Privacy Policy
Last updated: 5 July 2026
1. Who we are
Runora ("we", "us") provides a personalised running coaching web app. This policy explains what data we collect and how we use it.
2. Data we collect
- Account: email address and password (hashed).
- Runner profile: age, sex, height, weight, training history, goals, injuries, equipment.
- Weekly check-ins: energy, motivation, stress, confidence, pain notes.
- Coaching reports generated for you.
- Basic technical data (browser, device) needed to run the service.
- Strava data (only if you choose to connect your Strava account) — see Section 9 below.
3. How we use it
We use your data to generate personalised coaching reports and training plans, to operate and improve the service, and to send you reminders about your training.
4. AI processing
Your profile and check-in data are sent to our coaching model provider to generate your reports. Data is processed for the purpose of producing your plan and is not used to train third-party models.
5. Storage and security
Data is stored on managed cloud infrastructure with encryption in transit and at rest. Access is restricted by row-level security so you can only access your own data.
6. Your rights
You can request access to, correction of, or deletion of your data at any time by emailing us. You can also delete your account from inside the app.
7. Cookies & local storage
We use essential cookies and browser local storage to keep you signed in and to remember your preferences (e.g. units). We do not use third-party advertising cookies, analytics that build cross-site profiles, or tracking pixels.
8. Data retention & deletion
You can delete your account and all associated data at any time from Account settings, or by emailing hello@runora.app. Account deletion removes your profile, check-ins, coaching reports, run analyses, Strava connection and all imported Strava activities. Backups are rotated within 30 days. Anonymised, aggregated statistics (e.g. total users, aggregate AI usage) may be retained.
9. Strava integration
Connecting Strava is entirely optional. Runora works without it — you can use manual check-ins instead. If you choose to connect your Strava account, the following applies:
- What we access: your basic Strava profile (name, athlete ID, profile image, country, sex, weight if provided) and your running activities (date, name, type, distance, moving time, elapsed time, pace, average and max heart rate, elevation gain, cadence, perceived effort, calories, and workout type). We do not access your private notes, private messages, followers list, photos, or activities you have kept private in Strava unless the scopes you approve include them.
- Scopes you authorise: we only receive the permissions you grant during Strava's OAuth consent screen. You choose what to approve, and you can approve less than we request. Runora will only work with the scopes you actually grant.
- Why we collect it: to build an objective picture of your training — weekly volume, intensity, pace trends, heart-rate response, recent workouts and long runs — so the coaching content is grounded in what you actually did rather than what you remember.
- How we use it: your Strava activities are combined with your profile and check-ins to generate personalised coaching reports, weekly summaries and training insights. A capped summary of recent activity is sent to our coaching model provider for the sole purpose of producing your report; it is not used to train third-party models.
- Token storage: the OAuth access token and refresh token issued by Strava are stored encrypted on our managed cloud infrastructure, protected by row-level security so only your account can use them. Tokens are only used to request the data described above on your behalf.
- Access control: your Strava data is only visible to your own authenticated Runora account. Database row-level security prevents any other user from reading it, and our staff do not access it except where strictly necessary for support or security and only with your consent.
- Disconnecting & deletion: you can disconnect Strava at any time from the Profile & Goal page in Runora. Disconnecting immediately revokes our stored access and refresh tokens with Strava, deletes them from our database, and deletes every Strava activity we have stored for you. You can additionally revoke Runora's access from your Strava account settings at any time. Deleting your Runora account also deletes all synced Strava data.
- No sale or sharing of data: we do not sell your Strava data, share it with advertisers, or make it available to any third party, other than the coaching model provider strictly for the purpose of generating your report. Runora complies with the Strava API Agreement, including the prohibition on selling Strava data or using it for advertising.
- Legal basis (UK GDPR): we process your Strava data on the basis of your consent, given when you complete the Strava OAuth flow. You can withdraw that consent at any time by disconnecting Strava, without affecting the lawfulness of processing before withdrawal.
10. Contact
For any privacy questions, contact us at hello@runora.app.