Privacy Policy
Last updated 24 September 2026
This policy explains what Runvel collects, why, and what control you have. It covers the Runvel iPhone and Apple Watch apps and this website.
Some sections apply only when a feature is available and you use it. The community section describes how information will be handled for those features; it does not mean every feature described is available today or that we collect that information before you use it.
We collect and store account information, including your name and email address. When you sign in with Google or Apple, Firebase Authentication stores your email and the name and profile information your provider supplies, when available. Runvel also stores verified email addresses, your chosen contact email and account details in its cloud account records. Apple may provide a private relay address.
Your running history is stored on your devices. Runvel does not provide cloud backup of your training history. Your account, purchases, support conversations and notification settings use online services. Content you choose to share through an available feature or submit to support leaves your device.
Crash reports and app-usage diagnostics are optional. Each has its own choice and stays off until you enable it. Turning them off does not stop the account, security, payment or support processing needed for the features you use. Change these choices under You → Privacy & data.
We do not sell your personal data or use it to track you across other companies' apps or websites for advertising.
1. Who we are
Runvel is operated by Nir Hemo, an individual trading as Runvel ("Runvel", "we", "us"). For questions about this policy or your data, contact privacy@runvel.app.
We are the data controller for the personal data described below.
2. What we collect
Some information stays in your local running history; other information is sent to Runvel and its providers to operate the features you use. Account and billing information is collected independently of your optional diagnostics choices.
When you use Google sign-in, Google may process account details, including a name, email or phone number, account and device identifiers, approximate location and sign-in activity to operate, secure and understand use of its sign-in service. Runvel receives the basic profile information you authorize; it does not request or store your phone number in your Runvel profile. Google may process additional information within its own sign-in service, including your IP address to help prevent fraud. This processing is separate from Runvel's optional app-usage diagnostics. See Google's sign-in disclosure and Google's privacy policy.
| Category | What happens | Your control |
|---|---|---|
| Running profile, health and workouts | Your locally edited runner name, date of birth, running goals, training preferences, runs, routes, precise location, heart rate, sleep, body measurements, running metrics, recovery and plans are processed on your iPhone and, where applicable, paired Apple Watch. Runvel does not automatically upload these records to its account service or diagnostics. Connected services, maps, exports and voluntary support submissions are explained below. | Manage your running profile and local history in the app; control Apple Health, Location, Motion and connected-service access |
| Name, email and sign-in information | Firebase Authentication receives and stores your Google or Apple sign-in identifier, email address and provider profile details, including your name and photo URL when supplied. Runvel stores verified provider emails and your chosen contact email in Cloud Firestore with your account ID and linked sign-in methods. Apple may supply a private relay email. We use this information for sign-in, account management, subscription identification and support. | Manage linked sign-in methods and contact email in Your Account; request account deletion. Diagnostics opt-out does not delete account names or emails. |
| Profile photo | If you choose a Google photo or upload a photo, Runvel stores a resized copy in your cloud account so it can appear in the app, website and private support conversation. Uploaded photo metadata is removed. A sign-in provider's own photo information is separate from the photo you choose for Runvel. | Choose, replace or remove your Runvel photo; this does not change your Google or Apple profile |
| Device and security information | We store account, installation and session identifiers; device type/model; app and operating-system versions; language; time zone; recent activity; and records of account changes. Google and Cloudflare also process network addresses, browser/device information and security-verification data to authenticate requests and prevent abuse. | Review connected devices and sign them out on the website; manage sign-in methods or request account deletion |
| Crash reports | Crash and non-fatal error details, technical performance/context information, app/OS version, device model and installation identifiers. Runvel does not attach your account email, name, workout measurements, route or support messages to these reports. | Optional Crash Reports choice; disabled until you enable it |
| App-usage diagnostics | Categorical events such as onboarding step, run started or completed, subscription outcome and feature use, with an app-instance identifier and technical app/device information. Google may infer approximate location from the network connection. Runvel does not attach your account email, name, running measurements or health details. | Optional App-Usage Diagnostics choice; disabled until you enable it |
| Notifications and app updates | When permitted, we register a push token for your installation. We also store support/update alert preferences, quiet hours, language, app version/build, operating-system version, device family and App Store country or region to deliver relevant updates. Delivery records help prevent duplicate alerts. These records are separate from optional diagnostics. | Control Support & feedback updates and App updates in Notifications. iOS controls notification permission. Release notes and support replies remain available when alerts are off. |
| Purchases and subscriptions | App Store or website purchase records, transaction/subscription identifiers, trial eligibility, checkout state and access status, including renewals and refunds, are linked to your Runvel account. RevenueCat receives an account identifier and a verified email used to identify your subscription. Paddle receives the billing details you enter at website checkout. Runvel does not receive full payment-card details or send these providers your training history. | Manage or cancel billing with Apple or Paddle, where you bought the subscription. Account deletion does not cancel billing. |
Account information is different from diagnostics. Your account email and provider profile are collected for the account features described above, even if both diagnostics choices are off. Runvel does not send those contact details as Analytics or Crashlytics user properties, and does not use diagnostics to build an advertising profile.
