Privacy policy
This says what Runflect collects, why, who ever sees it, and how to get rid of it. It is longer than a summary because a summary is not a legal notice — but nothing in it is hidden, and there is no clause that takes back something said earlier.
1. Who we are
Runflect is a trading name of Chris Pickersgill, a sole trader based in England. For the purposes of the UK GDPR, Chris Pickersgill is the data controller for the personal data described here.
Address for service: [postal address — to be confirmed]
ICO registration number: [ICO number — to be confirmed]
Data rights and anything in this policy: privacy@runflect.com
General support: support@runflect.com
We have not appointed a Data Protection Officer, as we are not required to.
2. What we collect
2.1 Your account
Collected from you when you sign up.
| Data | Why we have it |
|---|---|
| Name | To address you in the app |
| Email address | To identify your account and sign you in |
| Password | Stored only as a salted hash. We never see it and cannot recover it |
| Units preference | To render your training the way you read it |
| Account role | Athlete, coach or both — decides which screens you get |
| Age confirmation | That you confirmed you are 18 or over, and the date you did. We ask for your date of birth to check it, and then discard it — we do not store your date of birth, because nothing in Runflect needs it once the check has passed |
2.2 Your sign-in sessions
Created automatically when you sign in: a session token stored in a cookie on your device, your IP address and your browser’s user-agent string. The token keeps you signed in; the other two let you and us spot a sign-in that wasn’t you. The session cookie is strictly necessary and there are no others — no advertising cookie, no analytics cookie, nothing to consent to. Sessions expire after 30 days, and signing out deletes the record.
2.3 Data from Strava
Collected from Strava, with your permission, after you authorise us on Strava’s own screen. We request two permissions — read for your basic profile and activity:read_all for your activities, including those you marked private. We request no write permission of any kind, so we are technically incapable of changing anything in your Strava account.
What we receive and hold: your Strava athlete ID and name; and for each activity its name, sport type, start date and time, distance, moving and elapsed time, elevation gain, average and maximum speed, average and maximum heart rate, average cadence, Strava’s Relative Effort score, achievement and kudos counts, your own perceived-exertion figure if you logged one, your private note on the activity, and the encoded map line of the route. For an activity you open, we additionally hold its splits, laps, best efforts and heart-rate zone breakdown.
Your OAuth tokens are encrypted at rest and are never sent to your browser. Every call to Strava happens on our servers.
Heart rate, heart-rate zones and route maps are health and location data. Section 4 explains what that means for the legal basis we rely on.
2.4 Files you import
If you drop a .FIT, .TCX, .GPX or .CSVfile into Runflect — or a whole account export archive — we read the sessions out of it. This is the route that does not need anybody else’s permission, and it is how you get your history in without Strava.
A file of this kind is higher resolution than anything Strava sends us, and we hold what it contains: the per-second record of the session, which typically means heart rate, position, altitude, speed and cadence sampled every second, plus laps and the device that recorded it. We also compute per-kilometre and per-mile splits from it, because no file format carries them and the diary draws both.
The uploaded file itself is stored only while it is being processed, and its bytes are released as soon as the sessions have been read out. We keep a one-way fingerprint of the file afterwards, so that dropping the same file twice is recognised rather than duplicated.
2.5 What you write and record yourself
This is yours, not any device maker’s, and we treat it differently throughout: your session and day notes, how a session felt, effort scores you logged, and sessions you planned — a title, a target distance and a note.
You can also record a voice note against a day, up to three minutes long. We store the recording exactly as you made it, and we treat it the same way we treat anything else you write — it may say something about your health, so it sits under the same consent as the rest of your diary. Recording is always something you start; your microphone is never opened otherwise, and your browser will ask you before it is opened at all.
2.6 Coaching
If you invite a coach we store the link itself: the email address you invited, when you invited them, when they accepted, when you last confirmed it, and when it ended if it has. We also store what a coach writes for you — their notes on your sessions and the sessions they plan.
