Outrun

Privacy Policy

Effective 15 September 2026 Version 2.0

The short version

Outrun is a paid app with no advertising and no free tier. We make money from subscriptions, not from your data.

  • We never sell your data, and we never share it with data brokers.
  • We never use your health or fitness data for advertising. Not ours, not anyone's.
  • We don't track you across other apps or websites. Outrun shows no ATT prompt because it has nothing to ask for.
  • You can export everything we hold about you, or delete your account entirely, from inside the app at any time.

The rest of this page explains exactly what we collect, why, who processes it on our behalf, and how long we keep it.

Who we are

Outrun (the "app") is provided by [YOUR FULL LEGAL NAME — see README], NIF [YOUR NIF — see README], of [YOUR REGISTERED ADDRESS — see README], Spain. Email: [email protected]. These identification details are published under Article 10 of Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).

For the purposes of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), that person is the data controller for the personal data described on this page. For users in the United Kingdom, the same person is the controller under the UK GDPR.

No Article 27 representative is appointed, and none is required. That obligation falls on controllers established outside the European Union. We are established in Spain, so you deal with the controller directly.

No Data Protection Officer is appointed. Article 37(1) requires one where processing is carried out by a public authority, where core activities consist of large-scale regular and systematic monitoring, or where core activities consist of large-scale processing of special-category data. None applies here: Outrun is a single-operator subscription app that processes health data only for the individual user who supplied it, and does not monitor anyone. Privacy matters are handled by the controller personally at [email protected].

Supervisory authority. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, https://www.aepd.es. You may complain to it, or to the supervisory authority of the country where you live or work.

What Outrun collects

Everything below is collected because a feature you use needs it. Nothing here is collected for advertising.

What Examples Why Linked to you
Health data Workouts, sleep, heart rate, steps, body weight and running routes read from Apple Health, with your permission To personalise your training plan and recovery guidance Yes
Fitness data Workouts, sets, reps and loads you log; sports and activities; food and macro entries The core function of the app Yes
Name The first name on your account To address you in the app and in coach replies Yes
Email address The address you sign up with Account creation, sign-in and essential service email Yes
User ID An internal account identifier To associate your data with your account across devices Yes
Photos Photos of meals, images you attach to a coach message, and your profile photo To estimate what you ate and to answer your questions Yes
Audio data Voice notes you record, and speech you dictate into the composer To turn what you say into a log entry or a coach message Yes
Purchase history Your subscription status, plan and renewal state To unlock the app and to support you when billing goes wrong Yes
Product interaction Which screens you open and which features you use To understand which parts of the app work and which don't Yes
Crash data Stack traces and device state at the moment of a crash To find and fix crashes No
Performance data Timings and error rates To find and fix slowness and failures No

Precise location. If you record an outdoor workout with GPS, Apple Health stores the route, and Outrun uploads a simplified version of it with that workout so your run detail is complete. That is precise location data and we declare it as such on our App Store privacy label. Outrun does not ask for location permission of its own, does not track you in the background, and only ever receives a route that is already attached to a workout you approved us to read.

We do not collect your contacts, your browsing history, or any advertising identifier.

What we deliberately do not do

Outrun does not display advertising, does not contain third-party advertising SDKs, and does not participate in cross-app tracking. NSPrivacyTracking is set to false in the app's privacy manifest, and no App Tracking Transparency prompt is shown because there is nothing to track.

Sensitive information

Two of the answers Outrun asks for can reveal more than fitness, so we call them out rather than leaving them inside "fitness data":

  • Dietary needs. Choosing halal or kosher can reveal religious belief. Choosing a medical exclusion can reveal a health condition.
  • Injuries and limitations. What you tell the coach to work around is health information about you.

Both are used for one purpose — so your plan and your meals do not suggest things you cannot or will not eat or do — and both are included in the context sent to the AI providers described below, because a plan that ignores them would be useless or unsafe. We do not use either for advertising, profiling or any decision with a legal effect, and we do not share them with anyone beyond the sub-processors listed here.

Both are special-category data under Article 9(1) GDPR — a dietary choice can reveal religious belief, and an injury is health data. We process them only on your explicit consent under Article 9(2)(a), given in two places: the consent text shown with the sign-up control, and the screen shown immediately before your first plan is generated, which states that your answers are sent to an AI provider and links to this page. Ticking through those screens is a specific, informed, affirmative act, and nothing in this category is processed before it.

