pando club.Your settings

YOUR INFORMATION. YOUR CHOICE.

Privacy policy

Pando Club · Effective October 2, 2026

This policy covers the Pando Club website, Android app and iOS app. Pando is a longevity coach that helps you build everyday fitness, nutrition and sleep habits for healthy ageing. You choose whether to add health information or connect the meal scanner.

Optional habit-change support

You may choose to record smoking, nicotine or alcohol goals, triggers, safety answers and daily reflections. Web entries are stored in your private account; native entries stay on your device and do not sync across platforms. These details are excluded from product analytics and employer or insurer reports. The coach button prepares a message for you to review; sending it shares that text with the AI provider under your chat-sharing consent. Deleting a habit plan removes its check-ins, but does not delete messages you previously sent. Native reminder text does not identify the habit.

Health document extraction

With explicit consent, the selected PDF or image, including any identifiers it contains, passes through Pando to OpenAI for text and finding extraction. Do not upload another person’s private record. The extraction endpoint does not persist the file or result in Pando storage; provider retention described below still applies. You review findings before saving and choose whether they are available as plan context. A report flag is not a diagnosis. Web originals and reviewed findings are stored in your private account. Native originals and findings stay in app-private device storage; they do not sync across devices. Android backup is disabled and iOS originals are excluded from cloud backup. Removing a record removes its native original and findings. On web, originals and extracted findings have separate remove controls. Removing context does not undo plans already adapted from it. Saved findings are sent to the coach or plan adaptation provider only when health-context sharing is enabled. Health files, extracted text and findings are excluded from product analytics.

Coaching agreements

When you save a coaching agreement, Pando stores its date, workout, cue, optional reward, feedback, adaptations and completion source in your signed-in account or installation account. Native apps cache agreements for offline viewing. Separate installation accounts are not automatically merged. If you enable workout matching, the workout type, time, duration and source are sent to Pando to match your agreement; these are not sent to an AI provider unless you also enable the relevant coach sharing. Missing or ambiguous records do not prove inactivity. Correct a match using Undo in Coach. Account or installation deletion removes these server agreements. Agreements older than 90 days are removed when a new agreement change is saved. Free-text cues and feedback are excluded from analytics.

Plan feedback

When you request a plan adaptation and consent, we send your feedback and current plan to OpenAI. Saved health notes are included only if you choose that option; health information typed into feedback is always part of the message. Proposed changes are saved only when you apply them. Web plans are stored in your account; native plans stay on that device. Feedback text is not included in product analytics.

Information you provide

On the website, we store your profile and preferences, goals, plans, activity and meal logs, health questionnaire answers, uploaded records and summaries, reminders, reflections and coach messages. Sign-in supplies an account identifier and may supply your email and name. We use the identifier to keep your records associated with your account.

Android stores your name, goals, check-ins, exercise checklists, meal estimates and health notes on your phone. These do not automatically sync with the website. Android cloud backup is disabled for the app. Pando automatically creates an anonymous installation credential for included AI features. It is encrypted using Android Keystore. No OpenAI account or user API key is needed. Pando stores a hash of this credential and an anonymous installation ID for authorization and rate limits.

Meal photos and AI processing

Only after you select a photo and consent to analysis, Pando sends the photo, meal description, portion details and answers through our server to OpenAI to estimate calories and macros. Health records are not sent with meal scans. Android resizes and re-encodes selected photos, removing metadata. Pando does not save meal-photo files on its server; it saves estimates only when you choose to log them. The camera app you use may retain its own copy.

Our API calls use storage disabled. OpenAI may retain abuse-monitoring logs, normally for up to 30 days, subject to its exceptions. API data is not used to train OpenAI models by default. Read OpenAI’s API data controls. Do not include faces, private documents or other people’s information in meal photos.

If you report an AI estimate, we store the estimate and selected reason with your account for safety and quality review. The report does not include your photo. Reports remain until account deletion.

AI longevity coaching and nudges

With your consent, we send your message, recent conversation and selected plan context to OpenAI to generate coaching replies. You can choose whether to include saved health notes, conditions, limitations and allergies. Uploaded medical documents are not included. Information you type into chat is part of the message even if the optional health-context switch is off. Web chats are stored in your Pando account. In the current Android version, chats stay on the phone and are not saved as server chat history. Reported responses are stored for safety review and removed with account deletion.

Optional Android notifications are scheduled on the phone at times you choose and use local check-ins to select a supportive reminder. No push-provider device token is collected. Notifications are marked private on the lock screen, follow quiet hours and can be disabled in the app or system settings. Browser nudges appear while using the site; dismissals are stored as a browser preference. WhatsApp messaging and background browser push are not connected.

Native subscriptions

When enabled, Apple or Google Play processes native subscription payments. Pando sends store purchase proofs to its server to verify access, and stores those proofs with the installation identifier, product and expiry. The server checks status with the store and may cache verified access for up to one minute. Purchase proofs do not contain your health records. Restoring purchases restores access, not health data. Deleting local data removes the installation’s stored purchase proof but does not cancel store renewal. Use Apple or Google Play subscription settings to cancel. Native checkout remains disabled until store activation and testing are complete.

