Privacy Policy

    Last updated: January 30, 2025

    Version: 2.0

    Effective Date: February 1, 2025


    1. Introduction

    PeakRunner Pty Ltd ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect your personal data when you use our mobile application and services.

    Key Points:

    • We collect health and fitness data with your explicit consent
    • We use AI to generate personalized training plans
    • We do NOT sell your personal data
    • You have comprehensive rights over your data

    2. Contact Information

    Data Controller:
    PeakRunner Pty Ltd
    Australia

    Privacy Officer:
    privacy@peakrunner.com

    Support:
    support@peakrunner.com

    For EU residents: Contact your local supervisory authority: https://edpb.europa.eu/about-edpb/board/members_en


    3. Information We Collect

    3.1 Account Information

    You provide:

    • Email address (required)
    • Password (encrypted, never stored in plain text)
    • Name (first and last)
    • Profile photo (optional)

    Profile data:

    • Age, gender (optional)
    • Fitness level (beginner, intermediate, advanced, elite)
    • Running experience and goals
    • Preferred race distance (5K, 10K, half-marathon, marathon, ultra)
    • Training preferences and schedule
    • Injury history (optional)

    3.2 Health and Fitness Data ⚠️ Special Category (GDPR Article 9)

    With your explicit consent, we collect from:

    Apple Health (iOS):

    • Workouts (running, walking, cycling, hiking)
    • Duration, distance, calories
    • Daily step count
    • Heart rate data
    • Sleep sessions

    Google Health Connect (Android):

    • Exercise sessions (running, walking, cycling)
    • Duration, distance, calories
    • Daily step count
    • Heart rate data
    • Sleep sessions

    We also write data back:

    • Completed PeakRunner runs saved to Apple Health/Health Connect

    How we obtain consent:

    During onboarding, you see a "Health Data Permissions" screen explaining what we collect, why, and how to revoke access. You explicitly choose "Grant Health Permissions" or "Skip for Now."

    How to withdraw consent:

    Settings > Privacy > Revoke Health Data Access

    Legal Basis:

    Explicit consent (GDPR Article 6.1.a and Article 9.2.a)

    3.2.1 Garmin Connect™ Data

    What we collect (with your explicit consent):

    When you connect your Garmin Connect™ account, we access data from your Garmin devices via Garmin's Activity API — completed activities and their detailed tracks: activity type, start time, duration, distance, pace/speed, heart rate, elevation, cadence, calories, GPS route, and the Garmin device model. On connect we import up to 14 days of activity history. We also use Garmin's Training API to send planned workouts from your PeakRunner training plan to your Garmin device.

    How we obtain consent:

    You authorize the connection through Garmin's OAuth2 sign-in and choose which permissions to grant on Garmin's consent screen. You can disconnect at any time in Settings > Connected Services, or revoke access from your Garmin Connect account; we process Garmin's deregistration and stop receiving your data.

    How we use it:

    To match your Garmin activities to planned sessions, generate AI coaching feedback and performance metrics, and sync planned workouts to your watch.

    Processing and storage (including third-party AI):

    Garmin data is stored in Microsoft Azure (Cosmos DB), encrypted at rest (AES-256), and processed by Microsoft Azure OpenAI to produce AI coaching insights (see Sections 6.1 and 8). Your Garmin data is not used to train Microsoft's models, is not sold, and is not shared with advertisers. Retention follows Section 9.

    Legal Basis: Explicit consent (GDPR Article 6.1.a and Article 9.2.a)

    3.3 Location Data (GPS)

    During active runs only:

    • GPS coordinates (every ~1 second)
    • Route polylines
    • Elevation data
    • Speed/pace calculations
    • City, state, country (reverse geocoded)

    Important: Location is ONLY tracked during active run sessions, not when app is closed or in background.

    Location Privacy Controls:

    • Privacy Zones: You can hide the start and end points of your activities by setting privacy zones around your home, work, or other sensitive locations (coming soon)
    • Map Visibility: Choose who can see your activity maps (Everyone, Followers, Only You)
    • Address Protection: Activities will not display your exact start/end address publicly

    How to manage: Settings > Privacy > Location Privacy

    Permissions:

    • iOS: "Location When In Use"
    • Android: "Fine Location"

    Legal Basis:

    Consent and contract performance

    3.4 Activity Data

    Each tracked run includes:

    • Activity name, type, start/end time
    • Duration, distance, pace, speed
    • Elevation gain
    • Heart rate (if available)
    • Calories burned
    • GPS route
    • Kilometer/mile splits
    • Weather, notes (optional)
    • AI-generated feedback

    3.5 Training Plan Data

    • Goals and target dates
    • AI-generated weekly training schedules
    • Planned sessions (type, distance, pace)
    • Completion status
    • AI coaching recommendations

    3.6 AI Coaching Interactions

    • Messages to AI coach
    • Questions about training, injury, nutrition
    • AI responses and recommendations

    3.7 Device & Technical Data

    Automatically collected:

    • Device ID (unique per device)
    • Device type, OS version
    • App version
    • IP address (security, regional pricing)
    • Request logs (debugging)

    Legal Basis: Legitimate interests (security, fraud prevention)

    3.8 Payment Data (via Stripe)

    We do NOT store credit card numbers.

    We receive from Stripe:

    • Customer ID
    • Subscription status (active, canceled, etc.)
    • Billing period dates
    • Plan type

    Legal Basis: Contract performance

    3.9 Usage Analytics

    • Screens viewed
    • Features used
    • Error logs and crash reports
    • Performance metrics

    Purpose: Service improvement (anonymized data)

    Legal Basis: Legitimate interests


    4. How We Use Your Information

    Core Services:

    • Generate personalized AI training plans
    • Track runs with GPS and live metrics
    • Sync data with Apple Health/Health Connect
    • Provide AI coaching feedback
    • Calculate performance metrics
    • Display running routes on maps
    • Send training reminders

    Payments:

    • Manage subscriptions via Stripe
    • Process billing

    Communications:

    • Service emails (verification, password reset)
    • Support responses
    • Important updates
    • Training milestones

    Improvements:

    • Analyze usage (anonymized)
    • Fix bugs
    • Develop features
    • Improve AI models (aggregated, anonymized data)

    Aggregated & Anonymized Data:

    • We create aggregated, anonymized data from user activities (e.g., average training intensity, popular running routes in cities, seasonal trends)
    • This data cannot identify you individually
    • We may use aggregated data to:
      • Publish insights and trends (e.g., blog posts about training patterns)
      • Improve AI training recommendations
      • Share with research partners (academic studies, sports science)

    Important: Once anonymized, this data is no longer personal data under GDPR and may be retained indefinitely

    Legal Compliance:

    • Respond to legal requests
    • Prevent fraud
    • Enforce Terms of Service
    • Tax/accounting records

    4.1 Legal Basis for Processing (GDPR)

    Consent (Article 6.1.a):

    • Health and fitness data from Apple Health/Google Health Connect
    • Special category health data (Article 9.2.a)
    • Location tracking during runs
    • Marketing communications (if opted in)

    Contract Performance (Article 6.1.b):

    • Account management
    • AI training plans and coaching
    • Activity tracking
    • Core app functionality
    • Subscription management

    Legitimate Interests (Article 6.1.f):

    • Analytics (anonymized)
    • Fraud prevention and security
    • Customer support
    • Error tracking
    • Product development

    Legal Obligation (Article 6.1.c):

    • Tax and accounting compliance
    • Legal requests
    • Record keeping

    5. AI and Automated Decision-Making

    ⚠️ GDPR Article 22 Disclosure

    What the AI does:

    • Generates personalized training plans
    • Provides coaching feedback
    • Suggests warm-ups and recovery advice
    • Answers training questions

    How it works:

    • Analyzes your profile, goals, and activity history
    • Applies sports science and training principles
    • Personalizes recommendations based on your data
    • Balances training stress with recovery

    Significance:

    • AI-generated plans affect your daily workout recommendations
    • Following AI advice impacts training intensity and volume
    • AI feedback influences performance understanding

    Your rights:

    • Request human review: support@peakrunner.com
    • Manually adjust or ignore AI recommendations
    • Request explanation of AI logic
    • Opt-out (track manually without AI plans)

    Human Oversight: Our support team can review AI recommendations upon request.

