Last updated: 9 April 2026
Norma Steller
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen, Germany
Email: legal@runnerd.de
A Data Protection Officer is not required under Art. 37 GDPR, as the controller is a sole trader without the requisite number of employees, and the processing of special categories of data does not constitute the core activity within the meaning of Art. 37(1)(c) GDPR.
Runnerd has been developed according to the principle of Privacy by Design:
Categories of data processed:
With the user’s explicit consent, Runnerd reads workout data from the Apple Health app, including:
Legal basis:
Art. 6(1)(a) GDPR (consent) in conjunction with Art. 9(2)(a) GDPR (explicit consent for health data). Consent is obtained through a dedicated in-app consent dialog prior to the first HealthKit access.
Nature of processing:
Health data is processed and stored exclusively on the user’s device (Core Data). No transmission to external servers takes place. All calculations (Readiness Score, PMC, TRIMP, coaching recommendations) are performed on the device.
Withdrawal:
HealthKit consent may be withdrawn at any time:
Withdrawal applies with effect for the future. Data already stored locally remains on the device until the app is uninstalled and can be deleted within the app itself.
Data entered manually by the user (race entries, goals, shoe profiles, training partners, settings) is stored exclusively on the device and is subject to the same privacy principles as HealthKit data.
Scope of synchronisation:
When iCloud synchronisation is enabled, Runnerd data is synchronised between the user’s own devices via Apple’s CloudKit Private Database.
Nature of the Private Database:
The CloudKit Private Database is associated exclusively with the user’s iCloud account. The controller has no access to this data — neither technically nor organisationally.
Legal basis:
Art. 6(1)(a) GDPR (consent given by enabling iCloud synchronisation).
Apple’s privacy policy:
https://www.apple.com/legal/privacy/
Runnerd offers optional paid features. Purchases are processed exclusively via the Apple App Store (StoreKit 2). Payment data is not processed by the controller.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Runnerd does not use any third-party crash reporting tools. If the Apple setting “Share Analytics & Improvements” is enabled, Apple may forward aggregated, anonymised crash data to developers.
Runnerd performs automated analyses (Readiness Score, PMC, coaching recommendations). These serve exclusively to support personal training and produce no legal or similarly significant effects within the meaning of Art. 22 GDPR.
Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA) is involved in CloudKit/iCloud, App Store/StoreKit, and Apple Crash Reporting. Apple is certified under the EU-US Data Privacy Framework (DPF).
https://www.dataprivacyframework.gov
Netlify, Inc. (44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA) is used as the hosting provider for runnerd.de. Transfers are carried out on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
https://www.netlify.com/privacy/
The website runnerd.de is hosted by Netlify, Inc. When the website is accessed, information is automatically stored in server log files (browser type, operating system, referrer URL, hostname, time, IP address). This data is deleted automatically after 30 days at the latest.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Runnerd.de does not use cookies for tracking or advertising purposes and does not use any analytics tool.
When contact is made by email, the data transmitted is stored exclusively for the purpose of processing the enquiry and is not passed on to third parties.
Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR.
App data: Data is stored on the device for as long as the app is installed. Upon uninstallation, all locally stored data is deleted. Data in the CloudKit Private Database can be removed via iCloud.com → Manage Storage → Apps.
Email enquiries: Emails are deleted upon completion of the enquiry, and no later than six months thereafter.
The following rights are available under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
Training and health data is technically inaccessible to the controller. Rights with respect to this data can only be exercised directly on the device:
Requests to: legal@runnerd.de
The competent supervisory authority is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg
(State Commissioner for Data Protection, Brandenburg)
Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany
https://www.lda.brandenburg.de
This privacy policy will be updated in the event of changes to the applicable legal framework or the app’s functionality. The current version is always available in the app under Settings → Privacy and at runnerd.de/datenschutz.