Skip to content
RASQ
TermsPrivacy

Privacy Policy

How the controller named below processes personal data in the RASQ apps and the services that support them, and the rights you have over that data.

ControllerStrukt AB, organisation number 559389-8686, 164 46 Stockholm, Sweden
Applies toRASQ for iPhone, RASQ for Apple Watch, the RASQ widgets, the online services that support them, and this website
Privacy contactprivacy@rasq.app
Supervisory authorityIntegritetsskyddsmyndigheten (IMY), Stockholm, Sweden
Version1.0
Effective date27 September 2026
Last updated27 September 2026

Privacy at a glance

This summary highlights the most important points. The full Policy below gives the details.

  • Most of your data never leaves your devices. Your runs, routes, heart rate and other Apple Health data, training plans, injury and illness check-ins, questionnaire answers, scores and run photos are stored and processed on your iPhone and Apple Watch. We do not receive them.
  • We only hold what the online features need. If you create an account and use Groups, our servers hold your account ID, display name, profile photo, plan type, Group membership and, for runs you share, the start time, distance, moving time and pace. They also count how often your account uses the online features, so that we can stop abuse. We never receive your routes, locations or heart rate.
  • We don’t sell your data, show ads, track you across other apps or websites, or use third-party analytics. Health data is never used for advertising or marketing.
  • Purchases are handled by Apple. We and our subscription provider, RevenueCat, see purchase records, but never your payment details.
  • You are in control. You can manage permissions in your iPhone settings, switch off run sharing, delete runs and local data, and delete your account in the App.
  • You have rights to access, correct and delete your data, to object and to withdraw consent, and to complain to the Swedish Authority for Privacy Protection (IMY) or your local authority.

Contents

  1. 1Who is responsible for your data
  2. 2What this Policy covers
  3. 3Where your data is kept: an overview
  4. 4Data processed only on your devices
  5. 5Data processed by us and our providers
  6. 6Purposes and legal bases
  7. 7Health data and your consent
  8. 8Automated processing and profiling
  9. 9What we do not do
  10. 10Who receives your data
  11. 11International transfers
  12. 12How long we keep data
  13. 13How we protect data
  14. 14Your rights
  15. 15Your choices and controls
  16. 16Children
  17. 17Your devices, backups and widgets
  18. 18Information for people in the United States
  19. 19Information for the UK and Switzerland
  20. 20Changes to this Policy
  21. 21Contact and complaints

This Policy is the information we are required to give you under Articles 13 and 14 of the General Data Protection Regulation. Section 3 shows at a glance where each kind of data is kept.

1.Who is responsible for your data

The controller responsible for the processing of personal data described in this Privacy Policy (the “Policy”) is:

Strukt AB (“we”, “us”, “our”)

Organisation number 559389-8686

Ärvingevägen 14, 164 46 Stockholm, Sweden

Privacy contact: privacy@rasq.app

We have not appointed a data protection officer, because we are not required to do so. Please send all privacy questions and requests to privacy@rasq.app.

2.What this Policy covers

This Policy explains how personal data is processed when you use the RASQ app for iPhone (the “iPhone App”), the RASQ app for Apple Watch (the “Watch App”), the RASQ widgets (together, the “Apps”) and the online services that support them (together with the Apps, the “Service”). It also covers the information you send us when you contact us, and our website at rasq.app, as described in section 5.11.

It does not cover how Apple, Google or other companies process data for their own purposes, for example when you use the App Store, Apple Health, iCloud or Sign in with Apple. Their own privacy policies apply to that processing. Capitalised terms not defined here have the meaning given in our Terms of Service.

3.Where your data is kept: an overview

RASQ is designed to keep as much of your data as possible on your own devices. The table below shows where each type of data is kept and who can access it.

WhereWhatWho can access it
Only on your iPhone and Apple WatchRecorded runs, including GPS routes, heart-rate data and calories; data read from Apple Health; questionnaire answers; training plans; injury, pain, illness and break check-ins; About you details (age, sex, weight, and the highest heart rate your runs have recorded); scores and achievements; run photos; the local copy of your name and profile photo; app settings.You, and anyone with access to your unlocked device or its backups. Not us.
On our servers (only if you create an account)Account ID and sign-in data; display name; profile photo; plan type; Group membership and Group details; summaries of runs you share (start time, distance, moving time, pace); leaderboards; people you have blocked; reports; counts of how often your account uses the online features, and any automatic pause (section 5.5).Us and our hosting provider, Google, in the United States. Parts of it are visible to members of your Group, as explained in section 5.3.
With our subscription providerPurchase and subscription records, a user ID and technical data.Us and RevenueCat.
Sent to Apple servicesAn approximate location (to about 1 km) for weather forecasts; the map area needed to draw your route maps; app attestation data; purchase, sign-in and Apple Health data under your Apple Account.Apple, under Apple’s own privacy policy.
When you email usYour email address, your message and anything you attach.Us and our email provider, Google (section 5.9).
When you visit our websiteYour IP address and technical details of your browser and request.Our website host, Cloudflare (section 5.11).

