Privacy Policy
Last updated 30 July 2026
This policy explains what Runvel collects, why, and what control you have. It covers the Runvel iOS app and this website. Plain English throughout. Where a term has a specific legal meaning we say so.
In short: Runvel collects diagnostics, and you can switch that off.
When the app crashes or something fails, it sends us a report so we can fix it, along with basic figures on which features get used. This is on by default. It contains no health data, it is never sold, and it is never used to track you across other apps.
To turn it off, open Runvel and go to Settings, Privacy and data, Diagnostics. Everything else in the app carries on working exactly as before. The rest of this page explains each category of data in full.
1. Who we are
Runvel ("Runvel", "we", "us") is the provider of the Runvel running-coach application. For questions about this policy or your data, contact privacy@runvel.app.
We are the data controller for the personal data described below.
2. What we collect
Runvel collects only what the features you turn on actually need. Every category below is declared on our App Store privacy label.
| Category | Examples | How it is authorised |
|---|---|---|
| Precise location | The GPS trace of a run: distance, pace, elevation, route | iOS location permission |
| Health & fitness | Heart rate, heart rate variability, resting heart rate, sleep, workouts, cadence | Apple Health permission, or a connected wearable |
| Imported activities | Past runs imported from Strava or Apple Health | Per integration consent you grant and can revoke |
| Contact info | Your email address, if you create an account | Supplied by you at sign-in |
| Identifiers | An account identifier | Created when you sign in |
| Calendar entries | Workouts and your race date written to a calendar you choose | Per integration consent |
| Diagnostics | Crash reports and basic usage events | On by default under legitimate interest, switchable off in Settings |
Runvel does not collect contacts, photos, browsing history, advertising identifiers, or your precise location outside a run you started.
3. Where your data lives
Runvel is local first. Your runs, plans, workouts, settings and health readings are stored in an encrypted database on your own device. Recording a run, being coached through it and saving it all work with no network connection, and nothing is uploaded in order for the app to function.
If you create an account so your data follows you between devices, that data is synchronised to our backend provider and stored there on our behalf. Sync is optional.
4. Why we process it
- To provide the app. Building your plan, measuring your runs, coaching you through them, and scoring your daily readiness. This is processing necessary to perform our contract with you.
- To honour a connection you asked for. Importing Strava history, reading Whoop recovery, writing sessions to your calendar. Each of these runs on your explicit consent and stops the moment you withdraw it.
- To keep the app working. Crash reports and aggregate usage tell us what is broken. This runs on our legitimate interest in keeping Runvel stable and safe to use, so it is on by default. You can turn it off at any time in Settings, Privacy and data, and everything else in the app carries on working exactly as before.
Where we rely on consent, you can withdraw it at any time in Settings without losing access to the rest of the app. Where we rely on legitimate interest, as we do for diagnostics, you have the right to object, and the switch in Settings is how you exercise it.
5. Connected services
Runvel asks for each connection separately, and each can be revoked separately:
- Apple Health (HealthKit) reads workouts, heart rate, HRV, resting heart rate and sleep; writes the runs you record so they appear in Health.
- Whoop reads your recovery, HRV and sleep via Whoop's API after you authorise Runvel in Whoop's own sign-in screen.
- Strava imports your past activities after you authorise Runvel in Strava's own sign-in screen.
- Calendar writes your planned sessions and race date to a calendar you select.
These providers have their own privacy policies governing what they hold. Revoking access in Runvel stops future reads; deleting data already held by that provider is done with them.
6. Health data, special rules
Health and fitness data receives stricter treatment, both because Apple requires it and because it is the right thing to do:
- It is never sold, and never shared with data brokers.
- It is never used for advertising or for tracking you across other companies' apps or websites. Runvel does not use the App Tracking Transparency framework because it does no such tracking.
- Data read from Apple Health is used only to deliver the features you enabled, and is not shared with third parties except as needed to run the sync you turned on.
- It is not used to make decisions about employment, insurance or credit, and we do not provide it to anyone who does.
7. Who we share with
We do not sell personal data. We share it only with service providers who process it on our instructions and under contract:
- Our cloud hosting and account provider, for optional sync and sign-in.
- Google, as our crash reporting and analytics provider (Firebase Crashlytics and Google Analytics), while diagnostics are switched on.
- Apple, for subscription billing. Apple processes your payment. Runvel never receives or stores your card details.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
8. How long we keep it
Data stored on your device stays until you delete it or remove the app. Synced data is kept while your account exists. When you delete your account, we purge your synced data and revoke the sessions of any device still signed in; local data is removed by deleting the app.
Anonymous, aggregated statistics that cannot identify you may be retained.
9. Your rights and controls
In the app: export everything as CSV or GPX, revoke any integration, turn diagnostics off, and delete your account and its data. Under GDPR, UK GDPR, the CCPA and comparable laws you also have the right to access, correct, delete, restrict or object to our processing of your data, and to data portability. Exercise any of these at privacy@runvel.app; we respond within 30 days.
If you are in the EEA or UK and believe we have handled your data improperly, you may complain to your local supervisory authority.
10. Children
Runvel is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
Data on your device sits in the app's protected container and benefits from iOS device encryption. Data in transit uses TLS. Access tokens for connected services are held in the iOS Keychain. No system is perfectly secure, and we cannot guarantee absolute security.
12. Changes
We will post any change here and update the date at the top. If a change materially affects how we use your data we will tell you in the app before it takes effect.
13. Contact
Privacy questions: privacy@runvel.app
Everything else: support@runvel.app