1. Who I am
UltraPlanRun is an app for planning ultramarathon races, available on iPhone and Android. It is developed and maintained by an independent developer. For enquiries, contact me at [email protected].
2. What data the app handles
UltraPlanRun stores the following information on your device, synced privately to your own iCloud account on iOS (if enabled) or backed up to your own Google Account via Android's Auto Backup on Android (if enabled). Nothing in this list is sent to us, to any third-party server I operate, or to any analytics or advertising service:
- Race plans you create: name, date, distance, segments, paces, ETAs, cut-off times, terrain notes
- GPX route files you import
- FIT activity files you import (for adaptive pacing and previous-race comparison)
- Nutrition plans, custom foods you add, and drop-bag flags
- Mandatory kit selections, including any custom items you add
- Travel & Logistics info you choose to enter (accommodation address, registration window, phone number, booking code)
- Parking & Transport coach pickups you add
- Emergency contact name and phone number
- Per-checkpoint weigh-ins, if you choose to log them
- App preferences (units, weight unit, theme, sort order, weather units)
- Health data read from Apple Health (iOS) or Health Connect (Android): workouts, resting heart rate, HRV, VO₂ max, sleep, elevation gained, displayed in the Training Log and Health Snapshot screens. This data is read-only, never written back, and never leaves your device
One feature is the exception to "stays on your device": if you enable Crew Live Link (Pro), the race plan details shown on the crew page, plus your live location, checkpoint progress, and phone battery level during a race, are sent to a server so your crew can follow you on a web page. This only happens if you turn it on, and is described fully in section 7.
3. What I do not collect
UltraPlanRun contains:
- No analytics SDK (no Firebase, no Mixpanel, no Amplitude, no homegrown analytics)
- No advertising SDK (no ad networks, no IDFA tracking)
- No crash-reporting SDK (I rely on Apple's anonymous crash reports through App Store Connect, which you can opt out of in iOS Settings → Privacy & Security → Analytics & Improvements)
- No account system: there's nothing to sign up for, nothing to log into
- No personal data on our servers, with one opt-in exception: your race plans, health data, and personal information never touch any server I operate. There are two server-side components. The Find a Race catalogue (see section 6) serves public race information and does not receive or store any of your data. Crew Live Link (see section 7) is opt-in: if you turn it on, it temporarily stores the shared race's plan details plus your live location, checkpoint progress, and battery level so your crew's page can display them, and deletes everything 48 hours after your race, or immediately if you tap Stop Sharing. iCloud sync goes to Apple's infrastructure under your own Apple ID, governed by Apple's privacy policy
4. Location data
On iOS, UltraPlanRun requests location permission at two different levels, depending on what you use:
- "When In Use": requested when you tap "Show my location" on the race map. This lets the app drop a blue dot showing where you are relative to the route while the app is open. This location data is used only on your device and is never uploaded to any server I operate.
- "Always" (background location): requested when you start Trail Track (live race-day tracking), record an Auto-Pace calibration run, or turn on Crew Live Link's race day beacon. This lets the app keep recording or checking your position while your phone is locked or in your pack, so it can auto-advance checkpoints, detect if you've gone off-course, and, if the beacon is on, keep your crew's live page updated.
- Location only ever leaves your device when the Crew Beacon is switched on. Background tracking for Trail Track and calibration runs happens entirely on your device and is never uploaded anywhere. The beacon is a separate, explicit toggle from background tracking itself; turning on Trail Track alone does not share anything with your crew. See section 7 for what the beacon sends and how long it's kept (deleted within 48 hours of the race ending, or immediately via Stop Sharing).
- You can review or revoke either permission at any time in iOS Settings → UltraPlanRun → Location.
If you tap "Share my location" the app constructs a Google Plus Code + coordinates link and hands it to the iOS Share Sheet. UltraPlanRun never sees the destination. Only you decide who receives the link.
On Android, UltraPlanRun requests location permission for two purposes: dropping the same "Show my location" blue dot on the race map, and, when you start live race-day tracking, a Track Me session, or an Auto-Pace calibration run, continuously reading your GPS position for the duration of that session via a foreground location service. Crew Live Link's race day beacon (see section 7) is currently an iOS-only feature; if and when it comes to Android, this section will be updated to describe the permission it uses there too.
- A persistent notification is shown for the entire time the foreground service is running, as Android requires. The service stops as soon as you end the session.
- Location is never tracked in the background.
