Privacy Policy
NxtStep Athletics™, Inc. — PAICE™ (Alpha/Beta)
Applies to nxt-step.com (corporate site) and paice.ai (product web application), and to the PAICE mobile application and companion applications for supported wearable devices.
Effective date: June 2026 Version: v1.5 — Alpha/Beta Last updated: 27 June 2026
1. Who We Are and What This Policy Covers
NxtStep Athletics, Inc. ("NxtStep," "we," "us," "our") is the developer of PAICE™, an AI-empowered running training platform currently in limited, invitation-only confidential Alpha and Beta release.
This policy describes how we collect, use, disclose, retain, and protect personal information across two web properties and our applications:
- nxt-step.com — our corporate website (company information, careers, press, investor and general inquiries). Limited data collection only.
- paice.ai — the PAICE product web application and account portal, together with the PAICE mobile application and companion applications for supported wearable devices. This is where health, fitness, and biometric data are processed.
Where a practice applies to only one property, we say so. Unless stated otherwise, the practices in Sections 3–14 describe the paice.ai product, where the substantive data processing occurs.
Note on a single combined policy. We have chosen one unified policy across both properties to ensure consistency and easier maintenance during Alpha/Beta. A future option is to split into a lightweight corporate-site policy and a dedicated product policy. Counsel to advise.
2. Our Regulatory Posture — Please Read Carefully
NxtStep is not a HIPAA "covered entity." We are not a healthcare provider, health plan, or healthcare clearinghouse, and we do not provide medical services. We are not currently a "business associate" of any covered entity. As a result, U.S. HIPAA does not legally apply to most data processed by PAICE, and we do not claim to be "HIPAA compliant" or "HIPAA certified."
We do voluntarily implement HIPAA-class safeguards. As a matter of trust and athlete protection, we have chosen to design PAICE to a "HIPAA-Class" or "HIPAA-Grade" standard — meaning we voluntarily adopt the kinds of administrative, technical, and physical safeguards associated with HIPAA-regulated systems (encryption, access controls, audit logging, multi-year log retention, and the like; see Section 9). This is a voluntary commitment, not a legal status, and should not be read as a representation that PAICE is regulated under HIPAA.
PAICE is not a medical device and does not provide medical advice. PAICE produces athletic training guidance and flags potential safety considerations so that you can make informed training decisions. PAICE does not diagnose, treat, cure, or prevent any disease or injury, and it does not provide medical, clinical, or psychological treatment. PAICE is not intended to be, and has not been cleared or approved as, Software as a Medical Device (SaMD). Always consult a qualified healthcare professional regarding your health, and seek emergency care for medical emergencies. The scope and regulatory classification of PAICE remain under formal review during Alpha/Beta.
Alpha/Beta status. PAICE is an invitation-only, confidential pre-commercial and under active development. Features, data practices, and this policy will evolve. Some categories of data described here (for example, voice interaction and certain future features) are not yet active and are identified as such.
3. The Personal Information We Collect
We collect the following categories. Not all categories apply to every user, and many are collected only with your separate, explicit permission.
3.1 Information you provide (paice.ai and apps)
- Account and identity data: name, email address, password credentials, date of birth / age, sex (where you choose to provide it for training-relevant calculations), and account settings.
- Athlete profile and goals: running history, target events and goals, and self-reported training background.
- Self-reported training inputs: perceived-exertion and readiness inputs, training-diary notes, and free-text entries you submit before or after sessions.
- Support and communications: messages you send us, survey responses, and Beta feedback.
3.2 Health, fitness, and biometric data from connected devices (paice.ai and apps)
With your explicit, device-level authorization, PAICE ingests data from wearables and health platforms you connect. Depending on the source and the permissions you grant, this may include:
- heart rate, resting heart rate, and heart-rate variability;
- sleep duration, stages, and quality;
- GPS location and route data captured during activities, pace, distance, and elevation;
- cadence, running power, ground-contact and stride metrics, and movement dynamics;
- muscle-oxygenation (SmO₂) data, where you use a compatible sensor;
- activity files and workout records; and
- where you explicitly enable it: menstrual-cycle / reproductive-health data and continuous-glucose data.
This data is collected from sources you authorize, which may include Apple Health (HealthKit), Garmin Connect, Oura, Polar, Coros, Amazfit/Zepp, Whoop, Moxy Monitor, Strava, and continuous-glucose monitors. You control which sources you connect and which data types each source shares, and you can revoke access at any time (Section 8).
