EZPal By Avenor Solutions
  • Features
  • Training With a Pal
  • Support
Features Training With a Pal Support

EZPal Privacy Policy

Last updated: July 31, 2026

This Privacy Policy explains how Avenor LLC, doing business as "Avenor Solutions" ("we," "us," or "our") collects, uses, shares, and protects information when you use EZPal, our mobile fitness and workout-tracking application (the "App" or "Service").

1. Overview

Avenor Solutions operates EZPal. This policy applies to all users of the App. If you have questions about this policy or your data, contact us at support@ez-pal.com.

Where EZPal is available. EZPal is currently offered only to users located in the United States and Canada. We do not currently offer, market, or knowingly make the App available outside these two countries.

2. What we collect

### 2.1 Account & identity information

  • Email address, and a password (hashed, never stored in plain text) if you sign up with email/password.
  • If you sign in with Google or Apple: the identity token/subject identifier those providers give us, and whatever name/email they share with us (Apple's private relay email address is fully supported for account and transactional communication).
  • If you enable two-factor authentication: a one-time code is sent to your email address at sign-in. No phone number is collected for 2FA today. If SMS-based 2FA is ever added in the future, a phone number would be collected solely for that purpose, disclosed separately, and never reused for marketing; see §9 (Changes to This Policy).
  • Your age self-attestation (a timestamp confirming you checked "I am 16 years of age or older" at signup); see §8 (Children's Privacy).

### 2.2 Body & fitness profile: treated as sensitive

  • Gender, height, weight, and a coarse age-range bucket, collected as a standard, required part of onboarding, the same as your email address. There is no opt-out for this category within the Service.
  • Goal, weekly workout-frequency target, equipment preference, and training environment (home/office/commercial gym), collected during onboarding to personalize your plan.

Any plan or suggestion generated from this data is general, rules-based fitness guidance, not medical advice or a personalized health recommendation. See our Terms of Service §4 for our full health & fitness disclaimer, including the recommendation to consult a physician before beginning any exercise program.

We treat gender, height, weight, and age-range as sensitive, health-adjacent data internally (see §4's access controls and §5's exclusion of this category from Training Pal sharing). This data is collected as a mandatory part of onboarding: you cannot create and use an EZPal account without providing it, and there is no consent toggle to decline.

### 2.3 Workout activity data

  • Your workout plans, logged sessions (date, effort level, a short "vibe" answer), exercise substitutions, and (if you choose to use it) per-set weight and rep detail.
  • If you use the optional Training Pal feature: the limited activity data shared with your paired Training Pal, and the data they share with you (see §5).

Any calorie figure shown to you (in your analytics summary or in a weekly summary notification) is a rough estimate based only on the effort level you record for each session, not a measured or personalized figure. See our Terms of Service §4 for the full explanation of how it's calculated and why you shouldn't rely on it for medical or dietary decisions.

### 2.4 Avatar / profile photo

  • An optional profile photo. If uploaded, it is automatically re-encoded, resized, and stripped of all metadata (including any location/GPS data embedded by your camera) before being stored. It is run through an automated content-safety check before becoming visible to anyone, including you. It is visible only to you and, if you pair with a Training Pal, to that one Training Pal.

### 2.5 Usage / interaction data

  • We log app interaction events (which screen you're on, what action you took, e.g. "tapped log set") for debugging and product-improvement purposes. This is first-party data: we do not use a third-party session-replay or ad-analytics SDK for this, and we never log the actual sensitive values you enter (e.g. the weight number you typed) as part of this log, only the fact that an action occurred. Each event is linked to a pseudonym derived from your account (an HMAC-SHA256 value computed from your account ID using a secret key that never leaves our backend), never your raw account ID, email, or any other directly-identifying field; this pseudonym cannot be reversed back to your identity without that secret key. These events are retained on a fixed schedule of 90 days or less, for every user, with no exceptions, after which they are automatically, permanently deleted in full, not reduced to an aggregate count or retained in any other form.
  • We separately use a third-party product-analytics service to understand feature usage and retention at an aggregate/cohort level (e.g., which screens are used, subscription conversion). These events are tied to your account (a persistent per-account identifier) and are declared as Linked to You usage data, not anonymous. They are retained for up to 3 years or until account deletion, whichever comes first. Session recording/replay is never enabled for this tool. This analytics provider does not receive raw sensitive field values (body stats, free-text goals, or the contact information you provide about someone you invite through our Invite program; see §2.10).

