Features Pricing FAQ Contact Log in Start your free month
Legal

Privacy Policy

Version 1.4 — Effective date: 18 June 2026

1. Data controller

Neural Ninjas, registered in the Netherlands (Chamber of Commerce number: 42051553), is responsible for the processing of personal data through AI RunCoach. You can reach us via our contact page.

2. What data do we collect?

  • Account data: name, email address, date of birth, language preference, password (hashed).
  • Training data from Strava (if connected): activity name, date, distance, duration, average and maximum heart rate, average pace, cadence, elevation gain, and activity type. Raw activity data is cached for a maximum of 7 days (see section 5). Derived metrics (weekly volume, average pace, heart rate zones) are retained for the lifetime of your account to enable training plan generation.
  • Training data from Health Connect / Apple Health (if granted): exercise sessions, heart rate samples, distance and speed data — read from your device's health database. This data is not stored on our servers beyond what is needed to synchronise your training plan.
  • Payment data: transaction status and subscription details (payments are processed by Stripe; we do not store card details).
  • Usage data: login times, app usage, technical log data.
  • GPS/location data (Android app): real-time position, speed and distance — only during active training sessions. Location data is not stored on our servers.

3. Purposes and legal basis

  • Performance of contract: to provide the service, generate training plans and track your progress.
  • Legitimate interest: service security, fraud prevention, service improvement.
  • Legal obligation: retention of accounting records.
  • Consent: for marketing communications (where applicable).

4. Third parties

  • Stripe — payment processing (Stripe, Inc., USA).
  • Anthropic — AI processing to generate training plans (Anthropic, PBC, USA). Training data is processed to generate your personal plan and is not used to train AI models.
  • Strava — retrieval of training activity data and, where you explicitly choose to do so, uploading completed runs on your behalf (Strava, Inc., USA). We request the minimum scopes required: read access to your activities and write access solely for workout uploads you initiate. We subscribe to the Strava Webhook Events API to receive real-time notifications of deletions and account deauthorisations, so that we can delete your data promptly in accordance with Strava's API Agreement. You can disconnect Strava at any time via Settings → Account in the app.
  • Garmin — delivery of planned training sessions to your Garmin device, if connected (Garmin International, Inc., USA). We write workout data only; we do not read health or activity data from Garmin.
  • Cloudflare — DDoS protection and captcha (Cloudflare, Inc., USA).

Transfers to countries outside the EEA are covered by appropriate safeguards (Standard Contractual Clauses or an adequacy decision).

5. Retention periods

  • Account data is retained for as long as the account is active and deleted within 30 days of account removal.
  • Raw Strava activity data (individual activity records retrieved via the Strava API) is cached for a maximum of 7 days, then automatically purged. Our system performs a daily cleanup to enforce this limit.
  • Derived Strava metrics (weekly running volume, average pace, heart rate zones — calculated from raw data at the time of sync) are stored for the lifetime of your account. These aggregated metrics are necessary to provide continuity in training plan generation. They contain no raw GPS or sensor data.
  • When you delete your Strava connection (via the app) or revoke access on Strava.com, all raw activity data and cached files are deleted immediately. Derived metrics are also deleted if you subsequently delete your AI RunCoach account.
  • When Strava notifies us via webhook that you have deleted an activity, that activity is removed from our cache within 48 hours.
  • Accounting records are retained for 7 years as required by law.
  • Technical logs are retained for a maximum of 90 days.

6. Your rights

Under the GDPR, you have the following rights:

  • Access: request an overview of your personal data.
  • Rectification: have incorrect data corrected.
  • Erasure: request deletion of your data. You can delete your account at any time via Settings → Account in the app. To disconnect only your Strava data, use the "Disconnect Strava" option in the same screen.
  • Restriction: restrict processing in certain cases.
  • Portability: request your data in a readable format.
  • Objection: object to processing based on legitimate interest.

Requests can be sent via our contact page. You also have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

7. Cookies and local storage

AI RunCoach uses only technically necessary cookies and local storage to save your language preference and session. No tracking or advertising cookies are used. The Android app stores your login token encrypted via Android Keystore — this token is not shared with third parties.

8. Android app — device features

  • GPS/location: requested exclusively during active running sessions to calculate pace and distance. Location data does not leave your device and is not stored on our servers.
  • Health Connect (Android): the app can read exercise sessions, heart rate and distance data from Health Connect if you grant permission. This data is used solely to display your training history and synchronise it with your training plan. We do not store raw Health Connect data on our servers.
  • Text-to-speech: the app uses your Android device's built-in TTS engine for audio coaching. No voice data is sent to our servers.
  • Permissions: ACCESS_FINE_LOCATION (GPS during training) and FOREGROUND_SERVICE (background timer). The app only requests permissions strictly necessary for its operation.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), encrypted password storage and access restrictions.

10. Changes to this policy

Neural Ninjas reserves the right to amend this Privacy Policy. Material changes will be communicated by email.

11. Contact

For privacy questions, please use our contact page.