RunZone
Legal

Privacy policy.

Last updated July 15, 2026

This privacy policy explains how RunZone handles information in the RunZone iPhone, iPad, and Apple Watch apps and on the RunZone website. It describes stable categories of data and processing boundaries so it remains accurate as features evolve. The short version: your health and workout data stays within your devices, Apple services you enable, and information you explicitly choose to share. RunZone does not operate a cloud database for your personal training data.

Controller and contact

RunZone is provided by ARC Tech GmbH, c/o Reto Haeberli, Allenmoosstrasse 56, 8057 Zurich, Switzerland. Privacy questions and data-protection requests can be sent to info@runzone.app.

HealthKit and app data

Depending on the functionality you use and the permissions you grant, RunZone may read, create, and process health and fitness data available through Apple HealthKit. This can include the following durable categories:

  • workout and activity records, samples, routes, and related metadata;
  • physiological measurements and wellness, recovery, or effort information;
  • sleep and rest information;
  • body measurements and characteristics;
  • mobility and running dynamics;
  • location, elevation, and environmental context;
  • settings, preferences, goals, and information you enter; and
  • scores, trends, recommendations, and other values derived from these inputs.

RunZone uses this information to record and save workouts, present history and trends, calculate fitness and training insights, personalize enabled functionality, keep your devices consistent, and troubleshoot the app. RunZone requests HealthKit access contextually, and you decide which data types the app may read or write. Fitness insights are informational and do not make decisions with legal or similarly significant effects.

Where personal training data stays

Health, fitness, workout-performance, and route data is processed in Apple HealthKit, protected RunZone app storage on your devices, your iCloud account when you enable Apple synchronization, and paired devices. RunZone does not send this data to RunZone-controlled servers, analytics providers, advertising services, or data brokers.

Data may be processed by Apple services you enable, such as HealthKit, iCloud, StoreKit, WeatherKit, and WatchConnectivity. Information may also leave your devices when you explicitly export or share it. Production and external TestFlight diagnostic exports are designed to remove exact health, workout-performance, route, and location values before sharing.

Analytics

RunZone uses TelemetryDeck for optional, privacy-preserving product analytics. Analytics categories include product interactions and workflow completion, subscription and purchase-flow outcomes, bounded crash and performance diagnostics, and operational outcomes such as whether an Apple service request succeeded. Signals can also include standard technical metadata such as device category, platform and operating-system version, app version and build, RunZone build channel, and an hour-rounded event time.

RunZone creates a random app-family analytics identifier. The identifier is stored in app settings, mirrored between your iPhone and iPad through iCloud Key-Value Storage, and synced to a paired Apple Watch. TelemetryDeck salts and hashes the identifier before analytics storage so it cannot be traced back to your Apple ID, advertising ID, name, email address, HealthKit identifiers, or route identifiers. You can reset the identifier in RunZone settings.

Analytics never include exact health or body measurements, workout values, performance history, routes, precise location, HealthKit identifiers, user-entered goals, or exact workout timestamps. Analytics do not start until the first-run disclosure has been acknowledged. You can turn them off at any time in RunZone settings. Product analytics are retained for no longer than 13 months.

Device sync

RunZone uses Apple services to keep your own devices consistent. App settings, preferences, entitlements, and derived configuration can sync between iPhone and Apple Watch through WatchConnectivity and across iPhone and iPad through iCloud Key-Value Storage. Effective heart-rate values are encrypted before they are written to iCloud Key-Value Storage.

Historical health and workout data sync through Apple HealthKit and iCloud only when you enable the relevant Apple synchronization. RunZone does not run a separate workout cloud-sync service. Apple's handling of information is described in the Apple Privacy Policy.

Weather and location

When location-dependent functionality is used, RunZone may process current location, route, elevation, and related context on your devices. Current location may be sent to Apple WeatherKit to obtain weather information. Weather context may be stored with a HealthKit workout. RunZone does not send workout routes, precise location, or live location trails to its own servers or analytics providers. You control location access in Apple system settings.

Subscriptions

Purchases and subscriptions are handled by Apple through StoreKit. RunZone receives product and entitlement status needed to present and unlock the correct access. An anonymous analytics signal may record that a purchase or subscription workflow completed, but it does not include your Apple ID, payment details, or full App Store billing history. Billing, renewal, cancellation, and refunds are managed by Apple.

