Privacy Policy
Last updated: 2026-07-30
Who we are
RunTogether is operated by RunTogether LLC (“we”, “us”). Our registered address is 838 6th St N #2, St Petersburg, FL 33710, and you can reach us at privacy@2gether.run. This policy covers the RunTogether mobile apps and the RunTogether website.
RunTogether lets people find local running clubs, see upcoming runs, check in to those runs, message their club, share photos and videos from runs, and earn rewards. Clubs themselves are run by their own organizers, who are members like you rather than employees of ours.
Information we collect
Account information. When you create an account you provide an email address and a password, or you sign in with Google or Apple. Your email address and sign-in credentials are held by Firebase Authentication; we do not copy your email address into our own user database. You also provide a display name, and you may add a profile photo.
Date of birth. RunTogether is for people aged 18 and over, so we ask for your date of birth when you create an account and use it to confirm you are old enough. It is also used so that your club can send you a birthday greeting and, if the club offers one, a birthday reward, and — unless you turn that off — so that your phone can match advertisements to your age range without sending your age to us.
Other optional profile details. You may add a phone number and your gender. Along with your date of birth these are stored separately from the rest of your profile, in a private record that only you and our servers can read.
Club membership and activity. Which clubs you have joined or requested to join, the runs you check in to, points you have accumulated, and rewards you have earned and redeemed.
Location.Checking in to a run uses your device's location to confirm you are at the run. The coordinates recorded at the moment of check-in are stored on that check-in record. Location is also used, while you are using the app, to sort and filter clubs and runs by distance from you. We do not track your location in the background.
Photos and videos.Photos and videos you post to a run or attach to a message, together with any caption you write, are stored in Firebase Storage. Photos and videos you add to a run's gallery are visible to the other members of that club, and because run galleries also appear on our public website, a gallery photo can be opened by anyone who has its direct link, including people without a RunTogether account — treat a run gallery as public. Photos and videos you attach to a message are different: they can only be opened from within RunTogether, by you and the people the message was sent to.
Device calendar. If you choose to add a run to your calendar, we ask your device for permission to see the list of calendars on it, so that you can pick one, and to write the run into the calendar you choose. We do not read the contents of your calendar events, none of your calendar information is sent to us or stored by us, and we never add anything to your calendar unless you ask us to.
Messages. Messages you send to your club or to another member, including attachments, are stored so they can be delivered and read.
Waivers. If a club requires a liability waiver, we record which version of the waiver you signed and when, along with the signature image you drew.
Device tokens for notifications. If you enable push notifications, your device registers a push token with us so we can deliver them. Tokens are private to your account and are removed when you sign out.
Advertising. Sponsor advertisements appear inside the app — on your clubs list, on Discover, and on club pages — and may also appear in emails a club sends you.
An advertiser can ask that an advertisement be shown only near a particular place, or only to people in a certain age range, or only to people of a particular gender. In the app, that matching happens on your phone: the advertisement carries the conditions, your phone checks them against your own profile, and your age and gender are never sent to us or to the advertiser for this purpose. If you have not given your age or gender, or you chose “Prefer not to say,” you are simply not shown advertisements that ask for them. You can turn this off entirely under Profile — advertisements will still appear, but they will not be matched to your profile. Advertisements in emails are matched only by where the club is located, never by your age or gender.
We record that an advertisement was shown or tapped, along with the club it appeared in, so the club and the sponsor can see how many people saw and clicked it. These records do not name you: we store a one-way code in place of your account, used only to avoid counting the same person twice on the same day.
Email engagement. Emails a club sends through RunTogether contain a small invisible image and links that pass through our email provider, so that we and the club can see how many people the email reached, how many opened it, and which links were clicked. We record these as counts, using a one-way code in place of your email address — the club is shown how many people opened an email, never a list of who did. Emails we send you directly, such as a birthday greeting or a notification, are sent without any of this tracking.
Moderation records. See automated screening below. Where the app checks a message before you send it, we keep a record of the outcome — the verdict, the categories involved, and the length of the text — but deliberately not the text of the message itself.
How we use this information
- To operate your account and show you your clubs, runs and rewards.
- To verify that you were present at a run when you check in.
