EZPal By Avenor Solutions
  • Features
  • Training With a Pal
  • FAQ
  • Support
  • Avenor Solutions
Features Training With a Pal FAQ Support Avenor Solutions

EZPal Privacy Policy

Last updated: September 15, 2026

This Privacy Policy explains how Avenor LLC, doing business as "Avenor Solutions" ("we," "us," or "our") collects, uses, shares, and protects information when you use EZPal, our mobile fitness and workout-tracking application (the "App" or "Service").

1. Overview

Avenor Solutions operates EZPal. This policy applies to all users of the App. If you have questions about this policy or your data, contact us at support@ez-pal.com.

Where EZPal is available. EZPal is currently offered only to users located in the United States and Canada. We do not currently offer, market, or knowingly make the App available outside these two countries.

2. What we collect

2.1 Account & identity information

  • Email address, and a password (hashed, never stored in plain text) if you sign up with email/password.
  • If you sign in with Google or Apple: the identity token/subject identifier those providers give us, and whatever name/email they share with us (Apple's private relay email address is fully supported for account and transactional communication).
  • If you enable two-factor authentication: a one-time code is sent to your email address at sign-in. No phone number is collected for 2FA today. If SMS-based 2FA is ever added in the future, a phone number would be collected solely for that purpose, disclosed separately, and never reused for marketing; see §9 (Changes to This Policy).
  • Your age self-attestation (a timestamp confirming you checked "I am 16 years of age or older" at signup); see §8 (Children's Privacy).

2.2 Body & fitness profile: treated as sensitive

  • Gender, height, weight, and a coarse age-range bucket, collected as a standard, required part of onboarding, the same as your email address. There is no opt-out for this category within the Service.
  • Goal, weekly workout-frequency target, equipment preference, and training environment (home/office/commercial gym), collected during onboarding to personalize your plan.

Any plan or suggestion generated from this data is general, rules-based fitness guidance, not medical advice or a personalized health recommendation. See our Terms of Service §4 for our full health & fitness disclaimer, including the recommendation to consult a physician before beginning any exercise program.

We treat gender, height, weight, and age-range as sensitive, health-adjacent data internally (see §4's access controls and §5's exclusion of this category from Training Pal sharing). This data is collected as a mandatory part of onboarding: you cannot create and use an EZPal account without providing it, and there is no consent toggle to decline.

Injury / area-to-work-around flags — optional, opt-in, never required. During onboarding, and any time afterward in Training Preferences, you can tell us about general areas (lower back, knee, shoulder, elbow/wrist) so we can avoid suggesting certain movements for you. Selecting "Nothing right now" is a full, equally-valid answer: you can complete onboarding and use the App having provided none of this information, and we do not create a consent record unless you select at least one flag. Choosing an area later, or clearing your selections back to none, only affects this data and its own consent record — it never touches your gender/height/weight/age-range above, or their status, and vice versa (see §3 and §7 for how to withdraw this specific consent).

We use this information for one purpose only: to reduce the number of exercises we suggest and to exclude certain types of movement from your plan. We do not evaluate, interpret, or reason about it medically, and telling us about an area does not mean any exercise has been assessed as safe for you. This is not medically approved guidance and is not a substitute for seeing a doctor. See our Terms of Service §4 for the full disclaimer that applies to this feature, including why you should talk to a doctor about what kind of exercise is right for you before relying on it.

2.3 Workout activity data

  • Your workout plans, logged sessions (date, session duration, effort level, a short "vibe" answer), exercise substitutions, and (if you choose to use it) per-set weight and rep detail.
  • If you use the optional Training Pal feature: the limited activity data shared with your paired Training Pal, and the data they share with you (see §5).

Any calorie figure shown to you (in your analytics summary or in a weekly summary notification) is a rough estimate derived from the duration and effort you record, the exercises in your session, and your body weight where you have provided it, not a measured or personalized figure. See our Terms of Service §4 for the full explanation of how it's calculated and why you shouldn't rely on it for medical or dietary decisions.