### 2.6 Device & technical data

  • Push-notification device tokens (if you enable notifications), app version, and device/OS version.

### 2.7 Payment data

  • We do not directly collect or store your payment card information. All subscription purchases are processed by Apple through the App Store; we receive only your subscription status/entitlement from our subscription-management vendor (see §4). If you and a Training Pal both hold active paid subscriptions, you may become eligible for a lower-priced "Duo" subscription, and you may separately earn discounts through our Invite program; see our Terms of Service §8 and §9 for how these work. Both flow through the same subscription vendor already described here; neither introduces a new payment-data category or a new third-party vendor.

### 2.8 Support requests

  • If you contact support, we collect the message you send us along with your account email, app version, device/OS, and subscription tier, to help us respond. We do not automatically attach your body-stat data or per-set workout logs to a support request; if a specific request genuinely needs that detail, you can choose to include it yourself.

### 2.9 Apple Health (HealthKit) sync: optional

If you turn on "Sync to Apple Health" in Settings, we write your logged workouts (workout type and, if you choose to enter it, how long the session took) directly to your device's Apple Health store, using Apple's HealthKit framework. This is a one-way, write-only connection: EZPal never reads any data from Apple Health, and we never request permission to. The duration figure, if you provide one, is written only to Apple Health; it is never sent to our servers, never stored in our database, and never included in any analytics event. We do not use HealthKit data for advertising or any other data-mining purpose, and we do not sell HealthKit data to advertising platforms, data brokers, or information resellers. You can turn this sync off at any time in Settings, or manage EZPal's Health permissions directly from the Health app (Health app → your profile icon → Apps → EZPal). Apple's own Health app retains this data under Apple's privacy terms, not ours, once written.

### 2.10 Invite (referral) program: contact information about someone you invite

If you use our Invite program to refer a friend to EZPal (see our Terms of Service §9 for how the program works), we ask you to provide the email address of the person you're inviting before you send the invite. We store this contact information so that we can track your Invite, prevent abuse of the reward program (e.g., checking whether the same contact has already been invited), and, if that person accepts and creates an EZPal account, apply the reward you've earned and show you the status of everyone you've invited.

We do not send the Invite message ourselves. After you provide the contact, the App prepares a pre-written invite link/message, but it is sent from your own device using your own Messages, Mail, or other app of your choosing, the same as if you had typed and sent it yourself. We do not use a third-party email-sending vendor to deliver Invite messages on your behalf, and this contact information is never used by us to send that person any message, marketing or otherwise.

The person you invite is not yet an EZPal user at the time you provide their contact information, and has not taken any action of their own at that point. If you received an Invite from an EZPal user but never created an account yourself, and would like us to delete the contact information that was provided to us about you, contact us at the address in §10 and we will honor that request.

3. Why we collect it: legal basis by category

  • Account, workout activity, and body & fitness profile data (§2.2) is processed because it's necessary to provide the Service you've signed up for (operating your account, generating and tracking your workouts, personalizing your plan). Body & fitness profile data (gender, height, weight, age-range) is collected as a required part of onboarding, on the same basis as your other account data, with no opt-out.
  • Training Pal sharing (§5) is processed only with your separate, explicit, opt-in consent, a distinct affirmative action at the point of pairing, not bundled into your general acceptance of this policy or the Terms of Service. You can withdraw this consent at any time (see §7).
  • Usage/interaction and analytics data (§2.5) is processed for our legitimate interest in debugging, maintaining, and improving the Service.
  • Payment data is processed by Apple as an independent party, under Apple's own privacy terms, not ours.
  • HealthKit sync (§2.9) is processed only with your separate, explicit, opt-in action (turning the toggle on), never bundled into general account creation, and never processed on our servers at all (§2.9).
  • Invite (referral) program contact information (§2.10) is processed for our legitimate interest in operating a referral/rewards program and preventing abuse of it (e.g., detecting duplicate or fraudulent invites). It is not used for marketing, and we do not send any message to the person whose contact information is provided; you do, from your own device (§2.10).

