Privacy Policy
Last updated: 2 September 2026
PB-Runner is built on a simple idea: your running data is yours. We made an app that records your runs, keeps them where you can get at them, and lets you point an AI you already pay for at your own training history — without us getting in the middle or selling anything. This policy sets out exactly what that means for your data: what we hold, where it sits, who else ever sees it, and the control you keep. It’s written to be read, not to be survived.
PB-Runner is made by Bunker 47 LTD, a company registered in England and Wales (company number 09169480), the data controller responsible for your data under this policy. It covers the PB-Runner iPhone app, the Apple Watch app, the Android app, the PB-Runner watch app for Garmin devices, the web dashboard, and the backend they sync to. Reach us any time at privacy@pb-runner.com.
The short version
- Your runs sync to a server we run ourselves. No Supabase, no Firebase, no third-party cloud. Your data sits in our own database on our own server in the United Kingdom.
- No advertising tools, no analytics SDKs, no trackersanywhere in the app. We never sell your data and never share it for advertising. There is nothing to opt out of, because we don’t do it.
- You stay in control. Take it all as one file, delete what you like, close your account from inside the app — any time.
- You decide who else sees it. Your data only leaves us when you choose it: when you connect your own AI, share a run to Strava, or connect to a coach.
What we collect
Once you sign in, your watch and phone record runs into Apple Health, and the app syncs that running data to our server so it follows you across devices, feeds your stats and dashboard, and is there for an AI you connect. What we hold:
- Your runs— date, time, duration, distance, pace, and every metric your watch produces: heart rate, running power, speed, stride length, vertical oscillation, ground contact time and cadence. Form metrics only exist when you’re wearing the watch.
- Your routes — the GPS points for runs that have them, with altitude and accuracy. This is precise location data.
- Wider fitness context from Apple Health — resting heart rate, heart-rate variability, sleep and VO₂max — which sharpen your stats and any coaching.
- Your profile — what you (or your connected AI) set: age, sex, max and resting heart rate, goal, target race, preferred units.
- Your plan — the sessions you or your AI schedule.
- Your account— the identifier, email and name that Sign in with Apple or Google gives us. Use Apple’s private relay and we only ever see the relay address.
- A device notification token— if you turn on notifications, so we can send race-day alerts. You can turn notifications off any time in your phone’s settings, on iPhone or Android.
On Android there is no Apple Health. The PB-Runner Android app records runs straight to your account: the GPS route, pace and distance, and the cadence and stride length derived from your phone’s motion sensors. You sign in with your Google account, which gives us the same identifier, email and name described above. The wider fitness context — resting heart rate, heart-rate variability, sleep and VO₂max — comes from Apple Health, so we only hold it when you use PB-Runner on an iPhone or Apple Watch.
We never ask you to type a name, and there’s no photo and no password — Apple or Google handles who you are. When you sign in, Apple or Google may pass us your name along with your account, and we store it as part of your account.
Apple Health data, and how we treat it
PB-Runner reads from Apple Health (HealthKit) to do its job. The specific health data we read is: your running workouts and their metrics (heart rate, running power, speed, stride length, vertical oscillation, ground contact time, cadence), your workout routes, and your wider fitness context — resting heart rate, heart-rate variability, sleep and VO₂max.
We are clear about the limits on this data, in line with Apple’s HealthKit rules:
- We use Apple Health data onlyto provide the features you’re using — your stats, your dashboard, your history, and any coaching you set up.
- We never use Apple Health data for advertising, marketing, or data-mining, and we never sell it.
- We never store your Apple Health data in iCloud. It lives in our own database, described below.
Using a Garmin watch
We publish a Connect IQ watch app, PB-Runner, that plays a session from your PB-Runner schedule on a Garmin watch and records the run. It’s optional, and none of this applies unless you install it and connect it to your account.
What it records.While the run is going it takes readings of where you are — latitude, longitude and altitude — along with your heart rate and your speed, each stamped with the time since the run started. This is precise location data, and we treat it the way the next section describes. At the end it sends the run’s totals: when it started and finished, the active duration, the distance the watch showed you, your average heart rate, a time for each kilometre, and, on a guided session, what you actually did in each rep — its duration, its distance, and its average and maximum heart rate. That’s everything it records, and it only records while you have it open and running.
Where it goes.To our own backend, described above, over your phone’s connection, using the Garmin Connect app on your phone as the link. It lands in your PB-Runner account as an ordinary run, alongside the ones your iPhone or Apple Watch record, and we hold it and delete it on exactly the same terms as the rest of your data.
