FREN

Version 1.1 — Last updated: 11 August 2026

This is a convenience translation. The French version is the legally binding text.

This Privacy Policy describes how Odyssey (published by Run Odyssey SAS, hereinafter "We") collects, uses and protects users' personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and French Act No. 78-17 of 6 January 1978 as amended (Data Protection Act).


1. Data controller

Identity: Run Odyssey, a simplified joint-stock company (SAS) with share capital of €1,000
Address: 9 rue des Colonnes, 75002 Paris, France
Trade register (RCS) no.: 105 654 354
EUID: FR7501.105654354
Contact email: hello@runodyssey.com
Data Protection Officer (DPO): The Privacy team, reachable at support@runodyssey.com


2. Personal data collected

We collect and process the following categories of data:

2.1. Identification and contact data

Source: provided directly by the User upon registration and when completing their profile.
Legal basis: performance of the contract (Article 6.1.b GDPR).

2.2. Connection and technical data

Source: collected automatically by the app during use.
Legal basis: legitimate interest (security of the Service, fraud prevention — Article 6.1.f GDPR).

2.3. Sports activity data

Source: the device's GPS and motion sensors during active use of the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).

2.4. Health data (sensitive category — Article 9 GDPR)

Source: your operating system's health service — Apple Health (HealthKit) on iOS, Health Connect on Android — with your explicit consent granted through the system permissions, together with self-declared profile data.

On Android, Odyssey reads exercise sessions, distance, heart rate and calories burned from Health Connect, in order to automatically import runs recorded by your watch or another app. The GPS route of an imported session is only read after an additional authorisation, requested by the system session by session.

Health Connect is a datastore that is local to your device: reading your data from it does not send it to Google. The data we import is however then sent to our servers to build your run history, under the same conditions as runs recorded directly in the app.

Legal basis: explicit consent (Article 9.2.a GDPR). You may withdraw this consent at any time:

2.5. Social data

Source: created directly by your social activity in the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).

2.6. Gamification data

Source: generated by your activity in the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).

2.7. Payment data (V2 — Premium subscription)

We do not store any banking data. Payments are handled entirely by the store the app was obtained from: Apple via App Store in-app purchases, or Google via Google Play billing. We only receive a transaction identifier and the subscription status.

Subscription tracking is carried out on our behalf by RevenueCat, which receives your Odyssey account identifier and the store transaction identifier, but no banking data whatsoever.

Legal basis: performance of the contract (Article 6.1.b GDPR).

2.8. Marketing data (with consent)

Source: your choices in Settings → Notifications.
Legal basis: consent (Article 6.1.a GDPR). You may withdraw this consent at any time via Settings.


3. Purposes of processing

Your data is used to:

PurposeLegal basis
Provide, maintain and improve the Odyssey ServicePerformance of the contract
Authenticate the user and secure their accountPerformance of the contract + legitimate interest
Calculate and display your sports statistics, levels, badgesPerformance of the contract
Personalize the Oracle's coachingPerformance of the contract
Enable social features (crews, clubs, sharing)Performance of the contract
Send functional notifications (crew run, challenge, etc.)Performance of the contract
Send marketing communications (news, premium promos)Consent (revocable)
Detect fraudulent use (faked GPS routes, multi-accounts)Legitimate interest
Comply with our legal obligations (GDPR, tax law, etc.)Legal obligation
Handle your right of access, rectification, erasure, portabilityLegal obligation

4. Cookies and trackers

4.1. Mobile app

No advertising SDK is integrated into the app, and none of your data is used for targeted advertising or sold to data brokers.

For local storage, the app uses:

It does however integrate two measurement tools, both hosted in the European Union:

Legal basis: legitimate interest (improving and ensuring the reliability of the Service — Article 6.1.f GDPR).

4.2. Website

The runodyssey.com website only uses a JWT session cookie strictly necessary to authenticate logged-in users (runner hub /me, club portal). No third-party cookie (Google Analytics, Meta Pixel, etc.) is placed.


5. Retention periods

Data categoryRetention period
Active user accountAs long as the account is active
Deleted accountAnonymised immediately, then retained in anonymised form
Technical data (logs, IPs)12 months maximum
Payment dataStatutory accounting period (10 years) — only Apple or Google Play transaction identifiers, not banking data
Authentication tokensRenewed at each login, expire within 7 days
Marketing data (with consent)Until consent is withdrawn
Support communications (emails, tickets)3 years after the last exchange

At the end of the retention period, your data is permanently deleted or irreversibly anonymized for statistical purposes.