2.4 Avatar / profile photo

  • An optional profile photo. If uploaded, it is automatically re-encoded, resized, and stripped of all metadata (including any location/GPS data embedded by your camera) before being stored. It is run through an automated content-safety check before becoming visible to anyone, including you. It is visible only to you and, if you pair with a Training Pal, to that one Training Pal.

2.5 Usage / interaction data

  • We log app interaction events (such as which screen you're on) for debugging and product-improvement purposes. This is first-party data: we do not use a third-party session-replay or ad-analytics SDK for this, and we never log the actual sensitive values you enter (e.g. the weight number you typed) as part of this log, only the fact that an action occurred. Each event is linked to a pseudonym derived from your account (an HMAC-SHA256 value computed from your account ID using a secret key that never leaves our backend), never your raw account ID, email, or any other directly-identifying field; this pseudonym cannot be reversed back to your identity without that secret key. These events are retained on a fixed schedule of 90 days or less, for every user, with no exceptions, after which they are automatically, permanently deleted in full, not reduced to an aggregate count or retained in any other form.
  • We separately use a third-party product-analytics service to understand feature usage and retention at an aggregate/cohort level (e.g., which screens are used, subscription conversion). These events are tied to your account (a persistent per-account identifier) and are declared as Linked to You usage data, not anonymous. They are retained for up to 3 years or until account deletion, whichever comes first. Session recording/replay is never enabled for this tool. This analytics provider does not receive raw sensitive field values (body stats, free-text goals, or the contact information you provide about someone you invite through our Invite program; see §2.10).

2.6 Device & technical data

  • Push-notification device tokens (if you enable notifications), app version, and device/OS version.

2.7 Payment data

  • We do not directly collect or store your payment card information. All subscription purchases are processed by Apple through the App Store; we receive only your subscription status/entitlement from our subscription-management vendor (see §4).

2.8 Support requests

  • If you contact support, we collect the message you send us along with your account email, app version, device/OS, and subscription tier, to help us respond. We do not automatically attach your body-stat data or per-set workout logs to a support request; if a specific request genuinely needs that detail, you can choose to include it yourself.

2.9 Apple Health (HealthKit) sync: optional

If you turn on "Sync to Apple Health" in Settings, we write your logged workouts (workout type and, if you choose to enter it, how long the session took) directly to your device's Apple Health store, using Apple's HealthKit framework. This is a one-way, write-only connection: EZPal never reads any data from Apple Health, and we never request permission to. The duration figure, if you provide one, is written only to Apple Health; it is never sent to our servers, never stored in our database, and never included in any analytics event. We do not use HealthKit data for advertising or any other data-mining purpose, and we do not sell HealthKit data to advertising platforms, data brokers, or information resellers. You can turn this sync off at any time in Settings, or manage EZPal's Health permissions directly from the Health app (Health app → your profile icon → Apps → EZPal). Apple's own Health app retains this data under Apple's privacy terms, not ours, once written.

2.10 Invite (referral) program: contact information about someone you invite

If you use our Invite program to refer a friend to EZPal (see our Terms of Service §8 for how the program works), we ask you to provide the email address of the person you're inviting before you send the invite. We store this contact information so that we can operate the Invite feature, prevent duplicate invites (e.g., checking whether the same contact has already been invited), and show you the status of everyone you've invited.

We do not send the Invite message ourselves. After you provide the contact, the App prepares a pre-written invite link/message, but it is sent from your own device using your own Messages, Mail, or other app of your choosing, the same as if you had typed and sent it yourself. We do not use a third-party email-sending vendor to deliver Invite messages on your behalf, and this contact information is never used by us to send that person any message, marketing or otherwise.

The person you invite is not yet an EZPal user at the time you provide their contact information, and has not taken any action of their own at that point. If you received an Invite from an EZPal user but never created an account yourself, and would like us to delete the contact information that was provided to us about you, contact us at the address in §10 and we will honor that request.

