RunLive

Privacy policy.

RunLive is a live app. When you go live, people see where you are while you are there. This page explains exactly what that means, what we keep, and what you control.

Last updated September 8, 2026

The short version

If you read nothing else, read this.

What we collect, and why

Nothing here is collected "just in case." Every item below is doing a job you can point at in the app.

Running the app

The live layer

The social side

Payouts and purchases

Safety, and keeping the app working

What we don't ask for at all: your address book, your camera, your calendar (beyond writing an event when you tap "Add to Calendar"), your precise location outside a run, your browsing, or anything about you from another company.

Going live: what your viewers see

This is the one part of RunLive where the privacy question is not abstract. Broadcasting shares where you physically are, while you are there. We want you to understand it before you tap the button, not after.

What actually goes out

While you are live, your phone sends your position about once a second to everyone watching, along with whichever stats you have left switched on. Your route draws itself behind you on their screens as you go. Roughly every fifteen seconds we also save a checkpoint of your latest position and stats, so someone who joins in the middle isn't staring at an empty map, and so your pin can appear on the live map.

Be clear-eyed about a public stream: it is public. Any signed-in RunLive user can find it, watch it, and see your dot move through the real world in real time. That includes the start of your run, which for most people is their front door.

Choosing your audience

Which numbers ride along

Distance, pace, heart rate, cadence, elevation, and calories each have their own switch in your broadcast settings. Turning one off means it is never sent. There is no server row holding it and no other person's app receiving it. Your dot still moves, because moving is what going live is; the number simply isn't there. The only figure that never has a switch is the clock, because a live run with no elapsed time isn't a live run.

Ending it

Ending the run ends the broadcast, immediately. Your stream closes, your pin comes off the live map, and viewers are told the run finished. You do not have to render a film first: "Finish, render later" stops the stream on the spot.

Two backstops exist for when a phone can't say goodbye. If your app stops checking in, your stream drops off the live map within a couple of minutes. And if a phone dies mid-run, our server closes any stream that has gone quiet for ten minutes, stamped with the moment the signal stopped rather than the moment we noticed.

After the run

Your route is saved with the run: on your phone and, for runs that reach your profile, as an encoded line on our servers, so the run can appear in your history and on any post you make from it. The 3D film is rendered on your phone and stays there. Films are never uploaded to us. If you want to share one, you save it to Photos and share it yourself, which means the sharing decision is yours and the file is yours.

Health and fitness data

We never use HealthKit data for advertising, marketing, or any use-based data mining, and we never sell it to anyone. There is no advertising in RunLive at all. This is an Apple requirement, and it is also simply what we do.

What RunLive reads from Health

Only with your permission, and only what a run needs:

What RunLive writes to Health

When a run finishes we save it as a workout, with its route map, in your Health app. That is the piece that makes RunLive play nicely with everything else: apps that read Health, including Strava, can pull in a run you recorded here. You can turn that off in iOS Settings, and revoke any of these permissions there at any time.

Where it lives

Health data stays on your device except for the parts you choose to send. Concretely: if you go live with heart rate switched on, your heart rate goes to your viewers; if you save or post a run, its summary numbers (distance, duration, pace, average heart rate, elevation) go with it. Nothing else from Health is uploaded. We never read your medical records, your sleep, your weight, or anything else Health can hold. We used to ask for height and weight in your profile and we removed the fields, because they were the most sensitive thing on the page and nothing in the app used them.

Runs recorded somewhere else

With your permission, RunLive can notice when a workout from another app lands in Health and offer to turn it into a film. It's an offer, once, and it's the only thing we do with it. We don't index your Health history or copy it anywhere.

The music you run to

If you pair Apple Music on the Go Live sheet, RunLive watches what your phone's Music app is playing during a run and publishes the title, artist, and Apple Music track id to your viewers, stamped with how far into the run the song started. That's how the now-playing chip appears on their screen, how the setlist builds itself as you run, and how someone watching can listen along on their own Apple Music subscription.

RunLive only reads what is playing. It never controls playback. It doesn't start, stop, skip, or change your music, and it doesn't take over your phone's audio. We also never retransmit the audio itself; what travels is the name of the song, not the song.

Your setlist is saved with the run, so the film can show what you were listening to and your run history keeps it. If you don't pair Apple Music, none of this happens. You can revoke media access in iOS Settings at any time.

Sparks, and cashing out

Sparks are RunLive's currency. Viewers buy them and send them to athletes mid-run. If you receive them, you can spend them on other athletes, or turn them into real money. That last step is the only place in RunLive where identity documents come into it, and none of them come to us.

