Privacy Policy — Løbeapp.dk
Last updated: 2026-06-14 · Version 1.0
1. Who are we?
Løbeapp.dk is a Danish running-training app for planning, logging, and analysing your training. The service is operated by:
Anders [Last name] CVR: [CVR number] Contact: privacy@løbeapp.dk
We are the data controller for the personal data we process about you.
2. What data do we process?
2.1 Account data (you provide it)
| Data | Purpose |
|---|---|
| Email address | Sign-up, login, notifications, and communication |
| Password | Stored encrypted in our identity system (Keycloak) only — we never see it |
| Age and weight | Used to calculate training intensity and AI-generated programmes |
| Language preference | Shows the app in your preferred language |
2.2 Training data (you create it)
- Running programmes and planned sessions (Forecast)
- Logged runs (Actual): date, time, distance, pace, segments
- Shoe data: shoe ID, accumulated kilometres, surface
- Goals and milestones
2.3 Technical data (collected automatically)
- IP address (used for rate-limiting and troubleshooting; not stored permanently)
- Timestamps for login and API calls
- Error and warning events from the app
We never log passwords, tokens, email addresses, weight, or age in system logs. See section 6 for details on logging.
2.4 Data when using Co-driver AI
When you use our AI-assisted programme generation (Co-driver), your answers from the interview — including training goals, level, available time, and any physical limitations — are sent to OpenAI's API for processing. See section 5 for details on this transfer.
3. Why do we process your data?
| Purpose | Legal basis | Data |
|---|---|---|
| Create and manage your account | Performance of contract (art. 6(1)(b)) | Email, password, age, weight |
| Provide app functionality (programmes, run logging, shoe tracker) | Performance of contract (art. 6(1)(b)) | All training data |
| Send service notifications (programme expiry, shoe wear, inactivity) | Legitimate interest (art. 6(1)(f)) | Email, training data |
| Generate AI training programmes via Co-driver | Performance of contract (art. 6(1)(b)) + your explicit choice to use the feature | Training goals, level, preferences |
| Product analytics and troubleshooting (PostHog, server logs) | Consent for analytics cookies (art. 6(1)(a)); legitimate interest for technical logs (art. 6(1)(f)) | Internal account ID, event data |
| Improve the product using anonymised running data | Legitimate interest (art. 6(1)(f)) | Fully anonymised aggregates — no link to you |
| Comply with legal obligations | Legal obligation (art. 6(1)(c)) | As required |
About our legitimate interests
When we process your data on the basis of legitimate interest, we have weighed this against your right to privacy. You can object to this processing at any time by contacting us at privacy@løbeapp.dk.
4. Storage and deletion
4.1 Active accounts
We store your data for as long as your account is active.
4.2 When you delete your account
Account deletion is a soft delete: your account is marked as deleted, and all personally identifiable information is removed within 30 days of your deletion request. The deadline runs from the date you request deletion.
During those 30 days, your account is deactivated and cannot be used.
4.3 Database backups
Our backup rotation is 30 days. This means personal data may remain in encrypted backups for up to 30 days beyond the deletion deadline above. Backups are used solely for system recovery and are not reviewed manually.
4.4 Anonymised running data
Aggregated and fully anonymised running statistics (e.g. average weekly distance per training level) may be stored indefinitely for product improvement. Anonymisation removes all information about:
- Who ran (no account ID or internal identifier)
- When the run took place (no dates or timestamps)
- Where the run took place (no GPS, routes, or geography)
It is not possible to reconstruct the individual user from this data.
4.5 Overview of retention periods
| Data | Retention period |
|---|---|
| Account data and training data | Until deletion, then max 30 days |
| Database backups | 30 days rolling |
| System logs (technical) | 30 days rolling |
| Analytics data (PostHog) | 1 year (PostHog's standard retention, EU infrastructure) |
| Anonymised product statistics | Indefinite |
5. Who do we share your data with?
We do not sell your personal data. We share only with the processors below for specific purposes, and all have signed a data processing agreement with us.
5.1 Processors within the EU/EEA
| Processor | Purpose | Data | Country |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of app, database, and infrastructure | All data (on server) | Germany 🇩🇪 |
| PostHog Inc. (EU) | Product analytics | Internal account ID, event data | EU infrastructure (Frankfurt) |
| Doppler (MetaBrainz) | Secure storage and distribution of system secrets | Configuration data, no user data | EU infrastructure |
5.2 Transfer to third countries — OpenAI (USA)
When you use the Co-driver AI feature, your interview answers are sent to OpenAI's API (OpenAI, LLC, USA) for processing by the language model.
What is sent:
- Your answers in the interview flow (training goals, level, weeks, preferences)
- Any physical limitations you disclose
- The conversation history in the current session
What is not sent:
- Your email address, your name, or other account data
- Your precise age or weight (only the abstracted level you specify)
Legal basis for the transfer: The transfer is made on the basis of EU Standard Contractual Clauses (SCC), which OpenAI has accepted in their API data processing agreement. OpenAI's API terms include an opt-out from using API data for model training, and we use it.
Your options: The Co-driver feature is optional. You can create and edit training programmes manually without using the AI feature.
5.3 Agent access via MCP (third-party agents)
If you choose to enable agent access (MCP tokens under "Agent access" in your profile), you grant third-party agents — e.g. Claude Code or your own automations — access to act on your behalf via our API.
You are responsible for:
- The actions the agent performs in your name
- Safe storage of your tokens
- Reporting compromised tokens to us (they are revoked immediately)
We have no control over and are not liable for actions carried out by third-party software that you have granted access.
6. Logging and security
6.1 Technical logs
Our backend generates structured logs for troubleshooting and security. We never log:
- Passwords in any form
- Access tokens or refresh tokens
- Email addresses
- Age or weight
- The content of AI prompts (only token usage for quota tracking)
- Plaintext values of agent tokens
6.2 Product analytics
With your consent, we use PostHog (EU) to measure usage of app features. Identification is done solely via an internal account ID — never email, name, or other personal data. Five key events are also measured server-side without cookies and without storing data on your device.
See our cookie policy for the full overview of what is stored.
6.3 Security measures
- All communication is encrypted with TLS (HTTPS)
- Passwords are handled solely by Keycloak with industry-standard hashing
- Refresh tokens are stored in httpOnly, Secure cookies — inaccessible to JavaScript
- Access tokens are kept in memory only and never written to cookies or browser storage
- Rate-limiting and IP-based protection against brute force
- All data is stored on servers in the EU
7. Your rights
You have the following rights under the GDPR. Request them via privacy@løbeapp.dk:
| Right | What it means |
|---|---|
| Access (art. 15) | Get confirmation of what data we process about you |
| Rectification (art. 16) | Correct inaccurate data — you can fix most of it yourself in your profile |
| Erasure (art. 17) | Request deletion of your account and data (see section 4.2) |
| Restriction (art. 18) | Ask us to restrict processing in specific situations |
| Data portability (art. 20) | Receive your data in a structured, machine-readable format |
| Objection (art. 21) | Object to processing based on legitimate interest |
| Withdrawal of consent | Withdraw your consent to analytics at any time — see the cookie policy |
We respond to requests within 30 days. Complex requests may take up to 90 days; if so, we will let you know.
Complaint to the supervisory authority
You have the right to lodge a complaint with Datatilsynet (the Danish Data Protection Agency): datatilsynet.dk · dt@datatilsynet.dk · Tel. +45 33 19 32 00
8. Children
Løbeapp.dk is not directed at children under 15. If you are under 15, creating an account requires consent from a parent or guardian.
If we become aware that we have unintentionally collected data about a child under 15 without parental consent, we will delete that data as quickly as possible.
9. Changes to this policy
Material changes are announced at least 14 days in advance via email or in-app message. The date and version number at the top of the page are updated with every change.
10. Contact
Questions about your data or this policy:
privacy@løbeapp.dk
Response within 2 business days for general enquiries; within 30 days for formal GDPR requests.