Legal
Privacy
Last updated 26 September 2026
ALLUNGO is a running-training app for iPhone and Apple Watch. This page explains what it does with your information. It is written to be read, not to be survived.
No account
ALLUNGO has no sign-up, no login and no password. You do not give us an email address to use the app, and we do not create one for you.
The optional coach described below does use a server, but that server never learns who you are. It knows each installation of the app only by a random identifier.
Where your training data lives
Your plan, your sessions, your paces, your completed runs and your settings are stored on your iPhone and Apple Watch.
They also sync through your own iCloud account, so the same training appears on your other devices. That is Apple’s storage, under your Apple Account and subject to Apple’s terms — not ours, and we cannot see it. Sync is on by default and needs you to be signed in to iCloud. You can turn it off in Settings, and your training then stays on the device.
Your data is also included in your device backup if you back your device up, under whatever protection you have set for that backup.
Apple Health
With your permission, ALLUNGO reads workouts and recovery data — such as heart rate variability, resting heart rate and sleep — from Apple Health, and writes the runs you record with ALLUNGO back to it.
- Health access is requested when you first use a feature that needs it, and you can decline.
- You can change or withdraw that access at any time in the Health app, under Sources.
- Health data read by ALLUNGO is used to show you your own training and recovery. It is not sold, and it is not shared for advertising.
The optional coach
ALLUNGO includes an optional coach that reads your recent training and explains it in plain language. It is off unless you turn it on, and the rest of the app works fully without it.
Turning it on takes an explicit consent step that tells you what would be sent before anything is. You are asked in More → AI Coach, and once at the end of first setup, where “Not now” is always available. Turning it off stops anything being sent, straight away.
When the coach writes a read, what goes with it is:
- Your first name — the first word of the name you entered, if you entered one. The field is optional, and leaving it blank sends no name at all.
- Your recovery markers for the last 14 days: heart rate variability, resting heart rate and sleep.
- Your runs from the last two weeks: date, distance, duration, pace and average heart rate.
- Your training plan and its target paces, your race goal and your race date.
- Anything you type to the coach.
- After a run, the app's own summary of how that run went.
What does not go with it:
- Your surname. Only the first word of the name is sent, whatever you typed.
- An email address. The app never asks for one.
- Your location, or the GPS route of any run.
- Your Apple Account, or any Apple Health data beyond the recovery markers and run figures listed above.
Where the coach sends it
The app sends that information to the ALLUNGO coach server, which runs on Vercel in the United States. The server passes it to Anthropic’s Claude API, which writes the read, and returns the reply to your phone. There is a limit on how many reads each installation can ask for in a day and in a month.
Before it answers, the server checks that the request came from a genuine copy of ALLUNGO on a real iPhone, using Apple’s App Attest. That is what lets the coach work without accounts: it proves the app is real without proving who you are. The server knows each installation only by a random identifier — not a name, an email address or an Apple Account.
The server keeps three things, in a database run by Upstash in the United States:
- How many reads that installation has asked for today and this month, so the limits can be applied.
- The installation's App Attest public key, so later requests from it can be checked.
- The coach's reply, for up to 24 hours, so asking the same thing twice does not cost twice.
It does not store the training or health data sent to it. Its logs record what happened, a hashed installation identifier, which model answered, and the tokens used and what they cost — never your health data, and never the reply.
Anthropic processes the request in order to generate the reply. Under its API terms, requests are kept for up to 30 days for safety review and are not used to train its models.
If you would rather none of this left your device, leave the coach off.
Who else is involved
- Apple — iCloud sync, Apple Health, and App Attest.
- Vercel — hosts the coach server, in the United States.
- Upstash — runs the coach server's database, in the United States.
- Anthropic — the Claude model that writes the coach's reads.
Nothing goes to analytics services, advertisers or data brokers. Your information is not sold.
Analytics and tracking
This website runs no analytics, no advertising pixels and no third-party trackers, and it sets no cookies. Fonts are served from this site rather than from a font network, so loading a page does not tell anyone else that you visited.
Children
ALLUNGO is not directed at children and is not intended for use by anyone under 13.
Not medical advice
ALLUNGO is a training tool, not a medical device. It does not diagnose, treat or prevent any condition, and nothing it shows you is medical advice. If something hurts, or you are unsure whether training is safe for you, speak to a qualified professional.
Changes
If this policy changes in a way that matters, the date at the top of this page changes with it.
Contact
A contact address for privacy questions will be published here alongside ALLUNGO’s public release.