2.11 Internal business-analytics reporting

Avenor LLC also operates an internal business-analytics system, used only by Avenor LLC's own team, for internal business and financial reporting (for example: cohort retention, subscription revenue, and per-user profitability analysis). This system receives your account's existing internal identifier (not your email or name), a keyed cryptographic fingerprint of your email address that cannot be reversed back to your email without a secret key we control, a partially masked version of your email address for human reference (e.g., e********r@example.com), your first name, and the fact that certain account events occurred (for example: signup, onboarding completion, your first logged workout, workouts logged, and subscription started or ended), together with the workout-activity fields already described in §2.3 (such as effort level and workout-split focus). It never receives your body & fitness profile data (§2.2), injury/area-to-work-around flags, per-set weight/rep detail, your plaintext email address, or any other sensitive data described elsewhere in this policy. This is an internal system operated by Avenor LLC itself, not a third-party service provider: nothing described in this section is shared outside Avenor LLC, sold, or used for advertising.

2.12 Advertising measurement (Meta)

EZPal uses Meta's (Facebook/Instagram) advertising measurement tools to measure the performance of our own advertising campaigns. We send Meta a small, fixed set of events when they happen: opening the app, creating an account, completing onboarding, pairing with a Training Pal, logging your first workout, starting your free trial, and subscribing (including the price and the specific product you subscribed to). We never send your name, email address, exercise or workout content, per-set weight/rep detail, body-stat data, or injury/accommodation flags to Meta, regardless of your tracking choice.

None of this is sent unless you grant App Tracking Transparency (“Allow Tracking”) when asked. If you tap “Ask App Not to Track,” dismiss the prompt without responding, or later turn tracking off for EZPal (Settings app → Privacy & Security → Tracking → EZPal), no event of any kind described above is sent to Meta — not the event itself, and not your device's advertising identifier. Every one of these events independently checks your current App Tracking Transparency status before doing anything, so revoking tracking later stops all further sharing from that point on, the same as never granting it in the first place.

When you do grant tracking, your device's advertising identifier (IDFA) is attached to these events so Meta can connect them to our ad campaigns; because no event is ever sent without your consent, no identifier is ever sent without it either. We use Meta's tools for measurement only, not to retarget you with ads or build an advertising profile of you elsewhere. We also configure Meta's Limited Data Use (LDU) setting, an additional processing restriction Meta applies on our behalf for California residents.

If we change what we send, add a new purpose beyond measurement, or otherwise materially change this feature, we will update this section first, consistent with §9 (Changes to This Policy).

2.13 Website analytics/advertising measurement (ez-pal.com)

Separately from the in-app measurement described in §2.12, our marketing website (ez-pal.com — the pages you are reading this on, not the App itself) also uses a Meta Pixel to measure the performance of our own advertising campaigns for the website. It sends two kinds of event: a page-view event each time you load a page, and a "Lead" event if you click an App Store download link or badge. App Tracking Transparency is an iOS App Store requirement and does not apply to a website viewed in a browser, so this measurement is not gated by it the way §2.12's in-app events are. Instead, it runs by default — the same as most websites' analytics or ad-measurement tags — unless you opt out, consistent with the CCPA/CPRA's opt-out (not opt-in) model; see §7.

You can opt out of this website's Meta Pixel at any time, and it takes effect immediately, in either of two ways: (1) click "Do Not Sell or Share My Personal Information" in the footer of any page on this website, or (2) enable a Global Privacy Control ("GPC") signal in your browser or a browser extension, which this website detects and honors automatically, with no need to also click the footer link. Either signal stops the website's Meta Pixel from initializing or sending any event, on every page of this website, for as long as the signal is present or your stored choice remains in effect on that browser/device; opting back in (available for the footer-link choice, not for a browser-level GPC signal, which only your browser/extension controls) resumes it. We never send your name, email address, or any account/workout data described elsewhere in this policy through this website pixel; it only ever sends the page-view/click events described above.

