This Policy explains what data the "Start Running" mobile app (the App) - a running programme built on alternating walking and running intervals - collects, why it is processed, who it is shared with, how long it is kept and how you can manage it.
The data controller is the developer of the App (we, the Operator). Contact for any data protection enquiries: support@sit30.net.
Processing is carried out in accordance with Russian Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" and, for users in the European Union, with the General Data Protection Regulation (GDPR, EU Regulation 2016/679).
By installing and using the App you confirm that you have read this Policy. If you do not agree with it, please do not use the App.
Your account is created through the shared SIT 30 service account and is used across our other apps as well. Registration and sign-in involve:
You can also sign in with Apple or Google. With Sign in with Apple we receive your Apple ID identifier, your name (if you shared it) and your email address; if you chose "Hide My Email", we only ever get a relay address ending in @privaterelay.appleid.com. With Google we receive your email address, your name and a link to your Google profile picture. In neither case is your password shared with us.
An account is needed to synchronise your data across devices and to use the community chat. Without one the App works in local mode (see section 5).
To calculate calorie expenditure and heart rate zones, the App asks you on first launch and stores in your profile:
The profile is shared across SIT 30 apps: height and weight entered here will also appear in our other apps connected to the same account, for example the calorie counter. Height, weight and sex are health-related information, so they are processed only with your explicit consent, which you give by filling in these fields.
For every workout the following is stored and, when you are signed in, sent to the server:
During an outdoor workout the App records your route. For each point the following is stored and sent to the server:
Coordinates are collected only during an active workout that you started with the start button, and keep being collected when the App is in the background or the screen is locked - this is what the "Location - Always" permission is for. Between workouts the App does not track your movements and does not collect coordinates in the background.
Location is optional: in treadmill mode GPS is not switched on at all, distance is counted by the pedometer and no coordinates are recorded.
Through the system motion sensors (Core Motion) the App receives your step count for the workout. Steps are stored with the workout and sent to the server. On a treadmill the pedometer also serves as the source of distance.
The iPhone has no heart rate sensor of its own and the App does not measure your pulse. It reads the measurements that your Apple Watch, headphones or chest strap take during the workout and write into the Health app. The values obtained (beats per minute and the time of the measurement) are stored with the workout and synchronised with the server so that the heart rate chart is available on your other devices. If read access is not granted or there is nothing to measure with, the workout is recorded without it.
With your permission the App:
Automatic saving of workouts can be turned off in the App settings, and the permissions themselves can be revoked in the Health app. Data obtained from Health is used only for the App features described in this Policy: it is not shared with advertising networks, data brokers or any other third parties and is not used for marketing. Apart from heart rate values attached to your workout, no Health metrics are sent to our server.
If you use the Apple Watch app, during a workout the watch starts a workout session of its own: this is what makes heart rate measurements frequent and shows the workout in Fitness on the watch. The watch sends your iPhone the heart rate, active calories and, in treadmill mode, distance and steps. This exchange happens directly between your own devices through the operating system, without involving our server.
When you sign in and whenever the notification token changes, the App sends the server:
As with any network request, the server learns the IP address of your connection, which is recorded in the technical logs.
The App includes a shared chat available after you sign in. It processes: your name and profile picture, the text of the topics and messages you create, attached photos, likes, reports about messages and the list of users you have blocked. Everything you post in shared topics is visible to other chat participants (see section 4).
Camera and photo library access is requested only at the moment you attach a photo or change your avatar yourself. The App does not browse your gallery and takes nothing from it beyond the images you select.
If the App crashes or runs into an error, we receive a crash report through the Firebase Crashlytics service. The report contains:
The report is created at the moment of the crash and sent the next time the App launches. It contains no coordinates, routes, workout contents, health metrics, email address or name.
The detailed technical log of the App's operation is kept only in the device's memory, is available to you in the settings and is never sent anywhere; it is erased when the App is closed.
The App includes the Firebase Analytics service. We do not send it any events of our own containing your workout data - only the anonymised information the service records by itself is collected:
The following is never sent to analytics: coordinates and routes, workout and health metrics, height, weight, heart rate, email address, name, chat message texts.
We use this information only to improve the App. The App does not request the advertising identifier (IDFA): the system tracking dialog is not shown, no advertising is displayed, and the collected data is not linked to information from other apps and websites.
The App does not collect or request: payment data, card or account numbers (there are no purchases in the App), phone number, postal address, identity document details, the contents of your address book, photos and videos from your device other than those you select, or data from other apps beyond the Health metrics listed in sections 2.6 and 2.7.
We do not use advertising networks, advertising identifiers or trackers, we do not pass data to data brokers, we do not sell it and we do not use it to train artificial intelligence systems. The third-party services that do receive data are listed in section 6.
| Data | Purpose | GDPR basis |
|---|---|---|
| Email, password, login, name, avatar | Creating an account, signing in, syncing across devices, taking part in the chat | Performance of a contract, Art. 6(1)(b) |
| Date of birth, sex, height, weight, target weight, activity level | Calculating calorie expenditure and heart rate zones, personal workout metrics | Explicit consent, Art. 6(1)(a) and Art. 9(2)(a) |
| Coordinates, route points, speed, altitude | Recording the route, calculating distance and pace, the workout map | Consent, Art. 6(1)(a); performance of a contract, Art. 6(1)(b) |
| Steps, distance, duration, intervals, calories | Workout metrics, statistics, progress through the programme and awards | Performance of a contract, Art. 6(1)(b) |
| Heart rate | The heart rate chart and heart rate zones of the workout | Explicit consent, Art. 6(1)(a) and Art. 9(2)(a) |
| Push token, device model, OS and App version, language | Delivering chat notifications and workout reminders, compatibility diagnostics | Consent (notifications), Art. 6(1)(a); legitimate interest, Art. 6(1)(f) |
| Messages, photos and marks in the chat | Running the community chat, moderation and handling reports | Performance of a contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) |
| IP address, request logs | Security, protection against abuse, incident investigation | Legitimate interest, Art. 6(1)(f) |
| Crash reports | Finding and fixing errors, App stability | Legitimate interest, Art. 6(1)(f) |
| Anonymised usage information | Understanding how the App behaves on different devices, improving it | Legitimate interest, Art. 6(1)(f) |
You give consent for location, motion, Health and notifications in the iOS system dialogs and can withdraw it at any time in your device settings. Once withdrawn, the corresponding feature stops working (without location, for example, the route will not be recorded), while data saved earlier remains until you delete it yourself.
Visible to other chat participants:
Visible to no one but you:
The App never publishes your workouts automatically and does not show them to other users. If you yourself post a message about a run in the chat or share an award card through the system share sheet (a messenger, a social network, email), that information becomes available to the recipients - what happens to it next is governed by the rules of the service you chose.
The App can be used without creating an account. In this mode the training programme, your runs, routes, statistics and awards are stored only in your device's memory, nothing is sent to the server and the chat is unavailable. Such data is deleted together with the App and cannot be restored by us, because we never had it. Saving workouts to Health still works: that is your device's own storage, not our server.
We do not sell your data, do not pass it to advertising networks or data brokers and do not use it to train artificial intelligence systems.
Data is shared only with the following service providers and only to the extent required for the corresponding feature to work:
| Recipient | Function | Data shared |
|---|---|---|
| Google LLC (Firebase Cloud Messaging) | Delivery of push notifications | Device token, notification text |
| Google LLC (Firebase Crashlytics) | App crash diagnostics | Call stack, device model, OS and App version, anonymous installation identifier |
| Google LLC (Firebase Analytics) | Anonymised usage information | Launch and session facts, device model, OS and App version, language, country by IP, App instance identifier |
| Google LLC (Sign in with Google) | Authentication via the "Sign in with Google" button | The exchange happens between you and Google; we receive back your email address, name and a link to your profile picture |
| Apple Inc. (Sign in with Apple) | Authentication via the "Sign in with Apple" button | The exchange happens between you and Apple; we receive back your Apple ID identifier and an email address (real or relayed) |
| Apple Inc. (MapKit) | Displaying the route map | Coordinates of the displayed map area |
Maps are drawn by the operating system, and requests to the mapping service are handled by Apple under its own privacy policy. The Health app and the exchange with Apple Watch are your device's own storage and mechanisms, not a transfer of data to third parties.
In addition, data may be disclosed upon a reasoned request from authorised government bodies where such a request is made in the manner prescribed by law.
The servers holding the App's data are physically located in the Russian Federation. This meets the requirement of Part 5, Article 18 of Federal Law No. 152-FZ on localising databases of Russian citizens.
Retention periods:
| Category | Period |
|---|---|
| Account and profile data | While the account is active |
| Workouts, routes, heart rate, awards | Indefinitely, until you delete them yourself or delete the account |
| Chat messages and photos | Until you delete the message; after account deletion they remain in anonymised form |
| Push notification token | Until notifications are disabled or the account is deleted |
| Technical logs with IP addresses | No more than 12 months |
| Crash reports | 90 days on the Firebase Crashlytics side |
| Anonymised usage information | Per the Firebase Analytics retention setting: 2 to 14 months. Aggregate reports are kept longer |
| Data in the device's memory | Until the App is removed or you delete the record |
For users in the European Union: your data is transferred to and stored in the Russian Federation, for which the European Commission has not issued an adequacy decision. The transfer is carried out on the basis of your explicit consent under Art. 49(1)(a) GDPR, which you give by creating an account and synchronising your workouts. Data is transmitted over a secure HTTPS connection.
The push notification token, crash reports and anonymised usage information are additionally processed by Google's infrastructure, whose servers are located in the United States among other places.
If you do not agree to such a transfer, you can use the App without registration (section 5) or stop using it.
We apply the following protective measures:
No system can guarantee absolute data protection.
You have the right to:
Some of these rights are exercised directly in the App: an individual workout together with its route and heart rate can be deleted in the workout journal or on the workout screen itself, your personal details are changed in the profile, saving to Health, voice prompts and notifications are turned off in the App and device settings, and your own chat messages can be edited or deleted.
Send any other requests to support@sit30.net from the email address you used to register. We reply within 30 days. To protect your data we may ask for additional proof of identity.
To delete your account and the data associated with it, send a request to support@sit30.net from the address used at registration. The account, profile, workouts, routes and heart rate data will be deleted within 30 days of the request being confirmed.
Please note the following:
Removing the App from your device does not by itself delete your server account.
The App is not intended for children under 14, and for users in the European Union under 16 without the consent of a parent or legal guardian. We do not knowingly collect data from such users. If you become aware that a child has provided us with data without proper consent, write to support@sit30.net and we will delete it.
We may update this Policy. The current version is always available at the permanent address given on the App's page in the App Store. We recommend opening it from time to time to stay aware of the current terms of data processing. By continuing to use the App you accept the version of the Policy then in force.
For any questions about the processing of personal data, to exercise your rights and to withdraw consent: support@sit30.net.