Legal Document

Privacy Policy

Effective: November 9, 2025 · Last Updated: 2026-07-15

Primary governing law: Republic of Indonesia (Law No. 27 of 2022). For EU/EEA residents: additionally governed by the General Data Protection Regulation (GDPR).

Activ.run Mobile Application Privacy Policy

This Privacy Policy describes how Activ.run ("we," "us," or "our") collects, uses, and shares information related to your use of the Activ.run mobile fitness application and workout tracker.

1. Data we collect

Account and profile information

We may collect name, email address, internal user identifiers, securely hashed passwords, and profile information such as gender, height, and weight. We use this data for account management and App functionality.

Health and fitness data

We collect workout logs, sets, reps, weight, total volume, rest times, bodyweight entries, and related health and fitness information. We use this data for App functionality, analytics, and personalization.

If you connect Google Health Connect on Android, activ.run may read activity data from Health Connect — including exercise sessions, distance, speed, heart-rate series, elevation gained, cadence and steps, total calories burned, and GPS exercise routes — and store it in your activ.run account and locally on your device to display your activity history, route map, heart-rate chart, and performance analytics alongside manually logged entries. Health Connect data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering. You can revoke Health Connect access at any time from Android settings or the Health Connect app.

If you connect your COROS account, activ.run receives run-family activity data pushed from COROS — including GPS route and heart-rate data — and stores it in your activ.run account. This data is used only within activ.run for first-party app functionality such as displaying your run history, route map, and performance analytics. COROS-sourced activity data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering.

If you connect your Polar account, activ.run receives run-family activity data pushed from Polar — including GPS route, heart-rate data, pace, splits, distance, duration, calories, cadence, and elevation — and stores it in your activ.run account. This data is used only within activ.run for first-party app functionality such as displaying your run history, route map, heart-rate chart, and performance analytics. Polar-sourced activity data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering.

Usage and diagnostics

We may collect app interactions, taps, views, in-app search history, crash logs, diagnostics, API speed, memory, and other performance data. We use this data for analytics, fraud prevention, security, compliance, and App functionality.

Device information

We may collect device identifiers, advertising identifiers, device make and model, and operating system version. We use this data for analytics, advertising or marketing attribution, fraud prevention, security, and compliance.

Location

We may collect approximate location, such as country or region derived from IP address or similar non-precise methods, for App functionality, analytics, and marketing.

Precise location (GPS) — when you use the running tracking feature, Activ.run collects your precise GPS location continuously throughout your run. This data is used to draw your route, calculate distance/pace/elevation, and generate your post-run summary. GPS data is stored as coordinate points associated with your run activity. You can delete any run and its GPS data from the Activity screen at any time.

2. How we use your data

We use your data to create and manage your account, secure your session, display workout history, track progress and streaks, monitor app stability, diagnose bugs, analyze usage patterns, improve performance, measure marketing attribution, and detect or prevent unauthorized access and policy violations.

3. Why we process your data (lawful basis)

If you are in the EU/EEA, we process your personal data under the following lawful bases:

Data categoryLawful basisExplanation
Account data (name, email, password)Contract (Art. 6(1)(b))Necessary to provide the service
Workouts logged nativelyContract (Art. 6(1)(b))Core app functionality
GPS / precise locationContract (Art. 6(1)(b))Necessary for running tracking feature
Health Connect dataExplicit consent (Art. 9(2)(a))Collected at point of Health Connect integration
Strava activity dataExplicit consent (Art. 9(2)(a))Collected at point of Strava integration
COROS activity dataExplicit consent (Art. 9(2)(a))Collected at point of COROS integration
Polar activity dataExplicit consent (Art. 9(2)(a))Collected at point of Polar integration
Analytics (PostHog)Legitimate interest (Art. 6(1)(f))Understanding app usage to improve it
Crash reporting (Sentry)Legitimate interest (Art. 6(1)(f))Maintaining app stability

4. How we share your data

We do not sell your personal data. We share data only when necessary with service providers that help us operate the App, including PostHog for product analytics and Sentry for crash reporting and error monitoring.

To help us improve our apps and user experience, we share your email address with PostHog (posthog.com), a third-party product analytics platform. This data is used solely for analytics to understand usage patterns and identify internal testers. You may opt out of this data sharing at any time by toggling off "Share usage data" in the Profile section of the app.

We may share advertising identifiers and related usage data with advertising networks and marketing platforms to measure campaign performance and serve relevant advertisements. We may also disclose information if required by law or in response to a valid legal request.

Health Connect data is never shared with third parties, including service providers, analytics platforms, or advertising networks. COROS-sourced activity data is likewise never shared with third parties, including service providers, analytics platforms, or advertising networks. Polar-sourced activity data is likewise never shared with third parties, including service providers, analytics platforms, or advertising networks.

5. Your rights under GDPR

If you are in the EU/EEA, you have the following rights under the General Data Protection Regulation:

  • Right to access — request a copy of the personal data we hold about you by emailing support@activ.run.
  • Right to rectification — correct inaccurate data via Profile > Edit in the app, or by emailing us.
  • Right to erasure — delete your account and all associated data via Profile > Privacy > Delete Account. Deletion is permanent and completes within 30 days.
  • Right to data portability — download a copy of your data via Profile > Privacy > Download my data.
  • Right to object — object to processing based on legitimate interest via Profile > Privacy > Manage consents.
  • Right to withdraw consent — withdraw consent at any time by deleting your account or emailing support@activ.run.
  • Right to restrict processing — request restriction of processing by emailing support@activ.run.
  • Right to lodge a complaint — you have the right to lodge a complaint with your local Data Protection Authority (DPA).

You can also reset your Advertising ID or opt out of personalized ads through your iOS or Android device settings.

6. Data security

We implement security measures including secure API wrappers, token-based authentication, encryption in transit via HTTPS, and secure session storage on device to protect your data from unauthorized access, alteration, disclosure, or destruction.

7. How long we keep your data

Data typeRetention period
Account dataUntil account deletion + 30 days
Workout and run historyUntil account deletion + 30 days
COROS-sourced activity dataUntil account deletion + 30 days
Polar-sourced activity dataUntil account deletion + 30 days
GPS track pointsUntil account deletion + 30 days
Body weight logsUntil account deletion + 30 days
Crash reports (Sentry)90 days
Analytics events (PostHog)12 months
Server logs30 days
Backups90 days after account deletion

8. International data transfers

Your data may be processed in countries outside your own. We use the following providers and safeguards:

ProviderPurposeLocationSafeguard
Oracle Cloud InfrastructureBackend hostingMultiple regionsStandard Contractual Clauses (SCCs)
Cloudflare R2File storageMultiple regionsStandard Contractual Clauses (SCCs)
PostHogAnalyticsEU regionEU hosting
SentryCrash reportingUSStandard Contractual Clauses (SCCs)
COROSConnected device activity source (inbound sync)Multiple regions (COROS infrastructure)Explicit consent at point of COROS integration; subject to COROS Privacy Policy
PolarConnected device activity source (inbound sync)Multiple regions (Polar infrastructure)Explicit consent at point of Polar integration; subject to Polar Privacy Policy

9. Health Connect

activ.run integrates with the Android Health Connect platform to read health and fitness data from compatible apps and devices you choose to connect. The following applies specifically to data obtained through Health Connect.

What we read

activ.run requests permission to read the following Health Connect record types: exercise session, distance, speed, heart rate (series), elevation gained, cadence and steps, total calories burned, and exercise route (GPS). All record fields are optional — data absent from a connected device is omitted, never zero-filled.

How we use it

Health Connect activity data is used only within activ.run to display your activity history, route map, heart-rate chart, and performance analytics, and to provide first-party, user-facing health and fitness insights such as trends, summaries, and progress.

What we do not do

activ.run does not sell, license, transfer, or share Health Connect data with advertisers, data brokers, third-party analytics providers, or other third parties. activ.run does not use Health Connect data for advertising, artificial intelligence or machine learning model training, resale, data brokering, or unrelated purposes.

Writing data

activ.run does not write data back to Health Connect.

Revoking access

You can revoke activ.run's Health Connect access at any time through Android settings or through the Health Connect app's app permissions screen. Revoking access stops activ.run from reading new Health Connect data.

Retention

Activity data already synced from Health Connect remains in your activ.run account and local app storage until you delete individual activities or delete your account.

Deleting your data

You can delete individual activities in activ.run, or delete your entire account and all associated activ.run data from Profile → Delete Account. Deleting a Health Connect-sourced activity from activ.run does not delete the original record from Health Connect or the source app. For deletion requests, contact support@activ.run.

Compliance

activ.run's use of Health Connect data complies with the Health Connect Permissions Policy: developer.android.com/health-and-fitness/health-connect/core-topics/privacy-policy-requirements