WI.RUN / KOMARSH LLC
Privacy policy
WI.RUN is operated by KOMARSH LLC, Florida. This private beta uses Supabase for accounts, private run history, social features and races, LiveKit for optional race voice, and Microsoft Azure for this website. The beta is still being tested; pending saves are not completed cloud backups.
1. Recording on your iPhone
WI.RUN processes location during a run to calculate distance, pace, active time and a route. Active and unfinished recordings use a protected device recovery file that may contain precise route points. Saving queues your run for your signed-in WI.RUN account; an explicit discard removes the unfinished recording. Saving to the device queue does not mean the server has received it.
Keeping precise routes is off by default. If you choose to keep a route when saving, the automatic-history update will include its precise location points in your private account history. Otherwise only the run summary is saved. Changing this preference affects future saves and does not remove older routes. Retaining a private route does not publish it or enable race map sharing.
When you open details for a run with a retained route, WI.RUN may send an approximate run-area coordinate rounded to two decimal places to Open-Meteo to show weather for the run’s time. The request does not include your WI.RUN account identifier or full route. No weather request is made for summary-only runs.
2. WI.RUN account and automatic history update
Signup and sign-in send your email address and password to Supabase Auth over an encrypted connection. Supabase handles authentication and related service/security information. WI.RUN stores access and refresh credentials in device-only iOS Keychain storage; it does not use your account password as a profile field.
Signup sends your chosen display name and handle as profile-draft metadata. After confirmation, signing in saves the draft to your private profile if no profile exists; a conflicting handle requires correction. You may also save a biography. The automatic-history update will save run identifiers, start/finish times, distance, active duration and goal timezone, plus precise route points only when you choose to retain them. It will restore your private history when you sign in and store appearance and route-retention preferences with your account. This account history does not upload photo or video posts.
The update keeps a protected, account-specific device cache and a queue for pending saves and deletions. It retries when the account and connection are available. Check the save status and retry any failed request; pending work can be lost if you remove the app before synchronization. Existing history from older builds is imported only after a separate confirmation naming the destination account.
The first valid submitted run freezes the account's goal timezone. Daily points use the run's actual day in that timezone, with at most one award for a qualifying 1 km and 5-active-minute run per day. Points come from the server; a run awaiting upload has not yet earned a confirmed award. Run summaries are self-reported, not a guarantee of GPS verification.
Email confirmation is required; signup uses an email link followed by returning to WI.RUN to sign in. General email delivery and actual signed-in hosted journeys still need verification; code-entry and recovery controls remain disabled. The automatic-history database update is deployed; signed-in end-to-end verification remains outstanding. An unavailable, pending or failed control has not completed its request.
Private fitness measurements and calorie estimates
You may enter height and weight in your account using metric or imperial units. We store these measurements privately in Supabase for app functionality; other runners and guests cannot retrieve them. You can update or remove them in Height & weight, and account deletion removes them. Running calorie estimates use weight in kilograms multiplied by distance in kilometers. They are approximate, are not medical measurements, and do not affect ranked points. Estimates captured with saved runs remain with those private runs until you delete the runs or account. Changing your weight does not rewrite saved estimates. Older runs without a saved estimate may display an estimate using your current weight.
3. Racing and the development community beta
Optional race voice is available to authorized runners and browser guests in an active race. Tapping Join voice requests microphone access and connects to a LiveKit audio room. Other people in the room can hear you until you mute your microphone or leave. Per-runner mute controls what you hear. Supabase verifies room membership before issuing a short-lived, audio-only token; LiveKit processes your audio and connection information to deliver the call. WI.RUN does not record calls. This beta uses encrypted transport and does not claim end-to-end encryption. Guest voice requires keeping the browser race page open.
Scheduled races start from a shared server timestamp. Hosts may choose an end time; unfinished runners are marked DNF at the cutoff. Accepted distance/time samples and finish/DNF status can be replayed by participants for 30 days. Replay samples do not include GPS coordinates. The 30-day access window does not mean samples are physically deleted automatically after 30 days.
The WI.RUN-account race database update is deployed; real signed-in two-device verification remains outstanding. It uses your authenticated WI.RUN profile, room membership and distance/time progress for small races of 2–10 runners. Shared countdowns use server time; connected progress refreshes approximately every two seconds. Results are provisional, affected by network delay and self-reported GPS progress.
In that update, optional map sharing starts hidden. The service rounds your latest position to 0.001 degrees (about 100 meters north–south, varying east–west) and only returns unexpired positions to room members. Each update expires from visibility after 15 seconds. The latest rounded position is stored in a private database table and can remain there until a later race request purges expired rows; a successful hide, leave or terminal-race cleanup also removes applicable markers. Visibility expiry is not a promise of physical erasure at exactly 15 seconds. The marker table does not accumulate a full live route. This is separate from your choice to retain a precise private run route.
