Privacy

Privacy Policy

Last updated: 26 August 2026

Improva Labs ApS (CVR 46606558), based in Denmark, operates Runsei (“we”, “us”). We are the data controller for the personal data described here. This policy explains what we collect, why, and the rights you have under the EU General Data Protection Regulation (GDPR).

Data we collect

  • Account details — your email and, if you sign in with Google or Apple, your name and profile photo.
  • Onboarding & profile — the running goals, experience, availability, sex and year of birth you share so we can coach you.
  • Training data — your plans, planned and completed workouts, laps and splits, personal bests, training zones, and progress.
  • Health & recovery data — heart rate during and after your runs, and, if you connect a source that carries it, your sleep, heart-rate variability (HRV), resting heart rate and body mass. Any injuries or physical constraints you tell us about, and how you say you feel in the morning check-in, are part of this too. This is health data, and we treat it as the sensitive category it is.
  • Location data from your runs — the GPS route of a run, where the source you connected provides one. We use it to draw the map, to read terrain and grade, and to look up the weather you ran in. We never track your location in the background.
  • Coach conversations — the messages you exchange with the AI coach, including any voice notes (transcribed to text) and images or PDFs you attach. These often mention your health and your life.
  • Connected services — if you connect Strava, Apple Health or Health Connect, the activity and health data you authorise us to import, and the access tokens needed to keep importing it. Every connection is optional and reversible in the app.
  • Technical data — basic device and usage information needed to run and secure the service, and diagnostic reports when something goes wrong.

How we use it

  • To provide the service: build and adapt your plan, answer you as a coach, and track your training.
  • To personalise coaching to you.
  • To keep the service secure and working, and to fix problems.

Legal bases

We process your data to perform our contract with you (providing the app), on your consent (e.g. connecting Strava, Apple Health or Health Connect, and recording voice notes), and on our legitimate interests in operating and improving a secure service. You can withdraw consent at any time.

Health data — including your sleep, HRV, resting heart rate and any injuries you tell us about — is a special category under Article 9 of the GDPR. We process it on your explicit consent, which you give by connecting a health source or by entering the data yourself, and only to coach you. You can withdraw it by disconnecting the source or deleting the data, both of which you can do yourself in the app.

AI processing

The coaching and transcription features send the relevant content (your messages, voice notes and attachments, and the training context needed to answer) to trusted AI providers — Anthropic (the coach) and OpenAI (voice transcription and read-aloud) — acting as our processors. Under their API terms this content is not used to train their models. We send only what is needed to produce your result.

When a question needs something we don’t hold — a race’s course profile, a recent result — the coach can run a web search, which Anthropic performs on its own side. Only the search query leaves; your training data does not travel with it, and the answer cites what it used. Web search is off entirely in EU-only mode.

Who we share it with

We do not sell your data. We share it with the processors that run the service:

  • Supabase — database, authentication and file storage (EU region).
  • Vercel — application hosting.
  • Anthropic, OpenAI and Mistral — the AI features above (Mistral is EU-based).
  • Resend — sending you email: sign-in links, account notices and anything you asked to be told about (EU region).
  • Expo — delivering push notifications to your phone, if you turn them on. A notification carries only a short line of text and the screen to open.
  • Sentry — error monitoring, so we find out a screen broke without you having to tell us. We deliberately strip request contents, your identity and your IP before anything is sent, so an error report carries the fault and not the runner.
  • Open-Meteo — the weather on your runs and planned sessions. It receives a coordinate and a time, never your identity.
  • OpenFreeMap — the map tiles for a run’s route, and only if you keep maps on (see below).
  • Strava, Apple Health and Health Connect — only when you connect them. Apple Health and Health Connect are stores on your own phone; connecting them lets Runsei read from them, and disconnecting stops it.

Some of these processors — Anthropic, OpenAI, Expo and Sentry among them — may process data outside the EU/EEA. Where that happens we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, and the data is not used to train anyone’s models. EU-only mode (below) removes the AI providers from that list.

Keeping your data in the EU

Your data is stored in the EU whichever mode you choose. If you’d rather it stayed in the EU end-to-end, set AI data processing to EU-only— you are offered the choice when you create your account, and it is under Profile → Privacy afterwards. It is open to everyone, not only to EU residents.

In EU-only mode the coach runs on an EU AI provider (Mistral), and the four features that depend on non-EU services are turned off rather than quietly re-routed: voice notes (speech-to-text), read-aloud (text-to-speech), the coach’s web search, and the route map. Both modes are fully GDPR-compliant — this option simply keeps everything within the EU. The setting currently lives in the web app; the phone apps follow your account’s choice but cannot yet change it.

How long we keep it

We keep your data while your account is active. Deleting your account is scheduled, not instant: your account keeps working normally for 14 days so you can change your mind, and after that your personal data is deleted permanently. Encrypted database backups roll off within 30 days, and we keep only what a legal obligation requires us to. The full detail — what goes, what stays, and how to delete individual runs or connections without closing your account — is on our account deletion page.

Your rights

Under the GDPR you can:

  • access, correct, or delete your data;
  • receive a copy in a portable format;
  • object to or restrict certain processing, and withdraw consent;
  • lodge a complaint with the Danish Data Protection Agency (Datatilsynet).

Most of this you can do yourself without asking us: Profile → Data & privacy → Export my data downloads everything Runsei holds about you as a single file, and Profile → Data sources disconnects any source and revokes the token behind it. For anything else, email privacy@runsei.com.

Security

We use industry-standard measures to protect your data, including encryption in transit and access controls. No system is perfectly secure, but we work to keep your data safe.

Children

Runsei is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

We may update this policy as the product evolves. We’ll change the date above and, for material changes, let you know in the app.

Contact

Improva Labs ApSprivacy@runsei.com.