1. Information we process
| Category | Information | Purpose |
|---|---|---|
| Account | User identifier, email, name or nickname, sign-in provider | Sign-in, account management, responding to inquiries |
| Location | Current location, selected starting location, recorded running route | Nearby route recommendations, run recording, safety features |
| Running and health | Distance, duration, pace, calories, exercise route, and heart rate if permitted by the user | Run recording, results analysis, Health Connect and HealthKit synchronization |
| Settings and content | Distance, difficulty and safety preferences, reviews, safety feedback | Personalized recommendations, quality and safety improvements |
| Device and notifications | FCM push token, app version, operating system | Sending notifications permitted by the user, checking compatibility |
During Google or Kakao sign-in, we receive only information permitted by the respective provider. NearbRun does not store passwords directly.
2. Processing methods and service providers
- OCI route engine: Routes are calculated using the starting location and distance, difficulty, and safety preferences. By default, raw requested locations are not stored in separate analytics logs after route generation.
- Weather information: This release does not use an external weather provider in its default production configuration. If a properly licensed weather feature is enabled in the future, starting locations will be reduced to a grid at two decimal places; precise original coordinates will not be sent.
- Google Firebase: Authentication, Cloud Firestore, and Cloud Messaging process sign-in, profiles, running preferences, and notification tokens. Firebase Storage and Cloud Functions are not currently used. FCM automatic initialization is disabled by default; tokens are created and synchronized only after the user enables push notifications and grants operating-system permission.
- Optional usage analytics: Disabled by default in production. Even if separate consent is obtained in the app in the future, only aggregates such as distance, duration, and quality will be processed, excluding user, run, and route identifiers and original coordinates. Error reporting is also disabled by default in production.
- Google·Kakao: Information is processed under each service's policies when providing social sign-in and map features.
- Health Connect·Apple HealthKit: Only exercise information explicitly authorized by the user is read or written. Health information is not used for advertising.
- Advertising services: In versions with advertising enabled, Google Mobile Ads may process device advertising information within the scope of consent and operating-system settings.
3. Retention periods
- Account, profile, and synchronized running information: until account closure or the user's deletion request
- FCM tokens: until token replacement, notifications are disabled, sign-out, or account deletion
- Run records and settings stored only on the device: until app data is cleared or the app is uninstalled
- Consented anonymous aggregate usage analytics: up to 14 days. Not currently collected in production
- Account deletion inquiries: retained for the minimum period needed for confirmation after processing, then deleted
Where retention is required by law, information is stored separately for the required period and then deleted.
4. Your choices and rights
- You can change location, notification, health, and advertising-tracking permissions at any time in operating-system settings.
- You can view or edit your running preferences and profile in the app.
- You can start account deletion in app settings. If you cannot access the app, you can request deletion using the website instructions.
- When an account is deleted, associated data not subject to legal retention requirements is also deleted.
5. Security measures
We apply encryption in transit, Firebase Security Rules, least privilege, and access restrictions. Features accessing precise location and health information are designed to operate only after user consent.
6. Children's personal information
NearbRun is not intended for children under 14. If we learn that information about a user under 14 has been processed without consent from their legal representative, we will verify and delete it.
7. Changes and inquiries
Important changes will be announced in the app or on this page. You can contact us below with privacy inquiries or to exercise your rights.