Privacy Policy
Perunika reads your health and location data. This page describes exactly what we take, where it goes, and who can see it — in enough detail that you can check our work.
The short version.
- We read workouts, heart rate and GPS routes from Apple Health, and upload them to our servers so your friends can see your activity.
- There are no analytics SDKs, no ad networks, no trackers, and no data brokers anywhere in Perunika. We have never sold data and the code contains nothing capable of it.
- Your feed is visible to accepted friends. Some summary figures are visible to any signed-in Perunika user — see Who can see your data, which is the section most worth reading.
- Everything is stored in the EU (Frankfurt).
- Account deletion is not yet self-serve. Email us and we will do it — see Your rights.
- Who we are
- Apple Health and fitness data
- Location
- Account information
- Photos, video and everything you write
- Device and diagnostic information
- What we never do
- Who can see your data
- Companies that process data for us
- Where your data is stored
- How long we keep it
- Your rights and choices
- Children
- Changes to this policy
- Contact
1. Who we are
Perunika is operated by RUBYNESS LTD, a private limited company registered in Scotland under company number SC729112, whose registered office is 272 Bath Street, Glasgow, Scotland, G2 4JR. For data protection purposes we are the controller of the personal data described here. You can reach us at hello@perunika.app.
Perunika is currently a beta. This policy describes the app as it exists today, and we will update it as the app changes.
2. Apple Health and fitness data
With your permission, Perunika reads the following from Apple Health: workouts, workout GPS routes, heart rate, walking and running distance, cycling distance, step count (used to calculate cadence) and active energy burned.
Perunika never writes anything to Apple Health. The permission is read-only.
What we upload to our servers
This is the part people usually assume stays on the phone, so we want to be plain about it. When you are signed in, Perunika automatically syncs your recent workouts — the first sync covers the previous 180 days. For each workout we upload:
- Activity type, start and end time, and duration
- Distance and active energy burned
- Average, maximum and minimum heart rate, plus a heart-rate series of up to 200 points across the workout
- Elevation gain and loss, plus up to 200 elevation samples
- Per-kilometre splits — pace, average heart rate, elevation change
- Your GPS route — up to 300 points of latitude, longitude, altitude and timestamp
- The name of the device or app that recorded the workout, such as "Apple Watch"
- The workout's Apple Health identifier, so we do not import the same workout twice
Route points are reduced in number but not blurred or rounded. They are the real coordinates, and they describe where you ran.
What stays on your device
Cadence and step counts, heart-rate zone breakdowns, and your weekly, yearly and streak summaries are calculated on your phone and are never sent to us.
3. Location
Perunika requests "while using the app" location access only. We never request background or always-on location, and the app does not track you as you move. Each time location is used, it is a single reading taken at roughly 100-metre accuracy, and only ever in response to something you tapped.
We upload location when you:
- Sync a workout — the GPS route described above, from Apple Health
- Tag a post — coordinates and a place name
- Check in to a quest — coordinates, place name, time and timezone, shared with your partner
- Set a location chip in the Together / Orbit view — coordinates and a label, shared with your partner and refreshed for weather
To turn coordinates into place names, and to draw route maps, the app uses Apple's geocoding and Apple Maps. That is a request to Apple, governed by Apple's privacy policy.
You can revoke location access at any time in iOS Settings ▸ Privacy & Security ▸ Location Services. Features that need it will stop working; nothing else will break.
4. Account information
You sign in with Sign in with Apple. Apple sends us an identity token that we verify, and from it we store your Apple user identifier, your email address, and the name you chose to share — recorded once, when your account is first created.
If you use Apple's Hide My Email, we only ever receive the relay address, and that is all we store. We never see your real address.
Alongside this we store your display name, your handle, and preferences such as your avatar colour, mood, timezone and palm colour.
5. Photos, video and everything you write
Perunika stores what you create in it: photos and videos attached to workouts, posts, stories and quest check-ins; the "circle videos" you record for check-ins; your avatar; comments, captions, notes and messages; and the music tracks you share, including the track title, artist and link.
The camera and microphone are used only while you are recording. Photos are chosen through Apple's system picker, which means Perunika never gets access to your photo library — only to the specific items you pick.
Media files are stored privately and served through links that expire. They are not publicly listed or browsable.
6. Device and diagnostic information
When a photo or video upload finishes or fails, the app sends us a diagnostic record so we can
fix upload problems: your app version and build, your device model (for
example iPhone15,2), your iOS version, and technical details of the file such as
its size, dimensions and codec. These records contain no location data.
This goes to our own servers. It is not an analytics product, and it is not shared with anyone.
7. What we never do
Perunika contains no third-party SDKs of any kind. There is no Google Analytics, no Firebase, no Facebook SDK, no Sentry or Crashlytics, no attribution or advertising framework. The app talks to our servers, to Apple, and to nothing else.