- Location is never uploaded to any server I operate.
- You can revoke location permission at any time in Android Settings → Apps → UltraPlanRun → Permissions → Location.
5. Platform-provided services I use
UltraPlanRun uses Apple's frameworks on iOS and Google's/Android's equivalents on Android. Each is listed below under its platform.
iOS
iCloud (CloudKit)
If you have iCloud enabled on your iPhone, UltraPlanRun uses Apple's CloudKit to sync your race plans across your devices and keep a private backup. Your data is stored in your personal iCloud account; I have no access to it. Apple's privacy policy at apple.com/legal/privacy governs how Apple handles CloudKit data. You can disable iCloud sync for UltraPlanRun at any time in iOS Settings → [Your Name] → iCloud → UltraPlanRun.
WeatherKit
The Weather screen fetches per-checkpoint forecasts from Apple's WeatherKit service. When you open the Weather screen, the app sends each checkpoint's latitude and longitude to Apple over an encrypted connection so Apple can return the forecast. I don't see this data; Apple's privacy policy at apple.com/legal/privacy applies to the request.
MapKit
The route map is rendered by Apple's MapKit. Map tile requests go directly from your iPhone to Apple. I don't intercept or store any of this traffic.
CLGeocoder (address lookup)
When you enter a postcode (for accommodation or a coach stop), the app calls Apple's geocoder to convert the postcode into latitude/longitude so the inline map can show the pin. This is an Apple-provided service; no data goes to us.
Apple Maps deep links
"Get directions" buttons open Apple Maps via a
maps.apple.com URL. UltraPlanRun never sees what you do
inside Apple Maps.
HealthKit (Apple Health)
The Training Log and Health Snapshot screens read workout and health data from Apple Health on your device. UltraPlanRun requests read-only access to:
- Workouts (running activities: distance, duration, heart rate, calories, elevation)
- Resting heart rate, heart rate variability (HRV), VO₂ max
- Sleep analysis
UltraPlanRun never writes to Apple Health and never uploads your health data to any server. All processing happens on your device. You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → UltraPlanRun.
Local notifications
Reminders you set (registration, race-day wake-up, coach pickups)
are scheduled with iOS's local
UNUserNotificationCenter. They fire on your device
only. I don't have a push notification server.
Android
Health Connect
The Training Log and Health Snapshot screens read workout and health data from Health Connect, Android's central health and fitness data store. UltraPlanRun requests read-only access to:
- Exercise sessions (workouts: distance, duration, calories burned, elevation gained)
- Heart rate, resting heart rate, heart rate variability (HRV), VO₂ max
- Sleep sessions
- Health data older than the default 30-day window, used only to show multi-month training trends (4/8/12/16-week history) ahead of a race
UltraPlanRun never writes to Health Connect and never uploads your health data to any server. All processing happens on your device. You can revoke Health Connect access at any time in the Health Connect app → App permissions → UltraPlanRun.
Google Maps
The route map on Android is rendered using the Google Maps SDK. Map tile requests go from your device directly to Google under Google's own privacy policy at policies.google.com/privacy. UltraPlanRun does not attach any personal identifiers to these requests.
Foreground location services
See section 4 for how UltraPlanRun uses Android's foreground location service during live race tracking, Track Me sessions, and Auto-Pace calibration runs.
Race reminders (exact alarms)
Reminders you set (registration, race-day wake-up, coach pickups) use Android's exact alarm permission so they fire at the precise time you set, even after the device has been rebooted since. These alarms run entirely on your device; there is no push notification server.
Background Training Log import
If you point UltraPlanRun at a folder of FIT or GPX files to bulk-import your training history, the import runs as a background task (via Android's WorkManager) so it can continue if you leave the app. Files are read and parsed on your device only; nothing is uploaded.
Android Auto Backup
If Android's Auto Backup is enabled on your device, your race plans and app data are backed up to your own Google Account, the same way any other app's data is; I have no access to it. You can disable this in Android Settings → Google → Backup, or per-app in Settings → Apps → UltraPlanRun → Storage.
6. Find a Race catalogue
The Find a Race feature lets you browse and
search a catalogue of ultra races hosted at
api.ultraplan.run. When you use this feature:
-
The app sends an HTTPS request to
api.ultraplan.runcontaining only your search query and optional continent/country filter. No personal data, device identifiers, or account information is included in the request. - The server returns public race information (race name, distance, elevation, region, checkpoint names) and, when you choose to download a plan, the race plan JSON.
