RunVue Privacy Policy
Effective Date: October 1, 2026 · Last updated: October 3, 2026
RunVue ("the App", "we", "our") is developed and operated by the developer reachable at setlog.net
RunVue turns your runs into 3D replay videos entirely on your device. This policy covers both versions of the App: the iPhone app, which reads your runs from Apple's Health app, and the Android app, which reads them from Health Connect. Neither version has user accounts, and neither uses analytics or tracking SDKs of its own. The iPhone app has no advertising. The Android app shows ads from Google AdMob to free users; RunVue Pro subscribers on Android see no ads. Where the two versions differ, this policy says so — see iPhone app and Android app. This Privacy Policy explains what the App accesses on your device, how it is used, and your rights regarding that information.
In short: the developer does not collect your health or route data. Your health and route data are processed entirely on your device and never sent to any server — including the ad SDK on Android. The only thing the App downloads from our server is the map data needed to build a video, and that request contains only the name of a map grid file covering a large area (or a country code for place names) — no route, coordinates, device identifier, or account information. Our hosting provider, Cloudflare, may process your IP address when you make that request. On Android only, the free version shows ads: Google AdMob receives your device's advertising ID, your IP address, how you interact with ads, and diagnostic information from its SDK, and where the law requires it you are asked for consent first. Your health data is never sold, never shared with third parties, and never used for advertising.
Data Both Versions Handle the Same Way
- No location permission: RunVue never asks for location access on either platform. It reads your route only from the workout route already recorded in Apple Health or Health Connect.
- Read-only health access: the App never writes anything to Apple Health or Health Connect, and it does not read your body weight, date of birth, or age.
- Map downloads: described under "Map Data Downloads" below.
- Sharing: videos leave your device only when you save or share them yourself (see "Sharing").
Map Data Downloads (both versions, unrelated to location permission)
- Purpose: the App downloads the map data needed to build a replay video from our static storage (Cloudflare R2, at
tiles.runvue.setlog.net).
- What's in the request: on iPhone, only a map tile number (a grid cell roughly tens of kilometers wide). On Android, the App downloads whole files: a world index file, map grid files whose name identifies a large grid cell (on the order of 100 km across), and a place-name file whose name contains a country code. Your route, coordinates, device identifier, and account information are never included, and no cookies are used. On Android the request headers are fixed (for example, the language header is always English), so they do not reveal your language settings.
- Request logs: we do not retain request logs. However, due to how internet communication works, our hosting provider (Cloudflare) may technically process communication records such as IP addresses; this is governed by Cloudflare's Privacy Policy.
- On-device cache: downloaded map data and place-name files are cached on your device and can be deleted at any time in Settings.
iPhone app. The sections that start with "iPhone:" apply only to the iPhone app. The Android app is described in the sections that start with "Android:".
iPhone: Data the App Uses
Everything below is processed on your device only. Each permission is requested when it is first needed, and you can change it at any time in Settings.
Health Data (HealthKit, Read-Only)
- Read from Health — 5 required types: workouts, workout route, heart rate, running speed, and walking + running distance. These are required to build a replay video.
- Read from Health — 1 optional type: active energy (calories). If a measured value is recorded in Health it is shown as-is in the video's calorie field; if none is recorded or you deny access, the App shows an estimate marked with "~", computed from the distance and a fixed standard body weight (70 kg) that is the same for every user — no personal body information is used. The App does not read your body weight, date of birth, or age — so that neither can be inferred from a video you share; heart-rate zone colors use a fixed reference that does not depend on age. Body-weight and date-of-birth read permissions you may have granted to an earlier version are no longer used, and you can turn them off in Health's data-access settings.
- Never written to Health: the App does not write any data to the Health app (it never requests write access).
- Where it goes: a copy of what the App reads is kept only on your device, in the App's own database. It is never uploaded to any server, and this copy is excluded from iCloud backups.
- Temporary use during rendering: heart-rate and calorie values are written to a temporary file on your device only while a video is being rendered, and are deleted immediately afterward.
- How it is not used: Health data is never used for advertising, marketing, or data mining, is never sold, and is never disclosed to advertisers, data brokers, or any other third party.
- Note: heart rate, average BPM, date and time, and (if you allow reading it) calories are rendered onto the video's on-screen display (HUD), so sharing the video shares those figures too. See "Sharing" below.
Photos (Add-Only)
- Permission: the App requests only an add-only permission to save finished videos and summary images to your Photos library.
