Privacy Policy
Last updated: July 22, 2026
RunningBuds is built to be private by design: no account, no tracking, and your conversations are encrypted - end-to-end for internet calls, traveling directly between you and your running partner or through an encrypted relay only when a direct connection isn't possible, and directly between the two phones for offline calls. This policy explains what the app accesses and why.
RunningBuds is provided by Codelous, LLC ("we," "us"). Questions: support@runningbuds.app.
The short version
- No account, no sign-up. We don't ask for your email, phone number, or login.
- No accounts and no call content stored. We don't operate a backend that collects or stores your personal information; we never receive or store your calls. (Connecting a call does briefly involve our connectivity service - the same service that issues relay credentials - which sees your device's IP address to rate-limit abuse and handles only opaque, end-to-end-encrypted setup data it cannot read. See below.)
- Your voice is encrypted end-to-end and travels directly to your buddy whenever possible - routed through an encrypted relay only when a direct connection can't be made. We never receive, record, or store your calls.
- No analytics, no ads, no trackers, no data sales.
What the app accesses on your device
- Microphone - to send your voice to your running partner during a call. Audio is processed on your device and transmitted end-to-end encrypted - directly to your partner, or via an encrypted relay when a direct connection isn't possible. It is not recorded, stored, or sent to us.
- Camera - only to scan your partner's pairing QR code. Scanning happens on your device; no photos or video are saved or transmitted.
- Photo library - if you set a profile photo, you choose it in Apple's system photo picker. The app never requests access to your photo library and receives only the single image you pick.
- Display name - the name you optionally enter is stored on your device and shared with your partner during a call so they know who they're talking to.
- Profile photo - optional. If you set one, it is resized and re-encoded on your device, which removes the original photo's embedded metadata such as location, and stored on your device. It is shared with your running partner during a call, with the same protections as the call itself (see "Connecting a call"): for internet calls it is end-to-end encrypted, including when routed through the Cloudflare relay, which carries only encrypted data it cannot read; for offline calls it travels encrypted at the Wi-Fi layer directly between the two phones. It is not sent to us or stored on our servers. If you use iCloud or device backups, your own photo is included in that backup.
- Your partner's profile photo - for offline calls, a copy of your partner's photo is saved on your device so it doesn't need re-sending on each run. It stays on your device, is never sent to us, and is deleted when you unpair that buddy in iOS Settings, when your partner removes their photo (applied on your next offline call together), or when you delete the app. For internet calls, your partner's photo is not saved - it is kept only for the duration of the call.
- Settings & relay usage count - your in-app preferences and a running total of relayed call time are stored locally on your device (the relay total is kept in the iOS Keychain, where it persists across app reinstalls so the monthly relay limit can't be bypassed). This stays on your device and is not sent to us.
- Paired offline buddies - if you use offline calls, the pairing you approve in the iOS pairing sheet is managed by iOS (Wi-Fi Aware), and the app keeps a small local record about each paired buddy (the pairing name and a device identifier) so it can show your buddy list and reconnect to them. This stays on your device, is never sent to us, and full unpairing is done in iOS Settings.
Connecting a call
- To connect two phones over the internet, RunningBuds uses standard real-time communication technology (WebRTC). Establishing a connection requires sharing your device's network addresses (IP addresses) with your partner's device and with connectivity servers - a Google-operated public STUN server (used only to discover your device's public address) and, when needed, the Cloudflare TURN relay. This is inherent to how direct device-to-device calling works.
- Offline calls don't use the internet or any of our services at all. The two iPhones connect directly to each other over peer-to-peer Wi-Fi using Apple's Wi-Fi Aware technology, after you approve a one-time pairing in the iOS pairing sheet. Apple documents these paired connections as authenticated and encrypted at the Wi-Fi layer, so the audio travels encrypted directly between the two phones - no servers, no relay, and nothing for us to receive. (This is a different encryption mechanism than the end-to-end DTLS-SRTP used for internet calls; both keep your call private in transit.)
- The code you show (the QR code or link) is shared directly between you and your partner. Completing the connection - your partner's reply and some connection details - is relayed through our connectivity service (the same service that issues relay credentials), but it is end-to-end encrypted with a key derived from the code that was scanned or tapped. That data stays opaque to the service and to us: we never receive the pairing content or your call. It is ephemeral and automatically deleted within minutes.
- When a direct connection isn't possible, the call is routed through a third-party relay service (Cloudflare TURN). The relay forwards your call between the two devices. Because the audio is end-to-end encrypted (DTLS-SRTP), the relay carries only encrypted data and cannot listen to your call, and we do not receive or store call content. Cloudflare may process connection metadata (such as IP addresses and bandwidth) to provide the relay; see Cloudflare's privacy documentation. To obtain short-lived relay credentials, the app contacts our credential service. That request includes your device's IP address, which the service uses only to rate-limit abuse; we do not use it to identify you, create an account, or access your calls.
- If a call drops mid-run (for example, when a phone switches from WiFi to cellular), the app may briefly use our reconnection service to help the two phones find each other again. These reconnection messages carry no audio and are end-to-end encrypted - we cannot read them - and they are automatically deleted within minutes. Nothing about your call is stored.
Subscriptions
- Subscriptions are sold and processed by Apple through in-app purchase. We do not receive or store your payment details. Your subscription status is determined on your device using Apple's StoreKit.
- We do not maintain subscriber accounts or profiles.
What we don't do
No advertising, no analytics or usage tracking, no cross-app or cross-site tracking, no selling or sharing of personal data, no user profiling.
Children
RunningBuds is not directed to children under 13 (or the minimum age required in your region), and we do not knowingly collect personal information from them.
Your choices and rights
Because we don't collect or store your personal data on servers, there's very little for us to access, correct, or delete. Your name, profile photo, and settings are held on your device and are removed when you delete the app. You can remove your profile photo at any time in the app; your partner's saved copy of it is deleted on your next offline call together. The running total of relayed call time is kept in your device's Keychain and is retained even if you delete and reinstall the app, so the monthly relay limit can't be reset by reinstalling; it is stored only on your device and is never sent to us. To cancel a subscription, use your Apple ID Account Settings. For any privacy questions or requests, contact support@runningbuds.app.
Third-party services
- Apple - in-app purchases and subscription processing (see Apple's Privacy Policy).
- Cloudflare - TURN relay connectivity when a direct connection isn't available (see Cloudflare's Privacy Policy).
- Google (public STUN server) - address discovery when establishing an internet call: the server sees your device's IP address and returns your public address, and processes no call content (see Google's Privacy Policy).
Changes to this policy
We may update this policy from time to time; the "Last updated" date above will reflect any changes. Material changes will be reflected in the app or on this page.
Contact
Codelous, LLC - support@runningbuds.app