Privacy Policy for Run Analytics
Updated 4 September 2026.
Plain-language summary: Run Analytics keeps its main workout history and analysis on your device. Apple Health and Health Connect data are read and processed on the device. If you choose to connect Garmin, a secure service must process Garmin authorization and the workouts you request. We do not sell health data or use it for advertising.
1. Scope
This policy explains how the Run Analytics mobile apps for iOS and Android and the run.analyticszone.app website handle information. Run Analytics is a wellness and sports-analysis product, not a medical device.
The controller is ArnoHealth S.L., Gran Via de les Corts Catalanes 699, 2-2, 08013 Barcelona, Spain. Contact: [email protected].
2. Data processed on your device
With your permission, Run Analytics reads running workout information from Apple HealthKit on iOS or Health Connect on Android. Depending on what your device provides, this can include exercise sessions, dates and times, duration, distance, speed or pace, heart rate, energy, splits and route information.
The app uses these records to show workout history, pace and split analysis, Critical Pace, training zones, rTSS, CTL, ATL, TSB, trends and best efforts. Platform-health records and the app's main analysis database are processed and stored locally on your device. Run Analytics requests read-only access and does not sell this information or use it for advertising.
You can change Apple Health or Health Connect permissions in your device settings. Removing permission stops future access but does not automatically delete records already stored in the app's local database.
3. Optional Garmin connection
Garmin sync is optional. If you connect it, Run Analytics uses a backend service to complete Garmin authorization and retrieve the workouts you request. The service may process:
- a random per-installation identifier generated by Run Analytics;
- Garmin account and authorization identifiers and OAuth tokens;
- connection status, synchronization cursors and technical timestamps;
- running workout fields such as activity identifier, date, duration, distance, heart rate, energy and splits; and
- route points when available.
This information is used only to provide Garmin connection, import, deduplication and route delivery. It is not used for advertising and is not sold. Backend requests use encrypted transport.
In the update that includes “Withdraw Garmin consent and delete server data” (version 2.25.1), this control stops app access and, after a successful online request, deletes this installation's active Garmin connection records, credentials, imported server workouts and route caches. Local workouts remain. The installation identifier stays on your device so failed deletion requests can be retried. Older versions do not provide the same complete server deletion: update when available or contact us. Uninstalling alone does not delete server data. You can also revoke authorization in Garmin account settings. For deletion assistance, contact [email protected]; never send passwords or security codes.
Version 2.25.1 introduces an explicit, initially unchecked consent control before optional Garmin server access, including after upgrading. Garmin processing includes background or automatic synchronization while connected. Declining does not prevent on-device Apple Health or Health Connect use. Consent version and acceptance time are stored on the device; withdrawal is available in Data sources.
4. Purchases
Subscriptions and other purchases are processed by Apple or Google. Run Analytics receives product, transaction and entitlement information needed to unlock access, but does not receive your full payment-card details. Apple's or Google's privacy terms apply to their processing.
5. Website analytics and contact
The Run Analytics website loads Google Analytics only after you accept optional analytics. Website analytics can include page views, referral information, approximate location derived from IP address, device/browser information and interaction events. This website data is separate from the workout data stored by the mobile app and is not used to build an advertising profile from your health information.
If you use the contact form, the name, email address, subject, message and technical anti-spam information you submit are sent through Web3Forms so that we can answer you. Do not include health records, passwords or security codes in the form.
6. Legal bases, retention, providers and transfers
Device health permissions and optional Garmin processing are based on your choice and explicit consent. We use purchase and entitlement information to provide the service you request. Website analytics is based on consent. Contact requests are handled to answer your request and on our legitimate interest in providing support. Security logs are processed on our legitimate interest in protecting the service.
Local app data remains until cleared or uninstalled, subject to the operating system and backups you control. Active Garmin data remains until a successful deletion request as described above; removing permissions or uninstalling alone is not server deletion. OAuth authorization attempts are valid for about ten minutes; this does not mean every stored record is deleted at that time. Ordinary Google Cloud logs have a 30-day retention setting; mandatory cloud audit logs have 400 days. These may contain request IP addresses, technical identifiers, timestamps and errors. Backup copies are not individually erased by the app's disconnect request and remain until the provider's backup rotation; contact us for the arrangements applicable to your request. Support correspondence is retained as needed to resolve the request and handle related legal obligations or disputes.
The Garmin API runs on Google Cloud Run in Belgium, with active PostgreSQL records hosted by Supabase in the United Kingdom. Cloudflare serves the website; Google Analytics handles consented website statistics; Google Fonts may receive your IP address and browser request to display web fonts; Web3Forms delivers contact forms. These providers may use infrastructure or support teams outside the EEA. Their service-specific data-processing and transfer terms apply; contact us to request details of the safeguards applicable to your data. Apple, Google and Garmin also process information under their own terms. Older app versions may send crash and performance diagnostics to Sentry; app-owned Sentry reporting is disabled starting in version 2.25.1.
7. Your choices and rights
- Revoke Apple Health or Health Connect access in device settings.
- Disconnect Garmin from Run Analytics and from your Garmin account settings.
- Delete local app data by using the operating system's clear-data option where available or by uninstalling the app.
- Request access to or deletion of server-side Garmin data by contacting us.
- Use Privacy choices on the website to accept or decline optional analytics at any time.
Where applicable, you may request access, correction, deletion, restriction, objection and portability, and withdraw consent at any time without affecting earlier lawful processing. You may also complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
We may ask for enough information to match and verify a request. We will not ask for your Garmin password, Apple ID password, Google password, MFA code or recovery code.
8. Children
Run Analytics is not directed to children under the minimum age required to consent to data processing in their country. If you believe a child has provided information through optional Garmin sync or the website, contact us so we can investigate and delete it where required.
9. Security and changes
We use reasonable technical and organizational safeguards, but no storage or transmission system is completely secure. We may update this policy when features, providers or legal requirements change. The date above identifies the current version.
10. Contact
ArnoHealth S.L., Gran Via de les Corts Catalanes 699, 2-2, 08013 Barcelona, Spain. For privacy questions or requests, email [email protected] or visit https://run.analyticszone.app.