- Never read: the App cannot read your existing photos or albums.
- No location metadata: the videos and images it saves contain no location metadata.
Notifications
- What: local notifications scheduled only on your device — that a video has finished rendering, or that rendering will resume when you return to the App. Notification text never includes distance, date, place names, coordinates, or heart rate. There are no push notifications and no marketing messages.
File Import
- GPX/FIT/zip files you choose are read on your device and converted into a run record. The original file is not kept once parsing finishes.
No Advertising or Tracking
The iPhone app has no advertising. It does not use advertising identifiers (IDFA) or any third-party analytics, advertising, attribution, or crash-reporting SDKs, and it does not track you across other apps or websites.
iPhone: Purchases (Subscriptions)
RunVue Pro is sold as an auto-renewing monthly or yearly subscription through the App Store (unlocks every playback speed from 2x to 60x, the Cinematic and Calm camera presets, and camera height and zoom). Videos at 1x and Summary speed, the Nav camera, and the pace and heart-rate waveform are free with no limit on how many you make. The small RunVue watermark appears in every video, free or Pro. Purchases, free trials, billing, renewals, refunds, and Family Sharing are handled entirely by Apple using StoreKit. We never see or store your Apple Account details or payment information. The App checks the purchase (transaction) information that Apple keeps on your device through StoreKit to unlock Pro features; it does not make its own copy of your subscription status or send it to any server. You can manage or cancel a subscription in Settings → your name → Subscriptions.
iPhone: Data Stored on Your Device
The following stay on your device and are never uploaded to any server:
- A copy of your run list — copies of the workouts and routes read from the Health app (plus anything imported from files)
- Library videos — your finished replay videos (up to 30, automatically trimmed by storage limits)
- Map cache — downloaded map tiles and place-name files (up to 500MB)
- Settings (subscription status comes from the transaction information Apple StoreKit keeps on your device; the App keeps no separate copy)
The copy of data read from Health, and anything derived from it, is excluded from iCloud backups. RunVue does not use iCloud or CloudKit to sync data.
iPhone: Diagnostics (Only If You Choose)
If something goes wrong, you can export a diagnostics file from Settings → Advanced → Diagnostic Log. Nothing is sent automatically. The file is created on your device and leaves it only if you pick a destination in the share sheet. The diagnostics file contains things like device model, iOS version, app version, per-step processing times, and error codes; it never contains coordinates, place names, or any value that could identify a location such as a home address.
MetricKit records only diagnostic counts on your device and does not transmit them automatically. The App has no separate crash-reporting SDK.
iPhone: Your Choices and Deleting Your Data
- Permissions: you can review or change Health, Notifications, and Photos (add-only) access at any time in the iOS Settings app.
- Delete health records: Settings → Advanced → Delete Health Records removes only the App's own copy (your run list and route copies). The original data in the Health app is left untouched.
- Delete all data: Settings → Advanced → Delete All Data (two-step confirmation) removes the App's database, library videos, map cache, and settings. The original data in the Health app is not affected.
- Uninstall: removing the App removes its data from that device. Original data already in the Health app stays there until you delete it yourself in the Health app.
- Subscription: the subscription itself is managed by Apple; the App only reads the status from StoreKit's local transaction information.
Android app. The sections that start with "Android:" apply only to the Android app (Android 9 and later). The App's Terms of Use for Android also apply.
Android: Summary — What Goes Where
| Data |
Where it is processed |
Who receives it |
| Workouts, routes, heart rate, speed, distance, calories from Health Connect |
On your device only |
No one — not us, not the ad SDK |
| Name of a map grid file or a country place-name file, IP address |
Sent when map data is downloaded |
Our storage host, Cloudflare (no logs kept by us) |
| Advertising ID, app set ID, IP address, ad interactions, ad SDK diagnostics |
Sent by the Google Mobile Ads SDK (free version only) |
Google (see "Android: Advertising") |
| Purchases and subscription status |
Google Play |
Google. We never see your payment details |
| Diagnostic log, emails or contact-form messages |
Only if you send them |
Us (and Tally for the contact form) |
Android: Health Connect
Health Connect is Android's on-device store for health and fitness data (built into Android 14 and later; on Android 9 to 13 it is an app from Google Play). RunVue reads your runs from Health Connect to turn them into replay videos. It only reads; it never writes, changes, or deletes anything in Health Connect, and it does not read Health Connect data in the background.
What the App reads (with your permission)
- Exercise sessions — to list your runs (start and end time, time zone, type).
