Privacy Policy
Effective date: August 19, 2026
This Privacy Policy describes how ClassPilot ("we," "our," or "us") collects, uses, and shares information when you use the ClassPilot mobile application and related services (collectively, the "Service"). ClassPilot is operated by the makers of StudioPilot, the app the studios themselves use.
ClassPilot connects you to independent fitness studios. Those studios are separate businesses, and this policy explains both what we hold and what a studio holds about you — because they are not the same thing.
1. Information We Collect
Information you provide
- Account information. Your name and email address. You may optionally add a phone number. If you sign in with Apple or Google, we receive a stable identifier from that provider along with an email address they have verified.
- Sign-in credentials. You can sign in with a one-time code sent to your email, with Apple, with Google, or with a password. If you set a password, we store only a cryptographic hash of it — we never store the password itself and cannot recover it.
- Support communications. If you email us, we keep a record of that correspondence to resolve your enquiry.
Location
If you allow it, ClassPilot uses your device's location to show you studios near you. Your location is used only at the moment of the search and is never stored on our servers. We do not build a location history, we do not track your movements, and we do not share your location with studios or anyone else.
Location is optional. If you decline the permission, you can still find any studio by name, and you can still join a studio with a code they give you.
Information created by using the Service
- Bookings and attendance. Classes you book, cancel, attend, or miss, and the class packs or credits used to pay for them. These records are kept rather than deleted because they are the evidence behind questions like whether a cancellation was made in time.
- Studio relationships. Which studios you have booked with, and any class packs or credits you hold with them.
- Operational records. We record the outcome of important actions — a sign-in code that was sent, a booking that failed, a cancellation that was refused — so we can answer a support question without asking you to reproduce the problem. These records identify you by an internal account identifier and a one-way index of your email address, never by your email address in readable form.
- Security records. Sign-in attempts, including failed ones, so we can lock an account that is being attacked and investigate unauthorised access.
What we do not collect
- No third-party analytics or advertising. The ClassPilot app contains no advertising SDK, no third-party analytics SDK, and no crash-reporting SDK. We do not sell your data, we do not share it with data brokers, and we do not use it for advertising.
- No payment card details. Payment for a class is handled directly by the studio. We do not collect, process, or store your card details.
- No stored location. See above — location is used transiently and discarded.
2. How We Use Information
- To create and secure your account, and to sign you in.
- To show you studios and their schedules, take your booking, and apply the class pack or credit that pays for it.
- To send you transactional email — your sign-in code, and confirmations relating to your bookings.
- To answer support requests and to investigate errors, fraud, and abuse.
- To meet our legal obligations.
3. What Studios Can See
This is the part worth reading closely, because it is the one people assume wrongly.
- Browsing does not identify you. Looking at a studio's page or schedule does not tell that studio who you are. Studios see aggregate interest only — how many people viewed, not which people.
- Booking does. When you book with a studio, you become a client of that studio, and they receive your name and contact details so they can run their business — a class register, a cancellation, a question about your booking.
- Studios cannot see each other's clients. A studio sees only its own relationship with you. It cannot see the other studios you use, your bookings elsewhere, or your credits elsewhere.
- Studios keep their own records. A studio's record of you — your name, contact details, and any private notes they write about your classes — belongs to that studio and is governed by their own privacy practices. It persists even if you delete your ClassPilot account (see section 6).
4. Service Providers
We share information with a small number of providers that operate parts of the Service on our behalf, under contract and only for that purpose:
- Hosting and database — our servers and database, which store the information described above.
- Email delivery — to send your sign-in code and booking emails. The provider receives your email address and the message.
- Geocoding — studio addresses are converted to map coordinates once, when the studio saves its address. This is the studio's address, not yours; your location is not sent to this provider.
- Apple and Google — if you choose to sign in with them, they confirm your identity to us. We do not send them your booking activity.
5. Security
- Your contact details are encrypted at rest. Where we need to look an address up, we do so using a one-way index rather than by reading it.
- Passwords, where set, are stored as a one-way hash and are never recoverable.
- Sessions can be revoked, and repeated failed sign-ins temporarily lock an account.
- All traffic between the app and our servers is encrypted in transit.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your information we will notify you as required by law.
6. Deleting Your Account
You can delete your ClassPilot account at any time in the app, or by emailing us. Deleting your account revokes every sign-in, removes your contact details from your ClassPilot account record, and disconnects you from every studio.
What it does not do is erase a studio's own records. A studio's client list is that business's record — much of it typed in by them — and their bookkeeping and class history depend on it. To have a particular studio erase its record of you, contact that studio directly. Full detail is on our account deletion page.
7. Data Retention
- Account information is kept while your account is open, and removed on deletion as described above.
- Booking and attendance records are retained as the studio's business records.
- Security and sign-in records are retained for a limited period — up to 12 months — and then deleted automatically.
- Operational diagnostic records are pruned on a rolling schedule and are not kept indefinitely.
8. Children
ClassPilot is not directed to children under 13, and we do not knowingly collect information from them. If a studio's class involves a minor, the booking should be made by a parent or guardian on their own account. If you believe a child has given us information, email us and we will delete it.
9. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to certain processing. Email us at support@classpilotapp.com and we will respond within the period required by applicable law. We will not discriminate against you for exercising these rights.
For information a studio holds about you in its own records, the studio is the responsible party and the request goes to them.
10. Changes to This Policy
If we change this policy we will update the effective date above, and for material changes we will notify you in the app or by email before the change takes effect.
11. Contact
Questions about this policy or your data: support@classpilotapp.com