Loading...

Privacy Policy

Last updated: August 19, 2026

At NavRun, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information.

Information We Collect

When you use NavRun, we collect:

  • Account Information: Email address and username when you create an account.
  • Fitness Data from Strava: Running activities, routes, pace, distance, heart rate, and other workout metrics synced from Strava when you connect your account.
  • Fitness Data from Apple Health (iOS app only): Running workouts you grant us permission to read: start time, duration, distance, pace, and heart rate. See the Apple Health section below for details.
  • Preferences: Your training preferences, goals, and settings.
  • Location Data from Finished Runs: GPS routes attached to activities synced from Strava, and GPS routes attached to running workouts read from Apple Health when you grant that permission.
  • Live Location (iOS app only, and only during a live session you start): While a live session is running, the app records your position roughly every 25 minutes and sends those points to NavRun, including when your phone is in a pocket with the screen off. See the Live Sessions section below.
  • Voice Recordings and Messages: Short voice clips and typed notes sent in a live session, by you and by the people holding your share link. See the Voice Messages section below.
  • Names Typed by People Following Your Run: Someone who opens your share link chooses a display name to sign their messages with. They do not need a NavRun account. See the People Without NavRun Accounts section below.
  • Device Tokens (iOS app only): If you enable push notifications, we store an Apple Push Notification service token routed through Firebase Cloud Messaging so we can deliver notifications to your device.

How We Use Your Information

We use your information solely to:

  • Display your running activities and statistics
  • Generate training plans, either with AI or from your own runs by rules, depending on which you chose (see the AI Features section below)
  • Provide weather forecasts for your planned runs and races
  • Create analytics and insights about your training
  • Show your position and your messages to the people you gave a live share link to, while that session is open
  • Improve the NavRun service

Data Sharing

We do NOT sell, rent, or share your personal data with third parties for marketing or advertising purposes.

Your data may only be shared in these limited circumstances:

  • Service Providers: We use trusted services that process data on our behalf under strict confidentiality agreements (see the Third-Party Services section below for the full list).
  • Legal Requirements: If required by law or to protect our rights.
  • People You Share With: When you start a live session and send someone the link, you are choosing to show them your position and your messages. That sharing lasts until you turn the link off, or you end the session, or it ends on its own. See the Share Links section below.

Apple Health data is never shared, sold, or used for advertising or marketing. Full stop. See the Apple Health section below for details.

Data Security

We implement industry-standard security measures to protect your data:

  • Encrypted data transmission (HTTPS)
  • Secure database storage
  • OAuth 2.0 for Strava integration (we never see your Strava password)
  • Regular security reviews

Third-Party Services

NavRun uses the following services to operate. Each is bound by their own privacy policy and processes data only as needed to provide their service:

  • Strava: Activity data sync when you connect your account. You can disconnect at any time from your Preferences page, which stops future syncing.
  • Apple HealthKit (iOS app only): On-device read of running workouts when you grant permission. See the Apple Health section below.
  • Anthropic and OpenAI: AI training plan generation, weekly reports, run feedback, race strategy, and analytics. Activity summaries (distance, pace, duration, heart rate), your race goals, and your training preferences are sent to Anthropic or OpenAI to generate these features. One of them also receives voice messages sent in a live session, as audio and as the text transcribed from it, for the safety check described in the Voice Messages section below. Neither trains on your data: both companies' API terms prohibit it. Nothing is sent to either of them unless you have turned AI on. See the AI Features section below.
  • Brevo (Sendinblue): Transactional email delivery (account emails, weekly reports, race-day notifications).
  • Firebase Cloud Messaging (Google): Push notification delivery on iOS. Stores only a device token, and no training data passes through FCM.
  • Apple WeatherKit and Open-Meteo: The weather a run happened in. The start coordinates and start time of one run are sent to look up the conditions for that place and hour. Neither service receives your name, your email address, or anything else about you, and neither is told whose run it was. Weather data provided by Apple Weather. See Other data sources.
  • Stripe: Subscription payment processing. Stripe handles all payment information; NavRun never sees your card details.
  • Sentry: Error and crash monitoring. Captures error context and stack traces, but no training data or fitness metrics.
  • Railway: Hosting infrastructure for the NavRun service, and the S3-compatible object storage that holds voice message audio.
  • CARTO, unpkg, and jsDelivr: Map tiles, the mapping library, and the styling and icon libraries the site is built with. Your browser fetches these directly when a page loads, so they can see your IP address. NavRun sends a same-origin referrer policy, so a share link's token is not passed to them, and share pages run no analytics at all.
  • Google Analytics: Website usage measurement on navrun.app, so we can see which pages work and which are broken. Aggregate page and session data only. No training data, no fitness metrics, and no advertising.
  • Ahrefs Analytics: Cookieless website traffic measurement on navrun.app. Aggregate visit counts only.

AI Features, and Why They Are a Choice

Generative AI affects this community, and plenty of runners want less of it in their lives. That is fair, and it is why this is a choice rather than a default.

