pacero
Как работаетЗабегиСравнениеЦенаFAQСкачать →
Как работаетЗабегиСравнениеЦенаFAQСкачать →
← Home
— Legal document

Personal Data Processing Policy

This is a convenience translation of the Russian-language Policy. If the two versions differ, the Russian version prevails.

This Policy has been developed in accordance with Federal Law No. 152-FZ of July 27, 2006 “On Personal Data” and sets out how the personal data (hereinafter “PD”) of users of the Pacero service is processed and protected. The service includes the pacero.ru website, the Telegram bot @pacero_bot, and the Pacero mobile apps for iOS and Android.

1.Personal Data Operator

The PD operator is Individual Entrepreneur Roman Alekseevich Bezaev, Taxpayer ID (INN) 525610246441. For inquiries about PD processing: r.bezaev@gmail.com.

2.What Data Is Processed

The Operator processes the following categories of user data:

  • Telegram account data: user_id, username, and name provided by the user when registering in the @pacero_bot bot (obtained automatically when the user taps /start);
  • Data for building the plan: the selected race, target distance, target time, current pace, and answers to the questionnaire (age, running experience, training schedule, weekly mileage);
  • Workout data from Garmin Connect — only if the user has connected the service themselves: distance, pace, heart rate, duration, and workout type;
  • Workout data from other devices, including Apple Watch — if the user submits it to the service themselves: distance, duration, start time, and heart rate (average and maximum);
  • Workout data from Apple Health (HealthKit, iOS) — only if the user has installed the Pacero app for iOS and granted access to health data. The following metrics of completed runs are sent to the Pacero server: distance, duration, start time, activity type, source, indoor flag, elevation gain, active calories, and average and maximum heart rate where available. For new runs, these are supplemented with average cadence, heart rate range, and splits for each full kilometer: the time, average heart rate, and cadence of each kilometer. Cadence is calculated on the device from steps over the duration of the run. On first connection, one year of history is retrieved to assess running fitness and pre-fill the questionnaire; after that, only new runs. Synchronization runs automatically, including in the background, until access is revoked. The route and other workout measurements — heart rate, distance, and step series, power, stride length, ground contact time, vertical oscillation — are read on the device for the map, charts, and run card and are not sent to the Pacero server. This data is used solely to create and adjust the training plan: it is not used for advertising and is not stored in iCloud. It is not shared with third parties, except for the language model provider, which receives completed workout metrics in de-identified form to adjust the plan (Section 6). Synchronization can be turned off in the app settings or in iOS settings; when it is turned off and when the user signs out, the local queue and data access are removed.
  • Workout data from Health Connect (Android) — only if the user has installed the Pacero app for Android and allowed access in Health Connect. With the user’s permission, the app reads running workouts (exercise sessions), distance, heart rate, steps, speed, power, active calories, elevation gain, and workout routes; the route is read only with separate consent. Separate Health Connect permissions allow the app to read data in the background, so that new runs reach the plan without opening the app, and to read history older than 30 days: on first connection, up to one year of run history is retrieved to assess running fitness and pre-fill the questionnaire. Only the summary metrics of each run are sent to the Pacero server: start date and time, distance, duration, average and maximum heart rate, active calories, elevation gain, the indoor workout flag, and the app that recorded the workout. For new runs, these are supplemented with average cadence, heart rate range, and splits for each full kilometer: the time, average heart rate, and cadence of each kilometer. Cadence is calculated on the device from steps over the duration of the run. These metrics are needed to take workouts into account in the plan and the forecast. The route and other workout measurements — heart rate, speed, power, and step series — are read on the device for the map, charts, and run card and are not sent to the Pacero server. Data from Health Connect is not shared with third parties, except for language model providers, which receive completed workout metrics in de-identified form to create and adjust the plan (Section 6). Synchronization can be turned off in the app profile — Pacero then deletes from the server the history summary obtained from Health Connect — or permissions can be revoked in Health Connect settings. Runs already counted in the plan remain in its reports until the account is deleted. Pacero only reads Health Connect data and does not write anything to it;
