Privacy Policy
This notice explains how Nebula Craft Design Ltd handles information in the PaceOut app, website, Plan Builder, support service and Partner Programme.
The short version
PaceOut is built around a parent-managed family relationship. We do not sell personal information or use advertising profiles. Some Apple, Cloudflare, Resend, PostHog and Sentry processing still exists and is described below.
In the current app architecture, Screen Time selections and tokens, app names and browsing data are kept on the device and are not sent to our CloudKit records or product analytics.
A parent creates the family relationship. PaceOut can sync family profiles, pace plans, status, messages and time requests through Apple CloudKit.
Optional first-party growth events are off until you choose Allow analytics. Cloudflare may still process essential hosting, security and performance telemetry.
App deletion starts a remote Apple cleanup and then clears local state. Provider logs, mailboxes and backups may have separate deletion timing.
1. Who controls your information
PaceOut is operated by Nebula Craft Design Ltd, registered in England and Wales, company number 17180534, registered office at 61 Bridge Street, Kington, HR5 3DJ, United Kingdom. Nebula is the controller for the processing described in this notice unless a provider acts as an independent controller for its own service.
Our privacy contact is legal@getpaceout.com. We have not designated that address as a Data Protection Officer address. We will publish separate representative or DPO details if that position changes.
2. Information used by the PaceOut app
Depending on how your family uses the app, the current source and configuration identify these categories:
- Apple account and family identifiers: an Apple user identifier, family and child identifiers, pairing and share information, and restore information.
- Family and pace information: parent and child display names, pace plans, broad category settings, allowances, warnings, bedtimes, pause plans, setup status, connection status and usage totals or status.
- Family communication: parent messages and child time requests, including their status and expiry state.
- Purchases and notifications: premium entitlement or transaction state, notification preferences and local notification identifiers.
- Optional analytics and diagnostics: the app source includes product events and crash diagnostics. The intended configuration disables advertising tracking, person profiles, automatic capture, session replay and default personal identifiers. Optional analytics should remain off unless the relevant in-app choice is made.
Screen Time selections and tokens, exact app names, browsing data, usage logs and personal device content are intended to remain in local Apple Screen Time and App Group storage. The current source does not map those values into CloudKit or analytics. A signed build and provider configuration still need operational verification.
3. Information used by the website
- Hosting and security: Cloudflare Pages, Workers and edge systems receive normal web requests. Cloudflare Web Analytics or RUM may process performance, browser, network and diagnostic information. Response headers can also cause edge reporting such as network error reporting.
- Optional growth events: if you allow analytics, the website sends an event name, page path and optional source to
/api/consumer-event. These events are stored in Cloudflare D1. The site does not put email addresses, child names or Plan Builder answers in this event payload. A request IP is used transiently for rate limiting and is not written to the event row by our function. - Plan Builder email: plan generation stays in your browser. If you request delivery, the email address and the selected household, age-band and routine choices are sent to the Plan Email function and Resend for one message. The website function does not write that request to D1.
- Support: the support form collects name, email, category and free-text message. The internal support email also receives the requester IP for abuse and troubleshooting context. The form does not create a website account.
- Partner applications: applicants provide contact details, country, organisation or creator details, platform and audience information, promotional proposals, free text and confirmation timestamps. The application is stored in Cloudflare D1 and email notifications are sent through Resend.
4. Why we use information
We use information for the following purposes:
- to provide family pairing, pace plans, status, messages, requests, notifications and account lifecycle features;
- to process an optional plan email or answer a support request you initiate;
- to receive and manually assess Partner Programme applications;
- to secure the service, prevent abuse, enforce rate limits, diagnose faults and maintain reliability;
- to measure optional website product usage where you have given analytics consent; and
- to meet legal, accounting, safety and dispute-handling obligations.
The proposed UK GDPR bases are contract or steps requested before contract for requested product and communication services, legitimate interests for security and service administration, consent for optional analytics or marketing where requested, and legal obligation where required. The parent or account holder remains responsible for deciding whether to add a child and for the permissions and family instructions they give. A policy statement is not a substitute for any consent, age-assurance or parent-authority workflow required by law.