4.Data processed only on your devices

The data in this section is stored and processed by the Apps on your iPhone and, where relevant, your Apple Watch. It is not sent to us or to our service providers, except for the limited items described in section 5. We describe it here so that you understand what the Apps do, and because we design how the Apps process it.

4.1Questionnaire, plans and check-ins

When you set up RASQ and create a training plan, you may provide:

  • Your goals and running background, such as why you want to run (which may include getting healthier or losing weight), how long you have been running, how often and how far you run, how your recent training has gone, how you pace your runs, recent race or run times, how long you can walk, what stopped you running before (which may include an injury) and what worries you about starting (which may include fear of injury);
  • Plan details, such as your goal distance or time, race name and date, the days and time you have available, your preferred start date, whether anything is getting in the way of training, and whether it hurts when you run;
  • Your year of birth and the standard to use for age-grading (women’s, men’s, or “I’d rather not say”);
  • About you: your age and sex (used to choose the age-grading standard for your score and to predict a maximum heart rate), and your weight if you set it (used to estimate calories). Heart-rate zones are built from your age and from the highest heart rate your runs have recorded; you do not enter heart-rate figures; and
  • Check-ins: whether you are injured, unwell or taking a break, whether you are running less or not at all, when you expect to run again (if you choose to add it), whether you have had a temperature, whether symptoms are in your head or in your chest or body, how an injury feels the morning after a run, and how a session felt.

The Apps use this information to build your report and training plan, to adapt it over time and to personalise pace, effort and heart-rate ranges.

4.2Runs and location

When you record an outdoor run, the iPhone App or the Watch App uses your device’s precise location to record your route: latitude, longitude, altitude, time and accuracy for each position. Location continues to be recorded while a run is in progress, including when the screen is off or the App is in the background. If you allow “Always” location access, the iPhone App can resume recording if iOS interrupts it during a run. The Apps do not track your location when you are not recording a run, except for the single approximate reading described in section 5.7.

From the route and timing, the Apps calculate distance, duration, moving time, pace, splits, elevation gain, best efforts and other analysis. Each run is stored together with its start time and start coordinates. For treadmill runs, no location is used; distance is estimated from the belt speeds you enter. While a run is being recorded, positions are also written to a temporary recovery file so that the run can be restored if the App closes unexpectedly.

4.3Apple Health

If you give permission, the iPhone App reads the following data from Apple Health:

  • workouts and workout routes (runs recorded by the Watch App, and running workouts saved to Apple Health by other apps or devices);
  • heart rate, resting heart rate, heart rate variability, heart rate recovery and cardio fitness (VO2 max);
  • active energy (calories), running stride length and running vertical oscillation;
  • sleep;
  • weight (body mass); and
  • date of birth and sex, as recorded in Apple Health.

The iPhone App uses this data to show heart rate and calories with your runs, to bring runs recorded on Apple Watch into RASQ, to analyse your runs and to calculate your age-graded Run Index and related insights. By default, it only imports workouts from the date you started using RASQ; you can choose to import earlier runs, and you can remove them again. The iPhone App does not write any data to Apple Health.

If you give permission, the Watch App reads heart rate, active energy and walking and running distance during a run so it can show them on your wrist, and writes each run you record to Apple Health as a workout, together with its route, heart rate, active energy and distance.

Apple Health data is used only to provide health and fitness features to you. The only information derived from it that can leave your devices is: the run summary (start time, distance, moving time and pace) of runs you share with a Group, as described in section 5.3; and, for runs recorded on Apple Watch, the rounded start location used for weather forecasts and the map area requested from Apple to draw the route, as described in section 5.7.

4.4Apple Watch and transfers between your devices

The iPhone App sends the Watch App the information it needs during a run: today’s planned session, your pace, effort and heart-rate ranges, your maximum heart rate, your display and voice preferences and your distance unit. The Watch App sends finished runs (including the route) and status information, such as which permissions it has, to the iPhone App. These transfers happen between your paired devices using Apple’s WatchConnectivity technology. We do not receive this data.

4.5Camera and photos

If you allow camera access, you can take a photo for a run. Run photos are stored in the iPhone App’s own storage on your iPhone and are never uploaded. You can also choose a profile photo using the system photo picker, which gives the App access only to the photo you select. Your profile photo is kept on your iPhone and is uploaded only if you have an account (section 5.2).

4.6Scores, widgets, notifications and voice

  • Run Index and achievements. Your Run Index, its components, percentile estimates (for example “top 10% of runners”) and achievements are calculated on your device from your runs, your Apple Health data and published reference tables. They are not sent to us.
  • Widgets. To display widgets, the iPhone App saves a small summary of your upcoming sessions and your Run Index in storage on your iPhone that only the RASQ widgets can read.
  • Notifications. If you start a free trial and allow notifications, the iPhone App schedules a reminder on your device shortly before the trial ends. We do not use a push notification server.
  • Voice coach. Spoken cues are generated on your device using Apple’s speech technology.
  • Settings. The Apps store your preferences and technical settings, such as your distance unit, whether run sharing is on, and which workouts have already been imported.

