PTAI
PrivacyTermsDelete accountSupport
Your data

Privacy Policy

This policy explains how NSTARC LTD handles personal information when you use the PTAI mobile app, website, support channels and service emails.

Effective 21 September 2026· NSTARC LTD · company 13709681
On this page
At a glanceWho we areInformation we collectHow and why we use itHealth and fitness dataAI and voice featuresWho receives informationInternational transfersHow long we keep itYour rightsCalifornia disclosuresSecurityContact and complaints

Privacy at a glance

  • PTAI uses your information to provide personalised fitness, nutrition and coaching features.
  • We do not sell personal information, show advertising or share information for cross-context behavioural advertising.
  • We do not use your data to train our AI models or permit our model providers to train on it.
  • When diagnostic capture is enabled, authorised staff can use AI conversation content in restricted observability logs for debugging and support. It expires after no more than 30 days.
  • PTAI sends crash reports to Sentry so we can find and fix defects. They contain no personal information and are not linked to your account.
  • Raw voice recordings are processed in memory for transcription and are not stored by PTAI.
  • You can withdraw consent or delete your account in Privacy settings. For access, correction, portability, restriction, objection or privacy help, email privacy@pocket-team.ai.

1. Who we are

NSTARC LTD is the controller responsible for PTAI. PTAI is our trading name.

NSTARC LTD
Company number 13709681
68 Queen Street
Sheffield, S1 1WR
United Kingdom

Email: privacy@pocket-team.ai

PTAI is intended for adults aged 18 and over. We do not knowingly collect personal information from children.

2. Information we collect

Depending on the features you use, we collect the following categories:

CategoryExamplesSource
Account and identityName, email address, date of birth, account identifiers and login statusYou and Auth0; Apple or Google when you choose social sign-in
Profile, health and fitnessSex, height, weight, BMI, body-fat estimates, fitness level, goals, constraints, discomfort and exercise feedbackYou and calculations or inferences made from your entries
Training and nutritionPlans, sessions, exercises, performance, metrics, meals, nutrient estimates and saved coaching outputsYou and PTAI features
Coach and AI interactionsPrompts, conversations, transcripts, relevant account context, responses and tool inputs or results. When diagnostic capture is enabled, copies may be retained in restricted observability logs for debugging and support for up to 30 days. If you report a coach reply, we keep that reply, the reason you chose and any comment you add. Request metadata may include time, model, status, latency and technical identifiers.You, your use of PTAI and our AI services
SubscriptionProduct, entitlement, trial, renewal and transaction identifiers; we do not receive your full payment-card detailsApple App Store, Google Play and RevenueCat
CommunicationsSupport requests and service-email delivery informationYou, Google Workspace and Resend
Device, usage and securityIP address, device/app information, timestamps, authentication events, API requests, errors and security logsYour device and our systems
Crash diagnosticsStack traces and error messages, device model and operating-system version, app version and build, and a random installation identifier. Crash reports are not linked to your account and contain no profile, health, training or conversation content. The installation identifier is reset if you reinstall PTAI.Your device, through Sentry
Push notificationsA push notification token for each device you enable reminders on, a random per-installation device identifier, your device platform and app version, and your device's time zone so reminders arrive at a sensible local hour. We also keep your reminder preferences and a record of which reminders were sent and when. Reminder text never contains a weight, measurement, meal, exercise or any other health detail, so nothing sensitive appears on your lock screen.Your device, through the Expo Push Service

Authentication is managed by Auth0. When you sign in through Apple or Google, PTAI receives account identifiers and tokens needed to sign you in, not your provider password. If account linking is suggested, you choose whether to link the identities.

We do not currently collect data from Apple Health, Health Connect or wearables; precise location; user photos; advertising identifiers; or website analytics. We will update this policy and obtain any required permission before adding materially different collection.

3. How and why we use information

PurposeUK/EU legal basis
Create and secure your account; provide plans, tracking, coaching, saved records and subscription accessPerformance of our contract with you
Personalise fitness, nutrition and coaching using information that may reveal healthPerformance of our contract and your explicit consent for health data
Transcribe voice entries and generate AI responsesPerformance of our contract and, where health data is included, your explicit consent
Send welcome, authentication, password-reset, account and other service messagesPerformance of our contract and our legitimate interest in operating the service
Answer support requests; debug failures; prevent fraud and misuse; protect PTAI and usersOur legitimate interests in reliable, secure services; explicit consent where the processing involves health data, unless another legal condition applies
Meet tax, accounting, consumer, privacy and other legal duties; establish or defend legal claimsLegal obligation and our legitimate interests

Where we rely on legitimate interests, we consider whether the use is necessary and balance it against your rights. You may object as explained below. We do not use solely automated processing to make decisions that produce legal or similarly significant effects, such as setting prices, suspending accounts or deciding access to the service.

