Legal
Privacy Policy
In short: we use your data to run Windlace for you. We never sell it and never show you ads. Your runs are yours: you choose who sees them, and you can download or delete them at any time. We don't use passwords, so there's no password of yours for us to store or lose. The AI coach only reads your data if you agree to it.
1. Who we are
Windlace ("Windlace", "we", "us") is a running app made and run by KoSolutions PH, a business registered with the Department of Trade and Industry (DTI) in the Philippines. This policy covers the website windlace.app, the web app my.windlace.app, our iPhone and Android apps, and our emails.
We handle personal data in line with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and the rules of the National Privacy Commission. We are the personal information controller for your data.
Windlace is made for runners worldwide. Wherever you live, this policy applies to you, and if your local law gives you more protection (for example the GDPR in the European Union, the UK GDPR, or California's CCPA), we follow it for your data. See section 12.
2. What we collect
You give us
- Account: name, email, username, and optionally a profile photo, bio and birthday. Your birthday is used to estimate your age for heart-rate formulas.
- Runs and activity files: runs you record, upload (.fit, .tcx, .gpx, .zip) or add by hand. They can include GPS routes and locations, times, distance, pace, heart rate, cadence, stride, elevation, calories, laps and splits, plus the device that recorded them. We keep the original file you upload.
- Training details: your weekly schedule and goal, PR goal and plan, sessions you mark done or skipped, notes, heart-rate straps and settings.
- Social content: who you follow, stories and photos you post, run images you share, and gifts you send.
- No passwords: Windlace doesn't use passwords. You sign in with Google or with a one-time 6-digit code we email you, so we never ask for, receive or store a password. Sign-in codes expire after 10 minutes, and we keep only a scrambled (hashed) form of your login session, not the session itself.
- AI coach chats: the questions you ask and the coach's answers.
- Messages to us: what you send when you email us for support.
From connected services (only if you connect them)
- Watch platforms (starting with COROS): your activities and their data, sent to us when you link your account. You can disconnect at any time.
- Payment providers (Stripe, Lemon Squeezy, PayPal, Apple App Store, Google Play): your plan, subscription status, renewal date, country and a payment reference. We never receive your full card number.
- Sign-in providers (Google): your name, email and profile photo. We never see your Google password.
Collected automatically
- Device and log data: IP address, browser or app version, device type, operating system, pages and screens used, and error reports. We use these to keep the Service working and secure.
- Location while recording: only while you record a run with the app, and only with your permission. We don't track your location in the background when you aren't recording.
- Views: when you open another runner's run, we record that you viewed it (for its view count).
Heart rate and other health-related data can be sensitive personal information. We only process it to provide the features you use, with your consent.
3. How we use your data
- To run Windlace: show your runs, maps and charts; calculate records, medals, fitness, zones, training load, recovery and predictions; build your plan; sync and import your activities.
- For the AI coach (only with your consent): see "The AI coach and your data" below.
- For social features: your feed, followers, stories, "runners on the same route" and view counts, always within your privacy settings.
- For Premium: to manage your subscription and gifts, and to check which features you can use.
- To contact you: account and security emails, receipts, replies to your messages and, if you turn them on, notifications such as new followers, new records, coach suggestions and weekly summaries.
- To keep Windlace safe and improve it: prevent fraud and abuse, fix bugs, and understand which features are used, using combined data where possible.
- To follow the law: when we must keep records or respond to lawful requests.
We don't sell your data, we don't show ads, and we don't let AI providers train their models on your data (where the provider offers that choice, it's turned off for Windlace).
The AI coach and your data
- It's your choice. The AI coach reads your running data only if you give your consent, by agreeing to it and choosing to use the coach. If you don't, nothing is sent to the AI and the rest of Windlace works as normal.
- What it reads: when you ask a question, we send the AI provider your question, a summary of your running data (for example recent runs, pace, heart rate, training load, goals and plan) and your recent chat, so the answer fits you. It never receives your password (we don't have one) or your payment details.
- What it does: it only answers and suggests. It never changes your runs, schedule, plan or settings. Any change is made by you.
- No training: your data is used only to answer you. It isn't used to train AI models and isn't sold.
- You can change your mind: withdraw your consent and stop using the coach at any time. Email us if you want your saved coach chats deleted.
4. Why we're allowed to
- Contract: to provide the Service you signed up for under our Terms.
- Consent: for health and location data, the AI coach, connected accounts and optional notifications. You can withdraw consent at any time; some features then stop working.
- Legitimate interests: to keep the Service secure, prevent abuse and improve it, in ways you would reasonably expect.
- Legal obligation: for tax, accounting and other records the law requires.