- We do not sell or rent your personal data. We never have.
- We do not share Apple Health data with advertisers, data brokers, insurers or employers — and Apple's rules forbid it.
- We do not use your data to build advertising profiles or to train machine-learning models.
- We do not track you across other apps or websites, and we ask for no tracking permission.
- The website you are reading uses no cookies and no analytics.
8. Who can see your data
This is the section that matters most, so please read it rather than assuming.
Accepted friends
People whose friend requests you have accepted see your activity feed: your workouts — including your GPS routes — your trainings, posts, photos, videos, reactions and comments.
Your pair partner
If you are paired with someone in the Together features, they see what those features exist to share: your location chip, mood, weather, what you are listening to, stories, quest check-ins with their coordinates and notes, schedules and challenges.
Any signed-in Perunika user
Some summary figures are not limited to friends. Any signed-in Perunika user who knows your handle can see your total distance, total time, streak, distance this week and month, your activity calendar, and your personal records. They cannot see your routes, your media or your posts.
We are telling you this because "private by default" could reasonably be read as meaning otherwise. We intend to bring this behind the friends check.
Anyone with a share link
If you create a share link for an activity, that page is public to anyone who has the URL, with no sign-in. It shows your display name, avatar, the date and time, distance, duration, pace, your average heart rate, and the first attached photo or video. It does not show your route.
You can revoke a share link in the app. Note that a preview image link already generated for that page can remain valid for up to 30 days after revocation — if a page has been shared somewhere sensitive, deleting the underlying activity is the reliable fix.
Invite links of the form /i/yourhandle show your display name to anyone who opens
them.
Us
Our administrators can access accounts to support and debug the service. We do this when there is a reason to, not routinely.
9. Companies that process data for us
We use as few as we can. In full:
- Amazon Web Services — hosting, database and media storage, in Frankfurt. All of the data described above sits here.
- Apple Push Notification service — delivers your notifications. Because a notification shows you what happened, its content passes through Apple: this includes display names, the text of comments and messages (up to about 160 characters), check-in place names, and music titles.
- Apple — sign-in verification, geocoding and map tiles, as described above.
- Open-Meteo — when you set a location chip, we send those coordinates to Open-Meteo to fetch the weather, and refresh it while the chip is active. No name or account identifier is sent with it.
- The service a shared music link points to (for example YouTube or Spotify) — we fetch the track's title and artwork from them. No user identifier is sent.
- OpenStreetMap — when you open a route map on the website (not in the app), your browser loads map tiles from OpenStreetMap and a map library from a public code host, which necessarily reveals your IP address to them.
We use no other processors. There is no email provider, because Perunika sends no automated email.
10. Where your data is stored
Your account, activities and media are stored in the European Union, in Frankfurt (AWS eu-central-1). Some of the processors above are based outside the EU, and data sent to them is transferred under the safeguards their own agreements provide.
11. How long we keep it
We keep your account data and your activities for as long as your account exists. We are not currently running automatic deletion of old activity data, so assume that what you upload stays until you or we delete it.
Two things are cleaned up automatically:
- The original file of a video is deleted 30 days after a compressed copy is made.
- Weather readings attached to a location chip are discarded within about a day.
You can delete individual posts, activities, comments, photos, videos and your avatar in the app at any time. Deleting media removes the underlying file.
12. Your rights and choices
Depending on where you live, you have rights to access, correct, delete, export, restrict or object to our use of your personal data, and to complain to your data protection authority. Under the GDPR we rely on your consent for Apple Health and location data — which you can withdraw at any time in iOS Settings — and on our legitimate interest in operating a working, secure service for the rest.
Deleting your account. Perunika does not yet have a delete-account button. Until it does, email hello@perunika.app from the address on your account, or tell us your handle, and we will delete your account and its data. We aim to do this within 30 days. We are building the in-app version; this is a gap, not a policy.
To exercise any other right, email us at the same address. We will not charge you or make it difficult.
You can also switch off Perunika's access to Apple Health (Settings ▸ Health ▸ Data Access & Devices), location, camera, microphone or notifications at any time, without deleting your account.
13. Children
Perunika is not intended for children. You must be at least 16 to use it. We do not knowingly collect data from anyone under that age; if we learn that we have, we will delete it. If you believe a child has given us data, contact us and we will act.
14. Changes to this policy
We will update this page as Perunika changes, and the date at the top will change with it. If a change materially affects what we collect or who can see it, we will make a reasonable effort to tell you in the app or by email before it takes effect.
15. Contact
Questions, requests, or anything about this policy that does not match what you observe in the app: hello@perunika.app
RUBYNESS LTD
Registered in Scotland, company number SC729112
272 Bath Street, Glasgow, Scotland, G2 4JR