ROUNDS

Privacy Policy

Effective {{MAINTAINER: EFFECTIVE_DATE}} · Version 1.0 · Changes are listed at the foot of this page.

ROUNDS is an interval trainer. You can browse it on your phone or tablet without an account, but starting a workout asks you to sign in, and an Apple TV asks you to sign in before anything else. Once you have an account, a deliberately narrow slice of your training data syncs so your workouts follow you between your phone, tablet and TV. Your heart rate, your calories and your age are not part of that slice.

Who is responsible for your data

The controller of the personal data described here is Garrenteed Labs LLC. You can reach us about anything on this page at {{MAINTAINER: PRIVACY_EMAIL}}.

What we collect before you sign in

On a phone or tablet, nothing reaches us: with no account there is no sync, and the app holds everything on the device. It does generate a random identifier the first time it runs, which stays on the device and is used to keep your own local records straight; it is not sent to us and is not tied to you.

There is one exception, and it is the flow that by definition happens before anyone is signed in. Signing a TV in asks our server for a pairing code while the TV is still signed out, and sends the label the TV reports about itself. "Pairing a TV" below sets out exactly what that record contains. It is not linked to any account unless and until the pairing succeeds.

What we collect when you create an account

Your identity

An email address and an account identifier — and, in practice, nothing else. You can sign in with an email and password, with Apple, or with Google. Where we sign you in with Apple we ask Apple for your email address only; we do not request your name. We hold no photograph, no phone number and no date of birth, and no name unless you connect Strava — in which case we store the display name Strava gives us, so the app can show you which account is linked.

Workouts you save

The name you typed, the workout's structure, whether you marked it a favourite, when you last ran it, and bookkeeping we need to merge edits made on two devices. If the workout was generated for you rather than authored by you, we also store the settings that generated it, so the same workout can be rebuilt.

Workouts you complete

The segments you ran, the label shown on the run, whether you finished or stopped early, when it started and ended, how long it lasted, when the record was created, a link to the saved workout it was started from, and a few tags describing the kind of session — its format, the drill or programme session it came from, and the body region, movement type and equipment it targeted.

What is not in that list is the point of it. No heart rate, no heart-rate series, no calories and no training zones. Those columns do not exist in our database, and automated tests on both platforms pin the exact set of fields that may be transmitted, so a new field cannot be added by accident.

Your subscription

If you subscribe, we store which store the subscription came from, which product it is, its status, when it expires, and the store's transaction identifier — so that Pro works on your other devices. We never see your card, and we are not told your billing address. In this version your device tells our server about its own subscription; we do not independently verify it with the store.

Pairing a TV

Signing a TV in creates a short-lived pairing code. Alongside it we store a label the TV reports about itself — its model and language, for example Apple TV · en_US — so that you can see which device you are approving. The code expires; the label stays with the pairing record. If a code is shown on a TV and never used, the record it created is never linked to any account. We also count failed pairing attempts against your account for a short window, so that a wrong code cannot be guessed at scale.

What we never receive

Heart rate from a Bluetooth chest strap, the heart-rate series behind the graph (roughly one reading every few seconds), your heart-rate zone breakdown, active calories read from Apple Health or Health Connect, the age you entered to calculate zones, your equipment list, your music preferences — the app can ask permission to show and control what is playing in Apple Music while you train, and what it reads there stays on the device — and your recently-used cue shortlist — the cue text itself syncs once it is part of a workout you save. On Apple watch-based runs, heart rate read from HealthKit stays on the device too.

We do not collect your location. We mention it because on Android 11 and older, connecting a heart-rate strap requires the system's location permission — that is simply how those versions of Android gate Bluetooth scanning, and the app asks for it for no other reason. Android 12 and later use a Bluetooth-scanning permission instead, which we declare as never used for location. Nothing about where you are is recorded, and nothing about where you are is sent to us.

One thing goes the other way. When you run a workout on the Apple Watch app, it saves that workout — with its active energy and distance — into Apple Health on your watch, the way any workout app does. That record then belongs to Apple Health under Apple's terms rather than to us; remove it in the Health app if you would rather not keep it. The phone app never writes to Apple Health; it only reads active calories.

We want to be precise about a limit on that promise, because the usual wording of it is not true for any app. We never transmit that data to our servers. It is not part of anything that syncs with your account. It is included in your device's own operating-system backup if you have that switched on — iCloud or an encrypted computer backup on Apple devices, Google's backup on Android. That backup belongs to you and to Apple or Google under their terms; the app cannot tell one kind of backup from another and cannot exclude itself from one without breaking the restore of your workout history. Your email address and your age ride the same backup.

There is one other way that data can leave the device, and only if you ask for it. If you connect Strava, the heart-rate graph from a strap is part of what is sent to Strava — the screen in the app tells you so before you connect. Strava is described under "Other companies" below.