6. What other runners see
- Your name, username, photo and bio are visible to other Windlace users so they can find and follow you (you can turn off being findable in search).
- Your runs are visible according to your setting: everyone, only followers, or only you. By default only your followers see them.
- Hide the start and end of your routes (on by default) so the maps others see don't show where you live or work.
- You choose whether you appear in "runners on the same route".
- Stories are visible to your followers for 48 hours, and you can see who watched them.
- Your training effect, coach summaries, AI coach chats, heart-rate zones and subscription are never shown to other runners.
7. Where your data is stored
Your data is stored on servers run by DigitalOcean, currently in Singapore. Some providers (for example the AI provider, email and payment providers) may process data in other countries, including the United States. When data moves between countries, we make sure it stays protected as the Data Privacy Act and your local law require, for example with the European Commission's Standard Contractual Clauses for data from the European Union or the United Kingdom.
8. How long we keep it
- Your account, runs and files: for as long as you have an account. When you delete a run, its activity file is deleted too.
- Stories: deleted automatically after 48 hours, including the image.
- AI coach chats: only the most recent messages are kept, so the coach can remember the conversation.
- After you delete your account: we delete your data within 30 days. Copies in our backups are removed within 7 more days, as the backups roll over.
- Payment and tax records: kept for as long as the law requires, even after you close your account.
- Server logs: kept for a short time (usually up to 90 days) for security.
9. Security
We protect your data with encrypted connections (HTTPS) everywhere, password-free sign-in (so there are no passwords to steal), hashed login sessions, restricted access to servers and databases, private storage for activity files, and daily backups. No system is 100% secure. If a breach puts your data at risk, we'll tell you and the National Privacy Commission as the law requires.
10. Your rights and choices
Under the Data Privacy Act you have the right to:
- be informed about how we use your data (this policy);
- access your data and get a copy of it;
- correct data that is wrong;
- delete or block your data, and delete your account;
- take your data with you (data portability), including your original activity files;
- object to processing and withdraw your consent;
- complain to the National Privacy Commission (privacy.gov.ph) and to claim damages as the law allows.
Many choices are in the app: privacy settings, notifications, connected watches, and editing or deleting runs. For anything else, email [email protected]. We reply within 30 days and may ask you to confirm it's really you.
11. Browser storage and cookies
The web app stores a small amount of data in your browser to keep you signed in and remember your settings (for example units and dark mode). We use no advertising cookies and no ad trackers. Our website loads fonts from Google Fonts, which receives your IP address to deliver them. To count visits to windlace.app and the web app we use Umami, a privacy-friendly analytics tool we run on our own server: it sets no cookies, doesn't track you across sites and keeps no personal data, only counts such as page views, the referring site, browser, device type and country. Clearing your browser data signs you out of the web app.
12. Users outside the Philippines
European Union, European Economic Area, United Kingdom and Switzerland
- We are the controller of your data. The reasons we use it (the "legal bases") are in section 4: contract, consent, legitimate interests and legal obligation. For health data such as heart rate we rely on your explicit consent, which you can withdraw at any time.
- You have the rights in section 10, plus the right to restrict processing, and to complain to the data protection authority in the country where you live or work.
- Your data is transferred to countries outside Europe (the Philippines, Singapore, the United States) under safeguards such as Standard Contractual Clauses. Ask us for a copy.
- Where the law requires it, we will appoint a representative in the European Union and the United Kingdom and list them here.
United States (including California)
- We don't sell your personal information and don't "share" it for cross-context behavioural advertising. We don't show ads.
- We use sensitive information (such as precise location while recording and heart rate) only to provide the features you use, never to profile you for other purposes.
- California residents (and residents of other US states with similar laws) can ask to know, access, correct and delete their data, and to limit the use of sensitive information. We won't treat you differently for using these rights. You can use them yourself or through an authorised agent, by emailing us.
- The categories of data we collect, why, and who receives them are listed in sections 2, 3 and 5. We keep data only as long as described in section 8.
Everywhere else
If you live in another country with privacy laws (for example Australia, Canada, Brazil, Japan, Singapore or India), you have the rights that law gives you. Email us and we'll help.
13. Children
Windlace is not for children under 13, or under the minimum age where you live if it is higher (up to 16 in some European countries). Users under 18 need a parent's or guardian's permission. If you think a child under 13 has given us data, contact us and we'll delete it.
14. Changes to this policy
We'll update this policy when Windlace changes, for example when we add new payment options or new connected watches. We'll change the "Last updated" date and, for important changes, tell you in the app or by email before they apply.
15. Contact us
For privacy questions and requests, contact:
Windlace Support
Email: [email protected]