3. Why we collect it: legal basis by category

  • Account, workout activity, and body & fitness profile data (§2.2) is processed because it's necessary to provide the Service you've signed up for (operating your account, generating and tracking your workouts, personalizing your plan). Body & fitness profile data (gender, height, weight, age-range) is collected as a required part of onboarding, on the same basis as your other account data, with no opt-out.
  • Injury / area-to-work-around flags (§2.2) are processed only with your separate, freely-given, opt-in consent — a specific selection of at least one flag. Choosing "Nothing right now" provides none of this data and creates no consent record. You can withdraw this consent at any time by clearing your selections in Training Preferences (see §7), without affecting your account or any other data category.
  • Training Pal sharing (§5) is processed only with your separate, explicit, opt-in consent, a distinct affirmative action at the point of pairing, not bundled into your general acceptance of this policy or the Terms of Service. You can withdraw this consent at any time (see §7).
  • Usage/interaction and analytics data (§2.5) is processed for our legitimate interest in debugging, maintaining, and improving the Service.
  • Payment data is processed by Apple as an independent party, under Apple's own privacy terms, not ours.
  • HealthKit sync (§2.9) is processed only with your separate, explicit, opt-in action (turning the toggle on), never bundled into general account creation, and never processed on our servers at all (§2.9).
  • Invite (referral) program contact information (§2.10) is processed for our legitimate interest in operating a referral program and preventing abuse of it (e.g., detecting duplicate or fraudulent invites). It is not used for marketing, and we do not send any message to the person whose contact information is provided; you do, from your own device (§2.10).
  • Internal business-analytics reporting (§2.11) is processed for our legitimate interest in operating and understanding our own business (for example, financial and retention reporting), using data already collected for the purposes described above.
  • Advertising measurement (§2.12) is processed only on the basis of your App Tracking Transparency response: nothing described in §2.12 is processed unless you have affirmatively responded “Allow” to that prompt, a specific, revocable, opt-in consent distinct from your acceptance of this policy. You can withdraw it at any time in Settings app → Privacy & Security → Tracking → EZPal, which stops any further sharing immediately.
  • Website advertising measurement (§2.13) is processed for our legitimate interest in measuring our own website advertising, under the CCPA/CPRA's opt-out model: it runs by default, unless you have opted out using Global Privacy Control or this website's "Do Not Sell or Share My Personal Information" link, either of which stops it immediately (see §7).

4. Third parties / subprocessors

We use the following service providers. Except where noted below, each acts as a processor under contract, not independently using your data for their own purposes:

  • Apple (StoreKit/App Store): processes payment and subscription purchase, for billing.
  • Our subscription-management vendor: processes subscription/entitlement status, for subscription management.
  • Our AI plan-generation service provider: processes your fitness profile (goal, equipment preference, training environment, gender, height, weight, and age-range) and any optional free-text note you add, when you generate or regenerate a plan, to help produce your suggested workout plan. Its output is always constrained by our own rules engine, never used on its own; see Terms of Service §3.
  • Our email-delivery service provider: processes email address and transactional email content, for account emails (verification, password reset, two-factor sign-in codes) and for the weekly progress email described in §2.3 and §5, including its Training Pal recap section for actively paired, subscribed users, and for the shared-goal proposal and removal emails described in §5, which name your Training Pal and describe the specific goal.
  • An SMS-verification service provider (not currently active, only if SMS-based 2FA is ever added) would process second-factor verification.
  • Our internal logging/observability infrastructure: processes pseudonymized interaction-log events, for first-party debugging/support tracing.
  • Our analytics service provider (US-hosted): processes account-linked usage/analytics events, for product analytics.
  • Our cloud storage provider: processes avatar image files, for avatar storage.
  • An automated content-safety/image-moderation service: processes the re-encoded avatar image, for automated content-safety screening.
  • Our customer-support ticketing platform (or equivalent): processes support message content, account email, and device/app metadata, for customer support ticketing.
  • Our hosting/infrastructure provider: processes all of the above, as the underlying infrastructure our backend runs on.
  • Meta Platforms, Inc.: processes the app-event data described in §2.12, for advertising-campaign measurement, only when you have granted App Tracking Transparency (we configure Meta's Limited Data Use setting for this processing); and, separately, the website page-view/click-event data described in §2.13, for measuring our website advertising, unless you have opted out via Global Privacy Control or this website's "Do Not Sell or Share My Personal Information" link.