- To deliver your messages, photos and videos to your club.
- To send you email and push notifications about your clubs — run reminders, club announcements, join requests and approvals, rewards you have earned, and birthday greetings.
- To screen member-posted content for harmful material, as described below.
- To keep the service secure and to investigate abuse.
We do not sell your personal information, we do not share it with advertising networks, and we do not use it to advertise to you anywhere outside RunTogether. Where an advertisement is matched to your age or gender, that matching happens on your own device, as described above.
Automated screening of member content
This is unusual enough that it deserves a plain description rather than a clause.
Photos and videos are screened before other members see them. When you upload a photo, it is sent to Google Cloud Vision, which reports how likely it is to contain adult, violent, racy, or medical content. When you upload a video, it is sent to Google Video Intelligence for explicit-content detection. If you wrote a caption, the caption text is also sent to Google's Gemini model for a separate check.
Flagged media is moved to quarantine, not deleted. If the screening flags an upload, the file is moved to a restricted storage area that no member can read, and the post is withheld from the club. It is retained rather than destroyed, specifically so that a club organizer can look at it and restore it if the screening was wrong — which happens with ordinary race photography.
Message text may be checked before it is sent.When enabled, the text of a message you are composing is sent to Google's Gemini model to check for targeted abuse, threats, sexual harassment, hate speech, or doxxing, and you may be warned before you send it. This check currently runs in shadow mode: the check happens and the outcome is recorded, but nothing is shown to you and no message is blocked. The text of the message is not stored by us as part of this check.
New club submissions are reviewed automatically.When someone creates a club, the club's public description is sent to Google's Gemini model, which either recommends approval or refers it to a human. It can never reject a club on its own.
None of this screening makes a decision that permanently removes your content without a person being able to reverse it.
What happens when you report something
You can report a message, a photo or video, or a member. This is worth describing plainly, because it shares information with people who could not otherwise see it.
Filing a report shares the reported content with whoever reviews it— normally your club's organizers, and in some cases platform administrators instead. We store a copy of the reported content as it was at the moment you reported it, so that the reviewer can still see what you were talking about even if it is deleted afterwards. The reviewer also sees the reason you chose, any note you wrote, your name, and how many different members have reported the same thing.
Reporting a direct message shares an excerpt of that message — up to 500 characters — with your club's organizers, or with platform administrators.A direct message is otherwise visible only to you and to the people you send it to. Apart from a report, there is one other situation in which an organizer sees one: if you choose to send a message for review after our automated check flags it, the message is held and shown to your club's organizers, who decide whether it is sent — and the people you addressed it to are not shown to them unless an organizer records a written reason for needing to know, which we keep a record of. If you report a message someone sent you, you are choosing to hand over your copy of a private conversation in order to get help with it. That is a real widening of who can read it, it applies to the other person's words as well as your own, and it cannot be undone once the report is filed. If that is not what you want, you can block the sender instead, which hides them from you without showing anything to anyone.
We do not tell the person you reported that you reported them. Your name is shown to reviewers so they can judge the report, and never to the person it is about.
Third parties that process data for us
- Google / Firebase — authentication, database (Firestore), file storage, push notification delivery (FCM), and website hosting (App Hosting).
- Google Cloud Vision — screening of uploaded photos.
- Google Video Intelligence — screening of uploaded videos.
- Google Gemini (Vertex AI) — screening of photo captions and message text, and automated review of new club submissions.
- Mailgun — delivery of the emails we send, and measurement of whether a club email was delivered, opened and clicked.
- Google Maps / Geocoding — turning club and run addresses into map coordinates, and displaying route maps on the website.
- OpenStreetMap Foundation— supplying the map images shown in the app, and looking up the address for a location you pick on a map. Your device's IP address and the coordinates you are viewing or have selected are sent to them.
- Stadia Maps— matching an uploaded route to real roads and paths. The route's coordinates are sent to them.
- Google reCAPTCHA — used by the website to verify that requests come from a real browser.
We operate in the United States, and the processors above store and process information on infrastructure in the United States and, in some cases, other countries. If you use RunTogether from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws different from those where you live. Where a transfer of personal data out of the United Kingdom or the European Economic Area is involved, we rely on the safeguards our processors make available for such transfers, such as the European Commission's Standard Contractual Clauses.
