Privacy Policy
Effective Date: 5 September 2025
Contact: info@runathonai.com
Controller: Kursat Keskin
Who We Are
Runathon ("we", "us", "our") provides a running app that tracks runs and, for premium users, generates training plans and post-run reports using AI.
Controller: Kursat Keskin
Contact: info@runathonai.com
Data We Collect
- Account & profile: email, (optional) name, age, gender, height, weight.
- Run data: GPS location/route, distance, pace, duration, timestamps, device motion/steps.
- Health/fitness (optional): heart rate (BPM) and zones from connected watch/health sources.
- Usage & device: in-app actions, device/OS, app version, approximate region, purchase status.
- AI inputs (premium): summary stats from your runs and any notes you provide.
How We Use Your Data
- Provide and improve core features (run tracking, stats, records).
- Generate training plans and post-run analyses for premium users.
- Process purchases, manage entitlements, detect fraud, and restore purchases.
- Support, diagnostics, and security.
- With consent: use heart-rate/health data for insights and plan adjustments.
Legal Bases (UK GDPR)
- Performance of a contract (providing the app and subscriptions).
- Legitimate interests (security, analytics, improvements).
- Consent (health integrations, notifications, background location).
- Legal obligations (tax/financial records).
Sharing with Service Providers
- RevenueCat (IAP/entitlements): product IDs, receipts, an app user ID.
- Supabase (auth/database hosting).
- OpenAI API (premium only): We send aggregated run statistics (e.g., distance, pace, duration) and any optional notes you provide to generate personalized training plans and post-run reports. OpenAI processes this data according to their API terms. Data sent via the API is not used by OpenAI to train their models. For details, see OpenAI's API data usage policies.
- Optional integrations you connect (e.g., Apple Health/Google Fit or your watch vendor). Only the categories you approve; not used for ads.
- Crash/diagnostics and basic analytics (OS, version, error traces).
We do not sell personal data.
Cookies and Tracking Technologies
Our app may use analytics and crash reporting tools that collect device information, app version, and usage patterns to help us improve the Service. We do not use traditional browser cookies, but mobile analytics SDKs may use persistent identifiers.
Health/Fitness Data
- Accessed only with your explicit consent.
- Used only to display insights and improve training plans.
- Not used for marketing; shared only with processors acting on our instructions.
International Transfers
Vendors may process data in the UK, EEA, or US. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
Retention
We retain account data while your account is active. If you delete your account, we delete or anonymize personal data within 30 days, except where we must keep records for legal/financial reasons.
Automated Decision-Making and Profiling
We use AI (powered by OpenAI) to generate personalized training plans and post-run analyses based on your running data and preferences. These AI-generated recommendations are provided as suggestions to support your training goals—you are not subject to decisions based solely on automated processing that produce legal or similarly significant effects. You maintain full control over whether to follow, modify, or ignore AI recommendations.
Your Rights
- Access, correct, delete, and export your data (provided in JSON format).
- Object to or restrict certain processing.
- Withdraw consent at any time (disconnect Health/HR; disable background location).
- Lodge a complaint with a supervisory authority (e.g., the UK Information Commissioner's Office or your local data protection authority).
To exercise your rights, email info@runathonai.com.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: You can request details about the categories and specific pieces of personal information we collect, use, and disclose.
- Right to delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to opt-out: We do not sell personal information. If our practices change, we will provide a "Do Not Sell My Personal Information" option.
- Non-discrimination: You have the right to not receive discriminatory treatment for exercising your CCPA rights.
Categories of Personal Information We Collect:
- Identifiers (email, app user ID, device identifiers)
- Commercial information (purchase history, subscription status)
- Internet/network activity (app usage, device info)
- Geolocation data (GPS routes and locations)
- Health/biometric information (optional: heart rate, fitness metrics)
- Inferences (training recommendations, performance insights)
Sources: Directly from you, from your device, and from connected health/fitness services you authorize.
Business purposes: Providing the app, processing subscriptions, analytics, security, and generating AI training plans.
Third parties we share with: Service providers (RevenueCat, Supabase, OpenAI), analytics providers, and crash reporting services. We do not sell your data.
To exercise your California privacy rights, email info@runathonai.com.
Children
Runathon is intended for users 18+.
Security
We use industry-standard safeguards (encryption in transit, access controls). No method is 100% secure.
Data breach notification: In the event of a data breach that affects your personal information, we will notify you via email and/or in-app notification without undue delay, and inform relevant supervisory authorities as required by law.
Changes
We'll update this policy as the app evolves. Material changes will be announced in-app or by email before they take effect.
Contact
Questions? Email info@runathonai.com.