Apple Health (HealthKit) is deliberately not listed above. It is an on-device framework provided by the operating system, not a third-party processor we send data to: EZPal writes directly to your own device's local Health store under Apple's own HealthKit permission model, and no HealthKit data is ever transmitted to us or to any provider above (§2.9).

No new vendor is introduced by the Invite program (§2.10). Invite messages are sent from your own device using apps already on it (e.g., Messages, Mail), not through any vendor in this list.

Our internal business-analytics reporting (§2.11) is deliberately not listed above either. It is operated by Avenor LLC itself, not by a third-party processor, so it does not belong in this list of outside service providers.

We do not sell your personal information. Other than the Meta advertising-measurement sharing described in §2.12, which only occurs if you have granted App Tracking Transparency, we do not share your data with any third party for cross-app or cross-site advertising purposes.

5. Training Pal sharing

You may optionally pair with one other EZPal account (a "Training Pal"). This is not automatic: it requires you to send a specific invitation and the other person to explicitly accept it, and either of you can end the pairing at any time, with immediate effect.

What is shared, by default, if you pair: your display name, profile photo (if you uploaded one), your active workout plan, your individual logged workout sessions (workout name, effort level, and date for each), weekly workout frequency, session streak, and how many exercises you log for each muscle group.

Shared goals. Either of you can propose a specific shared goal (for example, a joint session count for the month); it becomes active only once the other person accepts it, and either of you can end it at any time. While it's active, you can each see the other's progress toward it, or, for a small number of goal types, one combined number for the two of you together rather than a separate figure for each person.

Archiving a completed goal. Once a shared goal is completed, either of you can archive it from your own Completed-goals list at any time. Archiving only changes your own list: your Training Pal's copy is untouched, and you can restore yours from your own archive whenever you want.

Activity feed. Your Training Pal tab shows a shared, reverse-chronological feed built entirely from the categories already listed above: your logged sessions, milestones derived from them (for example, reaching a session-count or streak threshold), and updates to a shared goal. The feed does not add any new category of data beyond what's already described in this section.

Reactions. You and your Training Pal can each respond to something in the feed with one of a small, fixed set of reaction icons (for example, a clap or a flame). There is no free-text messaging in this feature: you can only choose from that fixed set, you can't attach a comment, and we don't tell the sender whether or when the recipient has seen a reaction.

Weekly email. If you're both actively paired and subscribed, the weekly progress email we send you (see §2.3) includes a short section summarizing your Training Pal's activity that week, drawn from the same categories described in this section.

Goal proposal and removal emails. If your Training Pal proposes a shared goal (including renewing or changing one) or ends one that's still active, we also email you about it, naming your Training Pal and describing the goal, in addition to sending a push notification. You can turn these emails off from Notification Settings without affecting anything else described in this section.

What is never shared through this feature: your gender, height, weight, age-range, exact date of birth, per-set weight/rep detail, or injury/area-to-work-around flags. This is enforced structurally in how our systems are built, not just as a policy: the queries that power the comparison view, the shared goal, the activity feed, and the weekly-email section cannot read this data at all.

You can review exactly what's shared with your Training Pal, and end the pairing, at any time from within the App. Ending the pairing stops all of the sharing described in this section immediately, for both of you: a shared goal you had together is marked ended, not deleted, so that if you pair with that same person again later you can both see that you once had it; any reactions between the two of you are deleted right away. There's no way to keep only part of this and unpair from the rest.

