RoundOne Privacy Policy
Last updated: September 13, 2026
This policy explains how RoundOne handles information across the RoundOne iPhone and Apple Watch app, coach portal, website, waitlist, and related backend services. It also separates data that stays on your devices from data that is sent to RoundOne or a service provider.
1. Who this policy covers
This policy applies when you use RoundOne as an athlete, coach, gym administrator, website visitor, or waitlist member. “RoundOne”, “we”, and “us” refer to the operator of the RoundOne service. For privacy questions or requests, email hello@roundone.club.
2. Data the app and service collect
Account and identity
When you create or use an account, RoundOne may receive and store:
- your name and email address, including an address supplied through Sign in with Apple or email-link sign-in;
- the account identifiers created by Apple and Firebase Authentication;
- authentication-provider, email-verification, account-creation, and last-sign-in status; and
- your gym, coach, class, membership, invitation, and referral relationships.
Sign in with Apple may let you use Apple’s private relay email address. RoundOne receives only the details Apple makes available under your choice.
Training profile, Gym Loop, and coach collaboration
To provide training plans and gym features, RoundOne may store your selected training goal, experience level, training days, reminder settings, starter-plan selection, joined classes, assigned work, attendance, and related progress records.
When you complete a coach or gym assignment and choose to save it, the app sends the gym ID, assignment ID, workout ID, completion time, duration, and any optional effort rating or note you submit. This lets the result appear for the relevant coach or gym. The assignment sync does not send your heart-rate samples, exact route, GPS coordinates, Apple Health records, workout photo, or general local workout notes.
Purchases, access, and referrals
Apple processes subscription payment details. RoundOne does not receive your payment-card or bank details. To verify access and operate referrals or offers, RoundOne may store subscription status, Apple transaction identifiers, an app-account token, referral relationships, reward status, and redeemed-offer status.
Shared-workout engagement
If you open and train from a shared workout link, RoundOne records the link and session identifiers, a randomly generated app-installation visitor identifier, whether the session started or completed, elapsed training time, and whether the source was the app or browser. This provides the workout owner with aggregate starter, completion, and trained-time totals. The visitor identifier is not deliberately joined to your RoundOne account, name, or email.
App integrity and service diagnostics
The iPhone app uses Firebase App Check with Apple App Attest to help distinguish genuine app requests from abuse. Apple and Google Firebase process app-attestation objects, assertions or tokens, and standard technical request information such as app, SDK, device, and operating-system versions. These signals are used for security and service operation, not advertising or cross-app tracking. App Check is an additional integrity signal and does not replace account authentication or access rules.
Firebase Authentication, Firestore, Storage, and hosting or function infrastructure may also process standard network and service metadata, such as IP address, request time, app version, device or operating-system family, and SDK status, for authentication, security, reliability, capacity, and aggregate SDK-adoption measurement. This Firebase service telemetry is separate from Google Analytics for Firebase.
Crash reporting: release-controlled
The iPhone app includes Firebase Crashlytics, but crash transmission occurs only in a release where RoundOne’s reviewed crash-collection switch is enabled. When the switch is off, unsent crash reports are deleted rather than held for a later upload.
If that switch is enabled, Crashlytics receives crash stack traces, relevant application state, crash time, app release and build, iOS version, device model and architecture, memory and disk information, a Crashlytics or Firebase installation identifier, runtime platform, and the App Check provider name. RoundOne does not attach your account ID, name, email, raw log or error text, workout note, coach content, HealthKit data, heart rate, route, or precise location. RoundOne uses this information only to find and fix app failures and operate crash alerts.
Mobile product analytics: current 1.9.0 release
The currently public iPhone app, version 1.9.0, uses Google Analytics for Firebase and PostHog for mobile product analytics, and its Apple Watch app uses PostHog. In that release, RoundOne links the Firebase account UID to mobile analytics events, so product-interaction, device, usage, and limited diagnostic event data can be associated with an account across Firebase Analytics and PostHog. Events include screen and feature use; workout, health-import, and other health- or fitness-related activity; subscription, purchase, offer, and referral flows; onboarding selections and progress; and stable outcome or failure codes. The providers also receive standard event and device information, such as event time, app release, device or operating-system family, and coarse location derived from a masked IP address. These diagnostic events are not crash reports, and this mobile analytics flow does not use Firebase Crashlytics or Firebase Performance Monitoring. RoundOne does not deliberately send exact GPS routes, precise coordinates, heart-rate samples, workout photos, free-text workout notes, names, or email addresses in these analytics events.
