Privacy Policy
Privacy Policy
Shakeout works out your training on your phone. Your plan, your paces and your fitness score are calculated on the device, not on a server. This page explains what does leave your phone, why, and how to get rid of it.
The short version
- You need an account. You can sign in with Apple, with Google, or with a code we email you. We never see a password.
- A copy of your training is stored on our server so you can get it back after a reinstall or on a new phone. That copy includes runs read from Apple Health.
- We read the GPS route of your runs from Apple Health, and that route never leaves your phone.
- We use analytics and crash reporting to find bugs and see where people get stuck.
- This website sets no cookies unless you accept the banner, and you can change your mind from the Cookies link at the bottom of any page.
- We do not sell your data, show you ads, or use anything from Apple Health for advertising.
- You can delete your account, the backup and everything on your phone from inside the app.
1. Scope
This policy covers the Shakeout app for iOS and this website, shakeout.io. It describes what we collect, what we do with it, who else sees it, and the choices you have.
Curtis Searle () is the data controller for the information described here. Contact details are in section 10.
2. Information we collect
This section is what we collect and where it comes from. What we do with it is section 3, and the legal basis for each purpose is the table in section 8.3.
2.1 Your account
Signing in is required to use Shakeout. There are three ways to do it, and none of them involves a password we could see or store.
Sign in with Apple, or sign in with Google. The provider confirms who you are and gives us an identifier for you. Apple's is specific to Shakeout and cannot be used to identify you anywhere else. We also receive your email address if the provider passes one on. Apple lets you hide yours behind a private relay address, and if you do, that relay address is all we ever see. We use it only to reply to you.
Sign in with an email code. You give us your email address and we send you a six-digit code. We store the address and a one-way scramble of the code, never the code itself. The code stops working after ten minutes or after five wrong guesses, and the record is deleted once it is used or expires. On this route your email address is what identifies your account, so it is stored for as long as the account exists.
Whichever route you use, we generate an account number of our own. It is a random identifier with no meaning outside our system, and it is what everything else below is filed under. It is not your email, not your Apple or Google ID, and not any advertising or device identifier. If you sign in with Apple on your phone and Google on another device, both point at the same account rather than making a second one.
An account is required because without one there is nowhere to keep your subscription or your backup.
2.2 Apple Health
If you allow it, Shakeout reads your running workouts from Apple Health so that sessions tick themselves off and your fitness score stays current. Access is read only, and the app never writes to Apple Health.
For each workout we read:
- The workout itself, its distance and its duration.
- Your heart rate during it.
- Your step count during it, which is how we work out your cadence. We do not read your daily step count, only the steps inside a run.
- Its route, meaning the GPS trace your watch or phone recorded. The route is what gives a run its climb and the detail in your run review.
Your route stays on your phone. It is not in the backup and it never reaches our server. If you restore onto a new phone your runs come back without their routes, and Apple Health fills them in again as it re-syncs. The climb figure calculated from a route does go in the backup, because it is part of the run.
Health and fitness information is a special category under UK data protection law, and we process it on your explicit consent. That is what the Apple Health permission prompt asks for, and you can withdraw it at any time in the iOS Settings app.
You can turn this off at any time in the iOS Settings app, under Privacy and Security, then Health, and you can allow some of the categories above and refuse others. Turning it off stops new runs being read. Runs already logged stay in your training history, and in the backup, until you delete them or delete your account.
Apple requires that health data is never used for advertising, marketing, or any purpose other than health and fitness. We do not use it for any of those things.
2.3 Your training backup
So that a lost or replaced phone does not cost you your training, Shakeout keeps one copy of it on our server. It is stored as a single file per account, and it is overwritten each time your phone sends an update.
That file contains:
- Your training plan, your goal race and the dates around it.
- Your fitness score and the race times you entered to produce it.
- Every run you have logged, including the details read from Apple Health: distance, duration, heart rate, cadence, climb, and the splits and laps within a run.
- Your settings, such as miles or kilometres, and which integrations you have turned on.
- A random name for the phone that wrote the file. It tells two of your own devices apart so they do not overwrite each other's backups. It is not an advertising or device identifier, and it is not restored onto a new phone.
This means information derived from Apple Health does leave your phone, as part of that backup.It is stored so that you can restore it, and for no other purpose. It is never used for advertising or marketing, never sold, and never shared with anyone outside the processors listed in section 4.1.
The GPS route of your runs is not in it. See section 2.2.
Alongside the file we keep a small record of the file itself: its size, a version tag, and when your phone last sent it. That record holds no details of any run.
2.4 Runs from somewhere else
You can also import a run as a .fit file, the format watches and bike computers export. The file is read on your phone and the run it describes is logged like any other, which means it is covered by section 2.3. We do not keep the file itself.
Sending a session to your watch works the other way round: the app writes a workout file and hands it to iOS to pass on. Nothing about that goes to us.
2.5 Your calendar
If you turn calendar sync on, Shakeout creates a calendar of its own on your device, called Shakeout, and puts your training sessions in it as events. We do not read your other calendars or any event we did not create, and none of it reaches our server. Deleting your account, or turning the setting off, removes the events the app created.