4. Health and fitness information

Information about pain, discomfort, physical constraints, body measurements, exercise performance and nutrition may be health data and may receive extra protection under data-protection law. PTAI asks for explicit consent before using this information for personalised features.

Consent is your choice, but this processing is necessary for PTAI's current personalised training, body-measurement, nutrition and coaching service. During initial setup, PTAI asks for consent before offering a subscription or collecting profile details. If you do not consent, you cannot activate the current service and may exit setup; PTAI will begin deleting the provisional sign-in and setup data created for you.

If you withdraw consent after activation, personalised product features and new diagnostic conversation capture stop. Previously captured diagnostic content expires within 30 days, subject only to a documented legal or security hold. You can still contact the privacy team, use deletion controls, give consent again, and manage an existing app-store subscription.

You may withdraw consent in the app or by contacting us. Withdrawal does not make earlier lawful processing unlawful and does not cancel a subscription billed by Apple or Google. PTAI provides an immediate subscription-management link with the withdrawal warning. Please do not include diagnoses, medical records or other medical details that PTAI has not asked for.

PTAI is a fitness and wellbeing service, not a medical service. Its processing of fitness information does not make PTAI a healthcare provider.

5. AI, coach conversations and voice

PTAI sends your prompt and the minimum relevant context through the Pydantic AI Gateway, operated by Pydantic Services Inc. (the provider of Pydantic Logfire), to Anthropic to produce a response. OpenAI is used for voice transcription and to compute search embeddings that power exercise suggestions. During a short transition that we are completing, some exercise-search requests still pass through Vercel AI Gateway. We may add or replace model providers only after privacy review and will update this policy before a material change. We select commercial API arrangements that do not use inputs or outputs to train provider models.

For a limited diagnostic period, PTAI may copy AI prompts, conversation transcripts, relevant context, responses and tool inputs or results to Pydantic Logfire when diagnostic capture is enabled. We use this content only to investigate errors and answer support requests. Access is restricted to authorised staff who need it for an investigation, it is not used for model training or advertising, and it expires after no more than 30 days. The capture is controlled by a configuration switch and can be disabled without a code change; when disabled, observability contains only content-free request metadata.

An AI or transcription provider may separately retain API content temporarily for abuse monitoring or security under its commercial terms—normally no more than 30 days unless a shorter or zero-retention setting applies. PTAI's content-free request metadata also expires after 30 days.

For voice input, audio is held only in memory long enough to send it to OpenAI for transcription. PTAI does not store the raw recording. The resulting transcript is handled like other text you submit. Entries you choose to save—such as a meal, goal or workout record—remain part of your account under the normal retention rules even if AI helped create them.

AI output can be inaccurate or unsuitable. You can edit, reject or ignore it. PTAI does not make legal or similarly significant decisions about you solely using AI.

You can report any coach reply in the app with the flag button under it, or by pressing and holding it. When you do, we store a copy of that one reply (not the rest of the conversation), the reason you chose and any comment you add, linked to your account. Authorised staff use reports only to review the reply and make the coach safer and more accurate. A report is kept for as long as your account exists, is deleted with your account, and is included when you request a copy of your data.

6. Who receives information

We disclose information only as needed to operate PTAI, comply with law or protect rights. Our service providers act under contracts and receive only information relevant to their role:

  • Identity: Auth0, Apple and Google.
  • Hosting, databases, delivery and logs: Railway, Expo/EAS and Pydantic Logfire.
  • Mobile crash diagnostics: Sentry. Crash reports are configured to exclude personal information and are not linked to your account.
  • AI and transcription: the Pydantic AI Gateway (Pydantic Services Inc.), Anthropic and OpenAI, plus Vercel AI Gateway during a short transition we are completing; any additional model provider will complete privacy review and be disclosed here before material use.
  • Subscriptions: Apple App Store, Google Play and RevenueCat.
  • Transactional email and support: Resend and Google Workspace.
  • Push notifications: the Expo Push Service, which delivers reminders through Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. These receive your device's push token and the reminder text only; they do not receive your account, health or training data.
  • Domain services: GoDaddy.
  • Professional and legal recipients: advisers, auditors, insurers, regulators, courts or law enforcement where reasonably necessary or legally required.

If NSTARC is reorganised, financed, sold or transfers PTAI, information may be disclosed under confidentiality and transferred as part of that transaction, subject to applicable law.

We do not sell personal information, share it for cross-context behavioural advertising, or display third-party advertising in PTAI.

7. International transfers

NSTARC is based in the United Kingdom. Some providers process information in the United States or other countries. Where information leaves the UK or European Economic Area, we use an adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum and/or EU Standard Contractual Clauses, together with supplementary protections where required. Contact us for information about the safeguard relevant to your data.

PTAI is not currently offered or actively marketed to residents of the European Economic Area. Before doing so, NSTARC will assess and complete any EU-representative requirement and update this policy.

