Privacy Policy

This is an English translation of the Korean Privacy Policy. If the two versions differ, the Korean version prevails.

The Rungle team (the “Team”) publishes this Privacy Policy to explain how we protect your personal information and handle related requests promptly and smoothly, in accordance with applicable privacy laws, including Korea’s Personal Information Protection Act.

Rungle is an iOS app that imports your running records, picks the best shots from your photos and videos, and helps you create and share record overlays and reels. This policy applies to the version currently available. You can sign up with a social login, or use the app without signing in (as a guest). Running records are stored on the Team’s server (in Korea) for backup and restore, and your photos and videos never leave your device. GPS routes are not stored on the server. There is one exception: when you choose to use a reel template in which artificial intelligence (AI) reads a video frame or creates a freeze-frame image (an “AI template”), the single video frame you select is sent through the Team’s server to overseas AI providers (Google and OpenAI), and the server deletes that frame as soon as it returns the result (Article 5). The freeze frame the AI creates is kept on the Team’s server (in Korea) for 90 days after your last edit so you can keep editing it and restore it on another device (Article 3). Gender and age group are optional and you do not have to answer (Article 1). App usage records for service improvement are sent to an external analytics tool, and install and launch records for ad performance measurement are sent to an external measurement tool (Article 5). The advertising identifier (IDFA) is used only if you allow app tracking (Article 10).

Key Points (Summary)

Article 1 (Personal Information We Process and How We Collect It)

You sign up for the service with a social login; the Team does not create or receive its own IDs or passwords. We process the following information to provide the service. Photos and videos are processed only on your device (the only exception is the single frame sent when you use an AI template, and the freeze frame the AI creates from it, which the Team keeps on its server for 90 days after your last edit so you can keep editing it), and running record measurements are stored on the server for backup.

ItemDetailsHow it is collected
Account informationLogin provider (Google, Apple, Kakao, or Naver), the user identifier issued by the provider, and email. If you use Apple’s ‘Hide My Email’, the relay address Apple creates is collected. We do not receive your name or profile photoReceived from the provider when you sign in with a social login
Profile information (optional)Gender (female or male) and age group. Both are optional, and every feature works the same if you do not answer. You enter a birth year, but the server stores only a 10-year age group (for example, 20s) and does not keep the birth year itself. We do not collect your name, birthday (month and day), or phone numberEntered by you in a form shown once after signing in (you can skip it) and on the My Info screen. For Naver login, received from Naver only if you opt in on Naver’s consent screen
NicknameA display name the service creates by combining an adjective and an animal name. You can change it in the appGenerated by the service, not collected
Device informationAnonymous device identifier, device model, OS version, app version, last access timeGenerated automatically when the app registers the device with the Team’s server
Running recordsRunning workout data such as distance, duration, pace, calories, heart rate, cadence, and GPS route (including the running location name). Of these, the measurements (distance, duration, pace, calories, heart rate, cadence, and splits) are stored on the Team’s server for backup and restore. GPS routes are not sent to the Team’s server, and the server rejects them even if it receives one. However, to display the running location name, one starting coordinate of the route is sent to Apple’s reverse geocoding server (a service that converts coordinates into place names) (Articles 5 and 11).Read from Apple HealthKit if you allow it. The place name is generated by converting the route’s first coordinate with Apple reverse geocoding
Photos and videosPhotos and videos taken during your run (candidates for best-shot recommendation and editing). Processed only on your device; only when you use an AI template, the single frame you select from a video (a still image reduced to 512 pixels wide, which may show a face) is sent through the Team’s server to the AI providers in Article 5. The server also receives which template you chose, but only the frame goes to the AI providers. The whole video and other frames are never sent. The freeze frame the AI creates from that frame is kept on the Team’s server for 90 days after your last edit (Article 3).Read from your photo library if you allow it. The frame is created only when you choose a video and a freeze point yourself in an AI template
Record screen capturesScreenshots of other running apps’ record screens, and the distance, duration, and pace extracted from them by text recognition (OCR)Screenshots you select yourself, analyzed on your device
Usage records (collected automatically)The anonymous device identifier issued by the app (a random value created when the app first launches, not a hardware number read from the device), the account identifier issued by the server when you are signed in (a random value, not your email or name, used to keep you as one user when you change devices), feature usage events, error logs, user experience survey responses (5-point scale), values derived from running records (distance bucket, whether a route exists, and so on; raw figures such as distance and heart rate are excluded)Generated automatically while you use the service and sent to analytics tools (Article 5)
Ad attribution information (collected automatically)Advertising identifier (IDFA, only if you allow app tracking, Article 10), identifier for vendors (IDFV), OS version, device type, language, time zone, IP address, screen size, app install and launch events, share-completed events (name of the channel shared to), the anonymous device identifier above (an alias that links the measurement tool’s records with the analytics tool’s), and attribution details (names of the ad channel, campaign, ad group, and creative)Generated automatically when you install and launch the app and sent to the ad performance measurement tool (Article 5). Attribution details are also recorded in the analytics tool when the measurement tool reports them

