Privacy Policy

Effective 25 August 2026 · Last updated 25 August 2026

The short version. Your run history lives on your iPhone, not on our servers. Rytme has no accounts, asks for no email address, shows no ads, and runs no analytics or tracking. The only things that ever leave your phone are the things a team feature needs to work — and only to the team you chose to join, only while you have sharing switched on.

This policy explains what Rytme (“Rytme”, “we”, “us”) collects, why, and what you can do about it. It covers the Rytme iPhone app, the Rytme Apple Watch app, and this website.

1. What stays on your device

Everything Rytme records about a run is written to your iPhone's local database and stays there. That includes:

We cannot see any of it. It is not uploaded, backed up to us, or shared with anyone. It is included in your device's own iCloud/iTunes backup if you have backups turned on, which is between you and Apple. Deleting the app deletes it.

2. Location

Rytme asks for location access so it can measure a run. Precise location is used:

Treadmill runs never use location at all. You can revoke location access at any time in iOS Settings; Rytme will keep working for indoor runs and lose outdoor distance tracking.

3. Teams, and what they can see

Rytme's team features — the live map, roster, and messages — are entirely optional. Rytme works as a solo running app if you never join a team.

When you create or join a team, Rytme signs your device in to Google Firebase anonymously. That gives your device a random identifier so the security rules can tell teams apart. There is no account, no password, no email address, and no profile — nothing that identifies you as a person beyond the display name you type in yourself.

Once you are an approved member of a team, the following is stored in our Firebase project and readable by that team's approved members only:

Location sharing is off by default for every team you create or join. It stays off until you switch it on for that team, and switching it off again removes your dot from that team's map. Leaving a team removes your membership record. Someone who merely knows a team's ID cannot read anything until the team's creator approves them.

Messages, blocking, and reporting

Text messages are checked against a list of prohibited words twice: on your device before the message is sent, and again on our server before it goes out to anyone's phone. A message that fails the check is not sent on, and its text is replaced in the team's message list with a note saying it was removed. Recorded voice cheers are not transcribed, so no automatic check runs over them. The rules these checks enforce are in the Terms of Use.

Reporting. Reporting a message sends its text, its sender's display name and anonymous identifier, the team it was sent in, and your own identifier as the reporter to us at support@rytme.run, where we review it. We keep reports so we can act on abuse. Nobody else on the team can read them, not even the person who runs it — in a small team the person you most need to report may well be the one in charge, and a report that named you to them would be worse than no report at all.

Blocking. Blocking someone hides every message of theirs on your device, and it also writes their anonymous identifier to a private list for that team so our server stops sending you notifications from them. That list is readable only by you and by us. Nobody else on the team can see it, and the person you blocked is not told and cannot find out. Unblocking removes them from it; leaving the team removes the list.

4. Weather

When an outdoor run ends, Rytme sends the coordinates where it finished to Apple's WeatherKit once, to fetch the conditions saved on that run and shown on your share badge. Apple does not tie that lookup to your identity. Rytme performs no weather lookup for treadmill runs. Weather data is provided by Apple Weather.

5. Apple Health

If you grant permission, Rytme will:

Health data is exchanged only between Rytme and the Health app on your device. It is never sent to us or to anyone else, and it is never used for advertising. You can grant or revoke each permission individually in the Health app, and Rytme works without any of them.

6. Notifications

If you allow notifications, Rytme uses Apple Push Notification service (via Firebase Cloud Messaging) to deliver teammates' messages and run-start announcements, and to deliver the run reminders you schedule yourself. Reminders are scheduled locally on your device. You can turn notifications off in iOS Settings at any time.

7. What we never do

8. Service providers

Rytme uses a small number of providers strictly to run the features described above. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderUsed forWhat it sees
Google Firebase (Authentication, Firestore, Cloud Messaging, Cloud Functions) Team membership, the live map, messages, push delivery Your anonymous device identifier, team display name, live location while sharing, message contents, push token
Apple (WeatherKit, APNs, HealthKit, iCloud backup) Run weather, push delivery, Health read/write, your own device backups One coordinate per finished outdoor run; push routing; Health data stays on device
Google (Gmail) Emailing abuse reports to our support inbox The contents of a report: the reported message, the team ID, and the anonymous identifiers of the person who sent it and the person who reported it
Cloudflare Hosting this website Standard web request logs for rytme.run — no app data passes through it

9. How long things are kept

10. Your choices and rights

Depending on where you live (for example the EEA, the UK, or California), you may have additional rights to access, correct, delete, or port your data, and to complain to a supervisory authority. Because Rytme holds no account and no contact details for you, we may need you to identify the specific team and display name so we can find the right records. We do not sell or share personal information as those terms are defined under California law.

11. Children

Rytme is not directed to children under 13, and we do not knowingly collect personal information from them. Teams often include family members; a parent or guardian is responsible for any child they add to a team. If you believe a child has provided information to us, contact us and we will delete it.

12. Security

Team data is protected by server-side security rules that scope every read and write to an approved member of that specific team, and all traffic to our providers is encrypted in transit. No system is perfect, but the smallest amount of data is the best protection there is — which is why nearly everything Rytme records never leaves your phone.

13. International transfers

Our providers operate globally, so the limited team data described above may be processed on servers outside your country, including in the United States, under the safeguards those providers offer.

14. Changes to this policy

If this policy changes materially, we will update the date at the top and, where the change affects how your data is used, note it in the app's What's New. Continuing to use Rytme after a change means you accept the updated policy.

15. Contact

Questions, deletion requests, or anything else: privacy@rytme.run.