Privacy Policy
Last updated: May 5, 2026 | Version 1.2.0
Contents
- Data We Collect & Consent Records
- Purposes & Legal Bases
- HealthKit Data
- Location Data
- Storage, Security & Retention
- Deletion & Account Removal
- Third-Party Services & Sub-processors
- iOS & watchOS Permissions
- Children's Privacy
- International Privacy Regulations
- Automated Processing & Profiling
- Data Breach Notification
- Cookies & Local Storage
- Policy Changes & Re-consent
- Contact & Rights Requests
Kenji Suzuki, operating as RouteRun ("we", "us", or "our"), respects your privacy and is committed to protecting your personal data in accordance with the Act on the Protection of Personal Information (APPI, as amended 2022), the EU General Data Protection Regulation (GDPR), CCPA/CPRA, the Washington My Health MY Data Act, EU AI Act Article 50, and other applicable laws.
Data Controller: Kenji Suzuki (trade name: RouteRun) — Tokyo, Japan (full address provided on request) — support@routerun.jp
1. Data We Collect & Consent Records
1.1 Location Data
- Used to generate running routes from your current location
- Used to record distance and pace during runs
- Used to surface nearby race events
1.2 HealthKit Data (GDPR Art.9 Special Category)
- Heart rate, step count, distance, active energy, workout data
- VO2 Max estimate, heart rate variability, recovery score (AI coaching only)
1.3 Account Information
- Email address, display name
- Profile settings (age, weight, height, gender)
- Postal code (optional)
- Running records and statistics
- Passkey credentials (if configured) — the private key is stored only in your device Keychain and is never transmitted to our servers. We retain only the public key reference.
1.4 Consent Records (GDPR Art.7(1) accountability)
- Date, time, and version number of consent to Terms and Privacy Policy
- Date and time of consent to AI coaching
- Date and time of consent to health data processing
- Method of consent (in-app consent flow)
1.5 Device & Usage Data
- Device type, OS version, app version, language settings
- Error logs and crash reports (non-identifying form)
- Feature usage patterns (for AI coaching quality improvement)
This information is securely stored via Firebase Authentication and Firestore (asia-northeast1 region, Tokyo).
2. Purposes & Legal Bases
| Purpose | Legal Basis (GDPR) |
|---|---|
| Running route generation & run record storage | Contract performance (Art.6(1)(b)) |
| AI coaching & personalisation | Explicit consent (Art.6(1)(a) & Art.9(2)(a)) |
| HealthKit health data processing | Explicit consent (Art.9(2)(a)) |
| App improvement, bug fixes, analytics | Legitimate interests (Art.6(1)(f)) |
| Legal compliance & rights protection | Legal obligation (Art.6(1)(c)) |
| Support & enquiry handling | Contract performance / Legitimate interests |
3. HealthKit Data
Data Accessed
- Read: Step count, distance, heart rate, active energy, workout data, VO2 Max estimate, heart rate variability
- Write: Workout records, calories burned, distance travelled, heart rate data
Storage Policy
Run data including heart rate and calorie information is stored encrypted in Google Firebase (asia-northeast1, Tokyo region) for multi-device sync. When AI coaching is used, VO2 Max estimates, HRV, and recovery scores are transmitted to the Gemini API (see §7).
Safeguards
- Never used for advertising or marketing
- Never sold or shared with third parties
- Protected by AES-256 encryption and TLS 1.3
- You can revoke access at any time via iOS Settings
- All data is permanently deleted upon account deletion
4. Location Data
4.1 Purpose & Collection
- Route generation starting from your current position; distance and pace measurement
- Displaying nearby race events
- Location is collected only while the app is in use; background collection occurs only during an active run
GPS coordinates of your running routes are stored in Google Firebase (asia-northeast1) to maintain your run history.
4.2 GPS Data After Account Deletion (Important Disclosure)
4.3 Disabling Location Access
- iOS: Settings → Privacy & Security → Location Services → RouteRun
- watchOS: iPhone Watch app → Privacy → Location Services → RouteRun
5. Storage, Security & Retention
5.1 Storage Location
Your data is stored in Google Cloud / Firebase in the asia-northeast1 (Tokyo) region. AI coaching inference is processed via Vertex AI (Gemini API) — see §7.1 for Google LLC sub-processor details on processing regions.