All permissions, including HealthKit, Photos, and Notifications, are optional. Declining them does not block you from using the service; you can keep using the features that remain available. For example, you can create content from record screen captures without connecting HealthKit. Each permission is requested with an explanation when the feature first needs it.

Signing in is also optional. You can use the service without signing in (as a guest). In that case we do not collect account information, and your records are linked only to the anonymous device identifier. Records backed up to the server while you are a guest are merged into your account when you sign in later. Once you sign in, your subsequent usage records also carry the account identifier, and usage records collected on the same device before you signed in are linked to that account as well. After you sign out, later records no longer carry it.Gender and age group are also optional. If you skip the form, we do not ask again, and you can change your answers at any time on the My Info screen.

Article 2 (Purposes of Processing)

  • Importing running records and automatically collecting photos and videos taken during your run
  • Best-shot recommendation (evaluating photo and video quality, faces, and composition on your device). Faces are only detected and evaluated, and are never generated, altered, or retouched except in the freeze-frame creation of AI templates below.
  • Creating and editing record overlays, reels, and frame content
  • Pose reading and freeze-frame creation in AI templates. From the single video frame you select, the AI reads the hand position and where the record text can be placed, and, depending on the template, creates a new freeze-frame image with an effect added based on that frame. When a freeze frame is created, the face and body of the person in the frame may be redrawn by the AI. The created freeze frame passes through Google once more so the AI can read where the record text can be placed and check the composition, and is then stored on your device and on the Team’s server (Article 3); we never process it to identify who someone is (no matching of the same person, no extraction of facial features)
  • Creating an account and keeping you signed in; backing up and restoring records when you switch devices or reinstall the app
  • Keeping the freeze frame the AI creates on the server so you can keep editing it and restore it on another device
  • Running statistics and personalized recommendations by gender and age group (only for users who answered the optional questions)
  • Delivering announcements and notifications (in-app inbox)
  • Analyzing usage records to improve service quality and recommendation features
  • Ad performance measurement (finding out which ad led to an install). The advertising identifier is used only if you allow app tracking, and photos, location, and health records are never used for ad performance measurement.

Article 3 (Processing and Retention Period)

Photos and videos are stored only on your device; the Team does not keep them on the server. The one exception is the freeze frame an AI template creates, which is kept as described below. Account information, device information, and running record backups are stored on the Team’s server (in Korea). When you delete the app, the information the app stored on your device is deleted with it, with one exception: the anonymous device identifier described below. Information on the server remains after you delete the app, so request account deletion to remove it (Article 7).