  • Images uploaded by the user — screenshots of workout summaries from a third-party tracker that the user sends to the @pacero_bot bot or attaches in the Pacero app for iOS or Android so that the service can recognize the metrics (distance, time, pace, heart rate, cadence). The image is sent to a language model provider that supports image recognition (Section 6) and is not stored by the Operator — neither in the database nor in file storage. Only the numerical workout metrics confirmed by the user remain in the service. If a screenshot is sent to the bot, a copy of the image remains in the chat on Telegram’s side;
  • Location for weather: when location access is granted, the iOS and Android app automatically requests a forecast near the user; approximate location is sufficient for this. It is rounded on the device and on the server and is passed through Pacero to MET Norway without account data. Coordinates are not stored in the profile or the database; the forecast is cached temporarily. Weather can be turned off in the app, and location access can be turned off in iOS or Android settings.
  • GPS run recording: location is used on the device to measure distance and pace after the user taps “Start run”, including when the screen is locked. On Android, a service with a persistent notification runs for the duration of the recording: it starts only when “Start run” is tapped and stops when the run ends; the app does not request background location access outside of recording. The route is saved locally for the map and run card. The summary metrics of the run — distance, time, and pace by segment — are sent to the Pacero report without the exact route coordinates. Loading the weather does not start run recording.
  • Route map: on iOS, the map is rendered by Apple MapKit using Apple Maps; on Android, by the MapLibre library using OpenFreeMap maps (tiles.openfreemap.org). The device downloads map tiles directly from the map service: the service sees the device’s IP address and the requested map area, but not the track or the Pacero account. The track is sent neither to the Pacero server nor to the map service; the map snapshot for the run card is created on the device.
  • Conversations with the coach: the text of the question, the conversation history, running data from the questionnaire, the available plan, and workout metrics and analyses are sent to OpenAI to generate a personalized answer. The app asks for explicit permission to share data with OpenAI before AI features are opened. Chat history is stored locally in the app for the current account; message texts are not written to server logs.
  • Photo for the run card: a selected photo or a camera shot is processed on the device to design the card. It is not sent to Pacero or OpenAI. Saving to the gallery (“Photos” on iOS) and sharing via the system menu happen only when the user chooses to do so.
  • Email — the user provides the address when paying or shares it through a sign-in service. When paying, the address is needed so that the fiscal receipt is sent to it. When signing in with Sign in with Apple, the address comes from Apple in a signed token if the user has allowed it to be shared; Apple lets the user share a forwarding address (@privaterelay.appleid.com) instead of the real one, and in that case the Operator receives only the forwarding address. When signing in with Google, the Operator receives the address from the Google-signed token only if Google confirms that the address is verified. When signing in with Yandex ID, the Operator receives the primary address from the Yandex profile if the user has allowed access to it. The address is used for receipts and for restoring access to the account; no mailings are sent to it;
  • Name — if the user allowed it to be shared when signing in with Sign in with Apple or it is present in the Google profile, and also if the user has specified in the app profile how they would like to be addressed. The name is used only to address the user in the app; it can be changed or deleted in the profile;
  • Apple ID identifier — when signing in with Sign in with Apple. This is not the Apple ID itself but a persistent identifier that Apple issues separately for each app: the Operator uses it to recognize a returning user and cannot match it with an account in other services;
  • Google account identifier — when signing in with Google, the Operator receives a persistent account identifier and uses it to sign in to Pacero. The Operator does not receive the Google password;
  • Yandex ID identifier — when signing in with Yandex ID in the Android app, the Operator receives a persistent Yandex account identifier and uses it to sign in to Pacero. The Operator does not receive the Yandex password. Matching email addresses in Apple, Google, and Yandex do not automatically merge Pacero accounts;
  • Purchase data — transaction identifier, purchased product, amount, currency, and date. When paying in the App Store, the app sends the Operator an Apple-signed transaction: access is granted by the Operator’s server, not by the app on the device. In the Android app, purchases are paid via YooKassa; Google Play’s billing system is not used;
  • Technical data: timestamps of requests to the bot, message and session identifiers, and, for app sessions, the platform (iOS or Android) and the app version.

Payment details (card numbers, CVV/CVC, expiration dates) are not processed or stored by the Operator. Payments are accepted entirely on the side of the YooKassa payment service (YooMoney, non-bank credit institution LLC, INN 7750005725), including in the Pacero app for Android, and for App Store purchases in the Pacero app for iOS, on Apple’s side.