The signed-in website uses your Runvel account to manage your profile, devices, account export and website subscription. It stores sign-in information in your browser to keep you signed in and recognise that browser as a connected device. Firebase App Check uses Apple's app-verification service in the iPhone app and Google's reCAPTCHA Enterprise on the account website to help prevent automated abuse. These security checks are separate from optional diagnostics. Google's Privacy Policy and Terms of Service apply to reCAPTCHA. Signing out removes account access; remote sign-out takes effect when a device reconnects. It does not erase locally saved runs. The optional Android waitlist is separate.
Website checkout opens at payment.runvel.app. Temporary browser-session information securely connects checkout to your signed-in Runvel account and lets you return to a pending payment. Paddle processes the payment details you enter there under its Privacy Policy.
Google or Apple sign-in may also provide your name and profile-photo information to our sign-in service. These details help identify your sign-in account. They are separate from the running-profile name you edit in the app.
Signing in does not publish your name, email, photo or training history to other runners. Account information and support conversations are private. A community profile and the information you choose to share through it are covered separately below.
Website analytics: we use Cloudflare Web Analytics to understand visits and page performance, including pages viewed, referring sites, country, browser and device type, and loading speed. This measurement does not use analytics cookies or fingerprint individual visitors. It is separate from the app's optional diagnostics and is not joined to your Runvel account or training records. See Cloudflare's Web Analytics information.
Support and feedback: when you submit a bug report, feature suggestion or support request, we store the information you enter, messages exchanged with Runvel Support, any screenshot you attach and technical details you choose to include. Requests are linked to your account and are private conversations with Runvel Support, not public posts. Our support team and the providers used to deliver and store the request process this information to respond and investigate issues. A screenshot or message may contain health, workout or other personal information you choose to share. Do not include passwords or unnecessary personal information. Ratings you give a completed run remain part of your local training data.
Community profiles and sharing, when available
When you create a community profile or use a social feature, we collect the information you provide and the interactions needed to operate that feature. This may include your chosen display name, username, profile photo and biography; posts, comments, photos and other uploads; reactions, follows and group membership; and messages and their recipients where messaging is offered. We also keep associated information such as the account that created content, its time, audience and moderation status. We use this information to display your profile, deliver your content and messages, show relevant community activity, notify you according to your settings and protect the community from misuse.
The feature shows which profile fields and content other people can see before you share. Your sign-in email, billing information and private support requests are not part of your public profile. Public content can be viewed and copied by others; content shared with a group or selected recipients is delivered to that audience. The name supplied by your sign-in provider is not automatically published just because you sign in.
If you choose to share an activity, the selected details may include distance, time, pace, workout measurements or a route map. Only the information selected for that sharing action is submitted for community display. Creating a community profile does not automatically upload or publish your private running history. Consider whether a map or photo reveals your home, routine or other sensitive information before sharing it.
We and providers operating these features process the submitted content to store and deliver it. Authorised moderators may review content and messages reported to us, together with relevant account and interaction information, to investigate abuse, enforce the community rules and handle legal requests. Reporting someone does not turn your report into a public post.
Community profile information is kept while the profile exists. Shared content is kept while you make it available, subject to deletion controls and service rules. Removing content does not recall copies already saved or shared by recipients. Limited copies may remain during backup removal or when necessary to investigate a report, prevent abuse or meet a legal obligation; they are not kept for those purposes longer than needed. Before introducing materially different data uses, audiences or retention, we will explain the change and obtain consent where required.
