Privacy Policy
Runplanner keeps your data on your device wherever it can, and tells you plainly when it can't.
Last updated: August 26, 2026 · Applies to Runplanner for Android and iOS, and to runplannerapp.com
The Short Version
Runplanner is a local-first app. There are no accounts, no ads, and no live run recording. Your saved routes, plans, gear and settings live in encrypted files on your device and are never synced to us.
A few things do leave your device, and we'd rather be specific than reassuring: the coordinates you route between (our routing server needs them, and briefly logs them), what you type into the search boxes, routes you deliberately share as a link, and your email address if you join the Pro waitlist. Each is explained below.
What We Keep, and For How Long
| Data | Where it lives | How long |
|---|---|---|
| Routes, plans, gear, settings | Your device only, encrypted | Until you delete them or uninstall |
| Route request coordinates & shape | Our routing server | 7 days, then reduced to a coarse aggregate |
| Routes you share as a link | Our API | 90 days, then deleted automatically |
| Discover searches | Our API | 90 days, then deleted |
| Install identifier | Your device + routing server | Reset on reinstall; only a daily device count is kept |
| Waitlist email address | MailerLite + our database | Until you unsubscribe or ask us to delete it |
| Health & fitness data | Your device only | Never leaves it; never sent to us |
Data We Process
Location Data
Runplanner uses your device's GPS to show where you are and to guide you along a route. Runplanner does not record runs — there is no activity tracker, and location is not collected in the background for tracking purposes. Location is used for:
- Showing your position on the map while planning
- Turn-by-turn guidance while you navigate a planned route
- Waypoints you place when planning a route
- Centring the map, roundtrip generation, and weather for a starting point
Storage: Your position is not stored or uploaded. The waypoints of a route you save stay on your device — but calculating that route requires sending those coordinates to our routing server, which is described in When Data Leaves Your Device.
Health & Fitness Data
If you choose to import past runs, Runplanner reads workout history and the GPS routes attached to those workouts from Health Connect (Android) or Apple Health (iOS). This happens only when you start an import, and only after you grant permission in the system dialog.
- Access is read-only. Runplanner never writes to, edits or deletes your health records.
- Imported runs are converted into ordinary saved routes on your device.
- Health data is never transmitted to our servers, never used for analytics, and never shared with any third party.
Control: You can revoke health access at any time in Health Connect or in iOS Settings > Privacy & Security > Health. Revoking it does not remove routes you already imported; delete those in the app.
Camera Access
The camera is used to scan Runplanner QR codes when importing a route or workout plan, and — if you choose one — to take a profile photo.
Storage: QR scanning is processed in real time and discarded immediately; no images are kept. A profile photo you take or pick is stored on your device only and is never uploaded.
Photos and Calendar
Two optional features ask for system permissions, and neither runs unless you start it:
- Photo library: used if you pick a profile photo, or save a route share image. Runplanner does not browse, index or upload your library.
- Calendar: used only when you tap "Add to calendar" for a scheduled run. Runplanner writes that one event and never reads your existing events.
Reminders and Background Activity
If you schedule a run, Runplanner may act while the app is closed:
- Reminders are scheduled locally on your device. Nothing is sent through a push server — we cannot see them.
- Pre-run weather briefings fetch a forecast for the starting point of your next scheduled run. This sends those coordinates to Open-Meteo while the app is closed. It only happens for runs you have scheduled.
- The Next Run widget writes your next run's details to shared storage on your device so the home screen can display it. It stays on the device.
Local Storage
The app stores data on your device to provide its features:
- Saved routes and waypoints
- Workout plans, gear and scheduled runs
- App settings and preferences
- Cached map and road network data for offline use
Encryption: Routes, plans, gear and schedules are stored as AES-256 encrypted files, with the key held in your device's secure keystore.
Deletion: Uninstalling the app removes all stored data. You can also delete individual routes, plans and scheduled runs from within the app.
When Data Leaves Your Device
A route planner cannot snap a route to real roads without sending coordinates somewhere. Here is exactly what leaves, when, and what happens to it.
Planning a route
When you place waypoints, the app sends those coordinates to our self-hosted routing service at valhalla.runplannerapp.com, together with an anonymous install identifier (see below). To keep the service healthy and to understand where it is used, that server keeps a log entry for each request containing the first waypoint's coordinates and the shape of the calculated route, plus timing and error information.
