Legal Document
Privacy Policy
Effective: November 9, 2025 · Last Updated: 2026-07-15
Primary governing law: Republic of Indonesia (Law No. 27 of 2022). For EU/EEA residents: additionally governed by the General Data Protection Regulation (GDPR).
Activ.run Mobile Application Privacy Policy
This Privacy Policy describes how Activ.run ("we," "us," or "our") collects, uses, and shares information related to your use of the Activ.run mobile fitness application and workout tracker.
1. Data we collect
Account and profile information
We may collect name, email address, internal user identifiers, securely hashed passwords, and profile information such as gender, height, and weight. We use this data for account management and App functionality.
Health and fitness data
We collect workout logs, sets, reps, weight, total volume, rest times, bodyweight entries, and related health and fitness information. We use this data for App functionality, analytics, and personalization.
If you connect Google Health Connect on Android, activ.run may read activity data from Health Connect — including exercise sessions, distance, speed, heart-rate series, elevation gained, cadence and steps, total calories burned, and GPS exercise routes — and store it in your activ.run account and locally on your device to display your activity history, route map, heart-rate chart, and performance analytics alongside manually logged entries. Health Connect data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering. You can revoke Health Connect access at any time from Android settings or the Health Connect app.
If you connect your COROS account, activ.run receives run-family activity data pushed from COROS — including GPS route and heart-rate data — and stores it in your activ.run account. This data is used only within activ.run for first-party app functionality such as displaying your run history, route map, and performance analytics. COROS-sourced activity data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering.
If you connect your Polar account, activ.run receives run-family activity data pushed from Polar — including GPS route, heart-rate data, pace, splits, distance, duration, calories, cadence, and elevation — and stores it in your activ.run account. This data is used only within activ.run for first-party app functionality such as displaying your run history, route map, heart-rate chart, and performance analytics. Polar-sourced activity data is not used for advertising, third-party analytics, machine learning model training, resale, or data brokering.
Usage and diagnostics
We may collect app interactions, taps, views, in-app search history, crash logs, diagnostics, API speed, memory, and other performance data. We use this data for analytics, fraud prevention, security, compliance, and App functionality.
Device information
We may collect device identifiers, advertising identifiers, device make and model, and operating system version. We use this data for analytics, advertising or marketing attribution, fraud prevention, security, and compliance.
Location
We may collect approximate location, such as country or region derived from IP address or similar non-precise methods, for App functionality, analytics, and marketing.
Precise location (GPS) — when you use the running tracking feature, Activ.run collects your precise GPS location continuously throughout your run. This data is used to draw your route, calculate distance/pace/elevation, and generate your post-run summary. GPS data is stored as coordinate points associated with your run activity. You can delete any run and its GPS data from the Activity screen at any time.
2. How we use your data
We use your data to create and manage your account, secure your session, display workout history, track progress and streaks, monitor app stability, diagnose bugs, analyze usage patterns, improve performance, measure marketing attribution, and detect or prevent unauthorized access and policy violations.
3. Why we process your data (lawful basis)
If you are in the EU/EEA, we process your personal data under the following lawful bases:
| Data category | Lawful basis | Explanation |
|---|---|---|
| Account data (name, email, password) | Contract (Art. 6(1)(b)) | Necessary to provide the service |
| Workouts logged natively | Contract (Art. 6(1)(b)) | Core app functionality |
| GPS / precise location | Contract (Art. 6(1)(b)) | Necessary for running tracking feature |
| Health Connect data | Explicit consent (Art. 9(2)(a)) | Collected at point of Health Connect integration |
| Strava activity data | Explicit consent (Art. 9(2)(a)) | Collected at point of Strava integration |
| COROS activity data | Explicit consent (Art. 9(2)(a)) | Collected at point of COROS integration |
| Polar activity data | Explicit consent (Art. 9(2)(a)) | Collected at point of Polar integration |
| Analytics (PostHog) | Legitimate interest (Art. 6(1)(f)) | Understanding app usage to improve it |
| Crash reporting (Sentry) | Legitimate interest (Art. 6(1)(f)) | Maintaining app stability |
4. How we share your data
We do not sell your personal data. We share data only when necessary with service providers that help us operate the App, including PostHog for product analytics and Sentry for crash reporting and error monitoring.
To help us improve our apps and user experience, we share your email address with PostHog (posthog.com), a third-party product analytics platform. This data is used solely for analytics to understand usage patterns and identify internal testers. You may opt out of this data sharing at any time by toggling off "Share usage data" in the Profile section of the app.
We may share advertising identifiers and related usage data with advertising networks and marketing platforms to measure campaign performance and serve relevant advertisements. We may also disclose information if required by law or in response to a valid legal request.
Health Connect data is never shared with third parties, including service providers, analytics platforms, or advertising networks. COROS-sourced activity data is likewise never shared with third parties, including service providers, analytics platforms, or advertising networks. Polar-sourced activity data is likewise never shared with third parties, including service providers, analytics platforms, or advertising networks.
5. Your rights under GDPR
If you are in the EU/EEA, you have the following rights under the General Data Protection Regulation:
- Right to access — request a copy of the personal data we hold about you by emailing support@activ.run.
- Right to rectification — correct inaccurate data via Profile > Edit in the app, or by emailing us.
- Right to erasure — delete your account and all associated data via Profile > Privacy > Delete Account. Deletion is permanent and completes within 30 days.
- Right to data portability — download a copy of your data via Profile > Privacy > Download my data.
- Right to object — object to processing based on legitimate interest via Profile > Privacy > Manage consents.
- Right to withdraw consent — withdraw consent at any time by deleting your account or emailing support@activ.run.
- Right to restrict processing — request restriction of processing by emailing support@activ.run.
- Right to lodge a complaint — you have the right to lodge a complaint with your local Data Protection Authority (DPA).
You can also reset your Advertising ID or opt out of personalized ads through your iOS or Android device settings.
6. Data security
We implement security measures including secure API wrappers, token-based authentication, encryption in transit via HTTPS, and secure session storage on device to protect your data from unauthorized access, alteration, disclosure, or destruction.
7. How long we keep your data
| Data type | Retention period |
|---|---|
| Account data | Until account deletion + 30 days |
| Workout and run history | Until account deletion + 30 days |
| COROS-sourced activity data | Until account deletion + 30 days |
| Polar-sourced activity data | Until account deletion + 30 days |
| GPS track points | Until account deletion + 30 days |
| Body weight logs | Until account deletion + 30 days |
| Crash reports (Sentry) | 90 days |
| Analytics events (PostHog) | 12 months |
| Server logs | 30 days |
| Backups | 90 days after account deletion |
8. International data transfers
Your data may be processed in countries outside your own. We use the following providers and safeguards:
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Oracle Cloud Infrastructure | Backend hosting | Multiple regions | Standard Contractual Clauses (SCCs) |
| Cloudflare R2 | File storage | Multiple regions | Standard Contractual Clauses (SCCs) |
| PostHog | Analytics | EU region | EU hosting |
| Sentry | Crash reporting | US | Standard Contractual Clauses (SCCs) |
| COROS | Connected device activity source (inbound sync) | Multiple regions (COROS infrastructure) | Explicit consent at point of COROS integration; subject to COROS Privacy Policy |
| Polar | Connected device activity source (inbound sync) | Multiple regions (Polar infrastructure) | Explicit consent at point of Polar integration; subject to Polar Privacy Policy |
9. Health Connect
activ.run integrates with the Android Health Connect platform to read health and fitness data from compatible apps and devices you choose to connect. The following applies specifically to data obtained through Health Connect.
What we read
activ.run requests permission to read the following Health Connect record types: exercise session, distance, speed, heart rate (series), elevation gained, cadence and steps, total calories burned, and exercise route (GPS). All record fields are optional — data absent from a connected device is omitted, never zero-filled.
How we use it
Health Connect activity data is used only within activ.run to display your activity history, route map, heart-rate chart, and performance analytics, and to provide first-party, user-facing health and fitness insights such as trends, summaries, and progress.
What we do not do
activ.run does not sell, license, transfer, or share Health Connect data with advertisers, data brokers, third-party analytics providers, or other third parties. activ.run does not use Health Connect data for advertising, artificial intelligence or machine learning model training, resale, data brokering, or unrelated purposes.
Writing data
activ.run does not write data back to Health Connect.
Revoking access
You can revoke activ.run's Health Connect access at any time through Android settings or through the Health Connect app's app permissions screen. Revoking access stops activ.run from reading new Health Connect data.
Retention
Activity data already synced from Health Connect remains in your activ.run account and local app storage until you delete individual activities or delete your account.
Deleting your data
You can delete individual activities in activ.run, or delete your entire account and all associated activ.run data from Profile → Delete Account. Deleting a Health Connect-sourced activity from activ.run does not delete the original record from Health Connect or the source app. For deletion requests, contact support@activ.run.
Compliance
activ.run's use of Health Connect data complies with the Health Connect Permissions Policy: developer.android.com/health-and-fitness/health-connect/core-topics/privacy-policy-requirements