Privacy at a glance
- PTAI uses your information to provide personalised fitness, nutrition and coaching features.
- We do not sell personal information, show advertising or share information for cross-context behavioural advertising.
- We do not use your data to train our AI models or permit our model providers to train on it.
- When diagnostic capture is enabled, authorised staff can use AI conversation content in restricted observability logs for debugging and support. It expires after no more than 30 days.
- PTAI sends crash reports to Sentry so we can find and fix defects. They contain no personal information and are not linked to your account.
- Raw voice recordings are processed in memory for transcription and are not stored by PTAI.
- You can withdraw consent or delete your account in Privacy settings. For access, correction, portability, restriction, objection or privacy help, email privacy@pocket-team.ai.
1. Who we are
NSTARC LTD is the controller responsible for PTAI. PTAI is our trading name.
NSTARC LTDCompany number 13709681
68 Queen Street
Sheffield, S1 1WR
United Kingdom
Email: privacy@pocket-team.ai
PTAI is intended for adults aged 18 and over. We do not knowingly collect personal information from children.
2. Information we collect
Depending on the features you use, we collect the following categories:
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, date of birth, account identifiers and login status | You and Auth0; Apple or Google when you choose social sign-in |
| Profile, health and fitness | Sex, height, weight, BMI, body-fat estimates, fitness level, goals, constraints, discomfort and exercise feedback | You and calculations or inferences made from your entries |
| Training and nutrition | Plans, sessions, exercises, performance, metrics, meals, nutrient estimates and saved coaching outputs | You and PTAI features |
| Coach and AI interactions | Prompts, conversations, transcripts, relevant account context, responses and tool inputs or results. When diagnostic capture is enabled, copies may be retained in restricted observability logs for debugging and support for up to 30 days. If you report a coach reply, we keep that reply, the reason you chose and any comment you add. Request metadata may include time, model, status, latency and technical identifiers. | You, your use of PTAI and our AI services |
| Subscription | Product, entitlement, trial, renewal and transaction identifiers; we do not receive your full payment-card details | Apple App Store, Google Play and RevenueCat |
| Communications | Support requests and service-email delivery information | You, Google Workspace and Resend |
| Device, usage and security | IP address, device/app information, timestamps, authentication events, API requests, errors and security logs | Your device and our systems |
| Crash diagnostics | Stack traces and error messages, device model and operating-system version, app version and build, and a random installation identifier. Crash reports are not linked to your account and contain no profile, health, training or conversation content. The installation identifier is reset if you reinstall PTAI. | Your device, through Sentry |
| Push notifications | A push notification token for each device you enable reminders on, a random per-installation device identifier, your device platform and app version, and your device's time zone so reminders arrive at a sensible local hour. We also keep your reminder preferences and a record of which reminders were sent and when. Reminder text never contains a weight, measurement, meal, exercise or any other health detail, so nothing sensitive appears on your lock screen. | Your device, through the Expo Push Service |
Authentication is managed by Auth0. When you sign in through Apple or Google, PTAI receives account identifiers and tokens needed to sign you in, not your provider password. If account linking is suggested, you choose whether to link the identities.
We do not currently collect data from Apple Health, Health Connect or wearables; precise location; user photos; advertising identifiers; or website analytics. We will update this policy and obtain any required permission before adding materially different collection.
3. How and why we use information
| Purpose | UK/EU legal basis |
|---|---|
| Create and secure your account; provide plans, tracking, coaching, saved records and subscription access | Performance of our contract with you |
| Personalise fitness, nutrition and coaching using information that may reveal health | Performance of our contract and your explicit consent for health data |
| Transcribe voice entries and generate AI responses | Performance of our contract and, where health data is included, your explicit consent |
| Send welcome, authentication, password-reset, account and other service messages | Performance of our contract and our legitimate interest in operating the service |
| Answer support requests; debug failures; prevent fraud and misuse; protect PTAI and users | Our legitimate interests in reliable, secure services; explicit consent where the processing involves health data, unless another legal condition applies |
| Meet tax, accounting, consumer, privacy and other legal duties; establish or defend legal claims | Legal obligation and our legitimate interests |
Where we rely on legitimate interests, we consider whether the use is necessary and balance it against your rights. You may object as explained below. We do not use solely automated processing to make decisions that produce legal or similarly significant effects, such as setting prices, suspending accounts or deciding access to the service.
4. Health and fitness information
Information about pain, discomfort, physical constraints, body measurements, exercise performance and nutrition may be health data and may receive extra protection under data-protection law. PTAI asks for explicit consent before using this information for personalised features.