  • Account information, server backups, and notifications are permanently deleted after a 30-day grace period once you request account deletion. The grace period lets you recover an account deleted by mistake; signing in again during that time cancels the deletion.
  • Gender and age group are kept with your account information and deleted together when the account is deleted. You can change them on the My Info screen; to erase your answers entirely, contact the Team ([email protected]).
  • Records backed up to the server as a guest are linked only to the anonymous device identifier, not to an account. To delete these records without an account, contact the Team ([email protected]).
  • Best-shot candidates use only references to your photo library; only the photos and clips you finally select are stored in the app.
  • The video frame sent to the server when you use an AI template is deleted from the server as soon as the AI provider’s result is returned to the app, and is not kept in any cache, log, or storage. Server records keep only the job number, the requesting account, the request time, file size, and processing status; the contents of the frame and the result are not kept. The freeze frame created by the AI is kept on the Team’s server (in Korea, encrypted storage) for 90 days after your last edit (or after it was created, if you never edit it) so you can keep editing it and restore it on another device, and is then deleted automatically. If you request account deletion, it is deleted together with your account information after the 30-day grace period. AI templates can be used only with a signed-in account, so no freeze frame is created on the server while you are a guest. To delete a freeze frame from the server before the 90 days are up, contact the Team ([email protected]). The freeze frame is also stored on your device and is deleted there together with the draft that uses it.
  • Usage records (event logs), error logs, and ad attribution information are stored on the servers of the providers listed in Article 5 and deleted once the purposes of service quality improvement and ad performance measurement are fulfilled. After you delete the app, no new records are collected.
  • The anonymous device identifier stays on your device even after you delete the app.It is kept in the iOS Keychain (the storage for an app’s secret values), so reinstalling the app on the same device reuses the same value. It is stored so that it is not copied off the device, so it does not carry over in device backups or when you move to a new device. The current version has no in-app way to erase this value; contact the Team ([email protected]) and we will delete the records tied to it at our service providers.

Article 4 (Provision to Third Parties)

The Team does not provide your personal information to third parties in principle. Exceptions are when you have given prior consent or when required by law, and the following provision may occur for ad performance measurement.

RecipientInformation providedRecipient’s purposeRetention
Meta Platforms, Inc.
facebook.com/privacy/policy
App install events, share-completed events (name of the channel shared to), advertising identifier (IDFA, only if you allow app tracking)Counting installs driven by Meta ads and optimizing ad deliveryPer Meta’s privacy policy

This provision happens while the Team runs ads on Meta, with the ad performance measurement tool in Article 5 (Airbridge) forwarding events from its server to Meta. The app sends nothing to Meta directly. This forwarding is currently turned off, and we will update the effective date of this policy when it is turned on. You can block the provision of the advertising identifier at any time by turning off app tracking in iOS Settings > Privacy & Security > Tracking (Article 7).

Article 5 (Outsourcing and International Transfers)

The Team outsources server operations to the provider below. The server is located in Korea, so this information is not transferred abroad.

ProviderOutsourced workLocation and retention
Amazon Web Services, Inc.
aws.amazon.com/privacy
Server operations: storing account information, device information, running record backups, notifications, and the freeze frames the AI createsRepublic of Korea (Seoul region) / until account deletion or the end of the contract (AI-created freeze frames: 90 days after your last edit, Article 3)

Social login providers (Google, Apple, Kakao, and Naver) are not our service providers; they are the parties you sign in with directly. Each provider’s own privacy policy applies to its processing of your personal information.

Separately, the Team outsources the processing of app usage records for service quality improvement and error response, ad performance measurement, the conversion of coordinates into place names for displaying the running location, and frame reading and freeze-frame creation for AI templates to the providers below. Their servers are located outside Korea, so the following information is transferred abroad.

