YOUR TRAINING. YOUR CHOICES.
Privacy policy
A clear guide to what Northline keeps, shares, and lets you delete.
Effective September 26, 2026
Your training history lives on your iPhone. Northline processes your training plans, runner profile, and insights there. Information leaves your device when you use Apple services (such as Apple Weather, Maps, Health, or the App Store), create or sign in to an optional Northline account, choose to sync or share activities, or contact support.
No advertising, cross-app tracking, or external AI service is included in this version.
Who is responsible
Northline is operated by Caroline Beauchamp, who is responsible for the personal information described in this policy. For support, privacy questions, or a request about your information, email forcedreality0@gmail.com.
This policy describes the Northline iOS app and its planned supervised, invitation-only adult beta. Northline works fully on your iPhone without an account. Account, sign-in, and sync features described below operate only when the app is connected to a Northline account service.
What stays on your device
Northline stores your training profile and preferences, goals, calendar and training plans, recorded and imported workouts, activity history, saved routes and segments, selected profile photo, and optional check-ins on your iPhone. Workout information can include dates, activity type, duration, distance, pace, elevation, splits, cadence, perceived effort, and route coordinates and timing.
Check-ins describe how you feel, such as sleep quality, energy, and legs. Training memory includes preferences you save, workout feedback, and patterns inferred from your training. Plans, readiness and load estimates, revisions, weekly reviews, and accepted next-week adjustments are calculated and stored locally. These records are not automatically uploaded to a community server or sent to an external AI provider. Training suggestions are fitness estimates, not a diagnosis or medical clearance.
The pause-for-symptoms control stores a recommendation hold, not a description of your symptoms. An interrupted recording may have a local recovery copy until it is saved or discarded. The app also stores settings needed to operate it.
Your runner profile. The runner assessment asks about your goal, target race and date, recent weekly distance and longest run, running days and time available, easy pace and recent race times, running experience and training structure, access to a track, trails, a treadmill or hills, strength and cross-training, typical sleep, how recovered you usually feel, your preferred training intensity, and which reminders you want. Every question can be skipped. Your answers are stored on your iPhone and used to personalize your training, weekly availability, and pace zones. They are not uploaded to an account, used for advertising, or sent to an external AI service. Sleep and recovery answers are your own descriptions and are separate from Apple Health data. You can edit the profile in You → Settings → Runner profile; erasing local data removes it. A target race you enter becomes one of your saved races, which you can choose to sync like other races.
Northline disables its own CloudKit synchronization and marks its app-controlled health, location, training, draft, recovery, profile-photo, and social-settings files for exclusion from device backups. This setting does not remove older backups or control Apple's own Health and iCloud copies. It is not a guarantee that every historical or operating-system copy has been erased.
Location, motion, Apple Maps, and weather
With your permission, Northline uses location during a workout to record the route and calculate distance and pace. An activity you start can continue recording in the background and while the phone is locked. Optional motion access supplies walking or running cadence. Without location, the app can record a clearly labelled time-only activity.
Apple Maps provides map displays, place searches, and directions. Using these features sends the relevant map, search, or directions request, including relevant locations, to Apple. See Apple Maps and privacy. Spoken workout guidance does not record your microphone.
Weather. When you have allowed location, Northline sends your current approximate area to Apple's WeatherKit service to show local conditions and a short forecast on Today. It requests weather only while you are using the app, or when you tap to check conditions; it never asks for background location for weather. The most recent conditions (not your location) are kept on your iPhone for up to 90 minutes so the app does not ask again on every launch. If location is off, weather is simply not shown and training still works. Apple processes weather requests under Apple's privacy policy.
Apple Health is optional
Northline requests access to workouts and workout routes only when you choose to connect Apple Health. It imports your runs and walks, and other workouts as cross-training, to inform your local training history. If you separately turn on recovery context, Northline also reads sleep, resting heart rate, and heart-rate variability from Apple Health on this iPhone to inform readiness. It does not request energy data. Your check-in answers and runner-profile sleep answers are separate from Apple Health data.
