RunMax Privacy

GDPR · Garmin-approved data handling

Privacy policy

What RunMax collects, why it collects it, and what you can do about it. Written against the EU General Data Protection Regulation and Garmin's Developer Program terms.

Last updated 4 December 2025 · 12 sections · Reading time 4 min

The short version

  • RunMax reads your Garmin data only after you connect it, and only the permissions you grant in Garmin's own consent screen (sections 2 and 7).
  • It is used to build and adjust your training, and for nothing else. We never sell it (section 3).
  • Workouts are pushed to your watch. Nothing is ever posted to your activity feed (sections 2 and 3).
  • You can revoke Garmin access from Garmin Connect at any time, and it stops immediately (section 7).
  • You can ask for a copy of your data or for it to be deleted, and GDPR gives us 30 days (section 8).

This summary is not the policy. Where the two differ, the numbered sections below are what applies.

Jump to a section
  1. 1Introduction
  2. 2Data We Collect
  3. 3How We Use Your Data
  4. 4How We Store and Protect Data
  5. 5How Long We Keep Your Data
  6. 6Third-Party Processing
  7. 7Garmin Permissions and Revocation
  8. 8User Rights (GDPR)
  9. 9Cookies
  10. 10Children's Privacy
  11. 11Changes to This Policy
  12. 12Contact Information

1. Introduction

RunMax ("we", "our", "us") provides training planning, structured workout generation, and performance analytics for athletes.

This Privacy Policy explains how we collect, use, store, and protect personal data—including health and activity data—when you use the RunMax Training App and when you connect your Garmin account via the Garmin Connect Developer APIs.

We comply with the EU General Data Protection Regulation (GDPR) and Garmin's Developer Program terms.

If you have questions, contact us at: kontakt@runmax.dk

2. Data We Collect

2.1 Account Information

When you create a RunMax account, we collect:

  • Name
  • Email address
  • Password (hashed and salted)

2.2 Garmin Data (Only After You Connect Garmin)

If you choose to connect your Garmin account, we receive data from the Garmin Connect Developer APIs, including (depending on your permissions):

Activity API

  • Running, cycling, and other recorded activities
  • Distance, speed, pace, duration
  • Elevation
  • Heart rate data
  • Activity metadata
  • FIT/TCX files when necessary

Health API

  • Daily summaries (steps, calories, heart rate, intensity minutes)
  • Epoch summaries
  • Sleep summaries
  • Body composition (if enabled on your device)
  • Stress, body battery, respiration, HRV
  • Pulse OX and other wellness metrics (if your device supports them)

Training API

  • Structured workouts you create in RunMax
  • Workout pushes to your Garmin devices
Important: We only access the data you explicitly grant permission to during Garmin's OAuth 2.0 consent flow.

3. How We Use Your Data

We use your data solely for the purpose of delivering training-related features inside RunMax:

  • Generate personalized training programs
  • Adjust training load and intensity based on recent activity
  • Provide insights and analytics
  • Sync structured workouts to Garmin
  • Receive completed activities for adaptive training
  • Improve accuracy of AI-based training recommendations
We never sell your data.
We never share your data with third parties except for essential processing (see section 6).

4. How We Store and Protect Data

4.1 Storage

All personal and activity data is stored securely on servers operated by our hosting provider.

Garmin OAuth tokens (access tokens and refresh tokens) are:

  • encrypted using AES-256
  • stored only for the purpose of syncing data
  • automatically refreshed per Garmin's OAuth 2.0 requirements

4.2 Security

We implement:

  • TLS/HTTPS encryption
  • Encrypted token storage
  • Strict API access control
  • Role-based access permissions
  • Server-level firewalls

Your password is stored using industry-standard hashing (bcrypt/argon2).

5. How Long We Keep Your Data

We retain training data as long as you have an active account.

If you delete your account:

  • All personal data is permanently deleted
  • All Garmin OAuth tokens are revoked
  • All synced activities and summaries are removed
  • Backup copies are deleted within 30 days

You may request deletion at any time by emailing kontakt@runmax.dk.

6. Third-Party Processing

We may use trusted providers for:

  • Hosting (e.g., AzeHosting)
  • Email notifications
  • Error logging
  • Database backup and recovery

No third parties have access to your Garmin health data unless required by law.

We never transmit your data to advertisers or analytics companies.

7. Garmin Permissions and Revocation

You control what Garmin data RunMax can access.

7.1 Revoking Access

You may revoke access at any time by:

  • Disconnecting Garmin inside the RunMax app, or
  • Removing RunMax from Garmin Connect → Account Settings → Third-Party Apps

Once revoked:

  • We immediately stop receiving data
  • Stored tokens are deleted
  • Webhook notifications from Garmin stop

8. User Rights (GDPR)

Under GDPR, you have the right to:

  • Access the data we store about you
  • Correct incorrect information
  • Delete your account and all related data
  • Export your data in a machine-readable format
  • Withdraw Garmin permissions at any time

To exercise these rights, contact kontakt@runmax.dk.

9. Cookies

RunMax uses functional cookies only for:

  • Authentication sessions
  • Keeping you logged in

We do not use tracking cookies or third-party advertising cookies.

10. Children's Privacy

RunMax is intended for users aged 16 or older.

We do not knowingly collect data from children under 16.

11. Changes to This Policy

We may update this Privacy Policy from time to time.

If we make significant changes, we will notify you via email or through the app.

Latest version is always available at: https://app.runmax.dk/privacy

12. Contact Information

RunMax

Email: kontakt@runmax.dk

Website: https://runmax.dk