Privacy policy
The Run · Last updated 10 October 2026
The short version. The Run doesn't ask for your name, email, age or gender. Your account is anonymous. Your routes and run history stay on your phone. The server stores only what it needs to rank each race (your time and whether your run passed the app's checks) and deletes it 14 days after the race closes. There are no ads, analytics or tracking.
Who I am
The Run is made by Thomas Martin, an independent developer in the United Kingdom, who is the data controller for the personal data described here. You can reach me at hello@thomas-martin.uk.
What stays on your phone
These are stored only on your device and never sent to me:
- Your location and routes. The Run uses your location while you're recording a run, including when your phone is locked, to measure the route and distance. The GPS points, maps and splits are saved on your phone.
- Motion data. Step counts and barometer readings during a run are used on your phone to check the run was on foot and to measure climbs.
- Your run history, results you've received and your settings.
The app checks each run on your phone and only sends a summary verdict ("pass" or "flagged") to the server, never the route itself. If you delete the app or your account, this data is erased from your phone.
What the server stores
The Run's backend is hosted by Supabase. It stores:
| Data | Why | How long |
|---|---|---|
| A random anonymous account ID, created when you first open the app | To tell your entries apart without knowing who you are | Until you delete your account |
| Your device's push notification token and app language | To send your result notification, in your language | Until you delete your account |
| Your subscription expiry date, if you subscribe to The Run+ | To unlock The Run+ races and stats | Until you delete your account |
| For each race you enter: your finish time, the run's verdict and your finishing position | To rank the race and tell you where you placed | Deleted automatically 14 days after the race closes |
| Special event prizes you've won | To give you the prize | Deleted 14 days after the event closes |
I can see submitted times and verdicts to review flagged runs, and may disqualify a time that doesn't look genuine. Your position is shown only to you. There is no public leaderboard.
Like any web service, Supabase's servers receive your IP address when the app connects. It's kept in short-lived service logs and isn't linked to anything else.
Services that receive data
- Supabase hosts the database and server functions described above.
- RevenueCat manages subscriptions. It receives your anonymous account ID and your App Store purchase details (product, price, dates and country), but not your name or payment card. See RevenueCat's privacy policy.
- Apple processes App Store payments and delivers push notifications. If you choose to, The Run saves your runs to Apple Health as workouts with their route. It never reads your health data.
- Expo relays result notifications to Apple's push service. It receives your push token and the notification text (your position). See Expo's privacy policy.
- Maps. Route maps use your phone's built-in map service (Apple Maps on iPhone), which loads map tiles for the area you're viewing.
- Strava, only if you connect it. When you choose to upload a race result, your phone sends it straight to your Strava account: the route, time, heart rate if available, and the race name and position. Your Strava sign-in is kept in your phone's secure Keychain. A server function only exchanges and refreshes the sign-in with Strava and stores nothing. Disconnecting Strava or deleting your account revokes The Run's access. Activities you've already uploaded stay on Strava. See Strava's privacy policy.
I don't sell your data or share it with anyone else. The Run contains no advertising, analytics or tracking SDKs, and doesn't track you across other apps or websites.
Some of these providers may process data outside the UK. Where they do, they rely on safeguards recognised under UK data protection law, such as the International Data Transfer Addendum or the UK–US data bridge.
Permissions
- Location (including while the phone is locked): to record your run. Only used while recording.
- Motion & fitness: step counting and barometer readings, used on your phone to check runs.
- Notifications: to tell you your result when a race closes.
- Apple Health (write only): to save your runs as workouts.
- Photos (add only): to save result cards when you tap Save to Photos. The Run can't see your photo library.
You can change any of these in your phone's Settings at any time.
Legal basis
Under UK GDPR, I process this data because it's needed to provide the service you asked for: entering races, ranking them and sending your results (contract). I also rely on my legitimate interest in keeping races fair, for reviewing flagged runs. Saving to Apple Health, connecting Strava and notifications rely on your choice to turn them on, which you can withdraw at any time.
Deleting your data
In the app, go to Settings → Delete account. This deletes your profile, race entries and RevenueCat customer record from the server, erases your runs from your phone, and disconnects Strava. Deleting your account doesn't cancel an App Store subscription, so cancel that in your Apple ID settings.
Your rights
You have the right to access, correct, delete or restrict the use of your personal data, to object to its use, and to data portability. Because accounts are anonymous, I usually can't tell which data is yours from an email alone. Deleting your account in the app is the quickest way to erase everything. For any other request, email hello@thomas-martin.uk.
If you're unhappy with how your data is handled, you can complain to the Information Commissioner's Office at ico.org.uk.
Children
The Run isn't directed at children under 13, and I don't knowingly collect data from them.
Changes
If this policy changes, I'll update it here and change the date at the top. If a change significantly affects how your data is used, I'll also tell you in the app.