    5.1 AI Training and Improvement

    How we improve our AI models:

    • We use aggregated, anonymized activity data to improve training recommendations for all users
    • Your individual data is used to personalize YOUR experience but does NOT train our underlying AI models
    • Azure OpenAI does NOT use your data to train Microsoft's models (per Azure OpenAI terms)

    What data is used for AI improvement:

    • Aggregated patterns: "runners at similar fitness levels respond better to X type of workout"
    • Anonymized trends: "recovery patterns by age group and training volume"
    • General feedback: "users find Y type of coaching advice more helpful"

    What data is NOT used:

    • Your individual health metrics to train models for other users
    • Personal identifiers or sensitive health data for model training
    • Your chat conversations beyond your personalized coaching context

    Your control:

    • Opt out of contributing anonymized data: Settings > Privacy > AI Training (coming soon)
    • This does not affect your personalized coaching (which uses your own data)

    6. Data Sharing

    We do NOT sell your personal data.

    6.1 Third-Party Processors:

    Stripe (https://stripe.com/privacy)

    • Payment processing
    • Data: Email, name, payment info (handled by Stripe)
    • Location: Global infrastructure

    Microsoft Azure (https://privacy.microsoft.com)

    • Cloud infrastructure and databases
    • Data: All user data and activity data
    • Location: Azure regions

    Azure OpenAI (https://privacy.microsoft.com)

    • AI coaching and training plans
    • Data: Profile, activities (including Garmin activity data), training history, chat messages
    • Your data is NOT used to train Microsoft's models
    • Location: Microsoft Azure data centers

    Expo (https://expo.dev/privacy)

    • App infrastructure and OTA updates
    • Push notification delivery
    • Data: Device tokens, app version, crash logs
    • Location: Global CDN

    Google Maps API (https://policies.google.com/privacy)

    • Map display (Android only)
    • Data: Map tile requests (no personal data sent)
    • Location: Google infrastructure

    6.2 OAuth Authentication:

    Google Sign-In (https://policies.google.com/privacy)

    Data: Email, name, profile photo (only if you sign in with Google)

    Microsoft OAuth (https://privacy.microsoft.com)

    Data: Email, name (only if you sign in with Microsoft)

    Apple Sign In (Apple Privacy Policy)

    Data: Email (optional relay), name (only if you sign in with Apple)

    6.3 Health Platforms:

    Apple Health (iOS)

    • You grant permissions to read/write
    • Apple's privacy policy applies
    • We don't share your health data with other third parties

    Google Health Connect (Android)

    • You grant permissions to read/write
    • Google's privacy policy applies
    • We don't share your health data with other third parties

    Garmin Connect (https://www.garmin.com/privacy/connect/)

    • You authorize access via Garmin OAuth2 and choose which permissions to grant
    • We receive activity and workout data from your Garmin devices (Activity API) and send planned workouts to your device (Training API)
    • Garmin's privacy policy applies to Garmin Connect; disconnect anytime in Settings > Connected Services or from your Garmin account
    • See Section 3.2.1 for how this data is used, processed, and stored

    6.4 Important Third-Party Disclaimer

    ⚠️ We are not responsible for third-party practices:

    When you interact with third parties through PeakRunner (OAuth providers, health platforms, payment processors), their privacy policies and terms apply to their services. We encourage you to review their policies:

    Third-party risks you should know:

    • OAuth providers (Google, Microsoft, Apple): Have access to your email and name when you use their sign-in
    • Health platforms (Apple Health, Health Connect): Store your health data on your device with their own security and privacy controls
    • Payment processor (Stripe): Handles payment information according to their PCI-compliant practices
    • Map providers (Google Maps on Android): May log map tile requests according to their policies

    Our responsibility ends where theirs begins:

    • We select reputable, GDPR-compliant processors
    • We have Data Processing Agreements (DPAs) with commercial processors
    • We limit data shared to what's necessary
    • However, we cannot control their internal practices, security, or how they use data within their terms

    What you should do:

    • Review privacy policies of services you connect (links provided in Sections 6.1-6.3)
    • Understand what permissions you grant to OAuth and health platforms
    • Contact third parties directly for their data practices
    • Disconnect services you no longer trust: Settings > Connected Services

    6.5 Legal Disclosures:

    We may disclose data to:

    • Comply with legal obligations (court orders, subpoenas)
    • Protect our legal rights and enforce Terms of Service
    • Prevent fraud, security threats, or illegal activity
    • In business transfers (merger, acquisition - with notice to you)
    • With your explicit consent

    We will notify you of legal requests unless prohibited by law.