You can revoke calendar access at any time in the iOS Settings app, under Privacy and Security, then Calendars.
2.6 Analytics and crash reports
We use PostHog to understand how the app is used and to find crashes. It records which screens were reached and which actions were taken, for example that a plan was generated or that a session was completed, along with a category such as the race distance.
PostHog also records your screen while you use the app, so we can see how a fault or a confusing screen actually played out. Anything you type is hidden before the recording leaves your phone, as are images. Text the app has drawn on screen is not hidden, so a recording can show figures you may consider private, including your paces, your race times and numbers derived from Apple Health. Screen recordings are kept for 30 days and are then deleted.
Crash and error reports are collected automatically. These include the technical details of what failed and where in the app it happened.
Location lookup from your IP address is switched off, so we never learn where you are from it. PostHog does still receive your IP address as part of delivering the data, as any server does. Analytics are not tied to your account: we do not build a profile of you in PostHog, and the events carry a random identifier for your installation rather than your account number. Your installation identifier does not follow you to any other app or website.
If you would rather not be included, email us and we will tell you how to switch it off for your installation.
2.7 Feedback
If you send feedback from inside the app, we receive the category you picked, which is a bug, an improvement or a question, and whatever you write, up to 1,000 characters.
It reaches us through PostHog, which opens it as a ticket in our private issue tracker on GitHub so we can act on it. Both are listed in section 4.1. The tracker is private and is read only by us. Please do not include anything you would rather we did not read, such as health details you want to keep private.
2.8 Subscriptions and payments
Subscriptions are sold by Apple and billed to your Apple ID. We never see your card details. We use RevenueCat to tell us whether your subscription is active, which means sending them an app-specific identifier and the transaction from Apple. That identifier is generated by RevenueCat and is not your account number.
2.9 The launch waitlist
If you leave your email address on this website to hear when Shakeout launches, we store the address and the date you left it, and nothing else. We use it once, to tell you the app is out. We do not share it, and you can ask us to remove it at any time by emailingsupport@shakeout.io. The whole list is deleted after launch.
3. How we use your information
We use what section 2 describes to do these things, and nothing else:
- Give you an account, and keep you signed in on the devices you use.
- Build your training plan, and adapt it as you log runs against it.
- Tick off sessions automatically, and keep your fitness score current.
- Keep one off-device copy of your training so you can restore it.
- Put your sessions in your calendar, if you have asked for that.
- Confirm whether your subscription is active.
- Find faults, fix them, and see where people get stuck.
- Read and act on the feedback you send us.
Your training plan is generated by the app from your race times and your logged runs. That happens on your phone, no person reviews it, and it has no effect on you beyond telling you what to run. You can change any of the answers behind it, or edit the plan, at any time.
The legal basis for each of these is in the table in section 8.3.
4. How we share your information
4.1 Who processes your data, and where
We use these companies to run the service. They act on our instructions and nothing more.
- Cloudflare hosts our server, our database and your training backup, and sends the email containing your sign-in code.
- PostHog handles analytics, crash reports and feedback in the app, and, if you accept the cookie banner, counts visits to this website. Their servers are in the United States.
- GitHub holds the private issue tracker your feedback is opened in.
- RevenueCat confirms subscription status.
- Apple provides sign-in and takes payment.
- Google provides sign-in, if that is the way you signed in.
Some of these transfer data outside the UK. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on an equivalent safeguard.
4.2 What we never do
- We do not sell or rent your data.
- We do not show advertising, and there is no advertising identifier in the app. Our analytics do give your installation a random identifier so that one person's session can be told from another's, and that is the only identifier of its kind we use.
- We do not track you across other apps or websites.
- We do not use anything from Apple Health for advertising or marketing.
4.3 Connected watch services
Shakeout is built to connect to Garmin and COROS in future. That is not switched on, and no data flows to or from either service today. When it does, we will store the access credentials you grant, encrypted, and we will update this page before it goes live.
5. Cookies and similar technologies
This website sets no cookies until you say yes. The first time you visit, a banner asks whether we may count your visit. Nothing is loaded and nothing is stored while that question is open, so declining is not a matter of us switching something off. It is a matter of it never having started.
If you accept, we load PostHog and it sets a cookie so that your second page counts as the same visit as your first. It records the pages you opened, roughly where in the world you are from your IP address, and which site sent you here. It does not record your screen, and it does not follow you to any other website.
If you decline, nothing loads, and we store one small note in your browser remembering that you said no so the banner stops asking. That note is not a cookie, it is not sent to us, and it is the only thing we keep.
To change your mind either way, use the Cookies link at the bottom of any page. Withdrawing is the same two clicks as agreeing was.
Lawful basis: your consent, which is what the banner asks for and what the Cookies link withdraws.
None of this applies to the app, which does not use cookies. The app uses no advertising identifier and no cross-app tracking technology, and the only identifier of that kind anywhere in Shakeout is the random installation identifier described in section 2.6.
