Legal

Privacy policy

Last updated 3 September 2026Terms of service

This says what Runflect collects, why, who ever sees it, and how to get rid of it. It is longer than a summary because a summary is not a legal notice — but nothing in it is hidden, and there is no clause that takes back something said earlier.

1. Who we are

Runflect is a trading name of Chris Pickersgill, a sole trader based in England. For the purposes of the UK GDPR, Chris Pickersgill is the data controller for the personal data described here.

Address for service: [postal address — to be confirmed]
ICO registration number: [ICO number — to be confirmed]
Data rights and anything in this policy: privacy@runflect.com
General support: support@runflect.com

We have not appointed a Data Protection Officer, as we are not required to.

2. What we collect

2.1 Your account

Collected from you when you sign up.

DataWhy we have it
NameTo address you in the app
Email addressTo identify your account and sign you in
PasswordStored only as a salted hash. We never see it and cannot recover it
Units preferenceTo render your training the way you read it
Account roleAthlete, coach or both — decides which screens you get
Age confirmationThat you confirmed you are 18 or over, and the date you did. We ask for your date of birth to check it, and then discard it — we do not store your date of birth, because nothing in Runflect needs it once the check has passed

2.2 Your sign-in sessions

Created automatically when you sign in: a session token stored in a cookie on your device, your IP address and your browser’s user-agent string. The token keeps you signed in; the other two let you and us spot a sign-in that wasn’t you. The session cookie is strictly necessary and there are no others — no advertising cookie, no analytics cookie, nothing to consent to. Sessions expire after 30 days, and signing out deletes the record.

2.3 Data from Strava

Collected from Strava, with your permission, after you authorise us on Strava’s own screen. We request two permissions — read for your basic profile and activity:read_all for your activities, including those you marked private. We request no write permission of any kind, so we are technically incapable of changing anything in your Strava account.

What we receive and hold: your Strava athlete ID and name; and for each activity its name, sport type, start date and time, distance, moving and elapsed time, elevation gain, average and maximum speed, average and maximum heart rate, average cadence, Strava’s Relative Effort score, achievement and kudos counts, your own perceived-exertion figure if you logged one, your private note on the activity, and the encoded map line of the route. For an activity you open, we additionally hold its splits, laps, best efforts and heart-rate zone breakdown.

Your OAuth tokens are encrypted at rest and are never sent to your browser. Every call to Strava happens on our servers.

Heart rate, heart-rate zones and route maps are health and location data. Section 4 explains what that means for the legal basis we rely on.

2.4 Files you import

If you drop a .FIT, .TCX, .GPX or .CSVfile into Runflect — or a whole account export archive — we read the sessions out of it. This is the route that does not need anybody else’s permission, and it is how you get your history in without Strava.

A file of this kind is higher resolution than anything Strava sends us, and we hold what it contains: the per-second record of the session, which typically means heart rate, position, altitude, speed and cadence sampled every second, plus laps and the device that recorded it. We also compute per-kilometre and per-mile splits from it, because no file format carries them and the diary draws both.

The uploaded file itself is stored only while it is being processed, and its bytes are released as soon as the sessions have been read out. We keep a one-way fingerprint of the file afterwards, so that dropping the same file twice is recognised rather than duplicated.

2.5 What you write and record yourself

This is yours, not any device maker’s, and we treat it differently throughout: your session and day notes, how a session felt, effort scores you logged, and sessions you planned — a title, a target distance and a note.

You can also record a voice note against a day, up to three minutes long. We store the recording exactly as you made it, and we treat it the same way we treat anything else you write — it may say something about your health, so it sits under the same consent as the rest of your diary. Recording is always something you start; your microphone is never opened otherwise, and your browser will ask you before it is opened at all.

2.6 Coaching

If you invite a coach we store the link itself: the email address you invited, when you invited them, when they accepted, when you last confirmed it, and when it ended if it has. We also store what a coach writes for you — their notes on your sessions and the sessions they plan.

2.7 Messages

Runflect has a messaging screen between an athlete and their coach. We store the messages, who sent them, when, and whether they have been read. They are visible to the two of you and to nobody else.

We email you each time a message arrives. You can turn that off in your settings. It governs message email only: emails about the account itself, such as a coaching invitation or a confirmation that something was deleted, are the record of something happening to your account and always send.

2.8 When you contact us

If you use the contact form or email us we receive your name, your email address, the subject you picked and whatever you write. We use it to answer you and for nothing else. Threads are kept for two years and then deleted. We do not add you to a mailing list, and we have no mailing list to add you to.

2.9 Payment

Runflect does not charge anyone today. If and when paid coach plans open, payment will be handled by Stripe, card numbers will be entered on Stripe’s systems and never touch ours, and this policy will be updated before that happens rather than after.

2.10 What we do not collect

No advertising or analytics cookies and no third-party trackers. No location beyond the route lines attached to sessions you chose to record. No contacts, no device identifiers, no cross-site tracking. And no data about you from data brokers, marketing lists or any other outside source.

We do not transcribe your voice notes, and nothing listens to them. No speech recognition of any kind runs on them, here or anywhere else — they are not sent to a transcription service, and we do not use them to identify you or to work anything out about you. A voice note exists to be played back: by you, and by a coach you invited.

3. What we use it for

PurposeWhat it covers
Running your diaryRendering your runs, weeks, trends and write-ups
Analysing your trainingTraining load, strain, session type, rep detection, intensity labels and threshold estimates — for you, about you, shown only to you
CoachingShowing a coach you approved what you approved them to see
MessagingDelivering messages between you and your coach, and telling you one arrived
Keeping your account secureSign-in, sessions, rate limiting, spotting abuse
SupportAnswering you when you write in

We do notuse your data to train, fine-tune, ground, evaluate or operate any AI or machine-learning system, and we do not feed it into one. Strava’s API Policy forbids this for Strava-sourced data, and we apply the same rule to everything else because it is the right rule.

We do not profile you, and no decision with a legal or similarly significant effect on you is made automatically.

4. Health data, and our legal bases

Heart rate, heart-rate zones, perceived exertion and how a session felt are data concerning health under UK GDPR Article 9. Route lines are location data. Both need more than an ordinary legal basis.

DataLawful basis (Art. 6)Condition (Art. 9)
Account and sign-in dataContract — we cannot provide the service without itNot applicable
Security and rate-limiting recordsLegitimate interests — keeping accounts safe from unauthorised accessNot applicable
Strava activity data, including heart rate and routesContractExplicit consent, given when you authorise the Strava connection
Files you import, and the streams inside themContractExplicit consent, given by choosing that file and importing it
Notes, feel, effort, planned sessionsContractExplicit consent, given when you write them
Sharing with a coach you approvedContractExplicit consent, given by approving that specific coach
Messages between you and your coachContractExplicit consent, to the extent you choose to write about your health

You can withdraw consent at any time, and withdrawing is as easy as giving it: disconnect Strava, end a coaching link, delete a session you imported, or delete your account. Withdrawal does not make what we did beforehand unlawful, but it stops it continuing.

5. Who your data reaches

5.1 Nobody, by default

There is no feed, no public profile, no leaderboard and no discovery. Another Runflect user cannot come across your training, because there is no surface on which that could happen.

5.2 A coach you invited

A coach sees your diary only because you invited them by name, and only for as long as you leave that in place. A coach cannot request their way in — the athlete starts the relationship, always.

That includes any voice note you have recorded — a coach you approved can play it and hear it in your own voice. They cannot delete it, and they cannot record one for you. If you would rather they did not hear a particular day, delete that recording, or write it instead.

Your approval runs out after 60 days unless you confirm it again. That is a hard stop, not a warning: when it lapses the coach loses access to your diary and your trends, and can write nothing further. Sessions and notes they already wrote stay in your diary, because those are things that were said and un-saying them is not what lapsing means. You can end the link outright at any moment, with immediate effect.

A coach you have approved can see the activities in your diary, including those that came from Strava.

Either way, a coach never sees your messages with a different coach, and never sees another athlete’s anything.

5.3 Service providers

These are processors under UK GDPR Article 28, bound by contract, and none of them may use your data for their own purposes.

ProviderWhat they doWhere
Vercel Inc.Hosts and serves the applicationLondon
Neon Inc.Hosts the databaseLondon
HostingerHosts our mailbox and carries the email we send you. No training data passes through it[region — to be confirmed]

We will provide the current list on request, with each provider’s name, role and processing location.

5.4 Strava

Strava is not our processor. Under Strava’s API Policy, Strava and Runflect are separate and independent data controllers for the personal data each of us handles. What Strava does with your data is governed by Strava’s own privacy policy, which we cannot change and which controls if anything here conflicts with it.

Strava monitors and collects usage data about how Runflectuses its API, and may use that for any business purpose, including improving their platform and checking that we are complying with our agreement with them. This statement appears here because Strava’s API Policy requires it.

5.5 Legal requests

We would disclose data if we were legally required to — a court order, or a lawful demand we are obliged to answer. We will tell you if we are permitted to.

5.6 What never happens

We do not sell your personal data. We do not license it, rent it, lease it, trade it, or make it available to anyone in exchange for money or anything else of value — not to advertisers, not to data brokers, not to AI companies or model developers. This holds even if you were to tell us we could. We do not share it for behavioural advertising and we do not use it to target advertising anywhere.

If Runflect were ever sold or merged, your data would move with it, the buyer would be bound by this policy, and you would be told before anything changed.

6. Where your data is held

Runflect is operated from the United Kingdom and your training data is stored in the United Kingdom. The database is in London, the application runs in London, and your runs, your notes and everything else you write stay there.

Email is the first exception. Messages we send you go out through our mail provider and may pass through their delivery and filtering partners. No training data is ever sent by email: what travels is your email address, the text of the message, and in a deletion confirmation the number of records removed. We are confirming the country with the provider and will name it here.

Stravais the second, and only because you asked us to. Strava is a US company, so connecting your Strava account means data coming to us from the United States. That transfer is protected by the Standard Contractual Clauses and the UK International Data Transfer Addendum, as set out in Strava’s API Policy. Once it reaches us, it stays here.

