Privacy Policy
Runergy
The protection of your personal data is of great importance to us. This privacy policy explains what personal data the Runergy running app (referred to as the ’App’) collects, how it is processed, and what rights you have as a data subject.
We act in accordance with the revised Swiss Data Protection Act (revDPA / nDPA, in force since 1 September 2023) and the implementing provisions based on it.
| Company | Runergy |
| Owner | Martin Lang |
| Address | Kantonsstrasse 110, 6048 Horw, Switzerland |
| info@runergy.ch | |
| Website | www.runergy.ch |
As a sole trader, the owner named above is the data controller responsible for the processing of your personal data in connection with the Runergy app.
We process your personal data in accordance with the following principles:
The following data is processed when you register for and use the app:
The following data is collected automatically whilst using the app:
When you access our services, technical access data is collected:
We process your personal data for the following purposes:
| Purpose | Legal basis (revDSG) |
| Provision and operation of the app | Performance of a contract |
| Creation and management of your user account | Performance of a contract |
| GPS tracking and run recording | Consent (location sharing) |
| Apple Health (HealthKit) workout metrics | Consent (Health access) |
| Creation of personalised training plans | Performance of a contract |
| Payment processing and subscription access | Performance of a contract |
| Customer communication and support | Performance of a contract / legitimate interest |
| Technical development, stability, and crash diagnostics | Legitimate interest |
| Fulfilment of legal obligations (e.g. accounting) | Legal obligation |
| Sending newsletters (only with consent) | Consent |
| Messages | Consent – training reminders and training plan messages → this can be changed at any time in the device settings |
The Runergy app accesses your device’s GPS sensor only while an active run or workout is in progress. This includes situations where the screen is locked or the app is backgrounded during that active session, so distance, pace, and route can continue to be recorded correctly.
The location data collected is used for:
Runergy does not track your location outside an active run or workout. You can disable location access at any time in your device’s system settings. This will result in the app’s GPS functions no longer being available.
The Runergy Apple Watch app uses Apple Health (HealthKit) to support workout and run features. HealthKit access is requested only with your permission through Apple’s system prompts.
Depending on the permissions you grant, Runergy may read the following HealthKit data types:
HealthKit data is used solely to provide workout and run features, such as showing live heart rate and calories during a workout and storing completed training results in your Runergy account. HealthKit data is not used for advertising, is not sold, and is not used for marketing profiling.
Workout metrics derived from HealthKit during an active session (for example heart rate, calories, distance, and related training values) may be transmitted to and stored on Runergy’s secured backend as part of your training history, so your runs stay available in the app. Date of birth obtained from HealthKit for heart-rate zone estimation is used for that on-device calculation and is not sold or used for advertising. Retention of training and related HealthKit-derived metrics follows Section 11.
Runergy currently accesses HealthKit on a read-only basis and does not write workout samples or completed workout summaries to Apple Health.
You can revoke HealthKit access at any time in the Apple Health app or in iOS / watchOS Settings. After revocation, Runergy can no longer read the affected HealthKit data types.
The Runergy app offers an optional integration with Garmin Connect that lets you synchronise your Garmin device and account with your Runergy training. This integration is only activated if you explicitly connect your Garmin account. This section explains, in accordance with Garmin’s requirements, how Garmin data is collected, used, processed, and stored, and whether it is shared with or processed by any third-party services.
You start the connection from within the app. Authorisation takes place exclusively through Garmin’s official login and consent screen using the OAuth 2.0 standard. Runergy never receives or stores your Garmin username or password. After you grant consent, Garmin provides us with secure access tokens that allow us to exchange data with Garmin on your behalf, together with the specific permissions (scopes) you have approved.
Depending on the permissions you grant, we may collect and process the following Garmin data:
Garmin data is used solely to provide the features you have requested:
Garmin data is never used for advertising, is not sold, and is not used for any purpose unrelated to providing the Runergy service.