RecipientCountry, timing, and methodInformation transferredPurpose and retention
Amplitude, Inc.
amplitude.com/privacy
United States / continuously while you use the app / network (HTTPS encrypted)Anonymous device identifier, account identifier issued by the server (only when signed in), feature usage events, user experience survey responses, values derived from running records (distance bucket, whether a route exists, whether a place name exists), attribution details (names of the ad channel, campaign, ad group, and creative)Usage analysis and service quality improvement, comparing attribution performance by ad / until the end of the contract or fulfillment of the purpose
AB180 Inc.
(Airbridge)
airbridge.io/en/privacy-policy
Japan (AWS Tokyo region) / when you install and launch the app and when a share is completed / network (HTTPS encrypted)Advertising identifier (IDFA, only if you allow app tracking), identifier for vendors (IDFV), OS version, device type, language, time zone, IP address, screen size, app install and launch events, share-completed events (name of the channel shared to), anonymous device identifier (alias)Ad performance measurement to find out which ad led to an install / until the end of the contract or fulfillment of the purpose
Google LLC
(Firebase Crashlytics)
policies.google.com/privacy
United States / when the app crashes / network (HTTPS encrypted)Anonymous device identifier, error logs (crash logs), device and OS informationDiagnosing errors and improving stability / until the end of the contract or fulfillment of the purpose
Apple Inc.
apple.com/legal/privacy/en-ww
United States / when you open the overlay editor and a running location name is generated / network (HTTPS encrypted)One starting coordinate of the running route (latitude and longitude)Converting the coordinate into a place name (reverse geocoding) / until the conversion is complete. The returned place name is stored only on your device
Google LLC
(Gemini API)
policies.google.com/privacy
United States / when you choose a video and a freeze point in an AI template and run it / sent over the network (HTTPS encrypted) through the Team’s serverThe single video frame you select (a still image 512 pixels wide, which may show a face), and the freeze frame the AI created from it (for reading where the record text can be placed and checking the composition)Reading the hand position in the frame; reading where the record text can be placed and checking the composition in the AI-created freeze frame; creating the freeze frame instead when OpenAI’s freeze-frame creation is blocked by its safety policy / until the result is returned. Under its paid API terms, Google does not use the frame for training or product improvement and keeps it only for a limited period to monitor for prohibited use
OpenAI, L.L.C.
openai.com/policies/privacy-policy
United States / when you run an AI template that creates a freeze frame / sent over the network (HTTPS encrypted) through the Team’s serverThe single video frame you select (a still image 512 pixels wide, which may show a face)Creating a freeze-frame image with an effect added based on the frame / until the result is returned. OpenAI does not use data received through its API for training and deletes it after keeping it for up to 30 days for abuse monitoring

The transferred information does not include account information that identifies you, original photos or videos, or raw running record figures.There are two exceptions: the single starting coordinate sent to Apple for place-name conversion, and the single video frame sent to Google and OpenAI when you use an AI template (along with the freeze frame the AI created from it). The frame is the original picture before any record overlay is applied, so it contains no running record figures, and no account information, device identifier, or running record is sent with it. If you do not want your information transferred abroad, delete the app; no new records are sent after deletion. To block only the advertising identifier, turn off app tracking in iOS Settings > Privacy & Security > Tracking (Article 7).

If you only want to avoid the transfer to AI providers, simply do not use AI templates.No frame is sent until you choose a video and a freeze point in such a template and run it yourself, and nothing other than that template is restricted if you do not use it. Google and OpenAI act as processors on the Team’s behalf and, under their paid API terms, may not use the frame for their own purposes or for training. We do not send photos or videos to any AI service other than these two, and we will disclose any change in scope through this policy.

Article 6 (Procedures and Methods of Destruction)

  • Information stored in the app is deleted immediately by iOS when you delete the app. The anonymous device identifier stays on the device even after you delete the app (Article 3).
  • Drafts being edited, selected photos, and similar items can be deleted individually in the app.
  • Account information, running record backups, notifications, and AI-created freeze frames stored on the server are deleted by an automated process 30 days after you request account deletion, in a way that cannot be recovered.
  • AI-created freeze frames stored on the server are also deleted by the storage’s automatic expiry rule 90 days after your last edit, even if you do not delete your account (Article 3).

