Last updated: August 19, 2026
At NavRun, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information.
When you use NavRun, we collect:
We use your information solely to:
Your data may only be shared in these limited circumstances:
Apple Health data is never shared, sold, or used for advertising or marketing. Full stop. See the Apple Health section below for details.
We implement industry-standard security measures to protect your data:
NavRun uses the following services to operate. Each is bound by their own privacy policy and processes data only as needed to provide their service:
Generative AI affects this community, and plenty of runners want less of it in their lives. That is fair, and it is why this is a choice rather than a default.
Knowing how to train for an ultra sits with veterans and with coaches most of us cannot reach. It is in here so nobody gets gatekept out of this sport. That is the reason NavRun offers it at all, and the reason it is offered rather than imposed.
With AI on: your week is written for you, each run gets read back, and you get weekly reports and race strategy.
With AI off: your week is built from your own runs by rules. Same caps, same rest days. Nothing about your training reaches a model.
What is sent, when it is on: runs, heart rate, race goals, and Apple Health workouts go to Anthropic or OpenAI. Neither trains on them. Your name, email address, and payment details are never sent.
Turning it on or off: the switch is on your Preferences page on the web and in Settings in the iOS app. Turning it off takes effect immediately, for the background weekly reports and plan revisions as well as anything you trigger yourself. Turning it off deletes nothing you already have: plans, run feedback, and reports stay in your account.
The one exception, either way: voice clips and messages sent in a live session are checked for safety before the people holding your share link hear or read them. That check runs whether AI is on or off, because turning it off would not give you privacy, it would remove a safety check standing between unscreened content and someone else's phone. See the Voice Messages section below.
If you use the NavRun iOS app, you can grant permission for NavRun to read your running workouts from Apple Health. This data is read on-device with your explicit consent through the standard iOS permission prompt.
What we read: Running workouts only: start time, duration, distance, pace, and heart rate.
What we do with it:
What we will never do with Apple Health data:
You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → NavRun. We will stop reading new data immediately. Previously synced workouts remain in your NavRun account until you delete them or your account.
With your permission, NavRun sends push notifications about your training plan, workout reminders, weekly reports, and race-day pacing. To deliver these, we store an Apple Push Notification service token, routed through Firebase Cloud Messaging (a Google service).
You can disable push notifications at any time in iOS Settings → Notifications → NavRun.
A live session is the feature that lets the people you care about follow along while you are still out on a run. It only ever starts because you tapped start in the NavRun app, and it stops when you end it.
What we collect while a session is running: your position (latitude and longitude), the time your phone took the reading, how accurate iOS said that reading was, your elevation where the phone reports it, and your phone's battery level at that moment. The battery level is there so the people following you can tell the difference between a quiet stretch and a dead phone.
How often: about one position every 25 minutes. iOS has no way to hand an app a location on a timer, so the app receives readings continuously and throws almost all of them away on your phone. Only the roughly one-per-25-minutes that survives is ever sent to NavRun. The app asks iOS for accuracy of about 100 metres rather than the finest fix your phone can produce.
In the background: yes. This is the point of the feature. Once a session is running, your position is still collected with your phone in a pocket and the screen off, which is why the app asks for the "Always" location permission. iOS shows its own location indicator while this is happening, and you can revoke the permission at any time in iOS Settings → Privacy & Security → Location Services → NavRun.
When you have no signal: positions wait on your phone and upload when you are back in range. Nothing is lost, it just arrives late.
When it stops: when you end the session, or automatically 48 hours after it started, whichever comes first.
Outside a live session, the NavRun app does not ask iOS for your live position at all. Live tracking has exactly one trigger, which is a session you started. Routes that arrive with a finished run are a separate thing, described at the top of this page: those come from Strava or Apple Health after the run is over, not from the app watching you.
How long we keep it: position points stay with the session for as long as your account exists, so you can look back at a run you shared. They are not currently on an automatic deletion schedule. Deleting your account deletes them.
