RythmRun Privacy Policy
Last Updated: July 27, 2026
Introduction
RythmRun (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the “App”).
By using RythmRun, you agree to the collection and use of information in accordance with this policy.
- Account Information: Username, first name, last name, email address
- Profile Information: Profile picture (optional)
- Authentication Data: Secure token-based authentication
Location Data
- We collect real-time location data when you use the GPS tracking feature during workouts
- Location data includes latitude, longitude, altitude, speed, and accuracy
- This data is used solely to track your fitness activities and provide distance/pace information
Activity Data
- Workout type, duration, distance, speed, calories
- Start and end times of activities
- Descriptive text and activity routes
- Optional activity photos
- The current service does not expose friends, likes, comments, public
activities, or route sharing
- Network request metadata needed to serve and rate-limit requests
- Server-minted request identifiers and privacy-minimized security event
categories
- Device, OS, app-version, and error details when you choose to send them to
support
Purpose of Data Collection
- Service Delivery: To provide and maintain the App’s features
- Activity Tracking: To record and display your fitness activities
- Troubleshooting: To diagnose errors and improve functionality using
minimized technical information
- Security: To authenticate users and protect against fraud
- Account Communication: To send verification and password-recovery emails
Data Usage Limitations
- We do not sell your personal information
- We do not share your data with advertisers
- We do not use your data for marketing purposes beyond essential app updates
Data Storage
Local Storage
- Profile information and preferences are stored on your device
- Activity data is cached locally for offline access
Cloud Storage
- Your account information, synchronized activities, and uploaded images are
stored through our database and object-storage providers
- Network traffic is protected in transit with HTTPS/TLS
- Passwords are stored as hashes and refresh credentials are stored as digests
- Retained routes and activity photos on the device are app-private but do not
yet have an additional app-level encryption layer
Retention Period
- Your account data is retained as long as your account is active
- Deleted activities are removed from active views while queued cleanup
completes; provider backups may retain data for their configured retention
period
- Self-service account deletion is not yet available. Contact support for an
account or data-removal request
We Share Data With:
- Service Providers: Infrastructure and email providers necessary for app
functionality, only as needed to provide the service
We Do NOT Share:
- Activities or exact routes with other RythmRun users; the current product
keeps activities private and exact activity details owner-only
- Personal contact information
- Your personal information for sale
Your Privacy Rights
Requests You May Make:
Depending on applicable law, you may ask for:
- Access: Request a copy of your personal data
- Correction: Update your information at any time through app settings
- Deletion: Request account and data removal through support
- Portability: Request data in a portable format
- Opt-out: Disable location tracking
How to Exercise Rights:
- Update profile: Use in-app settings
- Account deletion or data removal: Contact support at [saurabh.iiitk.job@gmail.com]; in-app self-service deletion is not currently available
- Data request: Email us at [saurabh.iiitk.job@gmail.com]
Location Privacy
Location Data
- We only collect location data when you actively start a workout
- Location tracking can be disabled in app settings at any time
- Location data is stored to recreate your workout route
- Activities are private in the current service
Location Sharing
- Your exact location is never shared with other users in real-time
- Exact completed routes are owner-only; the current service exposes no
friend/public route-sharing journey
Children’s Privacy
Our App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
Security
Security Measures
- All data transmission is encrypted using HTTPS/TLS
- Passwords are hashed using industry-standard bcrypt
- Authentication uses secure JWT tokens
- Security controls are reviewed and updated as the service changes
While we use commercially acceptable means to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
International Data Transfers
Your information may be transferred to and maintained on servers located outside of your country. By using our App, you consent to this transfer.
Changes to This Policy
We may update this Privacy Policy from time to time. We may notify you of changes by:
- Posting the new Privacy Policy in the App
- Sending an account email when appropriate and email delivery is configured
- Updating the “Last Updated” date
You are advised to review this Privacy Policy periodically.
If you have questions about this Privacy Policy, please contact us:
- Email: [saurabh.iiitk.job@gmail.com]
- Website: [https://github.com/cosmicsaurabh]
Privacy Requests
Privacy rights vary by jurisdiction. To ask a question, exercise an applicable
right, or raise a concern, contact [saurabh.iiitk.job@gmail.com].
Your acceptance of these terms
By using RythmRun, you signify your acceptance of this Privacy Policy. If you do not agree to this policy, please do not use our App.