- Exercise routes — the GPS route of a run, which is what the replay video follows. Android asks you separately for route access: you can allow a single run's route or choose to always allow routes. Without route access, that run cannot be turned into a video.
- Heart rate, speed, and distance — shown in the video's on-screen display and used to pace the replay.
- Active calories burned (optional) — if a measured value exists it is shown in the video; otherwise the App shows an estimate marked with "~", computed from the distance and a fixed standard body weight (70 kg) that is the same for every user.
- Health data history (optional) — lets the App see runs older than 30 days. Without it, Health Connect only gives the App data from about 30 days before you first granted access onward.
The App does not read body weight, date of birth, or age (heart-rate zone colors use a fixed reference of 190 bpm for everyone), and it requests no other Health Connect data.
What is copied to your device, and what is not
- Kept in the App's database on your device: each run's start and end time, time zone, distance, duration, and whether it was indoors; its source (the Health Connect record ID and the name of the app that recorded it); and the route.
- Not stored: heart rate, speed, and calories. They are read from Health Connect into memory each time you preview or save a video, and are not saved in the App's database.
How Health Connect data is used and not used
- It stays on your device. It is never sent to us or to any server.
- It is never used for advertising or marketing, and it is never passed to the ad SDK (Google AdMob) or any other third-party SDK. Ad requests contain no route, location, or health information.
- It is never sold, and it is never given to data brokers, advertising platforms, insurers, lenders, or employers, or used for decisions about credit, insurance, or employment.
- It leaves your device only inside a video you choose to save or share (see "Sharing").
- No person reads it. We have no access to it.
The use of information received from Health Connect will adhere to the Health Connect Permissions policy, including the Limited Use requirements.
Your control
- Grant or revoke each permission at any time in Health Connect (in Android Settings on Android 14 and later, or in the Health Connect app on Android 13 and earlier).
- If you revoke access, runs already imported stay in the App until you delete them (see "Android: Deleting Your Data").
- Deleting data in the App never deletes the originals in Health Connect.
Android: Other Data the App Uses on Your Device
- Saving to your gallery: finished videos are saved to
Movies/RunVue and images to Pictures/RunVue through Android's media store. The App does not read your existing photos or videos (it requests no storage-read permission; on Android 9 only, it uses the storage-write permission to save). The files it saves contain no location metadata (no GPS EXIF).
- Notifications: on Android 13 and later the App asks for notification permission. Notifications are local only — that a video is ready, or that making a video was interrupted. They never include your route or health values. There are no push notifications and no marketing messages.
- File import: GPX/FIT/zip files you choose with Android's file picker are read on your device. The temporary copy is deleted after import; the App keeps the run's route plus the file's display name and a fingerprint (SHA-256 hash) to avoid importing the same file twice.
- Network state: the App checks whether you are online or on a cellular connection, for example to warn before a large download over cellular.
Android: Advertising (Free Version)
The free Android version shows ads so that making videos at 1x and Summary speed can stay free. Ads are provided by Google AdMob (Google Mobile Ads SDK), and consent is managed with Google's User Messaging Platform (UMP).
Where and when ads appear
- A banner at the bottom of the Runs and Library tabs.
- A full-screen ad, occasionally, when you leave the final preview after saving — at most once a day, at least 6 hours apart, and only after every second save.
- An optional video ad you can choose to watch to use a Pro speed for one save — at most 3 times a day.
- No ads: during the first 24 hours after installation, before you have made your first video, for RunVue Pro subscribers, and never during onboarding, the Health Connect permission steps, Settings, the subscription screen, video generation, playback, or sharing.
What the ad SDK collects (Google's disclosure)
- Device identifiers: the Android advertising ID and the app set ID.
- IP address, which may be used to estimate your general location.
- Interactions: app launches, ad views, taps, and video views.
- Diagnostics: performance information about the App and the SDK.
This information is sent by the SDK directly to Google, encrypted in transit, and is used by Google to show and measure ads, for analytics, and to prevent fraud. We do not receive or store it. Google's use is described in How Google uses information from sites or apps that use our services and the Google Privacy Policy; Google's ad technology partners are listed at support.google.com/admob/answer/9012903.
What we never give the ad SDK
- No health, heart-rate, workout, route, or location data. Ad requests contain no keywords, content URLs, extra targeting data, or location.
- The App removes the permissions for Android's Privacy Sandbox Topics and Attribution Reporting APIs, so the ad SDK cannot use them to derive interest topics from your use of the App.
