Privacy Policy
Last updated: 16 September 2026
The short version. Your health and workout data stays on your device and is used only to power your progress in the game. The one exception is if you create an account: your career — including the workout metrics behind it — is then backed up to our EU server so you can restore it after a reinstall, and only you can read it. We also ask, when you set the App up, whether we may link your anonymous usage data — which screens and actions people use, so we can see where the App is confusing — under one random id. Say no and we still count that usage, but unlinked, with nothing stored on your device; either way it never includes anything from Apple Health, and Account → Send nothing at all stops it completely. Crash reports are on by default so we can fix what breaks. We never sell any of it, never advertise against it, and never share it with data brokers.
This policy explains what RunToDrive (the “App”) collects, why, and what control you have over it. It applies to the RunToDrive iPhone and Apple Watch app and to this website. RunToDrive is operated by Lluís Armengol (“we”, “us”).
1. Health and fitness data
With your explicit permission, the App reads the following from Apple Health:
- Workouts (running, walking and cycling), including start and end time and duration
- Walking and running distance
- Cycling distance
- Active energy burned
- Heart rate, used to score the effort of a session you tracked in the App
This data is used for one purpose: converting your real-world effort into in-game progression (driver XP, resource points, energy and season objectives). It is stored locally on your device, and — if you create an account — included in your cloud backup so your career survives a reinstall (see section 3).
We do not use health data for advertising or marketing, we do not sell or rent it, and we do not share it with third parties for their own purposes. You can revoke Health access at any time in Settings → Privacy & Security → Health → RunToDrive. The App remains usable without it — you simply won't earn progression from imported workouts.
2. Location and motion data
If you use the App's in-app training tracking, it requests access to location and motion & fitness data to measure distance, pace and route while a session is running. This data is processed on your device to produce the workout summary that drives your progression.
Location access is only requested when you start a tracked session, and can be revoked at any time in iOS Settings. We do not use your location for advertising, profiling or any purpose unrelated to measuring the workout you started.
3. Account data and cloud save
You can use the App without an account. Without an account, nothing about your career or your workouts leaves your device.
If you create an account, we store your email address and an account identifier with Supabase (EU-hosted), our authentication and database provider. Authentication credentials are handled by that provider, and access tokens are stored in the iOS Keychain — never in plain files or logs.
Creating an account also enables cloud save: a backup of your career is uploaded to your own row in our database, so you can restore it if you reinstall the App or change device. It contains:
- Game state — race results and their event logs, garage and upgrades, energy, season progress, XP and levels, and your cosmetic choices
- Your display name, onboarding status and preferred activity
- The workout metrics your progression was calculated from: activity type, start and end time, duration, distance, active energy, average heart rate, step count and elevation gain — plus your benchmark results
Workout routes and GPS coordinates are never uploaded, and neither is anything from your Health records beyond the metrics listed above. The backup is written when you create your account and refreshed when you leave the App; it is transmitted over TLS and protected by row-level security, so no other user — and no unauthenticated request — can read it. It is a backup only: gameplay always runs from the copy on your device.
Deleting your account in Account → Delete Account deletes the account and its cloud save immediately (see Retention).
4. Analytics
Nothing is sent until you answer. During setup the App asks, in plain terms, whether we may link your anonymous usage data under one random identifier. Say yes and that identifier is stored on your device, so repeat use counts as one player. Say no and we still record the same anonymous events — but unlinked: each one carries a fresh random value that is never reused, and nothing is stored on your device at all. Declining is a real answer; the App works exactly the same either way, and you can change it whenever you like in Account → Anonymous usage data.
If you want none of it, that is one switch. Account → Send nothing at all stops every analytics event, linked or not, from that moment. We rely on your consent for the linked version and on our legitimate interest in knowing whether the App works for the unlinked version, so that switch is also how you object to the latter under GDPR Article 21.