3. The Android waitlist
Runvel is available on the Apple App Store. If you select Android on runvel.app, you can optionally leave an email address to be told when Runvel launches on Android. The iPhone and Apple Watch download does not require an email address, and nothing else on the site or in the app depends on joining this list.
| What we store | Why |
|---|---|
| Your email address | So we can send you the one Android launch email you asked for |
| That you used the Android waitlist, and the date | To operate the list and know when you joined it |
| A one-way hash of your network address | To limit automated sign-ups. The waitlist database stores a salted hash rather than the raw address. Cloudflare separately processes network information to host and protect the website. |
The waitlist form does not set a cookie or attach your browsing history to your sign-up. The list sits in our own database on Cloudflare, who host the site for us.
Legal basis: your consent, given by submitting the form. Retention: we delete the Android list once its launch email has gone out, and in any case within 24 months. Withdrawing: every email we send carries an unsubscribe link, and you can ask us to remove you at any moment at privacy@runvel.app, with no reason needed.
We will not sell this list, rent it, or pass it to anyone else for their own purposes.
4. Where your data lives
Your training history, running profile and plans are stored in the app's protected container on your device, using the file protections provided by iOS. Recording a run, being coached through it and saving it all work with no network connection. Account, subscription, notification and voluntarily submitted feedback information travels to the service providers described in this policy. Content submitted through community features, when available, is also stored online for the sharing purpose you choose. Your private training history is not backed up or synchronized through the account service.
Runvel can create account and device identifiers before you connect a sign-in method, to keep track of account and subscription access. Firebase Authentication stores sign-in information; Cloud Firestore stores Runvel's account, device, purchase-access and support records, including the account emails described above. Google Cloud Storage stores private support attachments. A paired Apple Watch and iPhone exchange plans, settings and recorded runs so a Watch run can appear on the phone. The optional Android waitlist remains separate from your Runvel account.
Apple Health and device backups that you enable are governed by Apple's settings and policies. Runvel's lack of a training-history cloud backup does not mean that Apple Health, your own device backups or an export you share cannot hold a separate copy.
If you connect Polar, Runvel's website briefly processes the authorisation information needed to connect your account securely. It does not retain that connection information on the server. The app stores the connection securely on your device and downloads exercise and recovery data directly from Polar to your device.
Our service providers may process information in countries outside the country where you live. For example, Google's sign-in service processes account information in the United States. Selecting a location for Runvel's account storage does not mean every connected provider processes data only in that location. Contact privacy@runvel.app for information about the handling of your data.
5. Why we process it
- To provide the app. Building your plan, measuring your runs, coaching you through them, and scoring your daily readiness. This is processing necessary to perform our contract with you.
- To provide paid access. Verifying subscription status, restoring purchases and migrating existing Apple subscriptions so paid features remain available.
- To manage your account and provide support. Keeping your sign-in methods, profile and connected devices available; responding to requests; investigating reported problems; and sending updates according to your notification choices.
- To operate community features you use, when available. Hosting the profile and content you submit, delivering messages and interactions to their intended audience, and handling reports and moderation as described above.
- To protect the service. Preventing unauthorised access, automated abuse and misuse of account or payment services.
- To honour a connection you asked for. Importing your Apple Health, WHOOP or Polar runs and reading WHOOP or Polar recovery. Each connection runs on your explicit consent and stops reading new data when you withdraw it.
- To improve stability, if you consent. The optional Crash Reports choice sends technical failures so we can diagnose them. The optional App-Usage Diagnostics choice sends a small set of categorical feature events so we can see where the app succeeds or fails. Neither choice is required to use Runvel.
Diagnostics are processed only with your affirmative consent. You can withdraw either choice independently at any time in Settings without losing access to the rest of the app. Collection for that category stops immediately. Data already received is handled under the retention rules below.
6. Connected services
Runvel asks for each connection separately, and each can be revoked separately:
- Apple Health (HealthKit) can read workouts, heart rate, HRV, resting heart rate, sleep, body weight, routes, distance, calories, steps, running speed/power, running form metrics and workout effort where supported; it can write your recorded workouts, routes and associated measurements back to Health. Your weight is used for one thing only: working out the calories a run burned. If Health holds no weight, the finish screen says the figure came from a reference weight instead.
- WHOOP reads completed running-workout summaries, including start and end time, sport type, distance and elevation where available, plus your recovery, HRV and sleep, after you authorise Runvel in WHOOP's own sign-in screen. It also requests body-measurement information to read maximum heart rate for your zones; that response may include height and weight. WHOOP does not provide Runvel a GPS route or second-by-second heart-rate stream through this workout endpoint.
