TL;DR — The Short Version
- No ads. No tracking. No analytics.
- We never sell your data.
- Routes and settings live on your device by default. Cloud Sync (opt-in Pro feature) mirrors them to your private Firebase account for cross-device access.
- Location data is processed on-device for navigation. Mapbox and our own routing engine receive coordinates for map tiles and route calculation. NWS receives your position when Weather Callouts are on. Wikipedia receives your position when Tour Mode is on.
- Group Ride shares your position with other members in your group only. Public groups are discoverable by name + creator's approximate start location.
- Photos on Map (opt-in) reads GPS coordinates from your photo library on-device. Photos never leave your phone.
- Account info (email) is stored securely via Firebase for authentication only.
PreRun.io is designed with privacy at its core. We collect the minimum data needed to make the app work. Optional features that share more (Cloud Sync, Group Ride, Weather, Tour Mode, Photos on Map) are all off by default and clearly toggleable.
Introduction
PreRun.io ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application and web app PreRun.io (the "App").
By using PreRun.io, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Account Information
- Email Address: When you create an account (required for Pro features), we store your email address via Firebase Authentication. This is used solely for sign-in and account management.
- Authentication Provider: If you sign in with Google or Apple, we receive your name and email from the provider. We do not access your contacts, calendar, or other account data.
Location Data
- GPS Coordinates: When you use Follow Mode (GPS navigation), the App accesses your device's GPS to show your real-time position on the map, calculate distance to waypoints, and provide turn-by-turn guidance.
- How Location Is Used: Your GPS coordinates are sent to Mapbox to load map tiles and calculate driving routes via the Mapbox Directions API. This is necessary for the app to function.
- We Do Not Store Location: Your GPS position is calculated in real-time on your device. We do not log, record, or store your location history on any server.
GPX Files and Route Data
- GPX Files (local): When you import a GPX file, it's processed entirely on your device. It stays on your device unless you opt in to Cloud Sync.
- Waypoints and Settings: Your custom waypoint labels, navigation settings, and app preferences are stored locally on your device.
- Cloud Sync (opt-in Pro feature): If you enable Cloud Sync in Settings, PreRun uploads your GPX files, collection metadata, and settings to your private Firebase account (Firestore + Cloud Storage) so they mirror across your devices. Only you can access this data — it is scoped to your Firebase UID by our security rules. Toggling Cloud Sync off stops the sync; you can delete uploaded data by removing the collection from any signed-in device.
Photo Library (opt-in, iPhone / iPad only)
- Platform availability: The Show My Photos feature is available on iPhone and iPad. It is not available on Android — Google Play's Photos policy restricts full-library access to gallery / photo-editor apps, so PreRun on Android does not request photo permissions at all.
- What we access (iOS): When you turn on Show My Photos on Map in Settings → Map Overlays, PreRun reads the GPS coordinates from your photo library's EXIF metadata to display geotagged photos as pins on the map. Thumbnail images are loaded from the device when a pin is rendered; the full-resolution photo is loaded only when you tap a specific pin to view it.
- Photos never leave your device. PreRun does not upload, transmit, share, or copy your photos anywhere. All processing is on-device.
- Toggle off any time. When the feature is off, the permission is not accessed.
Group Ride Data (opt-in)
- Position sharing while in a group: When you Start or Join a group ride, your real-time position, display name, speed, and heading are broadcast to other members of your group through Firebase Realtime Database. This is throttled to about once per second. Your position is visible only to members of your specific group.
- Persistent group ID: Your group's 6-character code and friendly name are stored in Firebase RTDB so members can rejoin day-to-day on multi-day trips. A group entry expires after 30 days of inactivity.
- Public groups (opt-in per group): If you flip the Public toggle when starting a group, PreRun writes a discovery record to Firestore containing the group name, your display name as creator, and a static point representing your approximate location when you started the group (captured once and never updated). This lets other users find and join. Turning Public off removes the group from the discovery list.
- Meshtastic LoRa Mesh (optional hardware): If you pair a Meshtastic device, positions are additionally broadcast over LoRa radio to other group members with paired devices. This is direct device-to-device radio; PreRun servers are not involved unless a "gateway" device with both mesh and internet is also present.
- Leaving the group: Ending or leaving a group stops all position broadcasts.
Run Track Logs
- Local recording: When you use Follow Mode or Record Mode, PreRun records your GPS track as a run log saved to a collection on your device. Track logs are not uploaded unless you have Cloud Sync enabled (see above).
Subscription Data
- Subscription Status: If you subscribe to PreRun Pro, your subscription status (active/inactive and expiry date) is stored in Firebase Firestore linked to your account. This allows the app to verify your subscription across devices.
- Payment Information: Payments are processed by Stripe. We never see, store, or have access to your credit card number or payment details. Stripe handles all payment security.
Information We Do NOT Collect
- Usage Analytics: We do not collect analytics, usage patterns, or track how you use the App.
- Advertising Data: We do not collect data for advertising. The App contains no advertisements.
- Device Identifiers: We do not collect device IDs, IDFA, or fingerprint your device.
- Location History: We do not log or store your GPS position history.
Third-Party Services
PreRun.io integrates with the following third-party services:
Mapbox
- Used for: Map display, 3D terrain visualization, satellite imagery, driving directions (Directions API), and business / POI / coordinate search (Search Box API in the Discover feature).
- Data shared: Your approximate location (via map tile requests) and exact coordinates when requesting driving routes or search results.
- Privacy Policy: https://www.mapbox.com/legal/privacy
Firebase (Google)
- Used for: User authentication (sign-in), subscription status storage (Firestore), Cloud Sync (Firestore + Cloud Storage, opt-in), and Group Ride live position sharing (Realtime Database).
- Data shared: Email address, authentication tokens, and any GPX / collection / setting you have Cloud Sync enabled for. Group Ride real-time positions while in a group.
- Privacy Policy: https://firebase.google.com/support/privacy
Stripe
- Used for: Processing Pro subscription payments.
- Data shared: Email address (for receipts). All payment data is handled directly by Stripe.
- Privacy Policy: https://stripe.com/privacy
PreRun.io Off-Road Routing Engine
- Used for: Building routes with our custom off-road routing engine (Build Route, Trail Finder, Connect Mode, and Go To). Runs on our own server at
routing.prerun.io. - Data shared: The two or more waypoint coordinates that define the route request, plus your Route Preferences (vehicle type, offroad slider, trail class, surface preference, seasonal availability).
- Retention: Route requests are processed in-memory and are not logged with user identity. Standard web-server access logs (IP, timestamp) rotate weekly.
National Weather Service (NWS)
- Used for: Destination forecast, severe weather alerts, and precipitation lookahead when Weather Callouts are enabled.
- Data shared: Your current location coordinates (during a Run with Weather Callouts on).
- Notes: NWS is a US federal government service. No account, no tracking. Requests are anonymous.
Iowa Environmental Mesonet (NEXRAD Radar)
- Used for: Live weather radar map tiles when the Weather Radar overlay is enabled.
- Data shared: Standard tile requests based on the map area you're viewing.
Wikipedia
- Used for: Nearby landmark lookups when Tour Mode is enabled.
- Data shared: Your current location coordinates. Wikipedia returns a list of nearby articles. PreRun then fetches the first sentence of the closest one you haven't heard yet.
- Notes: Anonymous, no account, no tracking.
Data Storage
- On Your Device (always): GPX files, waypoints, navigation settings, cached map tiles, and app preferences are stored locally by default.
- In the Cloud (Firebase, required): Your email address, authentication credentials, and subscription status (active/inactive, expiry date) are stored in Firebase. This data is secured by Google Cloud infrastructure and is scoped to your account.
- In the Cloud (Firebase, opt-in Cloud Sync): When Cloud Sync is enabled, your GPX files, collections, and settings are mirrored to your private Firebase account. This data is scoped to your Firebase UID by our security rules — no one else can read it. Toggling Cloud Sync off stops mirroring; deleting a collection from any device removes it from the sync.
- In the Cloud (Firebase, ephemeral): Group Ride positions. Real-time positions during an active group ride are written to Firebase Realtime Database and are visible only to members of your group. Positions are overwritten as you move; the group record itself expires after 30 days of inactivity.
- We Do Not Store on any server: Photos, photo library metadata (photo overlay is on-device only), or your GPS position history outside of an active group ride or your own opt-in Cloud Sync.
Data Sharing
We do not sell, trade, or share your personal data with third parties for marketing or advertising purposes.
Data is only shared with the third-party services listed above, and only as necessary for the App to function (maps, authentication, payments).
Children's Privacy
PreRun.io does not knowingly collect any information from children under the age of 13. The App is not directed at children under 13.
Data Security
- Local data is protected by your device's built-in encryption
- All network communication uses HTTPS encryption
- Authentication is handled by Firebase with industry-standard security
- Payment processing is handled by Stripe (PCI DSS compliant)
- We do not store passwords — authentication is handled by Firebase and third-party providers
Your Rights
- Access: Your local data is on your device. Your account data can be viewed in the App's settings.
- Deletion: You can delete your account at any time, which removes all cloud-stored data (email, subscription status). Uninstalling the App removes all local data.
- Portability: You can export your routes as GPX files at any time.
- No Account Required: Free features work without creating an account.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes are effective when posted. We will update the "Last Updated" date at the top of this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: support@prerun.io
Website: https://prerun.io