Consent is your choice, but this processing is necessary for PTAI's current personalised training, body-measurement, nutrition and coaching service. During initial setup, PTAI asks for consent before offering a subscription or collecting profile details. If you do not consent, you cannot activate the current service and may exit setup; PTAI will begin deleting the provisional sign-in and setup data created for you.
If you withdraw consent after activation, personalised product features and new diagnostic conversation capture stop. Previously captured diagnostic content expires within 30 days, subject only to a documented legal or security hold. You can still contact the privacy team, use deletion controls, give consent again, and manage an existing app-store subscription.
You may withdraw consent in the app or by contacting us. Withdrawal does not make earlier lawful processing unlawful and does not cancel a subscription billed by Apple or Google. PTAI provides an immediate subscription-management link with the withdrawal warning. Please do not include diagnoses, medical records or other medical details that PTAI has not asked for.
PTAI is a fitness and wellbeing service, not a medical service. Its processing of fitness information does not make PTAI a healthcare provider.
5. AI, coach conversations and voice
PTAI sends your prompt and the minimum relevant context through the Pydantic AI Gateway, operated by Pydantic Services Inc. (the provider of Pydantic Logfire), to Anthropic to produce a response. OpenAI is used for voice transcription and to compute search embeddings that power exercise suggestions. During a short transition that we are completing, some exercise-search requests still pass through Vercel AI Gateway. We may add or replace model providers only after privacy review and will update this policy before a material change. We select commercial API arrangements that do not use inputs or outputs to train provider models.
For a limited diagnostic period, PTAI may copy AI prompts, conversation transcripts, relevant context, responses and tool inputs or results to Pydantic Logfire when diagnostic capture is enabled. We use this content only to investigate errors and answer support requests. Access is restricted to authorised staff who need it for an investigation, it is not used for model training or advertising, and it expires after no more than 30 days. The capture is controlled by a configuration switch and can be disabled without a code change; when disabled, observability contains only content-free request metadata.
An AI or transcription provider may separately retain API content temporarily for abuse monitoring or security under its commercial terms—normally no more than 30 days unless a shorter or zero-retention setting applies. PTAI's content-free request metadata also expires after 30 days.
For voice input, audio is held only in memory long enough to send it to OpenAI for transcription. PTAI does not store the raw recording. The resulting transcript is handled like other text you submit. Entries you choose to save—such as a meal, goal or workout record—remain part of your account under the normal retention rules even if AI helped create them.
AI output can be inaccurate or unsuitable. You can edit, reject or ignore it. PTAI does not make legal or similarly significant decisions about you solely using AI.
You can report any coach reply in the app with the flag button under it, or by pressing and holding it. When you do, we store a copy of that one reply (not the rest of the conversation), the reason you chose and any comment you add, linked to your account. Authorised staff use reports only to review the reply and make the coach safer and more accurate. A report is kept for as long as your account exists, is deleted with your account, and is included when you request a copy of your data.
6. Who receives information
We disclose information only as needed to operate PTAI, comply with law or protect rights. Our service providers act under contracts and receive only information relevant to their role:
- Identity: Auth0, Apple and Google.
- Hosting, databases, delivery and logs: Railway, Expo/EAS and Pydantic Logfire.
- Mobile crash diagnostics: Sentry. Crash reports are configured to exclude personal information and are not linked to your account.
- AI and transcription: the Pydantic AI Gateway (Pydantic Services Inc.), Anthropic and OpenAI, plus Vercel AI Gateway during a short transition we are completing; any additional model provider will complete privacy review and be disclosed here before material use.
- Subscriptions: Apple App Store, Google Play and RevenueCat.
- Transactional email and support: Resend and Google Workspace.
- Push notifications: the Expo Push Service, which delivers reminders through Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. These receive your device's push token and the reminder text only; they do not receive your account, health or training data.
- Domain services: GoDaddy.
- Professional and legal recipients: advisers, auditors, insurers, regulators, courts or law enforcement where reasonably necessary or legally required.
If NSTARC is reorganised, financed, sold or transfers PTAI, information may be disclosed under confidentiality and transferred as part of that transaction, subject to applicable law.
We do not sell personal information, share it for cross-context behavioural advertising, or display third-party advertising in PTAI.
7. International transfers
NSTARC is based in the United Kingdom. Some providers process information in the United States or other countries. Where information leaves the UK or European Economic Area, we use an adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum and/or EU Standard Contractual Clauses, together with supplementary protections where required. Contact us for information about the safeguard relevant to your data.
PTAI is not currently offered or actively marketed to residents of the European Economic Area. Before doing so, NSTARC will assess and complete any EU-representative requirement and update this policy.