3.Purposes of Processing

  • providing the service — creating a personalized training plan and adjusting it every week;
  • recognizing workout screenshots uploaded by the user — to fill in the workout report without entering numbers manually;
  • communicating with the user in the Telegram bot: clarifying questions, reminders, service messages;
  • maintaining accounting and tax records (generating fiscal receipts);
  • keeping the service running, diagnosing incidents, and protecting against abuse;
  • de-identified usage statistics to improve the product.

4.Legal Grounds for Processing

  • consent of the PD subject — Clause 1, Part 1, Article 6 of Law 152-FZ (expressed through the user’s actions: starting the bot, signing in to the app, filling out the questionnaire, making a payment, and, for workout and location data, granting access to them in the iOS, Android, or Health Connect system prompt);
  • the need to perform a contract to which the PD subject is a party — the public offer published at pacero.ru/oferta;
  • fulfillment of obligations imposed by the legislation of the Russian Federation on taxes and fees and on accounting.

The service is intended for persons aged 16 and over. It does not accept a questionnaire with an age under 16.

5.Data Retention Period

5.1. The Operator stores the user’s personal data for the entire period during which the service is provided and for an additional three (3) years after the service ends — within the limitation period under the Civil Code of the Russian Federation.

5.2. Fiscal data (receipts, payment information) is stored for the period established by the tax legislation of the Russian Federation.

5.3. The user may at any time submit a request to delete their data as described in Section 8 of this Policy.

6.Transfer to Third Parties

6.1. The Operator transfers user data only to those third parties that are necessary to provide the service, and only to the extent sufficient for them to perform their functions:

  • Telegram — the messenger through which the service is provided (messaging with the bot);
  • YooKassa (YooMoney, non-bank credit institution LLC, INN 7750005725) — accepting payments and generating receipts;
  • Apple — Sign in with Apple and accepting payment in the App Store for users of the Pacero app for iOS. In such a purchase, Apple acts as the seller: Apple accepts the payment details, and the Operator receives only a signed confirmation of the completed transaction. Data processing on Apple’s side is governed by Apple’s own privacy policy;
  • Google — Sign in with Google in the iOS and Android apps. The app uses the official Google SDK; the Operator verifies the signed Google token and creates a Pacero session. Access to Gmail, contacts, and Google Drive is not requested. Data processing on Google’s side is governed by Google’s own privacy policy;
  • Yandex — sign-in with Yandex ID in the Android app. The app uses the official Yandex LoginSDK; the Operator verifies the received token through the Yandex ID service and creates a Pacero session. Only the account identifier and email address are requested; access to Yandex Mail, Yandex Disk, and other services is not requested. Data processing on Yandex’s side is governed by Yandex’s own privacy policy;
  • Garmin Connect — only at the initiative of the user who has connected the service to transfer workout data to the bot;
  • OpenAI — processing of requests to the language model. The first purpose is generating and adjusting the training plan: race preparation parameters and completed workout metrics are sent in de-identified form, without name, username, user_id, or email. The second is recognizing workout screenshots: the model needs the image itself, so the image is sent in full and the Operator cannot de-identify it; user identifiers are not sent along with the image, and the file itself is not stored by the Operator;
  • xAI via OpenRouter — backup plan generation: if OpenAI does not respond or takes too long to respond, the request to generate the training plan is sent to a backup xAI language model via the OpenRouter platform. The data is the same as for OpenAI: race preparation parameters in de-identified form, without name, username, user_id, or email. Screenshots, conversations with the coach, and workout analyses are not sent to the backup provider;
  • OpenAI — coach chat: receives the question, the history, and the running context described in Section 2. Pacero does not add the account identifier, name, or email to the context; information that the user has written in free text is sent as part of the message.
  • MET Norway (Norwegian Meteorological Institute) — receives rounded coordinates for the weather forecast, without name, email, or Pacero account identifier.
  • OpenFreeMap — the base map in the Android app: receives the device’s IP address and the requested map area from the device, without the track or Pacero account data;
  • Hosting provider — hosting the server side of the service (VPS located in the Russian Federation).

6.2. The Operator does not sell users’ personal data and does not share it for third-party marketing.

6.3. Workout and health data from Apple Health and Health Connect is used only for training plan features: tracking runs, creating and adjusting the plan, forecasting race results, workout analyses, and coach answers in the chat. This data is not sold, is not shared with third parties for advertising — advertising platforms, data brokers, or other intermediaries — and is not used to show advertising, including personalized advertising, or for decisions about lending, insurance, or employment. There is no advertising in the Pacero apps. The use of data obtained from Health Connect complies with the Health Connect Permissions Policy, including the Limited Use requirements.