Sending a Training Pal invitation requires an active, paid EZPal subscription. Accepting one does not: you can accept an invitation and be paired while on the free tier. Seeing any of the shared data described in this section, including the shared goal, the activity feed, reactions, and the weekly-email section, however, requires an active, paid subscription on both sides. If either person's subscription lapses, is not renewed, or is refunded, you lose the shared view, and if that isn't resolved, the pairing ends automatically, the same as if you had manually ended it, and we'll show a notice in the App when this happens. See our Terms of Service §7 for the full terms.

6. Retention

  • Account, workout, body-stat data: until you delete your account, or you remove specific optional data earlier.
  • Injury / area-to-work-around flags: retained only while at least one flag is selected; deleted, and the associated consent withdrawn, immediately if you clear your selections back to "Nothing right now," and deleted with the rest of your account data if you delete your account.
  • Shared goals (§5): retained for as long as your account exists and the pairing remains, whether the goal is active or already ended. If you unpair, an ended shared goal is not deleted, only marked ended, so that if you pair with the same person again later, you can both see that you once had it. If either of you deletes your account, every shared goal between you and that person is deleted along with the rest of your account data.
  • Reactions (§5): retained only while the pairing that produced them is active. If you unpair, every reaction between you and that Training Pal is deleted immediately, whether or not either of you deletes your account. If you delete your account, any reaction you sent or received is deleted as part of that same process.
  • Activity feed (§5): not stored as its own record. It's assembled, each time you open it, from your logged sessions, streak, and shared-goal data, each already covered by the retention rules above, so it never outlives the data it's built from.
  • Weekly progress email content (§2.3, §5), including the Training Pal recap section: we don't separately retain a copy of this email's content once it's sent; our email-delivery service provider retains the delivered message under its own configured retention, the same as our other transactional email described in §4.
  • Interaction/debug logs (our internal logging infrastructure): fixed schedule of 90 days or less, for every user; automatically deleted in full at the end of that window (no aggregate-count fallback exists). Because this data is already pseudonymized and already short-lived by design, it is not part of the immediate deletions in §7's account-deletion cascade; see §7.
  • Analytics events (our analytics provider): up to 3 years from the event, or until account deletion, whichever is sooner.
  • Internal business-analytics reporting (§2.11): retained for as long as your account exists, then deleted automatically, without a manual step, once your account is deleted; see §7 for how quickly.
  • HealthKit data (if sync enabled): not retained by us at all, written directly to your device's Apple Health store, governed by Apple's own retention, not ours (§2.9).
  • Crash/hang diagnostic reports (if the App crashes or hangs): not retained by us at all; captured and stored entirely on your own device by Apple's MetricKit framework, never linked to your EZPal account or sent to us or any third party automatically. Account deletion has no effect on this device-local data, since it was never sent to us in the first place.
  • Consent records (what you agreed to and when): retained as an audit trail even after you withdraw a specific consent or unpair a Training Pal, for dispute-resolution purposes.
  • Invite (referral) program contact information (§2.10): retained as part of your Invite history for as long as your account exists, so you can see the status of everyone you've invited; if the invited person never creates an account, we do not currently delete this information on any fixed schedule beyond your own account's lifecycle, but will delete it on request from either you or the person whose contact information was provided (§2.10).
  • Anonymous, aggregate account-deletion statistics (see §7): retained indefinitely; contains no identifying information by design, so ordinary personal-data retention limits don't apply the same way; see §7.
  • Support tickets: retained for a limited period after resolution (typically 12–24 months), consistent with our helpdesk provider's configured retention settings.
  • Advertising measurement (§2.12): we do not separately retain the events sent to Meta. If you have granted App Tracking Transparency and an event has been sent, it is retained under Meta's own data-retention policies, not ours; if you have not granted tracking, no event has been sent and there is nothing to retain.