- Polar AccessLink reads running exercises, including distance, duration, route, elevation, heart rate and cadence where available. It also reads Nightly Recharge and sleep data used for readiness: RMSSD heart-rate variability, the overnight heart-rate average, sleep duration, and Polar's six-level Nightly Recharge status. This happens only after you authorise Runvel on Polar's own page. The connection is read-only. Runvel does not request Polar's daily activity or physical-information categories.
For WHOOP connections in updated app versions, Runvel's authenticated Google Cloud service exchanges authorisation codes and renews access tokens. User tokens remain in your iPhone Keychain. To recover an interrupted exchange, an encrypted token response is available only to the same Runvel account and device for up to ten minutes. Expired responses are removed by scheduled cleanup; physical deletion can take longer. This service does not receive your WHOOP workout, sleep or recovery records.
Maps: Runvel uses Apple Maps to display live and completed routes and create map images for sharing. Loading a map requests map content from Apple for the area shown. Your recorded route and zone colours are drawn by Runvel; this does not create a training backup in your Runvel account. Apple's handling of map-service information is described in Apple Maps & Privacy.
Exports and sharing: when you export a run or share a run card, the file or image can contain your route, workout details and any photo you choose to include. The app, person or service you select receives that content and handles it under its own terms.
These providers have their own privacy policies governing what they hold. Revoking access in Runvel stops future reads and removes that provider's link. Runs already imported into your local Runvel history remain there until you explicitly delete them in Runvel; deleting data held by the provider is done with that provider.
7. Health data, special rules
Health and fitness data receives stricter treatment, both because Apple requires it and because it is the right thing to do:
- It is never sold, and never shared with data brokers.
- It is never used for advertising or for tracking you across other companies' apps or websites. Runvel does not use the App Tracking Transparency framework because it does no such tracking.
- Data read from Apple Health is used to deliver the features you enable on your device and is not automatically uploaded to Runvel. If you choose to include health information in a support message or screenshot, that submitted content is handled as described in section 2.
- It is not used to make decisions about employment, insurance or credit, and we do not provide it to anyone who does.
8. Who we share with
We do not sell personal data. The following providers help operate Runvel. Payment and sign-in providers also process information under their own policies and legal obligations:
- Google, as our crash-reporting provider (Firebase Crashlytics), only while Crash Reports is enabled, and as our app-usage provider (Google Analytics for Firebase), only while App-Usage Diagnostics is enabled.
- Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service), for delivering notifications. Runvel registers the device for remote notifications after iOS permission is granted. Individual alert preferences control which alerts we send; they do not necessarily remove the push token.
- Google, through Firebase Authentication, Cloud Firestore, Google Cloud Storage and account-security services, for the account emails, provider profile, account/device records, private support content and temporary encrypted WHOOP token responses described above. These account services operate independently of optional diagnostics. See Firebase's privacy information.
- Apple, for Sign in with Apple, App Store billing, app verification, notifications, HealthKit and map services. Apple may provide a relay email instead of your personal email. Payment providers process card details; Runvel does not store them.
- RevenueCat, for managing paid access. RevenueCat receives purchase and subscription records linked to your Runvel account and a verified email used to identify your subscription. Its services also process technical connection and purchase information. This lets Runvel verify and restore purchases, combine your accounts and provide billing support. We do not send RevenueCat health, workout, route or training-plan records.
- Paddle, as the merchant of record for website purchases. Paddle processes the billing details you enter, payment information, tax information and subscription transactions, and shares purchase, renewal, cancellation and refund records with Runvel and RevenueCat. Runvel links the payment to the signed-in Runvel account. We do not receive full payment-card details or send Paddle training or health records. See Paddle's privacy policy.
- Cloudflare, who host and protect runvel.app, provide the website analytics described above, proxy account and support requests, store the Android launch waitlist, and process the one-time Polar authorisation-code exchange. Polar codes and tokens are not stored by Runvel on Cloudflare. Cloudflare also processes network and security information to operate its services, as explained in Cloudflare's privacy policy.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
9. How long we keep it
Training data stored locally stays until you delete it in Runvel or remove the app. Paired Watch and iPhone copies are subject to deletion on their respective devices. Runvel holds no cloud backup of your private training history. Content you separately choose to submit or share is retained under the applicable support or community rules in this policy.