4.7Legal basis for processing on your devices

We do not have access to the data described in this section. To the extent that its processing by the Apps is nevertheless processing for which we are responsible under data protection law, we rely on:

  • performance of our contract with you (Article 6(1)(b) GDPR) to provide the features you choose to use; and
  • for health data, your explicit consent (Articles 6(1)(a) and 9(2)(a) GDPR), which you give when you allow access to Apple Health and when you choose to provide health information such as injuries, pain, illness, heart rate or weight. See section 7.

The Apps access and store information on your devices only as strictly necessary to provide the features you request, or with your permission through the relevant iOS and watchOS permission prompts.

5.Data processed by us and our providers

5.1Your account

You need an account to use Groups, and you can also sign in to link purchases to you across devices. Accounts are created with Sign in with Apple, and our authentication service is provided by Google Firebase.

  • What we receive from Apple: a unique identifier for your Apple Account that is specific to our apps, a signed token proving that you signed in, and your name if you choose to share it (Apple provides it only on your first sign-in). We do not ask Apple for your email address.
  • What our systems create: an account ID, the dates your account was created and last signed in, and sign-in tokens. Google’s authentication service also processes your IP address and device information to operate and secure sign-in, and keeps logged IP addresses for a few weeks.
  • Why: to create and maintain your account, to authenticate you, to link your purchases to you and to provide Groups.
  • Legal basis: performance of our contract with you (Art. 6(1)(b)); for security logging, our legitimate interest in keeping accounts secure (Art. 6(1)(f)).

5.2Your profile

When you are signed in, the iPhone App stores a profile on our servers so that it can be shown to members of any Group you join:

  • display name (the name you shared through Apple, a name you choose, or “Runner”);
  • profile photo, if you set one. The App reduces it to a small square image before sending it, and our servers check that it is an ordinary photo of that size before storing it;
  • plan type, which is the kind of plan you follow (for example “Half marathon”). It does not include race names, target times, injuries, illness or other plan details; and
  • the ID of your current Group, the IDs of any accounts you have blocked, and the dates the profile and photo were created and updated.

Your profile is not visible to other users unless you are in the same Group. Your profile photo is not publicly accessible. It is stored by our server functions and can only be fetched through them, by a signed-in member of your current Group using a genuine copy of the iPhone App. Someone who leaves or is removed from your Group can no longer fetch it, although their device may keep a copy in its cache for a limited time. If you remove your photo or delete your account, the photo is deleted from our servers. Legal basis: performance of our contract with you (Art. 6(1)(b)).

5.3Groups and leaderboards

When you create a Group, we store its name, a Group ID, a join code, the number of members, you as its owner, and the time zone of your device, which defines when the Group’s week starts.

When you join a Group, we store your membership, your role (owner or member), the time you joined, and a copy of your display name, photo address and plan type.

When you share runs (sharing is on by default in a Group and can be switched off in the Group settings), the iPhone App sends us, for each run: a run ID, your account ID, the date and time the run started, its distance, its moving time and its pace. Runs are shared as you finish or import them, and when you join a Group, the runs you have already done in its current week are shared too. This can include runs recorded on Apple Watch or imported from Apple Health. We never receive your route, map, start location, heart rate, calories or any other health measurement.

From these, our servers calculate each Group’s weekly leaderboard, which contains, for each member, their display name, photo address, plan type, weekly distance, number of runs and position, together with a feed of the week’s most recent runs (member, start time, distance and pace). When the week ends, its final positions and totals are archived on our servers, without the feed of individual runs. Archived weeks are not shown in the App.

What other members of your Group see: your display name, photo, plan type and role; your weekly distance, number of runs and position; and the start time, distance and pace of your recent shared runs. They cannot see your individual shared runs beyond this, or anything from before they joined. Anyone who has your Group’s join code can join the Group and see this information, which is why you should share codes carefully.

The iPhone App keeps a copy of your Group’s leaderboard and members’ photos on your iPhone so that the Group screen works offline. Legal basis: performance of our contract with you (Art. 6(1)(b)).

5.4Safety: blocking, reports and moderation

  • Blocking. When you block a member, their account ID is added to your profile so that the App can hide their name and runs from you. They are not told.
  • Reports. When you report a member, we store your account ID, their account ID, the Group ID, the reason you chose, any note you add (up to 500 characters), the time and the status of the report. The member is not told who reported them. If another member reports you, we process that report about you in the same way, including anything they write in their note.
  • Reports by email and appeals. If you report content or appeal a decision by email, we process your email address, your message and any information you include.
  • Moderation. We review reports manually and keep records of our decisions, the reasons for them and our communications.