    6.6 No Third-Party Advertising:

    • We do NOT share data with advertisers
    • We do NOT use tracking pixels or ad networks
    • We do NOT sell or rent personal data

    7. International Data Transfers

    Processing Locations:

    • United States (Azure infrastructure)
    • Europe (Azure regions for EU users)
    • Australia (company headquarters)

    7.1 For EU Residents:

    Standard Contractual Clauses (SCCs):

    • Approved by European Commission
    • In place with Azure and Expo
    • Provides equivalent EU-level protection

    Your rights:


    8. Data Security

    8.1 Technical Measures:

    Encryption:

    • Data in transit: TLS 1.3 (HTTPS)
    • Data at rest: AES-256
    • Passwords: bcrypt hashing

    Access Controls:

    • Multi-factor authentication (admin)
    • Role-based access controls
    • Least privilege principle
    • Regular access reviews

    Infrastructure:

    • Secure Microsoft Azure hosting
    • Firewall protection
    • DDoS mitigation
    • Regular security updates
    • Network segmentation

    8.2 Organizational Measures:

    • Regular security audits
    • Vulnerability scanning
    • Incident response procedures
    • 72-hour breach notification (GDPR)
    • Staff training
    • Confidentiality agreements

    8.3 Your Responsibility:

    • Use strong, unique passwords
    • Don't share credentials
    • Log out of shared devices
    • Report suspicious activity: security@peakrunner.com

    Note: No system is 100% secure. We strive to protect your data but cannot guarantee absolute security.


    9. Data Retention

    Data TypeRetention PeriodReason
    Active accountDuration of serviceOngoing service delivery
    Deleted account30 daysAccount recovery period
    Health data7 years after deletionMedical data standards
    Activity historyWhile account activeTraining analysis
    AI interactionsWhile account activePersonalized coaching
    Payment records7 yearsLegal/tax requirements
    Audit logs6-12 monthsSecurity and compliance
    Backups90 daysDisaster recovery
    Anonymized analyticsIndefinitelyProduct improvement

    9.1 Retention Exceptions

    We may retain certain data beyond the standard periods in these situations:

    1. Legal obligations: Tax records, financial transactions, and audit logs retained as required by law (up to 7 years)
    2. Ongoing legal proceedings: Data relevant to litigation, investigations, or regulatory inquiries retained until resolution
    3. Security incidents: Logs and data related to security breaches or fraud investigations retained for forensic analysis
    4. Unpaid debts: Account information retained until outstanding subscription fees are resolved
    5. Terms violations: Records of users banned for Terms of Service violations retained to prevent re-registration
    6. Anonymized research: Once truly anonymized (cannot be linked back to you), data may be retained indefinitely for research and analytics
    7. Backup systems: Data in encrypted backups purged within 90 days but not immediately on deletion

    Important: These exceptions apply only when legally required or necessary for legitimate purposes. We minimize retention wherever possible.

    9.2 Account Deletion Process:

    1. 30-day grace period: Data soft-deleted, can be recovered
    2. After 30 days: Permanent deletion from production
    3. Backups: Deleted within 90 days
    4. Exception: Anonymized analytics (no PII) may be retained

    9.3 What Happens After Deletion

    What gets deleted immediately:

    • Your account profile and personal information
    • Your private activities and training plans
    • Your chat history with AI coach
    • Your saved preferences and settings
    • Access to your account (cannot log in)

    What may persist (anonymized):

    • Aggregated, anonymized statistics (e.g., contribution to "average runner pace" calculations)
    • De-identified research data (cannot be linked back to you)
    • Cached data in third-party systems (purged per their retention policies)

    What may persist (with identifiers) temporarily:

    • Audit logs for security/compliance (6-12 months)
    • Financial records for tax purposes (7 years)
    • Backup systems (up to 90 days)
    • Legal hold data (if applicable)

    Content you shared with others:

    • If you participated in group challenges or shared activities publicly (future feature), those interactions may remain visible but your profile will show as "Deleted User"
    • Other users' copies of your shared data (e.g., screenshots) are beyond our control

    Third-party data:

    • Data you authorized to health platforms (Apple Health, Health Connect) remains on your device until you delete it there
    • OAuth providers (Google, Microsoft, Apple) retain your authentication history per their policies - disconnect via their account settings

    To delete account:

    • Settings > Account > Delete Account
    • Or email: privacy@peakrunner.com
    • You'll receive confirmation within 48 hours

    10. Your Privacy Rights

    10.1 All Users:

    Right to Access (GDPR Article 15)

    Right to Rectification (Article 16)

    Right to Erasure (Article 17)

    • Delete your account and data
    • How to exercise: Settings > Account > Delete Account

    Right to Restriction (Article 18)

    Right to Data Portability (Article 20)

    • Export data in JSON format
    • Includes: profile, activities, training plans, chats
    • How to exercise: privacy@peakrunner.com

    Right to Object (Article 21)

    Right to Withdraw Consent

    • Health data: Settings > Privacy > Revoke Health Data Access
    • Location: Device Settings > PeakRunner > Location
    • Marketing: Unsubscribe links or Settings > Notifications

    Important: Withdrawal doesn't affect prior lawful processing

    Re-consent Rate Limiting:

    • If you decline health data permissions, we will not ask again for 12 months unless you initiate the permission flow
    • This prevents repeated consent requests that could be perceived as coercive
    • You can manually grant permissions anytime: Settings > Privacy > Health Data Permissions

    10.2 Automated Decision-Making Rights (Article 22):

    • Not be subject to automated decisions with significant effects
    • Request human intervention and review
    • Express your point of view
    • Contest automated decisions
    • Contact: support@peakrunner.com

    10.3 EU Residents (GDPR):

    Right to Lodge Complaint:

    10.4 California Residents (CCPA):

    Right to Know:

    • Categories collected: See Section 3
    • Sources: See Section 3
    • Business purposes: See Section 4
    • Third parties: See Section 6

    Right to Delete:

    • Request deletion via Settings or privacy@peakrunner.com
    • 30-day recovery period
    • Exceptions: legal obligations, fraud prevention

    Right to Opt-Out of Sale:

    • We do NOT sell personal data
    • No action required

    Right to Non-Discrimination:

    • Same service quality for all
    • No discrimination for exercising rights

    How to exercise: privacy@peakrunner.com or [PHONE NUMBER TO ADD]

    Verification: We may request info to verify identity

    Authorized Agents: May designate agent with written authorization


    11. Children's Privacy

    Minimum Age: 13 years old

    • We don't knowingly collect data from children under 13
    • Users confirm age 13+ during registration
    • EU: Some countries require 16+ or parental consent under GDPR Article 8

    11.1 Age-Differentiated Protections (Ages 13-17)

    For users aged 13-17, we provide enhanced privacy protections:

    Default Privacy Settings:

    • Activity visibility: "Only Me" (not public)
    • Profile visibility: Private
    • Location: Start/end points hidden by default

    Important: Users can change these settings, but we recommend keeping enhanced protections until age 18

    Health Data Restrictions:

    • Heart rate monitoring: Minimum age 16 (due to medical device considerations)
    • Sleep tracking: Requires parental acknowledgment for ages 13-15
    • Training intensity: AI limits high-intensity recommendations for growing athletes

    Parental Rights (Ages 13-15):

    • Parents/guardians can request to review their child's data
    • Parents can request account deletion on behalf of minor
    • Parents should supervise minor's use of fitness apps
    • Contact: privacy@peakrunner.com with proof of guardianship

    Age Verification:

    • We may request age verification if we suspect account holder is under 13
    • If unable to verify, we reserve the right to suspend access until verification

    11.2 For Parents/Guardians

    If your child under 13 created an account:

    • Email: privacy@peakrunner.com immediately
    • We'll promptly delete the account and all associated data
    • Right to review and delete child's information

    Supervising teens (13-17):

    • Discuss appropriate sharing and privacy settings
    • Review who can see their activities and location
    • Understand health data they're authorizing PeakRunner to access
    • Monitor training intensity to prevent overtraining
    • Consider enabling "private account" mode

    Red flags to watch for:

    • Excessive training volume or intensity
    • Sharing location publicly
    • Interacting with unknown users (when social features launch)

    12. Device Permissions

    12.1 iOS Permissions:

    Location (When In Use):

    • Purpose: Track runs with GPS, record routes
    • When: Only during active run sessions
    • Manage: iOS Settings > PeakRunner > Location

    Health (HealthKit):

    • Purpose:
      • Read: Import workouts, steps, heart rate, sleep
      • Write: Save runs to Apple Health
    • When: With explicit consent, background sync every 15+ min
    • Manage: iOS Settings > Health > Data Access & Devices > PeakRunner