3.3 Derived data PAICE generates
From the inputs above, PAICE computes derived training and readiness values and personalized settings that we use to tailor the guidance you receive and improve its relevance to you over time. These derived values are part of your record and are protected on the same basis as the underlying inputs.
3.4 Voice data — Beta only, opt-in, not active in Alpha
PAICE's Alpha release uses a visual/text interface only and does not process voice. If and when a voice-interaction feature is introduced in Beta, it will require separate, explicit opt-in. Where enabled, voice processing may include converting your spoken input to text for commands and an optional spoken training-diary feature. We will describe voice-data handling in detail before any such feature is enabled.
3.5 Website and app usage data
- paice.ai / apps: device and app diagnostics, crash and error logs, and authentication events. We do not use analytics, crash-reporting, or messaging tools that are not covered by an appropriate data-protection agreement in any pathway that touches health data.
- nxt-step.com: standard, privacy-respecting web analytics and any information you submit through contact, careers, or inquiry forms. The corporate site does not process wearable or health data.
3.6 Future categories (not yet collected)
We anticipate offering, in later releases, optional features involving nutrition/dietary logs, at-home biomarker data, and mental-wellness features. These categories are not collected today. When introduced, each will carry its own enhanced, granular consent and disclosures appropriate to its sensitivity, and this policy will be updated first.
4. Sensitive Data and How We Treat It
Much of the data above is sensitive personal information / special-category data under laws such as the California Privacy Rights Act (CPRA), other U.S. state privacy laws, and (where it later applies) the EU/UK GDPR. This includes health, biometric, precise-geolocation, and reproductive-health data.
We process sensitive data only:
- with your explicit consent, granted per data type at the device/source level and through your in-app privacy controls; and
- for the purposes described in Section 5.
You may decline any sensitive category. PAICE is designed to continue operating using the data you have chosen to share: if you withhold a data stream (for example, menstrual-cycle data or GPS), PAICE works with the remaining data you have authorized, with correspondingly reduced personalization.
5. How We Use Your Information, and Why
We use personal information to:
| Purpose | Example | Legal basis (where GDPR/UK GDPR applies) |
|---|---|---|
| Provide the service | Generate and adjust your training guidance; display your analytics | Performance of a contract; explicit consent for health data |
| Support athlete safety | Identify potential overload, environmental, and recovery considerations and surface guidance | Explicit consent; vital/legitimate interests in athlete safety |
| Personalize the service | Tailor guidance to you and improve its relevance over time | Explicit consent |
| Operate and secure the platform | Authentication, diagnostics, abuse/fraud prevention, audit logging | Legitimate interests; legal obligation (security) |
| Improve PAICE | Product development and quality improvement using de-identified or aggregated data | Legitimate interests; consent where required |
| Beta Trials / research | Limited human-subjects research under separate IRB-approved consent (Section 6) | Separate explicit research consent |
| Communicate with you | Service messages, Beta updates, support responses | Performance of a contract; legitimate interests |
What we do NOT do with your data:
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under the CPRA).
- We do not use health, fitness, biometric, or device-sourced data for advertising, marketing, or data-brokerage purposes.
- We do not use data obtained through Apple Health or other connected-device APIs for any purpose other than providing and improving health-and-fitness functionality to you.
- We do not disclose your identifiable data to data brokers, advertising networks, or information resellers.
6. Beta Trials and Human-Subjects Research (IRB)
Certain Beta activities are conducted as human-subjects research reviewed and approved by the University of Oregon Institutional Review Board (UO IRB) (or its designated equivalent). If you are invited to participate in a Beta Trial:
- You must be at least 19 years of age to participate as a trial user or tester.
- You will receive a separate, IRB-approved informed-consent document specific to the study. This privacy policy does not itself constitute, and does not replace, that informed consent.
- Participation is voluntary, and you may withdraw at any time as described in the study consent.
- Research data handling, retention, de-identification, and any data sharing with academic collaborators are governed by the IRB-approved protocol and consent form.
Using PAICE outside of a formal Beta Trial does not enroll you in research.
7. AI Transparency
PAICE is, by design, an artificial-intelligence service. We want you to understand how AI interacts with your data.
- Your data is processed by AI. Connected-device and self-reported data are processed by automated systems, including artificial intelligence, to generate your personalized training guidance and related safety information.
- We personalize PAICE for you. We use your data to tailor the guidance you receive and to improve its relevance to you over time. Any personalized profile or derived data we create about you is part of your record and is deleted on the same basis as your other data (Section 8).