8. How long we keep information

We keep information only as long as reasonably needed for the purpose described, including legal, accounting and dispute requirements. Our intended periods are:

InformationNormal retention
Account, profile, workouts, goals, plans, metrics, nutrition and saved outputsWhile the account is active. An account inactive for 24 months may be scheduled for deletion after at least 30 days’ warning.
Deleted account data in live systemsDeleted or irreversibly de-identified within 30 days, subject to limited exceptions below.
Backups containing deleted dataExpire through rotation within 90 days and are not restored except for disaster recovery.
Raw voice recordingNot stored by PTAI.
AI diagnostic conversation logs and request metadataWhen diagnostic capture is enabled, conversation content in PTAI's restricted observability logs expires after no more than 30 days. Content-free request metadata also expires after 30 days. AI providers may separately retain API content under commercial abuse/security controls, normally up to 30 days.
Coach replies you reportThe reported reply, your reason and any comment are kept while your account is active and deleted with it.
Mobile crash diagnosticsUp to 90 days in Sentry, then deleted by its retention setting.
API and security logsNormally up to 90 days, unless needed longer for a documented security incident or legal claim.
Support correspondenceUp to 2 years after the matter closes.
Service-email delivery recordsNormally up to 30 days, subject to provider operations and security requirements.
Push notification tokensKept while the device is registered for reminders. A token that stops working, or that you turn off by signing out, is deleted within 30 days.
Reminder historyUp to 90 days, then deleted. Your reminder preferences are kept for the life of the account.
Consent and privacy-request recordsUp to 6 years to demonstrate compliance and resolve claims.
Required transaction and accounting recordsUp to 6 years from the end of the relevant financial year, or longer if law requires.

We may preserve a limited record beyond these periods where reasonably necessary for fraud prevention, security, a legal hold, a dispute or another legal obligation. Access is restricted and the information is deleted when the reason ends.

9. Your privacy rights

We make the following core controls available regardless of where you live, subject to lawful exceptions. You may ask us to:

  • confirm whether we process your information and provide access to it;
  • correct inaccurate or incomplete information;
  • delete your account and personal information;
  • provide information you supplied in a portable format;
  • restrict processing or object to processing based on legitimate interests; and
  • withdraw consent at any time.

Use Privacy settings to withdraw consent or delete your account. Email privacy@pocket-team.ai for access, correction, portability, restriction, objection or other privacy help. You do not need to use legal wording; tell us clearly what you need. See our account deletion instructions. We normally respond within one month. We may ask you to verify control of the account, usually by signing in or replying from the account email. An authorised agent may submit a request, but we will verify their authority and may verify the request with you.

You may complain to the UK Information Commissioner’s Office at ico.org.uk. If you live elsewhere, you may also contact your local data-protection authority. We would appreciate the chance to address your concern first.

10. California privacy disclosures

NSTARC does not currently meet the business thresholds that generally make the California Consumer Privacy Act, as amended by the CPRA, applicable. We nevertheless provide the core access, correction, deletion and portability controls described above and will reassess our obligations as PTAI grows.

The categories of personal information we collect, their sources, purposes, recipients and retention are described in sections 2, 3, 6 and 8. These may include identifiers, customer records, commercial information, internet or electronic activity, approximate location derived from IP address, audio/transcript information, inferences, and sensitive personal information such as account credentials and health-related information.

We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We do not use sensitive personal information to infer characteristics for advertising or other purposes that would trigger a right to limit. We do not knowingly sell or share the personal information of people under 18. We will not discriminate against you for making a privacy request.

Do Not Track and Global Privacy Control

Our public website does not currently use advertising or cross-site tracking technologies, so browser Do Not Track or Global Privacy Control signals do not change its behaviour. We do not allow other parties to collect personal information about your online activities across third-party sites through PTAI for advertising.

Website cookies

We do not currently use non-essential cookies or website analytics. Essential hosting and security technologies may process technical requests to deliver the site. Before introducing analytics or similar technologies, we will update our notice and provide consent controls where required.

11. Security

We use technical and organisational measures designed to protect information, including encryption in transit and at rest, role-based access restrictions, multi-factor authentication for relevant administrative access, secrets management, logging, backups, recovery planning, incident response and dependency review. No online service can guarantee absolute security. Please use a unique password and contact us promptly if you suspect account misuse.

12. Changes, contact and complaints

We may update this policy as PTAI or the law changes. We will post the new policy here, change the effective date and email or provide an in-app notice where a change materially affects your rights or how we use information.

Questions or requests can be sent to:

Privacy Lead
NSTARC LTD
68 Queen Street
Sheffield, S1 1WR
United Kingdom
privacy@pocket-team.ai
PTAI · Pocket TeamA service of NSTARC LTD · © 2026 Pocket Team
HomePrivacyTermsDelete accountSupport