7. Your rights

You can, at any time, from within the App:

  • Request an export of your data, from Settings → Export My Data in the App. We email a secure download link to your account address; the link stays valid for 7 days. You can also contact us using the details in §10 and we will provide your data to you directly.
  • Delete your account (Settings → Delete Account); this is available directly in the App, not only by contacting support, and it cascades across every system described above: your workout history and body stats are deleted; any linked Apple sign-in grant is revoked with Apple, not just unlinked; any linked Google sign-in is unlinked from your EZPal account, though revoking Google's own access grant is not done automatically as part of this. You can revoke that yourself, at any time, in your Google Account's security settings at myaccount.google.com. Any 2FA credential is deleted immediately; any active Training Pal pairing is ended, with a notice shown to the other party, and any shared goal and any reaction between you and that Training Pal is deleted at the same time, not merely marked ended the way it would be if you simply unpaired without deleting your account (see §5). Interaction/debug-log events (§2.5) are handled differently, and are deliberately not deleted early: these events are already stored under a pseudonym (an HMAC-SHA256 value computed from your account ID using a secret key that is held only on our backend and never your raw account ID, email, or any other identifying field) and are automatically deleted for every user, without exception, on a fixed schedule of 90 days or less from when they were logged. Data held in the internal business-analytics system described in §2.11 is also deleted automatically as part of this same account-deletion process, not through a manual step: deleting your account generates a deletion instruction immediately, which is delivered to that system on an automated schedule that runs at least every 10 minutes, so removal typically completes within minutes. If that system is briefly unreachable, delivery is retried automatically, on a bounded schedule, until it succeeds. This differs only in timing, not in automation, from your account, workout, and body-stat data described above, which we delete immediately and in full within our own systems the moment you confirm deletion. Deleting your account does not automatically cancel an active App Store subscription. Manage that separately through your Apple ID. HealthKit data you've previously synced (§2.9) is not affected by deleting your EZPal account at all, since we never held a copy of it. Manage or delete it directly in the Health app. Even after your account is deleted, we keep anonymous, aggregate statistics about account deletions in general, for example, how long accounts typically last before deletion, or whether deleted accounts had ever been paying subscribers. These statistics never include your account ID, email, exact age, exact deletion date, or any other information that could identify you or any other specific person; they are stored only as rounded, grouped totals (e.g., "12 accounts in the 8–30-day tenure range deleted this month"), and any group too small to protect individual privacy is never shown on its own.
  • Withdraw consent for the Training Pal sharing feature (§5) by unpairing from within the App at any time, which immediately stops all of the sharing described in §5 (including the shared goal, activity feed, reactions, and weekly-email section), ends any shared goal you had (marked ended, not deleted, in case you pair with that person again later), and deletes any reactions between you and that Training Pal right away; or withdraw consent for injury/area-to-work-around flags (§2.2), without deleting your whole account — clear your selections in Training Preferences to withdraw the latter at any time. Body & fitness profile data (§2.2's gender/height/weight/age-range) is collected as a required part of onboarding, not an opt-in category, so there is no separate consent to withdraw for it; if you no longer want to provide that data, you may delete your account (see above).

EZPal shows an App Tracking Transparency prompt, and, only if you respond “Allow,” sends the events described in §2.12 to Meta for ad-campaign measurement. You can review or change your choice at any time in the Settings app → Privacy & Security → Tracking → EZPal; turning tracking off (or never turning it on) means nothing further is sent to Meta from that point forward.

