This Privacy Policy explains how Avenor LLC, doing business as "Avenor Solutions" ("we," "us," or "our") collects, uses, shares, and protects information when you use EZPal, our mobile fitness and workout-tracking application (the "App" or "Service").
Avenor Solutions operates EZPal. This policy applies to all users of the App. If you have questions about this policy or your data, contact us at support@ez-pal.com.
Where EZPal is available. EZPal is currently offered only to users located in the United States and Canada. We do not currently offer, market, or knowingly make the App available outside these two countries.
Any plan or suggestion generated from this data is general, rules-based fitness guidance, not medical advice or a personalized health recommendation. See our Terms of Service §4 for our full health & fitness disclaimer, including the recommendation to consult a physician before beginning any exercise program.
We treat gender, height, weight, and age-range as sensitive, health-adjacent data internally (see §4's access controls and §5's exclusion of this category from Training Pal sharing). This data is collected as a mandatory part of onboarding: you cannot create and use an EZPal account without providing it, and there is no consent toggle to decline.
Injury / area-to-work-around flags — optional, opt-in, never required. During onboarding, and any time afterward in Training Preferences, you can tell us about general areas (lower back, knee, shoulder, elbow/wrist) so we can avoid suggesting certain movements for you. Selecting "Nothing right now" is a full, equally-valid answer: you can complete onboarding and use the App having provided none of this information, and we do not create a consent record unless you select at least one flag. Choosing an area later, or clearing your selections back to none, only affects this data and its own consent record — it never touches your gender/height/weight/age-range above, or their status, and vice versa (see §3 and §7 for how to withdraw this specific consent).
We use this information for one purpose only: to reduce the number of exercises we suggest and to exclude certain types of movement from your plan. We do not evaluate, interpret, or reason about it medically, and telling us about an area does not mean any exercise has been assessed as safe for you. This is not medically approved guidance and is not a substitute for seeing a doctor. See our Terms of Service §4 for the full disclaimer that applies to this feature, including why you should talk to a doctor about what kind of exercise is right for you before relying on it.
Any calorie figure shown to you (in your analytics summary or in a weekly summary notification) is a rough estimate derived from the duration and effort you record, the exercises in your session, and your body weight where you have provided it, not a measured or personalized figure. See our Terms of Service §4 for the full explanation of how it's calculated and why you shouldn't rely on it for medical or dietary decisions.
If you turn on "Sync to Apple Health" in Settings, we write your logged workouts (workout type and, if you choose to enter it, how long the session took) directly to your device's Apple Health store, using Apple's HealthKit framework. This is a one-way, write-only connection: EZPal never reads any data from Apple Health, and we never request permission to. The duration figure, if you provide one, is written only to Apple Health; it is never sent to our servers, never stored in our database, and never included in any analytics event. We do not use HealthKit data for advertising or any other data-mining purpose, and we do not sell HealthKit data to advertising platforms, data brokers, or information resellers. You can turn this sync off at any time in Settings, or manage EZPal's Health permissions directly from the Health app (Health app → your profile icon → Apps → EZPal). Apple's own Health app retains this data under Apple's privacy terms, not ours, once written.
If you use our Invite program to refer a friend to EZPal (see our Terms of Service §8 for how the program works), we ask you to provide the email address of the person you're inviting before you send the invite. We store this contact information so that we can operate the Invite feature, prevent duplicate invites (e.g., checking whether the same contact has already been invited), and show you the status of everyone you've invited.
We do not send the Invite message ourselves. After you provide the contact, the App prepares a pre-written invite link/message, but it is sent from your own device using your own Messages, Mail, or other app of your choosing, the same as if you had typed and sent it yourself. We do not use a third-party email-sending vendor to deliver Invite messages on your behalf, and this contact information is never used by us to send that person any message, marketing or otherwise.
The person you invite is not yet an EZPal user at the time you provide their contact information, and has not taken any action of their own at that point. If you received an Invite from an EZPal user but never created an account yourself, and would like us to delete the contact information that was provided to us about you, contact us at the address in §10 and we will honor that request.
Avenor LLC also operates an internal business-analytics system, used only by Avenor LLC's own team, for internal business and financial reporting (for example: cohort retention, subscription revenue, and per-user profitability analysis). This system receives your account's existing internal identifier (not your email or name), a keyed cryptographic fingerprint of your email address that cannot be reversed back to your email without a secret key we control, a partially masked version of your email address for human reference (e.g., e********r@example.com), your first name, and the fact that certain account events occurred (for example: signup, onboarding completion, your first logged workout, workouts logged, and subscription started or ended), together with the workout-activity fields already described in §2.3 (such as effort level and workout-split focus). It never receives your body & fitness profile data (§2.2), injury/area-to-work-around flags, per-set weight/rep detail, your plaintext email address, or any other sensitive data described elsewhere in this policy. This is an internal system operated by Avenor LLC itself, not a third-party service provider: nothing described in this section is shared outside Avenor LLC, sold, or used for advertising.