[DRAFTED — requires legal review] Draft international-transfer disclosure assuming US operation and Google/Mailgun as processors. A lawyer should confirm which transfer mechanism actually applies (SCCs, UK IDTA, adequacy), name it precisely, and align it with the processors' current terms and any DPA in place.
Your choices
- Block another member.Blocking hides that member's messages from you and prevents them from messaging you.
- Control your visibility.You can choose whether you appear in a club's member list, per club.
- Leave a club at any time.
- Notifications.You can turn off push notifications in your device settings, and mute a club's messages in the app.
- Delete your account. You can delete your account yourself, from the Delete your account section at the bottom of your profile page. We ask you to confirm your sign-in first. If you organize a club, you must transfer or close that club before your account can be deleted, so that its members are not left without an organizer. You can also contact us at privacy@2gether.run and we will delete your account for you.
Your privacy rights
Depending on where you live, you may have some or all of the following rights over the personal information we hold about you:
- to access a copy of it;
- to have inaccurate information corrected;
- to have it deleted — you can delete your account yourself, as described above, or ask us to;
- to receive a portable copy of the information you provided to us;
- to object to or restrict certain processing, and to withdraw consent where we rely on it — for example, device location for check-in, which you can turn off in your device settings at any time.
To exercise any of these, write to privacy@2gether.run; we may need to verify your identity first. We will not discriminate against you for exercising a privacy right. As stated above, we do not sell your personal information and do not share it for cross-context behavioural advertising.
[DRAFTED — requires legal review] Drafted to be broadly consistent with the GDPR/UK GDPR and CCPA/CPRA without claiming full compliance with any one regime. A lawyer must confirm which laws actually apply, state the legal bases for processing, set the identity-verification and response-time procedures, and add any required state-specific disclosures (e.g. a 'Do Not Sell or Share' mechanism, categories/purposes tables, and an appeals process).
How long we keep information
We keep your account and club activity for as long as your account exists. Media flagged by the automated screening is kept in quarantine so that an organizer can review or restore it.
When you delete your account, we remove your profile and private profile details, your club memberships and join requests, your check-ins, points and rewards, your notification records and devices, and your waiver signatures. Photos and videos you uploaded are deleted outright, including any copy held in quarantine.
Some things are deliberately not erased:
- Messages you sent to other peopleremain visible to the people who received them, because deleting them would remove one side of someone else's conversation; instead we detach them from you and they are shown as sent by “Deleted member”. Messages addressed to you are left as they are, because editing their recipient list could widen who is able to read a private conversation.
- Content a club still relies on, such as a route you uploaded that the club's runs still use, remains with the club.
- Advertisements you submitted, if you advertised with us, along with the images in them — they remain with the clubs they were approved for.
- Safety reports. If you reported someone, or someone reported you, that report is kept — including up to 500 characters of the reported message, the name shown on the account at the time, and the name of the person who filed it. Unlike your messages, these are notchanged to “Deleted member”: a report has to stay readable for the decision to be reviewed, and so that a pattern of behaviour is not erased by deleting an account and making a new one. Reports are visible only to the organizers of the club involved and to platform administrators, and are kept while they may still be needed for that purpose.
How long specific things are kept:
- Account and club activity — while your account exists. When you delete your account, we delete it straight away. Copies can persist for up to 30 days in our encrypted backups, which are kept for that period so we can recover from a failure, after which they are overwritten. We may keep something longer only where we must to comply with law or resolve a dispute.
- Quarantined media — kept while your account exists so an organizer can review or restore a wrongly flagged upload, and deleted when you delete your account.
- Moderation records for message checks — the verdict, the categories, and the text length, but never the message text — kept for about 12 months to operate and audit safety, then deleted automatically.
- Advertising measurement — records of which advertisements were shown or tapped — kept for about 24 months, then deleted automatically. These records identify a club and an advertisement rather than you: they are stored under a one-way code and carry no account reference.