Your Runvel account information, including stored emails, chosen photo and device records, is retained while your account exists. A deletion request disables cloud-account activity and starts a seven-day cancellation period. After that period, deletion processing removes account records and requests deletion of the associated Firebase Authentication user. Provider processing, retries and backup removal can take longer than seven days. A minimal deletion receipt is retained for 30 days after completion. Deletion processing also removes associated account-change references and notification delivery records for the account's registered devices. Outside account deletion, release-notification jobs are scheduled for removal after 30 days and delivery receipts after 90 days; scheduled storage removal may take additional time. Support content and billing-provider records are covered separately below. When you combine your accounts, we retain a limited record while the account exists so connected devices can complete the change safely. Temporary copies of photos, email addresses and information used to check that change are removed once it finishes.
Feedback and screenshots submitted before deletion are retained for investigating issues and improving Runvel, with their connection to the deleted account removed. Removing the reporter connection does not remove personal information you may have written or shown in an attachment. You can contact us about information within a retained report.
Deletion does not erase local runs or plans. Returning with the same Google or Apple sign-in after deletion creates a new account; old local data is not silently assigned to it. Billing records needed for an ongoing website subscription remain until that subscription ends, after which deletion processing resumes.
Firebase Crashlytics retains crash reports and associated identifiers for 90 days before starting their removal from live and backup systems.
Our Google Analytics for Firebase retention settings are two months for event data and 14 months for user-level data and key events. New activity does not restart the retention period for a user identifier. Data that reaches its retention limit is removed through Google's scheduled deletion process. Standard aggregated reports may remain.
Firebase Authentication retains sign-in information until deletion is requested for the Firebase user. Google says removal from its live and backup systems then takes up to 180 days; authentication IP logs are retained for a few weeks. See Firebase's retention information.
Turning off an alert category stops that category's notifications; it does not delete your account or all notification identifiers. When Runvel detects that iOS notification permission is off, it requests removal of its push token and updates the server registration when it can connect. This does not automatically delete the separate Firebase installation identifier. Google retains that identifier until deletion is requested, after which removal from live and backup systems takes up to 180 days. Limited delivery records may remain to prevent duplicate messages and troubleshoot delivery.
Apple, Paddle and RevenueCat retain purchase and subscription records as needed to operate billing, prevent fraud, meet legal obligations and support restoration. Deleting local Runvel data or the app does not cancel a subscription and does not automatically erase those processor records. Manage or cancel App Store purchases through Apple and website purchases through Paddle; contact privacy@runvel.app for a RevenueCat data-deletion request.
Connected-service credentials are kept in the device Keychain. Disconnecting removes the local connection; where supported, Runvel also asks the provider to revoke access. You can manage access directly with the provider. Previously imported runs remain until you delete them.
An Android waitlist address is deleted once the Android launch email has been sent, and within 24 months at the latest, or sooner if you ask.
Anonymous, aggregated statistics that cannot identify you may be retained.
10. Your rights and controls
The signed-in website offers an account-information download, including your feedback and its screenshots. Export your running and training data separately from the app; it is not included in the website's account download. You can manage signed-in devices on the website and request account deletion in the app or website.
In the app, you can export runs as CSV or GPX, revoke any integration, control Crash Reports and App-Usage Diagnostics independently, and delete local data. Local deletion does not cancel a subscription; use Apple's settings for App Store purchases or Paddle's customer portal for website purchases. Under GDPR, UK GDPR, the CCPA and comparable laws, where applicable, you may also have rights to access, correct, delete, restrict or object to processing, and to data portability. Contact us to exercise your applicable rights at privacy@runvel.app; we respond within 30 days.
If you are in the EEA or UK and believe we have handled your data improperly, you may complain to your local supervisory authority.
11. Children
Runvel is for people aged 16 or older. The app's onboarding flow asks users to confirm this before continuing. Runvel is not designed or marketed for children under 16.
If you believe someone under 16 has sent personal data to Runvel or its service providers, contact us at privacy@runvel.app so we can investigate and delete it where applicable.
12. Security
Runvel uses the protections provided by iOS for data stored on your device, encrypted connections when information is sent to our services, and access controls for account and support information. Connected-service credentials are kept in Apple's secure storage on your device; WHOOP exchanges also use the temporary encrypted server storage described above. Protect your device with a passcode and keep your sign-in methods secure. No system is perfectly secure, and we cannot guarantee absolute security.
13. Changes
We will post any change here and update the date at the top. If a change materially affects how we use your data we will tell you in the app before it takes effect and obtain consent where required. A routine feature improvement that uses the same information for the same disclosed purposes does not by itself change this policy. Describing an optional feature here does not authorise an unrelated use of information collected for another purpose.
14. Contact
Privacy questions: privacy@runvel.app
Everything else: support@runvel.app