RecRun Privacy Policy

This is a courtesy translation. The Korean original prevails. / 이 문서는 참고용 번역본이며 한국어 원본이 우선합니다.

Effective 2026-07-08 · Last updated 2026-09-15.

2026-09-15 change. Section 1 now names guide points (spots on a course and the note you wrote) as part of the course information that is stored and shown only when you publish the course — a clarification of an existing item, not a new category.
2026-09-12 change. Contact address moved to our company domain, recrun@airony.xyz (no change in processing).
Added section b-5 (prize delivery details): an optional delivery address and note were added, and for races hosted by a
member the details are passed only to that race's host, and only after results are final (Terms, Article 6-2). Not adverse to
users — effective immediately.
2026-09-11 changes (later the same day). (a) App and device integrity attestation (section 1-b-4 expanded): race entry,
start and record submission carry an iOS App Attest / Android Play Integrity token; Android tokens are decrypted by Google's
Play Integrity API; we keep only the verdict and a per-race hash, never the token. Google (Play Integrity) and Apple (App Attest)
added to the processor table — effective from the app version that produces attestations (1.0.14 and later). (b) Corrected an
omission: Android push notifications go through Google Firebase Cloud Messaging since 2026-08-21; the table listed only Apple.
2026-09-11 changes. Added section 1-b-3, race-verification trace: for an official race
only, and only if you give a separate consent before the run, the raw route of that one run is
sent to our server encrypted, used solely to re-judge that race record, and destroyed
automatically after the appeal window. Everyday and free runs, and crew events, are unchanged —
their raw route never leaves your phone. This applies from the day the feature is switched on;
until then the app shows no such consent screen.
2026-08-09 changes. Corrected the motion & fitness section: two derived values
(steps per km, movement check) *are* sent with a finished run, and the previous wording said
nothing left the device. Added Google (Maps SDK, used on iOS as well as Android), Apple,
Toss Payments and the OSRM routing server to the processor table, added a legal-basis table,
and described the heart-rate consent.

Irony Company Inc. (주식회사 아이러니컴퍼니, "we", "the Company") operates RecRun (Korean name: 렉런, "the Service").

This policy explains what we collect, why, how long we keep it, and what you can do about it.

The short version

Your GPS trace never leaves your phone. What we receive from a run is a list of times at

which you passed each checkpoint — no coordinates, no timestamps. There are two exceptions, both

of which you choose: publishing a course uploads that route so other runners can find it, and in

an official race, if you separately consent before the run, the raw route of that run is sent

encrypted so our server can re-judge your race record (section 1-b-3). Nobody else ever sees it,

and it is destroyed automatically after the appeal window.

1. What we collect

a. Account (required to sign in)

b. Created while you use the Service

notifications. It is unrelated to location or run data and is destroyed when you delete your account.

premiere viewing, return visit) and on what date. Aggregated under an irreversible hash

combined with a random value that exists only on your device, so we cannot recover the

original account. Contains no location, run data or nickname. No third-party analytics SDK

is used; we aggregate on our own server.

b-2. Purchased-points refund (only when you request one)

Nothing is collected otherwise, and the Service works without it.

Only the amount, time, the last four digits of the account number and the bank country / SWIFT code

(bank identifiers) remain; bank name, account number, holder name and recipient address are deleted.

The refund record itself is kept for the period required by e-commerce law.

b-3. Race-verification trace (official races only, separate consent)

(5 decimal places), elapsed time relative to the start declaration (milliseconds), horizontal

accuracy, whether the device flagged a fix as a mock location, a list of GPS gaps, a three-number

motion summary, and the checkpoint times your device computed. **No absolute date/clock time and

no start address are included.**

affected; their raw route stays on your device as before.

separate screen. It is distinct from the location permission and from starting the run, and

nothing is pre-selected. If you decline, no trace is sent and the run proceeds normally, but the

server cannot independently verify that record, so it may be **excluded from the official ranking,

medals and prizes** (the finish record itself is kept).