Garmin data reaches us in two ways: (1) on-demand requests to Garmin’s Wellness/Health and Training APIs when you connect your account or synchronise a workout; and (2) automatic notifications sent by Garmin to our secured server endpoints when new activity data is available, when your granted permissions change, or when your account is deregistered. We process these notifications to keep your data synchronised and to respect any changes to your consent.
Garmin data is stored on our secured backend infrastructure and linked to your Runergy account. Access and refresh tokens are stored so that the connection can be maintained, and application secrets are held in a dedicated secrets-management system. Data is transmitted using SSL/TLS encryption and is retained only for as long as necessary to provide the service, in line with Section 11 (Retention period).
Garmin data is exchanged with the following parties:
| Recipient | Purpose |
| Garmin International, Inc. | Source of the data; exchanged via Garmin’s Connect, Wellness/Health, and Training APIs and governed by Garmin’s own privacy policy (garmin.com/en-US/privacy/connect). |
| IT and hosting service providers | Technical operation and secure storage of the data on our behalf. |
We do not share Garmin data with advertisers or data brokers, and we do not sell it. Any processor that handles Garmin data does so only to operate the Runergy service and under appropriate confidentiality and data protection obligations.
You can disconnect your Garmin account at any time in the app, which stops further data collection and deregisters Runergy’s access with Garmin. You may also revoke access directly in your Garmin Connect account settings. When you disconnect your Garmin account or delete your Runergy account, the associated Garmin authorisation data is removed, and any imported Garmin activity data is deleted or anonymised in accordance with Section 11.
We will only disclose your personal data to third parties to the extent that it is necessary for the performance of the contract or permitted by law. Depending on the features you use, this includes the following categories of recipients:
| Recipient | Purpose of disclosure |
| Runergy hosting / backend infrastructure | Operation of the App, account storage, training history, and API services |
| Apple App Store / In-App Purchase | Subscription purchase processing on iOS (see Section 9) |
| Google Play Store | Subscription purchase processing on Android |
| Firebase Authentication (Google) | Account authentication and identity management (Firebase Privacy) |
| Firebase Cloud Messaging (Google) | Push notifications and messaging delivery |
| Firebase Crashlytics (Google) | Crash reporting and app stability diagnostics |
| Google Sign-In | Optional sign-in with your Google account (Google Privacy Policy) |
| Sign in with Apple | Optional sign-in with your Apple ID (Apple Privacy Policy) |
| Google Maps | Map display and location visualisation for routes (Google Privacy Policy) |
| Garmin International, Inc. | Optional Garmin Connect synchronisation when you connect Garmin (see Section 7) |
| Government authorities | Compliance with legal obligations upon request |
Data processing generally takes place in Switzerland. Some providers (for example Google and Apple) may process data in other countries, including the United States. Where service providers outside Switzerland or countries with an adequate level of data protection are used, we take appropriate measures (for example standard contractual clauses or reliance on applicable adequacy mechanisms) to protect your data.
Your data will not be shared for advertising purposes or sold to third parties.
Subscription payments are processed by Apple (App Store / In-App Purchase) or Google (Google Play), depending on your device platform. Apple or Google handle your payment-card and payment-method details. Runergy does not receive or store your full payment-card number or payment credentials.
To validate purchases and manage access to paid features, Runergy receives and stores only the purchase identifiers and entitlement information needed for that purpose, such as product ID, transaction ID / original transaction ID, and subscription status or expiry. Current subscription prices are shown in the app purchase flow via the app store and may vary by storefront; they are not fixed in this privacy policy.
Terms of Use (EULA) for iOS subscriptions are provided in the app purchase flow and in the App Store listing. Where Runergy uses Apple’s standard EULA, the current Apple Standard EULA is available at: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.
The app uses technically necessary mechanisms (for example session tokens) for authentication, security, and basic functionality.
For app stability, Runergy uses Firebase Crashlytics to collect crash reports and related diagnostic information (such as device type, OS version, app version, and stack traces). This processing supports troubleshooting and improving reliability. It is not used for advertising.