The shared-workout aggregate measurement and the Firebase service metadata described above are separate service flows. Analytics generated by version 1.9.0 may remain associated with account identifiers after an update until the relevant provider retention or deletion process removes it.
Onboarding usage analytics in the upcoming iPhone update
An upcoming RoundOne iPhone update uses Google Analytics for Firebase to understand which onboarding steps work well and where people get stuck. Sharing is on automatically in that update. You can turn Share usage analytics off through Analytics privacy during onboarding, before signing in, or through Usage analytics in Settings → Privacy & Data. Turning sharing off does not limit workouts, account features or subscription access.
RoundOne measures progress through Focus, Level, Plan, Move and Save, including resumed steps, time spent, the short first-round demonstration, the sign-in method and a limited success or failure category, whether the subscription offer appeared, and whether access became active. These events contain a limited set of categories and numbers. They do not include your name, email, account identifiers, workout or gym identifiers, exact training schedule, Health records, precise location, full links, or free-form text.
Firebase also processes a random Analytics app-instance identifier, event times, app and operating-system versions, device and language information, approximate country or region derived from network information, session and engagement details, and applicable App Store purchase or subscription events. Purchase measurement can include product identifiers, price, currency, quantity and subscription or trial status. We do not attach your RoundOne account ID to Analytics, including after sign-in. The app-instance identifier distinguishes installations; it is not a count of individual people.
The update disables automatic screen reporting, IDFV collection and advertising features. It does not use the advertising identifier (IDFA), an App Tracking Transparency prompt, PostHog mobile analytics, or analytics in the Apple Watch app. Google signals, advertising personalisation and granular location and device collection are disabled in the production Analytics property. Essential Firebase authentication and security processing remains separate from optional usage analytics.
Turning sharing off stops new usage collection on that installation and resets its local Analytics data. The choice persists across app launches, sign-out and account switching. Turning it on again permits future collection in an analytics-enabled release. On upgrade, the app also resets legacy Analytics data queued on the device and its old app-instance state once before any new collection. Neither reset deletes records already held by a provider.
3. Data that stays on your devices or in Apple services
The app can process detailed fitness information locally, including workout history, rounds, exact GPS routes, distance, pace, heart rate, energy, photos, and workout notes. If you grant permission, it may read or write approved workout, route, heart-rate, and active-energy data using Apple Health. Roadwork uses location only while the workout feature is active under the permission you grant.
RoundOne does not upload exact routes, GPS coordinates, Apple Health samples, heart-rate timelines, workout photos, or your general local workout journal to the RoundOne backend or coach portal in the upcoming iPhone update. Those items stay in the app’s local storage and, when you choose the relevant feature, in your Apple Health or iCloud account. Apple controls those services under your Apple settings and its own privacy terms. The limited coach-assignment summary described in section 2 is the exception: its completion time, duration, optional effort, and optional note are sent to RoundOne.
If you choose the Strava export, the app creates a TCX activity and sends the workout upload and follow-up activity update directly from your device to the Strava account you connected. An interrupted export may retry later. Depending on the selected workout, that transfer can include a RoundOne workout identifier, start and end time, duration, calories, heart-rate samples, exact GPS coordinates, workout type and name, whether it was recorded with GPS, top combo, and workout note. Strava redirects an OAuth authorisation code through auth.roundone.club; RoundOne’s function transiently processes that code and the access or refresh credentials and expiry needed for exchange, refresh, and attempted revocation. The function has no application credential store and does not receive the TCX workout payload, although ordinary hosting request and security metadata described above may still be processed. The app stores the Strava credentials in the protected iOS Keychain. Strava handles the exported activity under its own terms and privacy policy.
4. Website, waitlist, and coach-portal data
- Netlify and other hosting providers process ordinary web-request information, including IP address, browser, device type, requested page, referrer, and request time, for delivery, security, and diagnostics.
- Waitlist or contact forms process the email address and other information you submit.
- The coach portal may use configured PostHog product analytics with automatic capture, session recording, heatmaps, surveys, exception capture, and performance capture disabled. Allowed events use limited properties and are not deliberately joined to a Firebase account ID.
- The waitlist page uses Meta Pixel for page-view, lead, scroll, and time-on-page measurement. Meta may receive browser identifiers, cookies, IP address, and page activity under Meta’s own terms.
- Referral pages may use local storage to preserve a referral code until you open the app.