Buying sparks

Purchases go through Apple's in-app purchase system. Apple takes the payment and tells our server that a transaction happened; we verify it and credit your balance. We never receive your card number, your billing address, or your Apple ID password. What we store is the product you bought, the transaction id, and the sparks it was worth.

Receiving sparks

Sparks sent to you during a live run accrue as earnings. Every one of them is a line in the ledger: who sent it, when, and what it was worth. That ledger is append-only: corrections are made by adding a reversing line, never by editing history, because it's the record that has to hold up if a payout is ever questioned.

Where the money goes

Nothing about the split is hidden, so here it is. A pack of sparks costs what the App Store shows. Apple keeps its commission on that price (15% under the App Store Small Business Program, 30% otherwise) and passes the rest to RunLive. Half of what a buyer paid for a spark goes to the athlete who receives it: half a cent for every paid-for spark. Bigger packs come with bonus sparks on top. Those cheer exactly like the others and count on the stream, but they don't carry a payout, so an athlete's earnings track what their supporters actually spent. What remains after Apple and the athlete is RunLive's, and it is what runs the live channels, the servers, and the film engine.

On the athlete's side, the balance shows a cash value and not just a spark count, because a spark is worth what its gift paid for. If you pass earned sparks on to another athlete, their cash value travels with them. Cash-outs start at US$25 and go out through Stripe; RunLive covers the transfer fee, so the amount shown is the amount that arrives.

Turning sparks into money

Cashing out requires a verified Stripe account. When you start, RunLive creates a Stripe Connect account for you and hands you off to Stripe's own onboarding, which opens outside the app. That visible handoff is deliberate: from that point, you are giving your information to Stripe, not to us.

Stripe collects what financial regulation requires it to collect, which typically includes:

Stripe holds all of it. RunLive stores two things: a reference to your Stripe account, and whether it is pending, verified, or restricted. We never see your bank account number, your ID document, or your date of birth. If our database were ever breached, there would be no financial identity data in it to take. By construction, not by promise.

What we send Stripe to open the account is your display name and the email address on your RunLive account. Everything else, you give to Stripe directly. Stripe's own privacy policy governs what they do with it.

Payouts, holds, and the records we keep

There is a minimum cash-out amount, a hold on fresh earnings, and one payout in flight at a time. These exist because gifts bought with a stolen card and immediately cashed out is a real pattern, and the friction is what stops it. Current amounts are shown in the app; they're set on our server so they can change without an app update.

For every payout we keep: the sparks it drew down, the amount, its status, and the Stripe transfer id. A failed transfer writes reversing ledger lines and puts the balance back. We keep payout and ledger records after a payout completes because financial records have to be keepable.

Taxes

Money you earn on RunLive may be taxable income where you live, and above certain thresholds the law requires tax reporting. Stripe handles that reporting and will collect any tax details it needs from you directly; that's part of what the verified account is for. We don't set those thresholds and we don't hold your tax forms. If you earn meaningfully here, talk to someone who does taxes for a living; we're not qualified to advise you.

Who can see what

Visibility in RunLive is enforced by the database, on every request, not by the app being polite. If you can't see something, our server won't send it, no matter what asks.

A public account

Any signed-in RunLive user can see your profile (name, handle, bib, city, bio, photo, cover) plus your posts, your run history, your follower and following counts, your events, and your live streams.

A private account

Only people who follow you can see your profile, your posts, your runs, your comments, or your streams. To everyone else your account simply isn't there. Private accounts always broadcast to followers only.

Blocking

A block cuts both ways. Neither of you can see the other's profile, posts, streams, comments, or chat, and any follow between you is deleted on the spot. Unblocking restores visibility, but it does not restore the follow. A block is not a pause. Your block list is visible only to you.

Activity status

"Show activity status" controls whether you appear in the Live tab and on the map while you're broadcasting. Switched off, you don't get advertised; the stream still works for anyone you deliberately send it to. RunLive has no passive online or last-seen status at all; broadcasting is the only presence this app has.

When you're the viewer

Watching a stream adds you to its viewer count. The broadcaster sees the number, not a roster of names. The moment you speak up, you're visible: chat messages, hearts, and gifts all appear with your name and handle, to the broadcaster and to everyone else watching, and they're saved with the stream. Broadcasters can also have comments read aloud mid-run, so the words you type may be heard in their headphones as well as seen on their screen.

WhatPublic accountPrivate account
Profile & bibAnyone signed inFollowers only
Posts & photosAnyone signed inFollowers only
Run historyAnyone signed inFollowers only
Live streamYour choice: anyone, or followersAlways followers only
Live positionWhoever can watch the streamFollowers only
Direct messagesThe people in the threadThe people in the thread
Saved posts & blocksOnly youOnly you
Wallet, ledger, payoutsOnly youOnly you
3D filmsYour phone, until you share oneYour phone, until you share one

Photos, voice notes, and messages

Photos and audio you add are compressed on your phone and uploaded to storage at Cloudflare R2. Your phone never holds storage keys; it asks our server for a short-lived, single-purpose upload link each time.