Inside a live session, you and the people holding your share link can leave each other short voice messages, or type a note instead. Everyone in the session hears everything: this is one shared room, not private mail.
The microphone: NavRun uses it only while you are actively recording a message, and only after you allow it. In the iOS app that is the standard iOS microphone prompt. On the share page in a web browser it is the browser's own microphone prompt. NavRun does not listen at any other time, and there is no background recording.
What gets stored: the audio file itself, the display name attached to it, how long the clip runs, and when it was sent. Clips are capped at 60 seconds. Typed notes are capped at 500 characters.
Where it is stored: voice clips are uploaded to a private bucket on Railway Object Storage, the S3-compatible storage run by our hosting provider, under a random, unguessable path. The bucket is not public. Clips are played back through signed links that expire, so a link copied out of the page stops working.
The safety check: every clip is transcribed automatically and that text is checked, so abuse can be caught without a person having to listen to someone's run first. The clip is held back while the check runs, and nobody approves anything by hand. The hold is bounded at about 25 seconds: if the check is slow or it fails, the clip goes out at the end of that window rather than being lost, so a clip can reach the runner before its check has finished. If the check comes back against it after that, the message is pulled from every screen, including screens already open. To do that, the audio and the text it produces are sent to our AI provider. That is the only thing either is used for. The text is not shown to anyone unless a message is reported or held back, and neither the audio nor the text is used for advertising, marketing, or to train anybody's model.
How long we keep it: voice messages are deleted 30 days after they are sent, on NavRun's servers, audio file and transcript included, by a job that runs daily. If you played a clip in the iOS app, a copy stays in the app's own storage on your phone until you delete the app.
We never use voice messages for advertising or marketing.
Who can hear them: you, and anyone holding the share link for that session, for as long as the link works and the message has not yet aged out.
This section is about the people you send a share link to. They are usually family, friends, or a crew at an aid station, and most of them will never create a NavRun account. NavRun still collects data from them, so they deserve to be told what.
What we collect from someone following your run:
What we do not do: we do not create an account for them, ask for their email address, ask them to log in, build a profile of them, or use anything they send for advertising or marketing.
The safety check applies to them too. A clip sent from the share page is transcribed and checked exactly as described in the Voice Messages section above, held back while that runs, and pulled from every screen if the check comes back against it. The bounded hold described there applies here as well, so a clip can occasionally reach the runner before its check has finished. The audio and text go to our AI provider for that check and nothing else. It is there so that a runner alone at night is not handed abuse.
Where their name shows up: the names of people who have left messages appear to the runner in the app, as a short reminder of who has been out there with them. That list is drawn from messages, so a name disappears from it when the messages behind it are deleted.
Their choices: nobody has to send anything. Opening the page and reading it records nothing about the visitor. Adding a name is the one thing that changes that: it is what tells the runner someone is out there with them, and the hint under the name box on the page says so before anyone types. Anyone who has sent a message and wants it taken down, or wants their name removed, can email [email protected] and we will remove it. The runner can also turn the link off at any time, or end the session, and either one closes the page for everyone holding the link.
If you are the runner: the people you send the link to are trusting you with their voices. Our Community Rules cover what is and is not allowed in a session.
You have the right to:
We retain your data for as long as your account is active. You can delete your account and all data at any time from your Preferences page. Deletion is immediate and permanent, and no data is retained after account deletion except where legally required.
Three things have their own schedule, whether or not your account is still open:
NavRun accounts are not intended for users under 13 years of age, and we do not knowingly let a child create one.
A live share link is different, because the runner decides who gets it and we never see who that is. A child can end up in a session because a parent opened the link at home and passed the phone over. If that has happened and you would rather it had not, email [email protected] and we will delete the message and the name it was sent under. You do not have to explain why, and there is no account to prove you own.
We may update this policy from time to time. We will notify you of significant changes by email or through the app.
If you have questions about this privacy policy or your data, please contact us at: