Privacy Policy.

Effective date · July 18, 2026

Namio Run (“we”, “our”, “the app”) is a running app that matches music to your cadence. This policy explains what data we collect, how we use it, and your rights.

1. Data Controller

Namio Tech Ltd is the data controller responsible for the processing of personal data described in this policy. For any questions about how your data is handled, contact us at hello@namiotech.com.

2. Information We Collect

Account information.When you sign in with Google or Apple, we receive your name (or a name you choose to share), your email address (or, if you use Apple's Hide My Email, a private relay address that forwards to you), and a unique identifier. We use this to create and manage your account.

Workout and fitness data. The app stores workouts you create, workout sessions you complete (duration, timestamps), and cadence observations (steps per minute). This data powers workout recommendations and tracks your progress.

Music preferences. We store your playlist configurations, volume settings, track play history, and skipped or excluded tracks. This helps us match music to your running cadence.

App preferences. Settings such as measurement units, metronome mode, and onboarding progress are stored to personalize your experience.

3. Legal Basis for Processing

We process personal data to provide and improve the Namio Run service. The legal bases for processing include:

  • Performance of a contract– to create and manage your account and provide the core functionality of the app.
  • Legitimate interests– to analyze app usage, improve features, and maintain service reliability.
  • Legal obligations– where required by applicable law.

4. How We Store Your Data

Your data is stored in two places:

  • On your device using a local database. This is the primary copy of your data and works offline.
  • In the cloud using Google Firebase (Firestore). This enables syncing across devices and data backup.

All cloud data is stored under your unique user account and is not accessible to other users.

Some data may be processed on servers located outside the United Kingdom or European Economic Area by our service providers. These providers operate under appropriate safeguards such as Standard Contractual Clauses.

5. Third-Party Services

We use the following third-party services:

  • Firebase Authentication– to manage sign-in via Google.
  • Sign in with Apple– to manage sign-in via Apple. If you use Apple's Hide My Email feature, we receive a private relay address instead of your real email.
  • Cloud Firestore– to store and sync your data securely.
  • Firebase Storage– to store and deliver audio files.
  • Firebase Analytics– to understand how the app is used (e.g., which features are popular, workout completion rates). Analytics data is used solely to improve the app and is not sold to third parties.
  • Firebase Crashlytics– to collect crash reports so we can fix bugs. Crash reports may include your device model, OS version, and app state at the time of the crash.

These services are governed by Google's Privacy Policy.

In addition to the services listed above, we may use trusted third-party service providers to help us operate, analyze, and improve the app, for example analytics and data-analysis tools. These providers process personal data only on our instructions, under appropriate safeguards and data processing agreements, and are not permitted to use it for their own purposes.

6. Workout Sharing

If you share a workout, the following information is made available to anyone with the share link: workout name, description, category, duration, and structure. Your display name is attached as the creator. No other personal data is shared.

7. Website Analytics

This section applies when you visit the Namio website (namiorun.com).

Analytics cookies. We use Google Analytics 4 to understand aggregate website usage (pageviews, traffic sources, country, device type). Analytics storage is denied by default, so until you accept our cookie banner Google receives only anonymous, aggregated pings with no cookies set on your browser. If you accept the cookie banner, Google Analytics sets cookies that let us measure return visits and conversions across your sessions. We anonymize IP addresses, do not collect advertising or remarketing signals, and do not share data with Google Ads. You can decline, or change your mind, at any time via the banner.

Legal basis for analytics. For the default, cookieless aggregated pings, our legitimate interest in understanding website traffic to improve the site. For analytics cookies, your consent, which you give through the cookie banner and may withdraw at any time.

Advertising measurement.Some visits reach the site through an ad link (for example, from Reddit). When you arrive this way, our server records which campaign the link belonged to, the ad network's click identifier, and the time of the visit. We do not store your IP address or any other information that identifies you, and this is not used to build a profile of you or to serve you ads. We use it only to count how many visits each ad brings and to spot invalid or automated (“bot”) clicks, on the basis of our legitimate interest in measuring our advertising.

Aggregate funnel measurement.To see how visitors move through the site, we keep anonymous, aggregate counts of how many browsers reach each stage (page loads, opening the download options, and clicking through to an app store) for each marketing campaign, along with a coarse browser category (for example, whether a visit arrived through an app's in-built browser). These are simple counters. We set no cookie, store no identifier, no IP address, and no device or browser fingerprint; the browser category is worked out on our server and the underlying user-agent is discarded immediately. Because this is anonymous aggregate statistics that cannot identify you, it relies on our legitimate interest and does not require your consent.

On-page engagement.If you accept our cookie banner, then for visits that arrive through an ad link we also measure how long the page is actually visible to you, sent from your browser to our own server, so we can tell whether ad traffic is genuine. It uses a random identifier held only in your browser's memory for that visit, with no cookie and nothing that identifies you personally. If you decline, we do not measure this.

Browser storage.If you accept our cookie banner, we store the source of your visit (such as a campaign tag) in your browser's session storage, so a later app-store click can be attributed to the right source. This is first-party and is cleared when you close the tab. If you decline, we do not store it.

Beta signup form (retired). The website previously offered an email signup for the beta. That form has been removed and the site no longer collects your email — the app is now available on Google Play and Apple TestFlight, and any account you create is covered by the sections above. If you signed up while the form was live, your email was stored in a Cloud Firestore database controlled by Namio Tech Ltd (see Section 5); you can request its deletion at any time by emailing hello@namiotech.com with the subject “Beta Signup Deletion Request”.

8. What We Do Not Do

  • We do not sell your personal data to third parties.
  • We do not serve advertisements.
  • We do not collect location data.
  • We do not access your contacts, camera, or microphone.

9. Your Rights

Under applicable data protection laws, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request restriction of processing
  • Receive a copy of your data in portable form
  • Object to certain processing activities

You can exercise these rights by contacting us at hello@namiotech.com.

10. Data Retention and Deletion

Your data is retained as long as you have an active account. You can delete your account and all associated data using either of the following methods:

  • In the app:Go to Settings, scroll to the Account section, and tap “Delete account”.
  • By email: Send a request to hello@namiotech.com with the subject “Account Deletion Request”.

When your account is deleted, all your cloud data (including workouts, sessions, preferences, and music data) is permanently removed from our servers within a reasonable period.

11. Security

We implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, or misuse.

12. Children's Privacy

Namio Run is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Changes to This Policy

We may update this policy from time to time. If we make significant changes, we will notify you through the app or by updating the effective date above.

14. Contact Us

If you have questions about this privacy policy or your data, contact us at:

hello@namiotech.com

Namio Run is developed by Namio Tech Ltd.