Either way we use PostHog (EU-hosted) to understand how the App is used so we can improve it. The events are anonymous: we do not create a profile for you and we never connect them to your account, your name or your email address. If you allow linking, PostHog stores a random identifier on your device so that repeat use can be counted as one player rather than many; it is not a device or advertising identifier, and reinstalling the App replaces it with a new one. Your IP address is not stored: PostHog discards it on arrival, but first derives an approximate area from it — usually the country, sometimes the city — and that area is what we keep. We do not enable session recording, autocapture or screen recording.
We record a small, fixed vocabulary of product events, such as: app opened, onboarding started and completed, the outcome of the Health access request, workout import started, completed or failed, reward screen viewed, engineering screen entered, engineering project started, and whether the core gameplay loop was completed and later repeated. Each carries only the context needed to interpret it, always from a fixed list of values — for example which onboarding step, or whether an import found anything new. Alongside them we send your app version and build, the App's own schema version, whether the build is a production or internal one, and, if you allowed linking, your country as a two-letter code taken from your device's Language & Region setting. We never receive your precise location, a coordinate, or anything from your device's location services for analytics.
What is never sent to analytics: anything from Apple Health, workout type, dates, durations, distances, pace, calories or heart rate, routes or location, the points a workout earned, your name, email address or display name, free text, and raw error messages.
5. Crash reports
We use Firebase Crashlytics to receive automatic reports when the App crashes. These contain diagnostic information such as device model, OS version and a stack trace, and are used solely to fix defects.
6. Feedback sent through this website
The feedback page submits your message anonymously to PostHog. We do not ask for, or attach, your name, email address or IP-based identity, and no tracking cookie is set. Please don't include personal or sensitive information in the message itself — since it is anonymous, we have no way to link a request back to you in order to delete it.
7. What we do not do
- No advertising, and no advertising SDKs
- No selling or sharing of personal data with data brokers
- No tracking you across other companies' apps or websites
- No use of health data for anything other than your in-game progression
8. Where your data is processed
| Provider | Purpose | Region |
|---|---|---|
| On your device | Health, workout, location and game data | Your device |
| Supabase | Account, and cloud backup of your career including workout metrics | EU |
| PostHog | Anonymous product analytics — linked to a random id only if you allow it — and anonymous feedback | EU |
| Google (Firebase Crashlytics) | Crash diagnostics | US / global |
| Apple | App distribution and Health | Global |
9. Retention
Data on your device is kept until you delete the App or clear it in-app. Your account and its cloud save are kept for as long as the account exists; one backup is stored per account and each upload replaces the previous one, so we keep no history of past saves. Deleting your account — in the App under Account → Delete Account, or by emailing us — deletes the account and its cloud save together, immediately and permanently. Analytics events are retained in aggregate for product analysis and are never linked to your account, so they cannot be traced back to you individually; unlinked events cannot be grouped into a person at all. Crash reports are retained according to Firebase's default retention period.
10. Your rights
If you are in the EEA or UK, the GDPR gives you the right to access, correct, export, restrict and delete your personal data, and to object to processing. Our legal basis is your consent (for Health, location, account creation and the cloud backup that comes with it, and for linking analytics to an identifier stored on your device — which is why that linking is off until you choose it, and can be switched off again just as easily) and our legitimate interest in knowing whether the App works (for unlinked analytics and crash diagnostics). You can object to anything we rely on legitimate interest for, in the App, under Account → Send nothing at all.
You can delete your account and its cloud save yourself at any time, in the App under Account → Delete Account. To exercise any other right, email runtodrive.app@gmail.com. We'll respond within 30 days. You also have the right to complain to your local data protection authority.
11. Children
RunToDrive is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Security
Data in transit is encrypted with TLS. Access tokens are stored in the iOS Keychain. Backend data is protected with row-level security so a user can only reach their own records. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
13. Changes
We'll update this page when the App changes, and revise the “last updated” date above. Material changes will be announced in the App.
14. Contact
Questions about this policy: runtodrive.app@gmail.com.