Retention: These log entries are deleted after 7 days. Before deletion they are reduced to permanent aggregates: a daily request count, a daily count of distinct devices, and a coarse grid of activity by area. The aggregates contain no route shapes and no identifiers.
The install identifier
On first launch the app generates a random identifier and sends it as a header to the routing service only. It is not derived from your device, phone number, advertising ID or any account, it is not shared with third parties, and it is regenerated if you reinstall. Its only purpose is counting how many distinct devices use the routing service each day.
Sharing a route with a link
When you create a share link, the route's name, waypoints, pace and creation date are uploaded to our API and stored so that whoever opens the link can load it. This happens only when you tap share and choose a link; it never happens automatically for routes you simply save. The same applies to shared workout plans.
Retention: Shared routes and plans stop working 90 days after creation and are then deleted from our database outright. Anyone with the link can open it during that window, so treat a share link as public. To have one removed sooner, email us the link.
Discover
The Discover tab loads a curated, editorially maintained catalog of public routes from our API. Browsing it does not change the catalog. We count views and saves per route, per day, as plain totals — these are not linked to you, your device or your install identifier.
We also log the searches themselves, so we know which areas and distances people look for and where the catalog comes up empty. Each entry holds what you typed into the Discover search box, the filters you set, how many results came back, and the map location you were browsing rounded to two decimals — roughly a one-kilometre square, not your actual position. No install identifier, IP address or device information is stored alongside it, so entries cannot be traced back to you or joined up with each other.
Retention: These entries are deleted after 90 days. Place search in the map tab is a separate feature and is not logged by us at all — see Photon below.
The Runplanner Pro waitlist
Runplanner Pro does not exist yet. If you enter your email address and tap join, that address is sent to MailerLite, our email provider, and stored in our own database as a backup, along with the date and which page you signed up from. This is the only personal identifier Runplanner collects, and it is collected only if you type it in.
Your control: Every email includes an unsubscribe link. Unsubscribing stops the mail; to have your address erased from both MailerLite and our database, email us and we will delete it.
What never leaves: your saved route library, workout plans, gear, scheduled runs, settings, profile photo, health and fitness data, and your live position while navigating.
Third-Party Services
To provide mapping, routing and related features, Runplanner connects to the following external services. Apart from the install identifier sent to our own routing service, no identifier of ours is attached to these requests.
Runplanner Routing Service
Our self-hosted Valhalla server (valhalla.runplannerapp.com) is the primary route engine, and also generates roundtrips and surface data. Receives waypoint coordinates and the install identifier. See above for what it logs.
Mapbox
Provides map tiles and styling. Subject to Mapbox Privacy Policy.
OpenStreetMap & Overpass
Provides road network data used by the offline fallback router, which runs only when our own routing service cannot be reached. Requests go to one of the public Overpass mirrors — overpass-api.de, overpass.kumi.systems or overpass.openstreetmap.fr — and contain the map area you are planning in. OSM Privacy Policy.
Nominatim
Looks up street names for turn-by-turn instructions during navigation. Receives coordinates along your route. OSMF Privacy Policy.
Photon (Komoot)
Powers place search. Receives what you type into the search box and your approximate area to rank results. Komoot Privacy Policy.
Open-Meteo
Provides weather and elevation data for a route's coordinates, including pre-run briefings. Open-Meteo Terms.
Open-Elevation
Fallback elevation lookup when Open-Meteo is unavailable. Receives route coordinates only.
Runplanner Static & Discover
static.runplannerapp.com serves a traffic-signal dataset the app caches offline; runplannerapp.com/api serves the Discover catalog and share links. Neither receives an identifier.
Firebase Analytics & Crashlytics
Optional diagnostics and usage analytics, off by default. See the section below. Firebase Privacy.
MailerLite
Processes email addresses submitted to the waitlist to send welcome emails and updates. MailerLite Privacy Policy.
Note: Contacting any of these services necessarily reveals your device's IP address to them, as with any internet request. We do not add identifiers of our own to those requests, apart from the install identifier sent to our own routing service.
Diagnostics and Analytics
Both of the following are controlled by a single opt-in toggle in Settings > Privacy, which is off by default. Leave it off and neither collects anything: both ship switched off at the system level and stay dormant unless the toggle turns them on, so nothing is gathered during app start-up either.
- Firebase Analytics: counts feature usage — routes created, navigation started, a plan shared — and which screens are opened. It never includes coordinates, route geometry, route names, or anything you typed.
- Firebase Crashlytics: reports crashes and handled errors so we can fix them, attaching your device's manufacturer, brand, model identifier, marketing name, OS version and whether it is a physical device or a simulator. The device name you set yourself is deliberately excluded, because it usually contains a real name. Crash reports may contain technical details such as file names and error messages, but no route data and no personal identifiers.
Advertising: the Android advertising ID permission is explicitly removed from the app, and no advertising or attribution SDK is present.
What We Don't Do
No Accounts
We don't require registration or accounts to use the app
No Run Recording
Runplanner plans and navigates; it never records or logs your runs
No Data Sales
We never sell your data, and never share it for advertising
No Route Sync
Your saved library stays on your device — only links you deliberately share are uploaded
No Ads or Tracking
No advertising networks, no ad ID, no cross-app tracking
No Social Login
No Facebook, Google, or other social integrations
Sharing Features
Runplanner includes optional sharing features that you control. Nothing is shared unless you start it:
- Share links: creating a link uploads the route to our API so the recipient can open it. Links work for 90 days, after which the stored route is deleted, and anyone holding a live link can view the route.
- QR codes: generate a code containing the route to share in person. Scanning happens device to device.
- GPX export: export a route as a GPX file for another app or watch. The file is written to your device and goes wherever you send it.
- Share images: a route card image is rendered on your device and handed to whichever app you pick.
A route can reveal where you live if it starts at your front door. Consider starting shared routes at a nearby landmark instead.
Your Rights & Control
Almost everything Runplanner holds is on your device, so most control is directly in your hands:
- Delete anytime: remove individual routes, plans and scheduled runs in the app, or remove everything by uninstalling.
- Export your data: export any route as GPX to keep a backup or move it to another service.
- Revoke permissions: disable location, camera, photos, calendar or health access at any time in your device settings.
- Opt out of diagnostics: the analytics and crash reporting toggle lives in Settings > Privacy and is off unless you turn it on.
- Remove a share link: links stop working after 90 days and the stored route is then deleted; email us the link to have it removed sooner.
- Access, correct or erase your email: if you joined the waitlist, unsubscribe from any email, or write to us to have the address erased entirely.
GDPR: if you are in the EEA or UK you have the right to access, correct, erase, restrict or port your personal data, and to object to its processing. Because Runplanner has no accounts, the only personal data we hold that can be tied to you is a waitlist email address — write to us and we will act on any such request. You also have the right to complain to your national data protection authority.
This Website
Separately from the app, runplannerapp.com itself processes a small amount of data:
- Google Analytics measures page visits so we know which pages are useful. It sets cookies and receives your IP address. Google Privacy Policy.
- Google Fonts, unpkg and LottieFiles serve the site's typeface, icons and the animation on the home page. Loading them reveals your IP address to those providers.
- Local storage remembers your light or dark theme choice. It stays in your browser and is never sent anywhere.
- Cloudflare hosts the site and its API and processes request data, including IP addresses, to serve pages and to rate-limit abuse. We do not store visitor IP addresses ourselves.
You can block cookies in your browser or use an ad blocker; the site works fine without analytics.
Android and iOS
Android
Health data is read through Health Connect under three read-only permissions — exercise, exercise routes, and health data history, the last of which lets you import runs older than the past 30 days — and is used solely to import past runs into the app. It is not transmitted, sold, or used for advertising, and is never shared with third parties. The advertising ID permission is removed from the app.
iOS
Runplanner ships a privacy manifest declaring what it collects. It does not track you across apps or websites, requests no tracking permission, and contacts no tracking domains. Health data read from Apple Health stays on your device.
Children's Privacy
Runplanner is not directed at children and we do not knowingly collect personal information from anyone under 13. The app needs no account and asks for no personal details to work; the only personal identifier it can collect is a waitlist email address, which is entered voluntarily. If you believe a child has submitted an email address to us, contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy as the app changes. Any changes will be posted on this page with an updated revision date, and material changes to what we collect will also be noted in the app's What's New screen. We encourage you to review this policy periodically.
Contact Us
Questions about this policy, or a request to delete a share link or your email address? Write to us and we'll respond within 30 days:
[email protected]