- Ad content is limited to a maximum content rating of "Teen" (T).
Consent and your choices, by region
- EEA, UK, and Switzerland: before ads are requested, Google's consent message asks whether you agree to personalized ads and related data use; it includes a "Do not consent" option. If you do not consent, you get only limited, non-personalized ads or no ads, and every feature of the App still works.
- United States: where US state privacy laws apply, a "Do not sell or share my personal information" option lets you opt out of the use of your information for targeted advertising.
- Republic of Korea and elsewhere: you can refuse personalized (behavioral) advertising at any time by deleting or resetting your advertising ID, as described below.
- In the App: Settings › About › Ad privacy lets you change your privacy choices (shown when your region requires it), open Android's ad ID settings, and open this policy.
- In Android: in Android Settings › Privacy › Ads (on some devices Settings › Google › Ads) you can reset or delete your advertising ID; after deleting it, apps receive no advertising ID. You can also manage ad personalization at adssettings.google.com.
Your consent choice is stored on your device by Google's UMP SDK. Uninstalling the App or deleting its data does not delete information Google has already received; to make requests about that information, use the options in the Google Privacy Policy.
Pro has no ads
While RunVue Pro is active, the App shows no ads and does not even start the Google Mobile Ads SDK, so no ad requests are sent from your device.
On-device ad counters
To limit how often ads appear, the App keeps on your device when ads were last shown and how many were shown that day. These counters are stored in storage that is excluded from backup and are never sent anywhere.
Android: Purchases (Google Play)
RunVue Pro on Android is an auto-renewing monthly or yearly subscription sold through Google Play Billing, with a one-month free trial for eligible users. It unlocks every playback speed from 2x to 60x, the Cinematic and Calm camera presets, camera height and zoom, and removes ads. Purchases, free trials, billing, renewals, and refunds are handled by Google under the Google Privacy Policy and Google Play's terms. We never see or store your payment information.
The App has no server for purchases: it checks your purchase on your device using Google Play's signature. So that Pro keeps working offline for up to 7 days, it keeps a small copy on your device — the plan, when the current period ends, whether it auto-renews, and a hashed (not readable) form of Google Play's purchase token. This copy is excluded from backup and is never sent to us. You can manage or cancel your subscription in Google Play › Payments & subscriptions › Subscriptions, or from the App via Settings › RunVue Pro › Manage subscription on Google Play.
Android: Backup and Moving to a New Device
- What may be backed up: if Android backup is turned on, only the App's preferences (such as units, the on-screen display language, and which notices you have already seen) may be saved to your Google account by Android's backup service, or copied when you move to a new device.
- Never backed up or transferred: the App's database (your imported runs and routes), library videos, map cache, the subscription copy, and the ad counters. After restoring or moving to a new device, the App imports your runs from Health Connect again.
Android: Diagnostics and Contact (Only If You Choose)
- Diagnostic log: Settings › Advanced › Export Diagnostic Log creates a file on your device containing the app version and build, Android version and API level, language setting, a log of events recorded only as numbers and codes (for example, processing times and error codes), and ad diagnostic counters. It contains no routes, coordinates, place names, or health values. It leaves your device only if you pick a destination in Android's share sheet, and nothing is sent automatically.
- Email: the Contact button opens your email app with a message to support@setlog.net that includes the app version and your device model, which you can edit or delete before sending.
- No crash reporting or analytics SDK: the Android app uses no Firebase, Crashlytics, or analytics SDK. If you have chosen to share usage and diagnostics data with Google on your device, Google Play may provide us with aggregated crash and performance statistics (Android vitals) from which we cannot identify you.
Android: Deleting Your Data
- Delete Health runs: Settings › Advanced › Delete Health Runs removes RunVue's copies of runs imported from Health Connect and stops them from being imported again. The originals in Health Connect and videos you made are not affected.
- Delete all data: Settings › Advanced › Delete All Data (two-step confirmation) deletes the App's database, library videos, map cache, and settings. The originals in Health Connect and videos already saved to your gallery are not affected.
- Library: you can delete single videos or clear the whole Library; copies saved to your gallery remain.
- Map cache: can be cleared at any time in Settings.
- Uninstall: removes all of the App's data from that device. Records in Health Connect stay until you delete them there.
- Permissions: manage Health Connect access in Health Connect, and notifications in Android Settings.