- No personal data is collected, logged, or stored by the Find a Race service. Standard web server access logs (IP address, timestamp, request path) may be retained temporarily by the hosting provider (Cloudflare) under their own privacy policy at cloudflare.com/privacypolicy.
- Downloaded race plans are saved to your device like any other race plan; they are not treated differently from plans you create yourself.
This is the only feature in UltraPlanRun that makes a network request to a server I operate. Every other network request goes to Apple (iCloud, WeatherKit, MapKit, geocoding) on iOS, or to Google (Google Maps) on Android.
7. Crew Live Link & race day beacon
Crew Live Link (Pro, iOS) lets your support crew follow your race on a private web page, no app or account needed on their side. This is the one feature where your data leaves your device and reaches a server I operate, and it only happens if you choose to turn it on.
- What's sent: creating the link uploads a snapshot of the plan details the crew page shows: race name, distance and start time, checkpoint names, locations, planned ETAs and cut-offs, the crew member names you've assigned to each checkpoint, and any checkpoint notes. Then, when you turn on the race day beacon, the app periodically sends your GPS location, which checkpoints you've reached, and your phone's battery percentage. Your emergency contact, crew phone numbers, travel & logistics details, weigh-ins, and health data are never sent.
- Who can see it: only someone holding the unique link you shared. There is no directory, search, or public listing of active links. Crew phone numbers stored in your plan are never sent to the server. The crew member names you assign to checkpoints, and any checkpoint notes, do appear on the page so your crew can see who covers each stop — keep those to first names if that matters to you.
- How long it's kept: location and race progress data is deleted from the server automatically 48 hours after your race, or immediately if you tap Stop Sharing. The beacon also stops sending updates on its own once you finish.
- Who it's used by: the data is used solely to render your crew's live page. It is not used for analytics, advertising, or any purpose beyond showing your crew where you are during the race.
-
Hosting: the Crew Live Link server is hosted
at
crew.ultraplan.run, under my control, behind an HTTPS connection. Standard web server access logs (IP address, timestamp, request path) may be retained temporarily by the hosting provider under its own privacy policy. - Your control: the beacon is off by default and only activates when you flip it on at the start line. You can turn it off, or tap Stop Sharing to delete everything immediately, at any point during or after the race.
8. Backups and sharing
In addition to automatic iCloud sync, UltraPlanRun gives you two manual ways to send a race plan elsewhere:
- Save Backup: writes a JSON file to your phone's temporary folder, then opens the share sheet (iOS Share Sheet, or Android's Share intent). You decide where it goes (iCloud Drive, Files, AirDrop, Google Drive, Mail, Messages, Dropbox, etc.). This backup contains your full plan including personal information, since it's intended for restoring on your own device.
- Share with a friend: writes a sanitised JSON file with your emergency contact, weigh-ins, FIT files, accommodation phone + booking code, crew phone numbers, registration date, travel & coach data, and reminder times stripped before the file leaves your phone. The recipient gets your route, segments, paces, nutrition, drop bags and kit only.
In both cases the file is generated on your device and travels via whichever channel you pick. UltraPlanRun has no role in transmitting it.
9. Children
UltraPlanRun is not directed at children under 13 and I don't knowingly collect data from anyone. The App Store age rating reflects the general content suitability.
10. Changes to this policy
If a future version of UltraPlanRun changes what data it handles I'll update this page and bump the date at the top. Material changes will also be flagged in the app's "What's New" release notes on the App Store.
11. Contact
Questions, concerns, or a data request? Email [email protected]. The aim is to respond within seven days.
12. Your rights
Because UltraPlanRun stores everything on your iPhone (and syncs to your own iCloud account) and I do not hold any of your data, your data rights (access, deletion, correction, portability) are exercised directly through the app or iOS:
- Access: open any race in the Races tab.
- Portability: use Save Backup to export a full JSON copy.
- Deletion: swipe-to-delete a race, or uninstall the app to remove all local data. On iOS, to also remove iCloud data, go to iOS Settings → [Your Name] → iCloud → Manage Account Storage → UltraPlanRun → Delete Data. On Android, to also remove Auto Backup data, go to Android Settings → Google → Backup, or Settings → Apps → UltraPlanRun → Storage → Clear data.
- Crew Live Link data: tap Stop Sharing in the app at any time to delete your live location and race progress from the server immediately, otherwise it's deleted automatically 48 hours after your race.