Legal
Privacy
Last updated 26 September 2026
ALLUNGO is a running-training app for iPhone and Apple Watch. This page explains what it does with your information. It is written to be read, not to be survived.
No account
ALLUNGO has no sign-up, no login and no password. You do not give us an email address to use the app, and we do not create one for you. The beta list on this website is the one place an email address is asked for, it is entirely optional, and it has nothing to do with the app — joining it does not make an account, and the app never sees it.
The optional coach described below does use a server, but that server never learns who you are. It knows each installation of the app only by a random identifier.
Where your training data lives
Your plan, your sessions, your paces, your completed runs and your settings are stored on your iPhone and Apple Watch.
They also sync through your own iCloud account, so the same training appears on your other devices. That is Apple’s storage, under your Apple Account and subject to Apple’s terms — not ours, and we cannot see it. Sync is on by default and needs you to be signed in to iCloud. You can turn it off in Settings, and your training then stays on the device.
Your data is also included in your device backup if you back your device up, under whatever protection you have set for that backup.
Apple Health
With your permission, ALLUNGO reads workouts and recovery data — such as heart rate variability, resting heart rate and sleep — from Apple Health, and writes the runs you record with ALLUNGO back to it.
- Health access is requested when you first use a feature that needs it, and you can decline.
- You can change or withdraw that access at any time in the Health app, under Sources.
- Health data read by ALLUNGO is used to show you your own training and recovery. It is not sold, and it is not shared for advertising.
The optional coach
ALLUNGO includes an optional coach that reads your recent training and explains it in plain language. It is off unless you turn it on, and the rest of the app works fully without it.
Turning it on takes an explicit consent step that tells you what would be sent before anything is. You are asked in More → AI Coach, and once at the end of first setup, where “Not now” is always available. Turning it off stops anything being sent, straight away.
When the coach writes a read, what goes with it is:
- Your first name — the first word of the name you entered, if you entered one. The field is optional, and leaving it blank sends no name at all.
- Your recovery markers for the last 14 days: heart rate variability, resting heart rate and sleep.
- Your runs from the last two weeks: date, distance, duration, pace and average heart rate.
- Your training plan and its target paces, your race goal and your race date.
- Anything you type to the coach.
- After a run, the app's own summary of how that run went.
What does not go with it:
- Your surname. Only the first word of the name is sent, whatever you typed.
- An email address. The app never asks for one.
- Your location, or the GPS route of any run.
- Your Apple Account, or any Apple Health data beyond the recovery markers and run figures listed above.
Where the coach sends it
The app sends that information to the ALLUNGO coach server, which runs on Vercel in the United States. The server passes it to Anthropic’s Claude API, which writes the read, and returns the reply to your phone. There is a limit on how many reads each installation can ask for in a day and in a month.
Before it answers, the server checks that the request came from a genuine copy of ALLUNGO on a real iPhone, using Apple’s App Attest. That is what lets the coach work without accounts: it proves the app is real without proving who you are. The server knows each installation only by a random identifier — not a name, an email address or an Apple Account.
The server keeps three things, in a database run by Upstash in the United States:
- How many reads that installation has asked for today and this month, so the limits can be applied.
- The installation's App Attest public key, so later requests from it can be checked.
- The coach's reply, for up to 24 hours, so asking the same thing twice does not cost twice.
It does not store the training or health data sent to it. Its logs record what happened, a hashed installation identifier, which model answered, and the tokens used and what they cost — never your health data, and never the reply.
Anthropic processes the request in order to generate the reply. Under its API terms, requests are kept for up to 30 days for safety review and are not used to train its models.
If you would rather none of this left your device, leave the coach off.
Helping improve the plans
Version 1.0 (build 202) adds an optional feature called “Help improve ALLUNGO plans”. If your copy is an earlier build it is not there yet, and nothing described in this section has been sent. When it does arrive it is off unless you switch it on. You are asked once, on Home, after your first finished plan week, and you can change your mind at any time in More › Help improve plans, which also has “See what’s sent” and “Delete my data”.
If you switch it on, ALLUNGO sends one short record a week describing how the plan went:
- The plan itself — its goal, engine, phase, level, which week of how many, weeks until your race, and the runs it planned.
- Sessions planned, done, skipped and moved; kilometres planned and run.
- Your average effort score for the week, and on tempo runs how your pace compared with the target.
- The long run planned against the long run you did.
- How you answered the daily adjustment card.
- Race and time-trial results, against what the plan predicted for that distance.
- The app's build number, so a change in the numbers can be matched to a change in the app.
Never in it: your name, email or Apple Account. No GPS or routes. No dates finer than the week — a record is stamped “2026-W41”, not with the days you ran. No heart rate, heart rate variability or sleep figures.
It carries a random identifier made on your phone when you switch the feature on. It is linked to nothing else — not your Apple Account, not your iCloud data, not the coach. “Delete my data” removes every row stored against it and discards the identifier, so what you send afterwards cannot be joined to what you sent before.
The record goes to the ALLUNGO coach server on Vercel, which checks the request came from a genuine copy of the app and records only that a send happened and how many records were in it — never their contents. It is then stored in a Supabase database owned by Veylor Studio, in Sydney, Australia.
It is used for one thing: judging ALLUNGO’s training rules against what actually happened, so the plans get better. Never advertising, never sold, never shared with anyone else. It is kept until you delete it — there is no automatic expiry yet, and this page will say so when there is.
Strava
ALLUNGO can put your runs on Strava. It is off until you connect it, in More › Strava, which sends you to Strava’s own page to grant access. ALLUNGO asks for permission to upload only: it never reads your Strava activities, and nothing from Strava reaches the coach.
Once connected, three switches decide what happens, and all three start on: upload finished runs automatically, include the GPS route, and include heart rate. Each run goes up as a file containing what your device recorded:
- The GPS route, with elevation, unless you switch the route off.
- Per-point heart rate, and the run's average and maximum, unless you switch heart rate off.
- Times, distances and cadence, and the session's warm-up, reps and recoveries as separate laps.
- The activity's title and description — the session's name, the plan and which week of it, any personal best the run set, the run's figures, and the coach's one-line verdict if you have the coach on.
One thing to know, because switching the route off does not hide it: if the run has a GPS route, ALLUNGO asks Apple’s geocoder what the first point is near, and may put that park or suburb in the activity’s title — “Central Park Tempo Run”. The title is yours to change on Strava, and giving the run your own name in ALLUNGO replaces it.
ALLUNGO’s server does the upload, so your phone never holds a Strava token. The server keeps your Strava access and refresh tokens encrypted, alongside a link between your Strava athlete number and your installation’s random identifier, and a count of uploads per day. It does not keep the run files; it passes them to Strava and keeps the result. Disconnecting revokes ALLUNGO’s access at Strava and deletes all of it. If you revoke access from Strava’s side instead, Strava tells the server and it deletes the same things. Runs already on Strava stay there, and are yours to edit or delete in Strava.
The race list
When you pick a race, the list comes from ALLUNGO’s own server. The app downloads the same public file everyone gets, keeps it for an hour, and falls back to the copy it last downloaded — or the one it shipped with — when there is no network. The request is a plain download: it carries no identifier, no name, nothing about you, and it is not signed or counted against your installation.
It is still a request to a server, so as with any website the host sees the IP address it came from and when. That is the one connection ALLUNGO makes without being asked; everything else below is yours to switch on.
Who else is involved
- Apple — iCloud sync, Apple Health, and App Attest.
- Vercel — hosts the coach server, in the United States, and hosts this website and counts its visits.
- Upstash — runs the coach server's database, in the United States. It also holds your Strava tokens, if you connect Strava.
- Anthropic — the Claude model that writes the coach's reads.
- Supabase — stores the optional weekly plan outcomes described above, in Sydney, Australia.
- Strava — receives your runs, if you connect it. It is your account there, under Strava's own privacy policy.
- Kit — runs the beta mailing list, in the United States, if you join it.
Nothing goes to advertisers or data brokers, and your information is not sold. The app sends nothing to an analytics service; this website counts its visits, which is described below.
From the app, three things send your information anywhere, each described above and each off until you turn it on: the coach request, the weekly plan outcome, and your runs going to Strava. Besides those, the app downloads the race list, which tells the server nothing about you.
Analytics on this website
This website counts its visits, using Vercel Web Analytics. Vercel already serves every page of this site, so this tells no one new that you were here. There are no advertising pixels, no third-party trackers, no cookies and no cross-site tracking, and the fonts are the ones already on your device rather than a font network’s.
With each page view Vercel records:
- The page you looked at, and the page you came from.
- A rough location from your IP address — country, region and city, not your address and not the IP itself.
- Your device type, operating system and browser, with their versions.
- The time.
There is no cookie and nothing is kept on your device. Repeat views within a visit are matched by a hash Vercel makes from the request itself, which is discarded after 24 hours. It cannot be turned back into you, and it does not follow you to any other site.
What you type in the race search is not part of it. Vercel normally keeps the query string with each page view, and the race list puts your search in the address so a filtered list can be linked. The address recorded for a view is cut off before the question mark, so a search for a race is counted as a visit to the race list and the words are not recorded.
The pace calculator is not part of this. It does its arithmetic in your browser: what you type is never sent to a server, never written into the address, and never saved — reload the page and it is gone.
The beta list
If you put your address in the beta list on the home page, it goes straight from your browser to Kit, which runs the list. It does not pass through this website, and it is not stored here.
Kit emails you a link to confirm you meant it, and you are on the list only once you follow that link. The list is used for one thing: to tell you when the beta opens. Every email has an unsubscribe link, which removes you from Kit, and you can ask at the address below to be taken off it instead.
Kit is Kit.com, in the United States, and it holds your address and what it records about the emails it sends you, under its own privacy policy. The confirmation email is sent by ALLUNGO and shows Kit’s postal address in its footer, as the law requires of a mailing list.
This is the website. The app is separate: it has no analytics at all, and the only things it sends are the three described above, each off until you turn it on.
Children
ALLUNGO is not directed at children and is not intended for use by anyone under 13.
Not medical advice
ALLUNGO is a training tool, not a medical device. It does not diagnose, treat or prevent any condition, and nothing it shows you is medical advice. If something hurts, or you are unsure whether training is safe for you, speak to a qualified professional.
Changes
If this policy changes in a way that matters, the date at the top of this page changes with it.
Contact
Questions about privacy can go to support@allungo.run.