Privacy Policy

Runergy

Version 1.1 – Horw, October 2026

Valid from: 9 October 2026

The protection of your personal data is of great importance to us. This privacy policy explains what personal data the Runergy running app (referred to as the ’App’) collects, how it is processed, and what rights you have as a data subject.

We act in accordance with the revised Swiss Data Protection Act (revDPA / nDPA, in force since 1 September 2023) and the implementing provisions based on it.

1. Data Controller

CompanyRunergy
OwnerMartin Lang
AddressKantonsstrasse 110, 6048 Horw, Switzerland
Emailinfo@runergy.ch
Websitewww.runergy.ch

As a sole trader, the owner named above is the data controller responsible for the processing of your personal data in connection with the Runergy app.

2. Principles of data processing

We process your personal data in accordance with the following principles:

3. What data we collect

3.1 Data that you actively provide to us

The following data is processed when you register for and use the app:

3.2 Data generated whilst using the app

The following data is collected automatically whilst using the app:

3.3 Automatically recorded technical data

When you access our services, technical access data is collected:

4. Purposes and legal basis for processing

We process your personal data for the following purposes:

PurposeLegal basis (revDSG)
Provision and operation of the appPerformance of a contract
Creation and management of your user accountPerformance of a contract
GPS tracking and run recordingConsent (location sharing)
Apple Health (HealthKit) workout metricsConsent (Health access)
Creation of personalised training plansPerformance of a contract
Payment processing and subscription accessPerformance of a contract
Customer communication and supportPerformance of a contract / legitimate interest
Technical development, stability, and crash diagnosticsLegitimate interest
Fulfilment of legal obligations (e.g. accounting)Legal obligation
Sending newsletters (only with consent)Consent
MessagesConsent – training reminders and training plan messages
→ this can be changed at any time in the device settings

5. GPS Data and Location Access

The Runergy app accesses your device’s GPS sensor only while an active run or workout is in progress. This includes situations where the screen is locked or the app is backgrounded during that active session, so distance, pace, and route can continue to be recorded correctly.

The location data collected is used for:

Runergy does not track your location outside an active run or workout. You can disable location access at any time in your device’s system settings. This will result in the app’s GPS functions no longer being available.

6. Apple Health and HealthKit

The Runergy Apple Watch app uses Apple Health (HealthKit) to support workout and run features. HealthKit access is requested only with your permission through Apple’s system prompts.

Depending on the permissions you grant, Runergy may read the following HealthKit data types:

HealthKit data is used solely to provide workout and run features, such as showing live heart rate and calories during a workout and storing completed training results in your Runergy account. HealthKit data is not used for advertising, is not sold, and is not used for marketing profiling.

Workout metrics derived from HealthKit during an active session (for example heart rate, calories, distance, and related training values) may be transmitted to and stored on Runergy’s secured backend as part of your training history, so your runs stay available in the app. Date of birth obtained from HealthKit for heart-rate zone estimation is used for that on-device calculation and is not sold or used for advertising. Retention of training and related HealthKit-derived metrics follows Section 11.

Runergy currently accesses HealthKit on a read-only basis and does not write workout samples or completed workout summaries to Apple Health.

You can revoke HealthKit access at any time in the Apple Health app or in iOS / watchOS Settings. After revocation, Runergy can no longer read the affected HealthKit data types.

7. Garmin Connect Integration

The Runergy app offers an optional integration with Garmin Connect that lets you synchronise your Garmin device and account with your Runergy training. This integration is only activated if you explicitly connect your Garmin account. This section explains, in accordance with Garmin’s requirements, how Garmin data is collected, used, processed, and stored, and whether it is shared with or processed by any third-party services.

7.1 Establishing the connection

You start the connection from within the app. Authorisation takes place exclusively through Garmin’s official login and consent screen using the OAuth 2.0 standard. Runergy never receives or stores your Garmin username or password. After you grant consent, Garmin provides us with secure access tokens that allow us to exchange data with Garmin on your behalf, together with the specific permissions (scopes) you have approved.

7.2 What Garmin data we collect

Depending on the permissions you grant, we may collect and process the following Garmin data:

7.3 How Garmin data is used

Garmin data is used solely to provide the features you have requested:

Garmin data is never used for advertising, is not sold, and is not used for any purpose unrelated to providing the Runergy service.

7.4 How Garmin data is processed

Garmin data reaches us in two ways: (1) on-demand requests to Garmin’s Wellness/Health and Training APIs when you connect your account or synchronise a workout; and (2) automatic notifications sent by Garmin to our secured server endpoints when new activity data is available, when your granted permissions change, or when your account is deregistered. We process these notifications to keep your data synchronised and to respect any changes to your consent.

7.5 How and where Garmin data is stored

Garmin data is stored on our secured backend infrastructure and linked to your Runergy account. Access and refresh tokens are stored so that the connection can be maintained, and application secrets are held in a dedicated secrets-management system. Data is transmitted using SSL/TLS encryption and is retained only for as long as necessary to provide the service, in line with Section 11 (Retention period).

7.6 Sharing with and processing by third parties

Garmin data is exchanged with the following parties:

RecipientPurpose
Garmin International, Inc.Source of the data; exchanged via Garmin’s Connect, Wellness/Health, and Training APIs and governed by Garmin’s own privacy policy (garmin.com/en-US/privacy/connect).
IT and hosting service providersTechnical operation and secure storage of the data on our behalf.

We do not share Garmin data with advertisers or data brokers, and we do not sell it. Any processor that handles Garmin data does so only to operate the Runergy service and under appropriate confidentiality and data protection obligations.

7.7 Disconnecting and deleting Garmin data

You can disconnect your Garmin account at any time in the app, which stops further data collection and deregisters Runergy’s access with Garmin. You may also revoke access directly in your Garmin Connect account settings. When you disconnect your Garmin account or delete your Runergy account, the associated Garmin authorisation data is removed, and any imported Garmin activity data is deleted or anonymised in accordance with Section 11.

8. Disclosure of Data to Third Parties and Service Providers

We will only disclose your personal data to third parties to the extent that it is necessary for the performance of the contract or permitted by law. Depending on the features you use, this includes the following categories of recipients:

RecipientPurpose of disclosure
Runergy hosting / backend infrastructureOperation of the App, account storage, training history, and API services
Apple App Store / In-App PurchaseSubscription purchase processing on iOS (see Section 9)
Google Play StoreSubscription purchase processing on Android
Firebase Authentication (Google)Account authentication and identity management (Firebase Privacy)
Firebase Cloud Messaging (Google)Push notifications and messaging delivery
Firebase Crashlytics (Google)Crash reporting and app stability diagnostics
Google Sign-InOptional sign-in with your Google account (Google Privacy Policy)
Sign in with AppleOptional sign-in with your Apple ID (Apple Privacy Policy)
Google MapsMap display and location visualisation for routes (Google Privacy Policy)
Garmin International, Inc.Optional Garmin Connect synchronisation when you connect Garmin (see Section 7)
Government authoritiesCompliance with legal obligations upon request

Data processing generally takes place in Switzerland. Some providers (for example Google and Apple) may process data in other countries, including the United States. Where service providers outside Switzerland or countries with an adequate level of data protection are used, we take appropriate measures (for example standard contractual clauses or reliance on applicable adequacy mechanisms) to protect your data.

Your data will not be shared for advertising purposes or sold to third parties.

9. Payments and Subscriptions

Subscription payments are processed by Apple (App Store / In-App Purchase) or Google (Google Play), depending on your device platform. Apple or Google handle your payment-card and payment-method details. Runergy does not receive or store your full payment-card number or payment credentials.

To validate purchases and manage access to paid features, Runergy receives and stores only the purchase identifiers and entitlement information needed for that purpose, such as product ID, transaction ID / original transaction ID, and subscription status or expiry. Current subscription prices are shown in the app purchase flow via the app store and may vary by storefront; they are not fixed in this privacy policy.

Terms of Use (EULA) for iOS subscriptions are provided in the app purchase flow and in the App Store listing. Where Runergy uses Apple’s standard EULA, the current Apple Standard EULA is available at: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.

10. Cookies, Diagnostics, and Crash Reporting

The app uses technically necessary mechanisms (for example session tokens) for authentication, security, and basic functionality.

For app stability, Runergy uses Firebase Crashlytics to collect crash reports and related diagnostic information (such as device type, OS version, app version, and stack traces). This processing supports troubleshooting and improving reliability. It is not used for advertising.

We do not use separate marketing/analytics tracking SDKs that require an in-app consent toggle beyond what is described here. If additional optional analytics are introduced later, we will update this policy and, where required, request consent.

11. Retention period

We retain your personal data only for as long as is necessary for the respective purposes or as required by legal retention obligations:

Data CategoryRetention Period
Account dataDuration of account maintenance + 30 days after account deletion
Training, GPS, and HealthKit-derived workout metricsDuration of account maintenance, until you delete the relevant training data, or until account deletion is completed
Purchase identifiers / entitlement recordsAs long as needed to manage access and meet statutory accounting retention (up to 10 years under the Swiss Code of Obligations where applicable)
Support and communication data3 years from last contact
Crash diagnostics (Firebase Crashlytics)According to Firebase/Crashlytics retention settings, typically up to 90 days unless a longer period is required for investigation
Technical log files90 days (automatic deletion)

When you delete your Runergy account, associated account data, training/location history, HealthKit-derived workout metrics stored in Runergy, and Garmin authorisation data linked to that account are deleted or anonymised, subject to any statutory retention that still applies (for example purchase/accounting records). Once a retention period has expired, the data will be deleted or anonymised so that it can no longer be traced back to you.

12. Data Security

We implement appropriate technical and organizational safeguards to protect your data from unauthorized access, loss, misuse, or alteration. These include, in particular:

Despite all due care, absolute security cannot be guaranteed. Data transmission over the Internet (e.g., via email) always carries a certain residual risk. We recommend that you do not send us any particularly confidential information via unsecured channels.

13. Your rights as a data subject

Under the revised Swiss Data Protection Act (revDSG), you have the following rights. These rights apply unless there are legal exceptions or overriding interests that preclude them:

RightsContent
Right of AccessYou may request, free of charge, information regarding whether and what data we process about you, as well as a copy of that data.
Right to RectificationYou may request the correction of inaccurate or incomplete data.
Right to DeleteYou may request the deletion of your data, provided that it is no longer needed or subject to statutory retention requirements.
Right to Data PortabilityYou may request that we provide your data to you in a commonly used format or—where technically feasible—transfer it directly to another data controller.
Restriction of ProcessingUnder certain conditions, you may request a temporary restriction of data processing.
Right to ObjectYou may object to the processing of your data, particularly for direct marketing purposes or legitimate interests.
Withdrawal of ConsentYou may withdraw your consent (e.g., for GPS access, HealthKit access, newsletters) at any time with future effect.

To exercise your rights, please contact: info@runergy.ch

Please note that in certain cases, we may need to verify your identity before we can respond to your request.

Exercising your rights will not result in any disadvantages for you (no higher prices, no poorer service).

14. Right to File a Complaint with the Supervisory Authority

You have the right to file a complaint with the competent data protection supervisory authority:

AuthorityFederal Data Protection and Information Commissioner (FDPIC)
AddressFeldeggweg 1, 3003 Bern, Switzerland
Websitewww.edoeb.admin.ch

15. Minors

The Runergy app is intended for users 16 years of age and older. We do not knowingly collect personal data from children under 16 without parental consent.

Legal guardians who become aware that a child under the age of 16 has created an account without their consent are asked to contact us at info@runergy.ch. We will promptly delete such accounts and data.

16. External Links

The app may contain links to external websites or services. We are not responsible for the privacy practices of external providers. We recommend that you read the privacy policies of the respective third-party providers.

17. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time, particularly in the event of changes to the app’s features, the legal landscape, or our data processing practices.

In the event of significant changes, we will notify you via email or by posting a clear notice in the app. The current version is available in the app and at www.runergy.ch. The version number and date at the top of this document indicate the status of the most recent update.

18. Contact and Privacy Inquiries

If you have any questions about this Privacy Policy, the processing of your personal data, or the exercise of your rights, please contact:

RunergyMartin Lang
AddressKantonsstrasse 110, 6048 Horw, Switzerland
Emailinfo@runergy.ch
Websitewww.runergy.ch