Privacy Policy
Last updated: 13 August 2026
In short
Runnr has two halves, and they handle data very differently:
- The running app works without an account. Your routes, your runs and your history stay on your phone.
- The social side requires an account. What you publish, comment on and like is stored on a server, because other people are meant to see it. That is the entire point of sharing.
We do not sell data, we do not show ads, and we do not track you across other apps or websites.
Data controller
Runnr, Denmark. Contact: support@runnr.dk.
If you have questions about how we handle your information, write to us. We reply within 30 days.
Part 1: Without an account
Location
Runnr uses your position to build routes that start where you are, to follow the route as you run, and to give spoken guidance.
- Your position is shown and processed on the phone.
- When you generate a route, a starting point and a target distance are sent to our own routing server in Denmark (Hetzner, Falkenstein). The server calculates the route and answers. The request is not tied to you and is not kept as a profile.
- Your GPS trace during a run is not sent to us. It stays on the phone unless you publish the route yourself on the social side.
- Maps are provided by Mapbox. To draw the map around you, Mapbox sends your location and a random device identifier to their servers, where it is also used for their own analytics. You can turn that analytics off inside the app: tap the ⓘ in the corner of the map. Mapbox' processing is covered by Mapbox' privacy policy. The watch and a few older views still use Apple MapKit, covered by Apple's privacy policy.
You can decline location access. The app still works, you just cannot get routes from where you are.
Saved routes and runs
Generated routes, saved runs, distances, times, pace and your streak are stored locally on the device. You can delete them individually or all at once under Settings. Delete the app and they are gone.
Health
With your permission, Runnr reads sleep, resting heart rate, heart rate variability, body mass and your workouts from Health in order to estimate your daily form, estimate calories, and avoid saving the same run twice. Runnr can also write your runs to Health.
Health data never leaves the phone. It is not sent to us, to the social side, or to any third party. Access is controlled in the Health app and can be withdrawn at any time.
Usage statistics
We use Google Firebase Analytics to see how the app is used: how many people build a route, how many run it, and where things go wrong. These are numbers about actions, not about you as a person, and we do not link them to your name or email.
Firebase assigns a random app instance ID to the installation. We do not use IDFA, we show no ads, and we share nothing with ad networks. That is why the app never asks for tracking permission.
Purchases
Payment is handled entirely by Apple. We never see your card details. Subscription status is verified through Apple StoreKit on the device, and if you have an account, a plain yes/no flag is stored on your profile so the server knows whether premium features are available to you.
Reminders
Run reminders are local notifications scheduled by the phone itself. We send no push messages, and we cannot see whether you open them.
Part 2: With an account (the social side)
With an account you can publish routes, follow others, like and comment. Accounts are created with Sign in with Apple or Sign in with Google. We receive your name and email address from the provider, plus a user ID. If you use Apple's Hide My Email, we only ever see the relay address.
What we store
- Profile: name, username, bio, city, profile picture, and when you last started a run (so others can see that someone is running, never where).
- Posts: title, description, tags, artwork and the route's actual geography. Publishing a route publishes its path, which can reveal where you run and where you start. A rounded city point (about 1 km) is also stored for search.
- Actions: likes, saved posts, comments, follows and friend requests, and the fact that you completed a route.
- Moderation: reports you submit, users you block, and, if it becomes necessary, that an account has been banned and why.
This data is held by Supabase on servers in the EU (Stockholm). Profile pictures are stored in the same place.
Runnart: images you upload
When you build a figure from a photo, the image is sent to our server in Denmark and on to OpenAI, which first checks it for inappropriate content and then redraws it as line art.
- The photo is not stored by us. Only the finished figure, the line itself, is kept on your account.
- If an image is rejected, it is not stored - only the fact that something was rejected.
- Do not upload pictures of other people without their consent.
Profile pictures
A profile picture is checked by OpenAI for inappropriate content before it is uploaded. If the check cannot be completed, the image is rejected. Approved images are stored in Supabase and are publicly accessible, because they appear next to your posts.
Text you write
Titles, descriptions, tags, name, username, bio and comments are sent to OpenAI's moderation service before they become public. The text is used only to decide whether it can be published.
When you ask for a route in words
If you type or say a route request - "10 km past the harbour" - the text is sent to our server in Denmark and on to OpenAI, which turns it into settings: distance, route profile, surface and place names. The name of the town you are in is sent along with the text, so "the harbour" can become your harbour rather than a random one. The town is derived on your phone from your location; no coordinates are sent. We do not store the text, and we only count how many requests you have used of your monthly allowance.
If you speak the request instead of typing it, the speech recognition happens on your phone. The recording never leaves the device - only the finished text is sent on.
Legal bases
- Contract (GDPR art. 6(1)(b)): account, profile, posts, likes, comments, follows and subscription. This is the service you asked for.
- Consent (art. 6(1)(a), and art. 9(2)(a) for health): location, health data, photos and photo library access. You give it in the system dialogs and can withdraw it in your phone's settings.
- Legitimate interests (art. 6(1)(f)): moderation, abuse prevention, security, debugging and aggregate usage statistics. Our interest is keeping a public feed decent and the app running.
- Legal obligation (art. 6(1)(c)): accounting and responding to lawful requests from authorities.
Who receives your information?
We do not sell data. We use these processors and suppliers:
- Apple (Ireland/USA): App Store, payment, maps, Sign in with Apple.
- Google / Firebase (Ireland/USA): sign-in, usage statistics.
- Supabase (EU, Stockholm): database and file storage for the social side.
- Hetzner (Germany): our routing server and figure service.
- Mapbox (USA): map display. Receives your location and a random device identifier.
- OpenAI (USA): moderation of text and images, redrawing of Runnart artwork, and turning your route requests into settings.
Transfers to the USA: Google, Apple, Mapbox and OpenAI may process data in the United States. Transfers are made on the basis of the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Anything you publish on the social side can be seen by other users - and for posts set to "Everyone", by anyone who opens the app, including people without an account.
How long do we keep it?
- Local data: until you delete it or delete the app.
- Account and posts: for as long as you have an account.
- Deleted posts: marked as deleted immediately and gone for everyone. The row is purged within 90 days.
- Reports and bans: up to 2 years, so that repeat offences can be recognised as a pattern. This is necessary for moderation to work at all.
- Usage statistics: according to Firebase's standard retention, at most 14 months.
- Purchase records: 5 years under Danish bookkeeping law. Handled by Apple.
Deleting your account
You can delete your account in the app under Profile → Delete account. This deletes your profile, your posts, comments, likes, saved posts and profile picture. Your local routes and runs on the phone are untouched - you delete those yourself in Settings.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where you have given consent, you can withdraw it at any time without affecting the lawfulness of processing already carried out.
Write to support@runnr.dk. Much of it you can do yourself, immediately, in the app: edit your profile, delete posts, delete your account, delete local data.
If you are unhappy with how we handle your information, you can complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.
Children
The social side is not intended for children under 13, and you must be at least 13 to create an account. If you are under 18, a parent or guardian must have accepted the terms. If we become aware of an account created by a child under 13, we delete it.
Security
All traffic is encrypted. Access to the social database is governed by row-level rules, so your account can only touch its own data. Keys with elevated privileges exist only on our servers, never in the app.
Changes
If we change this policy, the date at the top is updated. You will be told about significant changes in the app before they take effect.