5.2 Security Measures
- TLS 1.3 transport encryption
- AES-256 database encryption
- Firebase Authentication password management (irreversible hash managed by Google)
- Passkey (WebAuthn/FIDO2) — private key stored on device only
- Continuous dependency vulnerability monitoring; static analysis in CI pipeline; periodic code review
- Apple App Transport Security (ATS) compliance
- Firestore security rules access control
5.3 Retention Periods
| Data Type | Retention Period |
|---|---|
| Account information & run records | Duration of account. Deleted within 30 days of deletion request. |
| AI coaching conversation logs | Most recent 12 months; older records auto-deleted. |
| Consent records | Up to 7 years per legal obligation. |
| Backups | Fully purged within 90 days of account deletion. |
| Error logs / crash reports | Up to 90 days (non-identifying form). |
| Service operation logs (Cloud Logging) | Up to 30 days (auto-deleted). User IDs in logs are SHA-256 hashed. |
| Support enquiry data (name, email, message) | Up to 2 years after resolution, then deleted. Stored in Firestore (asia-northeast1) or email (fallback). |
5.4 BigQuery Analytics Data (Important Disclosure)
6. Deletion & Account Removal
6.1 Account Deletion
- Open the app → Settings → Profile → Delete Account
- Re-authenticate to confirm your identity
- All run records and personal data are deleted
- A confirmation email is sent from support@routerun.jp
6.2 Individual Data Deletion
- Individual run records can be deleted from the History screen
- HealthKit data can be deleted via the Health app
- Passkey credentials can be removed via app Settings → Passkey Management
6.3 Withdrawing Consent
- Consent to AI coaching can be withdrawn at any time via Settings → AI Coach → Withdraw Coaching Consent
- Withdrawal does not affect the lawfulness of processing carried out before withdrawal (GDPR Art.7(3))
7. Third-Party Services & Sub-processors
7.1 Sub-processor List
| Entity | Role | Processing Region | Safeguards |
|---|---|---|---|
| Google LLC (US) | Cloud infrastructure (Firebase/Firestore/Cloud Functions), AI coaching (Gemini API), analytics (BigQuery), mapping (Routes API) | Data storage: asia-northeast1 (Tokyo) AI & route processing: US servers |
Google Cloud DPA, EU SCC (Module 2), EU-US DPF |
| Apple Inc. (US) | HealthKit access, in-app purchase, Sign in with Apple, Passkey | Apple-managed infrastructure | Apple Privacy Policy |
| Zipcloud | Postal code lookup (address auto-fill at registration only) | Japan | Search data is not stored |
7.2 AI Coaching & Cloud Processing (EU AI Act Art.50 Transparency)
AI-Generated Content Labelling (EU AI Act Art.50(1)): Coaching advice generated by Ayumu is AI-synthesised content.
Data transmitted to Google LLC:
- Message text
- Recent running statistics (distance, pace, frequency)
- Biometric health data from Apple HealthKit (VO2 Max estimate, HRV, recovery score)
- Personal coaching profile (training phase, typical pace range)
- Up to 5 turns of recent conversation history
Not transmitted: Your name, email address, or precise GPS coordinates.
- Weekly running statistics are automatically processed through Gemini AI every Sunday to generate a weekly digest (within the scope of your AI coaching consent)
- Transmitted data is used solely to generate AI responses and is not used to train Google's AI models (contractually guaranteed by the Google Cloud DPA)
- Cloud AI features require explicit consent recorded at first use
- Where Apple Foundation Models (iOS 26.0+) are available, processing occurs entirely on-device (no data transmitted)
- AI coaching advice is for informational purposes only and is not a substitute for medical advice
- The US does not have a comprehensive data protection law equivalent to Japan's APPI (disclosure per APPI Art.28)
7.3 Maps & Other Services
- Google Maps Platform: Route display and navigation
- Google Cloud Logging: Service operation logs (incident response, security monitoring). 30-day retention. User IDs in logs are SHA-256 hashed.
- WKWebView: Legal document display within the app only. Browsing history and input data are not collected.
- Google Analytics (this website): Aggregate website usage analysis
- Apple WeatherKit: Weather-aware coaching recommendations. Weather data is processed on-device per Apple's WeatherKit terms. Weather data powered by Apple WeatherKit.
