Privacy Policy

Last updated: September 8, 2026

Article 1 (Controller and purposes)

Meongstore processes information necessary for RUNTORY account authentication, running records, pet/challenge/badge gameplay, friends, account backup and restore, subscriptions, advertising for free users, support and legal obligations. Firebase Authentication is the current remote account authority. Both iOS and Android support direct Sign in with Apple and Google sign-in as Firebase authentication methods. Cloud Firestore handles remote profile, Friends and structured backup data; Cloud Storage for Firebase handles large route/photo backup assets; Cloud Functions for Firebase performs sensitive server operations.

Article 2 (Data processed)

  • Firebase-based RUNTORY user identifier; Apple/Google sign-in identifiers; email/display name when provided
  • required-consent version, time and language, and 14+ confirmation
  • public friend display name, friend code, requests/relations and weekly running aggregates
  • precise location, completed-run GPS coordinates/order/timestamps, distance, duration, pace, calories, motion and step data
  • record photos selected by the user and app-managed copies
  • pet, egg, challenge, ticket, inventory, badge, quest, settings and backup data
  • subscription products, StoreKit/Google Play transaction/verification state, account-binding references and Plus entitlement state
  • Firebase App Check and other integrity/security proof or server-request information
  • ad privacy state and app/device/SDK information needed for advertising. Google Mobile Ads may process IP-derived approximate location, ad impressions/interactions, diagnostics/performance and device identifiers depending on SDK/OS configuration.

RUNTORY does not directly collect or store payment-card or bank-account numbers.

Article 3 (Storage, retention and deletion)

Data may be stored locally in Drift/SQLite, SharedPreferences and app-managed files. Raw local route geometry for a completed run is redacted on the next normal startup after the run becomes older than 365 days. Non-route summaries may remain for record functionality.

A signed-in user's Firebase account backup may contain structured data, precise completed-run route assets and app-managed original-photo bytes. Firebase backup has a generation/retention lifecycle separate from the local 365-day route policy. Account deletion invokes the server deletion job to clean account-scoped Firebase Storage and Firestore backup data. Local route deletion does not mean every remote backup asset is deleted immediately.

Account, Friends, game and settings data are retained as needed to provide the service and are subject to deletion when the relevant data/account is deleted, except where law requires separate retention. Location-use fact records carry a six-month retention deadline from the event time, and the current withdrawal/account-deletion path performs the applicable deletion process for the current user.

Article 4 (Firebase, Apple services and legacy CloudKit)

Firebase Authentication is the current remote account authority. Cloud Firestore may process profile, Friends and structured backup data; Cloud Storage for Firebase may process precise running-route and app-managed original record-photo backup assets. Cloud Functions for Firebase performs sensitive server processing such as backup finalization/retention, account deletion, subscription verification and location-use fact record/purge operations. Firebase App Check is used to protect applicable server requests.

Sign in with Apple and Google sign-in are Firebase account authentication methods on supported iOS and Android clients. App Store/StoreKit provides iOS subscription purchase, renewal, restore and transaction verification. Deleting the RUNTORY account or app does not automatically cancel an App Store subscription, and Apple-held payment/transaction records are handled under Apple's policies and legal obligations.

CloudKit is no longer the current account, Friends or backup store. A narrow legacy iOS deletion path remains temporarily so withdrawal/account deletion can address pre-Firebase location-use fact records. It may read the historical Apple-linked identity evidence only to locate/delete those historical records and does not create new CloudKit account, Friends, backup or location-use fact data.

Article 5 (Advertising and Google services)

Free users may receive Google Mobile Ads banner/rewarded ads and Google UMP manages ad-request eligibility/privacy choices. Current ad requests apply non-personalized ads (NPA) and restricted data processing (RDP), disable publisher first-party ID before Mobile Ads initialization and do not request ATT. Plus users are blocked from ad requests in-app.

NPA/RDP limit certain advertising/data use but are not identical to Google's Limited Ads mode and do not mean identifiers are never processed. Mobile identifiers may still be used for purposes such as frequency capping, aggregate reporting and invalid-traffic prevention under Google's policies.

Article 6 (International processing and external services)

RUNTORY uses Firebase/Google Cloud backend services, Apple sign-in/App Store subscription services, and Google advertising services. Because these paths have different roles, Firebase backend outsourcing/storage is described separately from Google advertising SDK direct collection. Any PIPA Article 28-8 disclosure follows the actual release configuration, provider contract and processing locations.

