Privacy Policy
Effective Date: August 26, 2026
RunBeat is operated by Mushin Labs, LLC ("we," "us," or "our"). We are committed to protecting your privacy. This Privacy Policy explains what information RunBeat collects, how it is used, and how it is protected. By using RunBeat, you agree to the terms of this Privacy Policy. These terms should be read alongside our Terms of Use.
1. Information We Collect
RunBeat is designed to operate locally on your device. We do not require account creation, and we do not collect your name, email address, or phone number.
a. Heart Rate Data
RunBeat connects to Bluetooth Low Energy (BLE) heart rate monitors and Apple Watch via HealthKit to provide real-time heart rate zone training. Continuous heart rate readings are processed on your device; the samples recorded during a training session are stored in your training session history (see Section 1h) and never reach us.
b. User-Provided Settings
Information you configure in the app, such as your resting heart rate, maximum heart rate, and zone calculation preferences, is stored locally on your device. We do not store it on our own servers.
c. Apple Music
RunBeat uses Apple's MusicKit framework to access your Apple Music library for playlist selection and playback during training. Your playlist names and selections are stored locally on your device for convenience. We do not transmit your Apple Music data to our servers or any third party. All music playback is handled directly by Apple's systems on your device. Apple's Privacy Policy governs your use of Apple Music.
d. Bluetooth
RunBeat scans for and connects to Bluetooth heart rate monitors. Information about nearby Bluetooth devices and connection status is temporarily accessed to provide real-time heart rate monitoring. Your selected device name is stored locally on your device for automatic reconnection and may be included in usage analytics events (see Section 1g).
e. HealthKit
RunBeat may access heart rate data from Apple Watch via Apple's HealthKit framework. This data is used for real-time training feedback and is recorded as part of your training session history (see Section 1h). Heart rate readings from HealthKit are never transmitted to us or any third party and are not used for advertising or other use-based data mining.
f. Purchase Information
If you purchase a subscription, payment is processed entirely through Apple's App Store. We do not have access to your payment information, credit card number, or billing details.
We use RevenueCat, a third-party service, to validate App Store receipts and manage subscription status. RevenueCat identifies your installation with a randomly generated App User ID rather than your name, email address, or phone number. We deliberately reuse that same identifier as your Amplitude user ID and your OneSignal external ID, so subscription, usage, and notification activity for one installation can be joined together. We describe that shared identifier as pseudonymous rather than anonymous: it does not tell us who you are, but it is stable, and activity carrying it can be linked. You can review RevenueCat's privacy policy at revenuecat.com/privacy.
We also collect anonymous ad attribution data from Apple's AdServices framework to measure the performance of our Apple Search Ads campaigns. This data includes campaign and keyword identifiers only, does not include any personally identifiable information, and is not used for cross-app tracking.
g. Analytics and Crash Reporting
RunBeat uses Firebase Crashlytics and Amplitude to collect usage data and crash reports. This helps us understand how the app is used and identify stability issues. These events describe how you use the app, including the settings you configure (such as your resting and maximum heart rate) and which permissions you have granted. They do not include your name, email address, phone number, or the heart rate readings recorded during a training session.
Amplitude generates and stores its own device identifier in your device's keychain, and we also set your Amplitude user ID to the shared identifier described in Section 1f. Neither identifier is linked to your Apple advertising identifier (IDFA), and neither contains information that identifies you personally. Both are pseudonymous: they let us group one installation's activity together over time without telling us who you are. Amplitude also receives user properties to help us understand usage patterns in aggregate.
We do not collect the information that would identify you personally: no name, no email address, no phone number. You can review Google's privacy policy at policies.google.com/privacy and Amplitude's privacy policy at amplitude.com/privacy.
h. Training Session Data
RunBeat stores your training session history, including workout duration, heart rate samples and zone breakdowns, session timestamps, and (when GPS is enabled) distance, pace, and route data, using Apple's CloudKit service. This data is stored in your private iCloud account and syncs across your devices. We do not have access to this data. It is fully controlled by your Apple ID and subject to Apple's iCloud terms and privacy policy.
