Legal
Privacy Policy
Last updated 28 July 2026
This policy explains what personal data RUSA collects, why, and what you can do about it. It applies to the RUSA mobile app and to rusaapp.com.
Who is responsible
The data controller is [YOUR FULL LEGAL NAME OR COMPANY, ORG. NUMBER], [ADDRESS], Sweden. For anything in this policy, contact privacy@rusaapp.com.
What we collect
Account information
When you create an account we store your email address, a securely hashed version of your password, and a display name if you provide one. We never see or store your password in readable form.
Training data
The plans you start, the workouts in them, and your progress: XP, level, rank, which workouts you have completed and when. If you record how a run felt or add a note, we store that too.
Health and fitness data
If you choose to connect Apple Health, RUSA reads the runs you select and stores details of those runs: distance, duration, average and maximum heart rate, calories burned, activity type, and an identifier Apple uses for that workout so the same run is not imported twice.
This is health data, and both European law and Apple treat it as especially sensitive. We only read runs you actively pick — RUSA does not browse your health record. We never use health data for advertising or marketing, never sell it, and never share it with anyone for their own purposes. You can revoke RUSA's access at any time in the iOS Health app, and revoking it stops any further reading immediately.
Diagnostics
When something in the app fails, we record what went wrong, the app version, the platform, the time, and the account it happened to. This is used only to find and fix bugs.
Mailing list
If you enter your email on this website, we store that address, the time, whether you agreed to receive updates, and which version of the consent wording you agreed to.
Why we are allowed to use it
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account information | Creating and securing your account | Performance of a contract, Art. 6(1)(b) |
| Training data | Running the training plan and progression | Performance of a contract, Art. 6(1)(b) |
| Health and fitness data | Logging your runs against your plan | Your explicit consent, Art. 9(2)(a) |
| Diagnostics | Keeping the app working | Legitimate interest, Art. 6(1)(f) |
| Mailing list | Telling you about RUSA | Your consent, Art. 6(1)(a) |
Who else touches it
We keep this list short on purpose. These providers process data on our instructions and may not use it for their own ends:
- Supabase — database, authentication and file hosting. Data is stored in [YOUR SUPABASE REGION, e.g. eu-central-1].
- Vercel — serves this website.
- one.com — sends account emails such as welcome and password reset messages.
We do not sell personal data, and we do not use advertising or analytics trackers on this site.
How long we keep it
- Account and training data — until you delete your account, then removed.
- Health data — same as above, or sooner if you delete individual logged runs.
- Diagnostics — up to 12 months.
- Mailing list — until you unsubscribe or ask us to remove you.
Your rights
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you
- correct anything that is wrong
- delete your data
- send your data to you or another provider in a portable format
- restrict or object to certain processing
- withdraw consent at any time, including for health data and emails
Email privacy@rusaapp.com and we will respond within one month. Withdrawing consent does not undo anything done beforehand.
You can delete your account and everything attached to it from inside the app — see Support for the steps.
Complaints
If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se.
Children
RUSA is not intended for children under 16. If you believe a child has given us personal data, contact us and we will delete it.
Security
Data is encrypted in transit and at rest. Access to the production database is restricted by row-level security, so an account can only reach its own records. Administrative access is limited to named accounts on an explicit allowlist.
Changes
If we change this policy materially we will update the date above and, where the change matters to you, tell you in the app or by email.