2.7 Messages
Runflect has a messaging screen between an athlete and their coach. We store the messages, who sent them, when, and whether they have been read. They are visible to the two of you and to nobody else.
We email you each time a message arrives. You can turn that off in your settings. It governs message email only: emails about the account itself, such as a coaching invitation or a confirmation that something was deleted, are the record of something happening to your account and always send.
2.8 When you contact us
If you use the contact form or email us we receive your name, your email address, the subject you picked and whatever you write. We use it to answer you and for nothing else. Threads are kept for two years and then deleted. We do not add you to a mailing list, and we have no mailing list to add you to.
2.9 Payment
Runflect does not charge anyone today. If and when paid coach plans open, payment will be handled by Stripe, card numbers will be entered on Stripe’s systems and never touch ours, and this policy will be updated before that happens rather than after.
2.10 What we do not collect
No advertising or analytics cookies and no third-party trackers. No location beyond the route lines attached to sessions you chose to record. No contacts, no device identifiers, no cross-site tracking. And no data about you from data brokers, marketing lists or any other outside source.
We do not transcribe your voice notes, and nothing listens to them. No speech recognition of any kind runs on them, here or anywhere else — they are not sent to a transcription service, and we do not use them to identify you or to work anything out about you. A voice note exists to be played back: by you, and by a coach you invited.
3. What we use it for
| Purpose | What it covers |
|---|---|
| Running your diary | Rendering your runs, weeks, trends and write-ups |
| Analysing your training | Training load, strain, session type, rep detection, intensity labels and threshold estimates — for you, about you, shown only to you |
| Coaching | Showing a coach you approved what you approved them to see |
| Messaging | Delivering messages between you and your coach, and telling you one arrived |
| Keeping your account secure | Sign-in, sessions, rate limiting, spotting abuse |
| Support | Answering you when you write in |
We do notuse your data to train, fine-tune, ground, evaluate or operate any AI or machine-learning system, and we do not feed it into one. Strava’s API Policy forbids this for Strava-sourced data, and we apply the same rule to everything else because it is the right rule.
We do not profile you, and no decision with a legal or similarly significant effect on you is made automatically.
4. Health data, and our legal bases
Heart rate, heart-rate zones, perceived exertion and how a session felt are data concerning health under UK GDPR Article 9. Route lines are location data. Both need more than an ordinary legal basis.
| Data | Lawful basis (Art. 6) | Condition (Art. 9) |
|---|---|---|
| Account and sign-in data | Contract — we cannot provide the service without it | Not applicable |
| Security and rate-limiting records | Legitimate interests — keeping accounts safe from unauthorised access | Not applicable |
| Strava activity data, including heart rate and routes | Contract | Explicit consent, given when you authorise the Strava connection |
| Files you import, and the streams inside them | Contract | Explicit consent, given by choosing that file and importing it |
| Notes, feel, effort, planned sessions | Contract | Explicit consent, given when you write them |
| Sharing with a coach you approved | Contract | Explicit consent, given by approving that specific coach |
| Messages between you and your coach | Contract | Explicit consent, to the extent you choose to write about your health |
You can withdraw consent at any time, and withdrawing is as easy as giving it: disconnect Strava, end a coaching link, delete a session you imported, or delete your account. Withdrawal does not make what we did beforehand unlawful, but it stops it continuing.
5. Who your data reaches
5.1 Nobody, by default
There is no feed, no public profile, no leaderboard and no discovery. Another Runflect user cannot come across your training, because there is no surface on which that could happen.
5.2 A coach you invited
A coach sees your diary only because you invited them by name, and only for as long as you leave that in place. A coach cannot request their way in — the athlete starts the relationship, always.
That includes any voice note you have recorded — a coach you approved can play it and hear it in your own voice. They cannot delete it, and they cannot record one for you. If you would rather they did not hear a particular day, delete that recording, or write it instead.
Your approval runs out after 60 days unless you confirm it again. That is a hard stop, not a warning: when it lapses the coach loses access to your diary and your trends, and can write nothing further. Sessions and notes they already wrote stay in your diary, because those are things that were said and un-saying them is not what lapsing means. You can end the link outright at any moment, with immediate effect.
A coach you have approved can see the activities in your diary, including those that came from Strava.
Either way, a coach never sees your messages with a different coach, and never sees another athlete’s anything.
5.3 Service providers
These are processors under UK GDPR Article 28, bound by contract, and none of them may use your data for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosts and serves the application | London |
| Neon Inc. | Hosts the database | London |
| Hostinger | Hosts our mailbox and carries the email we send you. No training data passes through it | [region — to be confirmed] |
We will provide the current list on request, with each provider’s name, role and processing location.
5.4 Strava
Strava is not our processor. Under Strava’s API Policy, Strava and Runflect are separate and independent data controllers for the personal data each of us handles. What Strava does with your data is governed by Strava’s own privacy policy, which we cannot change and which controls if anything here conflicts with it.
Strava monitors and collects usage data about how Runflectuses its API, and may use that for any business purpose, including improving their platform and checking that we are complying with our agreement with them. This statement appears here because Strava’s API Policy requires it.
5.5 Legal requests
We would disclose data if we were legally required to — a court order, or a lawful demand we are obliged to answer. We will tell you if we are permitted to.
5.6 What never happens
We do not sell your personal data. We do not license it, rent it, lease it, trade it, or make it available to anyone in exchange for money or anything else of value — not to advertisers, not to data brokers, not to AI companies or model developers. This holds even if you were to tell us we could. We do not share it for behavioural advertising and we do not use it to target advertising anywhere.
If Runflect were ever sold or merged, your data would move with it, the buyer would be bound by this policy, and you would be told before anything changed.
6. Where your data is held
Runflect is operated from the United Kingdom and your training data is stored in the United Kingdom. The database is in London, the application runs in London, and your runs, your notes and everything else you write stay there.
Email is the first exception. Messages we send you go out through our mail provider and may pass through their delivery and filtering partners. No training data is ever sent by email: what travels is your email address, the text of the message, and in a deletion confirmation the number of records removed. We are confirming the country with the provider and will name it here.
Stravais the second, and only because you asked us to. Strava is a US company, so connecting your Strava account means data coming to us from the United States. That transfer is protected by the Standard Contractual Clauses and the UK International Data Transfer Addendum, as set out in Strava’s API Policy. Once it reaches us, it stays here.
7. How long we keep it
| Data | Kept |
|---|---|
| Account details | Until you delete your account |
| Sign-in sessions | 30 days, or until you sign out |
| Support emails | Two years from the last message in the thread |
| Strava-sourced activity data | While your Strava connection is live. Deleted when you disconnect, when you revoke us at Strava, or when you delete your account |
| An activity you delete or hide on Strava | Removed from Runflect within 48 hours |
| Sessions you imported from a file | Until you delete them or delete your account. Disconnecting Strava does not remove them — they did not come from Strava |
| The uploaded file itself | Released as soon as the sessions have been read out of it |
| Your notes, feel and planned sessions | Until you delete them, or delete your account |
| Your voice notes | Until you delete them, or delete your account. Deleting one cannot be undone — unlike a run, a recording cannot be fetched again from anywhere |
| Coach links, coach notes and messages | Until you delete your account |
| Record that a deletion happened | 24 months. See below — a record of the deletion, not a copy of what was deleted |
| Database backups | Deleted data disappears from our database provider’s change history within 6 hours. We keep no other backups and take no snapshots |
Deletion requests are completed within 30 days at the outside and in practice immediately — records are removed as you press the button, not queued.
One thing survives a deletion, and you should know what it is. We keep a dated note that a deletion happened: the date, whether it was a Strava disconnection or a whole account, how many records were removed, and a one-way fingerprint of your email address. We keep it so we can answer you if you come back and ask what happened to your data, and so we can show Strava we honoured the deletion, which our agreement with them requires. UK GDPR permits this — being able to demonstrate that we complied is itself an obligation.
It holds no activities, no notes, no name and not your email address — only a fingerprint of it, which cannot be turned back into an address but does let us match you if you write in. It is not a shadow copy and nothing can be rebuilt from it. We delete the record itself 24 months after the deletion it describes. We are honest that a fingerprint is not the same as nothing: we hold the key that made it, so while it is far safer than your address it is still, in law, information about you. Keeping it for a bounded period is reasonable; keeping it indefinitely would not be.
8. Disconnecting, and deleting
Disconnect Strava — from your Runflect settings, or from strava.com/settings/apps. Both work and neither needs the other. Every activity, split, lap, effort and route line we hold that came from Strava is permanently deleted, along with your stored tokens, immediately and while you wait. We also withdraw our own access at Strava’s end, so Runflect stops appearing under My Apps there. Everything you wrote yourself stays, and so does anything you imported from a file. We confirm it to you by email.
Delete your account — from your settings, or by emailing privacy@runflect.com. That removes everything: imported sessions, the Strava mirror, your notes, your effort scores, your planned sessions, your messages, your coaching links and the account itself. It happens immediately, it is not recoverable, and we confirm it in writing.
Both leave behind the dated deletion record described in section 7, and nothing else. You can always get your Strava data from Strava, free, using their own bulk export tool — nothing here limits that.
9. Security
Passwords are stored as salted hashes and are never recoverable, by us or by anyone. Strava tokens are encrypted at rest and never sent to a browser. All traffic is over HTTPS. Sign-in, sign-up and password-reset endpoints are rate limited. Database credentials are held as encrypted environment secrets, and access to production data is limited to those who need it to run the service.
No system is perfectly secure and we won’t claim otherwise. If a breach affected your personal data and posed a risk to you, we would tell you and report it to the ICO within 72 hours, as the law requires. Where a breach touched Strava-sourced data we are also required to notify Strava within 24 hours, and we would.
10. Your rights
Under the UK GDPR you have the right to be told what we hold and why; to access a copy of it; to rectify anything inaccurate; to erase it; to restrict how we process it; to portability — receiving it in a machine-readable format; to object to processing based on legitimate interests; to withdraw consent at any time without that being harder than giving it; and not to be subject to solely automated decisions with legal or similarly significant effects, of which we make none.
Runflect lets you exercise most of these yourself, in the app, without asking us. Access and portability are in Settings → Your data → Download everything, which gives you a file holding everything we hold for you — your activities, your diary, your voice notes, your injuries and goals, and your messages — in formats you can open in a spreadsheet or load into another service. Erasure is in Settings → Account → Delete my account. Both are immediate and free, and neither needs our permission. For anything else, email privacy@runflect.com. We respond within one month and there is no charge.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office — ico.org.uk, 0303 123 1113. We would rather you came to us first, but you do not have to.
11. Children
Runflect is not intended for anyone under 18 and we do not knowingly collect data from under-18s. That is a higher bar than the law sets, and it is deliberate: the coaching feature lets one adult see where another person runs and message them privately, which needs safeguards we have not built yet. If you believe a child has given us personal data, email privacy@runflect.com and we will delete it.
12. Changes
If we change this policy we will update the date at the top. If a change materially affects what we do with your data — particularly if it changes the types of data we collect — we will tell you by email and, where the law requires it, ask for your consent again before it takes effect.
We will never change this policy to permit selling your data.
13. Contact
privacy@runflect.com
Chris Pickersgill, [postal address — to be confirmed]
Runflect is not affiliated with, endorsed by or sponsored by Strava. Strava is a trademark of Strava, Inc.