8. How long we keep information
We keep information only as long as reasonably needed for the purpose described, including legal, accounting and dispute requirements. Our intended periods are:
| Information | Normal retention |
|---|---|
| Account, profile, workouts, goals, plans, metrics, nutrition and saved outputs | While the account is active. An account inactive for 24 months may be scheduled for deletion after at least 30 days’ warning. |
| Deleted account data in live systems | Deleted or irreversibly de-identified within 30 days, subject to limited exceptions below. |
| Backups containing deleted data | Expire through rotation within 90 days and are not restored except for disaster recovery. |
| Raw voice recording | Not stored by PTAI. |
| AI diagnostic conversation logs and request metadata | When diagnostic capture is enabled, conversation content in PTAI's restricted observability logs expires after no more than 30 days. Content-free request metadata also expires after 30 days. AI providers may separately retain API content under commercial abuse/security controls, normally up to 30 days. |
| Coach replies you report | The reported reply, your reason and any comment are kept while your account is active and deleted with it. |
| Mobile crash diagnostics | Up to 90 days in Sentry, then deleted by its retention setting. |
| API and security logs | Normally up to 90 days, unless needed longer for a documented security incident or legal claim. |
| Support correspondence | Up to 2 years after the matter closes. |
| Service-email delivery records | Normally up to 30 days, subject to provider operations and security requirements. |
| Push notification tokens | Kept while the device is registered for reminders. A token that stops working, or that you turn off by signing out, is deleted within 30 days. |
| Reminder history | Up to 90 days, then deleted. Your reminder preferences are kept for the life of the account. |
| Consent and privacy-request records | Up to 6 years to demonstrate compliance and resolve claims. |
| Required transaction and accounting records | Up to 6 years from the end of the relevant financial year, or longer if law requires. |
We may preserve a limited record beyond these periods where reasonably necessary for fraud prevention, security, a legal hold, a dispute or another legal obligation. Access is restricted and the information is deleted when the reason ends.
9. Your privacy rights
We make the following core controls available regardless of where you live, subject to lawful exceptions. You may ask us to:
- confirm whether we process your information and provide access to it;
- correct inaccurate or incomplete information;
- delete your account and personal information;
- provide information you supplied in a portable format;
- restrict processing or object to processing based on legitimate interests; and
- withdraw consent at any time.
Use Privacy settings to withdraw consent or delete your account. Email privacy@pocket-team.ai for access, correction, portability, restriction, objection or other privacy help. You do not need to use legal wording; tell us clearly what you need. See our account deletion instructions. We normally respond within one month. We may ask you to verify control of the account, usually by signing in or replying from the account email. An authorised agent may submit a request, but we will verify their authority and may verify the request with you.
You may complain to the UK Information Commissioner’s Office at ico.org.uk. If you live elsewhere, you may also contact your local data-protection authority. We would appreciate the chance to address your concern first.
10. California privacy disclosures
NSTARC does not currently meet the business thresholds that generally make the California Consumer Privacy Act, as amended by the CPRA, applicable. We nevertheless provide the core access, correction, deletion and portability controls described above and will reassess our obligations as PTAI grows.
The categories of personal information we collect, their sources, purposes, recipients and retention are described in sections 2, 3, 6 and 8. These may include identifiers, customer records, commercial information, internet or electronic activity, approximate location derived from IP address, audio/transcript information, inferences, and sensitive personal information such as account credentials and health-related information.
We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We do not use sensitive personal information to infer characteristics for advertising or other purposes that would trigger a right to limit. We do not knowingly sell or share the personal information of people under 18. We will not discriminate against you for making a privacy request.
Do Not Track and Global Privacy Control
Our public website does not currently use advertising or cross-site tracking technologies, so browser Do Not Track or Global Privacy Control signals do not change its behaviour. We do not allow other parties to collect personal information about your online activities across third-party sites through PTAI for advertising.
Website cookies
We do not currently use non-essential cookies or website analytics. Essential hosting and security technologies may process technical requests to deliver the site. Before introducing analytics or similar technologies, we will update our notice and provide consent controls where required.
11. Security
We use technical and organisational measures designed to protect information, including encryption in transit and at rest, role-based access restrictions, multi-factor authentication for relevant administrative access, secrets management, logging, backups, recovery planning, incident response and dependency review. No online service can guarantee absolute security. Please use a unique password and contact us promptly if you suspect account misuse.
12. Changes, contact and complaints
We may update this policy as PTAI or the law changes. We will post the new policy here, change the effective date and email or provide an in-app notice where a change materially affects your rights or how we use information.
Questions or requests can be sent to:
Privacy LeadNSTARC LTD
68 Queen Street
Sheffield, S1 1WR
United Kingdom
privacy@pocket-team.ai