6.4. Calculation before sign-in. On first launch, with your permission, the iOS and Android app reads workouts from Apple Health or Health Connect and analyzes them on the device. To calculate running fitness and the forecast before sign-in, only aggregated metrics are sent to the Pacero server: weekly running volume, the longest run, best results at standard distances with dates, experience, and age if you have provided it, as well as the race distance and date you have selected. The server does not store this data and does not link it to an account. The list of workouts, heart rate, routes, and sex are not sent before sign-in. The app does not read date of birth or sex from Apple Health.

In addition, the app sends onboarding screen events (which screen is open, which action was selected) with an anonymous installation identifier. They are stored for funnel statistics and are linked to the account after sign-in; when the account is deleted, the installation identifier is removed from these events.

7.Rights of the Personal Data Subject

The user has the right to:

  • receive information from the Operator about the processing of their PD;
  • demand that their PD be corrected, blocked, or destroyed if the data is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated purpose of processing;
  • withdraw consent to PD processing at any time;
  • appeal the Operator’s actions or inaction to the authorized body for the protection of the rights of personal data subjects (Roskomnadzor) or in court.

8.Withdrawal of Consent and Data Deletion

8.1. A user of the Pacero app for iOS or Android can delete their account themselves: “Profile” tab → “Delete account” → confirmation. The account and the data associated with it are deleted immediately. Only the data that the Operator is required to retain by law (Clause 5.2 of this Policy) and the service records listed on the pacero.ru/delete-account page are retained, for the periods specified there. That page also provides step-by-step instructions and explains how to request deletion without the app.

8.2. To withdraw consent to PD processing and request data deletion, the user sends an email to r.bezaev@gmail.com with the subject “Withdrawal of consent to PD processing” or “Pacero account deletion”.

8.3. To identify the user, the email must include the email address the user signs in to the app with via Google, Yandex ID, or Apple, the Telegram username, or the email address used for payment.

8.4. The Operator deletes the user’s data within 30 calendar days of receiving the request, except for data that the Operator is required to retain by law (Clause 5.2 of this Policy).

9.Cross-Border Data Transfer

9.1. The server side of the service and the Operator’s database are located in the Russian Federation.

9.2. Some data is transferred to the third parties listed in Section 6 whose infrastructure is located outside the Russian Federation. This is a cross-border transfer, and it covers:

  • de-identified race preparation parameters and completed workout metrics — sent to the language model provider to generate and adjust the plan;
  • workout screenshots uploaded by the user — sent to the language model provider to recognize the metrics;
  • the user’s messages and their Telegram account data — messaging with the bot takes place on Telegram’s infrastructure;
  • rounded coordinates for the weather forecast — MET Norway; the device’s IP address and the requested map area — OpenFreeMap (Android app).

9.3. Uploading a screenshot is a voluntary action by the user. Workout metrics can be entered manually, in which case the image is not sent anywhere.

9.4. Data is transferred to Garmin Connect solely at the initiative and with the direct consent of the user, who connects this service to their account in the bot themselves.

10.Security Measures

The Operator applies the following measures to protect PD:

  • data transfer over secure communication channels (TLS/HTTPS);
  • restricted access to data — only the Operator has administrative access;
  • encryption of secrets (API tokens, access keys) on the server;
  • regular backups with controlled access.

11.Contacts

For any questions about the processing of personal data, the user may contact the Operator at r.bezaev@gmail.com.

— PD Operator
Individual Entrepreneur Roman Alekseevich Bezaev
Taxpayer ID (INN): 525610246441
Email for PD inquiries: r.bezaev@gmail.com
Version of October 7, 2026
pacero

ИИ-тренер для iPhone

Бегуну

  • Забеги 2027
  • Калькулятор темпа
  • Подготовка к марафону
  • Подготовка к полумарафону
  • Сколько бегут марафон
  • Бег на 5 км
  • Бег на 10 км
  • Разряды по бегу
  • VO2max
  • Как выбрать цель на забег

Документы

  • Публичная оферта
  • Политика конфиденциальности
  • Возврат средств

Связь

Техподдержка
r.bezaev@gmail.com
Правовые вопросы, возвраты, ПДн
r.bezaev@gmail.com
ИП Безаев Роман Алексеевич · ИНН 525610246441pacero.ru · 2026