- Club email records — the emails a club sends, and whether each was delivered, opened or clicked — kept for as long as the club exists, so organizers keep the history of what they have sent. Who opened a given email is recorded under a one-way code rather than your email address.
- Backups — routine encrypted backups may retain copies for a short period (typically up to 30 days) after deletion, after which they age out.
[DRAFTED — requires legal review] RETENTION IS LIVE as of 2026-08-12 (legal audit, issue 12) — the 12- and 24-month sentences above are now TRUE and safe to publish. All three parts are done and were verified, not assumed: expiresAt is written at creation on messageCheckLogs (12mo) and adImpressions/adClicks (24mo); backfillRetentionExpiry backdated all 2,055 existing documents from their own createdAt; and the Firestore TTL policies read ACTIVE on exactly those three collection groups. TTL deletes within roughly 24 hours of expiry, which is why the text says 'about' rather than a hard guarantee. THOSE THREE ARE THE ONLY COLLECTIONS THAT EXPIRE — check-ins, points, rewards, waiver signatures, photos, messages and the clubEmails records including their delivered/opened/clicked history carry no expiry field and never get one. If a fourth collection group ever appears in `gcloud firestore fields ttls list`, something is deleting data meant to be permanent; note that qrTokens uses a field of the same name. STILL OUTSTANDING: the BACKUPS bullet. Point-in-time recovery is DISABLED and there are zero backup schedules on this database (checked 2026-08-12), so 'typically up to 30 days' describes nothing that currently exists — it becomes accurate only once launch-plan O2 lands (PITR at 7 days + daily backups at 30-day retention). Remove this note when O2 is verified; a lawyer should still confirm each window is lawful.
Children
RunTogether is intended for adults. You must be at least 18 years old to use it, and the service is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it and close the account. If you believe a child has provided us information, contact us at privacy@2gether.run and we will act promptly.
[DRAFTED — requires legal review] States the 18+ minimum consistent with the Terms. The app does not yet enforce an age gate at sign-up — that must be built for this statement to be true. A lawyer should confirm 18 (vs 13 with COPPA-compliant parental consent) and whether any children's-data law imposes further obligations.
Security
Access to data is enforced server-side by Firebase security rules rather than by the app alone: private profile fields and push tokens are readable only by their owner, quarantined files are readable by no member at all, and privileged information such as other members' email addresses is served only through checked server functions. Direct messages are readable only by the people who sent or received them, and by an organizer where you have reported a message or sent one for review. We use Firebase App Check to reject requests that do not come from the genuine RunTogether app or website.
[DRAFTED — requires legal review] LEGAL AUDIT issue 10, PENDING CODE — App Check only. The App Check sentence is NOT yet true: it runs in monitor mode, NEXT_PUBLIC_RECAPTCHA_SITE_KEY is commented out in apphosting.yaml, and no callable sets enforceAppCheck. The decision is to enable it properly (D10.1). THAT SENTENCE MAY NOT BE PUBLISHED until the fix ships — if App Check enforcement slips past submission, DELETE the sentence rather than ship it untrue. Issue 4 (direct messages) is RESOLVED: shipped and deployed 2026-08-11, so the direct-message sentence is now accurate — clubMessages and messageMedia both carry a recipient predicate, DM sends go through the sendDirectMessage callable, and rules-tests cover it. Remove this note once App Check lands.
Governing law and disputes
This policy and any dispute about how we handle your information are governed by the laws of the State of Florida, without regard to its conflict-of-laws rules, and the state and federal courts located in Pinellas County, Florida have exclusive jurisdiction. If you have a concern, please raise it with us first at privacy@2gether.run so we can try to resolve it directly. See our Terms of Service for how disputes about the service more generally are handled.
[DRAFTED — requires legal review] Governing law/venue set to Florida (Pinellas County), matching the Terms. A lawyer should confirm this is appropriate for a privacy policy and consistent with any mandatory forum or supervisory-authority rights that apply to users outside Florida (e.g. an EU/UK user's right to complain to their data-protection authority).
Changes to this policy
If we change this policy we will update the date at the top of this page.
Contact us
RunTogether LLC, 838 6th St N #2, St Petersburg, FL 33710. Email: privacy@2gether.run.
See also our Terms of Service.