Rungtime · Privacy
Privacy policy for the Rungtime app
1. Controller and contact
Patrick WagnerDarkstone / Rungtime
Uttendorf 13
3385 Prinzersdorf
Austria
Email for privacy and support: support@darkstone.app · Imprint: https://darkstone.app/imprint
We have not appointed a data protection officer because there is currently no obligation to do so.
2. In short
- Rungtime works without an account. Your training data is then stored only on your device.
- Rungtime contains no ads, no advertising or analytics services and does no tracking.
- For purchases the app talks to the App Store or Google Play and to the purchase service RevenueCat. No training data is sent.
- Rungtime sends crash reports only if you explicitly switch them on.
- Apple Health, Health Connect, the watch connection and location in Bar Radar run only with your permission.
- A Rungtime account is optional. It backs up only what you explicitly choose, on our servers in Germany. Sync, the web view, friends, groups and shared templates are separate steps (section 12).
- Rungtime uses neither the camera nor the microphone, contacts or photos.
In the app, all external services are listed under Settings → Privacy & diagnostics.
3. Data on your device
Rungtime stores your plan, your sessions and confirmed results, notes, training places (names you choose, no positions), information about restrictions, heart rate readings from the watch, achievements and settings in a database on your device. Without an account we have no access to it, and none of it is sent to us.
- The app folder is excluded from the operating system’s device backup (iOS: excluded from backup; Android:
allowBackupoff). - You can export your data as a CSV file at any time or save it as an encrypted backup file with a separate key (Me → Data & backup). You choose where the file goes in the system dialog; a cloud storage you choose there processes it under its own terms.
- Rungtime reads a workout import (CSV) only on the device.
- Deleting: Me → Data & backup → “Delete training data on this device”. Files you exported and trainings sent to Health stay where they are. Your purchase rights are kept.
This processing takes place only on your device and under your control; we do not receive this data. Section 12 covers what you put into the cloud.
4. Purchases (App Store, Google Play and RevenueCat)
You buy Rungtime Pro through the App Store or Google Play. The store handles the purchase and payment with your store account; Rungtime does not see payment details. Apple or Google process store account, payment and purchase data as independent controllers under their own privacy terms.
To show offers and check the purchase state, the app talks to RevenueCat (RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA) at start, when it returns to the foreground, on the “Rungtime Pro” page, when buying, when restoring and when opening subscription management. This involves:
- a randomly generated, pseudonymous identifier of this installation (no advertising or device identifier),
- product identifier, purchase history, entitlement status, store receipt or purchase token, price, currency and times,
- technically necessary connection and app data: IP address, platform, SDK, app and system version, device language and store country.
It does not send training data, profile, plans, notes, places, health values, email address, names or advertising or attribution identifiers. Automatic device identifiers and RevenueCat diagnostics are switched off. With an account and sync, a random purchase identifier of your account is added (section 12.3).
The app stores the last confirmed purchase state sealed on your device so that Pro also works offline under the rules of the terms of use. It is never part of an export or backup.
Purpose: offers, purchase, unlocking, restoring and checking the purchase state. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (our legitimate interest in a reliable purchase state and in preventing abuse). Accessing purchase data on your device is technically necessary for the purchase you request (§ 165(3) Austrian TKG 2021 or § 25(2) German TDDDG). RevenueCat processes the data as our processor, also in the USA (section 14). Retention: as long as needed for unlocking, restoring, refunds, abuse prevention and legal duties; you can ask us by email to delete your record at RevenueCat.
5. Crash reports (Sentry, only with consent)
Under Settings → Privacy & diagnostics → “Send crash reports” you can allow Rungtime to send a cleaned report to Sentry (Functional Software, Inc., USA; data region EU, Frankfurt) after a crash or error. The switch is off by default; without consent no Sentry code runs.
A report contains the app version, build, operating system and version, device model, error type, a cleaned error message and call sites. It does not contain training values, plans, notes, place names, heart rate, restrictions, account or purchase identifiers, tokens, email addresses, file paths or screenshots. Before sending, the app checks every report and removes texts you typed yourself. Your IP address is technically used for the transfer but is not stored by Sentry.
Without a connection a report waits on the device (at most ten). Switching off stops sending and deletes waiting reports. Sentry deletes reports already sent after 30 days. Not every crash is captured.
Independently of this, the app keeps the last error message, cleaned, on the device for 30 days. It leaves the device only if you attach it to a support message.
Legal basis: your consent (Art. 6(1)(a) GDPR; for reading device data § 165(3) Austrian TKG 2021 or § 25(1) German TDDDG). You can withdraw it at any time with the switch; this does not affect the lawfulness of reports sent before. Sentry processes the reports as our processor. For its parent company in the USA see section 14.
