Version 1.1 — Last updated: 11 August 2026
This is a convenience translation. The French version is the legally binding text.
This Privacy Policy describes how Odyssey (published by Run Odyssey SAS, hereinafter "We") collects, uses and protects users' personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and French Act No. 78-17 of 6 January 1978 as amended (Data Protection Act).
1. Data controller
Identity: Run Odyssey, a simplified joint-stock company (SAS) with share capital of €1,000
Address: 9 rue des Colonnes, 75002 Paris, France
Trade register (RCS) no.: 105 654 354
EUID: FR7501.105654354
Contact email: hello@runodyssey.com
Data Protection Officer (DPO): The Privacy team, reachable at support@runodyssey.com
2. Personal data collected
We collect and process the following categories of data:
2.1. Identification and contact data
- Last name, first name
- Runtag (unique public identifier chosen by the User)
- Email address
- Profile picture and cover photo (optional)
- Phone number (optional)
- Personal bio (optional)
Source: provided directly by the User upon registration and when completing their profile.
Legal basis: performance of the contract (Article 6.1.b GDPR).
2.2. Connection and technical data
- IP address, device identifier (UDID)
- Device type, operating system version (iOS or Android), app version
- Connection history (dates, times)
- Authentication token, refresh token
- Push notification token (APNs on iOS, Firebase Cloud Messaging on Android)
- IANA time zone
- Approximate neighbourhood of last activity, obtained by reverse geocoding your last known position (at most once every 12 hours), in order to show crews and clubs near you
Source: collected automatically by the app during use.
Legal basis: legitimate interest (security of the Service, fraud prevention — Article 6.1.f GDPR).
2.3. Sports activity data
- GPS route (latitude, longitude, altitude, timestamps)
- Distance covered, duration, pace
- Cadence, positive and negative elevation gain
- Per-kilometer splits
Source: the device's GPS and motion sensors during active use of the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).
2.4. Health data (sensitive category — Article 9 GDPR)
- Heart rate during runs
- Active calories burned
- VO2 Max (estimated by the system health service)
- Weight and height (self-declared, optional)
- Date of birth, sex (self-declared, optional)
- Calibrated max HR
- Self-declared fitness level
- "Return from injury" indication (V2)
Source: your operating system's health service — Apple Health (HealthKit) on iOS, Health Connect on Android — with your explicit consent granted through the system permissions, together with self-declared profile data.
On Android, Odyssey reads exercise sessions, distance, heart rate and calories burned from Health Connect, in order to automatically import runs recorded by your watch or another app. The GPS route of an imported session is only read after an additional authorisation, requested by the system session by session.
Health Connect is a datastore that is local to your device: reading your data from it does not send it to Google. The data we import is however then sent to our servers to build your run history, under the same conditions as runs recorded directly in the app.
Legal basis: explicit consent (Article 9.2.a GDPR). You may withdraw this consent at any time:
- iOS: Settings → Health → Data Access & Devices → Odyssey
- Android: Settings → Security & privacy → Privacy → Health Connect → App permissions → Odyssey
2.5. Social data
- Crews and clubs you belong to (role, seniority)
- Posts, comments, kudos published on the crew/club feed
- Running sessions shared between members
- List of invited friends (via the referral system)
Source: created directly by your social activity in the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).
2.6. Gamification data
- Level, total XP, XP transactions
- Unlocked badges, showcased badge display
- Streak (sequence of consecutive days with a run)
- Personal records (1K, 5K, 10K, half, marathon, longest distance/duration)
- Completed quests
- Personal referral code
Source: generated by your activity in the app.
Legal basis: performance of the contract (Article 6.1.b GDPR).
2.7. Payment data (V2 — Premium subscription)
We do not store any banking data. Payments are handled entirely by the store the app was obtained from: Apple via App Store in-app purchases, or Google via Google Play billing. We only receive a transaction identifier and the subscription status.
Subscription tracking is carried out on our behalf by RevenueCat, which receives your Odyssey account identifier and the store transaction identifier, but no banking data whatsoever.
Legal basis: performance of the contract (Article 6.1.b GDPR).
2.8. Marketing data (with consent)
- Notification preferences (categories: crew, club, achievements, system, product marketing, premium marketing)
Source: your choices in Settings → Notifications.
Legal basis: consent (Article 6.1.a GDPR). You may withdraw this consent at any time via Settings.
