Foil Run

Privacy policy

Foil Run Privacy Policy

GPS tracks are precise location history. This policy explains what Foil Run stores, what stays private, what becomes public when you choose to share, which services process your data, and how to delete it. It is written in plain language by the person who builds Foil Run — an individual, not a company — and has not been reviewed by a lawyer yet.

Version privacy-v1 · Effective August 13, 2026 · Last updated August 13, 2026.

What Foil Run stores

  • Account email, display name, sign-in state, and profile settings.
  • When you join the iPhone beta through TestFlight, Apple shares your tester name and email address with the developer so the beta can be delivered.
  • Your account-level Help improve Foil Run choices (aggregate contribution and private session dig-in) and when each was last changed.
  • Your account-level Gemini voice processing choice and when that choice was last changed.
  • Saved private sessions, parsed GPX points, analysis results, gear/setup metadata, and notes you add.
  • Native account uploads retain the exact source GPX privately with the saved session so owner-only reopen and consented debugging preserve motion, recovery, heart-rate, and future vendor extensions.
  • Start and Finish voice recordings and optional on-device Apple transcripts saved with a session when you record them; they stay private with that session.
  • Heart rate samples when the native app upload setting is explicitly enabled; they are private by default and appear in a future share or rider-review view only when you deliberately share that analysis.
  • Watch live-wind instrument events embedded by the native recorder; they stay with the private saved session and are not included in public shares or boards.
  • Optional Watch motion files, including wrist acceleration, relative altitude, pressure, device orientation settings, and capture diagnostics, when you enable Motion data with sessions. They attach to your private saved session for owner-only debugging and are not included in shares, boards, or feedback reports.
  • When the Watch app is open before Start, it may take one bounded foreground location fix and send its location and time through the paired iPhone and Foil Run backend to Open-Meteo for a nearby wind estimate.
  • Shared-session snapshots and public course-board attempts when you choose to publish or compete.
  • Donated feedback reports, including GPX/debug bundles and analysis snapshots when you explicitly consent; a donated GPX may be kept indefinitely for debugging and regression testing.
  • Operational logs needed to run, secure, debug, and prevent abuse of the service.

Who operates Foil Run

Foil Run is operated by Wren Dougherty, an individual based in the United States, not a company. Questions, data requests, and everything else in this policy go to privacy@foil.run — the one address Foil Run publishes.

Foil Run runs on infrastructure in the United States, so using it from anywhere else means your data is transferred to and processed in the United States. Foil Run is built and operated from the US and does not target any other market.

What is private by default

Saved tracks in your account are private by default. They are not public course-board entries and they do not create public share pages unless you publish or compete from that session. Native account uploads retain their exact source GPX only with the private saved session, where the owner can reopen it without losing recorder extensions. Heart rate is included in that source only when the native upload setting is explicitly enabled. The source GPX and native Watch live-wind instrument log are not loaded by ordinary public/session-list reads.

Motion data with sessions is one Watch choice: capture and private-account upload together. Enabling it records wrist acceleration, pressure, and relative altitude during Watch sessions and sends retained and future sidecars through your paired iPhone to the private saved session in your account. Apple Motion & Fitness permission is required for capture. The owner can inspect health details, download the raw file, or delete the sensor attachment without deleting the GPS session. Motion sensor data is never added to public shares, course boards, or feedback reports automatically. You can revoke Motion & Fitness in Apple Settings to stop future capture.

Private does not mean no operator can ever access the data. Foil Run admins may access stored tracks and debug reports for operations, support, debugging, and abuse/security. Product or algorithm improvement using account sessions requires the separate Help improve Foil Run setting.

Before a Watch recording starts, the nearby-wind check processes one foreground location and timestamp through your paired iPhone, the Foil Run backend, and Open-Meteo. The backend operational request currently carries the precise location in its HTTPS query. Foil Run's application wind-lookup log rounds the location to two decimal degrees; hosting or network infrastructure also processes the request and may retain operational request logs under its configured service settings. Foil Run has not independently verified a fixed infrastructure-log retention period. The Watch keeps up to 96 successful location-and-wind breadcrumbs locally. They are eligible for reuse for 24 hours and are physically pruned on the next store access after expiry. Those breadcrumb coordinates are not added to your account or exported in the GPX.

Separately, the Watch can remember the final wind from prior sessions as an optional offline suggestion. This spot memory stores only a coarse 0.02-degree location cell, the final wind direction, and time: up to 12 samples for each of 20 recently used spots. Samples do not expire by age. The oldest samples and least-recently-used spots are discarded when those limits are reached, and every retained-wind suggestion must be confirmed for the current session. Spot memory stays on the Watch and is not added to your account or exported in the GPX.