6. Help, reporting a problem and website
Help and common questions work without an account and offline. Report a problem hands your message to your mail app; Rungtime sends nothing itself. Only when you send the mail there does it go through your mail provider to our support inbox support@darkstone.app. It contains your description, an optional contact, the attachments you pick one by one (“Technical report”, “Last error”) and the sender address of your mail app. Please do not send us passwords, the key of your backup file, payment details or health information we do not need for your request.
Purpose: handling your request and fixing errors. Legal basis: Art. 6(1)(b) GDPR where it concerns the app or your purchase, otherwise Art. 6(1)(f) GDPR (our interest in answering requests). Our inbox runs on Google Workspace; the processor is Google Cloud EMEA Limited (70 Sir John Rogerson’s Quay, Dublin 2, Ireland) with affiliated companies, also in the USA (section 14). Processed are your email address, the content of your message with its attachments and the mail metadata (time, sender, recipient, subject, technical headers). We delete support messages twelve months after the last message of the request. We keep a message longer only as long as we need it to establish, exercise or defend legal claims (Art. 17(3)(e) GDPR). Error descriptions without personal data may stay longer.
When you open a page on darkstone.app (help, privacy, terms, imprint), your browser calls the fixed address without parameters. These pages are static, set no cookies and contain no analytics, advertising or social media services. Your IP address is technically needed to deliver the page over HTTPS; the web server and the proxy in front of it keep no regular access logs. The server is operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Legal basis: Art. 6(1)(f) GDPR (secure and reliable operation of the website).
7. Apple Health and Health Connect
Both features are off by default and run only with your system’s permission.
- Export trainings (Settings → Health): Rungtime writes the start, end and type (strength training) of each finished session that ends after you switch this on to Apple Health or Health Connect. Exercises, sets, notes, heart rate and skill evidence are not transferred.
- Reading (two separate switches): Rungtime shows other strength workouts of the last 30 days in History and the latest available resting heart rate as context in Analytics. The values are only displayed; they are not stored, backed up, exported or sent to the cloud. Rungtime’s own workouts are excluded.
These features send nothing over the network; the data stays in your device’s health store, and we do not receive it. What happens to it there is governed by Apple Health or Health Connect and the apps you give access. Switching off stops new transfers; you delete trainings already transferred in Health. Data from Apple Health and Health Connect is not used for advertising, not sold and not passed on to third parties.
8. Apple Watch and Wear OS
Apple Watch (Rungtime Pro): phone and watch exchange today’s session, your set results and – only with your Health permission on the watch – heart rate readings over the connection between the devices. Rungtime uses no server of its own for this. The watch workout session is discarded at the end and not saved to Apple Health. The app stores heart rate readings on the iPhone with the session; they are part of your backup file and your CSV export and go to the cloud only if you allow the “Heart rate” category there.
Wear OS (Android, Rungtime Pro): the connection is off by default and is switched on under Settings → Watch. Then Rungtime transfers the session with targets, equipment and restrictions, your set results and – with heart rate permission on the watch – readings between phone and watch. Google Play services carry the data over Bluetooth or encrypted through Google servers. Google acts as the provider of Google Play services under its own terms; we do not receive this data. No Rungtime account is needed. Switching off stops new transfers; saved values stay on your devices.
9. Location in Bar Radar
Bar Radar shows training spots from OpenStreetMap packs included in the app (Berlin, Vienna). The map loads nothing from the network. When you open the map, the system asks at most once for “While using the app” permission. Rungtime then uses a single position, only while the map is open, only in memory. It is not stored, not backed up and not sent. Without permission the map stays fully usable.
Links to openstreetmap.org (edit, copyright, licence) open only after your tap; the edit link contains only the type and number of the map object. Data: © OpenStreetMap contributors, ODbL.
10. Notifications, widgets, Live Activity and voice prompts
Reminders and Grease the Groove cues are local notifications without a push service and without a server. Widgets and the Live Activity (iOS) read only data on the device. Voice prompts use only voices installed on the device.
11. Sharing
When you share an achievement card, your year in review, a friend code or a file, Rungtime hands it to your system’s share dialog. You decide where it goes; the receiving app processes it under its own rules.
12. Rungtime account and cloud (optional)
You do not need an account to train. An account backs up only what you explicitly choose afterwards; signing in alone uploads nothing. All cloud data is stored on servers of Hetzner Online GmbH in Falkenstein (Germany), which we operate ourselves.