On the device, your sign-in tokens are held in the platform's secure store. Your email address and age are not, deliberately: they are not secrets, and treating them as such would put them somewhere harder for the app to use correctly. So "everything is encrypted on your device" is a sentence we will not write.

Other companies

We use no analytics, no attribution, no advertising and no crash-reporting service. There is no advertising identifier, no tracking, and nothing about you is sold or shared for advertising. This website loads nothing from anyone else and sets no cookies.

Two companies are nonetheless involved. Supabase hosts the database and the sign-in system for accounts. Strava receives your finished workouts if you connect it, which the next paragraph describes in full. Where you choose to sign in with Apple or Google, that company knows you signed in.

Nothing reaches Strava unless you connect it, and the app explains this on the screen that connects it. Once connected, every workout you finish on that device is uploaded to Strava automatically, from the moment you connect until you disconnect, and you are not asked again for each workout. The upload includes your heart-rate graph — roughly one reading every few seconds — whenever you wear a strap, along with your rounds, rest periods and total time. Workouts you end early are not uploaded, and workouts recorded on your watch are not uploaded. We ask Strava for permission to write activities and nothing else. Strava grants a basic read scope alongside it whether we ask for it or not; we never use it, and nothing in ROUNDS reads anything back out of your Strava account. On our side we store the access and refresh tokens Strava issues us, when they expire, the scope you granted, your Strava athlete identifier and your Strava display name, so the app can show which account is linked; disconnecting deletes all of it, and so does deleting your account.

Where your data is held, and transfers

Account data is stored on Supabase infrastructure in the United States, in the us-east-2 region. If you are in the United Kingdom or the European Economic Area, storing it in the United States means your data is transferred outside the UK or the EEA. That Supabase transfer relies on the Standard Contractual Clauses adopted by the European Commission, which are incorporated into our data-processing agreement with Supabase, together with the additional measures described there. You can ask us for a copy at {{MAINTAINER: PRIVACY_EMAIL}}. What is sent to Strava, if you connect it, is a separate transfer, handled under Strava's own terms, and it happens only while you are connected.

Why we are allowed to hold it

Where the UK GDPR or EU GDPR applies: we process your account email and your synced training data to provide the service you asked for — that is, to perform our contract with you. We process subscription records both to perform that contract and to meet our own legal obligations. We do not rely on legitimate interests for anything described here, with one narrow exception: keeping the service secure. The failed-attempt counts described under "Pairing a TV" exist to stop someone guessing their way into your account, and that is a legitimate interest rather than something we do for you. There is one thing we ask you to consent to: connecting Strava. The app shows you what connecting means before you tap, connecting is optional, and you can withdraw it at any time by disconnecting — which also deletes the connection from our servers. We ask for no other consent, because nothing else here would require one.

How long we keep it

Until your account is deleted. You can do that yourself in the app: go to Settings and, under Account, choose Delete account — on iPhone, iPad and Android, and under Preferences on Apple TV. You can also ask us to. We do not run a retention timer. Workouts you delete in the app are marked deleted and stop appearing, but the record is retained rather than erased, and completed runs are kept as a permanent history. A single workout or a single run cannot be erased on its own. When your account is deleted, all of it goes together — see deleting your account.

One kind of record sits outside that, because it is created before there is an account to attach it to. A pairing code shown on a TV and never used stays in our database with the label that TV reported about itself. It is not linked to you, it cannot be used to sign anything in once it has expired, and there is nothing in it that identifies a person — but we do not currently sweep those rows, and we would rather say so than let "until your account is deleted" imply a completeness it does not have.

What you can ask us to do

You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, and ask for it in a portable form. Where the GDPR applies you can also complain to your national supervisory authority. Write to {{MAINTAINER: PRIVACY_EMAIL}}. We answer from the address you wrote from, because an email address is the only thing that identifies an account here — see deleting your account for why that matters and how we confirm it is you. For deletion you do not have to ask us at all, as long as you can still sign in: the app deletes the account itself, from SettingsAccountDelete account.

Content you create

Workout names, run labels, the cue text you type and any exercise names you enter are free text that you write, and they all sync with your account inside the stored structure of the workout, along with the reps and weights you record. We keep that structure exactly as your device sent it and never read into it. Only your recently-used cue shortlist stays on the device. The name and the label also appear in any workout summary you choose to share from the app. Nothing filters what you type, so please do not put anything private in a workout name.

Children

ROUNDS is not directed to children and is not intended for anyone under 13. We do not knowingly collect personal data from anyone under 13, and we do not ask for an age category. We hold no age and no date of birth on our servers. The app asks for an age on the device only, to work out your heart-rate zones, and it is never sent to us — see "What we never receive". If you believe a child has given us data, write to {{MAINTAINER: PRIVACY_EMAIL}} and we will delete it.

Changes to this policy

This page is the policy; it has a single address that the apps link to, so it is updated in place rather than replaced. Every change is recorded below with its date. If we make a material change, ROUNDS will show you a notice the next time you open it.

Change log