checkpoint times from the raw route and screening out illegitimate records (mock location,

vehicles, cutting the course). We use it for nothing else: not recommendations, advertising,

statistics, course analysis or course data (the statistics in section 4-2 never use it).

key is a secret kept separately from the account database, and any operator decrypting a trace is

written to an audit log. The trace is never shown to other users in any form.

after the race results are revealed (the appeal window)**. Only a coordinate-free judgment summary

(tier, server-computed checkpoint times, reasons) remains. A record under appeal is kept until the

appeal is decided. Deleting your account deletes it immediately.

to 24 hours. The queue itself holds no coordinates; a retry is rebuilt from the track already

stored on your device (section 1-b). After 24 hours the queue is dropped and the server treats the

record as "no trace".

b-4. App and device integrity attestation (iOS Apple App Attest · Android Google Play Integrity), and a per-race hash of it

from an unmodified RecRun app on a healthy device. On iOS this is an Apple App Attest assertion, on Android a Google Play

Integrity token — both single-use, bound to a one-time nonce issued by our server and to a digest of the request body.

Android tokens are encrypted by Google, so our server asks the Google Play Integrity API to decode them; Google receives

only the token and our app's package name — no account, location or run data (Google determines device and app state through

Play services on the device when it issues the token). iOS assertions are verified by our server against Apple's public root

certificate and are not sent to Apple. We store only the verdict (pass/fail and a reason code) and the hash below —

never the token itself. A missing or failed attestation affects the record's grade (verified / provisional) exactly as

described on the Fairness page.

one-way hash scoped to that race (mixed with the race id and a company secret) and kept on the run session. The raw

identifier, device serial numbers and advertising identifiers are not stored.

accounts in one race, those records are held from ranking and awards until an organizer checks (families do share a phone, so

nothing is disqualified automatically).

b-5. Prize delivery details (winners only, and only if you enter them)

The Service works fully without them.

if you drop out of the prize ranks when results are finalized, and automatically 30 days after results become final even if the

host never marks delivery (only the fact of expiry remains).

and only after results are final** (appeal window closed); the host contacts you directly and is responsible for delivery, shipping

and taxes (Terms, Article 6-2). Before finalization the host sees only your nickname and rank. For races hosted by us, operators only.

Never shared with other users.

c. Location — governed by the separate Location-Based Service Terms (see section 8).

server and other users is the de-identified checkpoint record (splitSec).

consent in section 1-b-3, the raw route of that run is sent and stored encrypted for

re-judging and destroyed after the appeal window. It is still never shown to other users.

pre-selected; the finish screen offers two separate save buttons and nothing uploads until

you press one.

current position and the course start coordinates are handed to the maps app you chose

(Kakao Map, Naver Map, Google Maps or your device's default). Directions cannot work without

a starting point.

- We do not read your location for this unless you press the button, and we neither store the

handed-off coordinates nor send them to our server.

"World journey" screen uses your current position as the journey's starting point. That coordinate is

rounded to about 1 km and stored only on your device; it is never added to run records or sync,

never sent to our server, and never shown to other users. You can clear it any time with "Reset".

- What the receiving maps app does with them is covered by that provider's own policy.

d. Motion & fitness (optional)

Your step history stays on the device. What is sent with a finished run is **two derived

values only**: steps per kilometre and a movement check (normal / low).

- From 2026-09-11, for race records only, three more integers — a motion-window summary: how many one-minute

windows the device's accelerometer evaluated while you were moving, how many of them showed no foot-strike impacts, and

the longest run of such windows. Raw accelerometer waveforms and per-second values are consumed on the device and never

sent. On devices without a step sensor or its permission, this summary is what lets a run be recognised as running.

enter running leaderboards. It is shown to our operators and never changes ranks or medals.

e. Body data (optional)

it is never sent to our server.

(off by default). It is displayed during a run; average and maximum values are stored only with

that run on the paired phone and are never sent to our server. With consent off, the watch does not read heart rate.