- Third-party AI services and Zero Data Retention. We use certain third-party AI services to support conversational and reasoning features. Where such services are used in pathways that could process your data, we contract for Zero Data Retention (ZDR) so the provider does not retain your inputs, and we do not permit your identifiable health data to be used to train third-party foundation models.
- De-identified improvement. We may use de-identified or aggregated data to evaluate and improve PAICE. De-identified data is processed so it cannot reasonably be linked back to you.
- Human oversight. During Alpha/Beta, qualified reviewers may review flagged safety events and system outputs to validate that the service behaves safely. Access is role-restricted and audit-logged.
This statement also serves as our AI transparency disclosure for purposes of connected-platform developer requirements.
8. Your Choices and Rights
You have meaningful control over your data, regardless of where you live.
Granular consent controls. Within PAICE you can grant and revoke permissions per data type and per connected source (for example: GPS on/off, sleep on/off, menstrual-cycle data on/off). There is no all-or-nothing terms-of-service gate for sensitive data.
Disconnecting a source. You can disconnect any wearable or health platform at any time, in PAICE and/or in the source platform's own settings (for example, Apple Health permissions or your Garmin, Oura, or Polar account settings). Disconnecting stops future data flow from that source.
Your statutory rights. Subject to applicable law (including the CPRA and other U.S. state privacy laws, and the GDPR/UK GDPR where it later applies), you may request to:
- access the personal information we hold about you and obtain a copy in a portable format;
- correct inaccurate information;
- delete your personal information (see Section 9);
- withdraw consent at any time (without affecting prior processing);
- object to or restrict certain processing;
- opt out of any sale or sharing — note that we do not sell or share for cross-context behavioral advertising, so there is nothing to opt out of in that respect; and
- be free from discrimination for exercising your rights.
To exercise any right, contact us at privacy@nxt-step.com. We will verify your identity and respond within the timeframes required by applicable law.
Account deletion. On verified account deletion, we delete or de-identify your personal data as described in Section 9, subject to limited retention required for legal, security, audit, or research-consent obligations.
9. How We Protect and Retain Your Data
Security safeguards (HIPAA-Grade voluntary standard). We design PAICE to protect your data using safeguards that include:
- Encryption in transit: TLS 1.3 with Perfect Forward Secrecy across all data-in-transit paths.
- Encryption at rest: AES-256 with managed encryption keys.
- Access control: role-based access with least privilege, and multi-factor authentication for any access to sensitive data.
- Network isolation: service-perimeter controls around sensitive data stores, and denial-of-service protections.
- Audit logging: immutable audit logs with multi-year retention (target six years) in protected storage.
- AI safety screening: automated screening of inputs to, and outputs from, our AI components before any output is delivered to you.
- Agreement-covered infrastructure: for pathways involving sensitive data, we use service providers operating under appropriate data-protection agreements and exclude those that are not.
No system is perfectly secure, and we cannot guarantee absolute security. We will notify affected users and regulators of qualifying data breaches as required by applicable law.
Erasure. Sensitive data is encrypted with per-user keys. When you delete your account and request erasure, we can destroy the associated encryption keys so that the underlying data becomes unrecoverable — supporting prompt fulfillment of erasure requests (for example, CPRA deletion rights and, where it later applies, GDPR Article 17).
Retention. We retain personal data only as long as needed to provide the service, support your account, meet legal/audit obligations, and honor any research consent you have given. Audit and security logs are retained on the multi-year schedule above. De-identified and aggregated data may be retained without the time limits applicable to identifiable data.
10. When and With Whom We Share Data
We share personal information only in these limited circumstances:
- Service providers / subprocessors who process data on our behalf under contract and confidentiality and security obligations — principally our cloud infrastructure provider (under a data-protection/business-associate agreement) and the third-party AI services described in Section 7 (under Zero Data Retention terms).
- Connected platforms you authorize, solely to enable the data connection you requested (for example, exchanging authorization tokens with Apple Health, Garmin, Oura, or Polar).
- Research collaborators, only for IRB-approved Beta Trials and only as described in the study's separate informed-consent document.
- Legal and safety disclosures, where required by law, legal process, or to protect rights, safety, and security.
- Corporate transactions, where data may transfer as part of a merger, acquisition, financing, or asset sale — in which case we will require the recipient to honor commitments at least as protective as this policy, notify you where required, and provide any notice required to connected platforms.
We require any third party that receives connected-device data to provide protections equivalent to those in this policy and consistent with the source platform's developer terms. We do not sell your data and do not disclose it for advertising.
