Effective Date: January 21, 2026
Last Updated: September 03, 2026
Runvia (“the App”) is an AI-powered running assistant that provides training insights, performance analysis, and workout recording. By accessing or using Runvia, you agree to this Privacy Policy and Terms of Service.
For the purposes of Regulation (EU) 2016/679 (GDPR), the Data Controller is:
Runvia
Email: fabio.barbieri@runvia.it
The Data Controller determines the purposes and means of processing personal data described in this document.
Runvia follows a Privacy-by-Design approach. We process only the minimum data necessary to:
Provide AI-powered training insights.
Maintain secure authentication and cloud synchronization.
Record in-app GPS workouts during active sessions (including background processing).
Improve app performance and stability.
Runvia collects location data to enable fitness tracking, route mapping, and real-time pace analysis even when the app is closed or not in use, but strictly only when a workout recording session is actively running.
Foreground Service: The App uses a foreground service with a persistent notification to ensure the user is always aware that location tracking is active.
Purpose: This data is used solely to generate your workout map and activity metrics. It is not used for advertising or shared with third-party brokers.
User Control: Tracking starts only upon your explicit "Start" command and ceases immediately when you "Stop" or "Save" the session.
During an active in-app GPS workout, Runvia may use on-device sensors:
Android: the ACTIVITY_RECOGNITION permission for step count / cadence when a hardware pedometer is available.
iOS: Motion & Fitness (Core Motion) for the same purpose, including cadence estimates when GPS is poor.
Barometer (if present) for elevation; accelerometer for map heading.
This data is processed on the device to improve workout metrics. It is not used for advertising. Summaries may be stored with the activity and synced to your cloud backup if you are logged in.
Optional Bluetooth sensors (heart rate, cadence, power) are used only if you connect them in the app. That is a separate permission from ACTIVITY_RECOGNITION. Health Connect / Apple Health import is described in Section 6.7, not here.
You can request full account and data deletion at any time by emailing fabio.barbieri@runvia.it. Data stored in Supabase, Strava, Garmin Connect, and Suunto tokens will be purged within 30 days. Apple Health / Health Connect data imported into Runvia will also be deleted from our storage; you can revoke Health access at any time in the iOS Health app or Android Health Connect settings.
6. Data Integration & Storage
6.1 Strava API Integration:
With your OAuth authorization, Runvia may access your Strava athlete profile (including Athlete ID) and activity data: activity list and details, GPS/maps, distance, duration, pace, elevation, heart rate, cadence, and related streams. Runvia may also update an activity description on Strava when you choose a coaching/share action that writes back (activity:write).
This data is used for coaching insights, progress tracking, and displaying activities in the app. Use, AI processing (Google Gemini), sharing, storage, disconnection, and deletion follow the same rules as Sections 6.2, 6.3, 6.5, and 5. Strava tokens are stored only to sync on your behalf and are revoked when you disconnect in app settings.
6.2 Supabase – Cloud Backup:
Runvia uses Supabase for authentication and automatic cloud backup. Access is restricted via Row Level Security (RLS); only you can access your data.
6.3 Google Gemini AI:
Selected metrics are transmitted to Google Gemini API via encrypted HTTPS for generating insights. Data is not used to train public models.
6.4 Analytics:
Firebase Analytics collects limited technical usage data to monitor app stability.
6.5 Garmin Connect Integration:
With your OAuth authorization, Runvia accesses the following data from your Garmin Connect account:
Activity data: running activities, GPS coordinates, distance, duration, pace, cadence, and elevation.
Health metrics: resting heart rate, heart rate variability, stress levels, Body Battery energy monitoring, sleep duration and quality, and SpO2.
Bidirectional workout sync: Runvia can push structured workouts and training plans to your Garmin device, and receive completed activity data from Garmin Connect.
How we use Garmin data:
To provide AI-powered coaching insights, performance analysis, training load monitoring, and recovery readiness assessments.
To display your activity history, workout metrics, and health trends within the app.
Third-party AI processing: Garmin device-sourced data is transmitted to Google Gemini API (see Section 6.3) via encrypted HTTPS to generate personalized coaching insights and training recommendations. This data is not used to train public AI models.
Data sharing: Garmin data is not sold, rented, or shared with any third party other than Google Gemini API as described above. No advertising networks or data brokers receive your Garmin data.
Data storage: Garmin data is stored locally on your device (SQLite database) and backed up to your secure Supabase cloud account (see Section 6.2). Access is restricted via Row Level Security (RLS); only you can access your data.