When you choose “Save to Apple Health,” Northline can write the workout and its full recorded route to Health. A workout can save even if route permission or a route export fails; the app reports that separately.
Apple Health records and Northline's local copies are separate. Revoking Health access stops permitted future access but does not remove existing imports or exports. Deleting a workout or erasing Northline's local data does not delete the Apple Health record. Manage Health records and permissions in Apple Health or iPhone Settings. Importing again can bring a Health workout back into Northline. Apple's account and privacy settings govern Apple's copies.
If you deliberately share an imported workout, its selected summary and any included route use the same sharing path as a recorded workout. Health-derived information is not used for advertising, sold, synced to an account, or sent for external AI processing.
Northline accounts and sign-in
An account is optional. When the app is connected to a Northline account service, you can create an account with your email address, Sign in with Apple, or Google.
- Email (not yet offered; it will be enabled once verification email is set up): the service stores your email address, display name, a salted password hash, whether your email is verified, and session records. A mail provider receives your address and the message to deliver one-use verification and password-reset codes. If you try to sign up with an address that already has an account, that address receives a notice instead of a code; no second account is created.
- Apple or Google: the provider confirms who you are. The service stores the provider's stable account identifier and an encrypted token needed to revoke Northline's access if you unlink the provider or delete your account. With Sign in with Apple you can choose to share a private relay email address. Northline never receives your Apple or Google password.
- Sessions: sign-in tokens are stored in this iPhone's Keychain and are removed when you sign out. Accounts are never merged just because email addresses match.
If you choose private sync, the activities (including full routes), saved routes, races, and shoes you sync are stored in your account so you can restore them on another device. Your runner profile, check-ins, plans, and training memory are not synced. Signing out keeps everything already saved on this iPhone. Deleting your account removes it and its synced records from the service after any linked Apple or Google access is revoked. The account service runs on Fly.io infrastructure in the United States, which processes connection data such as IP addresses to deliver the service. An email provider will be named here before email sign-up is enabled.
Optional sharing and community
Local recording does not require an account. If you connect a community server, that service receives information needed for the features you use: your account identifier, handle, display name, bio, email when supplied, authentication inputs, and community actions such as follows, Cheers, comments, blocks, and reports. It does not read your phone's address book. Your local profile photo is not automatically uploaded.
Posting an activity sends its selected workout summary, caption or highlight, chosen audience, and optional trimmed route to that server. “Only me” still uploads the post. Followers-only and public audiences change who can see the post, not whether it is stored remotely. Public posts are available to other authenticated users of that service after review.
Route trimming hides endpoint areas but does not guarantee anonymity. Changing the default trim does not change older posts. A shared image or other export also goes to the recipient or app you select, which may keep its own copy.
The community implementation holds profiles, posts, and comments for review before other users see them. Authorized operators can review submitted content, including shared routes and private reports. Pending and rejected submissions remain stored until removed. Reporting and blocking controls are available in the community interface.
A separately configured community server's operator controls its hosting and logs; this policy cannot promise deletion from an independently operated server.
Northline+ and Apple payments
Apple processes App Store purchases and subscriptions. Northline uses StoreKit to read product information and verified purchase or subscription information, including product and transaction identifiers, expiration, revocation, and relevant renewal or grace-period status, to decide whether Northline+ is available, to show when it renews or ends, and to restore purchases. Access is granted only from transactions Apple has cryptographically verified. StoreKit supplies its signed on-device transaction records across launches. This version does not send those records to a Northline server or link them to your Northline account.
Northline does not receive your payment-card information from Apple. Apple manages billing under its own policies.
Deleting a social account, erasing app data, or uninstalling the app does not cancel an Apple subscription. Manage or cancel it in iPhone Settings → your name → Subscriptions. Cancellation is separate from requests to delete Northline information.
Retention and deletion
Local workouts and saved training information generally remain until you delete or replace them; there is no general automatic expiry. Some derived training information is refreshed, bounded, or replaced as your history changes.