Subscriptions and payments

When you choose a web subscription, Stripe processes your checkout, payment details, billing information and subscription management. Pando stores a mapping between your account and Stripe customer identifier, checkout references and trial eligibility. We do not store your full card number. We send an opaque account reference to Stripe, never your health notes, meals, photos or coaching messages. Payment status is checked to grant paid features. Signed billing events are retained for up to 30 days without their payment or personal-data payloads. Stripe may retain transaction records after account deletion for financial and legal obligations. Read Stripe’s privacy policy.

Why we use information

To save your plans and progress, display your health context, provide requested meal estimates, secure accounts, limit misuse and respond to support requests. Optional website product analytics count feature events and screen names associated with your account. Analytics exclude health answers, documents, phone numbers and chat text. You can turn analytics off in Settings; account deletion removes previous events.

Service providers and third-party content

OpenAI Sites and Cloudflare infrastructure host the website, database and uploaded files. OpenAI processes meal scans. ChatGPT provides website sign-in. These providers may process network information such as IP addresses and operational/security logs under their own policies. When you choose a technique video, YouTube receives a connection from your device and may process viewing and device information. See Google’s privacy policy and OpenAI’s privacy policy.

Pando has no advertising SDKs and does not sell your personal information or share health data with employers or insurers. WhatsApp connections are currently demonstrations; they do not transmit data. Wearable connections, when configured, send the data you authorize to Pando’s separately hosted Open Wearables service. This can include activity, steps, workouts, heart rate and sleep. Pando keeps a pseudonymous mapping to your wearable-service profile. Raw imported wearable data is stored in Open Wearables; Pando reads recent summaries to display them. Android Health Connect uploads occur when you tap Sync, or approximately every 12 hours after you enable automatic sync and grant background read permission. Android may delay scheduled runs. Turn automatic sync off in Wearables at any time. You can separately choose to include wearable summaries in an AI coach request to OpenAI. Disconnect and delete wearable data in Wearables to remove that profile, revoke its connections and erase its stored data. Account or Android installation deletion also attempts this removal and reports failure if the wearable service cannot complete it. This does not erase records held by the original device provider. Revoke phone health permissions to stop further access. Provider or service backups may follow separate retention periods. We do not request location, contacts, microphone, broad photo-library access. The Android wearable feature requests read-only Health Connect access to steps, sleep and exercise sessions after your permission. Recent Android versions store seven days of aggregated totals, source app identifiers and time zone in Pando’s database; deleting wearable data removes these summaries. Raw exercise sessions are not uploaded.

Retention and deletion

Account information and uploaded health records remain until you remove them or delete your Pando account. Older manually connected scanner and coach credentials expire after 30 days. Current Android installation access remains until deleted in the app. Operational usage counters are kept while the account exists. Device data remains until you clear it in the app or uninstall. Android Privacy & data deletion also removes installation access, usage records and AI reports from Pando. Uninstalling alone does not notify the server; delete through the app first to remove those records. Enrollment uses a daily hashed network identifier and counters to limit misuse. These counters are purged after two days during enrollment.

Delete your Pando account and stored data at any time. Successful deletion removes active database records and uploaded files and revokes scanner access. A one-way identifier and deletion status remain only to prevent old sessions restoring your account; explicitly creating a new account removes that marker. Provider-managed backups and security logs may outlast active-data deletion according to provider retention policies. We have not independently verified all infrastructure backup-retention periods.

Your choices and security

Use Settings to edit information, export your web data, remove individual uploaded records or turn off analytics. Android offers local-data deletion and a link to web-account deletion under You → Privacy & data. Connections use HTTPS. Access to cloud records is restricted to the signed-in account; no system can guarantee absolute security. Service providers may process information in countries outside yours.

Health information and children

Pando is a general-wellbeing product intended for adults, not a medical device. It does not diagnose, treat, cure or prevent medical conditions. Consult a qualified healthcare professional about medical decisions. Do not use estimates for medication dosing. This release is not designed for children under 18.

Optional native membership linking

If you link your phone to an existing web membership, we store an association between that installation and your account to check subscription access. Linking codes expire after 10 minutes and can be used once. This does not merge health records, plans or chat history. Unlinking removes the association but does not cancel billing. Deleting the web account removes its device membership links and cancels associated web subscriptions.

Contact and updates

For privacy, access or deletion issues, use the contact details provided in Pando’s store listing. A dedicated public privacy contact is being finalized before Play Store submission.

We update this page when data practices change and show the effective date above. Material new uses of health information require a new disclosure and consent where applicable.

Product analytics

Optional analytics records platform, screen visits, feature actions, a session identifier and traffic source labels. It excludes chat content, food photos, medical notes and wearable readings. Browser tracking asks for permission; native tracking is off until enabled in Privacy & data. Linked memberships can combine usage across your devices. Older opted-in web events are retained with unknown attribution where unavailable. Anonymous browser data uses a random identifier. Signed-in and installation analytics are removed with account or installation deletion. Billing records are separate and retained by Stripe for financial administration.

Privacy policyDelete account & dataTerms & health information