Security
Last updated: 18 August 2026
Your data, and your members’. What we do to protect it, in plain language. If you need detail beyond this, ask us and you’ll get a real answer.
Data separation
Each gym’s data is walled off from every other gym’s. This is enforced at the database level rather than by application logic — the isolation doesn’t depend on our code being bug-free in every path.
Members see only their own data. Staff see only what their role permits.
Access controls
Role-based access for staff. Owner, coach and staff roles carry different permissions. You control who has which.
Trainer scoping. Where you assign a member to a specific trainer, that relationship governs who can message whom.
Sign-in options. Email, Google or Apple. Members and staff authenticate against your gym specifically.
Payments
We never hold your members’ payment details. Card and bank details go to your payment provider, not to us — we hold references, not credentials.
You connect your own payment account, which means the money moves between your member and your provider. We aren’t in the middle of it, which is a security property as well as a commercial one.
Your members’ health data
Gyms hold sensitive information — health declarations, injuries, body composition. That’s handled as sensitive by default.
PATO won’t give medical advice. Injury, pain and medical questions route to your coaches by design, not by policy. That’s a product boundary, not a disclaimer.
AI and your data
Your gym’s data is used to answer your gym’s questions. Nothing more.
Every AI conversation is logged and reviewable, so there’s a record of what was asked and what was returned.
On nutrition specifically: the AI recognises food, but never produces a nutrition number — values come from a verified catalogue and the arithmetic runs on our servers. That’s an accuracy property, and it also means there’s an auditable source behind every figure.
Where your data lives
Your data is stored in Australia.
That’s deliberate rather than incidental. Hosting in the region keeps your members’ data close to them and out of a US data centre chosen because that’s where the software company happens to be.
Your data is still yours, and it’s still ours to protect. Our hosting provider stores and processes it on our behalf — they don’t use it for their own purposes, and they can’t. Under New Zealand privacy law that means responsibility for your members’ information stays with us. We don’t get to point at a supplier if something goes wrong.
What that means in practice: the obligations we’re held to are the New Zealand ones, regardless of which country the servers sit in.
Privacy
We disclose what we collect by category and why. See our Privacy Policy.
For NZ gyms: the Privacy Act 2020 covers the member information your gym holds. We handle that information on your behalf, and the policy sets out what that means in practice.
If something goes wrong
We’ll tell you. New Zealand privacy law requires notifying the Privacy Commissioner and affected people as soon as practicable after a breach likely to cause serious harm — and the Commissioner’s guidance points at 72 hours from discovery.
Two things worth knowing about how we treat that:
A breach at our hosting provider is our breach. Because they hold data on our behalf, anything they know, we’re treated as knowing. There’s no gap where a problem is technically someone else’s.
You’ll hear from us before you hear from anyone else. If your members are affected, you need to be the one telling them — not finding out alongside them.
If you have a security review, we’ll do it
Larger gyms and franchise groups often have a checklist before they sign anything. Send it through and you’ll get real answers from someone who understands the system rather than a form letter.
Get in touch and we’ll work through it.
Try it for two weeks. Decide after that.
Everything switched on, no card, no contract. If you like it, take 40% off permanently as a founding gym.
14 days · No card · Cancel any time
Pass