5. Apple and other providers
We use service providers and platform services to operate PaceOut. These include Apple for Sign in with Apple, CloudKit, StoreKit, Family Controls, DeviceActivity, Managed Settings, Apple Watch and widgets; Cloudflare for hosting, Workers, D1, edge security and performance telemetry; Resend for transactional email; and PostHog and Sentry for optional app analytics and diagnostics where enabled by the app configuration.
These providers may process information in countries outside the UK. The exact transfer mechanism, provider retention setting and contractual role must be checked against the current account configuration and the service terms before treating a transfer as closed. We do not use advertising networks or data brokers for PaceOut, and we do not sell personal information.
6. Retention criteria
We keep information only for as long as it is needed for the purpose collected, legal obligations, security, dispute handling or a documented deletion schedule. The current native source provides these product-level criteria: parent messages expire after about one hour, time requests after about 30 minutes, pairing invitations after about 30 minutes, local pace history for 30 days, and local notification de-duplication records for up to 30 days or 200 entries. CloudKit account deletion is designed to remove known family records and verify expected absence before local cleanup.
Website growth-event rows, support mail, partner applications, Resend message records, Cloudflare logs, Apple records, analytics and diagnostics provider records may have separate retention controls. We do not claim an exact period for those systems until the relevant provider and operational schedule is confirmed. The Partner Applicant Privacy Notice is a separate notice for that application flow.
7. Children and parent-managed use
PaceOut is a parent-managed family service with child-facing screens and content. Children do not create an independent PaceOut account or provide an email address in the current onboarding flow, but child-related information can still be personal information when it is created by a parent or used by a paired child-facing device. We do not use child information for advertising or sale.
Your parent can set the pace plan and may see the family status, the remaining allowance, the pace state and requests you send. In the current app design, your selected app names, browsing history, private messages and photos are not sent to PaceOut. If something in the app does not make sense, ask your parent or contact legal@getpaceout.com with a trusted adult.
For UK Children's Code design, we use a high-privacy, minimum-collection approach for child-facing use and do not collect date of birth or add age verification to this website by default. For US COPPA purposes, the result depends on the audience and whether information is collected online from a child. Parent-created profile details are not automatically child-originated, while a child request, push registration or child-authored message needs separate native analysis. We do not describe this notice as a certification of COPPA, UK GDPR or the ICO Children's Code.
9. Your rights
Depending on the law that applies to you, you may have rights to access, correct, delete, restrict or object to processing, receive portable information, withdraw consent and complain to a supervisory authority. You may also object to direct marketing. Some rights have conditions and exceptions.
Send a request to legal@getpaceout.com with enough detail for us to identify the relevant account or submission. We may need to verify authority, especially for a child or family record. We aim to respond within one calendar month where UK or EU GDPR timing applies, subject to lawful extensions.
In the app, a parent can start account deletion in Settings. The app attempts remote CloudKit deletion before clearing local account state and may ask you to retry if the remote operation cannot complete. For website, email or partner data, contact us and we will coordinate deletion or restriction across systems where applicable.
10. Profiling and automated decisions
PaceOut does not use personal information for advertising profiles. The Plan Builder uses fixed prompts to generate a routine and is not a health, eligibility or suitability decision. Partner applications are manually reviewed. We do not currently describe product analytics as a decision system. If that changes, we will update the notice and provide any information required by law.
11. Security
We use Apple identity and platform controls, CloudKit permissions, local protected storage where configured, HTTPS, input validation, payload limits, rate limiting and restricted operational access. No online service can promise absolute security. Report a suspected security or child-safety issue promptly to legal@getpaceout.com.
12. Complaints and contact
Nebula Craft Design Ltd
61 Bridge Street
Kington, HR5 3DJ
United Kingdom
Privacy: legal@getpaceout.com
Product support: support@getpaceout.com
If you are not satisfied, tell us first so we can investigate. You may also complain to the data protection regulator that applies to you, including the UK Information Commissioner's Office where appropriate.
13. Changes to this notice
We may update this notice when the product, providers, law or data flows change. The date and version at the top show the current revision. Material changes will be highlighted in the product or website where appropriate.