4. Third parties / subprocessors

We use the following service providers, each acting as a processor under contract, not independently using your data for their own purposes:

  • Apple (StoreKit/App Store): processes payment and subscription purchase, for billing.
  • Our subscription-management vendor: processes subscription/entitlement status, for subscription management.
  • Our email-delivery service provider: processes email address and transactional email content, for account emails (verification, password reset, two-factor sign-in codes).
  • An SMS-verification service provider (not currently active, only if SMS-based 2FA is ever added) would process second-factor verification.
  • Our internal logging/observability infrastructure: processes pseudonymized interaction-log events, for first-party debugging/support tracing.
  • Our analytics service provider (US-hosted): processes account-linked usage/analytics events, for product analytics.
  • Our cloud storage provider: processes avatar image files, for avatar storage.
  • An automated content-safety/image-moderation service: processes the re-encoded avatar image, for automated content-safety screening.
  • Our customer-support ticketing platform (or equivalent): processes support message content, account email, and device/app metadata, for customer support ticketing.
  • Our hosting/infrastructure provider: processes all of the above, as the underlying infrastructure our backend runs on.

Apple Health (HealthKit) is deliberately not listed above. It is an on-device framework provided by the operating system, not a third-party processor we send data to: EZPal writes directly to your own device's local Health store under Apple's own HealthKit permission model, and no HealthKit data is ever transmitted to us or to any provider above (§2.9).

No new vendor is introduced by the Invite program (§2.10). Invite messages are sent from your own device using apps already on it (e.g., Messages, Mail), not through any vendor in this list.

We do not sell your personal information, and we do not share your data with any third party for cross-app or cross-site advertising purposes. None of the vendors above are used for advertising.

5. Training Pal sharing

You may optionally pair with one other EZPal account (a "Training Pal"). This is not automatic: it requires you to send a specific invitation and the other person to explicitly accept it, and either of you can end the pairing at any time, with immediate effect.

What is shared, by default, if you pair: your display name, profile photo (if you uploaded one), your active workout plan, your individual logged workout sessions (workout name, effort level, and date for each), weekly workout frequency, and session streak.

What is never shared through this feature: your gender, height, weight, age-range, exact date of birth, or per-set weight/rep detail. This is enforced structurally in how our systems are built, not just as a policy: the queries that power the comparison view cannot read this data at all.

You can review exactly what's shared with your Training Pal, and end the pairing, at any time from within the App.

Using the Training Pal feature (sending or accepting an invitation) requires an active, paid EZPal subscription on both sides. If either person's paid subscription later lapses, is not renewed, or is refunded, the pairing ends automatically, the same as if you had manually ended it, and we'll show a notice in the App when this happens. See our Terms of Service §7 for the full terms, and §8 for how subscription pricing can change once you're paired with a Training Pal who is also an active paying subscriber.

6. Retention

  • Account, workout, body-stat data: until you delete your account, or you remove specific optional data earlier.
  • Interaction/debug logs (our internal logging infrastructure): fixed schedule of 90 days or less, for every user; automatically deleted in full at the end of that window (no aggregate-count fallback exists). Because this data is already pseudonymized and already short-lived by design, it is not part of the immediate deletions in §7's account-deletion cascade; see §7.
  • Analytics events (our analytics provider): up to 3 years from the event, or until account deletion, whichever is sooner.
  • HealthKit data (if sync enabled): not retained by us at all, written directly to your device's Apple Health store, governed by Apple's own retention, not ours (§2.9).
  • Crash/hang diagnostic reports (if the App crashes or hangs): not retained by us at all; captured and stored entirely on your own device by Apple's MetricKit framework, never linked to your EZPal account or sent to us or any third party automatically. You can view and choose to share a report yourself from Settings → Diagnostics; account deletion has no effect on this device-local data, since it was never sent to us in the first place.
  • Consent records (what you agreed to and when): retained as an audit trail even after you withdraw a specific consent or unpair a Training Pal, for dispute-resolution purposes.
  • Invite (referral) program contact information (§2.10): retained as part of your Invite history for as long as your account exists, so you can see the status of everyone you've invited; if the invited person never creates an account, we do not currently delete this information on any fixed schedule beyond your own account's lifecycle, but will delete it on request from either you or the person whose contact information was provided (§2.10).
  • Anonymous, aggregate account-deletion statistics (see §7): retained indefinitely; contains no identifying information by design, so ordinary personal-data retention limits don't apply the same way; see §7.
  • Support tickets: retained for a limited period after resolution (typically 12–24 months), consistent with our helpdesk provider's configured retention settings.

