← Vado

Vado Privacy Policy

Effective date: August 31, 2026

Vado is a running app for iPhone and Apple Watch, made by an independent developer. This page explains, in plain language, what data the app touches, where it lives, who can see it, and how to get out of anything you would rather not be in.

The short version:

Every section below answers the same four questions: what we collect, where it lives, who can see it, and how to leave.


Who we are

Vado is built and operated by an independent developer ("we", "us"). If you have any question about your privacy or this policy, see Contact at the bottom of this page.


Runs, health and fitness (Apple Health / HealthKit)

Vado records runs and reads your fitness data through Apple's HealthKit framework.

What the app reads from Health:

What the app writes to Health:

Where it lives: on your device, in Apple Health. Apple, not us, controls whether your Health data syncs to your other Apple devices through your own iCloud.

Who can see it: you. This data does not leave your device and reach our servers except through the specific, opt-in features described further down (cloud backup, Strava, and the social layer).

How to leave: you control HealthKit access in the iOS and watchOS Settings app, and you can revoke it at any time. The app keeps working, it just falls back to what it can measure on its own.


Location and motion

Where it lives: with the run, in Apple Health on your device.

Who can see it: you, unless you sign in (cloud route backup), connect Strava, or share the run with friends. Each of those is described below, and each is a choice you make.

How to leave: revoke Location in the iOS Settings app. Indoor and treadmill runs still work.


Camera and photos

Vado can use your camera to photograph a race bib, and it can save a share card to your photo library.

Vado never asks for permission to read your photo library. When you choose a picture, iOS shows you its own picker, which runs outside the app, and hands Vado only the single image you picked. The app cannot see the rest of your library, and does not ask to.


Weather (Apple WeatherKit)

To draw the sky in the running scene and to stamp the conditions on a finished run, the app asks Apple's WeatherKit for the current conditions at your run location. This sends your location to Apple, which returns the weather. That exchange is handled by Apple and is covered by Apple's privacy policy. The app keeps only the few weather fields it needs: the sky condition, the temperature and the wind speed. There is no wind direction and no place name. If weather cannot be fetched, the app falls back to a time of day sky.

Weather is fetched by the Apple Watch, so a run you recorded on the phone, and an indoor run, carry no weather stamp at all.

Where it lives: the weather stamp is stored with the run, the same way the run's other facts are.

Who can see it: the same people who can see the run. If you share a run with friends, the weather stamp goes with it.


Your account and cloud backup (optional)

Vado works completely offline with no account. If you want your training data backed up and restorable on a new phone, you can create one. You can sign in with:

With Sign in with Apple you can use "Hide My Email", in which case we only ever see Apple's relay address, not your real email address.

Our backend is hosted on Supabase. Every account's data is isolated by row level security, so your account can only ever read and write its own rows.

What syncs to your account when you are signed in:

What a backed-up run carries. The route track file for a run you recorded in Vado also carries the per run measurements that let us upload an honest activity rather than an estimate: a cadence series worked out from your step counts, the distance your own devices measured for that run, and the run's calories. If you switch "Send heart rate to Strava" on in Settings, that run's heart-rate readings ride along too. That switch is off unless you turn it on, and with it off the app does not even read those heart-rate readings, let alone write them into the backup. Everything here is per run, for runs you recorded in Vado. It lives in the same private, account-scoped file as the route track, and it is deleted when you delete your account.

What does NOT sync to our servers: your raw Apple Health database. Your complete workout archive, your day to day health history outside the runs you record in Vado, your VO2max samples, and your water log all stay in Apple Health on your device. Beyond the run metadata, route tracks (including the per run series described just above) and training state listed here, we store nothing from Health.

Where it lives: on Supabase, in rows and private storage files scoped to your account.

Who can see it: you. Nobody else sees any of it unless you send it to Strava or share it through the social features described below.

How to leave: if you never sign in, none of this leaves your device. Your training data lives locally on your phone and is cleared if you delete the app. If you have signed in, you can delete your account at any time (see Data retention and deletion).


Strava (opt-in)

Connecting Strava is entirely optional and off by default. If you connect it:

Where it lives: on Strava, under your own Strava account.

Who can see it: whoever you have given access to on Strava. That is Strava's setting, not ours.

How to leave: disconnect Strava at any time in Settings. Deleting your Vado account also asks Strava to revoke Vado's access, and destroys the token we hold either way. What Strava does with data you send it is governed by Strava's own privacy policy.


Social: your username, friends, leagues and sharing

Vado has an optional social layer: weekly leagues, friends, a shared run feed, props and comments, and mid run cheers. None of it is on until you choose a username. A new account has no username. You are invisible on every social surface until you pick one, and picking one is the switch that turns discovery on. Here is exactly what each piece shares, and with whom.

Your username

You choose it. The app never generates one for you. You can change it whenever you like, and it is the one name every social surface uses.

Who can see it: anyone on the board of a public weekly league you join (a cohort of roughly thirty runners, most of whom will be strangers to you), anyone who searches for it, and anyone you share anything with: your profile, shared runs, comments, props and cheers.

Search is on by default, and it matches parts of a name, not just the whole name. We cap how much of the name directory any one account can see, so nobody can page through everybody.

How to leave: the Private profile switch, in your profile's Edit screen. With it on:

Your profile photo

Adding a photo is optional.

Friends

Friendship is mutual accept. A request has to be accepted before either of you sees anything beyond a username. You can add people by searching their username or by sharing your invite link or QR code.

Your invite link contains no name and no account number. It is a random code that only our database can resolve, and following it creates a request for you to accept, never an instant friendship. Replacing the link stops the old one resolving immediately.

What accepted friends can see: your photo, the runs you choose to share (below), a count of consecutive weeks you have shared a run, league trophies, the leagues you share with them, and whether you are out running right now (see Cheers).

Sharing runs (the feed)

Sharing is per run. There is a toggle on each run, plus an optional "share new runs automatically" setting that you control. Unsharing removes the run from the feed, and deleting the run removes it from your friends' feeds too.

What a shared run carries:

Your calories, your cadence, your water log and the individual moments the app celebrates are not part of a shared run. They stay on your device or in your own private backup.

Route privacy trim. By default the app cuts the first and last 200 metres off every shared route, so the map never starts at your door. A runner who never opens Settings is trimmed. You can adjust the trim distance or turn it off in Settings, and the server re-applies your trim itself rather than trusting the app, so a bug in the app cannot leak the endpoints. The trim also removes any part of the route that passes near your start or finish mid run, and if too little of the route survives, the card shows no map at all rather than a revealing fragment.

Ran together. If you and a friend ran together, same time and same route, the server may group your two shared runs into one card, visible only to people allowed to see both runs. It matches on the shared geometry of runs you both already chose to share. It never reveals a run either of you kept private. A reader who can only see one of you gets an ordinary single card.

Props, comments and moderation

Friends can leave props (our word for a kudos) and comments on shared runs. Comments and usernames pass a server side profanity filter that rejects rather than rewrites. You can delete comments on your own runs.

Report and block work everywhere a person appears. Blocking is mutual and immediate: it ends the friendship, hides each of you from the other across the app, and is not undone by unblocking. Reports come to us for review, and the reported person is never told who reported them.

Cheers (live presence)

While you are on a run, accepted friends can see that you are running and send a cheer that plays on your watch or phone mid run. What they see is your username and the fact that a run is in progress. They never see your location, your route, your distance or your pace. Nothing about your run is written down for this: the live badge exists only while you are running and leaves no record behind.

This one starts on. It is the single social setting that is on by default rather than off, and it only does anything once you have a username and an accepted friend. A "let friends send props mid run" switch in Settings turns it off, and with it off your friends see no badge and no cheer button at all.

Push notifications (social)

If you allow notifications, our server stores three things so it can reach you: your device's push token, whether it is an iPhone or an Apple Watch, and when it was last registered. Nothing else. The token is used to deliver props, comments, cheers, friend requests and league results through Apple's push service. No app on any device, including yours, can read that list back. Declining notifications just means you see these things when you open the app. Your push token is deleted when you delete your account.

What the social layer never shares


Your race bibs (the Bib Wall)

You can photograph a race bib into a framed collection beside your medal case, and each bib links to the run it belongs to.

A race bib usually has your name, your race number, the race, and the date printed on it, so Vado treats a bib photograph as carefully as a profile photograph:

How to leave: delete a bib in the app, mark it private, or delete your account.


Feedback and Ideas

The app has a "Send Feedback" channel that goes straight to the developer. When you send one, we store what you typed, an optional reply address if you choose to give one, and the app version, build number and platform, so that a bug report can be reproduced.

You do not need an account to send feedback. If you are signed in, the note is stamped with your account, so we can reply in context, and it is deleted when you delete your account. If you are signed out, it arrives with no account attached to it, which also means we have no way to find it later and delete it for you. Write to us at the address at the bottom of this page if you want something you sent removed.

Who can see it: the developer. Feedback is never published and is never shown to other users.


Coach's note (written by an AI, and not switched on yet)

Vado is building a short written note about a run you rated, called the Coach's note. It is written by a large language model operated by Anthropic (the Claude API), which means a briefing about your run is sent to Anthropic's servers to be turned into a paragraph.

This feature is not switched on, and no version of Vado has ever sent anything to Anthropic. We are telling you before it exists so that none of it is a surprise later. When it does arrive it will be a Vado Pro feature, it will be off until you turn it on, and the app will ask you before it sends anything for the first time.

What the briefing would carry, and this is the complete list, because the briefing is built one named field at a time:

What the briefing never carries: your name, your email address, your location, or any device identifier.

Where it lives: the briefing goes to Anthropic to answer that one request. Anthropic's published commercial terms state that inputs and outputs from its commercial products are not used to train its models by default. On our side we keep a small record that a note was generated for a run: the run's identifier, the app's own verdict on it, and a count. We do not store the note's text on our servers. It comes back to your phone.

