Privacy Policy

Last updated: February 15, 2026

1. Overview

RunDNA ("we", "our", "the Service") is an AI-powered running analytics platform operated by Jason Moon. This policy explains how we collect, use, and protect your information when you use our web application and mobile application.

2. Information We Collect

We collect the following data when you connect your Strava account:

  • Strava Profile: Name, profile photo, city, and country
  • Running Activities: Date, distance, duration, pace, heart rate, elevation, and activity name
  • Authentication Tokens: Strava OAuth access and refresh tokens (stored securely server-side)

We do not collect:

  • GPS route/location data or maps
  • Payment or financial information
  • Device identifiers or advertising IDs
  • Contacts, photos, or other personal files

3. How We Use Your Data

  • Generate your Running DNA personality analysis
  • Provide AI coaching advice based on your training history
  • Create personalized race training plans
  • Calculate training load (ACWR) and race predictions
  • Generate weekly training report cards

4. Third-Party Services

We use the following third-party services to operate RunDNA:

  • Strava API: To read your running activities (with your authorization)
  • Supabase: Database hosting and data storage (encrypted at rest)
  • Fireworks AI: AI model provider for coaching and plan generation
  • Vercel: Web application hosting

Your running data may be sent to AI services to generate coaching responses. We do not sell or share your personal data with advertisers or unrelated third parties.

5. Data Storage & Security

  • Data is stored in Supabase (PostgreSQL) with Row Level Security (RLS) enabled
  • Authentication tokens are stored server-side only and never exposed to the client
  • Session cookies are HMAC-signed, httpOnly, and secure in production
  • All connections use HTTPS/TLS encryption

6. Data Retention & Deletion

Your data is retained while your account is active. You can request complete deletion of your data at any time by contacting us at the email below. Upon request, we will delete your user record, cached activities, and all associated data within 30 days.

You may also revoke RunDNA's access to your Strava data at any time through your Strava Settings.

7. Children's Privacy

RunDNA is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

8. Your Rights

  • Access your personal data stored by RunDNA
  • Request correction of inaccurate data
  • Request deletion of your data
  • Revoke Strava access at any time
  • Export your data upon request

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this privacy policy or wish to exercise your data rights, please contact:

Jason Moon
Email: skypeople41@gmail.com
Website: jasonmoon.dev