Diagnostics and support

RunZone writes protected local diagnostic logs to troubleshoot crashes, hangs, performance, connectivity, Apple-service interactions, and failed operations. Logs can include app lifecycle and operational events, device and system configuration, app version and build, error information, and bounded state or count information. Production and external TestFlight logs are sanitized and do not contain exact health measurements, workout values, routes, precise location, or HealthKit identifiers.

Local logs stay on your devices unless you choose to share an export with support. RunZone keeps rolling local logs and is designed to prune logs older than 30 days. Shared support material is retained only while needed to investigate the request, communicate with you, maintain necessary business records, or meet legal obligations.

Website and communications

The RunZone website does not use advertising cookies, cross-site tracking, website analytics, user accounts, a waitlist, or a contact form. It is delivered through Cloudflare, which may process technical network-request information such as IP address, browser or device information, requested URL, and request time to deliver and protect the site.

If you contact RunZone by email, we process your contact details, message, and related correspondence to respond, provide support, and maintain necessary business records. Do not include health or workout data unless it is necessary for your request and you intend to share it.

Service providers and international processing

Information is disclosed only as described in this policy: to Apple for Apple services you choose to use, to TelemetryDeck for anonymized analytics, to Cloudflare for website delivery and security, to communication providers when you contact us, or where disclosure is legally required. TelemetryDeck states that its analytics infrastructure is hosted in the European Union. Apple, Cloudflare, and communication providers may process information in Switzerland, the European Economic Area, the United States, or other places where they operate, subject to their privacy terms and applicable transfer safeguards.

Legal bases

Where the GDPR or similar laws require a legal basis, RunZone relies on the following bases for the purposes described in this policy:

  • App functionality and device sync: performing our agreement with you and providing the functionality you request, including recording workouts, calculating insights, and keeping your devices consistent.
  • Health and fitness data: providing the functionality you request and, where the GDPR applies, your explicit consent to process special-category health data. HealthKit authorization controls which specific data types RunZone can read or write.
  • Location, weather, and mapping: providing the location-dependent functionality you request through the Apple services involved in that functionality.
  • Subscriptions: performing our agreement with you and managing access to purchased functionality through Apple.
  • Privacy-preserving analytics: where personal data is involved before anonymization, our legitimate interests in understanding how RunZone is used, improving reliability, and fixing problems. Analytics is optional and can be turned off at any time.
  • Support, website delivery and security: performing our agreement when you request support and our legitimate interests in answering questions, operating and protecting RunZone, and maintaining necessary business records.
  • Legal compliance: complying with legal obligations that apply to RunZone.

Apple permission prompts control access to device data and services; they are separate from the legal bases described above. When RunZone relies on legitimate interests, we consider the limited information involved, the safeguards described in this policy, and your rights. We do not rely on those interests where your interests or fundamental rights override them. You may revoke Apple permissions, withdraw consent, or disable optional analytics at any time. This does not affect processing that was lawful before the change.

Retention and deletion

HealthKit data is retained according to your Apple Health, iCloud, and device settings. Protected local caches and app data are kept while needed to operate RunZone and are removed when the app or relevant data is deleted, subject to platform behavior. Deleting RunZone does not automatically delete records already stored in Apple Health or iCloud. Analytics and diagnostic retention are described above. Apple retains subscription and transaction records under its policies.

Your choices and rights

  • You can grant, deny, or revoke HealthKit and location permissions in Apple system settings.
  • You can disable analytics and reset the analytics identifier in RunZone settings.
  • You can delete RunZone-saved workouts from supported RunZone views or Apple Health.
  • You can delete the app to remove its local app data, subject to Apple Health and iCloud behavior.
  • You can manage subscriptions in Settings > Apple ID > Subscriptions.
  • You can request access, correction, deletion, restriction, objection, or portability where applicable.

To exercise a right concerning information controlled by RunZone, contact us using the details below. You may also complain to the Swiss Federal Data Protection and Information Commissioner or another competent supervisory authority. Apple controls data held in Apple services, so some requests must be managed through Apple settings or directed to Apple.

Children

RunZone is not directed to children under 13. If you believe a child has sent us personal information through support, contact us and we will delete it where required.

Changes

We update this policy when our data categories, purposes, recipients, storage or synchronization boundaries, retention, tracking practices, account model, RunZone-controlled infrastructure, or legal obligations materially change. Ordinary feature changes that remain within the categories and boundaries described here may not require a policy update. The current effective date appears at the top of this page.

Contact

Questions about this policy? Email info@runzone.app.