6. Your privacy rights and choices
6.1 Your rights
Under UK data protection law you have the right to see the data we hold about you, to have it corrected, to have it deleted, to take it elsewhere, and to object to or restrict how we use it. To exercise any of these, email support@shakeout.io.
To delete everything: open Shakeout, go to the ME tab, and choose Delete account. This removes your account, your backup and the training stored on your phone. It cannot be undone, and you do not need to contact us to do it.
Two things that deletion does not reach, because neither is filed under your account: analytics and crash reports, which carry your installation's random identifier and not your account number, and any feedback you chose to send us. Screen recordings age out after 30 days either way. Email us if you want those removed as well and we will do it.
Signing out is not the same thing. It stops the backup updating and leaves your training on your phone, and your account and its backup stay where they are.
If you think we have handled your data badly, please tell us first so that we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
6.2 Your choices
- Apple Health: allow it, refuse it, or allow some categories and not others, in the iOS Settings app. See section 2.2.
- Calendar sync: off unless you turn it on. See section 2.5.
- Analytics in the app: email us and we will switch it off for your installation.
- Cookies on this website: off unless you accept the banner, and reversible from the Cookies link at the bottom of any page. See section 5.
- Feedback: only sent when you write it and press send. See section 2.7.
- The launch waitlist: only if you typed your address on this website, and removable by email. See section 2.9.
- Everything: delete your account from the ME tab. See section 6.1.
7. Children's privacy
Shakeout is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has given us information, contact us and we will remove it.
8. Additional important information
8.1 Where your data is stored, and how it is protected
Your account and your training backup are held by Cloudflare. Everything else your phone knows about your training stays on your phone.
- The token that keeps you signed in is held in the iOS Keychain and is deliberately kept out of the backup, so it can never be restored onto another device.
- A sign-in code is stored as a one-way scramble, so the stored form cannot be turned back into a code that works.
- Credentials for a connected watch service, when that is switched on, are encrypted before they are stored.
8.2 How long we keep it
- Your account and your backup: for as long as your account exists. The backup is a single file that is replaced each time your phone updates it, so we do not keep a history of earlier versions.
- A sign-in code and the address it was sent to: deleted once the code is used or expires, within ten minutes. If you signed in with an email code, the address itself is kept for as long as the account exists, because it is what identifies the account.
- A waitlist address: until the app launches and the announcement is sent, or until you ask us to remove it, whichever is first.
- Screen recordings: 30 days, then deleted.
- Analytics and crash reports: 12 months.
- Website visit counts: the same period, and only if you accepted the banner. The cookie itself expires after a year, or sooner if you decline or clear your browser.
- Feedback you send us: for as long as the ticket is open, and afterwards as part of our record of what was reported and fixed.
Deleting your account removes the first of these, as described in section 6.1.
8.3 Notice for individuals in the UK and the EEA
We process your information only where the law gives us a basis to. This table sets out each purpose, the data it uses, and the basis we rely on.
| Why and how we process data | What data is processed | Legal basis |
|---|---|---|
| Give you an account and keep you signed in | Your sign-in identifier from Apple or Google, your email address, your account number | Performance of our contract with you |
| Tell you when the app launches, if you asked us to | The email address you left on this website | Your consent, withdrawable at any time |
| Build your training plan and adapt it as you run | Your race times, your fitness score, your goal race, the runs you log | Performance of our contract with you, and your explicit consent for the health and fitness parts |
| Read your runs from Apple Health so sessions tick themselves off | Workouts, distance, duration, heart rate, step count during a run, route | Your explicit consent, given at the Apple Health prompt and withdrawable at any time |
| Keep one off-device copy of your training so you can restore it | The file listed in section 2.3 | Performance of our contract with you, and your explicit consent for the health and fitness parts |
| Put your sessions in your calendar | Session dates, names and times | Your consent, given at the iOS calendar prompt and withdrawable at any time |
| Confirm whether your subscription is active | An app-specific identifier from RevenueCat, the transaction from Apple | Performance of our contract with you |
| Find faults, fix them, and see where people get stuck | Analytics events, screen recordings, crash reports, your installation identifier, your IP address | Our legitimate interest in fixing faults and improving the app |
| Count visits to this website | The pages you opened, the site that sent you here, your IP address, and a cookie so a second page counts as the same visit | Your consent, given at the cookie banner and withdrawable from the Cookies link at the bottom of any page |
| Read and act on your feedback | The category you picked and what you wrote | Our legitimate interest in fixing what you tell us is wrong |
8.4 If something goes wrong
If your data is lost, exposed or taken, and it is likely to put you at risk, we will tell you what happened and what to do about it. We will report it to the Information Commissioner's Office within 72 hours of finding out, which is what the law requires of us.
9. Policy updates
If we change how we handle your data we will update this page and change the date at the top. For anything significant we will tell you in the app before it takes effect.
10. Contact us
For anything about your data, including a request to see or delete it, contact support@shakeout.io. We are Curtis Searle, .