1-2. Device permissions we ask for

The Korean version of this policy carries a statutory permission notice (Network Act art. 22-2); here is the same table.

Required

PermissionWhy
Location (while using the app)Measuring route, distance and pace during a run; showing your position on the map
Location (always / background)Only while a run or course recording is in progress, so measurement continues with the screen off. It stops when the run ends

Optional

PermissionWhy
NotificationsLocal notifications (finish, premiere start) and server push (premiere reminders, crew chat)
Photos (add)Saving finish/record share cards to your photo library
Photos (read, selected items only)Choosing a photo or video as a screen background; uploading sponsor logos and banners for branded races. Nothing beyond what you pick is read
Motion & Fitness (iOS) / Physical activity (Android)Cadence and stride during a run, and the bike / scooter check (steps per km, movement-window summary — section 1-d)

You can use the core features without the optional permissions, and change any of them in your device settings at any time.

2. Why we use it

PurposeData
Sign-in, account recoveryEmail, user ID, password hash
Judging runs, ranking, ghost replayCheckpoint pass times, finish time, nickname
Independent re-judging of official race records (section 1-b-3, separate consent)Encrypted race-verification trace — nothing else
Course discoveryPublished course routes
Notifications you asked forDevice token
Product improvementDe-identified counters

We do not use your data for advertising profiling, and we do not sell it.

Legal basis

WhatKorea (PIPA / Location Information Act)EEA & UK (GDPR art. 6)
Account, run records, courses, eventsPIPA art. 15(1)4 — performance of a contract6(1)(b) contract
Location (run measurement, maps)Location Information Act arts. 15, 18 — consent6(1)(a) consent
Race-verification trace (official races)Location Information Act arts. 15, 18 — separate consent given on its own screen before the run; PIPA art. 15(1)16(1)(a) consent
Steps per km, movement checkPIPA art. 15(1)1 — consent (device permission); fraud prevention6(1)(a) consent · 6(1)(f) legitimate interests
Heart rate, weightPIPA art. 23 — separate consent for sensitive data9(2)(a) explicit consent
Prize delivery details (name, phone, address, note)PIPA art. 15(1)4 — performance of a contract (prize delivery); transfer to the race host under art. 17(1)1 — consent given when you enter the details6(1)(b) contract
De-identified usage countersPIPA art. 15(1)6 — legitimate interests6(1)(f) legitimate interests
Payment recordsStatutory retention (Korean e-commerce law)6(1)(c) legal obligation

Withdrawing consent is always possible (device settings for location and motion, in-app

switches for heart rate and for sharing your runs) and never blocks the rest of the app.

3. How long we keep it

(required by Korean location-information law).

account identifiers removed.

14 days from receipt and 7 days after results are revealed, then destroyed automatically (a

coordinate-free judgment summary remains). Kept until an appeal is decided. Deleted immediately

with your account.

4. Who we share with

We do not sell or rent personal data, and we do not provide it to third parties for their own

purposes. Data is processed by the following providers strictly on our instructions:

ProviderPurposeData reaching themLocation
Fly.ioApplication hosting and storageAccount, run records (splitSec, steps/km, movement check), published courses, eventsTokyo (NRT) region; company in the United States
Google LLCMap display (Google Maps SDK, on both iOS and Android)Device and current-location data needed to draw the map, when you open a map screenUnited States
Google LLCAndroid push notification delivery (Firebase Cloud Messaging)Device token and notification content, only if you allowed notifications (since 2026-08-21)United States
Google LLCAndroid app integrity attestation (Play Integrity API) — token issuance and decodingThe encrypted token and our package name when you enter, start or submit a race (section 1-b-4); device and app state read by Play services on the device to issue itUnited States
ResendSending verification emailsEmail address, message contentUnited States
ApplePush notification delivery (APNs), app distribution, iOS app integrity attestation (App Attest)Device token, notification content; device/app identification when the device requests an attestation for a race (section 1-b-4)United States
Toss PaymentsPaid event entry fees and refunds (Korea only, when a paid event runs)Order number, amount, approval result. Card details are handled by them, never stored by usRepublic of Korea
FOSSGIS / Project OSRM"Snap to roads" while designing a course (optional, off by default)Only the waypoints you tapped on the map — not a live positionEuropean Union