Why and legal basis: to keep Groups safe, enforce our Terms of Service and protect users, based on our legitimate interests (Art. 6(1)(f)), and to comply with our legal obligations to handle notices of illegal content and give reasons for our decisions under the EU Digital Services Act (Art. 6(1)(c)). Where a report reveals a threat to someone’s life or safety, we may share information with the competent authorities.

5.5Usage limits and automatic pauses

Our online features could be misused, for example to guess join codes, to flood a Group with runs that did not happen, or to run up the cost of the Service. To prevent this, our servers count, for each account, how often it uses them: redeeming join codes, creating Groups, changing join codes, removing members, reporting members, sharing and removing runs, changing its name, photo or plan type, and uploading or fetching profile photos. Each count covers a period of at most one day, and the limits are set well above what a person normally does.

  • Refusals. When an account reaches a limit, further requests of that kind are refused until the period ends, and the App asks you to try again later.
  • Automatic pauses. If an account shares or removes runs, or changes its profile, far more often than a person does, our servers automatically pause its ability to do those things for 24 hours, and runs shared over the limit are removed from the Group. We record the account ID, which limit was exceeded, the Group and when the pause ends.

These counts and pauses are stored with your account ID. They are not visible to other users and are not used for anything else. Legal basis: our legitimate interests in protecting Groups, our users and the Service from abuse, fraud and excessive cost (Art. 6(1)(f)).

5.6Subscriptions and purchases

Purchases are made through Apple’s App Store. Apple processes your payment under its own terms and privacy policy, and we never receive your payment card details, billing address or Apple Account email address.

We use RevenueCat to manage subscriptions. RevenueCat receives from the App and from Apple:

  • transaction and subscription information, such as the product purchased, price and currency, App Store country, purchase, renewal and expiry dates, whether a free trial or offer was used, renewal status, billing problems, cancellations and refunds;
  • a user ID, which is a random identifier or, if you are signed in, your account ID; and
  • technical information such as your IP address, device model, operating system and App version, and language settings.

Why: to validate purchases, give you access to what you have paid for, restore purchases, prevent fraud and keep financial records. RASQ needs an active subscription to open, so the App asks RevenueCat whether yours is active each time you open it and when you finish setting up. The answer and the date it was given are stored on your iPhone, so that the App still opens for up to 30 days when it cannot reach the service. Legal basis: performance of our contract with you (Art. 6(1)(b)); our legitimate interest in preventing fraud (Art. 6(1)(f)); and compliance with accounting and tax laws where applicable (Art. 6(1)(c)).

5.7Weather and maps

  • Weather. To show a forecast on the Home screen, the iPhone App sends Apple’s weather service (WeatherKit) a location rounded to two decimal places, which is accurate to about 1 km. This location is where your most recent outdoor run started or, if there is none, a single approximate reading of your current position, taken only if you have already allowed location access. We do not send your account ID.
  • Maps. To draw maps of your runs, the Apps request map imagery for the area of the run from Apple Maps.

Apple processes these requests under its own privacy policy. Legal basis: performance of our contract with you (Art. 6(1)(b)).

5.8Security and integrity

  • App attestation. We use Firebase App Check with Apple’s App Attest to confirm that requests to our servers come from a genuine copy of the iPhone App on a genuine Apple device. This involves a cryptographic key generated on your device and an attestation from Apple. Attestation material is not retained, and the resulting tokens expire within 7 days.
  • Server logs. When the App uses our online functions, our hosting provider records technical logs, such as the function called, the time, error details, the IP address and device information of the request, and some identifiers (for example a Group ID, or the account ID in a photo address).
  • Crash reports. If you have turned on “Share With App Developers” in your iPhone’s Analytics & Improvements settings, Apple may share crash and diagnostic reports with us. These do not identify you, and you can turn this off at any time.

Legal basis: our legitimate interests in protecting the Service, our users and our systems against abuse, fraud and attacks, and in fixing errors (Art. 6(1)(f)).

5.9When you contact us

When you email us, we process your email address, name, message and anything else you include, such as screenshots, or the app and iOS version a support email from the iPhone App opens with. We use this to answer you and to improve our support. Our email is hosted by Google (Google Workspace); see section 10. Legal basis: performance of our contract with you (Art. 6(1)(b)) or our legitimate interest in responding to enquiries (Art. 6(1)(f)). If you send us health information, we process it only to handle your enquiry, based on your explicit consent (Art. 9(2)(a)).

5.10Legal obligations and legal claims

We may process and disclose any of the data we hold where necessary to comply with the law, a court order or a request from a competent authority (Art. 6(1)(c)), or to establish, exercise or defend legal claims (Art. 6(1)(f) and, for health data, Art. 9(2)(f)).

5.11Our website

Our website at rasq.app is hosted by Cloudflare. When you visit it, Cloudflare processes your IP address and technical information about your browser and request, as needed to deliver the pages and to protect the website against attacks. The website does not use cookies, analytics, advertising or tracking technologies, does not load anything from other companies, and does not ask you for any information. We do not keep logs of visits. Legal basis: our legitimate interest in providing a secure website (Art. 6(1)(f)).