Guest entry is available only in host-enabled rooms. Guests enter a name, agree to the terms, and grant GPS permission. Supabase creates a temporary anonymous identity linked to that room. Its name, accepted distance, time and finish/DNF status are visible to participants. Precise guest GPS coordinates stay on the phone. Browser tracking requires keeping the race page visible; guest results are provisional and do not earn ranked points. Guests can remove their identity using the guest page’s deletion control. After a race, guests may choose to keep the same identity by linking and verifying an email address and setting a password; race results stay linked to that identity.
The hosted feed is available to signed-in runner accounts, including on rest days. Guest race identities remain race-only. Publishing is a separate explicit action that shares your caption and selected photo, video, poll or run summary with eligible runners, subject to blocks and moderation. Photos and exported video clips are rebuilt without source metadata. Choosing route replay shares a normalized, endpoint-trimmed route shape rather than precise coordinates; recognizable media or a route shape can still reveal a place. Following and Everyone are discovery filters and do not make published posts private.
Your social profile photo, handle, display name, status and permitted profile activity can be viewed by other runners. Follower relationships, counts, comments, replies, mentions and attributed reposts are social data. Bookmarks are private to the bookmarking account. Blocking removes applicable connections; unblocking does not restore them. Reports, blocks and own-post deletion limit future access but cannot erase information another person already saw.
Video playback uses authenticated downloads and protected temporary files. Viewer cleanup removes these files when playback closes, the app leaves the foreground, or the account changes; interrupted-session files are cleaned at the next launch. Debug previews use labeled fictional data.
4. Retention, deletion and device protection
With the automatic-history update, individual-run and all-history deletion request removal from your WI.RUN account. Offline deletions remain pending until accepted by the server. The service keeps account-scoped deletion markers to prevent stale devices from restoring deleted runs. Discarding an active/interrupted recording is a separate control. Removing the app or signing out does not delete account records.
Account deletion removes your owned account profile, saved runs, retained routes, preferences and points; other runners' shared history is preserved without the deleted host identity. Browser guests can delete their temporary identity from the race page. Provider security logs and backups may have separate retention and cannot be assumed erased instantly.
WI.RUN applies iOS file protection and backup exclusion to its run cache and queued changes. Finished history uses complete file protection; recovery files remain accessible after first device unlock for active recording. Credentials use device-only Keychain protection. Signing into another account changes the visible history to that account's cache. These controls do not promise absolute security or recovery from every interruption.
Maps are rendered using MapLibre Native with OpenFreeMap tiles. OpenFreeMap and its delivery providers receive network requests, including IP addresses and the requested map area. WI.RUN draws route lines and runner labels on the device rather than sending those overlays to the tile provider. OpenFreeMap states that it does not normally log IP addresses, but may temporarily log them during security incidents for up to 30 days; see its privacy policy. Supabase processes account-service requests and, private run history and preferences. GPS recording on the device does not mean the app makes no network requests.
5. Website visits and support
Microsoft Azure hosts this website and processes technical requests, including IP address, browser details, requested pages and security events, to deliver and protect it. We have not added advertising trackers, behavioral analytics, a mailing-list form or third-party social embeds.
If you email support@komarsh.com, we and our email providers process your address and message to respond and maintain necessary support records. Do not send passwords, access tokens, recovery codes, full routes or unnecessary health information. Correspondence is retained as needed for support and applicable obligations.
6. Providers and future integrations
We do not sell personal information or use health/fitness information for targeted advertising. Providers process data to operate authentication, hosting and support. Information may also be disclosed when required by law or reasonably necessary to protect rights, safety or service security.
Apple Watch, Garmin, WHOOP and HealthKit connections are not enabled. Future integrations will require their own permissions and updated disclosures. Account and hosting providers may process information in the United States and other locations where they operate.
Optional weekly leaderboard
Your account starts hidden from the weekly leaderboard. If you choose Join in the app, signed-in runners can see your handle, display name and weekly points. Your email, biography, run summaries and coordinates are not included. Leave the leaderboard to stop appearing in future requests; this cannot erase information someone already saw. The board excludes blocked runners, shows up to 50 entries and uses self-reported daily points. Signing out does not change your saved visibility choice; use Leave leaderboard before signing out if you want to be hidden.
7. Your choices and contact
Use the in-app controls for run and account deletion, location permission, optional precise-route retention and social sharing. See privacy choices. For access, correction, deletion or other applicable requests, email support@komarsh.com. We may need proportionate verification. Your rights depend on your location and are not limited by this policy.
WI.RUN is not directed to children under 13. Contact us if you believe a child has provided personal information. We will update these disclosures as development and data practices change. Contact KOMARSH LLC, Florida, United States, at support@komarsh.com.
Error diagnostics
WI.RUN can collect account-linked error codes, affected feature, HTTP status, app version, platform, and time to troubleshoot failures. Diagnostics do not include message text, photos, audio, health measurements, precise GPS, passwords, or tokens. You can disable diagnostic sharing in Settings. Administrators can also view aggregate first-run, second-run, guest account conversion and group-return metrics from existing account and race records. This does not introduce additional GPS or message tracking. Recent diagnostics are accessible only to you and authorized support administrators; administrator reads are audited. The review window is 30 days, and older records are cleared on subsequent diagnostic submissions or account deletion.