International transfer: our servers are in Japan (Tokyo) and several providers process

data in the United States. Wherever you use the Service from, your data is transferred to and

processed in those locations. For EEA/UK users these transfers rely on the providers' Standard

Contractual Clauses (Fly.io, Google, Apple and Resend each publish their data-processing terms incorporating the SCCs).

Maps are separate from location permission. Opening a map screen sends device information

to Google even though your run's raw GPS trace still never leaves your phone.

Sharing that needs your consent. Apart from the processors above, we provide personal data to

a third party only after telling you who receives it, what is shared, why, and for how long — and

only if you agree. Saying no costs you nothing in the Service, and you can withdraw at any time.

4-2. Course statistics we may publish or sell

We build course-level statistics that cannot identify anyone from run records, and we may

provide them (including for a fee) to local governments, public bodies, researchers and sponsors.

We may also **use collected location data in de-identified, statistical form for course analysis

and building course data** — for example, producing the per-segment (split) information shown in

the app and analysing course quality. This internal use follows the same scope and safeguards below.

Statistics are not personal data, but here is exactly what they contain.

What goes out — numbers about a course, never about a person:

WhatExample
Relative pace per segment"everyone is ~15% slower around the 3 km mark"
Suspected waiting segments"1.5–2.0 km varies a lot between runners — likely a crossing"
Usagemonthly unique runners, weekday and time-of-day spread, seasonality

What never goes out: names, IDs, emails, nicknames, crew tags; individual records, times or

rankings; raw GPS traces and run timestamps (these never reach our servers at all); heart rate

and weight (stored only on the user's paired devices and never sent to our servers).

Safeguards enforced in code

statistics at all — with a tiny sample, "the median" *is* one person's run.

Your choice: turning off Profile › Make my runs public removes your runs from the pace and

segment statistics. Usage statistics only ever count people, never who they were. Deleting your

account erases the underlying records. Questions: recrun@airony.xyz

5. Your rights

You can, at any time:

account, server-side run records and event entries, and clears local data. You may also

email us (section 9).

features stop working but the rest of the app continues.

If you are in the EEA or the UK, you additionally have the rights to restriction, portability

and objection under the GDPR, and may lodge a complaint with your local supervisory authority.

⚖️ *Our GDPR representative arrangements are under legal review; contact us at the address in

section 9 in the meantime and we will respond.*

6. Security

Access to systems holding personal data is restricted and authenticated; data is transmitted

over TLS; access is logged. Race-verification traces (section 1-b-3) are stored encrypted with

AES-256-GCM under a key kept separately from the account database, operator decryption is audit

logged, and expiry is enforced automatically by the server rather than by manual action. We have designated a person responsible for location information

(section 9) and follow the administrative and technical safeguards required by Korean

location-information law.

7. Children

The Service is not directed to children under 14, and we do not knowingly collect their

personal data.

8. Location-based services

Location handling is described in the separate Location-Based Service Terms, which also

records our Korean regulatory filing: location-based service business registration no. 1357

(Korea Communications Office, 2026-08-04).

9. Contact

10. Remedies (Korea)

BodyPhoneWeb
Personal Information Dispute Mediation Committee1833-6972kopico.go.kr
Privacy Infringement Report Centre118privacy.kisa.or.kr
Supreme Prosecutors' Office Cybercrime1301spo.go.kr
National Police Agency Cyber Bureau182ecrm.police.go.kr

11. Changes

We announce changes in the app at least 7 days before they take effect, or 30 days before if

the change is unfavourable to you.