7.4 Website Chat
The AI chat on our support page transmits your message text, session ID, and up to 10 turns of conversation history to Google Cloud Platform (US) for processing. IP addresses are temporarily processed server-side for rate limiting. Data is handled under this Privacy Policy. Chat responses are generated by AI (Google Gemini).
8. iOS & watchOS Permissions
8.1 Location Services (Required)
Permission level: "While Using" or "Always" (background collection during active runs only)
Disable: Settings → Privacy & Security → Location Services → RouteRun
8.2 HealthKit (Optional)
Supported OS: iOS 26 or later, watchOS 26 or later
Disable: Settings → Health → Data Access & Devices → RouteRun
8.3 Notifications (Optional)
Run completion, goal achievements, weekly digest from AI coach, etc.
Disable: Settings → Notifications → RouteRun
8.4 Apple Watch (Optional)
Standalone run recording on Apple Watch, real-time heart rate monitoring, automatic iPhone sync.
8.5 Motion & Fitness (Optional)
Step counting, distance measurement, activity tracking.
Disable: Settings → Privacy & Security → Motion & Fitness → RouteRun
8.6 Sign in with Apple & Passkey (Optional)
Sign in with your Apple ID, or use a Passkey (FIDO2/WebAuthn) with biometric authentication. The passkey private key is stored only in your device Keychain and is never sent to our servers.
8.7 Face ID / Touch ID (when using Passkey)
Biometric data is stored exclusively within your device's Secure Enclave and can never be read by us or any third party.
9. Children's Privacy
9.1 Age Requirements
- RouteRun is available to users aged 13 and over
- EEA: Users under 16 require explicit consent from a parent or guardian (GDPR Art.8). Some member states permit the age to be lowered to 13.
- Japan: Processing of data relating to minors under 18 requires separate parental consent.
- United States (COPPA): We do not knowingly collect personal information from children under 13 without verifiable parental consent.
9.2 Unintended Collection
If we become aware that we have inadvertently collected information from a child under 13, we will delete it promptly. Contact us at support@routerun.jp.
10. International Privacy Regulations
10.1 Japan (APPI)
We handle personal information as a Personal Information Handling Business Operator in compliance with the Act on the Protection of Personal Information (as amended 2022).
- Privacy contact: support@routerun.jp
- Third-party provision: We do not provide data to third parties without consent except as required by law.
- To request access, correction, or suspension of use, contact us by email or post.
Destination country: United States
US legal framework: No comprehensive federal data protection law; FTC enforces industry self-regulation.
Google LLC safeguards: Google Cloud Data Processing and Security Terms (including SCCs) provide appropriate protections.
Automated processing disclosure (APPI Art.35-8): The AI coaching feature automatically generates a coaching profile from your run history and HealthKit metrics. You can opt out via app Settings → AI Coach.
10.2 European Economic Area (GDPR)
Under the EU General Data Protection Regulation, you have the following rights:
Request a copy of your personal data.
Request correction of inaccurate personal data.
Request deletion of your personal data.
Request restriction of processing under certain conditions.
Receive your data in a structured, machine-readable format (GPX/CSV).
Object to processing based on legitimate interests.
Withdraw consent for consent-based processing at any time.
Request an explanation of and human review of AI coaching automated processing.
Data processing region: User and analytics data is stored in asia-northeast1 (Tokyo). AI coaching inference (Vertex AI / Gemini) is processed on Google infrastructure, which may include the US. See §7.1.
Cross-border transfers: Because Google LLC is a US entity, transfers rely on Standard Contractual Clauses (SCC 2021/914, Module 2) and the EU-US Data Privacy Framework (DPF).
You also have the right to lodge a complaint with your national data protection authority (EDPB member list).
10.3 California Residents (CCPA/CPRA)
- Right to Know: Request details of personal information collected, used, or disclosed.
- Right to Delete: Request deletion of your personal information.
- Right to Opt Out: Opt out of the "sale" or "sharing" of personal information (we do not sell personal data).
- Non-discrimination: You will not be disadvantaged for exercising your rights.
- ADMT Opt-Out: To opt out of automated decision-making by AI coaching, withdraw your AI coaching consent in app Settings or contact support@routerun.jp.
10.4 Washington State (My Health MY Data Act)
Under the Washington My Health MY Data Act (HB 1155), you have the following rights regarding consumer health data:
- Right to access and confirm your health data
- Right to delete your health data
- Right to withdraw consent to collection or sharing of health data
Exercise rights: support@routerun.jp
10.5 United Kingdom
For UK residents, the UK GDPR and Data Protection Act 2018 apply. You may lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk.
10.6 Governing Law
This Privacy Policy is governed by the laws of Japan (APPI). For EEA residents, GDPR takes precedence; for California residents, CCPA/CPRA; for Washington State residents, My Health MY Data Act. EEA residents retain the right to bring proceedings in their country of residence under mandatory consumer protection laws notwithstanding the Tokyo venue clause.
11. Automated Processing & Profiling
11.1 AI Coaching Profile Generation
We automatically analyse your running history to generate a personal coaching profile (training phase, typical pace range, estimated fitness level). This profile is used to improve AI coaching response quality.
Legal basis (GDPR Art.22): Explicit consent per Art.22(2)(c).
Logic description: Run distance, pace, and HealthKit metrics (heart rate, VO2 Max, etc.) are input to the Gemini LLM which generates coaching advice.
Human review: To request an explanation of AI coaching automated processing or human review, email support@routerun.jp with the subject line "GDPR-Art22-Review". We respond within 30 days.
11.2 Coaching Style Optimisation
Based on your feedback (thumbs up/down), coaching tone is automatically adjusted using multi-armed bandit optimisation. This processing does not produce legal or similarly significant effects.
11.3 Weekly Digest Auto-generation
Every Sunday, your weekly running statistics are automatically processed through Gemini AI to generate a performance digest. This is within the scope of your AI coaching consent.
12. Data Breach Notification
In the event of a security breach affecting your personal data:
- Under GDPR Art.33, breaches affecting EEA residents' data will be notified to the competent supervisory authority within 72 hours of discovery.
- Under GDPR Art.34, high-risk breaches will be communicated to affected individuals without undue delay.
- Notifications will be sent from support@routerun.jp.
- Under APPI Art.26, breaches meeting the statutory threshold will be reported to the Personal Information Protection Commission and affected individuals will be notified.
13. Cookies & Local Storage
Essential Cookies
Required for basic website functionality (session management, security). These are set without consent.
Analytics Cookies
Google Analytics is used to analyse website usage (visitor counts, page views, etc.). Analytics cookies are only set after you select "Accept all" in the consent banner. You can withdraw consent at any time by clearing local storage or choosing "Essential only" in the banner.
In-App Cookies
When legal documents are displayed within the app via WKWebView, cookies are used for session management only. Browsing history and input data are not collected.
Cookie & Storage Inventory
| Name | Type | Purpose | Expiry | Party |
|---|---|---|---|---|
| _ga | Cookie | GA client ID | 2 years | Third-party (Google) |
| _ga_N224LHTCPT | Cookie | GA session | 2 years | Third-party (Google) |
| rr_consent_v1 | localStorage | Consent preference | Persistent | First-party |
| rr-lang | localStorage | Language preference | Persistent | First-party |
California Privacy Rights (CCPA/CPRA) — Your Privacy Choices
California residents may exercise the following rights:
- Right to Know: Request details of personal information collected, used, or disclosed about you.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Delete: Request deletion of your personal information.
- Opt Out of Sale/Sharing: To stop sharing data with Google Analytics, select "Essential only" in the cookie banner.
- Limit Use of Sensitive Personal Information: Request limits on use of GPS location data and health data (HealthKit).
Submit rights requests to: support@routerun.jp
14. Policy Changes & Re-consent
If we update this Privacy Policy, we will notify you in advance via in-app notification or email. For material changes (new processing purposes, new third-party disclosures, etc.), we will obtain fresh consent. If the current policy version changes, you will be presented with a re-consent prompt at next login.
15. Contact & Rights Requests
For privacy enquiries or to exercise your rights, contact us at:
Email: support@routerun.jp
Support page: routerun.jp/support
Hours: Monday–Friday, 10:00–18:00 JST
EEA residents' GDPR rights requests will receive a response within 1 month of receipt (GDPR Art.12(3)). Complex requests may be extended to a maximum of 2 months; we will inform you of any extension with the reason. A confirmation email will be sent upon completion of deletion.
Last updated: 5 May 2026 (Version 1.2.0)