EZPal uses Meta's (Facebook/Instagram) advertising measurement tools to measure the performance of our own advertising campaigns. We send Meta a small, fixed set of events when they happen: opening the app, creating an account, completing onboarding, pairing with a Training Pal, logging your first workout, starting your free trial, and subscribing (including the price and the specific product you subscribed to). We never send your name, email address, exercise or workout content, per-set weight/rep detail, body-stat data, or injury/accommodation flags to Meta, regardless of your tracking choice.
None of this is sent unless you grant App Tracking Transparency (“Allow Tracking”) when asked. If you tap “Ask App Not to Track,” dismiss the prompt without responding, or later turn tracking off for EZPal (Settings app → Privacy & Security → Tracking → EZPal), no event of any kind described above is sent to Meta — not the event itself, and not your device's advertising identifier. Every one of these events independently checks your current App Tracking Transparency status before doing anything, so revoking tracking later stops all further sharing from that point on, the same as never granting it in the first place.
When you do grant tracking, your device's advertising identifier (IDFA) is attached to these events so Meta can connect them to our ad campaigns; because no event is ever sent without your consent, no identifier is ever sent without it either. We use Meta's tools for measurement only, not to retarget you with ads or build an advertising profile of you elsewhere. We also configure Meta's Limited Data Use (LDU) setting, an additional processing restriction Meta applies on our behalf for California residents.
If we change what we send, add a new purpose beyond measurement, or otherwise materially change this feature, we will update this section first, consistent with §9 (Changes to This Policy).
Separately from the in-app measurement described in §2.12, our marketing website (ez-pal.com — the pages you are reading this on, not the App itself) also uses a Meta Pixel to measure the performance of our own advertising campaigns for the website. It sends two kinds of event: a page-view event each time you load a page, and a "Lead" event if you click an App Store download link or badge. App Tracking Transparency is an iOS App Store requirement and does not apply to a website viewed in a browser, so this measurement is not gated by it the way §2.12's in-app events are. Instead, it runs by default — the same as most websites' analytics or ad-measurement tags — unless you opt out, consistent with the CCPA/CPRA's opt-out (not opt-in) model; see §7.
You can opt out of this website's Meta Pixel at any time, and it takes effect immediately, in either of two ways: (1) click "Do Not Sell or Share My Personal Information" in the footer of any page on this website, or (2) enable a Global Privacy Control ("GPC") signal in your browser or a browser extension, which this website detects and honors automatically, with no need to also click the footer link. Either signal stops the website's Meta Pixel from initializing or sending any event, on every page of this website, for as long as the signal is present or your stored choice remains in effect on that browser/device; opting back in (available for the footer-link choice, not for a browser-level GPC signal, which only your browser/extension controls) resumes it. We never send your name, email address, or any account/workout data described elsewhere in this policy through this website pixel; it only ever sends the page-view/click events described above.
We use the following service providers. Except where noted below, each acts as a processor under contract, not independently using your data for their own purposes:
Apple Health (HealthKit) is deliberately not listed above. It is an on-device framework provided by the operating system, not a third-party processor we send data to: EZPal writes directly to your own device's local Health store under Apple's own HealthKit permission model, and no HealthKit data is ever transmitted to us or to any provider above (§2.9).
No new vendor is introduced by the Invite program (§2.10). Invite messages are sent from your own device using apps already on it (e.g., Messages, Mail), not through any vendor in this list.
Our internal business-analytics reporting (§2.11) is deliberately not listed above either. It is operated by Avenor LLC itself, not by a third-party processor, so it does not belong in this list of outside service providers.
We do not sell your personal information. Other than the Meta advertising-measurement sharing described in §2.12, which only occurs if you have granted App Tracking Transparency, we do not share your data with any third party for cross-app or cross-site advertising purposes.
You may optionally pair with one other EZPal account (a "Training Pal"). This is not automatic: it requires you to send a specific invitation and the other person to explicitly accept it, and either of you can end the pairing at any time, with immediate effect.
What is shared, by default, if you pair: your display name, profile photo (if you uploaded one), your active workout plan, your individual logged workout sessions (workout name, effort level, and date for each), weekly workout frequency, session streak, and how many exercises you log for each muscle group.
Shared goals. Either of you can propose a specific shared goal (for example, a joint session count for the month); it becomes active only once the other person accepts it, and either of you can end it at any time. While it's active, you can each see the other's progress toward it, or, for a small number of goal types, one combined number for the two of you together rather than a separate figure for each person.
Archiving a completed goal. Once a shared goal is completed, either of you can archive it from your own Completed-goals list at any time. Archiving only changes your own list: your Training Pal's copy is untouched, and you can restore yours from your own archive whenever you want.
Activity feed. Your Training Pal tab shows a shared, reverse-chronological feed built entirely from the categories already listed above: your logged sessions, milestones derived from them (for example, reaching a session-count or streak threshold), and updates to a shared goal. The feed does not add any new category of data beyond what's already described in this section.
Reactions. You and your Training Pal can each respond to something in the feed with one of a small, fixed set of reaction icons (for example, a clap or a flame). There is no free-text messaging in this feature: you can only choose from that fixed set, you can't attach a comment, and we don't tell the sender whether or when the recipient has seen a reaction.