7. How long we keep it

DataKept
Account detailsUntil you delete your account
Sign-in sessions30 days, or until you sign out
Support emailsTwo years from the last message in the thread
Strava-sourced activity dataWhile your Strava connection is live. Deleted when you disconnect, when you revoke us at Strava, or when you delete your account
An activity you delete or hide on StravaRemoved from Runflect within 48 hours
Sessions you imported from a fileUntil you delete them or delete your account. Disconnecting Strava does not remove them — they did not come from Strava
The uploaded file itselfReleased as soon as the sessions have been read out of it
Your notes, feel and planned sessionsUntil you delete them, or delete your account
Your voice notesUntil you delete them, or delete your account. Deleting one cannot be undone — unlike a run, a recording cannot be fetched again from anywhere
Coach links, coach notes and messagesUntil you delete your account
Record that a deletion happened24 months. See below — a record of the deletion, not a copy of what was deleted
Database backupsDeleted data disappears from our database provider’s change history within 6 hours. We keep no other backups and take no snapshots

Deletion requests are completed within 30 days at the outside and in practice immediately — records are removed as you press the button, not queued.

One thing survives a deletion, and you should know what it is. We keep a dated note that a deletion happened: the date, whether it was a Strava disconnection or a whole account, how many records were removed, and a one-way fingerprint of your email address. We keep it so we can answer you if you come back and ask what happened to your data, and so we can show Strava we honoured the deletion, which our agreement with them requires. UK GDPR permits this — being able to demonstrate that we complied is itself an obligation.

It holds no activities, no notes, no name and not your email address — only a fingerprint of it, which cannot be turned back into an address but does let us match you if you write in. It is not a shadow copy and nothing can be rebuilt from it. We delete the record itself 24 months after the deletion it describes. We are honest that a fingerprint is not the same as nothing: we hold the key that made it, so while it is far safer than your address it is still, in law, information about you. Keeping it for a bounded period is reasonable; keeping it indefinitely would not be.

8. Disconnecting, and deleting

Disconnect Strava — from your Runflect settings, or from strava.com/settings/apps. Both work and neither needs the other. Every activity, split, lap, effort and route line we hold that came from Strava is permanently deleted, along with your stored tokens, immediately and while you wait. We also withdraw our own access at Strava’s end, so Runflect stops appearing under My Apps there. Everything you wrote yourself stays, and so does anything you imported from a file. We confirm it to you by email.

Delete your account — from your settings, or by emailing privacy@runflect.com. That removes everything: imported sessions, the Strava mirror, your notes, your effort scores, your planned sessions, your messages, your coaching links and the account itself. It happens immediately, it is not recoverable, and we confirm it in writing.

Both leave behind the dated deletion record described in section 7, and nothing else. You can always get your Strava data from Strava, free, using their own bulk export tool — nothing here limits that.

9. Security

Passwords are stored as salted hashes and are never recoverable, by us or by anyone. Strava tokens are encrypted at rest and never sent to a browser. All traffic is over HTTPS. Sign-in, sign-up and password-reset endpoints are rate limited. Database credentials are held as encrypted environment secrets, and access to production data is limited to those who need it to run the service.

No system is perfectly secure and we won’t claim otherwise. If a breach affected your personal data and posed a risk to you, we would tell you and report it to the ICO within 72 hours, as the law requires. Where a breach touched Strava-sourced data we are also required to notify Strava within 24 hours, and we would.

10. Your rights

Under the UK GDPR you have the right to be told what we hold and why; to access a copy of it; to rectify anything inaccurate; to erase it; to restrict how we process it; to portability — receiving it in a machine-readable format; to object to processing based on legitimate interests; to withdraw consent at any time without that being harder than giving it; and not to be subject to solely automated decisions with legal or similarly significant effects, of which we make none.

Runflect lets you exercise most of these yourself, in the app, without asking us. Access and portability are in Settings → Your data → Download everything, which gives you a file holding everything we hold for you — your activities, your diary, your voice notes, your injuries and goals, and your messages — in formats you can open in a spreadsheet or load into another service. Erasure is in Settings → Account → Delete my account. Both are immediate and free, and neither needs our permission. For anything else, email privacy@runflect.com. We respond within one month and there is no charge.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office — ico.org.uk, 0303 123 1113. We would rather you came to us first, but you do not have to.

11. Children

Runflect is not intended for anyone under 18 and we do not knowingly collect data from under-18s. That is a higher bar than the law sets, and it is deliberate: the coaching feature lets one adult see where another person runs and message them privately, which needs safeguards we have not built yet. If you believe a child has given us personal data, email privacy@runflect.com and we will delete it.

12. Changes

If we change this policy we will update the date at the top. If a change materially affects what we do with your data — particularly if it changes the types of data we collect — we will tell you by email and, where the law requires it, ask for your consent again before it takes effect.

We will never change this policy to permit selling your data.

13. Contact

privacy@runflect.com
Chris Pickersgill, [postal address — to be confirmed]

Runflect is not affiliated with, endorsed by or sponsored by Strava. Strava is a trademark of Strava, Inc.