01
Introduction
This Privacy Policy describes how Ooi Aik Keat, the individual operator of RunStart in Malaysia (referred to as “RunStart,” “we,” “us,” or “our”), handles information in connection with the RunStart iPhone application, the website at runstart.creolab.space, and support communications.
This Policy applies from August 19, 2026. It should be read together with the RunStart Terms of Service.
02
Information RunStart uses
RunStart uses information needed to set up alarms, verify active walking or running missions, show mission history, remember app preferences, and determine access to the first free completed RunStart and subscription features.
Core app information is primarily processed and stored locally on your iPhone. RunStart does not currently operate an account system, backend server, remote database, or cloud-synchronization service. Information that remains on your device is not available to us merely because the app processes it.
03
Information you provide
During setup and use, you may provide a name, onboarding responses about your running intentions and starting habits, preferred distance and measurement unit, commitment selections, alarm choices, and related setup preferences. RunStart also creates local state showing your onboarding progress, whether your first free completed RunStart has been used, and whether certain app or subscription screens have been shown.
This information is used locally to personalize the app, continue setup, select mission targets, and apply access rules. RunStart does not upload these onboarding responses or preferences to a RunStart-operated server.
04
Precise location information
With your permission, RunStart uses precise location during an eligible active mission to measure distance and assess whether movement is consistent with walking or running. Location readings may include latitude, longitude, accuracy, time, and available speed information. RunStart may operate mission-related location tracking in the background while an active mission is underway, such as when the app is not on screen or the iPhone is locked.
Raw location readings and location-derived verification state are processed locally as part of the current mission. Tracking stops when no eligible mission remains, the mission reaches a terminal state or expires, required permission is lost, or the implemented tracking lifecycle otherwise ends.
RunStart does not continuously track location outside eligible missions. Raw coordinates are not copied into completed or missed mission history. Archived history does not contain a route map or continuous GPS track; it retains only the derived mission information described in section 7.
05
Motion & Fitness information
With your permission, RunStart uses Apple Motion & Fitness information through Core Motion, including pedometer and recent-movement evidence, while verifying an active mission. This helps distinguish walking or running from stationary GPS drift or vehicle-like movement.
RunStart uses derived movement evidence locally with mission location readings. Native in-memory samples are cleared when tracking stops, and motion evidence attached to raw active-mission points is not copied into archived mission history. RunStart does not use Apple HealthKit.
06
Alarm, schedule, and mission information
RunStart stores the information needed to provide alarms and missions, including schedule times and recurrence, alarm and configuration identifiers, whether a schedule is enabled, selected target distance and unit, mission state, timing, pause state, accepted distance, GPS-quality and verification state, and related local processing identifiers.
AlarmKit and RunStart’s native alarm storage keep device-local alarm definitions and pending alarm actions so the app and iOS can reconcile what should occur. This information is used to schedule alarms, handle actions such as starting or pausing, prevent duplicate handling, maintain the fixed mission window, and determine completion or a missed mission.
07
Mission history
When a non-demo mission is completed or missed, RunStart stores a derived local history record. This may include the mission and alarm identifiers, scheduled and trigger times, completed or missed outcome, target and accepted distance, distance unit, pause count, mission or movement start time, completion or missed time, duration, and start delay.
Archived history does not retain raw latitude, longitude, speed, accuracy, or other raw location points. It is used to show your history, calculate local completion information, and record the first completed RunStart. History currently has no in-app delete or export control.
08
Subscriptions and Apple StoreKit
RunStart uses Apple StoreKit and the App Store for subscription offerings, purchases, trials, renewals, entitlement checks, restoration, and subscription management. Depending on what Apple makes available, RunStart can receive limited product, transaction, entitlement, trial-eligibility, expiration, revocation, and purchase-status information needed to present an offer or provide subscription access.
Apple handles App Store transactions under Apple’s own terms and privacy policy. RunStart does not receive your payment-card number, bank-account details, or other payment credentials. Subscription entitlement is obtained from Apple separately from RunStart’s local mission and first-free records.
09
Alarms and notifications
RunStart uses Apple AlarmKit for its alarm functionality. If you separately allow ordinary notifications, RunStart may also schedule optional local trial or re-engagement reminders. Local notification details and a pending tap response may be held by iOS or in local app storage so reminders can be scheduled, cancelled, or handled.
RunStart does not operate a remote push-notification server and does not register or collect a remote push token in the audited launch implementation. You can change alarm and notification permissions in iOS Settings. Delivery depends on Apple’s operating system and device conditions and is not guaranteed.
10
Analytics, advertising, and tracking
The launch version of RunStart does not include a production analytics SDK, third-party behavioral analytics, crash-reporting SDK, advertising SDK, or advertising-attribution SDK. It does not use the advertising identifier and does not request App Tracking Transparency permission.