- Data held by Google (ads, purchases) is kept under Google's policies; use the options in the Google Privacy Policy.
What We Do Not Collect
On both platforms, RunVue does not collect, store on any server, or share any of the following:
- Name, email address, phone number, or any other personal identifier — the App has no accounts or sign-in (unless you contact us yourself)
- Your route or coordinates — not even in map download requests
- Your health data — it is never sent off your device by the App, and never given to the ad SDK
- Contacts, existing photos or videos in your library, or browsing history
- Payment information — purchases are handled entirely by Apple (iPhone) or Google Play (Android)
- Analytics, usage statistics, or crash reports sent automatically by the App's own code
Advertising identifiers: the iPhone app does not access the advertising identifier (IDFA) and does not track you. The Android app's free version uses the Android advertising ID only through Google AdMob, as described in "Android: Advertising"; Pro subscribers' devices do not start the ad SDK.
Sharing
A video you choose to save or share yourself goes wherever you send it (Photos or your gallery, messages, another app, and so on). Because a video shows your entire route from start to finish, along with street names, date and time, and heart rate, a one-time notice appears before your first save or share ("The video shows your full route, including start and finish. If you started near home, this could reveal your location."). This notice is shown only once.
Sharing and Third Parties
We do not sell or rent your data. Your health and route data are not shared with anyone, and the developer receives none of it. The services involved are:
- Both versions: Cloudflare, which hosts our static map storage (Cloudflare Privacy Policy), and Tally, which hosts our contact form if you choose to use it.
- iPhone: Apple's App Store and StoreKit for purchases, and HealthKit and the Health app for the data you choose to let the App read (Apple's Privacy Policy).
- Android: Google AdMob and User Messaging Platform (ads and consent, free version only), Google Play Billing (purchases), and Health Connect (the on-device health data store you control). Google's handling is governed by the Google Privacy Policy.
We may disclose information we hold (only messages and files you sent us) if required by law. Map data is sourced from © OpenStreetMap contributors and the Overture Maps Foundation (ODbL).
Your Rights
- Data on your device is under your control: you can delete it in the App (see the deletion sections above) and manage permissions in your device's settings, Apple Health, or Health Connect.
- Depending on where you live (for example under the GDPR, UK GDPR, US state privacy laws, or Korea's Personal Information Protection Act), you may have the right to access, correct, delete, restrict, or object to the processing of personal information, to withdraw consent, to opt out of targeted advertising or the "sale" or "sharing" of personal information, and to complain to your data protection authority.
- For data we hold (only messages and files you sent us), contact us and we will respond without undue delay. For data Google received through its SDKs on Android, use the options in the Google Privacy Policy. Ad consent and opt-out controls are described in "Android: Advertising".
- We do not discriminate against you for exercising these rights.
Children's Privacy
RunVue is not directed to children and does not knowingly collect information from children under 13. The App has no accounts and collects no personally identifiable information itself. On Android, ads are not configured as child-directed and are limited to a maximum content rating of "Teen". If you believe a child has sent us personal information, contact us and we will delete it.
Hosting Providers and International Data Transfers
Our map storage is hosted by Cloudflare, Inc. (United States; requests are served from a Cloudflare data center close to you). When the App downloads map data, Cloudflare receives your IP address and the name of the file requested. We do not store request logs; Cloudflare may keep short-lived technical counters (for example, for rate limiting) under its own policy. Your health data and routes are never sent to Cloudflare or anyone else.
On Android, information collected by Google's ad and consent SDKs (free version) and by Google Play Billing is processed by Google LLC and its affiliates, including in the United States, under Google's safeguards. If you submit the contact form, it is hosted by Tally BV (Belgium, EU) and receives what you type, including your email address if you enter one. On iPhone, purchases are processed directly by Apple.
If you do not want these transfers, you can avoid downloading maps for new areas, subscribe to Pro on Android (the ad SDK is not started), not use the contact form, or stop using the App.
Changes to This Policy
If we make material changes, we will update the dates above. Significant changes will also be noted in the App Store and Google Play release notes, and if a change adds new data processing, we will update this policy before releasing the feature.
Change history
- October 1, 2026: First published
- October 2, 2026: Corrected the Pro subscription description and the description of how subscription status is kept; added hosting and international transfer details
- October 3, 2026: Added the Android version (Health Connect, Google AdMob ads and consent for free users, Google Play Billing, Android backup and deletion); separated iPhone-only statements; added "Your Rights"
Contact
For any privacy-related questions or requests: