This policy explains data processing in the Runbay mobile app and how its static website differs. Legal bases, transfers and data subject rights are set out in the Data Protection Notice. Accepting this policy does not replace explicit consent where separate consent is required.
This document is based on features present in the current source code. It does not claim that data from inactive integrations is collected today or that production infrastructure has been audited.
SECTION 02
Accounts and sessions
Runbay uses Apple or Google sign-in. Your selected provider authenticates you, and the response is converted into a Runbay session through Supabase. The provider’s name and email may be used for account operations. An Apple private relay email may be used where provided.
The Runbay interface does not request your Google or Apple password. Access and refresh tokens are stored in app storage on your device to keep you signed in. Closing your identity provider account or uninstalling the app is not the same as deleting your Runbay account.
SECTION 03
Profile, measurements and recommendations
Your initial profile uses display name, birth year, height, weight, gender preference, experience level, goal, training setting and weekly day preference. You may choose not to disclose gender. Body fat percentage is an optional additional measurement.
Program matching ranks candidates using rules based on goal, level, setting and weekly training days. Matching inputs, candidates, scores and recommendations are recorded. Collecting height, weight or birth year does not mean every field is used in current matching calculations. Recommendations are not medical fitness assessments or examinations by a personal trainer.
SECTION 04
Workout and performance records
Sessions you start may contain exercises, sets, reps, weight, warm-ups, effort and timing. Records are used to calculate volume, active time, consistency, estimated one-rep maximum and personal bests. Results depend on the accuracy of inputs and calculation methods.
Do not enter other people’s information, medical reports or unnecessary sensitive details in notes. The service is not presented as reliably filtering sensitive information from free text.
SECTION 05
GPS, background location and maps
Pre-run signal checks and outdoor runs obtain latitude, longitude, timestamps, accuracy, speed and altitude from device location services. These produce routes, distance, pace, moving time and kilometer splits. Routes and start coordinates may be sent to the server as part of a running record.
Background location permission supports recording a run you started while the screen is off. It is not authorization for general continuous tracking. Ending a recording and revoking device permission are separate controls; revoking permissions does not automatically delete previous records.
Routes use the device’s mapping infrastructure. The map provider may receive the geographic area to display and connection information. A share card can show the shape of a route without a map background; this does not make it anonymous.
SECTION 06
Notifications and visible content
Enabling workout reminders stores a push token, device platform and registration time on the server. Notifications use Expo and the device platform’s delivery infrastructure. The planned session title and display name may appear in the reminder; lock-screen previews can expose this information to people who see your phone.
To stop notifications entirely, use the operating system’s Runbay notification settings. The in-app toggle and operating system permission are separate controls. Disabling notifications does not delete your account or activity history.
SECTION 07
Device storage and synchronization
Runbay stores sessions, sets, GPS checkpoints and a sending queue in a local database to preserve records during network interruptions. Session information and some preferences are stored separately in app storage. Eligible records are sent to your account when connectivity returns.
Sign-out and account deletion include operations to clear local activity tables. Operating system backups, temporary share files and copies sent to other apps are outside the same scope. Screen locks and operating system updates are important on shared devices.
No commitment is made that local data is encrypted with a dedicated application key or that the service uses end-to-end encryption. Security statements are limited to verifiable practices.
SECTION 08
Sharing and third-party content
Run sharing converts your selected card into an image on the device and opens the system share menu. The route and performance values in the image are sent to your selected app or person by your action. The current version does not provide a public user feed or automatic social posting.
Check the card and recipient before sharing. Route start and finish points can reveal places such as your home or workplace. Deleting your Runbay account does not recall images sent to others.
External links such as exercise videos may open another browser or service. Accounts, cookies and data use there are also subject to that provider’s terms.
SECTION 09
Health platforms and inactive features
The reviewed mobile version does not actively read data from Apple Health/HealthKit or Health Connect. A server interface accepting imports and fields such as heart rate or calories do not mean the mobile app currently reads those data from the device.
Before these integrations are offered, data types, purposes, permissions, explicit consent requirements and deletion behavior must be explained separately. The current code did not reveal an advertising network, behavioral advertising profile, payment card collection or a flow sending workout data to a generative AI service.
SECTION 10
Account deletion and consent controls
You can initiate account deletion on the mobile app’s Delete my account screen by entering the required confirmation (SİL in Turkish). The main account and related records enter the deletion flow. Once completed, the same history cannot be recovered through the app. This is distinct from canceling a workout or uninstalling the app.
Canceling a workout currently changes its status or visibility; it does not physically delete the server record. Successful account deletion removes related app records from the primary database but does not simultaneously erase backups and provider logs. Retention and request details appear in the Data Protection Notice.
The right to withdraw health data consent cannot be reduced to account deletion. As the current version lacks a separate withdrawal screen, the operator needs a functioning request channel and a process to stop processing.
SECTION 11
Security and access limitations
The app is designed to provide access to your own account records. Server requests use session authentication and user-specific record checks, with rate limits. Server logging rules remove authorization and cookie headers.
These measures do not mean the infrastructure has passed an independent security audit, that all error logs are free of personal data or that incidents are impossible. Backups, authorized staff access, retention periods and breach response procedures need separate confirmation by the operator.
SECTION 12
Website, age requirement and contact
The website code does not connect to mobile accounts and contains no signup form, advertising tracker or analytics code. Hosting access controls and technical logs are considered separately. See the Cookie Policy for details.
The mobile app is designed for people aged 18 or over. A birth-year check is not age verification using identity documents. If an account belonging to someone under 18 is identified, the controller should be notified.
Use the verified request channels in this document’s identity section for privacy requests. The policy is updated when providers, purposes or features change; changes requiring explicit consent require separate appropriate action.