RACERZ

Privacy Policy

Version 2.2 — Effective 2 September 2026

1. Who We Are

The data controller is Bred Applications, CVR 45915905, Denmark. Contact: contact@bredapplications.com.

We are not required to appoint a Data Protection Officer and have not appointed one. Privacy requests go to the address above.

You can lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or the supervisory authority in your own country.

2. Data We Collect

Account: email address, username, display name, avatar — via Apple Sign-In, Google Sign-In, or email magic link. We never collect or store passwords.

Physiological data (health data — explicit consent, see section 4): weight, height, gender.

Fitness and performance: distance, duration, pace, estimated calories, step count, cadence, per-kilometre splits, elevation, VDOT fitness score, fatigue profile, personal records, training zones.

Route shape: for each run we store a normalized outline of its shape — the route reduced to a simplified line, scaled into a unit square so that absolute position is removed before it leaves your device, plus a coarse area type (urban, park, or mixed). It is what lets a run card draw a map without us holding a map. It contains no coordinates and no absolute position, and cannot be turned back into either.

Competitive: ELO ratings, match history, XP, coins, rank, season progression, penalties.

Social: posts, comments, likes, friendships, club membership, club chat messages, notifications.

Device and technical: a mock-location flag (anti-cheat), a push notification token, and — for each ranked submission — your platform and app version together with a device-integrity check from Apple or Google. Our authentication provider records the IP address and browser/app identifier of each sign-in session for security. We do not collect advertising identifiers or contacts.

Product analytics: we use TelemetryDeck (TelemetryDeck GmbH, Augsburg, Germany; hosted in the EU) to learn which screens are used and in what order — for example whether the placement race was started from onboarding or booked for later. The identifier is hashed on your device with a salt before it is sent and hashed again on arrival; it cannot be linked back to you, your account or your IP address, which TelemetryDeck does not store. Analytics never contains your location, your runs, your pace, your body data, your health consent or your user ID. Because it cannot be tied to an account, it is not part of your data export and is not affected by account deletion.

Payment: subscription status via RevenueCat, keyed to your user ID. Payment card details never reach us — Apple and Google process all payments.

Feedback: if you rate the app or send us written feedback, we store your star rating, your message, and your app version and platform, keyed to your user ID. If you tell us why you left when removing the app, we store that reason and anything you write with it in the same way.

3. GPS and Location

GPS coordinates are processed in real time during your runs for distance calculation and validation, and are never stored on our servers — no coordinates, no route polylines.

Your route maps live only on your own phone. They are held in a folder belonging to your account, so a different account signing in on the same handset cannot see them. We hold no copy, so no server-side retention period applies to them: they stay until you delete the run, delete your account, or remove the app, and they are included in whatever device backup you have switched on with Apple or Google. If a race result cannot be sent for validation straight away, that run's coordinates are also held on your phone until it can be — in temporary storage excluded from device backups, cleared once the result goes through and whenever you log out.

What we do store for every run is the normalized route shape described in section 2 — the outline with absolute position mathematically stripped out. It is what draws the map on a run card. If you share a run, that shape and your run statistics are what other users see — never where you ran. During races, opponents see your relative progress, never your location.

4. Health Data and Your Explicit Consent

Your weight, height, gender, and derived fitness metrics (VDOT score, fatigue profile) are treated as health data under GDPR Article 9. We process them only with your explicit consent, which the app requests as a separate step — not bundled into acceptance of the Terms.

That consent covers these purposes: simulating your performance as an opponent, fair matchmaking, anti-cheat validation, and displaying the resulting race simulations to other users.

You can withdraw consent at any time in Settings. Withdrawing deletes your body data and derived metrics. Because ranked races are simulated from your fitness profile, ranked play stops working until you complete a new placement race. Everything else in RACERZ — free runs, the feed, clubs, your history — keeps working.

5. How We Use Data

Product analytics rests on legitimate interest (Article 6(1)(f)): the interest is to see which screens are used so the app can be improved, and it works on data that cannot identify you.

Providing an email address and username is necessary to create an account — without them there is no account to attach your runs and results to. Health data is optional: declining only disables the features that need it.