Disconnection and deletion: You can disconnect your Garmin Connect account at any time from the app settings. Upon disconnection, Garmin OAuth tokens are immediately revoked. You can request full data deletion by emailing fabio.barbieri@runvia.it; all Garmin-related data will be purged within 30 days.
6.6 Suunto Integration:
With your OAuth authorization, Runvia may access activity data from your Suunto account (supported workouts, GPS, distance, duration, pace, cadence, heart rate, elevation, and FIT files) and may push structured workouts (SuuntoPlus guides) to your device.
Use, AI processing (Google Gemini), sharing, storage, disconnection, and deletion follow the same rules as Sections 6.2, 6.3, 6.5, and 5. Suunto tokens are stored only to sync on your behalf and are revoked when you disconnect in app settings.
6.7 Apple Health, Health Connect, and Apple Watch:
There is no Apple or Google health “account login.” Access is only via system permission dialogs (HealthKit on iOS; Health Connect on Android). You may deny or revoke them at any time.
With your authorization, Runvia may read eligible workouts (running, treadmill, walking, hiking, and similar), associated GPS routes, heart-rate samples, and on Android also distance, steps, and active energy if granted. Runvia does not request menstrual, clinical, or unrelated Health categories.
Imported workouts appear in your activity history and may be used for coaching. If calendar sync is on, WorkoutKit may schedule planned sessions on a paired Apple Watch; that is not a Health archive upload. A watch used as a live remote during an in-app GPS session (pause/resume) is not HealthKit import.
Health and fitness data from Apple Health or Health Connect is not used for advertising or marketing, not sold, and not shared with data brokers. AI, storage, and deletion otherwise follow Sections 6.3, 6.2, and 5. Revoke access in iOS Health (Data Access & Devices → Runvia) or Health Connect permissions, or turn off import in Runvia settings.
Runvia is not a medical provider. The App provides informational AI-generated suggestions only. Always consult a healthcare professional before starting a new exercise program.
Running involves inherent physical risks. You voluntarily assume full responsibility for injuries. To the maximum extent permitted by law, the independent developer shall not be liable for personal injury, loss of data, or interruptions in third-party API services (Strava, Garmin Connect, Suunto, Apple Health / Health Connect, WorkoutKit, Google, Supabase, Firebase).
1. Titolare: Runvia – Sviluppatore indipendente (fabio.barbieri@runvia.it).
2. Posizione in Background: Runvia raccoglie i dati sulla posizione per consentire il monitoraggio dell'attività e la mappatura dei percorsi anche quando l'app è chiusa o non in uso, ma esclusivamente durante una sessione di allenamento attiva avviata dall'utente.
3. Dati Trattati:
Backup cloud (Supabase): backup automatico per la persistenza dei dati.
Strava: previa autorizzazione OAuth, profilo atleta, attività (GPS, ritmo, cadenza, FC) e, se richiesto, aggiornamento della descrizione dell’attività su Strava. Dettaglio: sezione 6.1.
Garmin Connect: previa autorizzazione OAuth, attività (GPS, ritmo, cadenza, dislivello), metriche di salute autorizzate (es. frequenza a riposo, HRV, stress, Body Battery, sonno, SpO2) e sincronizzazione bidirezionale degli allenamenti. Dettaglio: sezione 6.5 (versione inglese).
Suunto: previa autorizzazione OAuth, attività (GPS, ritmo, cadenza, FC, FIT) e invio di allenamenti strutturati (guide SuuntoPlus). Dettaglio: sezione 6.6.
Apple Health / Health Connect: previa autorizzazione di sistema, import di allenamenti compatibili, tracciati e frequenza cardiaca. Apple Watch: pianificazione allenamenti con WorkoutKit. I dati Health non sono usati per pubblicità. Dettaglio: sezione 6.7.
Sensori: in una sessione GPS, ACTIVITY_RECOGNITION (Android) e Motion (iOS) per passi/cadenza; barometro per il dislivello. Fasce BLE solo se collegate. Health: sezione 6.7.
AI (Google Gemini): elaborazione di metriche selezionate per consigli personalizzati; i dati non addestrano modelli pubblici.
4. Responsabilità: Runvia non fornisce consulenza medica. L'utente si assume ogni rischio. Lo sviluppatore non risponde di infortuni o malfunzionamenti di servizi terzi (Strava, Garmin Connect, Suunto, Apple Health / Health Connect, WorkoutKit, Google, Supabase, Firebase).
5. Diritti: cancellazione dell’account scrivendo a fabio.barbieri@runvia.it. Si può revocare Health in Impostazioni iOS / Health Connect; si possono disconnettere Strava, Garmin e Suunto dalle impostazioni dell’app.