SyncRun Privacy Policy
| Item | Detail |
|---|---|
| Document version | v1.6 |
| Effective date | 24 October 2026 |
| Last amended | 17 September 2026 |
This English text is a translation provided for your convenience. The Korean version is the authoritative original. If the two differ, the Korean version governs. Article numbers match the Korean original so that references line up across both versions.
SyncRun Labs (the "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly.
This Policy applies to the iOS and Android running application SyncRun (the "Service") provided by the Company.
The Company's business information is set out in Article 27 of the Terms of Service, and matters concerning the location-based service business filing in Article 16 of the Location-Based Services Terms. Enquiries and requests concerning personal information protection are received at contact@syncrunlabs.com.
Article 1 Purposes of Processing Personal Information
The Company processes personal information for the following purposes. Personal information processed is not used for purposes other than these, and where the purpose of use changes, the Company takes the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
Article 2 Items of Personal Information Processed
The Company processes the following items of personal information in order to provide the Service.
1. Items collected and processed on membership registration
| Category | Item | Method of collection | Required |
|---|---|---|---|
| Account | Apple sign-in identifier | Provided by Apple when using Sign in with Apple | Required |
| Account | Google sign-in identifier (sub) | Provided by Google when using Sign in with Google | Required |
| Account | Email address | Provided by Apple only on the first Sign in with Apple, and by Google when using Sign in with Google | Required |
| Account | User ID (UUID issued by the server) | Generated automatically by the server on joining | Required |
| Account | Device identifier (UUID generated by the app) | Generated automatically by the app on first launch | Required |
| Profile | Name (entered by the user; default "Runner") | Entered by the user | Required |
| Profile | Profile photo | Registered at the user's option | Optional |
The device identifier is a UUID generated by the app itself and is not Apple's advertising identifier (IDFA) or Google's advertising ID. The Company does not collect advertising identifiers.
Members sign in with an Apple account or a Google account. An account signed in with Apple and an account signed in with Google are separate accounts and are not linked into one, even where the email address is the same. Because there is no path for signing up or signing in with an email address and password, the Company does not collect passwords. The email address is merely the value Apple or Google provides on sign-in; it is not used as a means of signing in, and an account cannot be accessed by email.
The Company uses the email address it retains only for service notices — announcements of amendments to the terms and this Policy, service inspections, and material changes to the Service. Because the Company does not obtain consent to receive advertising under Article 50 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, it does not send advertising information.
Where a user selects "Hide My Email" when using Sign in with Apple, a private relay address created by Apple (@privaterelay.appleid.com) is provided instead. The Company retains and uses it in the same way as any other email address, and in that case cannot know the user's actual email address.
2. Items generated and collected in the course of using the Service
| Category | Item | Method of collection | Required |
|---|---|---|---|
| Run record | Distance, time, pace, cadence, elevation gain, 1 km splits | Generated automatically from device sensors and GPS during a run | Required |
| Run record | Route (normalised 0–1 coordinates) | Location measured during a run, normalised on the device | Required |
| Run record | Place name (neighbourhood level, result of reverse geocoding) | Reverse geocoding of the run location | Required |
| Run record | Run title | Generated automatically and editable by the user | Required |
| Location information | Live latitude and longitude during a run | Collected automatically by device GPS | Required |
| Location information | Latitude and longitude while waiting to bump (while the group formation screen is open) | Collected automatically by device GPS | Required |
| Run record | Run card background photo | Chosen by the user in the Photos app | Optional |
| Sensitive information | Heart rate (average heart rate) | Collected via HealthKit from Apple Watch or heart-rate-capable earbuds | Optional |
| Technical information | Push token (APNs device token or FCM registration token) | Collected automatically when notification permission is granted | Optional |
| Usage record | Consent history (item consented to, document version, time of consent or withdrawal) | Recorded automatically on the consent screen | Required |
| Usage record | App settings (voice guidance, privacy defaults, step-distance calibration factor, notices read, list sorting and statistics period) | Set by the user and calculated automatically during runs | Required |
The route stored on the server as part of a run record consists of coordinates normalised to values between 0 and 1; actual latitude and longitude are not stored on the server. Place names are recorded only at the neighbourhood (dong) level. Users cannot lower these standards in settings.
A run card background photo is collected only where the user chooses one in the Photos app, and is kept with that run record. The purpose is to keep the card intact if you change device or delete and reinstall the app. If you do not choose a photo, none is collected, and not choosing one places no restriction on any other feature.
Consent history records, item by item, which version of which legal document you consented to, or withdrew consent from, and when. It is retained in order to confirm that the consents required by the Personal Information Protection Act and the Act on the Protection and Use of Location Information were actually obtained, and to determine who must be asked for what again when the documents are amended. Entries accumulate rather than being overwritten, so withdrawals of consent are also retained.
The step-distance calibration factor is a multiplier updated each run in order to reconcile the distance measured by steps with actual distance travelled where the location signal has been lost. The value itself is a number between 0.75 and 1.25 and is not used as body-related information.
3. How live location information is processed
The Service uses live latitude and longitude in two cases — during a run and while waiting to bump — each processed on a limited basis as follows. In both cases the data exists only in server memory, is not stored in a database, and coordinates are not written to logs.
During a run, the data is processed as follows.
While waiting to bump (while the group formation screen is open), the data is processed as follows.
Detailed matters concerning the collection, use and provision of location information are set out in the separate Location-Based Services Terms, and the Company complies with the Act on the Protection and Use of Location Information.
4. Processing of sensitive information
The Company processes the following as sensitive information under Article 23 of the Personal Information Protection Act.
| Sensitive item | Purpose | Retention and use period | Basis for collection |
|---|---|---|---|
| Heart rate (health information) | Calculating and storing the average heart rate of a run record, displaying metrics during a run, voice guidance | Until withdrawal of membership | Separate consent of the data subject |
5. Unique identifying information
The Company does not process any unique identifying information under Article 24 of the Personal Information Protection Act, such as resident registration numbers, passport numbers, driver's licence numbers or alien registration numbers.
Article 3 Period of Processing and Retention of Personal Information
| Item | Retention and use period |
|---|---|
| Account information (Apple or Google sign-in identifier, email address, user ID, device identifier) | Until withdrawal of membership |
| Profile information (name, profile photo) | Until withdrawal of membership |
| Run records (distance, time, pace, cadence, elevation, splits, normalised route, place name, title) | Until withdrawal of membership |
| Run card background photos | Until withdrawal of membership, deletion of that record, or removal of the photo by the user |
| Consent history (item, document version, time) | Until withdrawal of membership |
| App settings (including the step-distance calibration factor) | Until withdrawal of membership |
| Heart rate (average heart rate) | Until withdrawal of membership |
| Push token (APNs or FCM) | Until withdrawal of membership or withdrawal of notification permission |
| Live latitude and longitude during a run | Erased immediately when the session ends (held only in server memory, not stored in a database) |
| Latitude and longitude while waiting to bump | Erased immediately on leaving the group formation screen; erased automatically within 45 seconds if updates stop (held only in server memory, not stored in a database) |
| Records confirming use and provision of location information | Six months (Article 16(2) of the Act on the Protection and Use of Location Information). The time from which these are recorded is set out in Article 5 of the Location-Based Services Terms |
| Legal basis | Item preserved | Preservation period |
|---|---|---|
| Article 16(2) of the Act on the Protection and Use of Location Information | Records confirming use and provision of location information | Six months |
| Act on Consumer Protection in Electronic Commerce | Records on consumer complaints or dispute handling | Three years |
| Protection of Communications Secrets Act | Service use log records | Three months |
Article 4 Provision of Personal Information to Third Parties
| Recipient | Purpose | Items provided | When and how | Retention and use period |
|---|---|---|---|---|
| Participants of the same running session | To see one another's location and progress during a group run | Live location (latitude and longitude), distance, pace, name and profile photo during the run | Relayed in real time while the group run session is in progress | Provision stops when the session ends |
| Users waiting nearby to bump | To identify each other as bump partners and, where automatic formation does not occur, to request and accept joining | Display name and profile photo (location and distance are not provided) | While both users have the group formation screen open | Provision stops immediately on leaving the screen |
Article 5 Entrustment of Personal Information Processing
| Trustee | Entrusted work | Server location | Retention and use period |
|---|---|---|---|
| Google Cloud Korea, LLC | Operation of server infrastructure (application server, database and image store) and data storage | Republic of Korea (Seoul) | Until withdrawal of membership or termination of the entrustment agreement |
| Apple Inc. | Sending push notifications (APNs), Sign in with Apple authentication | United States | Until withdrawal of membership or termination of the entrustment agreement |
| Google LLC | Sign in with Google authentication, sending push notifications (FCM) | United States | Until withdrawal of membership or termination of the entrustment agreement |
Article 5-2 Transfer of Personal Information Abroad
| Item | Detail |
|---|---|
| Recipient | Apple Inc. |
| Contact | https://www.apple.com/legal/privacy/contact/ |
| Country of transfer | United States |
| Time and method of transfer | Transmitted from time to time over the information and communications network (HTTPS) at the time of sign-in and of sending notifications |
| Items transferred | Apple sign-in identifier, push token (APNs device token) |
| Purpose of use | Sign in with Apple authentication, sending push notifications |
| Retention and use period | Until withdrawal of membership or termination of the entrustment agreement |
| Item | Detail |
|---|---|
| Recipient | Google LLC |
| Contact | https://support.google.com/policies/contact/general_privacy_form |
| Country of transfer | United States |
| Time and method of transfer | Transmitted from time to time over the information and communications network (HTTPS) at the time of sending notifications |
| Items transferred | Push token (FCM registration token) |
| Purpose of use | Sending push notifications |
| Retention and use period | Until withdrawal of membership or termination of the entrustment agreement |
Article 6 Procedure and Method of Destroying Personal Information
Where personal information becomes unnecessary — because the retention period has elapsed, the purpose of processing has been achieved and the like — the Company destroys it without delay.
1. Destruction procedure
2. Destruction method
Article 7 Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
Article 8 Measures to Ensure the Safety of Personal Information
In accordance with Article 29 of the Personal Information Protection Act and Article 30 of its Enforcement Decree, the Company takes the following measures.
1. Administrative measures
2. Technical measures
3. Physical measures
Article 9 Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof
The Company does not install or operate devices that automatically collect user information, such as cookies or web beacons.
The Service is provided as a mobile application and does not use online behavioural advertising tools or third-party advertising or analytics SDKs that collect users' behavioural information. Accordingly, there is no separate method of refusing automatic collection devices.
Article 10 Processing of Personal Information of Children Under 14
Article 11 Personal Information Protection Officer
The Company designates a personal information protection officer as follows, who has overall responsibility for work concerning the processing of personal information and for handling data subjects' complaints and providing remedies in relation to personal information processing.
| Item | Detail |
|---|---|
| Name | Changmok Lee |
| Position | Representative |
| contact@syncrunlabs.com |
Data subjects may direct enquiries, complaints and requests for remedies concerning personal information protection to the contact above. The Company will answer and deal with them without delay.
Article 12 Department Receiving and Handling Requests for Access to Personal Information
Data subjects may make requests for access to personal information under Article 35 of the Personal Information Protection Act to the department below. The Company will endeavour to process such requests promptly.
| Item | Detail |
|---|---|
| Responsible | SyncRun personal information access request desk |
| contact@syncrunlabs.com |
Access to, correction and deletion of the profile and run records, and withdrawal of membership, can be done directly in the Me tab of the app; other access requests are received at the email address above.
