the map display, and in photos, notifications, and the purchase.

Data from Apple Health

With your permission, the app reads the following from Health:

From this data, the app calculates the charts, personal bests, heart rate zones, and recurring routes on your device. The purpose is to provide the app's functions. This is health data within the meaning of Art. 9 GDPR. The processing is based on your explicit consent, which you give by granting access in the Health permission dialog (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR). It takes place exclusively on your device.

You can withdraw your permission at any time, in iOS under Settings → Privacy & Security → Health → Pacelytics. After that, the app can no longer read any data; analyses already stored locally remain on the device until you delete the app.

Even in the free version, the app reads in your entire running history and stores the analysis locally; however, only your latest 20 runs are analyzed and displayed there. After you purchase the full history, the rest is available without reading it in again.

Data on your device

So that the app can show something right away at launch and only has to load what's new, it stores calculated analyses and your inputs locally in the app's storage:

This data is neither synced via iCloud nor uploaded or transmitted to the provider. The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship) and, for the health data, additionally your consent, see above.

Location

The app does not determine your location and does not use any location service. The GPS points come exclusively from the workout routes of your runs that are stored in Health.

Map display (Apple Maps)

In the “Your loops” area, the app overlays your running routes on a map. For the map background, iOS loads map tiles from Apple's servers via Apple Maps (MapKit); in the process, your IP address and the map section currently shown, among other things, are transmitted to Apple. The running routes themselves are only overlaid on the map on your device and are not transmitted.

The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple's Privacy Policy applies. The legal basis is Art. 6(1)(b) and (f) GDPR (displaying the feature you called up).

Photos for running shoes

You can add a photo to a running shoe you've created. For this, the app uses the iOS photo picker: the app receives only the one image you select and has no access to your photo library. The image is stored exclusively locally in the app's storage and is removed when you delete the shoe. The legal basis is Art. 6(1)(a) GDPR; the feature is voluntary.

Notifications

If you turn on “Notify on new personal best” in the app's settings and iOS allows it, the app checks during the sync with Health whether a new run beats a personal best, and then schedules a notification locally. Nothing is sent via a server, and the provider learns nothing about it. You can turn off notifications at any time in the app's settings or in iOS. The legal basis is Art. 6(1)(a) GDPR.

Purchase of the full history

You unlock the full history with a one-time in-app purchase. The purchase is handled entirely through Apple's App Store: your Apple ID and payment details are processed by Apple alone. Via Apple's StoreKit, the app only learns whether the purchase exists and remembers that locally; even when restoring an earlier purchase, the app communicates only with Apple. The provider receives neither payment nor account data. In App Store Connect, Apple provides the provider only with aggregated sales figures that cannot be traced back to you and – if you have agreed to share analytics data in iOS – aggregated usage statistics.

The provider of the App Store is Apple Distribution International Ltd. (address see above). The legal basis is Art. 6(1)(b) GDPR.

Retention and deletion

The locally stored data remains on your device until you delete the app; it is removed along with it. Your data in Health is unaffected, because the app never changes it. You can rebuild the local analysis at any time in the app's settings with “Resync everything”; you delete a shoe, along with its photo, in the shoe management.

As with all apps, the locally stored data may be included in a device backup (iCloud backup or a backup on a computer) if you have enabled one. Whether and for how long backups are kept is controlled in the iOS settings; Apple's privacy policy applies to this, not the provider's.

Recipients and what does not take place

Recipients

The provider receives no personal data from the app. The only recipient is Apple, insofar as this is necessary for making the app available and for the purchase via the App Store, as well as for the map display. Processing may also take place outside the EU; Apple relies on the EU Commission's standard contractual clauses and the EU-US Data Privacy Framework for this.

What does not take place

Apart from Apple (Maps and App Store), the app does not establish connections to any servers.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and the right to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future. To exercise your rights, a message to info@codewave.de is enough.

Since the provider receives no personal data from the app, it holds no data that it could disclose or delete in response to a request. You view and delete your locally stored data yourself, in the app, in Health, and by deleting the app.

Independently of this, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR); the authority responsible for the provider is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

Obligation to provide data

You are not obliged to allow access to your Health data. Without this permission, however, Pacelytics cannot display any runs; sensible use of the app is then not possible.

Changes

This policy will be updated whenever the app changes. The version published here at any given time applies.