Weekly email. If you're both actively paired and subscribed, the weekly progress email we send you (see §2.3) includes a short section summarizing your Training Pal's activity that week, drawn from the same categories described in this section.
Goal proposal and removal emails. If your Training Pal proposes a shared goal (including renewing or changing one) or ends one that's still active, we also email you about it, naming your Training Pal and describing the goal, in addition to sending a push notification. You can turn these emails off from Notification Settings without affecting anything else described in this section.
What is never shared through this feature: your gender, height, weight, age-range, exact date of birth, per-set weight/rep detail, or injury/area-to-work-around flags. This is enforced structurally in how our systems are built, not just as a policy: the queries that power the comparison view, the shared goal, the activity feed, and the weekly-email section cannot read this data at all.
You can review exactly what's shared with your Training Pal, and end the pairing, at any time from within the App. Ending the pairing stops all of the sharing described in this section immediately, for both of you: a shared goal you had together is marked ended, not deleted, so that if you pair with that same person again later you can both see that you once had it; any reactions between the two of you are deleted right away. There's no way to keep only part of this and unpair from the rest.
Sending a Training Pal invitation requires an active, paid EZPal subscription. Accepting one does not: you can accept an invitation and be paired while on the free tier. Seeing any of the shared data described in this section, including the shared goal, the activity feed, reactions, and the weekly-email section, however, requires an active, paid subscription on both sides. If either person's subscription lapses, is not renewed, or is refunded, you lose the shared view, and if that isn't resolved, the pairing ends automatically, the same as if you had manually ended it, and we'll show a notice in the App when this happens. See our Terms of Service §7 for the full terms.
You can, at any time, from within the App:
EZPal shows an App Tracking Transparency prompt, and, only if you respond “Allow,” sends the events described in §2.12 to Meta for ad-campaign measurement. You can review or change your choice at any time in the Settings app → Privacy & Security → Tracking → EZPal; turning tracking off (or never turning it on) means nothing further is sent to Meta from that point forward.
If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, request deletion, and limit the use of sensitive personal information (which, per our conservative posture in §2.2, includes your body-stat and injury/accommodation data). We honor these requests as a matter of policy. This policy covers two separate Meta Pixel channels, each with its own opt-out mechanism appropriate to where it runs:
You can exercise the rights above at any time by contacting us at the address in §10, and you can exercise the website-specific opt-out above at any time, without contacting us, using the footer link or your browser's GPC setting.
EZPal is not currently offered or distributed in the European Economic Area or United Kingdom (see §1). If our distribution ever expands to include those regions, this policy will be updated to reflect your rights under the GDPR before that happens.
If you are located in Canada, in addition to the rights above (which we extend to all users as a matter of policy), you have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to know why your information is collected, to access it, and to challenge our compliance with applicable Canadian privacy law. If you are located in Quebec specifically, additional protections apply to you under Quebec's Act respecting the protection of personal information in the private sector ("Law 25"), including the right to be informed of the identity of our designated privacy officer. Under section 3.1 of Law 25, that role belongs by default to the person holding the highest authority within Avenor LLC, its Chief Executive Officer, as it has not been delegated in writing to anyone else. You can reach the Privacy Officer at support@ez-pal.com. Contact us using the details in §10 with any question about your rights under Canadian law.
EZPal requires every user to confirm, at account creation, that they are at least 16 years old. This same requirement governs the optional Training Pal pairing feature: there is no separate or higher age requirement to pair. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it.
We will update the effective date above whenever this policy changes. For material changes, particularly any new data category, we will provide notice within the App (and, for changes affecting the sensitive-data or Training Pal consent categories in §3, may require you to re-consent) rather than silently updating this page.
September 15, 2026 update. §5 now names two additions that ship with the shared-goal lifecycle: archiving a completed goal, which changes only your own Completed-goals list and never your Training Pal's copy, and the goal proposal and removal emails, which name your Training Pal and describe the goal. §4's email-delivery bullet names those emails too. Neither changes what we collect; both describe new ways existing Training Pal information is shown to you or sent to you, and the emails can be turned off in Notification Settings.
September 2026 update. §5 previously did not name two things that were already part of the Service: how many exercises you log for each muscle group, which had already been shared with paired Training Pals since August 29, 2026 without being named here, and the shared-goal, activity-feed, reaction, and weekly-email-recap features, which are built entirely from categories already disclosed in this policy and don't add a new one. We've corrected §5 to name all of them. Every existing Training Pal pair is being asked, on their own device, to review and reaffirm the updated Training Pal sharing consent, and until you do, none of these categories, including muscle-group data, will keep being shared with your Pal.
September 2026 update (Training Pal age requirement). The Training Pal pairing feature previously required a separate, self-attested date of birth confirming you were 18 or older, in addition to the general 16-and-older account requirement. We've removed that additional pairing-specific requirement: the same 16-and-older attestation now governs both account creation and Training Pal pairing. We have also stopped collecting dates of birth, since that requirement was the only thing they were collected for.
Questions about this policy or your data: support@ez-pal.com.