Privacy Policy

Effective Date: August 26, 2026

RunBeat is operated by Mushin Labs, LLC ("we," "us," or "our"). We are committed to protecting your privacy. This Privacy Policy explains what information RunBeat collects, how it is used, and how it is protected. By using RunBeat, you agree to the terms of this Privacy Policy. These terms should be read alongside our Terms of Use.

1. Information We Collect

RunBeat is designed to operate locally on your device. We do not require account creation, and we do not collect your name, email address, or phone number.

a. Heart Rate Data

RunBeat connects to Bluetooth Low Energy (BLE) heart rate monitors and Apple Watch via HealthKit to provide real-time heart rate zone training. Continuous heart rate readings are processed on your device; the samples recorded during a training session are stored in your training session history (see Section 1h) and never reach us.

b. User-Provided Settings

Information you configure in the app, such as your resting heart rate, maximum heart rate, and zone calculation preferences, is stored locally on your device. We do not store it on our own servers.

c. Apple Music

RunBeat uses Apple's MusicKit framework to access your Apple Music library for playlist selection and playback during training. Your playlist names and selections are stored locally on your device for convenience. We do not transmit your Apple Music data to our servers or any third party. All music playback is handled directly by Apple's systems on your device. Apple's Privacy Policy governs your use of Apple Music.

d. Bluetooth

RunBeat scans for and connects to Bluetooth heart rate monitors. Information about nearby Bluetooth devices and connection status is temporarily accessed to provide real-time heart rate monitoring. Your selected device name is stored locally on your device for automatic reconnection and may be included in usage analytics events (see Section 1g).

e. HealthKit

RunBeat may access heart rate data from Apple Watch via Apple's HealthKit framework. This data is used for real-time training feedback and is recorded as part of your training session history (see Section 1h). Heart rate readings from HealthKit are never transmitted to us or any third party and are not used for advertising or other use-based data mining.

f. Purchase Information

If you purchase a subscription, payment is processed entirely through Apple's App Store. We do not have access to your payment information, credit card number, or billing details.

We use RevenueCat, a third-party service, to validate App Store receipts and manage subscription status. RevenueCat identifies your installation with a randomly generated App User ID rather than your name, email address, or phone number. We deliberately reuse that same identifier as your Amplitude user ID and your OneSignal external ID, so subscription, usage, and notification activity for one installation can be joined together. We describe that shared identifier as pseudonymous rather than anonymous: it does not tell us who you are, but it is stable, and activity carrying it can be linked. You can review RevenueCat's privacy policy at revenuecat.com/privacy.

We also collect anonymous ad attribution data from Apple's AdServices framework to measure the performance of our Apple Search Ads campaigns. This data includes campaign and keyword identifiers only, does not include any personally identifiable information, and is not used for cross-app tracking.

g. Analytics and Crash Reporting

RunBeat uses Firebase Crashlytics and Amplitude to collect usage data and crash reports. This helps us understand how the app is used and identify stability issues. These events describe how you use the app, including the settings you configure (such as your resting and maximum heart rate) and which permissions you have granted. They do not include your name, email address, phone number, or the heart rate readings recorded during a training session.

Amplitude generates and stores its own device identifier in your device's keychain, and we also set your Amplitude user ID to the shared identifier described in Section 1f. Neither identifier is linked to your Apple advertising identifier (IDFA), and neither contains information that identifies you personally. Both are pseudonymous: they let us group one installation's activity together over time without telling us who you are. Amplitude also receives user properties to help us understand usage patterns in aggregate.

We do not collect the information that would identify you personally: no name, no email address, no phone number. You can review Google's privacy policy at policies.google.com/privacy and Amplitude's privacy policy at amplitude.com/privacy.

h. Training Session Data

RunBeat stores your training session history, including workout duration, heart rate samples and zone breakdowns, session timestamps, and (when GPS is enabled) distance, pace, and route data, using Apple's CloudKit service. This data is stored in your private iCloud account and syncs across your devices. We do not have access to this data. It is fully controlled by your Apple ID and subject to Apple's iCloud terms and privacy policy.

i. Location

If you enable GPS tracking for a training session, RunBeat uses your device's precise location to calculate distance, pace, and your route. Location data is captured on your device and stored as part of your training session history in your private iCloud account (see Section 1h). We do not have access to this data, and it is never transmitted to us or used for advertising or cross-app tracking. The derived distance of a session may be included in usage analytics events (see Section 1g); your precise location itself is never sent to us or any third party. You can enable or disable GPS tracking per session (distance-based sessions require GPS).

j. Motion & Fitness

If you grant Motion & Fitness permission, RunBeat reads step counts and whether you're stationary to estimate distance when GPS signal drops during a distance-based session. This data is processed on your device and never leaves it. Distance estimated from steps counts toward the session total, which is stored and handled like any other session distance (Sections 1g, 1h, 1i).

k. Push Notifications

If you grant notification permission, RunBeat uses OneSignal, a third-party service, to deliver push notifications such as reminders to start your first training session. OneSignal receives a push token for your device, the shared identifier described in Section 1f as your external ID, and limited app activity flags used to time these notifications. This information does not include your name, email address, or phone number, and it is not used for advertising or cross-app tracking. You can review OneSignal's privacy policy at onesignal.com/privacy.

2. How We Use Your Information

Data processing happens on your device to support RunBeat's core features, except where this policy names a third-party service:

3. Data Storage and Security

Settings and preferences are stored locally on your device. Training session history is stored in your private iCloud account via Apple's CloudKit and syncs across your devices. We do not have access to your iCloud data.

We do not maintain any servers that store your personal data. The security of your data depends on your device security and your Apple ID account security.

4. Sharing and Disclosure

We do not sell, rent, or share your personal information with any third parties. The only third-party services that process data on our behalf are:

None of these services receive your name, email address, or phone number. RevenueCat, Amplitude, and OneSignal do share the common pseudonymous identifier described in Section 1f.

5. Children's Privacy

RunBeat does not knowingly collect information from children under the age of 13. The app does not require account creation and does not collect a name, email address, or phone number. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

6. Your Rights

Settings and preferences are stored on your device and can be deleted by deleting the app. Training session history is stored in your private iCloud account. You can delete individual sessions within the app or manage your iCloud storage through Apple's settings. We do not have access to your iCloud data and cannot manage, modify, or delete it on your behalf. Location, Motion & Fitness, Bluetooth, and notification permissions can be reviewed and revoked at any time in your device's system settings.

Depending on where you live, you may have additional rights under applicable privacy laws:

If you have questions about your rights, please contact us.

7. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated effective date. Your continued use of RunBeat after changes are posted constitutes acceptance of the revised Privacy Policy.

8. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at:

support@runbeat.app