We do not use separate marketing/analytics tracking SDKs that require an in-app consent toggle beyond what is described here. If additional optional analytics are introduced later, we will update this policy and, where required, request consent.
We retain your personal data only for as long as is necessary for the respective purposes or as required by legal retention obligations:
| Data Category | Retention Period |
| Account data | Duration of account maintenance + 30 days after account deletion |
| Training, GPS, and HealthKit-derived workout metrics | Duration of account maintenance, until you delete the relevant training data, or until account deletion is completed |
| Purchase identifiers / entitlement records | As long as needed to manage access and meet statutory accounting retention (up to 10 years under the Swiss Code of Obligations where applicable) |
| Support and communication data | 3 years from last contact |
| Crash diagnostics (Firebase Crashlytics) | According to Firebase/Crashlytics retention settings, typically up to 90 days unless a longer period is required for investigation |
| Technical log files | 90 days (automatic deletion) |
When you delete your Runergy account, associated account data, training/location history, HealthKit-derived workout metrics stored in Runergy, and Garmin authorisation data linked to that account are deleted or anonymised, subject to any statutory retention that still applies (for example purchase/accounting records). Once a retention period has expired, the data will be deleted or anonymised so that it can no longer be traced back to you.
We implement appropriate technical and organizational safeguards to protect your data from unauthorized access, loss, misuse, or alteration. These include, in particular:
Despite all due care, absolute security cannot be guaranteed. Data transmission over the Internet (e.g., via email) always carries a certain residual risk. We recommend that you do not send us any particularly confidential information via unsecured channels.
Under the revised Swiss Data Protection Act (revDSG), you have the following rights. These rights apply unless there are legal exceptions or overriding interests that preclude them:
| Rights | Content |
| Right of Access | You may request, free of charge, information regarding whether and what data we process about you, as well as a copy of that data. |
| Right to Rectification | You may request the correction of inaccurate or incomplete data. |
| Right to Delete | You may request the deletion of your data, provided that it is no longer needed or subject to statutory retention requirements. |
| Right to Data Portability | You may request that we provide your data to you in a commonly used format or—where technically feasible—transfer it directly to another data controller. |
| Restriction of Processing | Under certain conditions, you may request a temporary restriction of data processing. |
| Right to Object | You may object to the processing of your data, particularly for direct marketing purposes or legitimate interests. |
| Withdrawal of Consent | You may withdraw your consent (e.g., for GPS access, HealthKit access, newsletters) at any time with future effect. |
To exercise your rights, please contact: info@runergy.ch
Please note that in certain cases, we may need to verify your identity before we can respond to your request.
Exercising your rights will not result in any disadvantages for you (no higher prices, no poorer service).
You have the right to file a complaint with the competent data protection supervisory authority:
| Authority | Federal Data Protection and Information Commissioner (FDPIC) |
| Address | Feldeggweg 1, 3003 Bern, Switzerland |
| Website | www.edoeb.admin.ch |
The Runergy app is intended for users 16 years of age and older. We do not knowingly collect personal data from children under 16 without parental consent.
Legal guardians who become aware that a child under the age of 16 has created an account without their consent are asked to contact us at info@runergy.ch. We will promptly delete such accounts and data.
The app may contain links to external websites or services. We are not responsible for the privacy practices of external providers. We recommend that you read the privacy policies of the respective third-party providers.
We reserve the right to update this Privacy Policy at any time, particularly in the event of changes to the app’s features, the legal landscape, or our data processing practices.
In the event of significant changes, we will notify you via email or by posting a clear notice in the app. The current version is available in the app and at www.runergy.ch. The version number and date at the top of this document indicate the status of the most recent update.
If you have any questions about this Privacy Policy, the processing of your personal data, or the exercise of your rights, please contact:
| Runergy | Martin Lang |
| Address | Kantonsstrasse 110, 6048 Horw, Switzerland |
| info@runergy.ch | |
| Website | www.runergy.ch |