Privacy Policy

NxtStep Athletics, Inc. — PAICE™ (Alpha/Beta)

Applies to nxt-step.com (corporate site) and paice.ai (product web application), and to the PAICE mobile application and companion applications for supported wearable devices.

Effective date: June 2026 Version: v1.5 — Alpha/Beta Last updated: 27 June 2026

1. Who We Are and What This Policy Covers

NxtStep Athletics, Inc. ("NxtStep," "we," "us," "our") is the developer of PAICE™, an AI-empowered running training platform currently in limited, invitation-only confidential Alpha and Beta release.

This policy describes how we collect, use, disclose, retain, and protect personal information across two web properties and our applications:

Where a practice applies to only one property, we say so. Unless stated otherwise, the practices in Sections 3–14 describe the paice.ai product, where the substantive data processing occurs.

Note on a single combined policy. We have chosen one unified policy across both properties to ensure consistency and easier maintenance during Alpha/Beta. A future option is to split into a lightweight corporate-site policy and a dedicated product policy. Counsel to advise.

2. Our Regulatory Posture — Please Read Carefully

NxtStep is not a HIPAA "covered entity." We are not a healthcare provider, health plan, or healthcare clearinghouse, and we do not provide medical services. We are not currently a "business associate" of any covered entity. As a result, U.S. HIPAA does not legally apply to most data processed by PAICE, and we do not claim to be "HIPAA compliant" or "HIPAA certified."

We do voluntarily implement HIPAA-class safeguards. As a matter of trust and athlete protection, we have chosen to design PAICE to a "HIPAA-Class" or "HIPAA-Grade" standard — meaning we voluntarily adopt the kinds of administrative, technical, and physical safeguards associated with HIPAA-regulated systems (encryption, access controls, audit logging, multi-year log retention, and the like; see Section 9). This is a voluntary commitment, not a legal status, and should not be read as a representation that PAICE is regulated under HIPAA.

PAICE is not a medical device and does not provide medical advice. PAICE produces athletic training guidance and flags potential safety considerations so that you can make informed training decisions. PAICE does not diagnose, treat, cure, or prevent any disease or injury, and it does not provide medical, clinical, or psychological treatment. PAICE is not intended to be, and has not been cleared or approved as, Software as a Medical Device (SaMD). Always consult a qualified healthcare professional regarding your health, and seek emergency care for medical emergencies. The scope and regulatory classification of PAICE remain under formal review during Alpha/Beta.

Alpha/Beta status. PAICE is an invitation-only, confidential pre-commercial and under active development. Features, data practices, and this policy will evolve. Some categories of data described here (for example, voice interaction and certain future features) are not yet active and are identified as such.

3. The Personal Information We Collect

We collect the following categories. Not all categories apply to every user, and many are collected only with your separate, explicit permission.

3.1 Information you provide (paice.ai and apps)

3.2 Health, fitness, and biometric data from connected devices (paice.ai and apps)

With your explicit, device-level authorization, PAICE ingests data from wearables and health platforms you connect. Depending on the source and the permissions you grant, this may include:

This data is collected from sources you authorize, which may include Apple Health (HealthKit), Garmin Connect, Oura, Polar, Coros, Amazfit/Zepp, Whoop, Moxy Monitor, Strava, and continuous-glucose monitors. You control which sources you connect and which data types each source shares, and you can revoke access at any time (Section 8).

3.3 Derived data PAICE generates

From the inputs above, PAICE computes derived training and readiness values and personalized settings that we use to tailor the guidance you receive and improve its relevance to you over time. These derived values are part of your record and are protected on the same basis as the underlying inputs.

3.4 Voice data — Beta only, opt-in, not active in Alpha

PAICE's Alpha release uses a visual/text interface only and does not process voice. If and when a voice-interaction feature is introduced in Beta, it will require separate, explicit opt-in. Where enabled, voice processing may include converting your spoken input to text for commands and an optional spoken training-diary feature. We will describe voice-data handling in detail before any such feature is enabled.

3.5 Website and app usage data

3.6 Future categories (not yet collected)

We anticipate offering, in later releases, optional features involving nutrition/dietary logs, at-home biomarker data, and mental-wellness features. These categories are not collected today. When introduced, each will carry its own enhanced, granular consent and disclosures appropriate to its sensitivity, and this policy will be updated first.

4. Sensitive Data and How We Treat It

Much of the data above is sensitive personal information / special-category data under laws such as the California Privacy Rights Act (CPRA), other U.S. state privacy laws, and (where it later applies) the EU/UK GDPR. This includes health, biometric, precise-geolocation, and reproductive-health data.

We process sensitive data only:

You may decline any sensitive category. PAICE is designed to continue operating using the data you have chosen to share: if you withhold a data stream (for example, menstrual-cycle data or GPS), PAICE works with the remaining data you have authorized, with correspondingly reduced personalization.

5. How We Use Your Information, and Why

We use personal information to:

Purpose Example Legal basis (where GDPR/UK GDPR applies)
Provide the service Generate and adjust your training guidance; display your analytics Performance of a contract; explicit consent for health data
Support athlete safety Identify potential overload, environmental, and recovery considerations and surface guidance Explicit consent; vital/legitimate interests in athlete safety
Personalize the service Tailor guidance to you and improve its relevance over time Explicit consent
Operate and secure the platform Authentication, diagnostics, abuse/fraud prevention, audit logging Legitimate interests; legal obligation (security)
Improve PAICE Product development and quality improvement using de-identified or aggregated data Legitimate interests; consent where required
Beta Trials / research Limited human-subjects research under separate IRB-approved consent (Section 6) Separate explicit research consent
Communicate with you Service messages, Beta updates, support responses Performance of a contract; legitimate interests

What we do NOT do with your data:

6. Beta Trials and Human-Subjects Research (IRB)

Certain Beta activities are conducted as human-subjects research reviewed and approved by the University of Oregon Institutional Review Board (UO IRB) (or its designated equivalent). If you are invited to participate in a Beta Trial:

Using PAICE outside of a formal Beta Trial does not enroll you in research.

7. AI Transparency

PAICE is, by design, an artificial-intelligence service. We want you to understand how AI interacts with your data.

This statement also serves as our AI transparency disclosure for purposes of connected-platform developer requirements.

8. Your Choices and Rights

You have meaningful control over your data, regardless of where you live.

Granular consent controls. Within PAICE you can grant and revoke permissions per data type and per connected source (for example: GPS on/off, sleep on/off, menstrual-cycle data on/off). There is no all-or-nothing terms-of-service gate for sensitive data.

Disconnecting a source. You can disconnect any wearable or health platform at any time, in PAICE and/or in the source platform's own settings (for example, Apple Health permissions or your Garmin, Oura, or Polar account settings). Disconnecting stops future data flow from that source.

Your statutory rights. Subject to applicable law (including the CPRA and other U.S. state privacy laws, and the GDPR/UK GDPR where it later applies), you may request to:

To exercise any right, contact us at privacy@nxt-step.com. We will verify your identity and respond within the timeframes required by applicable law.

Account deletion. On verified account deletion, we delete or de-identify your personal data as described in Section 9, subject to limited retention required for legal, security, audit, or research-consent obligations.

9. How We Protect and Retain Your Data

Security safeguards (HIPAA-Grade voluntary standard). We design PAICE to protect your data using safeguards that include:

No system is perfectly secure, and we cannot guarantee absolute security. We will notify affected users and regulators of qualifying data breaches as required by applicable law.

Erasure. Sensitive data is encrypted with per-user keys. When you delete your account and request erasure, we can destroy the associated encryption keys so that the underlying data becomes unrecoverable — supporting prompt fulfillment of erasure requests (for example, CPRA deletion rights and, where it later applies, GDPR Article 17).

Retention. We retain personal data only as long as needed to provide the service, support your account, meet legal/audit obligations, and honor any research consent you have given. Audit and security logs are retained on the multi-year schedule above. De-identified and aggregated data may be retained without the time limits applicable to identifiable data.

10. When and With Whom We Share Data

We share personal information only in these limited circumstances:

We require any third party that receives connected-device data to provide protections equivalent to those in this policy and consistent with the source platform's developer terms. We do not sell your data and do not disclose it for advertising.

11. Commitments to Connected Platforms

We honor the developer-program requirements of the health and fitness platforms PAICE connects to. Where a platform's developer terms impose stricter requirements than this policy, those stricter requirements control for data sourced from that platform.

Apple Health (HealthKit). Data obtained through HealthKit is used only to provide health and fitness services to you. We do not use HealthKit data for advertising or any use-based data mining, and we do not sell HealthKit data to advertising platforms, data brokers, or information resellers. We do not disclose HealthKit data to third parties except to provide or improve a health/fitness feature you use, and only with your consent and under equivalent protections. We obtain your explicit, informed permission before accessing HealthKit data, and we do not store HealthKit-derived data in iCloud.

Garmin Connect. We obtain your fully informed consent before transmitting or sharing Garmin-sourced data; we process Garmin data only for the purposes disclosed in this policy; and we provide the artificial-intelligence transparency disclosure in Section 7 covering AI processing of your data. We comply with applicable data-protection laws and Garmin's program and branding requirements.

Oura. We access Oura data only with your explicit consent and use it solely to provide and improve your PAICE experience. We do not disclose, market, sell, license, or lease Oura data to any third party — including advertisers or data brokers — even where you would consent to such use. You can express contact preferences and opt out of marketing at the point of collection, and we will provide Oura with notice of any merger or acquisition as required by its developer terms.

Polar. We access Polar device data through Polar's authorized interface only after you grant consent through Polar's authorization flow. We use Polar data solely to provide and improve your PAICE experience, never to build a service that competes with Polar, never to sell it, and never for advertising. We are responsible for handling Polar-sourced data in compliance with applicable privacy laws and honor your requests to disconnect and delete.

Coros. Where you connect a Coros account, we access your activity and physiological data only with your consent and use it solely to provide and improve PAICE. We never sell it or use it for advertising, and we honor disconnect and deletion requests.

Amazfit / Zepp. Where you connect Amazfit/Zepp data — whether directly or through a compatible platform such as Apple Health or Strava — we access it only with your consent, use it solely to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests.

Moxy Monitor. Where you use a Moxy muscle-oxygenation (SmO₂) sensor, its data reaches PAICE through your connected device or a compatible platform. We use it only to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests.

Other sources. For any other source you connect (for example, Whoop, Strava, or a continuous-glucose monitor), we access the data only with your consent, use it solely to provide and improve PAICE, never sell it or use it for advertising, and honor disconnect and deletion requests, consistent with that source's developer terms.

12. Where We Operate and International Handling

PAICE Alpha/Beta is currently offered only to participants located in the United States. We do not knowingly onboard participants located in the EEA, the United Kingdom, or Switzerland during this period. Your data may be processed in the United States and other countries where our service providers operate.

Before offering PAICE to participants in the EEA, the UK, or Switzerland, we will update this policy and implement the transfer safeguards required by applicable law (such as Standard Contractual Clauses and any required local representative). This is expected only in connection with a later, non-stealth release.

13. Eligibility, Children, and Minors

PAICE Alpha/Beta is available only to individuals 19 years of age or older. We do not knowingly collect personal information from anyone under 19 during Alpha/Beta. If we learn that we have collected data from a person under 19 without appropriate authorization, we will delete it. Youth-athlete support, where offered in the future, will carry age-appropriate consent mechanisms and safeguards (including, where applicable, verifiable parental consent).

14. California Privacy Notice (CCPA/CPRA)

California residents have the rights described in Section 8, including rights to know, access, correct, and delete personal information, and to limit the use of sensitive personal information. We collect the categories of personal information described in Section 3, including sensitive personal information (health, biometric, precise geolocation, and reproductive-health data), for the business purposes in Section 5.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We use and disclose sensitive personal information only to provide the service you request and for other purposes permitted without a right to limit (such as security and service performance); we do not use it to infer characteristics about you for any purpose outside providing PAICE. You will not be discriminated against for exercising your rights. You may use an authorized agent to submit requests.

15. Changes to This Policy

We will update this policy as PAICE evolves from Alpha to Beta to general availability. For material changes — especially any expansion in the categories of data we collect or how we use sensitive data — we will provide prominent notice and, where required, obtain renewed consent before the change takes effect.

16. Contact Us

NxtStep Athletics, Inc. Privacy inquiries: privacy@nxt-step.com 1500 NW Bethany Blvd, Suite 200 Beaverton, Oregon 97006 USA Attn: Charlie Davidson

This Alpha/Beta policy reflects NxtStep Athletics' current, pre-commercial data practices and voluntary HIPAA-Class safeguards. It is a living document and
will be revised before commercial launch.