6. Recipients of the data

Your data is never sold to third parties. It is shared only with the following recipients, strictly within the aforementioned purposes:

6.1. Technical data processors

ProcessorPurposeCountrySafeguards
Railway Corp.Hosting of the API and databaseUnited StatesEU Standard Contractual Clauses (SCC), SOC 2 certification
Cloudinary Ltd.Media storage (avatars, cover photos)United StatesEU SCC, ISO 27001 certification
Resend Inc.Sending transactional emails (verification, support)United StatesEU SCC
Apple Inc.App Store distribution, Apple Sign In, in-app purchases, push notifications (APNs)United StatesEU SCC + Data Processing Addendum
Google LLCGoogle Sign In, Google Play distribution, Play billing, push notifications (Firebase Cloud Messaging), mapsUnited StatesEU SCC + Data Processing Addendum
Meta Platforms Inc.Facebook LoginUnited StatesEU SCC
Stream.io Inc.In-app chat (crew/club messaging)United StatesEU SCC
RevenueCat Inc.Subscription management: account identifier and transaction identifier, no banking dataUnited StatesEU SCC + Data Processing Addendum
Anthropic PBCAI coach and run analyses: your training data is sent to the model to produce its answers. It is not used to train the model.United StatesEU SCC + Data Processing Addendum
Expo (650 Industries, Inc.)Push notification deliveryUnited StatesEU SCC
PostHogProduct usage analyticsEuropean UnionEU hosting — no transfer outside the EU
Sentry (Functional Software, Inc.)Crash reportingEuropean UnionEU hosting (Germany region) — no transfer outside the EU
Open-MeteoWeather shown before a run. Only rounded coordinates (accuracy of about 1 km) are transmitted, with no identifier or account data.European UnionPublic API, no account, no cookie

6.2. Other Odyssey users

Some of your data (first name, runtag, profile picture, public runs, badges, level) is visible to other users you interact with (members of your crew/club, public profile).

6.3. Authorities

Upon a legal request (police, courts, tax authorities), we may be required to disclose certain data in accordance with the applicable legal framework.


7. Transfers outside the European Union

Some of our processors are established in the United States (Railway, Cloudinary, Resend, Apple, Google, Meta, Stream, RevenueCat, Anthropic, Expo). Others are hosted within the European Union and involve no transfer: PostHog and Sentry. Transfers to the United States are governed by:


8. Data security

We implement the following technical and organizational measures to protect your data:

In the event of a data breach likely to create a risk to your rights and freedoms, we undertake to notify the CNIL within 72 hours and to inform you as soon as possible (Articles 33-34 GDPR).


9. Your rights (GDPR)

In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

9.1. Right of access (Article 15)

You can request a copy of all the data we process about you via: Settings → Export my data

We will respond within a maximum period of 30 days (Article 12.3 GDPR).

9.2. Right of rectification (Article 16)

You can edit most of your data directly from: Settings → My profile

For non-editable data (registration email, creation date), contact us at support@runodyssey.com.

9.3. Right to erasure / "right to be forgotten" (Article 17)

You can permanently delete your account via: Settings → Delete my account

Deletion entails:

9.4. Right to restriction of processing (Article 18)

You can ask us to temporarily freeze the processing of your data in certain cases (contesting accuracy, objection, etc.). Contact us at support@runodyssey.com.

9.5. Right to object (Article 21)

You can object at any time:

9.6. Right to portability (Article 20)

You can receive your data in a structured, commonly used and machine-readable format (JSON), via: Settings → Export my data

9.7. Right to withdraw consent (Article 7.3)

You can withdraw your consent at any time (marketing notifications, access to health data) without affecting the lawfulness of processing carried out beforehand. Withdrawal is done via the app's Settings, or via your device settings — Health on iOS, Health Connect on Android (see §2.4).

9.8. Right to define the fate of your data after your death

In accordance with Article 85 of the French Data Protection Act, you can send us your directives regarding the fate of your data after your death, by email to support@runodyssey.com.

9.9. Right to lodge a complaint

If you believe that your rights are not being respected, you can lodge a complaint with the French Data Protection Authority (CNIL):

CNIL — 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Website: https://www.cnil.fr
Phone: 01 53 73 22 22


10. Minors

The Service is reserved for persons at least 16 years old. If we discover that an account belongs to a minor under 16 without parental authorization, we will delete it without notice.

For users aged 16 to 18, use of the Service requires the consent of the holders of parental authority, who may exercise the GDPR rights on behalf of the minor at any time.


11. Changes to the Policy

We reserve the right to modify this Privacy Policy at any time. Substantial changes will be notified to you via the app at least 30 days before they take effect.


12. Contact

For any question, request or complaint regarding your personal data:

hello@runodyssey.com

Run Odyssey — 9 rue des Colonnes, 75002 Paris, France

We undertake to respond to you within a maximum period of 30 days (extendable to 3 months in case of complexity, with a reasoned notice from us).