    Notifications:

    • Purpose: Training reminders, achievements, updates
    • When: Based on training schedule
    • Manage: iOS Settings > Notifications > PeakRunner

    Camera (Optional):

    • Purpose: Profile photo
    • When: Only when you choose to add photo
    • Manage: iOS Settings > PeakRunner > Camera

    12.2 Android Permissions:

    Location (Fine/Coarse):

    • Purpose: Track runs with GPS, record routes
    • When: Only during active run sessions
    • Manage: Android Settings > Apps > PeakRunner > Permissions > Location

    Health Connect:

    • Purpose: Read/write exercise, steps, heart rate, sleep
    • When: With explicit consent, background sync
    • Manage: Health Connect Settings > App Permissions > PeakRunner

    Notifications:

    • Purpose: Training reminders, achievements
    • When: Based on training schedule
    • Manage: Android Settings > Apps > PeakRunner > Notifications

    Camera (Optional):

    • Purpose: Profile photo
    • When: Only when you choose
    • Manage: Android Settings > Apps > PeakRunner > Permissions > Camera

    Internet/Network:

    • Purpose: Sync data, access maps
    • Required: Yes

    12.3 Background Processing:

    Health Data Sync:

    • Background sync every 15+ minutes (system controlled)
    • Minimal battery impact

    Location:

    • Only during active run sessions
    • NOT tracked when app closed (except during runs)
    • GPS for accuracy

    Push Notifications:

    • Training reminders per schedule
    • Achievement celebrations
    • Service updates

    13. Cookies and Tracking

    Mobile App:

    • No cookies
    • No third-party ad trackers
    • No data sales to advertisers

    Local Storage:

    • Cached activities, plans, settings
    • Offline access
    • Cleared on app uninstall

    Analytics:

    • Anonymized usage data
    • No personally identifiable information
    • Service improvement only

    Website (if applicable):

    • Essential cookies for functionality
    • No advertising or tracking cookies
    • Analytics with consent

    14. Changes to This Policy

    14.1 Updates:

    We may update for:

    • Changes in data practices
    • Legal requirements
    • Clarity improvements
    • New features

    14.2 Notice:

    Material changes (affect rights significantly):

    • Email notification
    • In-app notification
    • Website notice
    • 30 days before effective (where required)

    Non-material changes:

    • Updated "Last updated" date
    • Release notes

    14.3 Your Options:

    14.4 Version History:

    • Current: 2.0 (effective February 1, 2025)
    • Previous: 1.0 (effective January 30, 2025)

    15. Jurisdiction-Specific Provisions

    15.1 EU Residents (GDPR):

    15.2 California Residents (CCPA/CPRA):

    • Categories collected: Section 3
    • Sources: Section 3
    • Business purposes: Section 4
    • Third parties: Section 6
    • Right to delete: Settings or privacy@peakrunner.com
    • We do NOT sell data
    • Non-discrimination guaranteed
    • Contact: privacy@peakrunner.com, [PHONE NUMBER]
    • Shine the Light: No data sharing for direct marketing

    15.3 UK Residents:

    15.4 Australian Residents:

    15.5 Other Jurisdictions:


    16. Additional Information

    16.1 Third-Party Links:

    • Not responsible for third-party practices
    • Review their privacy policies
    • This policy applies to PeakRunner only

    16.2 Business Transfers:

    In merger/acquisition/sale:

    • Data may transfer to new owner
    • Email and in-app notification
    • New owner must honor this policy
    • Right to delete before transfer

    16.3 Data Accuracy:

    Your responsibility:

    Our commitment:

    • Process in good faith
    • Correct inaccuracies upon request

    16.4 Data Minimization:

    • Collect only necessary data
    • No excessive data collection
    • Optional fields clearly marked
    • Minimal profile info required

    16.5 Anonymization:

    For analytics and AI improvement:

    • Remove PII where possible
    • Aggregated data for service improvement
    • Anonymized data can't be linked to you
    • May be retained indefinitely

    Acceptance

    By creating an account, you acknowledge:

    • You've read and understood this policy
    • You agree to data collection as described
    • You understand your rights
    • You can withdraw consent or delete account anytime

    Thank you for trusting PeakRunner with your fitness journey and personal data.