Firebase / Google Cloud backend

  • Basis for overseas outsourcing/storage: to the extent account, sync/backup, security, account-deletion, subscription-verification or legal-obligation processing is performed abroad and is necessary to enter into or perform the service contract, RUNTORY relies on the applicable PIPA Article 28-8(1)(3) outsourcing/storage basis.
  • Contracting/processing entities: Google's current Google Cloud contracting-entity guidance lists Google Cloud Korea LLC for customers with a South Korean billing address unless otherwise agreed. Google affiliates and disclosed subprocessors may participate in service delivery. The applicable Firebase/Google Cloud terms and Google Privacy Policy govern relevant provider processing.
  • Data: Firebase user identifier and auth/integrity request data, profile/Friends/structured backup data, backup route/photo assets, location-use fact records, and account/transaction references or server-operation data needed for account deletion/subscription verification.
  • Current storage/processing locations: as independently verified from the production configuration on August 28, 2026, the Cloud Firestore default database and Firebase Storage bucket are configured in the Seoul region (asia-northeast3/ASIA-NORTHEAST3), South Korea. Current sensitive Cloud Functions run in us-central1, United States. Firebase Authentication, App Check, support/operations and subprocessors may involve facilities in countries separate from the selected database/bucket region under Google's applicable terms.
  • Timing/method: encrypted network processing when the user signs in, uses profile/Friends, backup/restore, account deletion, subscription verification, or location-use fact record/purge functions.
  • Purpose: authentication/security, remote profile/Friends, backup/restore, server verification, account deletion, legal obligations and service operation.
  • Retention: RUNTORY-controlled data follows this policy and feature-specific retention/deletion rules; legally required records may be minimized and retained for the applicable period. Google's operational/security/subprocessor processing follows the applicable provider terms/policies.
  • Refusal/effect: core local running, on-device records and pet features can be used without a RUNTORY account. Users may choose not to use Firebase remote-account processing or account-based features such as Friends and cloud backup. Account-based features require sign-in when used. Account deletion can be requested in-app.

Apple services

  • Processing path: Apple services are used for Sign in with Apple authentication and App Store/StoreKit purchase, restore and transaction verification. CloudKit is not the current RUNTORY account/Friends/backup store.
  • Provider/contact: Apple identifies the relevant entities for users in South Korea, Apple Inc. and related processors. Privacy inquiries can be made through Apple Privacy Contact.
  • Data: Apple sign-in identifier, email/display name when Apple provides them, and App Store/StoreKit product, transaction, verification and account-binding information.
  • Purpose: Apple sign-in account authentication, App Store billing/subscription, StoreKit transaction verification, security and operation.
  • Separate management: Apple independently manages Apple-held account/payment/transaction/security information under its policies and legal obligations; deleting the RUNTORY account does not automatically cancel the App Store subscription.

Google advertising services

  • Provider: Google identifies Google Asia Pacific Pte. Ltd. as the contracting entity for AdMob publishers in South Korea. Relevant processing standards are described in the Google Privacy Policy.
  • Direct collection: Google Mobile Ads SDK/UMP may directly collect/process information from the user's device during advertising. RUNTORY does not intentionally attach a RUNTORY account id, email, precise GPS route or record photo as a custom ad parameter.
  • Potential data: ad/privacy-choice state, app/device/SDK information, IP-derived approximate location, device identifiers depending on configuration, ad impressions/interactions, diagnostics/performance, security and invalid-traffic information.
  • Country scope: Google states that it operates servers globally and information may be processed outside the user's country. RUNTORY does not infer a fixed ad-processing country from a contracting-entity address.
  • Current configuration: UMP gating, NPA/RDP signals, publisher first-party ID disabled and no ATT request. NPA/RDP is not the same as Limited Ads and does not mean identifiers are never processed. Plus users are blocked from ad requests in-app.

If Firebase regions, providers, advertising/SDK configuration or processing scope materially changes, RUNTORY will re-review this section against the actual release candidate and provider disclosures and apply any required notice/consent process.

Article 7 (Your rights)

Users can use app settings/record screens to delete available records/photos, withdraw location consent, log out and request account deletion. Requests to access, correct, delete or restrict personal/location information under applicable law may also be submitted to support; reasonable identity verification may be required.

For account deletion, iOS first attempts the reachable legacy CloudKit deletion path for pre-cutover location-use facts while Firebase authentication is still available. The Firebase server must then durably accept the authenticated deletion request before the client proceeds with accepted local user-scope teardown. The server continues physical deletion of remote backup, Friends, profile and account data under the durable deletion job and may retry temporary failures. An unaccepted server request is not treated as deletion success.

Article 8 (Permissions and safeguards)

  • Location, including background while an active run continues: outdoor run distance/route recording
  • Motion & Fitness: indoor running and step display
  • Photo library: user-selected record photos and saves
  • Sign in with Apple/Google sign-in: Firebase account authentication on supported platforms

RUNTORY applies user-scope separation, Firebase UID alignment checks, App Check/server authorization boundaries, app sandboxing, protected network transport and release logging rules that avoid exposing precise routes.

Article 9 (Children)

RUNTORY is operated for users aged 14 or older and does not provide a parental-consent enrollment flow for users under 14. RUNTORY does not separately collect date of birth or guardian information for such a flow.

Article 10 (Privacy officer, contact and changes)

  • Controller: Meongstore (멍스토어)
  • Privacy officer: Park Junghyun (박정현)
  • Business registration: 465-04-03240
  • Address: 서울시 금천구 두산로3길 17
  • Contact: support.runpet@gmail.com

Material changes to Firebase/Google/Apple providers or regions, Android processing scope, backup scope, advertising/ATT, subscriptions, location processing or analytics SDKs trigger a fresh review of this policy and store disclosures.