- Delete an activity: use its deletion control. Northline also removes associated local route and recovery copies, rebuilds surviving training load, and invalidates related generated plans, observations, memory evidence, and reviews. This may reset derived planning information. It does not delete a previously shared server post, a recipient's export, or an Apple Health record.
- Erase local data: open You → Training settings → “Erase all data on this iPhone.” This removes app-readable local workouts, routes, check-ins, your runner profile, plans, memory, reviews, photo, drafts, cached weather, recovery data, and saved sign-ins, then returns to the welcome screen. This control does not require Northline+.
- Delete your account: if connected, open You → Settings → Northline account → Delete account. Recent ownership verification may be required. Successful deletion removes the live account and associated community records. Required linked-provider revocation must succeed before the service confirms deletion. If deletion fails, the app reports it.
For the optional community implementation, content and reports have no automatic timed purge; explicit content or account deletion removes related records. Credential expiry is not the same as deleting every stored record. Backup and log retention depends on the actual server operator and must be established before a service is opened to testers.
Deletion means removal of application-readable records and known copies. It does not promise forensic overwriting of storage, erasure of older operating-system backups, or deletion of copies held by Apple or people with whom you shared. For a connected account, delete the server account before erasing saved local sign-ins if you want both removed.
Support, this website, and service providers
If you email us, your email address, message, and any attachments leave your device and are processed by the mail services delivering the message so we can respond. Send only information needed for your request; avoid health records and precise routes. Support correspondence is kept as needed to handle your request and related follow-up. You can ask us to delete it or explain any remaining retention.
This privacy and support website is hosted by GitHub Pages. We add no analytics, advertising, tracking pixels, cookies, forms, or JavaScript. The host processes connection and request information, such as your IP address and requested page, to deliver and secure the website under its privacy policy. Hosting is separate from the iOS app's local training store; visiting these pages does not upload your workouts.
Northline does not use advertising or cross-app tracking in this version, and does not sell personal information. These pages do not change behavior in response to a browser Do Not Track signal because they do not implement that tracking. Apple, website hosting, email services, and recipients you select may process information outside your location under their own arrangements; we do not promise US-only storage.
Security
Northline uses iOS data protection for its sensitive local files. Protection permits an explicitly started workout to continue after the phone has first been unlocked following restart. Sign-in tokens use device-only Keychain storage accessible when unlocked. Release builds require HTTPS for account and community connections. Apple and Google sign-in use single-use, nonce-bound requests verified by the account service. These safeguards reduce risk; no app, device, or transmission method can guarantee perfect security.
Adult beta eligibility
The planned beta is supervised and invitation-only for adults. Testers must be at least 18 and have reached the age of majority where they live. It is not intended for children or teenagers. This does not mean the app independently verifies your age. If you believe someone below the beta's adult eligibility has provided information, contact forcedreality0@gmail.com so the situation and appropriate removal steps can be addressed. A broader release or younger audience requires updated eligibility arrangements.
Your choices and privacy requests
You can choose whether to answer the runner assessment, connect Health, allow location or motion, create an account, sync or share an activity, or turn on reminders. Change permissions in iPhone Settings and use the deletion controls described above. Turning a permission off does not delete information already saved.
Depending on where you live and which rules apply, you may have rights to access, correct, obtain a copy of, or delete personal information, withdraw consent, object to or restrict certain uses, or complain to a privacy regulator. Email forcedreality0@gmail.com with your request or to ask for reconsideration of a response. We may need reasonable information to verify that the request concerns you. Do not email passwords, sign-in codes, or identity documents unless a necessary verification method has first been agreed.
We cannot remotely view or erase training records that exist only on your iPhone; we can help you use the app's controls. Requests about Apple's records or a separate server may also need to go to that provider.
Policy changes
Updates will appear on this page with a revised effective date. Material changes to the beta's data practices will be explained before those changed features are enabled, with any required permission requested at that time.
Questions or requests: forcedreality0@gmail.com.