If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, request deletion, and limit the use of sensitive personal information (which, per our conservative posture in §2.2, includes your body-stat and injury/accommodation data). We honor these requests as a matter of policy. This policy covers two separate Meta Pixel channels, each with its own opt-out mechanism appropriate to where it runs:

  • In the App: because no event described in §2.12 is ever sent to Meta unless you have granted App Tracking Transparency, turning tracking off (or never granting it) stops the underlying disclosure to Meta entirely, and functions as your opt-out for this specific channel; no “share” as the CCPA/CPRA defines that term (Cal. Civ. Code §1798.140(ah)) occurs once tracking is declined or revoked.
  • On this website (§2.13): the website's Meta Pixel is not gated by App Tracking Transparency, since that is an App Store mechanism that does not apply to a browser. Instead, this website provides a direct, standalone “Do Not Sell or Share My Personal Information” link in the footer of every page, and separately, automatically honors the Global Privacy Control (GPC) signal, a browser- or extension-sent opt-out preference signal recognized as a valid CCPA/CPRA opt-out request. Either one stops the website Meta Pixel from initializing or sending any event, on every page of this website, immediately and for as long as the signal or your stored choice remains in effect on that browser/device. Because GPC and the footer link fully stop the underlying disclosure before it happens, no “sale” or “share” as the CCPA/CPRA defines those terms occurs for a visitor who has either signal active.

You can exercise the rights above at any time by contacting us at the address in §10, and you can exercise the website-specific opt-out above at any time, without contacting us, using the footer link or your browser's GPC setting.

EZPal is not currently offered or distributed in the European Economic Area or United Kingdom (see §1). If our distribution ever expands to include those regions, this policy will be updated to reflect your rights under the GDPR before that happens.

If you are located in Canada, in addition to the rights above (which we extend to all users as a matter of policy), you have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to know why your information is collected, to access it, and to challenge our compliance with applicable Canadian privacy law. If you are located in Quebec specifically, additional protections apply to you under Quebec's Act respecting the protection of personal information in the private sector ("Law 25"), including the right to be informed of the identity of our designated privacy officer. Under section 3.1 of Law 25, that role belongs by default to the person holding the highest authority within Avenor LLC, its Chief Executive Officer, as it has not been delegated in writing to anyone else. You can reach the Privacy Officer at support@ez-pal.com. Contact us using the details in §10 with any question about your rights under Canadian law.

8. Children's privacy

EZPal requires every user to confirm, at account creation, that they are at least 16 years old. This same requirement governs the optional Training Pal pairing feature: there is no separate or higher age requirement to pair. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it.

9. Changes to this policy

We will update the effective date above whenever this policy changes. For material changes, particularly any new data category, we will provide notice within the App (and, for changes affecting the sensitive-data or Training Pal consent categories in §3, may require you to re-consent) rather than silently updating this page.

September 15, 2026 update. §5 now names two additions that ship with the shared-goal lifecycle: archiving a completed goal, which changes only your own Completed-goals list and never your Training Pal's copy, and the goal proposal and removal emails, which name your Training Pal and describe the goal. §4's email-delivery bullet names those emails too. Neither changes what we collect; both describe new ways existing Training Pal information is shown to you or sent to you, and the emails can be turned off in Notification Settings.

September 2026 update. §5 previously did not name two things that were already part of the Service: how many exercises you log for each muscle group, which had already been shared with paired Training Pals since August 29, 2026 without being named here, and the shared-goal, activity-feed, reaction, and weekly-email-recap features, which are built entirely from categories already disclosed in this policy and don't add a new one. We've corrected §5 to name all of them. Every existing Training Pal pair is being asked, on their own device, to review and reaffirm the updated Training Pal sharing consent, and until you do, none of these categories, including muscle-group data, will keep being shared with your Pal.

September 2026 update (Training Pal age requirement). The Training Pal pairing feature previously required a separate, self-attested date of birth confirming you were 18 or older, in addition to the general 16-and-older account requirement. We've removed that additional pairing-specific requirement: the same 16-and-older attestation now governs both account creation and Training Pal pairing. We have also stopped collecting dates of birth, since that requirement was the only thing they were collected for.

10. Contact us

Questions about this policy or your data: support@ez-pal.com.

© 2026 Avenor Solutions. EZPal is a product of Avenor LLC.
Privacy Policy Terms of Service FAQ Support Do Not Sell or Share My Personal Information Avenor Solutions →