7. Your rights

You can, at any time, from within the App:

  • Request an export of your data (Settings → Export My Data), or by contacting us using the details in §10; we will provide your data to you directly.
  • Delete your account (Settings → Delete Account); this is available directly in the App, not only by contacting support, and it cascades across every system described above: your workout history and body stats are deleted; any linked Apple/Google sign-in is revoked, not just unlinked; any 2FA credential is deleted immediately; any active Training Pal pairing is ended, with a notice shown to the other party. Interaction/debug-log events (§2.5) are handled differently, and are deliberately not deleted early: these events are already stored under a pseudonym (an HMAC-SHA256 value computed from your account ID using a secret key that is held only on our backend and never your raw account ID, email, or any other identifying field) and are automatically deleted for every user, without exception, on a fixed schedule of 90 days or less from when they were logged. This is different from your account, workout, and body-stat data described above, which we delete immediately and in full on request. Deleting your account does not automatically cancel an active App Store subscription. Manage that separately through your Apple ID. HealthKit data you've previously synced (§2.9) is not affected by deleting your EZPal account at all, since we never held a copy of it. Manage or delete it directly in the Health app. Deleting your account also affects our Invite program, if you've used it: any reward you had earned but not yet applied to a bill is cancelled, and if you were the person someone else invited, any reward that invite earned the other person is voided going forward (it does not claw back a discount already applied to a past bill). Even after your account is deleted, we keep anonymous, aggregate statistics about account deletions in general, for example, how long accounts typically last before deletion, or whether deleted accounts had ever been paying subscribers. These statistics never include your account ID, email, exact age, exact deletion date, or any other information that could identify you or any other specific person; they are stored only as rounded, grouped totals (e.g., "12 accounts in the 8–30-day tenure range deleted this month"), and any group too small to protect individual privacy is never shown on its own.
  • Withdraw consent for the Training Pal sharing feature (§5) without deleting your whole account. Body & fitness profile data (§2.2) is collected as a required part of onboarding, not an opt-in category, so there is no separate consent to withdraw for it; if you no longer want to provide this data, you may delete your account (see above).

If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, request deletion, and limit the use of sensitive personal information (which, per our conservative posture in §2.2, includes your body-stat data). We honor these requests as a matter of policy.

EZPal is not currently offered or distributed in the European Economic Area or United Kingdom (see §1). If our distribution ever expands to include those regions, this policy will be updated to reflect your rights under the GDPR before that happens.

If you are located in Canada, in addition to the rights above (which we extend to all users as a matter of policy), you have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to know why your information is collected, to access it, and to challenge our compliance with applicable Canadian privacy law. If you are located in Quebec specifically, additional protections apply to you under Quebec's Act respecting the protection of personal information in the private sector ("Law 25"), including the right to be informed of the identity of our designated privacy officer. Under section 3.1 of Law 25, that role belongs by default to the person holding the highest authority within Avenor LLC, its Chief Executive Officer, as it has not been delegated in writing to anyone else. You can reach the Privacy Officer at support@ez-pal.com. Contact us using the details in §10 with any question about your rights under Canadian law.

8. Children's privacy

EZPal requires every user to confirm, at account creation, that they are at least 16 years old. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it. We currently have no mechanism to allow minors to use the Training Pal feature, which additionally requires a self-attested date of birth confirming the user is 18 or older.

9. Changes to this policy

We will update the effective date above whenever this policy changes. For material changes, particularly any new data category, we will provide notice within the App (and, for changes affecting the sensitive-data or Training Pal consent categories in §3, may require you to re-consent) rather than silently updating this page.

10. Contact us

Questions about this policy or your data: support@ez-pal.com.

© 2026 Avenor Solutions. EZPal is a product of Avenor LLC.
Privacy Policy Terms of Service Support Avenor Solutions →