Where we rely on legitimate interests, we have weighed them against your interests and rights. The processing is limited to what keeps a competitive service honest and available — spotting impossible results, throttling abuse, product analytics, and acting on feedback you chose to send — it never profiles you for advertising, is never sold or shared with brokers, and health signals are excluded from it. We consider that balance to fall in our favour, but it is yours to challenge: you may object at any time to any processing based on legitimate interests by writing to contact@bredapplications.com, and we will stop unless we can show compelling grounds that override your objection. You can turn product analytics off at any time under Settings → Privacy; that stops it on that device.

6. Opponent Simulation — What Your Rivals' Devices Receive

When another runner races you in ranked mode, their device receives your VDOT score, fatigue profile, and recent maximum run distance so it can compute your simulated performance locally. It never receives your GPS data, your health inputs (weight, height, gender), or your identity beyond username and rank.

7. Automated Decisions

Runs and race results are validated by automated, rule-based server-side plausibility checks (speed, GPS accuracy, physiological consistency). What such a check can do is invalidate a single result: the race does not count, and no rating changes for either side. Nothing else follows from it automatically — no account is suspended or terminated by an automated process. A suspension is always a decision taken by a person.

Every such decision includes a statement of reasons. Under GDPR Article 22 you have the right to human review, to express your point of view, and to contest the decision: write to contact@bredapplications.com — a person with authority to overturn the decision will answer within one month.

8. Sharing and Processors

ServicePurposeTransfer basis
SupabaseDatabase, authentication, storageEU Standard Contractual Clauses
Google / FirebasePush notifications, remote configurationEU-US Data Privacy Framework
Apple & GoogleSign-in and payments (independent controllers)Their own terms
RevenueCatSubscription managementEU Standard Contractual Clauses
TelemetryDeckAnonymised product analyticsEU-hosted; anonymised usage events, no account id
GitHubStatic content delivery (voice model, these documents)EU-US Data Privacy Framework

If you share a run to Instagram, the image is handed to Instagram by your device; what happens to it is governed by Meta's terms, not ours.

We never sell personal data, run ads, or share data with brokers or advertising networks.

9. International Transfers

Your account data, your runs, and your health data are stored in the European Union (Ireland). That is where our database, authentication, and storage live, and none of it is moved out of the EU to run the service.

Some supporting processors are US-based. Transfers to Google and GitHub rest on the EU-US Data Privacy Framework adequacy decision; all other US transfers rest on EU Standard Contractual Clauses (Decision (EU) 2021/914) with supplementary measures. A copy of the safeguards is available on request.

10. Features Not Currently Active

Strava integration, live friend challenges, and an AI running coach exist in the app's code but are currently disabled. If we enable one of them, we will disclose it first — and where the feature would send your data to a processor not listed in section 8, we will ask for your consent before any data flows.

Named for completeness: the AI coach would send run data to OpenAI (US, EU Standard Contractual Clauses). It is switched off in the app and its server routes are not running, so no data reaches OpenAI today. That is why OpenAI is not listed in section 8 — it is not a processor we currently use. We will add it there, and ask for your consent, before the feature is ever turned on.

11. Retention

Account deletion is immediate and permanent.

12. Your Rights

Access, rectification, erasure, portability, restriction, objection, withdrawal of consent, and human review of automated decisions. We grant these rights to all users worldwide, not only where the law requires it.

In the app: full JSON data export (Settings, once per 24 hours) and immediate account deletion. Outside the app: contact@bredapplications.com or the account deletion page.

13. US State Privacy Rights

The rights above apply to you. We do not sell personal information and do not share it for cross-context behavioral advertising. Residents of Washington, Nevada, Connecticut, and other states with consumer-health-data laws: see our separate Consumer Health Data Privacy Policy.

14. Children

RACERZ is not directed at children. You must be at least 16 years old to use it; you confirm this when you accept the Terms. We do not collect a date of birth and do not otherwise verify age. If we learn that a user is under 16, we delete the account and its data.

15. Security

Row-Level Security on every database table, TLS on every connection, passwordless authentication, encrypted token storage, rate limiting, GPS-spoof detection, and server-side validation before any result counts.

16. Data Breaches

We notify the supervisory authority within 72 hours of becoming aware of a reportable breach, and affected users without undue delay where the risk to them is high.

17. Changes

We give 30 days notice of material changes via in-app notification.

18. Contact

contact@bredapplications.com