3. Purposes of processing
Your data is used to:
| Purpose | Legal basis |
|---|---|
| Provide, maintain and improve the Odyssey Service | Performance of the contract |
| Authenticate the user and secure their account | Performance of the contract + legitimate interest |
| Calculate and display your sports statistics, levels, badges | Performance of the contract |
| Personalize the Oracle's coaching | Performance of the contract |
| Enable social features (crews, clubs, sharing) | Performance of the contract |
| Send functional notifications (crew run, challenge, etc.) | Performance of the contract |
| Send marketing communications (news, premium promos) | Consent (revocable) |
| Detect fraudulent use (faked GPS routes, multi-accounts) | Legitimate interest |
| Comply with our legal obligations (GDPR, tax law, etc.) | Legal obligation |
| Handle your right of access, rectification, erasure, portability | Legal obligation |
4. Cookies and trackers
4.1. Mobile app
No advertising SDK is integrated into the app, and none of your data is used for targeted advertising or sold to data brokers.
For local storage, the app uses:
- The system's secure storage (iOS Keychain, Android Keystore): your authentication token and refresh token.
- AsyncStorage: non-sensitive local preferences (theme, last tab, list cache).
It does however integrate two measurement tools, both hosted in the European Union:
- PostHog (product usage analytics): app usage events, associated with an account identifier, to understand which features are used and improve the Service. No data is shared with advertisers.
- Sentry (crash reporting): stack trace, app and OS version, and account identifier when an error occurs, so that we can fix it.
Legal basis: legitimate interest (improving and ensuring the reliability of the Service — Article 6.1.f GDPR).
4.2. Website
The runodyssey.com website only uses a JWT session cookie strictly necessary to authenticate logged-in users (runner hub /me, club portal). No third-party cookie (Google Analytics, Meta Pixel, etc.) is placed.
5. Retention periods
| Data category | Retention period |
|---|---|
| Active user account | As long as the account is active |
| Deleted account | Anonymised immediately, then retained in anonymised form |
| Technical data (logs, IPs) | 12 months maximum |
| Payment data | Statutory accounting period (10 years) — only Apple or Google Play transaction identifiers, not banking data |
| Authentication tokens | Renewed at each login, expire within 7 days |
| Marketing data (with consent) | Until consent is withdrawn |
| Support communications (emails, tickets) | 3 years after the last exchange |
At the end of the retention period, your data is permanently deleted or irreversibly anonymized for statistical purposes.
6. Recipients of the data
Your data is never sold to third parties. It is shared only with the following recipients, strictly within the aforementioned purposes:
6.1. Technical data processors
| Processor | Purpose | Country | Safeguards |
|---|---|---|---|
| Railway Corp. | Hosting of the API and database | United States | EU Standard Contractual Clauses (SCC), SOC 2 certification |
| Cloudinary Ltd. | Media storage (avatars, cover photos) | United States | EU SCC, ISO 27001 certification |
| Resend Inc. | Sending transactional emails (verification, support) | United States | EU SCC |
| Apple Inc. | App Store distribution, Apple Sign In, in-app purchases, push notifications (APNs) | United States | EU SCC + Data Processing Addendum |
| Google LLC | Google Sign In, Google Play distribution, Play billing, push notifications (Firebase Cloud Messaging), maps | United States | EU SCC + Data Processing Addendum |
| Meta Platforms Inc. | Facebook Login | United States | EU SCC |
| Stream.io Inc. | In-app chat (crew/club messaging) | United States | EU SCC |
| RevenueCat Inc. | Subscription management: account identifier and transaction identifier, no banking data | United States | EU SCC + Data Processing Addendum |
| Anthropic PBC | AI coach and run analyses: your training data is sent to the model to produce its answers. It is not used to train the model. | United States | EU SCC + Data Processing Addendum |
| Expo (650 Industries, Inc.) | Push notification delivery | United States | EU SCC |
| PostHog | Product usage analytics | European Union | EU hosting — no transfer outside the EU |
| Sentry (Functional Software, Inc.) | Crash reporting | European Union | EU hosting (Germany region) — no transfer outside the EU |
| Open-Meteo | Weather shown before a run. Only rounded coordinates (accuracy of about 1 km) are transmitted, with no identifier or account data. | European Union | Public API, no account, no cookie |
6.2. Other Odyssey users
Some of your data (first name, runtag, profile picture, public runs, badges, level) is visible to other users you interact with (members of your crew/club, public profile).
6.3. Authorities
Upon a legal request (police, courts, tax authorities), we may be required to disclose certain data in accordance with the applicable legal framework.
7. Transfers outside the European Union
Some of our processors are established in the United States (Railway, Cloudinary, Resend, Apple, Google, Meta, Stream, RevenueCat, Anthropic, Expo). Others are hosted within the European Union and involve no transfer: PostHog and Sentry. Transfers to the United States are governed by:
- The Standard Contractual Clauses (SCC) approved by the European Commission
- The EU-US Data Privacy Framework (DPF) for certified processors
- Additional technical measures (encryption in transit TLS 1.3, encryption at rest AES-256)
8. Data security
We implement the following technical and organizational measures to protect your data:
- TLS 1.3 encryption for all communications
- Encryption at rest of the database (AES-256)
- Password hashing via bcrypt (irreversible)
- Short-lived signed JWT tokens (15 min) + refresh token (7 days)
- Multi-channel authentication (Apple/Google/Facebook or email+password)
- Rate-limiting on critical endpoints
- Audit logs for sensitive administrative actions
- Daily database backups
- Regular security updates of dependencies
In the event of a data breach likely to create a risk to your rights and freedoms, we undertake to notify the CNIL within 72 hours and to inform you as soon as possible (Articles 33-34 GDPR).
9. Your rights (GDPR)
In accordance with Articles 15 to 22 of the GDPR, you have the following rights:
9.1. Right of access (Article 15)
You can request a copy of all the data we process about you via: Settings → Export my data
We will respond within a maximum period of 30 days (Article 12.3 GDPR).
9.2. Right of rectification (Article 16)
You can edit most of your data directly from: Settings → My profile
For non-editable data (registration email, creation date), contact us at support@runodyssey.com.
9.3. Right to erasure / "right to be forgotten" (Article 17)
You can permanently delete your account via: Settings → Delete my account
Deletion entails:
- The immediate and irreversible anonymisation of your identifying data: email, first and last name, runtag, profile picture, bio, city, country, neighbourhood, phone number, date of birth, gender, height and weight are erased. Your account becomes inaccessible and your sign-in tokens are revoked.
- Removal from your crews and clubs, which frees up your seat.
- The retention of your activity history (runs, XP) in anonymised form, with no link to your identity. If you also want this anonymised history erased, write to support@runodyssey.com: we do so on request.
9.4. Right to restriction of processing (Article 18)
You can ask us to temporarily freeze the processing of your data in certain cases (contesting accuracy, objection, etc.). Contact us at support@runodyssey.com.
9.5. Right to object (Article 21)
You can object at any time:
- To the processing of your data for direct marketing purposes (via Settings → Notifications)
- To processing based on legitimate interest (upon a reasoned request to support@runodyssey.com)
9.6. Right to portability (Article 20)
You can receive your data in a structured, commonly used and machine-readable format (JSON), via: Settings → Export my data
9.7. Right to withdraw consent (Article 7.3)
You can withdraw your consent at any time (marketing notifications, access to health data) without affecting the lawfulness of processing carried out beforehand. Withdrawal is done via the app's Settings, or via your device settings — Health on iOS, Health Connect on Android (see §2.4).
9.8. Right to define the fate of your data after your death
In accordance with Article 85 of the French Data Protection Act, you can send us your directives regarding the fate of your data after your death, by email to support@runodyssey.com.
9.9. Right to lodge a complaint
If you believe that your rights are not being respected, you can lodge a complaint with the French Data Protection Authority (CNIL):
CNIL — 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Website: https://www.cnil.fr
Phone: 01 53 73 22 22
10. Minors
The Service is reserved for persons at least 16 years old. If we discover that an account belongs to a minor under 16 without parental authorization, we will delete it without notice.
For users aged 16 to 18, use of the Service requires the consent of the holders of parental authority, who may exercise the GDPR rights on behalf of the minor at any time.
11. Changes to the Policy
We reserve the right to modify this Privacy Policy at any time. Substantial changes will be notified to you via the app at least 30 days before they take effect.
12. Contact
For any question, request or complaint regarding your personal data:
Run Odyssey — 9 rue des Colonnes, 75002 Paris, France
We undertake to respond to you within a maximum period of 30 days (extendable to 3 months in case of complexity, with a reasoned notice from us).