Legal

Privacy Policy

Last updated 28 July 2026

This policy explains what personal data RUSA collects, why, and what you can do about it. It applies to the RUSA mobile app and to rusaapp.com.

Who is responsible

The data controller is [YOUR FULL LEGAL NAME OR COMPANY, ORG. NUMBER], [ADDRESS], Sweden. For anything in this policy, contact privacy@rusaapp.com.

What we collect

Account information

When you create an account we store your email address, a securely hashed version of your password, and a display name if you provide one. We never see or store your password in readable form.

Training data

The plans you start, the workouts in them, and your progress: XP, level, rank, which workouts you have completed and when. If you record how a run felt or add a note, we store that too.

Health and fitness data

If you choose to connect Apple Health, RUSA reads the runs you select and stores details of those runs: distance, duration, average and maximum heart rate, calories burned, activity type, and an identifier Apple uses for that workout so the same run is not imported twice.

This is health data, and both European law and Apple treat it as especially sensitive. We only read runs you actively pick — RUSA does not browse your health record. We never use health data for advertising or marketing, never sell it, and never share it with anyone for their own purposes. You can revoke RUSA's access at any time in the iOS Health app, and revoking it stops any further reading immediately.

Diagnostics

When something in the app fails, we record what went wrong, the app version, the platform, the time, and the account it happened to. This is used only to find and fix bugs.

Mailing list

If you enter your email on this website, we store that address, the time, whether you agreed to receive updates, and which version of the consent wording you agreed to.

Why we are allowed to use it

DataPurposeLegal basis (GDPR)
Account information Creating and securing your account Performance of a contract, Art. 6(1)(b)
Training data Running the training plan and progression Performance of a contract, Art. 6(1)(b)
Health and fitness data Logging your runs against your plan Your explicit consent, Art. 9(2)(a)
Diagnostics Keeping the app working Legitimate interest, Art. 6(1)(f)
Mailing list Telling you about RUSA Your consent, Art. 6(1)(a)

Who else touches it

We keep this list short on purpose. These providers process data on our instructions and may not use it for their own ends:

We do not sell personal data, and we do not use advertising or analytics trackers on this site.

How long we keep it

Your rights

Under the GDPR you can ask us to:

Email privacy@rusaapp.com and we will respond within one month. Withdrawing consent does not undo anything done beforehand.

You can delete your account and everything attached to it from inside the app — see Support for the steps.

Complaints

If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se.

Children

RUSA is not intended for children under 16. If you believe a child has given us personal data, contact us and we will delete it.

Security

Data is encrypted in transit and at rest. Access to the production database is restricted by row-level security, so an account can only reach its own records. Administrative access is limited to named accounts on an explicit allowlist.

Changes

If we change this policy materially we will update the date above and, where the change matters to you, tell you in the app or by email.