Help improve Foil Run

Help improve Foil Run has two separate account choices. For this friends learning alpha, both start on for new accounts and for existing accounts that had not yet chosen, and you can opt out at sign-up or later in Account. If you already turned a choice off, it stays off. Signing in or agreeing to these Terms/Privacy by continuing never silently buries them: the sign-in surfaces show the choices. Gemini voice processing is a separate account choice that stays off until you deliberately turn it on. A later public App Store release may keep aggregate contribution default-on while making private session dig-in opt-in as well.

Aggregate contribution lets Foil Run study climb and run metrics, gear names, session metadata, and coarse spot/time across accounts for aggregate gear and spot performance. It does not open your private sessions for dig-in. Private session dig-in lets Foil Run open existing and future private sessions in your account to develop and evaluate wind, VMG, segment, maneuver, Wave, course, and other riding algorithms. Dig-in can include precise GPS, what the Watch calculated and displayed, app and build details, apparatus and gear, and analysis results. If you enable Motion data with sessions, it can also include wrist acceleration, relative altitude, pressure, device-orientation settings, and capture diagnostics. Neither permission includes heart rate. Standard session upload, private visibility, sharing, and deletion behavior do not change.

Turning a choice off prevents newly-started jobs that need that permission; a job already running may finish. Neither choice makes a session public. Foil Run does not publish aggregate outputs from this program yet; when it does, they will use minimum cohort sizes and will not expose a private route, an individual rider's sessions, or who is in a cohort. Foil Run does not sell this data or use it for advertising. Session and account deletion keep their ordinary scope described below.

Gemini voice processing

Gemini voice processing is a separate account choice. It stays off until you deliberately turn it on: Foil Run offers it when you review a session's voice notes, and you can turn it on or off any time in Account. When it is on, Foil Run may send a saved session's Start and Finish voice recordings to Google Gemini, a third-party AI service, to transcribe them and draft a private session story, title, summary, conditions, wind, and gear suggestions for you to review.

Each request carries the stored audio for that one session, its apparatus, and a short list of gear candidate labels — brand, model, and size text drawn from your saved gear and matching catalog entries, with how often and how recently you used them. It does not carry GPS or track data, Watch sensor or altimeter data, heart rate, your email, database identifiers, notes from other sessions, or the Apple transcript already saved with the recording.

Suggestions come back as private drafts stored with your session; they stay drafts until you save them. Foil Run asks Google not to store the request and uses the paid tier of Google's Gemini API, whose published terms (as of August 2026) state that paid-tier content is not used to improve Google's models and may be kept for a limited time for abuse monitoring. Foil Run does not claim independent proof of Google's retention or training practices beyond those published terms.

This is a separate choice. Accepting the Terms, recording a voice note, uploading it to your private account, and Help improve Foil Run do not include it. Turning it off stops new Gemini calls; drafts already generated stay readable in your private session until you delete the voice note, the session, or your account. Recording, playback, the Apple transcript, session details, and editing your own session always work without it.

What becomes public

If you publish a share link, the public page at /s/[id] shows the shared session snapshot. If you submit to a public course board, the board entry can show your time, selected public rider name, gear/setup fields used by the board, and a link to the public proof track. Leaving a board or making a session private removes those public projections where the account controls them. A future share page includes recorded heart-rate samples when they are present in the analysis you deliberately publish. Course and leaderboard summary rows do not add a separate heart-rate statistic, although their linked public proof track can show the recorded samples. The private exact source GPX and Watch live-wind instrument log are not included in those public projections.

A track-debug report is not a public projection. It is a separate, private opt-in covered under Feedback reports below.

Feedback reports

General feedback can be anonymous and is not tied to a track. Track-debug reports require explicit consent because they can include precise GPS location data, the GPX/debug bundle, the selected Analyze view/context, an analysis snapshot, and any Watch instrument log embedded in that GPX. Track-debug reports do not store a Foil Run account ID and are not account-owned data, even when sent while signed in. An email is optional. If entered, it is stored only with the report so we can follow up and help locate that specific donation later; it is not converted into account ownership. Contact details and account identifiers are never copied into a test fixture.

The current track-report checkbox is an explicit consent agreement. It authorizes Foil Run to keep the private raw report, its GPX, and/or a reviewed test fixture indefinitely for debugging and regression testing. There is no promised automatic expiration. Fixture preparation strips contact details, account identifiers, original filenames, and unrelated metadata, but it does not hide or alter the donated track geometry.