RunStart does not use app information for cross-app advertising or tracking. If these practices change in a future version, this Policy and any required App Store disclosures will need to be updated before or when the change applies.
11
How information is stored
RunStart’s application data is stored mainly in the app’s local iOS container using AsyncStorage and native UserDefaults. This includes onboarding and preferences, schedule and alarm state, active mission state, derived history, first-free and paywall state, local reminder state, and bounded native alarm or notification records.
RunStart has no operated backend, remote database, cloud synchronization, or account system. It therefore does not provide server backup, cross-device synchronization, account deletion, or remote deletion of app data. Apple’s backup, restore, offload, and device-migration systems may affect whether particular local data remains or returns.
13
Data retention
Local app data generally remains on your device while the app and its data remain installed, unless it is overwritten or removed through normal app operation, an update, device settings, deletion, backup or restore, offloading, migration, or other iOS behavior. RunStart does not apply an artificial fixed retention period to all local records.
Location and motion samples are used for active mission verification. Native in-memory sample buffers are cleared when tracking stops, and raw coordinates are not retained in archived history. Derived mission history and onboarding, preference, first-free, and schedule state may remain locally without a fixed expiry.
Deleting the app is expected to remove app-related local data in the ordinary iOS case. Offloading may retain documents and data, and backups or device restoration may affect what returns. RunStart cannot guarantee deletion from every Apple backup or migration scenario.
Support correspondence may be retained for as long as reasonably necessary to respond, maintain appropriate records, handle disputes, or meet legal obligations. Website-hosting technical information is retained according to the deployed provider configuration and applicable provider terms; RunStart does not state a fixed Vercel log period before that configuration is verified.
14
Your choices and rights
You can choose whether to provide onboarding responses and whether to grant Alarm, Precise Location, Motion & Fitness, and ordinary notification permissions. Required permissions must remain available for features that depend on them. You can change permissions in iOS Settings, delete an eligible alarm configuration in RunStart, and manage an Apple subscription through your Apple Account.
RunStart currently does not provide Delete All Data, Clear History, data export, account deletion, cloud backup, or remote deletion features. You may delete the app using iOS controls, subject to the offload, backup, restore, and migration limits described above.
Applicable law may give you rights concerning information that the operator actually holds, such as support correspondence. You may contact us to make a request. Because local app information is not transmitted to a RunStart server and there is no account, we generally cannot remotely identify, access, export, correct, or delete information that exists only on your device.
15
Children and minors
RunStart is intended for users aged 13 or older. If you are below the age of majority where you live, you should use RunStart only with permission from a parent or legal guardian.
RunStart does not ask for a date of birth, perform age verification, or provide a parental-consent workflow. If you believe a person under 13 has sent personal information to the operator through support email, contact us so the situation can be reviewed.
16
Website privacy
runstart.creolab.space is a static website. RunStart does not intentionally set website cookies and does not use website analytics, forms, third-party embeds, Vercel Web Analytics, or Log Drains in the intended launch configuration.
The website host may still process ordinary technical request and security information needed to deliver the site, such as an IP address, user agent, requested path, time, response status, cache information, and request identifiers, depending on the deployed configuration. Browser history and caching are controlled by your browser and device.
The support link opens your configured email service. Information you voluntarily send—including your email address, message, device or iOS details, and attachments—is used to respond to and manage the support request. Do not send information that is not needed for support.
17
Security
RunStart limits its current architecture by keeping core app information in the normal iOS app container, using Apple permission controls for sensors, and avoiding an app-operated backend for that data. The website uses browser security headers intended to reduce certain web risks.
No storage or transmission method is completely secure. RunStart does not claim that local information is protected by separate app-layer encryption, and device, email, Apple, and hosting security also depend on the relevant systems and providers. Protect your iPhone, Apple Account, and email account with appropriate device and account security.
18
International use and applicable rights
RunStart is operated from Malaysia and is available only where offered through the Apple App Store. Apple, Vercel, and email providers may process information in countries other than your own under their services and policies.
This Policy is intended to preserve rights and protections that apply under Malaysian personal-data law and other mandatory law. Depending on where RunStart is offered and your circumstances, you may have additional rights that cannot lawfully be limited by this Policy. Contact us if you have a privacy question or request concerning information the operator holds.
19
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in RunStart, legal requirements, or provider practices. The updated version will be posted on this page with a revised effective date.
For material changes, RunStart may provide reasonable additional notice through the app, website, or another appropriate method where required.
20
Contact
For privacy questions or requests, contact:
Ooi Aik Keat Operator of RunStart Malaysia Email: support@creolab.space Website: runstart.creolab.space