6.Purposes and legal bases

This table summarises why we process personal data that we or our providers hold, and our legal basis under the EU General Data Protection Regulation (“GDPR”).

PurposeDataLegal basis
Providing features that run on your devices (sections 4.1–4.6)Runs, location, Apple Health data, plans, check-ins, profile settingsContract (6(1)(b)); explicit consent for health data (9(2)(a))
Creating and securing your accountAccount identifiers, name (if shared), sign-in data, IP addressContract (6(1)(b)); legitimate interests (6(1)(f))
Showing your profile and providing Groups and leaderboardsDisplay name, photo, plan type, membership, shared run summariesContract (6(1)(b))
Keeping Groups safe and handling reports and appealsBlock lists, reports, notes, moderation records, communicationsLegitimate interests (6(1)(f)); legal obligation (6(1)(c))
Preventing abuse and excessive use of the online featuresUsage counts, automatic pausesLegitimate interests (6(1)(f))
Selling and managing subscriptionsTransaction records, user ID, technical dataContract (6(1)(b)); legal obligation (6(1)(c))
Preventing fraud and securing the ServiceApp attestation data, logs, transaction dataLegitimate interests (6(1)(f))
Weather forecasts and mapsApproximate location, map areaContract (6(1)(b))
Answering your messagesContact details, message contentContract (6(1)(b)); legitimate interests (6(1)(f)); explicit consent for health data you send (9(2)(a))
Providing and protecting our websiteIP address, browser and request informationLegitimate interests (6(1)(f))
Complying with law and handling legal claimsAny relevant dataLegal obligation (6(1)(c)); legitimate interests (6(1)(f)); 9(2)(f) for health data

Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. You can ask us for more information about this balancing, and you have the right to object (section 14). Providing data for account and Group features is necessary to use those features; if you do not provide it, you can still use the parts of the Service that do not require it. You are not legally required to provide any personal data to us.

7.Health data and your consent

Some of the data processed in the Apps reveals information about your health, such as heart rate, heart rate variability, sleep, weight, injuries, pain, illness and certain goals. The law treats this as a special category of personal data.

  • It stays on your devices. Health measurements and check-in answers are processed on your iPhone and Apple Watch and are not sent to our servers. The run summaries you share with a Group contain no heart rate or other health measurements.
  • You choose. The Apps access Apple Health only with your permission, which you give through Apple’s permission screens and can give for some data types but not others. Entering health information such as injuries, pain or illness is optional, and the App tells you what it will use it for.
  • You can withdraw your consent at any time, by turning off the Apps’ access in the Health app (tap your profile picture › Privacy › Apps › RASQ), by deleting the information in the App, or by deleting the App. Withdrawing consent does not affect processing that happened before, and some features will stop working or become less accurate.
  • Strict limits. Data obtained from Apple Health is used only to provide health and fitness features to you. It is never used for advertising, marketing or data mining, never sold, and never shared with advertising platforms, data brokers or information resellers.

8.Automated processing and profiling

The Apps and our servers process your information automatically to provide the Service. This includes:

  • Training plans. The Apps build your plan from the answers you give when you set it up, following general training principles such as increasing training gradually and keeping most runs easy. Your plan does not rewrite itself from your runs. It changes when you tell it something (that you are injured, unwell or taking a break, or that you want different days or a different goal), and it then reduces, pauses and rebuilds your training gradually. Your recorded runs are used to mark sessions as done and to work out your Run Index and insights.
  • Run Index and insights. The Apps compare your running performance with published age-grading standards for your age and sex, and estimate where you sit among runners using published statistics.
  • Leaderboards. Our servers rank Group members by the distance of the runs they shared during the week.
  • Usage limits. Our servers automatically refuse requests over a limit, and pause an account’s run sharing and profile changes for 24 hours when it goes far beyond what a person does (section 5.5). A pause lifts by itself and does not affect your runs, your plan or your subscription.

The first three are forms of profiling. None of this involves decisions that produce legal effects on you or similarly significantly affect you within the meaning of Article 22 GDPR. You can change your answers, adjust or override your plan, and contact us if you have questions about how a result was produced or why a request was refused.

9.What we do not do

  • We do not sell your personal data, or share it with third parties for targeted or cross-context behavioural advertising.
  • We do not show advertising in the Apps.
  • We do not track you across other companies’ apps or websites, and we do not access your device’s advertising identifier.
  • We do not use third-party analytics, advertising or tracking software in the Apps or on our website.
  • We do not use Apple Health data, or any other health data, for advertising, marketing or data mining.
  • We do not store your health information in iCloud through the Apps.
  • We do not use your personal data to train artificial intelligence models.
  • We do not send you marketing emails. We do not collect your email address unless you email us.

10.Who receives your data

RecipientRole and dataLocation and safeguards
Members of your GroupOther users who can see your display name, photo, plan type, role, weekly distance, number of runs, position and the start time, distance and pace of your recent shared runs (section 5.3).Wherever they are. They access it through the App.
Google (Google Ireland Limited, Google Cloud EMEA Limited and their affiliates, including Google LLC)Our processor for Firebase (authentication, database, server functions, storage of profile photos and app attestation), which processes account, profile, Group, shared run, report, usage-limit and log data on our behalf; and for our email (Google Workspace), which processes the messages you send us and our replies (section 5.9).Firebase: United States, for the database (multi-region), server functions (Iowa), profile photo storage (South Carolina) and authentication. Email: any country where Google or its subprocessors have facilities, including the United States. Safeguards: Google’s data processing terms, the EU–US Data Privacy Framework and Standard Contractual Clauses.
RevenueCat, Inc.Our processor for subscription management. Processes purchase records, user ID and technical data on our behalf (section 5.6).United States. Safeguards: data processing addendum and Standard Contractual Clauses.
Cloudflare, Inc.Our processor for hosting this website. Processes visitors’ IP addresses and request information to deliver the website and protect it (section 5.11).Cloudflare’s global network, including the United States. Safeguards: data processing addendum, EU–US Data Privacy Framework and Standard Contractual Clauses.
Apple (Apple Inc. and, in the EU, Apple Distribution International Ltd.)Independent controller when it provides you with the App Store, payments, Sign in with Apple, Apple Health, iCloud, WeatherKit, Apple Maps, App Attest, WatchConnectivity and crash reporting. Apple provides us with purchase information and your sign-in identifier.Under Apple’s own privacy policy and safeguards.
Professional advisersLawyers, accountants and auditors, where necessary, under a duty of confidentiality.Mainly Sweden and the EU.
Authorities and courtsPolice, supervisory authorities, courts and other public bodies where the law requires it, or where necessary to protect someone’s life or safety or to defend legal claims.As required by law.
A buyer or successorIf we are involved in a merger, acquisition or sale of all or part of our business, data may be transferred to the new owner, who must continue to protect it in line with this Policy. We will tell you before this happens.As applicable.

Our processors may only process your data on our instructions and are contractually required to protect it to a standard at least equivalent to this Policy and applicable law. We do not share your data with any other third parties.

11.International transfers

The data on our servers is stored in the United States: our database, server functions and profile photo storage run in Google data centres there, and Google’s authentication service runs only in US data centres. Our email is hosted by Google Workspace, which may store messages in any country where Google or its subprocessors have facilities. Google may also access data from other countries to provide support and security, RevenueCat and its sub-processors operate in the United States, and Cloudflare serves our website from its global network. Where data is transferred to a country that the European Commission has not found to provide an adequate level of protection, we rely on:

  • the EU–US Data Privacy Framework, where the recipient is certified under it (Article 45 GDPR); or
  • Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR), together with supplementary measures such as encryption in transit and at rest.

You can request a copy of the relevant safeguards by contacting privacy@rasq.app.

12.How long we keep data

We keep personal data only for as long as necessary for the purposes described in this Policy. When the periods below end, the data is deleted or irreversibly anonymised. Deleted data may remain in our providers’ backups for a limited period (for Google, up to 180 days) until it is overwritten, and it is not used during that time.

DataRetention
Data on your devices (runs, plans, check-ins, photos and everything in section 4)Until you delete it: by using “Clear local data”, deleting your account, deleting the App or resetting your device. We cannot delete it for you. When you delete a single run, it is removed from your history, your totals and your Group straight away, and its photo and map images are deleted; the rest of the run’s record, including its route, stays hidden in the App’s storage on your iPhone until you use “Clear local data”, delete your account or delete the App. The temporary recovery file for a run is deleted when the run is saved or discarded.
Account and sign-in dataUntil you delete your account. Google keeps logged IP addresses for a few weeks.
Profile (display name, photo, plan type, block list)Until you change or remove the information, or delete your account.
Group membershipUntil you leave the Group, are removed from it or delete your account, or the Group closes.
Shared run summariesUntil you delete the run in the App, leave or are removed from the Group, delete your account, or the Group closes.
Current weekly leaderboardRecalculated continuously; your data is removed when you leave the Group or delete your account.
Archived weekly results (final positions and totals only)While the Group exists; they are deleted when it closes. Your rows stay if you leave the Group, and are removed when you delete your account.
Group details (name, join code, time zone)Until the last member leaves and the Group closes.
Usage countsEach count starts again when its period ends, which is at most one day. The record is deleted when you delete your account.
Automatic pausesA pause ends after 24 hours. The record of it is kept until you delete your account.
Reports, moderation decisions and appeals12 months after the matter is closed, or longer if needed for legal claims or required by law. Reports are kept after an account is deleted for this period, so that we can deal with repeated abuse.
Purchase and subscription records (RevenueCat)For as long as needed to provide and restore your purchases, and for up to 7 years where required by accounting or tax law. You can ask us to delete records that are not needed for these purposes.
Server logsUp to 30 days.
Website visitsWe keep no logs of visits. Cloudflare processes request data only as long as needed to deliver and protect the website.
Emails and support requests24 months after the matter is resolved.
Data needed for legal claimsUntil the claim is resolved and any applicable limitation period has expired.

