Privacy Policy
1. Controller
Ngbesso Simon Emmanuel Aboua
Anton-Sattler-Gasse 115/2, 1220 Wien, Österreich
Privacy and support contact: team.reuso@gmail.com
Phone: +43 660 3650905
No data protection officer has been appointed because no statutory appointment requirement is currently considered to apply.
2. Scope and minimum age
This Policy applies to the Runlocked iOS app and the public Runlocked legal website. The MVP is intended only for people aged 16 or older. People under 16 must not create an account or use the app.
If there is reason to believe that data relating to a person under 16 is being processed, this may be reported to team.reuso@gmail.com. After appropriate verification, the data will be erased unless a legal duty requires further processing.
3. Sign in with Apple and account
Runlocked uses Sign in with Apple exclusively. It processes the developer-specific Apple user identifier, an internal Supabase user ID, sign-in and account status, session and security tokens, account timestamps and—only where Apple supplies them on first sign-in—a name and direct or Apple relay email address. Runlocked receives no Apple password and creates no separate password.
The session is transmitted using encryption and stored in protected device key storage. The email address is not public. The purposes and legal bases are account creation, sign-in, synchronisation, and abuse prevention under Article 6(1)(b) GDPR and, for security measures, Article 6(1)(f) GDPR.
4. Profile and settings data
Profile data includes the unique username, display name, language, unit setting, chosen home district, notification setting, account status, and the version and time of confirming the minimum age, Terms, and Privacy notice.
Username and display name are public within the intended Runlocked views or visible to other signed-in users. Email address, home district, and settings are not provided as public profile data.
This data is needed to provide the account and selected app functions under Article 6(1)(b) GDPR.
5. Location, route, and run data
Runlocked does not access location merely because the app or progress map is opened. Only when you expressly start a run and grant the required device permission does the app record precise or—depending on device settings—approximate coordinates. If background permission is granted, recording continues while the screen is locked or the app is in the background until the run is finished or cancelled.
Data includes latitude and longitude, timestamps, accuracy, speed and—where supplied by the device—altitude, the resulting GPS route, start and end time, duration, distance, pace, cancellation and scoring status, and quality and plausibility values. The raw route is cached locally by user and sent to Supabase for synchronisation and evaluation.
Runlocked derives zone and district progress, mission results, weekly goals, valid distance and duration, and related progress and error reasons from run and route data. The legal basis is Article 6(1)(b) GDPR because this provides the tracking and game function expressly started by the user.
Location permission can be withdrawn in iOS settings. Run tracking cannot operate without the required access. Withdrawing permission does not erase existing runs; activity and account deletion are available for that purpose.
6. Local storage and voluntary sharing
App state, runs, progress, and pending uploads are also stored in local app storage separated by user ID. Authentication sessions are stored in protected device storage. On logout or account switch, user-related local caches and active location buffers are erased; before logout, the app attempts to synchronise pending runs or asks whether they should be discarded.
If you export a run graphic through the iOS share sheet, it is created locally and the beginning of the displayed route is shortened for privacy. Only your selection in the iOS share sheet sends the file to the recipient or third-party service you choose. This voluntary disclosure occurs outside Runlocked under the selected service's terms.
7. Technical, security, and support data
Technical event data may be processed to provide the service, secure transmission, troubleshoot faults, and protect against unauthorised or manipulated use. This may include time, requested function, internal user or run ID, processing status, limited error codes, app and operating-system version, and network and server information. The legal basis is Article 6(1)(f) GDPR and the legitimate interest in secure, stable, and accountable operation.
When team.reuso@gmail.com is contacted, the message, email address, timestamps, and voluntarily supplied content are processed to handle the request. Depending on the matter, this relies on Article 6(1)(b), (c), or (f) GDPR. Because the support address is hosted by Gmail, Google also processes the correspondence under the privacy terms applicable to Gmail.
Runlocked currently uses no advertising network or tracking, product analytics, attribution, or crash-reporting SDK and creates no marketing or behavioural profile. An operating-system notification may indicate active background location recording; promotional push notifications and a push-token service are not implemented.
8. Recipients and service providers
Supabase, Inc. provides authentication, PostgreSQL database, Storage, and Edge Functions. The active project is located in eu-west-1 (Ireland). Supabase therefore processes account, profile, route, run, progress, and technical operations data as required. The project currently uses the Free plan.
Apple is used for Sign in with Apple, app distribution, device permissions, and map display through react-native-maps with the iOS default map service, MapKit/Apple Maps. Apple processes device, sign-in, map-interaction and, where applicable, location information required for those services under its own responsibility. Runlocked does not separately send the complete run history stored in Supabase to Apple.
Expo or EAS is used to develop and create app builds. The production app uses no Expo analytics, push, or update service and does not send ordinary account, route, or progress data to Expo.
Netlify, Inc. hosts the static public legal website. When a page is requested, Netlify processes technically necessary web and CDN data such as IP address, time, requested page, browser and device information and, where applicable, referrer and security data. The legal website has no sign-in, forms, advertising, or proprietary analytics and Runlocked sets no cookie or local-storage entry there.
Data is not sold. Other recipients receive data only where necessary to provide the service, required by law, or necessary to establish, exercise, or defend legal claims.
9. Transfers outside the EEA
Depending on group structures, support, security operations, and subprocessors, Supabase, Apple, Netlify, and Google may process data outside the European Economic Area. Where no adequacy decision applies, the appropriate safeguards made available by the provider are used, particularly EU Standard Contractual Clauses and data-processing agreements. Information or copies concerning relevant safeguards may be requested through the privacy contact where they may lawfully be provided.
10. Retention, activity deletion, and account deletion
Account, profile, and settings data is generally retained until account deletion. Individual GPS routes, run summaries, and run-related evaluations remain until that activity or the account is deleted. Progress remains while needed for game functions and is rebuilt from the remaining runs after activity deletion.
When “Delete activity” is used, Runlocked removes the relevant route and run from the server and local state after server confirmation. Derived zone, mission, and weekly values are recalculated from the remaining runs. If deletion or recalculation fails, the app displays an error and does not confirm successful deletion.
“Delete account” requires recent Sign in with Apple and express confirmation. The account is immediately blocked from further access. Runlocked then attempts to revoke Apple authorisation, remove all route objects, permanently delete the Supabase Auth user, and remove dependent profile, run, and progress data through referential deletion. If a temporary error occurs, a technically necessary deletion job is retained and retried.
Technical security, server, and error data is kept only while needed for operation, troubleshooting, abuse prevention, or legal duties. No specific user-accessible backup rotation is promised for the current Supabase Free plan; Supabase documentation states that Storage routes are not included in database backups. Where providers temporarily keep backup or operational copies, they are no longer available in the live product and are removed under the provider's actual deletion and overwrite cycles. No fixed period is asserted until contractually verified.
Support correspondence is kept until the request is resolved and afterwards only while needed for follow-up, legal claims, or statutory duties. Mandatory legal retention requirements remain unaffected. Runlocked currently processes no purchase, payment, or invoice data.
11. Required data and automated evaluation
Sign in with Apple, internal user ID, username, age confirmation, and legal-document confirmation are required for a Runlocked account. Location and run data are required only for run tracking and dependent game functions.
Runs, zones, and missions are evaluated automatically under technical quality and game rules. These decisions produce no legal or similarly significant effect within Article 22 GDPR. Incorrect run results may be reported to support.
12. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Consent can be withdrawn for the future; the core functions described here rely mainly on contract performance rather than blanket privacy consent.
Requests may be sent to team.reuso@gmail.com. Appropriate identity verification may be required to protect the account.
You may complain to a data protection authority, particularly the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, email: dsb@dsb.gv.at.
13. Security and changes
Runlocked uses encrypted transmission, protected session storage, user-scoped Row Level Security, server-side ownership checks, separated local caches, and restricted service permissions. No technical system can guarantee absolute security.
This Policy will be updated when functions, providers, or legal requirements change. The version and update date are displayed in the app and on the public HTTPS page. Material changes will be communicated appropriately and confirmed again where legally required.