Privacy Policy
Last updated: May 2026 · Applies to: PhysioRun Pro app (physiorun.net/app)
This privacy policy explains how PhysioRun Pro handles your data. The short version: the app is designed to keep your data on your own device. We do not run a database. We do not collect or store personal information on any PhysioRun server.
Who We Are
PhysioRun Pro is a physiotherapist-built web app created by James Cruickshank, a qualified physiotherapist and founder of PhysioRun. The app is available at physiorun.net/app. If you have any questions about this policy, you can contact us at physiorun1@gmail.com.
What Data the App Uses
The app stores the following information in your browser’s local storage on your own device only:
- Strava OAuth tokens — if you choose to connect your Strava account, your access token, refresh token, and token expiry are stored locally so you don’t have to reconnect each visit. These tokens never leave your device.
- Strava activity cache — a small summary of your weekly mileage, monthly mileage, and training load ratio is temporarily cached to avoid unnecessary repeat API calls. This contains no personally identifiable information.
- parkrun ID — if you save your parkrun athlete number for the barcode feature, it is stored locally on your device only.
- Personal bests — race times you enter manually (3K, 5K, 10K, half marathon, marathon) are stored locally on your device only.
- App preferences — minor settings such as the last page visited may be stored locally to improve your experience.
None of the above is ever sent to or stored on a PhysioRun server. There is no PhysioRun user account, no login, and no backend database.
Strava Integration
PhysioRun Pro optionally integrates with Strava to provide training load insights and personalised physio advice based on your running data. This integration is entirely opt-in — you must actively choose to connect your Strava account.
When you connect Strava, PhysioRun accesses the following data via the Strava API:
- Your activity history (last 60 activities) — used to calculate weekly and monthly mileage, run frequency, and training load. Displayed back to you within the app only.
- Your athlete profile (first name, last name, profile photo) — displayed in the Strava card header for personalisation.
PhysioRun requests only the minimum necessary Strava permissions: read and activity:read. The integration is read-only — PhysioRun never posts to Strava, never modifies your activities, and never interacts with your Strava account beyond reading the data listed above.
Strava data is processed in your browser and displayed on screen. It is not uploaded to any PhysioRun server, not shared with any third party, and not used for any purpose other than showing you your own training information alongside physio-led insights.
You can disconnect Strava at any time using the Disconnect button in the app. This immediately clears all Strava tokens and cached data from your device’s local storage.
For information on how Strava handles your data on their end, please refer to Strava’s Privacy Policy.
Cookies
PhysioRun Pro does not use tracking cookies. The app uses browser local storage (not cookies) to save your preferences and connected account tokens on your own device. This data is not accessible to PhysioRun or any third party.
The physiorun.net website may use standard WordPress cookies for site functionality. These are limited to session management and do not track your activity across other websites.
Third-Party Services
The app integrates with the following third-party services at your request:
- Strava — for activity data (see Strava Integration above). Only accessed if you choose to connect.
- YouTube — exercise demonstration videos and running route videos open in YouTube when tapped. YouTube’s own privacy policy applies when you visit their platform.
- physiorun.net — article and resource links open on the PhysioRun website, which is a standard WordPress site.
PhysioRun does not use Google Analytics, Facebook Pixel, advertising networks, or any other tracking or analytics tools within the app.
Your Rights
Because PhysioRun does not hold your personal data on any server, there is no central record to access, correct, or delete. All data the app uses is stored locally in your browser. You can remove it at any time by:
- Disconnecting Strava using the button in the app (clears all Strava tokens and cache)
- Clearing your browser’s local storage or site data in your browser settings
- Uninstalling the app from your home screen if installed as a PWA
If you have any questions about your data or this policy, please contact us at physiorun1@gmail.com.
Changes to This Policy
We may update this policy from time to time, particularly as new features are added to the app. The date at the top of this page will reflect when the policy was last revised. We will not make changes that reduce your privacy protections without clearly noting them here.