When you delete your account, we remove you from your Group (which deletes your shared run summaries), remove your rows from archived weekly results, delete your profile photo, your profile and block list, your usage counts and any automatic pause, and then delete your account. If you owned a Group, ownership passes to the member who has been in it longest, or the Group closes if you were its only member. Other members’ devices may keep temporary copies of the leaderboard and your photo in their caches for a limited time. Reports are kept as described above, and purchase records are kept as described above. Deleting your account does not cancel a subscription.

The App also erases everything it keeps on the iPhone you delete the account from (your runs, training plan, check-ins, questionnaire answers, run photos, profile name and photo, and your settings) once the deletion has been confirmed, when you delete your account from the You tab or from the screen shown when you have no active subscription. If you delete your account from the subscription offer at the end of first-time setup, the App keeps what it has built on that iPhone until you clear it from the You tab. Data on your other devices is not affected, and your workouts remain in Apple Health.

13.How we protect data

We use appropriate technical and organisational measures to protect personal data, including:

  • data minimisation by design: sensitive data such as routes and health data stays on your devices, and run summaries shared with Groups are limited to four figures;
  • encryption of data in transit, and at rest on our providers’ systems;
  • server-side access rules that deny access by default, so that users cannot read other users’ profiles or shared runs, only members can read a Group’s leaderboard, and no user can change leaderboard results;
  • profile photos that are never publicly accessible, and are served only to current members of the same Group;
  • app attestation, per-account usage limits and automatic pauses (section 5.5), and server-side checks of shared runs, names and photos;
  • restricted access to our systems, limited to people who need it and who are bound by confidentiality; and
  • the security features of your devices, such as your passcode, Face ID or Touch ID, and data protection encryption.

No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection within 72 hours where required, and we will inform you without undue delay where the breach is likely to result in a high risk to you.

14.Your rights

Under the GDPR and other applicable data protection laws, you have the following rights:

  • Access: to find out whether we process your personal data and to receive a copy of it, together with information about the processing.
  • Rectification: to have inaccurate data corrected and incomplete data completed. You can change your display name and photo in the App at any time.
  • Erasure: to have your data deleted, for example when it is no longer needed or you withdraw consent. You can delete your account in the App.
  • Restriction: to ask us to restrict processing in certain circumstances, for example while we check the accuracy of data.
  • Data portability: to receive data you provided to us, which we process by automated means on the basis of consent or contract, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Withdrawal of consent: to withdraw your consent at any time, without affecting processing that took place before (see section 7).
  • Automated decisions: not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not make such decisions.
  • Complaint: to lodge a complaint with a supervisory authority (section 21).

Your right to object

Where we process your data on the basis of our legitimate interests, you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing the data unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. We do not process personal data for direct marketing.

14.1How to exercise your rights

  • In the App: many rights can be exercised directly using the controls in section 15.
  • By email: contact privacy@rasq.app. Please tell us which right you want to exercise. Because we do not hold your email address, we may ask you for information that lets us confirm that you own the account concerned, and we will use that information only for that purpose.
  • Data on your devices: we cannot access, copy or delete data that exists only on your devices. You can view and delete it in the Apps, and manage Apple Health data in the Health app.

We will respond within one month of receiving your request. We may extend this by up to two further months where necessary because of the complexity or number of requests, in which case we will tell you within the first month. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.

15.Your choices and controls

To…Do this
Change or stop location accessiPhone Settings › Privacy & Security › Location Services › RASQ (choose Never, While Using the App or Always, and turn Precise Location on or off). On Apple Watch, use the Watch’s Privacy settings.
Change or stop Apple Health accessHealth app › tap your profile picture › Privacy › Apps › RASQ.
Change camera, photo or notification accessiPhone Settings › RASQ.
Stop sharing runs with your GroupGroup settings › switch off “Share my runs”.
Remove a shared runDelete the run in the App.
Leave a GroupGroup settings › Leave group.
Block or report a memberOpen the member in your Group › Block or Report.
Change your name or photoThe You tab.
Remove earlier runs imported from Apple HealthThe You tab › remove the runs from before you had RASQ. They remain in Apple Health.
Delete all RASQ data on your iPhoneThe You tab › Clear local data, or delete the App. Deleting your account also erases it.
Sign out or delete your accountThe You tab › Sign out, or Delete account. You can also delete your account from the screen shown when you have no active subscription.
Stop using Sign in with Apple with RASQiPhone Settings › [your name] › Sign-In & Security › Sign in with Apple › RASQ.
Manage or cancel a subscriptioniPhone Settings › [your name] › Subscriptions. Subscriptions are managed by Apple, not inside the App.
Stop crash reports reaching usiPhone Settings › Privacy & Security › Analytics & Improvements › Share With App Developers.

Menu names may vary slightly between iOS versions and App updates.

16.Children

The Service is not intended for anyone under 16, and the setup questionnaire does not accept a year of birth for anyone younger. We do not knowingly process personal data of children under 16. If you believe that a child under 16 has created an account or provided us with personal data, please contact privacy@rasq.app and we will delete it. Users aged 16 or 17 need the permission of a parent or guardian, as explained in our Terms of Service.

17.Your devices, backups and widgets

  • Device access. Anyone who can unlock your iPhone or Apple Watch can see the data stored in the Apps. Use a passcode and keep your devices secure.
  • Backups. If you back up your iPhone with iCloud Backup or to a computer, the backup may include data stored by the Apps. These backups are controlled by you and, for iCloud, provided by Apple under its terms. We recommend encrypted backups.
  • Widgets and notifications. Widgets and notifications can show information such as your next session or your Run Index on your Home Screen, Lock Screen and other surfaces that may be visible to people near you. You can remove widgets and change notification previews in your iPhone settings.
  • Apple Health and Apple Watch. Data that the Watch App saves to Apple Health is managed by Apple Health, including its own sync and backup features, and is not deleted when you delete the Apps.

18.Information for people in the United States

18.1General

We do not sell personal information, and we do not “share” personal information for cross-context behavioural advertising or use it for targeted advertising. We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects. We do not share personal information with third parties for their own direct marketing purposes. Depending on the state where you live, you may have rights to know, access, correct, delete and obtain a copy of your personal information, and to appeal our decision on your request. You can exercise these rights as described in section 14.1, and we will not discriminate against you for doing so.

18.2Consumer Health Data Privacy Notice

This notice applies to residents of Washington, Nevada and other states whose laws protect consumer health data.

  • Categories of consumer health data: heart rate, heart rate variability, heart rate recovery, resting heart rate, cardio fitness (VO2 max), active energy, running form measurements, sleep, weight, workouts and routes, date of birth and sex from Apple Health; injury, pain, illness and symptom information and health-related goals that you enter; and information derived from these, such as training status, calorie estimates and your Run Index. Precise location recorded during runs is used only to measure runs, not to identify attempts to obtain health care services.
  • Sources: you, your devices’ sensors and, with your permission, Apple Health.
  • Purposes: to provide the features you request, such as recording and analysing runs, building and adapting training plans, and calculating your Run Index. We collect and use consumer health data only with your consent, or as necessary to provide the features you have requested.
  • How it is handled: consumer health data is processed on your devices and is not sent to our servers (section 7).
  • Sharing: we do not sell consumer health data and do not share it with third parties or affiliates. The only data derived from your runs that can be shared is the run summary (start time, distance, moving time and pace) that you choose to share with your Group, which contains no health measurements.
  • Your rights: you have the right to confirm whether we collect, share or sell your consumer health data, to access it, to obtain a list of any third parties and affiliates with whom it has been shared, to delete it, and to withdraw your consent. Because this data is stored on your devices, you can view and delete it directly in the Apps and in the Health app. You can also contact privacy@rasq.app.
  • Appeals: if we decline your request, you may appeal by emailing privacy@rasq.app with the subject line “Privacy appeal” within a reasonable time. We will respond in writing within 45 days, explaining the reasons for our decision. If your appeal is denied, you may contact the Attorney General of your state.

18.3Do Not Track

The Apps and our website do not track users across third-party apps or websites over time, and do not allow third parties to do so, so they do not respond to “Do Not Track” signals.

19.Information for the UK and Switzerland

If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply, references to the GDPR include the UK GDPR, you may complain to the Information Commissioner’s Office (ico.org.uk), and transfers from the UK are protected by the UK International Data Transfer Addendum to the Standard Contractual Clauses or UK adequacy regulations. If you are in Switzerland, the Federal Act on Data Protection applies, you may complain to the Federal Data Protection and Information Commissioner (edoeb.admin.ch), and transfers from Switzerland are protected by the Swiss–US Data Privacy Framework where applicable or Standard Contractual Clauses adapted for Swiss law.

20.Changes to this Policy

We will update this Policy when we change how we process personal data, for example when we introduce new features, or when the law changes. We will publish the updated Policy on this page with a new effective date. If we make material changes, we will tell you in the App before they take effect. If a new feature requires new processing of your personal data, such as storing runs on our servers or using artificial intelligence services, we will explain it before the processing begins and ask for your consent where required. Earlier versions of this Policy are available on request.

21.Contact and complaints

Strukt AB, organisation number 559389-8686

Ärvingevägen 14, 164 46 Stockholm, Sweden

Email: privacy@rasq.app

If you are unhappy with how we handle your personal data, please contact us first so that we can try to help. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA country where you live, work or where you believe an infringement took place. In Sweden, the supervisory authority is:

Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection

Box 8114, 104 20 Stockholm, Sweden

imy@imy.se · www.imy.se

RASQ Privacy Policy · Version 1.0 · Effective 27 September 2026

© 2026 Strukt AB

Terms of ServicePrivacy Policysupport@rasq.app