The run also saves on the watch as a normal Garmin activity, so it turns up in your own Garmin Connect account like anything else you record there. That’s your watch doing what it always does, under Garmin’s terms rather than ours.
Connecting the watch.You generate a six-character code in the PB-Runner app and type it into the watch app’s settings. The watch exchanges it once for a device token — a long random string that lets that watch, and only that watch, send runs to your account. We never keep the token itself, only a one-way hash of it, which is enough to recognise it and not enough to reconstruct it. The code works once and expires after an hour. The token lasts 90 days and that window moves forward every time the watch uses it, so a watch you run with stays connected and one you stop using falls away on its own. You can revoke a watch any time from the PB-Runner app, which ends its access there and then, and closing your account removes the link along with everything else.
What we don’t do.We have no connection to your Garmin Connect account and no access to what Garmin holds — your history there, your other activities, your sleep, your Garmin scores. Nothing comes back to us from Garmin; the link runs one way, from the watch app to us, and carries only the runs it recorded itself. If your Garmin watch also writes into Apple Health, those runs reach us the way any Apple Health run does, described above — that’s the Apple Health path you set up, not this one.
Health and location are sensitive, and we treat them that way
Heart rate, the rest of your fitness metrics, your age and sex, and your GPS routes can say a lot about you — under UK and EU law, health information is “special category” data, and a route can show where you live. We collect this only to run the features you’re actually using, never for advertising, and never for sale.
How we use your data, and the basis for it
- To run the app and the features you use — recording, syncing, stats, the dashboard, the export. (Performing our contract with you.)
- To send your data to an AI you connect, to a coach you connect, or to Strava when you tap share — only once you set it up. (Your consent.)
- To keep the service reliable and secure — backups, fixing faults, stopping abuse. (Our legitimate interest in a service that works.)
- To meet a legal obligation — if the law requires us to keep or hand over records. (Legal obligation.)
We don’t profile you for advertising, and we make no automated decisions that have a legal or similarly significant effect on you.
Where your data lives
Your data sits in our own PostgreSQL database, on a server we operate ourselves in the United Kingdom. We don’t hand it to a managed cloud-data service, and there are no advertising or analytics tools anywhere in the product — no ad networks, no tracking SDKs, no analytics SDKs.
Your data is encrypted in transit and protected by server-side and access controls.
The web dashboard is delivered by Vercel, but Vercel only serves the page — it never holds your data or your sign-in. Everything is fetched from our own backend. When you use the dashboard, your browser carries a first-party session cookie on pb-runner.compurely to keep you signed in across the dashboard and our API; it is not a tracking cookie and it isn’t used for advertising.
Who else ever sees it
We keep this list genuinely short, and nothing on it happens unless you make it happen:
- Apple and Google — Apple Health is where your runs come from, and Sign in with Apple or Google confirms who you are. Their terms govern that.
- An AI you choose to connect— only if you do. See “Connecting your own AI” below.
- A coach you choose to connect— only if you do. See “Connecting a coach” below.
- Garmin— only if you connect a Garmin watch, and only because the watch saves your run to your own Garmin account as it always would. See “Using a Garmin watch” above.
- Strava — only if you choose to share a single run. See below.
There are no advertising partners, no data brokers and no marketing networks. That’s the whole list.
Connecting your own AI
This is what PB-Runner is for. Rather than lock you into one coach, we let you aim an AI you already use — Claude, ChatGPT, Gemini or another — at your own running data.
When you connect one, you authorise it with Sign in with Apple. From then on, that AI can read your training data through our connector to analyse it and help plan your sessions, and it can only change your profile or schedule with your confirmation.
Here’s the honest shape of it: once you connect an AI, your running and health data (including sleep, heart-rate variability and recovery context) is sent to that provider, under your account with them and under theirterms — not ours. You’re choosing to send it, and you can disconnect whenever you want to stop the flow. This isn’t us selling or sharing your data; we’re the pipe, and you decide who’s on the far end. It’s worth reading the privacy terms of whichever AI you connect.
Connecting a coach
Connecting a coach means inviting another person to see your training. You decide what they get, you can see what they did with it, and you can end it at any moment.
- You choose what they can see. Your training data — runs, splits, pace, heart rate, training load, personal bests and your plan — is what coaching runs on, and is always shared. Your recovery data (resting heart rate, heart-rate variability, sleep, VO₂max) is separate, and only flows if you choose to share it.
- You choose whether they can add training sessions to your plan. Turning that off also stops them leaving you any note you would see — the two travel together — so a coach without it can read what you shared and nothing more.
- Their AI can read what you shared. A coach can use PB-Runner through an AI connector of their own, which means the AI they chose reads your training data to help them answer questions about it. You don’t choose which AI that is. If that matters to you, ask your coach before you connect them.