You can withdraw that consent at any time by deleting your account, which destroys the underlying answers. Withdrawal does not affect processing carried out before you withdrew. If you withdraw, Outrun can no longer generate a personalised plan, because there is nothing left to personalise it from — that is a consequence of withdrawal, not a penalty for it.

Apple Health data

Health data gets its own section because it deserves stricter handling, and because Apple requires us to be explicit.

Outrun reads — only the categories you approve, and only after you grant permission in the Health permission sheet: workouts, sleep, heart rate, step count, body weight, and workout routes.

Outrun writes — workouts and body weight that you log inside Outrun are saved back to Apple Health so they count toward your Activity rings and stay consistent with your other apps. Entries Outrun creates are marked so it can find and remove them again if you delete the original.

Our commitments on health data, which mirror Apple's HealthKit requirements:

  • Health data is never used for advertising, marketing, or any similar service.
  • Health data is never sold to anyone, including data brokers and insurers.
  • Health data is never shared with third parties except the infrastructure processors listed below that store or process it strictly on our instructions.
  • Health data is not used for any purpose other than your own health, fitness and coaching inside Outrun.

You can withdraw Health access at any time in iPhone Settings → Apps → Health → Data Access & Devices → Outrun. Outrun remains fully usable with Health access denied; the plan simply relies on what you log by hand.

AI coaching and your data

Outrun's coach, its plan generation, and its food estimates are produced by large language models run by third-party providers, routed through OpenRouter. This is how that works.

  • We minimise what is sent. The context we build for a model call carries your first name, the training and nutrition figures relevant to the question, and the conversation itself. It does not carry your email address, your account identifier, or your authentication tokens.
  • We route to no-retention providers. Every model request Outrun makes sets a zero-data-retention flag, which restricts routing to providers that do not retain request data and do not train on it. This covers coach messages, plan generation, food extraction, safety checks, image analysis and speech-to-text, including the meal photos attached to a request.
  • Model output is generated, not verified. Coach replies, plans and calorie estimates are AI-generated and can be wrong. Outrun labels estimates as estimates.
  • Your logs are not training data. We do not use your content to train our own models, and we do not license it to anyone for that purpose.

Why we are allowed to process your data

Every purpose below has a lawful basis under Article 6 GDPR. Where the data is health data or otherwise special-category, it also has a condition under Article 9.

Purpose Article 6 basis Article 9 condition
Creating your account, signing you in, keeping it secure 6(1)(b) — performance of a contract
Building, storing and adapting your training and nutrition plan 6(1)(b) — performance of a contract 9(2)(a) — explicit consent
Reading Apple Health data you approve, and writing back what you logged 6(1)(b) — performance of a contract 9(2)(a) — explicit consent, given in Apple's own permission sheet and in the app
Dietary needs and injuries, so plans and meals work around them 6(1)(b) — performance of a contract 9(2)(a) — explicit consent
Coach replies, weekly reviews and food estimates produced by AI models 6(1)(b) — performance of a contract 9(2)(a) — explicit consent
Taking payment, managing your subscription and entitlements 6(1)(b) — performance of a contract
Keeping accounting, invoicing and tax records 6(1)(c) — legal obligation (Spanish commercial and tax law)
Crash reports, error and performance diagnostics 6(1)(f) — legitimate interests
Product analytics: which features are used 6(1)(f) — legitimate interests
Preventing abuse, fraud and rate-limit circumvention 6(1)(f) — legitimate interests
Establishing, exercising or defending legal claims 6(1)(f) — legitimate interests 9(2)(f) — legal claims
Keeping proof of which policy version you accepted 6(1)(c) — legal obligation (accountability, Article 5(2))

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. In short: the data is minimal and first-party, it is hosted in the EU, it is never used for advertising, never sold, never combined with data from other companies, and never used to profile you or make decisions about you. Analytics does not run at all until you have an account and have accepted the terms. You have an absolute right to object to processing based on legitimate interests — email [email protected] and we will stop, unless we can show compelling grounds that override your objection, which for analytics we would not attempt.

Where we rely on consent, you can withdraw it at any time, and withdrawing is as easy as giving it: revoke Apple Health access in iPhone Settings, or delete your account in the app. Withdrawal does not affect the lawfulness of processing before you withdrew.

Automated decisions and profiling

Outrun does not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. Your plan is generated automatically, but it is a suggestion: it has no legal or financial consequence, every change the coach proposes is presented for your approval before it is applied, and you can edit or ignore any of it. We do not use your data to score, rank, or categorise you, and we do not use it to decide whether you can buy or keep the subscription.

Before you have an account

Outrun builds you a plan at the end of the signup questions, before you create an account. To do that it sends your answers — including height, weight, injuries and dietary needs — to our API and on to a model provider. The screen before that tells you so, with links to this page and the Terms, and continuing is what starts it.

That request carries no name, no email and no account identifier, because none exist yet. Nothing from it is stored against a person unless you go on to create an account.

Who processes your data for us

We use a small number of vendors ("sub-processors"). Each one is contractually limited to processing your data on our instructions.

Sub-processor What it does What it touches
Supabase Database, authentication and file storage Account details and everything you log, including photos
Fly.io Hosts the API worker Data in transit through the API
OpenRouter Routes requests to model providers Coach messages, plan inputs, meal photos and audio sent for processing
RevenueCat Manages subscriptions and entitlements Purchase history and your user identifier
Apple HealthKit, StoreKit, sign-in and push notifications Health data on your device; payment and subscription data
Sentry Crash and error reporting Crash and performance diagnostics
PostHog Product analytics Which features are used, on an EU-hosted instance. Off until you create an account — see below

Analytics does not run until you have an account. Product analytics stays switched off from the moment the app launches and is only enabled once you have created an account and accepted the terms — so nothing is measured before you have been told what we collect. Signing out switches it off again.

We do not sell personal data, and we do not disclose it for cross-context behavioural advertising, under any definition used by US state privacy laws.

Where your data is stored, and when it leaves the EEA

Everything we store is stored in the European Economic Area. Specifically:

  • Supabase — your account, your logs and your uploaded photos — is hosted in eu-west-1 (Ireland).
  • Fly.io — the API that serves the app — runs in Paris (cdg).
  • PostHog — product analytics — is the EU instance at eu.i.posthog.com.

Some processing nonetheless involves a transfer outside the EEA, and we tell you which:

Processor Transfer Safeguard
OpenRouter and the model providers it routes to United States and possibly elsewhere, for the duration of the request Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), plus zero-data-retention routing so the request is not stored at the far end
RevenueCat United States Standard Contractual Clauses, and the EU–US Data Privacy Framework where the recipient is certified
Apple United States and Apple's global infrastructure Apple's own published transfer safeguards, including Standard Contractual Clauses
Sentry United States, where the EU region is not in use Standard Contractual Clauses

For every one of these we rely on Article 46(2)(c) GDPR. We have carried out a transfer risk assessment covering the destination country's laws on government access, the categories of data involved, and the supplementary measures in place — encryption in transit, minimisation of what is sent, and, for model requests specifically, a no-retention routing flag that prevents the content being stored or used for training. For UK users the same transfers are made under the UK International Data Transfer Addendum to the Standard Contractual Clauses.

What is never transferred. We do not send your email address, your account identifier or your authentication tokens to any model provider. Your Apple Health data stays on your device and in our EU database; it is not sent to a model provider except where a specific figure you asked about is included in the question you asked.

You can ask us for a copy of the safeguards we rely on by emailing [email protected].

How long we keep your data

  • Your account content — plans, logs, coach history, photos — is kept for as long as your account exists.

  • Raw AI-usage and analytics events are pruned automatically on a rolling 400-day window (about 13 months). Aggregated, non-identifying statistics may be kept longer.

  • Deleting your account removes your content, including uploaded photos in every storage bucket. This is immediate and cannot be undone.

  • Deleting your account is a hard delete. Your plans, workouts, food log, coach conversations, journal notes, body metrics, Apple Health imports, workout routes and every uploaded photo, attachment and voice note are destroyed, not merely detached from your name.

  • Three things survive, and none of them describe you. Records of AI usage and cost, records of subscription and payment events, and an audit trail of administrative actions are kept, because we are required to account for what we charged and what we spent. They are re-pointed at an anonymous placeholder, so what remains is "an account of unknown identity used N tokens on this date", with no way back to you.

  • Proof that you accepted these terms — which version you accepted and when — is retained for the same reason, because we need to be able to show that consent was given. It contains no other personal data.

  • Accounting, invoicing and tax records are kept for as long as Spanish law requires us to keep them — six years for commercial books and supporting documents under Article 30 of the Commercial Code, and four years for tax purposes under Article 66 of the General Tax Law, running from the end of the relevant period. These records show what was charged and when. They are kept whether or not you delete your account, because we are not permitted to destroy them on request.

  • Records kept to defend a legal claim are kept until the relevant limitation period expires, and then deleted.

The 400-day window above is a settled policy decision, not a default we have yet to think about: it is a little over thirteen months, which lets us compare a period against the same period a year earlier and no longer.

Your rights

Depending on where you live, you have some or all of the following rights: access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent.

You can exercise the two most important ones yourself, immediately, without asking us:

  • Export everything. In the app: avatar → Settings → Export my data. You get a single machine-readable JSON file containing your profile, goals, plans, workouts, food log, coach conversations, body metrics, subscription records and more.
  • Delete everything. In the app: avatar → Settings → Delete account.

In full, you have the right to:

  • be told what we hold about you and why (Articles 13–15);
  • have it corrected if it is wrong (Article 16);
  • have it erased (Article 17) — the in-app delete does this immediately;
  • restrict how we use it while a dispute about it is resolved (Article 18);
  • take it elsewhere in a machine-readable format (Article 20) — the in-app export does this;
  • object to processing based on legitimate interests (Article 21);
  • withdraw consent at any time, without affecting what was lawful beforehand (Article 7(3));
  • not be subject to solely automated decisions with legal or similarly significant effects (Article 22) — we make none, as explained above.

For anything the in-app controls do not cover, email [email protected]. We answer within one month, extendable by two further months for complex requests, in which case we will tell you inside the first month and say why. Exercising these rights is free; we may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and we will explain our reasoning if we ever do.

We may need to verify that the request is really coming from you before we act on it — usually by asking you to send it from the email address on the account.

Complaints. If you think we have handled your data badly, please tell us first so we can fix it. You do not have to: you can complain directly to the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, https://www.aepd.es, or to the supervisory authority where you live or work. UK users may complain to the Information Commissioner's Office at ico.org.uk. You also have the right to an effective judicial remedy under Article 79 GDPR.

If you are in the United States

These rights apply in addition to the above, under California's CCPA as amended by the CPRA and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and other states:

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have never done so. There is therefore no "Do Not Sell or Share My Personal Information" link, because there is nothing to opt out of.
  • We do not use or disclose sensitive personal information — which includes your health data — for any purpose other than performing the service you asked for, and none of the purposes that would trigger a right to limit its use under §1798.121.
  • You have the right to know, delete, correct and obtain a portable copy of your personal information, and the right not to be discriminated against for exercising any of them. The in-app export and delete controls serve these directly; for anything else, email [email protected].
  • You may use an authorised agent; we will ask for proof of authority.
  • We honour Global Privacy Control signals where we receive them. This website sets no cookies and runs no analytics, so there is nothing for a GPC signal to switch off here.

Notice of financial incentive: none. There is no loyalty programme, discount or reward tied to giving us data.

Age

Outrun is not intended for children. You must be at least 16 years old to create an account, and the app asks you to confirm this at signup. If we learn that we hold data from someone under that age, we delete it.

16 is deliberately the highest floor the GDPR contemplates. Article 8(1) sets the digital-consent age at 16 and lets member states lower it, but never raise it — some go down to 13, and Spain's own floor is 14 under Article 7 LOPDGDD. By requiring 16 everywhere we are at or above the threshold in every EU and EEA market, in the UK, and in the United States, where the relevant floor under COPPA is 13. No market requires a higher age than the one we apply, so this single rule is compliant across all of them without per-country logic.

We do not knowingly collect data from anyone below that age. If you believe a child has created an account, email [email protected] and we will delete it and the associated data.

Security

Data is encrypted in transit. Access to your rows in the database is enforced at the database level, so one account cannot read another's data. Access to production systems is limited to the people who need it.

Specifically: traffic is encrypted in transit with TLS; data at rest is encrypted by our hosting providers; row-level security is enforced in the database so one account physically cannot read another's rows; uploaded files are held in per-user storage paths with the same enforcement; and administrative access to production is limited to the controller.

No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs we will notify the Agencia Española de Protección de Datos (AEPD) without undue delay and, where feasible, within 72 hours of becoming aware of it, as Article 33 GDPR requires. Where the breach is likely to result in a high risk to your rights and freedoms, we will tell you directly and without undue delay under Article 34, and we will tell you what happened, what it means for you, and what we are doing about it.

This website

useoutrun.app is a static site. It sets no cookies, runs no analytics, embeds no third-party scripts, and loads its fonts from its own server rather than from a font CDN. Nothing you do here is tracked, which is why there is no cookie banner to dismiss.

Changes

If we change this policy in a way that materially affects you, we will tell you in the app before the change takes effect. The version and effective date are at the top of this page, and the app records which version you accepted.

Contact

Privacy questions: [email protected] Everything else: [email protected]