11. Commitments to Connected Platforms
We honor the developer-program requirements of the health and fitness platforms PAICE connects to. Where a platform's developer terms impose stricter requirements than this policy, those stricter requirements control for data sourced from that platform.
Apple Health (HealthKit). Data obtained through HealthKit is used only to provide health and fitness services to you. We do not use HealthKit data for advertising or any use-based data mining, and we do not sell HealthKit data to advertising platforms, data brokers, or information resellers. We do not disclose HealthKit data to third parties except to provide or improve a health/fitness feature you use, and only with your consent and under equivalent protections. We obtain your explicit, informed permission before accessing HealthKit data, and we do not store HealthKit-derived data in iCloud.
Garmin Connect. We obtain your fully informed consent before transmitting or sharing Garmin-sourced data; we process Garmin data only for the purposes disclosed in this policy; and we provide the artificial-intelligence transparency disclosure in Section 7 covering AI processing of your data. We comply with applicable data-protection laws and Garmin's program and branding requirements.
Oura. We access Oura data only with your explicit consent and use it solely to provide and improve your PAICE experience. We do not disclose, market, sell, license, or lease Oura data to any third party — including advertisers or data brokers — even where you would consent to such use. You can express contact preferences and opt out of marketing at the point of collection, and we will provide Oura with notice of any merger or acquisition as required by its developer terms.
Polar. We access Polar device data through Polar's authorized interface only after you grant consent through Polar's authorization flow. We use Polar data solely to provide and improve your PAICE experience, never to build a service that competes with Polar, never to sell it, and never for advertising. We are responsible for handling Polar-sourced data in compliance with applicable privacy laws and honor your requests to disconnect and delete.
Coros. Where you connect a Coros account, we access your activity and physiological data only with your consent and use it solely to provide and improve PAICE. We never sell it or use it for advertising, and we honor disconnect and deletion requests.
Amazfit / Zepp. Where you connect Amazfit/Zepp data — whether directly or through a compatible platform such as Apple Health or Strava — we access it only with your consent, use it solely to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests.
Moxy Monitor. Where you use a Moxy muscle-oxygenation (SmO₂) sensor, its data reaches PAICE through your connected device or a compatible platform. We use it only to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests.
Other sources. For any other source you connect (for example, Whoop, Strava, or a continuous-glucose monitor), we access the data only with your consent, use it solely to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests, consistent with that source's developer terms.
12. Where We Operate and International Handling
PAICE Alpha/Beta is currently offered only to participants located in the United States. We do not knowingly onboard participants located in the EEA, the United Kingdom, or Switzerland during this period. Your data may be processed in the United States and other countries where our service providers operate.
Before offering PAICE to participants in the EEA, the UK, or Switzerland, we will update this policy and implement the transfer safeguards required by applicable law (such as Standard Contractual Clauses and any required local representative). This is expected only in connection with a later, non-stealth release.
13. Eligibility, Children, and Minors
PAICE Alpha/Beta is available only to individuals 19 years of age or older. We do not knowingly collect personal information from anyone under 19 during Alpha/Beta. If we learn that we have collected data from a person under 19 without appropriate authorization, we will delete it. Youth-athlete support, where offered in the future, will carry age-appropriate consent mechanisms and safeguards (including, where applicable, verifiable parental consent).
14. California Privacy Notice (CCPA/CPRA)
California residents have the rights described in Section 8, including rights to know, access, correct, and delete personal information, and to limit the use of sensitive personal information. We collect the categories of personal information described in Section 3, including sensitive personal information (health, biometric, precise geolocation, and reproductive-health data), for the business purposes in Section 5.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We use and disclose sensitive personal information only to provide the service you request and for other purposes permitted without a right to limit (such as security and service performance); we do not use it to infer characteristics about you for any purpose outside providing PAICE. You will not be discriminated against for exercising your rights. You may use an authorized agent to submit requests.
15. Changes to This Policy
We will update this policy as PAICE evolves from Alpha to Beta to general availability. For material changes — especially any expansion in the categories of data we collect or how we use sensitive data — we will provide prominent notice and, where required, obtain renewed consent before the change takes effect.
16. Contact Us
NxtStep Athletics, Inc. Privacy inquiries: privacy@nxt-step.com 1500 NW Bethany Blvd, Suite 200 Beaverton, Oregon 97006 USA Attn: Charlie Davidson
This Alpha/Beta policy reflects NxtStep Athletics' current, pre-commercial data practices and voluntary HIPAA-Class safeguards. It is a living document and
will be revised before commercial launch.