Services that process data

Foil Run currently uses these services to run the product. This list reflects what the code and deployment docs name. It is not a complete legal subprocessor schedule with regions, contracts, or retention periods.

  • Railway hosts the web app, API, and Postgres database.
  • Cloudflare provides DNS for the foil.run domain.
  • Resend sends sign-in emails (magic links or codes) when email delivery is configured.
  • Open-Meteo receives a precise location and time for a nearby wind estimate when the Watch requests one before Start.
  • Google Gemini receives a consented session's voice-memo request payload when Gemini voice processing is enabled for the account.
  • OpenStreetMap tile servers and unpkg (Leaflet CSS) receive ordinary browser map and stylesheet requests when you view a map.
  • Apple provides OS permissions and platform services used by the iPhone and Watch apps, including location, microphone, and Motion & Fitness where you grant them, and TestFlight for beta delivery.

Foil Run has not independently verified each provider's full retention, subprocessors, or training practices beyond what this page and the account disclosures already say.

Heart rate and consumer health data

Heart rate is the one kind of health data Foil Run holds. It is recorded only when you explicitly enable the native app's heart-rate upload setting, it stays private with your session, and it appears elsewhere only inside an analysis you deliberately publish. It is never sold, never shared for advertising, and never used by Help improve Foil Run — both improvement choices exclude it.

You can remove it by deleting the session or your account, and you can ask about it at privacy@foil.run at any time. If you live somewhere with specific consumer-health-data rights, such as Washington State's My Health My Data Act, those requests go through the same address and are honored.

Deletion and other data requests

You can delete saved sessions one at a time from your account. Deleting a session also deletes its retained exact native source GPX, attached motion sensor file, and saved voice recordings for that session. You can delete only the sensor attachment while keeping the GPS session, or delete your account from the Privacy & account deletion section in account settings.

Sensor-only deletion removes the raw sensor file and its capture-health details. Foil Run retains only the session and recording identifiers, the file's SHA-256 deletion marker, and deletion time until you delete the GPS session or account. This minimal marker prevents a retained Watch copy from recreating sensor data you already deleted.

Account deletion removes private sessions and their attached source GPX, motion sensor files, and voice recordings, shared-session projections the account owns, public course attempts tied to those shares, private or proposed courses, account profile fields, and sign-in sessions. It does not remove donated track-debug reports because those reports are separate from account ownership, even if their optional contact email matches the account email.

For broader deletion help, to ask what Foil Run holds about you, to correct something the product cannot edit, or to ask about deletion of a specific donated report, email privacy@foil.run and say what you want. These requests are honored for anyone, wherever you live; expect a reply within 30 days. Some operational or security logs may be retained only where necessary.

To the extent EU or UK data protection law applies to you, Foil Run relies on performing the service you asked for, the choices this policy describes, and its legitimate interest in running and securing the service; none of that changes what you can ask for here.

If the report became a reviewed test fixture, say whether you also want the project to stop using that fixture going forward.

What Foil Run does not do

Foil Run does not sell precise location data or share it for advertising or data-broker use. Foil Run is intended for adults 18 or older and is not directed at children. Do not use Foil Run if you are under 18.

Changes to this policy

Foil Run may update this policy as the product changes. The version and dates at the top state what is in force, and a material change takes effect no sooner than 14 days after Foil Run emails account holders or shows a notice in the product.

A change that would expand how data Foil Run already holds may be used is not applied retroactively: it takes a new, affirmative choice from you, not just a notice. That is why Help improve Foil Run, Gemini voice processing, and the track-donation checkbox carry their own versions and consents.

About this policy

This policy is the operator's best effort for a small alpha. It describes what the code actually does today, written by the person who builds Foil Run rather than by a lawyer, and it has not been reviewed by a lawyer yet. A lawyer may later redline it, and the wording can change with the notice promised above.

Some parts of a formal policy are deliberately missing rather than invented: contractual processor terms, regions, and subprocessor schedules, fixed retention periods, and the formal statutory-rights procedures a lawyer would add. This policy does not guess at them; the requests section above is honored regardless.

What it does say about keeping data is what the product does today: data in your account stays until you delete the session or the account, and a track you donated with the report checkbox may be kept indefinitely under that consent. There is no automatic expiry job, and none is claimed.

Foil Run also publishes a Terms of Service. The two are separate documents. Sign-in and sign-up surfaces say that by continuing you agree to both, with links. Neither document is a versioned acceptance gate yet: no Terms or Privacy version is recorded against your account.

This is plain-language product copy, not legal advice. Get formal legal review before broad launch or compliance-heavy use.