i. Location
If you enable GPS tracking for a training session, RunBeat uses your device's precise location to calculate distance, pace, and your route. Location data is captured on your device and stored as part of your training session history in your private iCloud account (see Section 1h). We do not have access to this data, and it is never transmitted to us or used for advertising or cross-app tracking. The derived distance of a session may be included in usage analytics events (see Section 1g); your precise location itself is never sent to us or any third party. You can enable or disable GPS tracking per session (distance-based sessions require GPS).
j. Motion & Fitness
If you grant Motion & Fitness permission, RunBeat reads step counts and whether you're stationary to estimate distance when GPS signal drops during a distance-based session. This data is processed on your device and never leaves it. Distance estimated from steps counts toward the session total, which is stored and handled like any other session distance (Sections 1g, 1h, 1i).
k. Push Notifications
If you grant notification permission, RunBeat uses OneSignal, a third-party service, to deliver push notifications such as reminders to start your first training session. OneSignal receives a push token for your device, the shared identifier described in Section 1f as your external ID, and limited app activity flags used to time these notifications. This information does not include your name, email address, or phone number, and it is not used for advertising or cross-app tracking. You can review OneSignal's privacy policy at onesignal.com/privacy.
2. How We Use Your Information
Data processing happens on your device to support RunBeat's core features, except where this policy names a third-party service:
- Heart Rate Zone Training — Your heart rate data from Bluetooth monitors or Apple Watch (via HealthKit) and configured settings are used to provide real-time voice-coached zone training.
- Music Playback — Your Apple Music playlist selections are used to play music during training sessions and are persisted locally for convenience.
- Subscription Management — Purchase data, carrying the pseudonymous identifier described in Section 1f, is used to verify your subscription status.
- App Improvement — Crash reports from Firebase and analytics from Amplitude help us improve app stability and the user experience.
- Training History — Session data is stored in your private iCloud account to provide training history and sync across your devices.
- GPS Tracking — When enabled, your device's location is used to calculate distance, pace, and route for a training session.
- Motion & Fitness — When granted, step counts are used to keep your distance accurate when GPS signal drops.
- Push Notifications — If enabled, a push token and limited activity flags are used to send you reminders via OneSignal.
3. Data Storage and Security
Settings and preferences are stored locally on your device. Training session history is stored in your private iCloud account via Apple's CloudKit and syncs across your devices. We do not have access to your iCloud data.
We do not maintain any servers that store your personal data. The security of your data depends on your device security and your Apple ID account security.
4. Sharing and Disclosure
We do not sell, rent, or share your personal information with any third parties. The only third-party services that process data on our behalf are:
- RevenueCat — Subscription receipt validation
- Firebase — Analytics and crash reporting
- Amplitude — Product analytics
- OneSignal — Push notification delivery
None of these services receive your name, email address, or phone number. RevenueCat, Amplitude, and OneSignal do share the common pseudonymous identifier described in Section 1f.
5. Children's Privacy
RunBeat does not knowingly collect information from children under the age of 13. The app does not require account creation and does not collect a name, email address, or phone number. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
6. Your Rights
Settings and preferences are stored on your device and can be deleted by deleting the app. Training session history is stored in your private iCloud account. You can delete individual sessions within the app or manage your iCloud storage through Apple's settings. We do not have access to your iCloud data and cannot manage, modify, or delete it on your behalf. Location, Motion & Fitness, Bluetooth, and notification permissions can be reviewed and revoked at any time in your device's system settings.
Depending on where you live, you may have additional rights under applicable privacy laws:
- European Economic Area & United Kingdom (GDPR) — You have the right to access, correct, delete, or port your personal data, and to object to or restrict its processing. RunBeat does not collect your name, email address, or phone number, and we do not store your training history on any server of ours. The usage and crash data processed by Firebase, Amplitude, and OneSignal is tied to the pseudonymous identifier described in Section 1f rather than to you personally. Our lawful basis for processing usage analytics is legitimate interest in improving app stability and performance.
- California (CCPA/CPRA) — You have the right to know what personal information is collected, to request its deletion, and to opt out of its sale. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising.
- Other Jurisdictions — If your local laws grant you additional privacy rights, we respect those rights. Because RunBeat keeps your settings on your device and your training history in your own iCloud account, and because we do not collect information that identifies you personally, the app's architecture satisfies most of these rights on its own.
If you have questions about your rights, please contact us.
7. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated effective date. Your continued use of RunBeat after changes are posted constitutes acceptance of the revised Privacy Policy.
8. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at: