RunPulse← RunPulse

Privacy Policy

Last updated: 4 August 2026 · Applies to RunPulse for iPhone

The short version. RunPulse has no sign-up, no ads and no tracking. Your runs, GPS routes, training plan, profile, coach chat history and achievements are stored on your iPhone and are never uploaded to us. Four things do leave your device: the text you type to the AI coach (with a small training summary) goes to Google Gemini to generate a reply; an anonymous identifier and an AI credit balance are kept so free usage can be counted; your subscription status is verified; and a device-integrity check protects the service from abuse. We never receive your name, email address, phone number or payment details.
  1. Who we are and how to reach us
  2. Data that stays on your device
  3. Data that leaves your device
  4. Location and background tracking
  5. Apple Health
  6. AI features and Google Gemini
  7. Your AI consent
  8. Anonymous identifier and AI credits
  9. Purchases and subscriptions
  10. Notifications
  11. Device integrity (App Check)
  12. Third parties and where data is processed
  13. How long we keep data
  14. Legal bases (GDPR)
  15. Your rights and how to exercise them
  16. What we never do
  17. Security
  18. Children
  19. Changes to this policy

1. Who we are and how to reach us

RunPulse ("the app", "we", "us") is an iPhone running tracker and AI coaching app developed by Alperen Çiftlikci as an independent developer. We are the data controller for the limited processing described below.

For any privacy question, data request or complaint, write to runpulse.app@gmail.com. You can also reach us from inside the app via Profile → Settings → Contact developer. We aim to reply within 30 days, and in practice much sooner.

2. Data that stays on your device

RunPulse is local-first. The following is written to your iPhone's private app storage and is never transmitted to us or to anyone else:

Deleting the app removes all of it. Settings → Delete my account wipes this local data immediately and permanently; it cannot be recovered afterwards.

3. Data that leaves your device

This is the complete list. Nothing else is transmitted.

WhatWhyWho receives it
Your coach message text and a short training summary (goal, runner level, current streak, lifetime run count) To generate the coach's reply Google (Gemini, via Firebase AI Logic)
Anonymised run or plan figures — distance, time, pace, workout type, weekly volume, days per week, weight for fuelling advice To write the one-line run comment, adapt your plan, generate fuelling advice and daily motivation Google (Gemini, via Firebase AI Logic)
An anonymous identifier, your AI credit balance, your premium flag and your AI-consent flag To count free AI usage fairly and to remember that you consented Google (Firebase Authentication, Cloud Firestore, Cloud Functions)
A device-integrity token To confirm the request comes from a genuine copy of the app Apple (App Attest) and Google (Firebase App Check)
The anonymous identifier plus your purchase and subscription status To unlock PRO features on your device RevenueCat, Apple

We do not send your name, email address, phone number, contacts, device advertising identifier, GPS coordinates, route geometry or run history off the device.

4. Location and background tracking

RunPulse requests location access so it can measure a run. Specifics:

5. Apple Health

Connecting Apple Health is entirely optional and the app is fully functional without it. If you do connect it:

All Health data is processed on your device. It is never sent to our servers, never sent to the AI provider, and never used for advertising or marketing — as required by Apple's rules. You can change or revoke each permission in the Health app at any time. If you decline, you lose only heart-rate figures and profile pre-fill; everything else keeps working.

6. AI features and Google Gemini

RunPulse uses Google's Gemini models through Firebase AI Logic to power the coach chat, the one-line comment on a finished run, plan adaptation, fuelling advice and daily motivation.

When you use one of these features, the relevant text and figures listed in section 3 are sent to Google for processing and a reply is returned. Google acts as our processor for this purpose and, under the Firebase AI Logic terms, does not use your prompts to train its models. Requests are proxied through Firebase so no API key is embedded in the app.

The AI coach provides general training guidance. It is not medical advice and is not a substitute for a doctor, physiotherapist or qualified coach. If something hurts, stop and seek professional advice.

Before the first message is sent to the AI coach, the app shows a consent screen naming Google Gemini as the provider and listing exactly what is sent. Nothing is transmitted until you accept. If you decline, your message is not sent and the AI feature simply does not run.

Your decision is stored on your device and, so you are not asked again on a reinstall, as a single boolean flag (aiConsent) against your anonymous identifier.

8. Anonymous identifier and AI credits

Free AI usage is limited by a daily credit balance. To count credits fairly and to stop abuse, the app creates an anonymous identifier using Firebase Anonymous Authentication.

9. Purchases and subscriptions

RunPulse offers a weekly subscription, a yearly subscription and a one-time lifetime purchase. All payments are processed by Apple through your App Store account. We never see or store your card number, billing address or any payment credential.

Purchase receipts are validated by RevenueCat, which tells the app whether your subscription is active. RevenueCat receives the anonymous identifier and the purchase status. Subscriptions renew automatically unless cancelled at least 24 hours before the period ends; you manage and cancel them in your Apple ID subscription settings, not in the app.

10. Notifications

Reminders are scheduled locally on your device. We operate no push server and send no remote notifications, so no push token is collected. Notification permission is optional and can be revoked in iOS Settings.

11. Device integrity (App Check)

To stop other software from calling our AI and credit endpoints, each request carries a short-lived attestation token produced by Apple's App Attest and verified by Firebase App Check. The token proves the request came from a genuine, unmodified copy of RunPulse. It contains no personal information and cannot be used to identify you.

12. Third parties and where data is processed

ProviderRoleData involvedLocation
Google (Firebase AI Logic / Gemini) Generates AI replies Coach message text, training summary, anonymised run figures Google data centres, may include the United States
Google (Firebase Auth, Firestore, Cloud Functions, App Check) Anonymous identity, credit ledger, abuse protection Anonymous identifier, credit balance, premium and consent flags Google data centres, may include the United States
RevenueCat Validates purchases Anonymous identifier, purchase and subscription status United States
Apple App distribution, payments, Health, Maps, App Attest Governed by Apple's own privacy policy Apple infrastructure

We use no advertising SDK, no analytics SDK and no crash-reporting SDK. There is no Google Analytics, no Facebook SDK, no attribution or measurement partner, and no cross-app tracking. Transfers outside the EEA and the UK rely on the European Commission's Standard Contractual Clauses entered into with these providers.

13. How long we keep data

15. Your rights and how to exercise them

Depending on where you live you have the right to access, correct, delete, restrict or object to the processing of your data, to data portability, and to withdraw consent at any time. If you are in California you additionally have the right to know what is collected and to opt out of any "sale" or "sharing" of personal information — we do neither.

16. What we never do

17. Security

All network traffic uses HTTPS/TLS. Local data is held in the app's private container, protected by iOS file-system encryption and your device passcode. Server-side, database security rules restrict every record to its own anonymous identifier, and the credit balance can be written only by our server. No system is perfect; if you believe you have found a vulnerability, please email runpulse.app@gmail.com and we will respond promptly.

18. Children

RunPulse is rated for general audiences but is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect data from them. If you believe a child has used the app and data is associated with them, contact us and we will delete it.

19. Changes to this policy

If this policy changes we will update this page and the date at the top. Material changes — for example a new processor or a new category of data — will be surfaced in the app before they take effect, and where the law requires it we will ask for your consent again.