Privacy Policy

Last updated · 2026-05-25

The short version : RUNDR is engineered to know nothing about you. No account, no login, no email, no analytics, no tracking SDK. The only data our server stores is an anonymous device ID and a daily counter — that's literally it. Your runs never leave your phone.

What we collect

RUNDR's backend (a Cloudflare Worker) stores exactly two things, both anonymous and ephemeral :

If you upgrade to Pro, we additionally store an opaque receipt hash to bypass the free tier limit — never your Apple ID, never your name, never your email.

What we do not collect

The route you generate

When you tap GENERATE LOOP, your phone sends 3 pieces of data to our backend :

Our backend forwards those coordinates to OpenRouteService, a Heidelberg University project, which computes the route and sends it back. We cache route results for 7 days in a key-value store to save quota and improve latency — keyed by location bucket and distance, never by user.

The generated route is then sent back to your phone, and from that point on it lives only on your device.

What stays on your phone

Once the route reaches your phone, the following data is stored locally only, in your phone's AsyncStorage, and never uploaded anywhere :

Run tracking is erased the moment you start a new run. We don't keep a history of your runs. We can't show you "your past activity" because we have no idea what your past activity is.

Apple HealthKit (opt-in, Pro feature)

If you enable "Save runs to Apple Health" in Settings (a Pro feature, off by default), RUNDR writes each completed run to Apple Health as a Workout. Specifically :

This is special category data (health) under GDPR Article 9 and requires your explicit consent, given by the iOS Health permission prompt the first time you enable the feature. You can revoke this consent at any time via iOS Settings → Privacy & Security → Health → RUNDR → Turn Off All Categories.

HealthKit data lives on your iPhone (and Apple Watch if mirrored) under Apple's control, never on RUNDR servers.

How long we keep things

Server-side (Cloudflare Worker) :

On your device :

Third-party services we use

We have no partnership, no data sharing, no advertising deal with any other entity.

International transfers

Some of our sub-processors are based outside the EU :

OpenRouteService (Germany) and OpenStreetMap (Switzerland — adequacy decision) are EU-based ; no transfer outside the EU/EEA.

Your rights (GDPR Articles 15–22)

You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw your consent at any time (especially for HealthKit data). Since RUNDR is engineered to know almost nothing about you, most of these rights are exercised locally :

For any request, we respond within 30 days (extendable by 60 days for complex requests, with notice), as required by GDPR Article 12(3).

You also have the right to lodge a complaint with your local supervisory authority — in France, the CNIL.

Children

RUNDR is not directed at children under 16 (GDPR Article 8) and does not knowingly collect any data from them. We don't collect data from anyone, so this should be obvious, but the legal world likes us to say it explicitly.

Changes to this policy

If we ever change this policy, we'll publish the new version with a new "Last updated" date and keep the old versions accessible. We will never change it in a way that broadens what we collect without an explicit, opt-in user prompt in the app.

Contact

Questions or concerns ? Write to support@rundr.me. We read every message.

Editor : Hadrien Hubert · Sole proprietorship DE.H.VS · France