Article 7 (Rights of Users and Legal Representatives and How to Exercise Them)

You and your legal representative may at any time request access to, correction of, deletion of, or suspension of processing of your personal information. Running records, photos, and videos are on your device, so you can exercise these rights directly as described below. For other requests, including app usage records, contact the Team ([email protected]) and we will act without delay.

  • Revoke access to running records: iOS Health app > Profile > Apps > Rungle, turn off read access
  • Revoke photo access: iOS Settings > Rungle > Photos, change or remove the access level
  • Refuse sending a frame to AI providers: Simply do not choose an AI template. All other templates and features remain available (Article 5)
  • Change gender or age group: You can change them on the My Info screen in the app. To erase your answers, contact the Team (Article 3)
  • Revoke app tracking (advertising identifier): Turn off Rungle in iOS Settings > Privacy & Security > Tracking, or turn off Allow Tracking in iOS Settings > Rungle. Once off, the advertising identifier is no longer used, and the service is not restricted in any way
  • Delete AI-created freeze frames from the server: To delete them before the 90 days are up, contact the Team. When you delete your account, they are deleted together with your account information (Article 3)
  • Delete your account: Request it at any time from the My Info screen in the app. 30 days after the request, the account information, running record backups, and AI-created freeze frames on the server are permanently deleted; signing in again before then cancels the deletion
  • Delete everything: Deleting the app destroys the information the app stored. Information on the server remains after you delete the app, so also request account deletion as above. Only the anonymous device identifier stays on the device; contact the Team to have it erased (Article 3)

Article 8 (Children Under 14)

The service is not directed at children under 14, and the Team does not collect personal information from children under 14. A child under 14 who wants to use the service must obtain the consent of a legal representative (such as a parent), and if we learn that a child’s personal information was processed without such consent, we destroy it without delay. This age applies even where local law sets a lower one (for example, 13 in the United States); if the law where you live sets a higher age, that higher age applies.

Article 9 (Security Measures)

The Team takes the following security measures in accordance with Article 29 of Korea’s Personal Information Protection Act.

  • On-device processing: Personal information processing, including photo analysis, face evaluation, and text recognition, is performed on your device, and the iOS app sandbox blocks access from other apps. The only exception is the single video frame for AI templates, which passes through the server to the AI providers; the server deletes the frame as soon as it returns the result and does not store it. The freeze frame the AI creates is kept in encrypted storage that only the Team’s server can access, and you download only your own freeze frames through short-lived signed URLs.
  • Minimal storage: Birth year is stored only as a 10-year age group, and the original value is not kept.
  • Administrative measures: Minimizing the staff who handle personal information and setting internal handling rules
  • Technical measures: TLS encryption on all external connections; the server is placed in a segment not directly reachable from outside, with access limited to the minimum staff; server credentials are kept in a separate secrets management service
  • Access limited to your own data: Running records stored on the server can be viewed and edited only by the signed-in owner; ownership is checked on every request.

Article 10 (Automatic Data Collection Tools and How to Refuse Them)

The Team does not use cookies. Usage records for service quality improvement are generated automatically, keyed to the anonymous device identifier issued by the app (and to the account identifier issued by the server when you are signed in), and sent to the providers in Article 5.

The advertising identifier (IDFA) is collected only if you allow it in App Tracking Transparency (ATT, the iOS prompt that asks whether to allow app tracking). On first launch the app explains what it is used for, then asks with the system prompt; every feature works the same whether or not you allow it. You can turn it off at any time in iOS Settings even after allowing it (Article 7). If you do not allow it, the ad performance measurement tool receives only install and launch events, without the advertising identifier.

Article 11 (Handling of Health Data)

Running records read from Apple HealthKit are used only to create content and to back up and restore your own records. Measurements (distance, duration, pace, heart rate, cadence, and so on) are stored on the Team’s server (in Korea) for backup, and GPS routes are not sent to the Team’s server, and the server is built not to accept them. In line with Apple’s policies, health data is never used for advertising or marketing, and is never sold or provided to third parties. Neither health data nor values derived from it are sent to the ad performance measurement tool in Article 5 or to Meta in Article 4. The video frame sent to the AI providers in Article 5 is the original picture before any record overlay is applied, so it contains no health data.

The running location nameis generated when you open the overlay editor, by sending one starting coordinate of the running route to Apple’s reverse geocoding server (a service that converts coordinates into place names) (Article 5). This is the only time a coordinate leaves your device, and the returned place name is stored only on your device and never uploaded to the Team’s server. Analytics events record only whether a place name exists (yes or no), not the name itself.

However, for service improvement analysis, values derived from running records are sent to the providers in Article 5. The derived values are the following three, and the raw figures cannot be recovered from them.

  • Distance bucket: one of under 5 km / 5 km to under 10 km / 10 km or more
  • Whether a route exists: whether the run has a GPS route (yes or no)
  • Whether a place name exists: whether a place name was generated for the run (yes or no)

These derived values are used only for analysis to understand which distance ranges produce content well, and are never used for advertising or marketing, or sold or shared elsewhere.

Article 12 (Remedies for Privacy Violations)

You may apply to the following organizations in Korea for dispute resolution or counseling regarding privacy violations. If you live outside Korea, you may also contact the privacy or data protection authority in your country.

  • Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (no area code) / privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / kopico.go.kr
  • Supreme Prosecutors’ Office, Cyber Investigation Division: 1301 (no area code) / spo.go.kr
  • Korean National Police Agency, Cyber Bureau: 182 (no area code) / ecrm.police.go.kr

Article 13 (Changes to This Privacy Policy)

When this Privacy Policy is added to, deleted from, or amended, we give notice on this page at least 7 days before the change takes effect. However, when a newly processed item arises only from a feature you choose to use and existing usage does not change, the change may take effect at the same time as the notice. In particular, this policy will be revised when any of the following is introduced: storing location data (GPS routes) on the server, server push notifications (notifications sent from the Team’s server; the run detection notification currently offered is a local notification created only on your device), sending a whole video or multiple frames to external AI, or storing your original photos or videos on the server.

This revision reflects the optional gender and age group questions and the use of overseas AI in AI templates. Compared with the previous policy (effective September 8, 2026), the changes are: the profile information item (gender and age group) and the video frame sent for AI templates (Article 1), the purposes of pose reading and freeze-frame creation and of statistics and personalized recommendations by gender and age group (Article 2), the retention of gender and age group and the immediate deletion of the frame (Article 3), the transfers to Google (Gemini API) and OpenAI and how to refuse them (Article 5), how to refuse sending a frame and how to change gender and age group (Article 7), the exception to on-device processing and minimal storage of the age group (Article 9), and the note that the frame sent to AI contains no health data (Article 11).

This revision takes effect at the same time as its notice. The newly added processing (collecting gender and age group, and sending a frame for AI templates) happens only in features you choose yourself, begins only once you install the app version released after this policy is published (1.2.0), and does not occur in earlier versions.

Revision of September 16, 2026: server retention of the freeze frame created by the AI (90 days after your last edit; deleted together with your account information when you delete your account) was added to the summary and Articles 1, 2, 3, 5, 6, 7, and 9. The policy effective September 9 stated that the freeze frame was stored only on your device; it is now kept on the server so you can keep editing it and restore it on another device. This retention occurs only when you choose to use an AI template, and AI templates first open in the app version released after this policy is published (1.2.0), so existing usage does not change and the revision takes effect at the same time as its notice.

Revision of September 17, 2026: Articles 1, 5, and 10 now state that the usage records of signed-in users carry the account identifier issued by the server and are sent to the analytics tool (Amplitude). This keeps you as one user when you change devices; the account identifier is a random value created by the server and contains no email or name. This processing begins only once you sign in on the app version released after this policy is published (1.2.0), and does not occur in earlier versions or in guest use, so it takes effect at the same time as its notice.

Date of notice and effective date: September 17, 2026 (AI template provisions first effective September 9, 2026)