Article 13 Remedies for Infringement of Rights
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Privacy Infringement Report Centre of the Korea Internet & Security Agency and the like, in order to obtain relief from infringement of personal information. For other reports of and consultation on privacy infringement, please contact the bodies below.
| Body | Role | Telephone | Website |
|---|---|---|---|
| Personal Information Dispute Mediation Committee | Applications for personal information dispute mediation and collective dispute mediation (civil resolution) | 1833-6972 (no area code) | www.kopico.go.kr |
| Privacy Infringement Report Centre (KISA) | Reports of and requests for consultation on privacy infringement | 118 (no area code) | privacy.kisa.or.kr |
| Cybercrime Investigation Division, Supreme Prosecutors' Office | Investigation of privacy infringement cases | 1301 (no area code) | www.spo.go.kr |
| Cyber Investigation Bureau, National Office of Investigation, Korean National Police Agency | Investigation of privacy infringement cases | 182 (no area code) | ecrm.cyber.go.kr |
In addition, a person whose rights or interests are infringed by a disposition or omission of the head of a public institution in respect of a request under Article 35 (access), Article 36 (correction or deletion) or Article 37 (suspension of processing) of the Personal Information Protection Act may request an administrative appeal as prescribed by the Administrative Appeals Act.
Article 14 Guidance on App Access Permissions
In accordance with Article 22-2 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Company designates as mandatory only the minimum access permissions necessary to provide the Service, and designates other permissions as optional so that users can use the basic features of the Service even without granting them.
1. Mandatory access permissions
| Permission | Purpose |
|---|---|
| Location | To measure distance and route during a run, to share live location with participants within a group run session, and to find users waiting nearby to bump |
| Motion and physical activity | To read steps and movement in order to measure pace and cadence, and to measure by steps the distance travelled where the location signal has been lost |
2. Optional access permissions
| Permission | Purpose | If not granted |
|---|---|---|
| Notifications | Sending notifications needed during a run, such as the last-runner alert and inactivity check | Those notifications cannot be received; other features work normally |
| Health | Reading heart rate and saving completed runs as workouts | Heart rate is not recorded, but runs can still be measured on the basis of distance and pace. Heart rate is not a prerequisite for any feature |
| Photos | Setting the profile photo and run card background, and saving run card images | The profile photo and card background cannot be set, and cards cannot be saved to the Photos app |
| Nearby Interaction | Precise distance determination (UWB) when tapping phones together to form a group | Automatic bumping is unavailable. A group can still be formed by requesting to join a nearby waiting user |
3. Processing of photos
Of the images loaded through the Photos permission, only those the user sets as a profile photo or as a run card background are kept on the servers. A profile photo is kept so that it can be restored on reinstallation or re-sign-in and shown to companions; a card background photo is kept so that the card survives a change of device or a reinstallation. No other image leaves the device.
A card background photo is provided only to the person who created that record, and not to other users. If the user removes the photo from the card, it is also deleted from the store.
4. How to withdraw permissions
Users may change or withdraw each access permission at any time in the device settings (iOS: Settings > Privacy & Security, or Settings > SyncRun; Android: Settings > Apps > SyncRun > Permissions).
Article 15 Changes to this Privacy Policy
| Version | Effective date | Notes |
|---|---|---|
| v1.6 | 24 October 2026 | Reflects the items collected, trustees, transfers abroad and app access permissions arising from Google sign-in and the Android app |
| v1.5 | 17 October 2026 | Reflects the retention in the account of run card background photos, consent history and app settings |
| v1.4 | 16 September 2026 | Change of server infrastructure trustee and country of storage (Seoul, Republic of Korea); correction of transfer-abroad details |
| v1.3 | 10 September 2026 | Statement of the operating entity and business information, and the name of the personal information protection officer |
| v1.0–v1.2 | 6 August 2026 – 28 August 2026 | Establishment and amendments during the free beta test period |
Addendum
This Privacy Policy takes effect on 24 October 2026 and replaces the previous Policy (effective 17 October 2026).
SyncRun Labs Sole proprietorship · Representative Changmok Lee · Business registration number 656-09-03142 32 Daehak-ro 8-gil, Gyeongsan-si, Gyeongsangbuk-do, Republic of Korea Contact: contact@syncrunlabs.com
