Privacy Policy
This Privacy Policy applies to the RITMIK.RUN apps (iOS and Android) and to our website at ritmik.run. In short: we run no accounts and collect no personal data that identifies you, and we never track you across other companies' apps or websites. To advertise our apps responsibly, we measure ad conversions in a privacy-preserving way — see 'Advertising measurement' below.
1. Controller
The controller responsible for data processing is:
Friedrich GroßKöhmesweg 8
27283 Verden
Germany
Email: info@ritmik.run
2. Our website
Our website uses privacy-friendly, cookieless analytics that we run entirely ourselves: no third parties, no advertising and no cross-site tracking. We store only anonymous, aggregated counts, such as page views per day, the approximate country a visit comes from, and the referring site. Your IP address is used only for a moment to determine that approximate country and is then immediately discarded; it is never stored, and nothing we keep can identify you. When you tap a link to the App Store or Google Play, you are taken to Apple's or Google's platform, where their respective privacy policies apply; we do not transfer personal data to them.
3. The RITMIK.RUN app
The RITMIK.RUN app works without any account, login, or registration, and does not collect personal data that identifies you.
Health and fitness data (smartwatch)
On your smartwatch, the app reads your heart rate to display it live during a walk or run. On Apple Watch this uses Apple Health (HealthKit), and your completed workouts are also saved back to Apple Health so they count toward your activity rings; on Wear OS (Android) the app reads your watch's heart-rate sensor directly. Your live heart rate and workouts are processed on your device for pace-matching and are not sent to our servers for that. If you turn on the optional AI features, limited derived summaries are sent to power them — see below. You can also use a standard Bluetooth heart-rate strap or a sports watch that broadcasts its pulse (for example Garmin, Polar, Coros or Wahoo) instead of a watch app. In that case the app reads only the current pulse value from the sensor; the RR intervals that such sensors also transmit are deliberately never evaluated or stored.
Camera and photos
If you add a photo to a run's share card, the app opens your camera or your photo library — only after you tap it, and only for the picture you choose. The photo stays on your device: it is placed onto the card locally and is not sent to us. On iOS the app asks for camera access the first time; on Android the system photo picker hands over only the single picture you selected, so the app needs no access to your gallery.
AI features (optional)
RITMIK.RUN offers optional AI features (a post-run coach note, trends and race estimates, an AI workout builder, and AI-optimized program tuning). When you use them, the app sends only derived, aggregated numbers — such as average and maximum heart rate, time-in-zone percentages, durations, pace and counts. It never sends your raw heart-rate series, your GPS or route, your location, or any identifier. These aggregates are processed on our own servers — no external AI provider is involved, and your data never leaves our infrastructure. They are used only transiently to generate your insight and are not stored. Your data is not used for advertising or to train AI models. On devices with the AI features turned off, nothing is sent.
Downloads, likes and dislikes
When you download a music package or like or dislike a track, the app contacts our music server. We store only anonymous, aggregated counts (for example, how often a track is liked or a package is downloaded) together with basic technical request data (app and operating-system version and the time of the request). This data is not linked to your identity, contains no personal identifiers, and we do not store IP addresses. You can turn off sending likes and dislikes at any time in the app's settings. To understand which countries our music reaches, we also derive an approximate country from your connection at the time of the request, again without ever storing your IP address.
Crash reports
If the app unexpectedly crashes, it sends us a technical report the next time it starts, so we can find and fix the error. The report contains only technical information: where in the code the app was when it crashed (a so-called stack trace), the app version, the operating-system version, the device model, and the time of the crash. It contains no name, no account, no identifier of your device or installation, no location, and no health data such as your heart rate — a report cannot be linked to you. Reports go only to our own server; no third parties are involved. Your IP address is used only to deliver the report and is not stored. We delete reports after 90 days at the latest. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in the stability of the app. You can turn off sending crash reports at any time in the app's settings.
Backup and restore
So you can restore your library when you set up a new device, the app can back up a small list of identifiers — the IDs of the music tracks in your library, which of them you liked, and your in-app settings — to your personal iCloud (iOS) or Google account (Android). No music files and no personal data are stored, only these identifiers, and we have no access to this data. You can disable this backup or delete the stored data at any time in the app under Settings → Backup & Restore.
You can also export all your app data — your runs including their routes, your settings, shoes, and the list of tracks in your library — into a single file via Settings → Export data, for example to move to a new phone. This file is created entirely on your device and is only stored or shared where you choose; it is never transmitted to us, and we have no access to it.
Route suggestions (map)
This applies only when you use the map feature to have a running route suggested — without that, no location data leaves your device for this purpose. To work out a round trip that starts and ends at your door, your device sends your current position to our server. We calculate the route on our own servers; no external routing provider receives your position. We do not store it: it is held only briefly in the server’s working memory so that identical requests can be answered faster, without any reference to you or your device, and it is discarded after 24 hours at the latest. Our access log records only the address of the request, never your position. Routes you save stay on your device and are not transmitted to us. The map itself is supplied by Google Maps (Android) or Apple Maps (iOS): to display it, the section of the map you are looking at is requested from them, and their respective privacy policies apply (policies.google.com/privacy, apple.com/legal/privacy).
Calendar (training plans)
This applies only if you switch on the calendar feature inside a training plan — without that, nothing described here happens. On iOS, your device sends that plan's session dates to our server, which offers them as a calendar feed your phone subscribes to. The feed contains only the plan name and the dates with generic entries such as “Training” — no name and no personal details — and it can only be reached through a random, unguessable address. You can remove it at any time in the app, which deletes the stored data. On Android, no calendar data reaches our servers at all: the app creates its own “Ritmik.Run” calendar in your Google account and writes the entries directly there, so they stay between your device and your Google account. On both platforms the app can only see the entries it created itself — never your other calendars or appointments.
Purchases
Subscriptions are processed by Apple (App Store) or Google (Google Play). We do not receive your payment details.
Advertising measurement
We advertise the RITMIK.RUN apps on Apple Search Ads and Google Ads, and we measure only whether an ad led to an app install or a subscription — never to build a profile of you or to track you across other companies' apps or websites. How this is measured differs by platform. On iOS, the app uses privacy-preserving conversion measurement: it includes Google's analytics tool (Google Analytics for Firebase) and Apple's AdServices attribution, and for this we transmit a randomly generated install identifier, a Firebase app-instance identifier, and the event that a free trial or a paid subscription started — to Google, plus an attribution token to Apple. On Android, the app contains no such measurement code and sends no advertising data to us or to Google; instead we rely on Google Play's own built-in conversion measurement, where Google measures installs from the Play Store and subscription purchases through Google Play on its own platform. On neither platform do we use your device's advertising identifier (no IDFA on iOS and no Advertising ID on Android), so no App Tracking Transparency prompt appears. This data is pseudonymous and cannot on its own identify you. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in measuring the effectiveness of our advertising. Google is a recipient of this data; see Google's Privacy Policy at policies.google.com/privacy and Apple's at apple.com/legal/privacy.
4. Your rights
Under the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17) and to object (Art. 21) regarding your personal data. To exercise these rights, please contact the controller listed above.