- Views of your training detail are logged. Opening your training, opening one of your runs, writing a session or writing a note — each is recorded with a time, and you can read that list yourself. We keep that list for twelve months; older entries are removed. (A coach glancing at their own roster list is not recorded against you.)
You make these choices when you generate a connection code, and you can change them from your settings on the website. You can revoke a coach outright — which stops all access immediately — from your settings on the website or in the iPhone app. The iPhone app doesn’t ask when you generate a code yet: a code made there shares your training but not your recovery data, and allows sessions. There is no way to connect or manage a coach on Android.
We don’t check coaches. There’s no vetting and no accreditation — we don’t verify anyone’s qualifications, identity or right to coach, and we don’t tell you that we have. Treat a connection code like a key to your training history: whoever redeems it first gets the access, and if it reaches the wrong person, generate a new one, which makes the old one useless.
A coach you connect is a recipient of the data you share with them. Once you’ve granted a coach access, what you share stays shared until you change it — it’s opt-out from that point, not asked again each time. If your coach deletes their PB-Runner account, your record of what they looked at stays with you; deleting your own account removes it, along with the rest of your data.
Sharing to Strava
Sharing to Strava is off unless you choose it, one run at a time. When you tap share, we post that single run (route, heart rate, cadence) to Strava using a permission that can only publish activities — activity:write and nothing more. We hold that Strava authorisation on our backend so we can complete the upload; you can disconnect it any time, which deletes it. PB-Runner never reads anything from your Strava account.
Race results
If you take part in a race run by one of our race partners, the race organiser may give us the official results — a finisher’s name, bib number, finish time, distance and finishing place — so we can show you and other entrants the results inside the app. We publish these on the organiser’s behalf, on the basis of our and the organiser’s legitimate interest in delivering race results to the people who ran. Results are shown to signed-in users who look one up in the app, not posted as a public list.
If you appear in race results and want your result removed or corrected, email privacy@pb-runner.com and we’ll take care of it, in coordination with the race organiser. This applies whether or not you use the app.
Your data, your control
We built the product around this:
- Take it — download your data from the dashboard any time, as a file (with your GPS routes available too).
- Remove it — delete individual runs, or close your account from within the app and have your data erased.
- Decide what you see — you can import your past runs from other apps if you want them, and the dashboard lets you switch between all your runs and just the ones PB-Runner recorded.
- The legal rights— wherever you live, you can ask to see, correct, limit or object to our use of your data, and withdraw a consent. In the UK and EU you can complain to a regulator (in the UK, the Information Commissioner’s Office, ico.org.uk). Under US state laws such as California’s you have access and deletion rights — and because we never sell or share your data for advertising, there’s simply no opt-out for that to give you. To use any of these, email privacy@pb-runner.com.
How long we keep it
While your account is open, we keep your data so it’s there when you want it. When you close your account or ask us to delete your data, we remove it from our systems within three days, and it clears from our routine backups on the short rotation that follows. We hold on only to anything the law specifically requires, and only for as long as required.
One exception, and it only applies if you coached other athletes here: the log of what you looked at as their coach stays with them when you close your account. It’s their record of who saw their data, so closing your account doesn’t take it away from them. Everything else about your account goes. See “Connecting a coach” above.
Children
PB-Runner isn’t for children. You must be at least 16to use the app and have us hold your data. We don’t knowingly collect data from anyone younger; if we find that we have, we delete it.
Where your data is processed, and moving between countries
We run our server in the United Kingdom and process your data there. PB-Runner is available internationally, so if you use it from outside the UK your data is handled on our UK server. The UK has been recognised by the EU as providing an adequate level of data protection, so data from people in the EU can be handled in the UK on that basis. Where we ever move your data across borders ourselves, we do so only with appropriate safeguards in place. And if you connect your own AI, your data goes to that provider — possibly in another country, under their terms — because you chose to connect them.
Our representatives
Bunker 47 LTD is established in the United Kingdom and is the controller of your data. Our registered address is 284 Brockley Road, London, SE4 2RA, United Kingdom.
For people in the European Union, our representative under Article 27 of the EU GDPR is Jamie Hever, 3 Rue des Arènes, 75005 Paris, France, reachable at jamie@pb-runner.com. You can contact our EU representative on any matter relating to our processing of your data.
Changes to this policy
If we change how we handle your data, we’ll update this policy and flag anything significant inside the app. The date at the top shows when it last changed.
Contact
Questions, requests or complaints: privacy@pb-runner.com. We’ll reply within the time the law allows.