Who can see it: you. A Coach's note is not shared with friends, is not posted to the feed, and is not visible to anyone else.

How to leave: do not turn it on. If you have turned it on, turn it off in Settings, and nothing further is sent.


Marketing communications (opt-in)

Vado can send you occasional product news email: new features, worlds, and the occasional update from the developer. This is entirely opt in and off by default.

Turning this off, or deleting your account, removes you from the list. This is separate from transactional email: messages you would expect as part of using an account, like a sign in confirmation or a password reset. Those are not marketing and are not controlled by this switch.


Subscriptions and payments

Vado offers an optional paid subscription. All payments are processed by Apple through the App Store using your Apple ID. We never see or handle your card number or payment details. Apple tells the app only whether your subscription is active. Manage or cancel your subscription in the App Store, or in your Apple ID settings.


App integrity (App Attest)

To protect the backend from abuse and fraud, signed in requests can carry an Apple App Attest token. This is a cryptographic check, generated by your device's Secure Enclave, that confirms a request comes from a genuine, unmodified copy of the app. It contains no personal information and is not used to identify or track you.


Diagnostics (on device, opt in to share)

To help us find and fix crashes, freezes and slow launches, the app keeps a small record of its own health using Apple's MetricKit framework. This is on device only.

This uses Apple's own first party framework. There is no third party crash reporting service involved.


The companies that touch your data

These are the only outside parties any part of Vado sends your data to, what each one does, and why it is there. Each of them is bound by its own agreement with us to protect your data to at least the standard this policy describes, none of them may use it for their own advertising, and none of them may sell it. We share your data with nobody else.

Who What they do for Vado What reaches them
Apple The App Store, HealthKit, WeatherKit, push notifications, Sign in with Apple, App Attest, payments Your purchase, the location the watch asks the weather for, and the push messages we ask Apple to deliver. Your Health data stays on your device: it does not travel to us through Apple.
Supabase Hosts our database, our sign-in system and our file storage Everything listed under "Your account and cloud backup", isolated to your account by row level security
Google Sign in with Google, only if you choose it Your Google sign in, which returns your name, your email address and an account identifier
Mapbox Draws every map in the app See the note below
Strava Receives runs you choose to upload, only if you connect it Only what the Strava section above lists, only for runs you upload
Anthropic Will write the Coach's note, once that feature is switched on Only the briefing listed in the Coach's note section, and only once you turn the feature on. Nothing is sent today.

About maps, in full. Every map in Vado is drawn by Mapbox. Two things follow from that, and we would rather spell them out than leave them to a sentence about SDKs:

  1. Drawing a map fetches tiles from Mapbox's servers, which necessarily see your device's internet address and the part of the map you asked for.
  2. Mapbox's map component can send usage and performance telemetry to Mapbox. Vado switches that map-load telemetry OFF before the first map is ever drawn, so by default no device identifier, model, screen or orientation details leave your phone on our account. Mapbox's attribution menu (the small "i" on maps) contains Mapbox's own telemetry toggle; if you deliberately turn it on there, we respect your choice. One honest limit: Mapbox's component may still send a minimal anonymous usage signal used for its own service accounting, inside Mapbox's closed code where we cannot inspect it; it is governed by Mapbox's privacy policy and never carries your name, your account, your route or your health data.

Our own code dependencies are a local database library, the Supabase client for your account backend, Google's sign in library (used only if you sign in with Google), Mapbox's map renderer, and Apple's own frameworks, together with the helper libraries those bring with them. None of them is an advertising service, a data broker, or an analytics product we send your data to.


What we do NOT do


Data retention and deletion

Local data. Anything stored only on your device (your local training data, and your workouts in Apple Health) is removed when you delete the app or clear it in Apple Health. Health data is controlled by you, in the Health app.

Account data. While your account exists, we keep the synced data described above so that it is there to restore. You can delete your account at any time from your profile (top left of Home), then Account, then Delete account, inside the app.

Deleting your account:

This is a hard delete. It cannot be undone, and it does not touch your Apple Health data, which remains yours on your device.

Two things account deletion does not reach, so that you know to ask us:

Write to us at the address below and we will delete either one.


Children

Vado is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, write to us at the address below and we will delete it.


Your choices at a glance


The launch-notify list (this website)

If you enter your email address in the "notify me" form on this site, we store four things, and nothing else:

That address is used for exactly one thing: to email you once, when Vado launches. It is kept separate from any app account, so deleting a Vado account does not remove it. We do not add it to any other list, we do not share or sell it, and no third party marketing or email tracking service is involved. Ask us at the address below and we will delete it.

This site itself uses Cloudflare Web Analytics for page view counts. It is cookieless, collects no personal data, and does not track you across other sites.


Changes to this policy

If we change how the app handles data, we will update this page and move the effective date at the top. Material changes are noted in the change log below.

Change log


Contact

Questions or requests about your privacy or this policy? Email us at alexbolton@gmail.com (founder-ruled 2026-08-31: this address until the hello@vado.run mailbox exists, then both hosted copies switch together).