Knowing how to train for an ultra sits with veterans and with coaches most of us cannot reach. It is in here so nobody gets gatekept out of this sport. That is the reason NavRun offers it at all, and the reason it is offered rather than imposed.

With AI on: your week is written for you, each run gets read back, and you get weekly reports and race strategy.

With AI off: your week is built from your own runs by rules. Same caps, same rest days. Nothing about your training reaches a model.

What is sent, when it is on: runs, heart rate, race goals, and Apple Health workouts go to Anthropic or OpenAI. Neither trains on them. Your name, email address, and payment details are never sent.

Turning it on or off: the switch is on your Preferences page on the web and in Settings in the iOS app. Turning it off takes effect immediately, for the background weekly reports and plan revisions as well as anything you trigger yourself. Turning it off deletes nothing you already have: plans, run feedback, and reports stay in your account.

The one exception, either way: voice clips and messages sent in a live session are checked for safety before the people holding your share link hear or read them. That check runs whether AI is on or off, because turning it off would not give you privacy, it would remove a safety check standing between unscreened content and someone else's phone. See the Voice Messages section below.

Apple Health (iOS app only)

If you use the NavRun iOS app, you can grant permission for NavRun to read your running workouts from Apple Health. This data is read on-device with your explicit consent through the standard iOS permission prompt.

What we read: Running workouts only: start time, duration, distance, pace, and heart rate.

What we do with it:

  • Sync workouts to your NavRun account so they appear alongside your Strava activities.
  • Use them as input to AI training plan generation, weekly reports, and analytics, the same way Strava activities are used.

What we will never do with Apple Health data:

  • Sell or share it with any third party.
  • Use it for advertising, marketing, or any form of tracking.
  • Use it for any purpose unrelated to the training history and AI features you have opted into.

You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → NavRun. We will stop reading new data immediately. Previously synced workouts remain in your NavRun account until you delete them or your account.

Push Notifications (iOS app only)

With your permission, NavRun sends push notifications about your training plan, workout reminders, weekly reports, and race-day pacing. To deliver these, we store an Apple Push Notification service token, routed through Firebase Cloud Messaging (a Google service).

You can disable push notifications at any time in iOS Settings → Notifications → NavRun.

Live Sessions (iOS app only)

A live session is the feature that lets the people you care about follow along while you are still out on a run. It only ever starts because you tapped start in the NavRun app, and it stops when you end it.

What we collect while a session is running: your position (latitude and longitude), the time your phone took the reading, how accurate iOS said that reading was, your elevation where the phone reports it, and your phone's battery level at that moment. The battery level is there so the people following you can tell the difference between a quiet stretch and a dead phone.

How often: about one position every 25 minutes. iOS has no way to hand an app a location on a timer, so the app receives readings continuously and throws almost all of them away on your phone. Only the roughly one-per-25-minutes that survives is ever sent to NavRun. The app asks iOS for accuracy of about 100 metres rather than the finest fix your phone can produce.

In the background: yes. This is the point of the feature. Once a session is running, your position is still collected with your phone in a pocket and the screen off, which is why the app asks for the "Always" location permission. iOS shows its own location indicator while this is happening, and you can revoke the permission at any time in iOS Settings → Privacy & Security → Location Services → NavRun.

When you have no signal: positions wait on your phone and upload when you are back in range. Nothing is lost, it just arrives late.

When it stops: when you end the session, or automatically 48 hours after it started, whichever comes first.

Outside a live session, the NavRun app does not ask iOS for your live position at all. Live tracking has exactly one trigger, which is a session you started. Routes that arrive with a finished run are a separate thing, described at the top of this page: those come from Strava or Apple Health after the run is over, not from the app watching you.

How long we keep it: position points stay with the session for as long as your account exists, so you can look back at a run you shared. They are not currently on an automatic deletion schedule. Deleting your account deletes them.

Voice Messages and the Microphone

Inside a live session, you and the people holding your share link can leave each other short voice messages, or type a note instead. Everyone in the session hears everything: this is one shared room, not private mail.

The microphone: NavRun uses it only while you are actively recording a message, and only after you allow it. In the iOS app that is the standard iOS microphone prompt. On the share page in a web browser it is the browser's own microphone prompt. NavRun does not listen at any other time, and there is no background recording.

What gets stored: the audio file itself, the display name attached to it, how long the clip runs, and when it was sent. Clips are capped at 60 seconds. Typed notes are capped at 500 characters.

Where it is stored: voice clips are uploaded to a private bucket on Railway Object Storage, the S3-compatible storage run by our hosting provider, under a random, unguessable path. The bucket is not public. Clips are played back through signed links that expire, so a link copied out of the page stops working.