12.1 Account. Sign-in runs in your system browser through our sign-in service at auth.rungtime.darkstone.app. It stores your email address (as user name) and a hash of your password; there are no name fields. The sign-in service sets only technically necessary session cookies. To prevent abuse, it keeps sign-in events with email address and IP address for 30 days, also after an account is deleted. When you register, you confirm with a required checkbox that you are at least 16 years old and accept the terms and this policy. With your account we store the day you last used it (any signed-in request from the app or the web view), so that we can delete unused accounts on time (12.9). We send confirmation, recovery and notice mails from noreply@darkstone.app through the SMTP relay of Google Workspace (replies go to support@darkstone.app). Google processes your email address, the mail content (confirmation link, notice of the deletion date) and delivery metadata (time, sender, recipient, subject, technical headers) as our processor; the mails are not stored in a mailbox of ours. On the device, a sign-in token is kept in the system’s protected storage (iOS keychain, Android Keystore); it is not included in device backups.
12.2 Cloud backup. You choose categories: “Trainings and plans”, “Heart rate”, “Restrictions”, “Notes”. Because training data can reveal information about your health (for example sessions ended because something hurt), Rungtime backs up only with your separate, explicit consent for health data; heart rate, restrictions and notes are off by default. The data is encrypted on the way to the server (HTTPS) and on the server per account; Rungtime can read it there to give it back to you – this is not end-to-end encryption. Account metadata such as identifiers, times and categories and the sign-in database are not additionally encrypted. The backup has a storage limit per account of 64 MiB; when it is reached, Rungtime backs up nothing new and cuts nothing existing.
12.3 Several devices (Rungtime Pro). When you switch on “Sync on this device”, Rungtime keeps your backed-up data in sync between up to ten devices. So that the server can check Pro, the app registers your purchase with RevenueCat under a random purchase identifier of your account (rt. plus a random number); our server asks RevenueCat for the Pro status using only this identifier. RevenueCat learns neither your email address nor training data, but it can link purchases of several devices of the same account. A refund takes effect up to 24 hours later.
12.4 Web view. At app.rungtime.darkstone.app you can sign in with your browser and read your backed-up history and plans, with Pro also edit plans. For this the browser keeps a copy of your data in its local storage; access tokens stay in memory only. Signing out removes the browser copy. The web view uses no analytics, advertising or third-party services, no external fonts and no cookies other than the sign-in service’s session cookies. Rungtime syncs a plan draft from the browser only after you confirm this on your main phone. Local storage and session cookies are technically necessary for the service you request (§ 165(3) Austrian TKG 2021 or § 25(2) German TDDDG).
12.5 Friends. A separate opt-in (“Turn on friends”). You enter a display name (1–24 characters) and choose which values confirmed friends see: weekly goals of the last four weeks, level, skill milestones (on by default) and weekly streak (off). People you send a request to also see your name. Invite codes are valid for 14 days, open requests for 30 days. Friends see only what you switched on; switching off removes the value at once. Sets, exercises, plans, notes, heart rate, restrictions, places and email are never shared. No address book, no search, no public profile.
12.6 Groups. Creating groups is Pro, joining is free. You consent separately for each group. All members of a group see the group name, your confirmed name and your role; your weekly goals of the last twelve weeks and your progress in the challenge only if you switch them on (off by default) – including members who are not your friends.
12.7 Template links. When you publish a template of your own, anyone with the link can read its name, your display name, your instructions, the source, the plan and – if you explicitly choose this – your own exercise definitions, without an account. Personal loads, logs, notes and health values are never included. The page has no scripts and no cookies and is not released to search engines. We do not record who opens the link; we keep no access log with IP addresses. You can deactivate or delete the link; content already read and copies already adopted cannot be called back. We may deactivate content that breaks the terms of use after a notice.
12.8 Operation and backups. Server logs contain no content, tokens, email or IP addresses, but a pseudonymous identifier of the calling account; they are deleted after 30 days. To limit requests we evaluate IP addresses only briefly in memory. We back up the databases daily, encrypted, to a second server at Hetzner in Germany and keep seven daily states; another encrypted copy is kept on a computer of the controller. Deleted data is gone from all backups after about eight days at most. A content-free deletion journal makes sure deletions also apply after a restore; it is deleted after 60 days. After an account is deleted, only a check value of your sign-in identifier remains, so that the deleted account cannot be linked again.
12.9 Deleting and withdrawing. Under Me → Data & backup you find: “Disconnect from account”, “Delete training data on this device”, “Permanently delete all training data” and “Delete account”. Withdrawing a cloud category deletes the copy in the cloud at once and from the backups after about eight days at most. “Delete account” removes data, permissions, devices, friend and group data, template links and the purchase identifier; the sign-in identity is deleted shortly afterwards. RevenueCat keeps the customer record with your purchases, because purchases belong to your store account. You cancel a subscription in the store.
Unused accounts. We delete an account that has not been used for 24 months (no signed-in request from the app or the web view) with the same effect as “Delete account”. We announce this at least 30 days in advance by email to the account’s confirmed address; if you sign in before then, the account stays. If there is no confirmed address or the mail cannot be delivered, we delete after the same period. Accounts linked to a running Pro subscription (purchase identifier, 12.3) are excluded. For Lifetime we also delete the account and the cloud copy after the notice; your purchase and the data on your devices stay. We delete sign-ins that were never linked to the app after 90 days, without notice.
Legal bases. Account, sync, web view and transactional mails: Art. 6(1)(b) GDPR. Cloud backup and sync of the chosen categories: your explicit consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR. Friends, groups and template links: your consent per permission under Art. 6(1)(a) GDPR. Sign-in events, server logs, backups and deletion journal: Art. 6(1)(f) GDPR (secure operation, abuse prevention, proof and effectiveness of deletions). Day of last use and notice mail: Art. 6(1)(f) GDPR (reliably keeping the retention periods under Art. 5(1)(e) GDPR). You can withdraw any consent in the app at any time with effect for the future.
13. Recipients and processors
| Recipient | Seat / region | Purpose | Role | When |
|---|---|---|---|---|
| Apple (App Store) or Google (Google Play) | the providers’ EU companies, also USA | purchase, payment, subscription management | independent controllers | on purchases |
| RevenueCat, Inc. | USA | purchase state | processor | on purchase checks; with sync also the purchase identifier |
| Functional Software, Inc. (Sentry) | USA, data region EU (Frankfurt) | crash reports | processor | only with consent |
| Google Cloud EMEA Limited (Google Workspace) | Ireland, also USA | support inbox and sending of account mails (SMTP relay) | processor | support only if you write; account mails only with an account |
| Google (Google Play services) | – | transport phone ↔ Wear OS watch | independent provider | only with the watch connection on |
| Hetzner Online GmbH | Germany (servers in Falkenstein) | servers, backups, website | processor | website always, otherwise only with an account |
| confirmed friends, group members, recipients of your links | – | what you share | – | only after your permission |
Contracts under Art. 28 GDPR are in place with our processors. We do not sell data and do not pass it on for advertising.
14. Transfers to third countries
RevenueCat (USA), Sentry’s US parent company and Google (Google Workspace for the support inbox and account mails) may involve a transfer to the USA. It is based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the EU standard contractual clauses in the data processing agreements (Art. 45 and Art. 46(2)(c) GDPR). For Google this is the “Cloud Data Processing Addendum (Customers)”; according to Google, Google LLC has certified to the EU-US Data Privacy Framework, and otherwise the standard contractual clauses incorporated there apply. You can request a copy of the safeguards. The Rungtime cloud itself is located only in Germany.
15. Retention
| Data | Retention |
|---|---|
| Training data on the device | until you delete it or remove the app |
| Crash reports at Sentry | 30 days |
| Last error on the device | 30 days |
| Support mails | 12 months after the last message; longer only for legal claims (Art. 17(3)(e)) |
| Health read values, location | only while displayed |
| Purchase data at RevenueCat | as long as needed for unlocking, refunds, abuse prevention and legal duties |
| Account and cloud data | until withdrawal or deletion; from backups after about 8 days at most |
| Browser copy of the web view | until you sign out |
| Sign-in events (email, IP) | 30 days |
| Server logs | 30 days |
| Deletion journal | 60 days |
| Check value of deleted accounts | permanently, without further data |
| Friend and group codes | 14 days |
| Open friend requests | 30 days |
| Template links | until you deactivate or delete them |
| Day of last use | until the account is deleted |
| Unused accounts | deleted after 24 months, notice at least 30 days before; not with a running subscription (12.9) |
| Sign-ins never linked | 90 days |
16. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability (Art. 15–20 GDPR), and the right to withdraw a consent at any time with effect for the future. You can exercise many of these rights directly in the app (export, download, delete, switches). For everything else, write to support@darkstone.app. We reply within one month and may ask for reasonable proof of identity, for example an email from your account’s address.
Right to object: where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR).
You can lodge a complaint with a data protection supervisory authority, in particular in the member state where you live. Our competent authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria, dsb@dsb.gv.at.
17. No automated decisions
Rungtime suggests plans, replacement exercises and next steps by fixed rules on your device. You confirm every change yourself. There is no automated decision with legal or similarly significant effects within the meaning of Art. 22 GDPR and no profiling for advertising.
18. Minimum age
Rungtime is intended for people aged 16 and over. You may use the account, cloud, friends, groups and template links only from the age of 16; you confirm this when you register. If we learn that an account belongs to a younger person, we delete it.
19. Obligation to provide data
You are not obliged to provide us with data. Without an account, purchase, support mail and crash reports we receive no personal data from you; individual features are then not available.
20. Changes
We update this policy when the app, our service providers or the law change. The current version is at https://darkstone.app/en/rungtime/privacy/. A changed policy does not extend a consent you gave for an earlier version; for new purposes we ask you again.