Public by URL

Profile photos, cover photos, and post photos live in a public bucket. Anyone with the file's link can open it, without signing in to RunLive. That's how a profile photo can load quickly for everyone who sees it. The link is a long random string that we only hand to people who can already see the post or profile. Treat it the way you'd treat any public web address, and don't post a photo here you wouldn't want reachable by link.

Private

Photos and voice notes sent in direct messages go to a separate private bucket. They cannot be opened by URL. Reading one requires a temporary signed link, minted for a signed-in member of that conversation and valid for a few minutes. Voice notes are the one thing here on a short clock: that bucket is set up to sweep them after about thirty days.

Talking to your viewers mid-run

Hold the mic on your watch and speak, and the clip travels to your phone, where your phone turns it into text and posts the text into your live chat. On devices that support on-device speech recognition, the words never leave your phone; on devices that don't, Apple's speech service does the transcription under Apple's privacy terms. The transcript is what your viewers read.

Messages

Direct messages are stored on our servers so they're there when you open the app. Only the members of a thread can read them, and threads carry read receipts and typing, so the person you're writing to can tell when you've seen their message. They are not end-to-end encrypted: they're encrypted in transit and at rest, but our infrastructure can technically access them, which is what makes moderation of a reported message possible. Don't use RunLive messages for anything you'd want mathematically private.

You can also share a run or a map location in a message. A shared location is a point you chose, sent once, to that thread.

Who we share data with

RunLive is a small operation and the list is short. These are service providers, not partners buying access; each one holds data because it is doing a specific job for you.

We may also disclose information if the law genuinely requires it, or if it is necessary to protect someone's safety. If RunLive is ever acquired, your data would move with the service, and you would be told before anything about this policy changed.

We do not sell your personal data, and we do not share it for advertising or cross-context behavioural advertising. There is no ad network, no analytics SDK, no attribution tracker, and no data broker anywhere in this app. The only third-party code RunLive ships is the Supabase client library.

How we protect it

The short version: the server enforces the rules, not the app.

No honest company claims to be breach-proof, and neither do we. If something ever happens that affects your data, you will hear it from us first, plainly and quickly.

Things we don't do

Your controls, in one place

In RunLive

In iOS Settings

Depending on where you live, you may also have the right to request a copy of your data, correct it, have it deleted, or object to how it's used. Write to us at cameron@runlive.live and we'll act on it.

How long we keep it, and how to delete it

While your account is open

Your profile, runs, posts, and messages stay until you delete them or delete your account. This is a training log and a history, and quietly expiring it would defeat the point. A few things clear on their own: voice notes in messages are swept after about thirty days, a finished stream stops appearing live within minutes, and old positions are never accumulated in the first place, because your live position is broadcast rather than written down.

Deleting individual things

You can delete your own posts, comments, and messages in the app. Deleting a post takes its likes and comments with it.

Deleting your account

Edit Profile → Delete Account. It is immediate and it is not reversible. Deleting your account deletes:

Two things do not vanish, and you should know both.

Other people's copies. A comment you left on someone's post, a message you sent to someone's inbox, a film someone saved to their own Photos: those are on their side. We can't reach into another person's phone, and deleting your account doesn't rewrite their history.

Financial records. Purchase, ledger, and payout records are kept where the law requires records of money to be kept, and Stripe keeps its own records under its own obligations. Everything else about you goes.

Backups roll off on their own schedule, so a copy of a deleted row can exist in a backup for a short period after deletion. Backups aren't used to bring anything back.

Age

You must be at least 13 years old to use RunLive. The app is not designed for children, and we don't knowingly collect anything from anyone under 13. If we learn that we have, we delete the account and its data.

Cashing out earnings has a higher bar. Payouts run through Stripe, and Stripe's own rules require an adult account holder who can be identity-verified. If you're under 18, you can use RunLive and receive sparks, but you won't be able to convert them to money.

If you're a parent or guardian and you believe your child has an account here, email cameron@runlive.live and we'll take care of it.

Changes to this policy

RunLive is being built quickly, and this page will change as it does. When something material changes: what we collect, who we share it with, or what a control does. We'll update the date at the top and tell you in the app before it takes effect. Small clarifications get a new date and nothing more.

Contact

Questions about anything on this page, a request about your data, or something here that doesn't match what you're seeing in the app:

cameron@runlive.live

If you think you've found a privacy or security problem in RunLive, please write to the same address and say so in the subject line. We'd much rather hear it from you first.