The safety check: every clip is transcribed automatically and that text is checked, so abuse can be caught without a person having to listen to someone's run first. The clip is held back while the check runs, and nobody approves anything by hand. The hold is bounded at about 25 seconds: if the check is slow or it fails, the clip goes out at the end of that window rather than being lost, so a clip can reach the runner before its check has finished. If the check comes back against it after that, the message is pulled from every screen, including screens already open. To do that, the audio and the text it produces are sent to our AI provider. That is the only thing either is used for. The text is not shown to anyone unless a message is reported or held back, and neither the audio nor the text is used for advertising, marketing, or to train anybody's model.

How long we keep it: voice messages are deleted 30 days after they are sent, on NavRun's servers, audio file and transcript included, by a job that runs daily. If you played a clip in the iOS app, a copy stays in the app's own storage on your phone until you delete the app.

We never use voice messages for advertising or marketing.

Who can hear them: you, and anyone holding the share link for that session, for as long as the link works and the message has not yet aged out.

People Without NavRun Accounts

This section is about the people you send a share link to. They are usually family, friends, or a crew at an aid station, and most of them will never create a NavRun account. NavRun still collects data from them, so they deserve to be told what.

What we collect from someone following your run:

  • A display name they type in themselves. It can be anything. It is stored with each message they send, and it is saved in a cookie on their own device for 90 days so they do not have to type it again.
  • Their voice recordings and typed notes, exactly as described in the Voice Messages section above. These are stored the same way, and deleted on the same 30-day schedule.
  • That they are here, once they add a name. Adding a name tells the runner that this person is out there with them, and it keeps that up to date while the page is open. It is the name and nothing else: no position, no record of what was read, and no count of anything. It is deleted 30 days after the last time that person had the page open. If someone never adds a name, nothing about their visit is recorded at all.

What we do not do: we do not create an account for them, ask for their email address, ask them to log in, build a profile of them, or use anything they send for advertising or marketing.

The safety check applies to them too. A clip sent from the share page is transcribed and checked exactly as described in the Voice Messages section above, held back while that runs, and pulled from every screen if the check comes back against it. The bounded hold described there applies here as well, so a clip can occasionally reach the runner before its check has finished. The audio and text go to our AI provider for that check and nothing else. It is there so that a runner alone at night is not handed abuse.

Where their name shows up: the names of people who have left messages appear to the runner in the app, as a short reminder of who has been out there with them. That list is drawn from messages, so a name disappears from it when the messages behind it are deleted.

Their choices: nobody has to send anything. Opening the page and reading it records nothing about the visitor. Adding a name is the one thing that changes that: it is what tells the runner someone is out there with them, and the hint under the name box on the page says so before anyone types. Anyone who has sent a message and wants it taken down, or wants their name removed, can email [email protected] and we will remove it. The runner can also turn the link off at any time, or end the session, and either one closes the page for everyone holding the link.

If you are the runner: the people you send the link to are trusting you with their voices. Our Community Rules cover what is and is not allowed in a session.

Your Rights

You have the right to:

  • Access: View all data we have about you
  • Delete: Delete your account and all associated data at any time from your Preferences page. All data is removed immediately and permanently.
  • Disconnect: Revoke Strava access at any time
  • Export: Download your data in standard formats

Data Retention

We retain your data for as long as your account is active. You can delete your account and all data at any time from your Preferences page. Deletion is immediate and permanent, and no data is retained after account deletion except where legally required.

Three things have their own schedule, whether or not your account is still open:

  • Voice messages and typed notes in a live session: deleted from NavRun 30 days after they are sent, audio file and transcript included. A clip you played in the iOS app stays on your own phone until you delete the app.
  • The names of people following a live session: when someone adds a name on your share page, that name is kept so you can see who is out there with you, and deleted 30 days after the last time they had the page open.
  • Live session position points: kept with the session for as long as your account exists. They are not currently deleted on a schedule of their own.

Cookies

We use essential cookies for:

  • Keeping you logged in
  • Security (CSRF protection)
  • Remembering the display name someone chose on a live share page, for 90 days, so they do not have to type it again
  • A second cookie on a live share page, also for 90 days, that stands for "this device" so a message can be traced back to the sender who left it and that sender can be blocked. It cannot be read by scripts, and it holds no name.

We also record the IP address of a device that sends a message, to limit how fast anyone can post.

Google Analytics also sets its own cookies to measure how the website is used, and Ahrefs Analytics is cookieless. Neither runs on a live share page or a crew sheet: those pages have a secret token in the URL, and the URL is exactly what analytics would send.

We do not use advertising cookies, and we do not sell or share your data with advertisers.

Children's Privacy

NavRun accounts are not intended for users under 13 years of age, and we do not knowingly let a child create one.

A live share link is different, because the runner decides who gets it and we never see who that is. A child can end up in a session because a parent opened the link at home and passed the phone over. If that has happened and you would rather it had not, email [email protected] and we will delete the message and the name it was sent under. You do not have to explain why, and there is no account to prove you own.

Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or through the app.

Contact Us

If you have questions about this privacy policy or your data, please contact us at: