OnlyRun Download on the App Store

Privacy Policy

TLDR

OnlyRun records and processes information needed to operate a running app, including account profile details, Apple sign-in identifiers, run activity data, route and segment data, live broadcast content, social actions, device push tokens, and app diagnostics.

No sale of runner data

OnlyRun does not sell personal data, individual route data, or aggregate or anonymized run data. We do not package runner location, pace, route, event, or audience data for advertising, data brokerage, insurance underwriting, city analytics, or similar resale use.

No AI training on runner data

OnlyRun does not use encouragement messages, runner voice replies, route data, or profile data to train AI. Automated processing is limited to operating and protecting the service, including safety checks, spam prevention, profanity filtering, live-message delivery, and optional generated message audio.

Maps

OnlyRun uses OpenStreetMap-compatible map data and tile services. Map tile requests are routed through OnlyRun infrastructure where practical so map providers do not receive your OnlyRun account identity. We are working toward independently hosted map tiles to further reduce third-party map dependencies.

Location and activity data

When you record a run, OnlyRun uses location data to calculate route, distance, pace, segments, event check-in eligibility, and challenge progress. If you enable live broadcasting, OnlyRun processes live location updates so invited viewers can follow the broadcast. Privacy controls may hide start and end areas or hide the map from public viewers.

Live broadcasts, messages, and voice

Legacy one-run live sharing can include route updates, signed-in cheers, short signed-in text messages, and optional runner voice replies. Content from that legacy feature, including generated or submitted reply audio, may be stored while the related live share and replay remain available and is removed through the applicable message, live-share, or account-deletion controls.

Scheduled Run rooms use a different, transient voice-burst design. After an eligible participant presses and holds the microphone, OnlyRun reserves and records one bounded clip. With the participant's explicit consent, the clip is sent to AssemblyAI for transcription. OnlyRun first applies deterministic safety checks. A transcript candidate that is neither an exact reviewed safe phrase nor deterministically rejected is sent to Anthropic Claude Haiku through AssemblyAI LLM Gateway for semantic safety screening. The gateway model receives transcript text and bounded safety context, not participant audio. Approved audio is delivered only to currently connected eligible room participants and is not written by OnlyRun to D1, R2, replay, marketing assets, analytics, or reconnect history. It is discarded after delivery or timeout.

The approved transcript persists as attributed user content in chronological session chat until it is deleted under the applicable message, account, safety, or legal-retention rule. OnlyRun also retains bounded non-audio moderation metadata, which may include the decision, provider/model identifiers, latency, confidence, and a one-way transcript hash. Rejected transcript text is not published as chat content.

When behavioral safety review is enabled for a session, proposed text and voice transcripts may be classified before publication. Rejected content and raw provider responses are not stored in behavioral event records; OnlyRun keeps only bounded facts such as the session, account, channel, closed reason category, confidence bucket, severity, provider/model identifiers, timestamps, temporary cooldown, and review state.

AssemblyAI and Anthropic process the information routed to them under OnlyRun's account settings and applicable provider terms. Their processing can include limited security, abuse-prevention, logging, backup, or legal-retention periods. OnlyRun does not claim that a Sync API identifier is a provider-side deletion handle. Production Run-room voice requires explicit room entry and consent, uses bounded clips and deterministic moderation before semantic review, and does not expose an open microphone.

With your explicit consent, optional generated message audio sends the text of eligible signed-in messages to Cartesia to create an audio file for the runner. OnlyRun does not send run route coordinates or microphone recordings to Cartesia for this feature. Generated audio is stored by OnlyRun and can be played during the live broadcast or replay while the related live-share content is available.

Creator Sessions and Plus attribution

When you are signed in and join a participating creator's club, RSVP to or join a session, set a reminder, or enroll in a program, OnlyRun may retain that eligible first-party action for up to 30 days. If you then make an eligible initial OnlyRun Plus purchase, OnlyRun may associate the purchase with that creator under the accepted creator-program terms.

This processing supports OnlyRun creator Sessions only. It is not used for third-party advertising, data brokerage, or tracking you across other companies' apps or websites. Creator reports use privacy-protected aggregates and do not expose runner identities, contact details, routes, payment details, or individual transaction records.

Sharing and public links

Your activity visibility settings control whether runs are public, follower-visible, password-protected, or private. Public share links and public live-broadcast links can expose the selected public content to anyone with the link.

Service providers

OnlyRun uses service providers for authentication, hosting, storage, security, databases, subscriptions and in-app purchases, push notifications, maps, creator-program operations and reporting, AssemblyAI voice transcription and LLM Gateway routing, Anthropic Claude Haiku transcript safety screening, and Cartesia generated message audio. These providers process data under OnlyRun's configuration and their applicable contractual, security, and legal requirements.

Contact and deletion

You can delete your account in the app from Settings > Delete account. This removes your account, profile, runs, live shares, social activity, device tokens, account-linked session messages and transcripts, and other account-linked product data from OnlyRun. OnlyRun also requests deletion of the corresponding RevenueCat customer record when RevenueCat is configured.

Deleting an OnlyRun account does not cancel an App Store subscription. Manage or cancel an active subscription in Apple's subscription settings before deleting the account if you do not want future renewal.

OnlyRun may retain the minimum anonymized accounting and audit records needed to reconcile creator-program revenue, prevent duplicate attribution, document payouts, handle refunds or chargebacks, and meet legal obligations. These retained records are separated from your deleted profile and do not preserve your public profile, routes, contact details, or payment credentials.

Safety reports, moderation records, and abuse-prevention logs may also be retained where needed to protect users, enforce our rules, or meet legal obligations.

For privacy requests, deletion support, or data questions, email team@onlyrun.app.