£7.99 a month or £49.99 a year14-day free trial
JogOn

Last updated 6 October 2026

Privacy policy

JogOn is a running training-plan app. This policy explains what we collect, why, who helps us run the service, how long we keep things, and your rights. We’ve tried to keep it short and specific.

The short version

  • We collect what we need to build and adjust your plan: your account, your goal, and the runs and workouts you choose to connect.
  • We don’t record GPS routes or your location, we don’t show ads, and we never sell your data.
  • Your calendar is read on your phone only. Event details never reach us.
  • Your data is stored in London, UK.
  • You can delete your account from inside the app, and everything goes with it.

Who we are

JogOn is run by [COMPANY NAME], [REGISTERED ADDRESS] (“we”, “us”). We are the controller of your personal data under UK data protection law (the UK GDPR and the Data Protection Act 2018). You can contact us about anything in this policy at [CONTACT EMAIL].

What we collect and why

WhatWhyLegal basis
Account: first name, email address, password (stored only as a one-way hash), time zone. If you sign in with Apple or Google, the account identifier they give us and the email they share (which may be an Apple “Hide My Email” address).To create your account, sign you in and keep it secure.Contract
Training profile: your goal race and date, target time, personal bests, the days you can train, run types to leave out, and strength-training preferences.To generate and adapt your plan.Contract
Activities from the services you connect: workout type (run or strength), start time, distance, duration, pace, elevation gain, average heart rate and lap splits.To match your runs and workouts to your plan and show your progress.Your explicit consent (heart rate is health data)
How you’re doing: how a run felt and any note you add, fortnightly check-ins, and injuries you log.To adjust your plan, including easing off when you report a niggle.Your explicit consent (this can be health data)
Gear: the shoes you add and the distance on them.To track shoe mileage.Contract
Connections: access tokens for Strava, COROS, Polar or Garmin (encrypted), and a record of workouts you send to your watch.To read your activities and send sessions to your watch, as you ask us to.Contract
App usage: which features are used (for example “plan created” or “replan applied”), tied to a random account ID, never your name or email. You can turn this off in the app.To understand what’s working and improve the app.Legitimate interests
Crash reports: technical details when the app or our server goes wrong, with no name, email, screenshots or tokens.To find and fix bugs.Legitimate interests

You give explicit consent to the health-related processing when you connect a source, log an injury or rate a run. You can withdraw it at any time by disconnecting the source, deleting the entry, or deleting your account.

What stays on your phone

  • Your calendar. If you turn on “Plan around my calendar”, JogOn reads when you’re busy on your device. Event titles, locations and attendees are never stored or sent. If you accept a suggestion, we only receive which days you can’t run, or how many minutes you have.
  • Reminders are scheduled on your device. We don’t run a push-notification server.
  • Apple Health and Health Connect are read on your device. JogOn only asks for read access to workouts, distance and heart rate, and never writes to them. The workouts it reads are uploaded to your account as activities (see above).

What we don’t collect

GPS routes or maps of your runs, your location, your contacts, your photos, or advertising identifiers. We don’t use your data for advertising and we don’t sell or rent it to anyone.

Connected services

You choose what to connect: Strava, COROS, Polar, Garmin (when available), Apple Health or Health Connect. We only request read access to your activities (plus, for COROS, permission to add sessions to your training calendar when you send one). You can disconnect any of them in the app; when you do, we revoke our access with that service and delete our tokens.

  • Apple Health: data from HealthKit is used only to provide JogOn’s features to you. It is never used for advertising or shared with third parties for their own purposes.
  • Health Connect: JogOn’s use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements.
  • Google Sign-In: we use only your Google account ID, name and email, to sign you in.
  • Strava: activities from Strava are only shown to you and are never shared with other users.

Who helps us run JogOn

These companies process data on our behalf, under contracts that only let them use it to provide their service to us:

ProviderWhat forWhere
Fly.ioRuns our serverLondon, UK
NeonDatabaseLondon, UK
ResendSends sign-in codes and account emails[REGION]
SentryCrash reports[EU or US: confirm when the Sentry organisation is created]
PostHogProduct analytics (if you haven’t opted out)EU
Apple, GoogleSign in with Apple and Google; app distribution and subscriptionsGlobal

Where a provider processes data outside the UK, we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to protect it. We may also disclose data if the law requires it.

How long we keep it

  • Your account data, plan and activities: for as long as you have an account.
  • When you delete your account (Profile → Delete account), we delete it straight away, along with your plan, activities, notes and connections, and we revoke our access to the services you connected.
  • Sign-in codes: deleted within 24 hours. Sign-in sessions expire after 60 days without use.
  • Database backups roll over within [BACKUP RETENTION, e.g. 7 days], so deleted data leaves backups by then.
  • Analytics and crash reports: kept for up to [ANALYTICS RETENTION] and then deleted.

How we protect it

Everything is encrypted in transit. Passwords are stored as Argon2id hashes, sign-in tokens as one-way hashes, and the access tokens for your connected services are encrypted (AES-256). On your phone, your sign-in is kept in the system keychain or keystore.

Your rights

Under UK data protection law you can ask us to:

  • give you a copy of your data, or send it to you in a portable format;
  • correct it;
  • delete it (you can also do this yourself in the app);
  • restrict or object to how we use it, including the analytics described above;
  • withdraw your consent at any time, which doesn’t affect processing before you withdrew it.

Email [CONTACT EMAIL] and we’ll reply within one month. If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk.

Children

JogOn isn’t intended for anyone under [MINIMUM AGE], and we don’t knowingly collect their data.

Changes to this policy

If we change what we collect or how we use it, we’ll update this page and its date, and tell you in the app before significant changes take effect.

Contact

[COMPANY NAME], [REGISTERED ADDRESS]. Email: [CONTACT EMAIL]. See also our support page.