The Meta Pixel applies to the waitlist website, not the RoundOne iPhone or Apple Watch app. The app contains no third-party advertising. Mobile analytics is used to understand and improve RoundOne. RoundOne does not combine it with data from other companies for targeted advertising or advertising measurement, or share it with data brokers.
5. Why we use data
RoundOne uses information to:
- authenticate accounts and provide the app, coach portal, subscriptions, referrals, and support;
- personalise the training plan and schedule you ask RoundOne to build;
- connect athletes with their chosen gym, coach, classes, assignments, announcements, and attendance history;
- sync assignment results and show aggregate shared-workout engagement;
- protect accounts and services, prevent abuse, diagnose failures, maintain capacity, and improve reliability;
- measure mobile product use in version 1.9.0, the onboarding and access journey in the upcoming iPhone update, coach-portal use, and website or waitlist performance as described above; and
- meet legal obligations, enforce our terms, and protect users or the service.
6. Who receives data
We disclose data only as needed for the purposes above:
- Google Firebase and Google Cloud: authentication, databases, storage, backend functions, App Check, and—only after the reviewed release switch—Crashlytics;
- Apple: Sign in with Apple, App Attest, App Store subscriptions, HealthKit, and iCloud features you choose to use;
- Netlify: website and portal delivery, forms, functions, and operational logs;
- Google Analytics for Firebase: mobile product analytics from version 1.9.0 and the onboarding usage analytics described in section 2;
- PostHog: mobile product analytics from the currently public version 1.9.0 and limited coach-portal analytics when configured;
- Meta: waitlist-page measurement through Meta Pixel;
- your coach or gym: membership, class, attendance, assignment, and completion information required for the Gym Loop you join; and
- a connected service: information you direct RoundOne to export or connect.
Service providers processing data on RoundOne’s behalf are expected, under their applicable service terms and our configuration or instructions, to protect it and use it only to provide the contracted service. Apple, Meta, and any service you independently connect may also act under their own privacy terms.
RoundOne does not sell personal information for money. The waitlist’s Meta Pixel may be treated as “sharing” for cross-context behavioural advertising under some laws. You can use browser privacy controls or email hello@roundone.club about an applicable opt-out request. We do not give fitness or Apple Health data to advertising providers.
7. Retention and deletion
- Account and cloud content: kept while needed to provide the account and service. The in-app Delete Account flow disables access and starts deletion or de-identification of the Firebase account, user-owned cloud records, linked gym identity fields, and user storage. Non-identifying gym records, such as attendance or completion totals without name, email, account ID, or athlete note, may remain so a gym can preserve legitimate history.
- Deletion receipt: RoundOne may keep an opaque receipt showing that deletion completed, without your account ID or email, for 90 days.
- Provider systems: deletion from live systems and backups may take additional time under provider schedules. Firebase states that authentication data deleted by its customer is removed from live and backup systems within up to 180 days, and that authentication IP logs are kept for a few weeks.
- Local and Apple data: deleting your RoundOne account clears the app’s local profile and workout history used by that installation, but it does not control copies already written to Apple Health or iCloud. Manage or delete those separately through RoundOne’s local/iCloud controls and Apple settings.
- Strava: disconnecting Strava or deleting your RoundOne account always clears local Strava credentials, pending exports, and local export history and attempts best-effort remote revocation. A network or provider failure can prevent that remote step. RoundOne does not delete activities already in your Strava account; manage those in Strava.
- Shared-workout engagement: the randomly generated visitor identifier is not joined to your account, so account deletion cannot reliably locate historical visitor-level engagement. Pseudonymous session records and aggregate totals may remain; deleting the app removes the local visitor identifier from that installation.
- App Check: Firebase states that it does not retain App Check attestation material. Successful tokens expire under their configured time-to-live; tokens used for replay protection may be retained for up to 30 days. Apple handles material sent to App Attest under its terms.
- Crashlytics, if enabled: Firebase states that crash traces and associated installation identifiers are retained for 90 days before removal begins. Because RoundOne deliberately does not attach an account identity, an account-deletion request cannot select an earlier anonymous crash report by user.
- Mobile analytics: updating the app does not itself delete analytics records previously generated by version 1.9.0. Existing provider-held records remain subject to the applicable Firebase and PostHog retention and deletion settings. For the upcoming onboarding analytics, Google Analytics is configured to retain event-level and user-level data for two months, without restarting the retention period on new activity. These controls do not delete aggregated reports. Because the new Analytics app-instance identifier is not joined to your RoundOne account, deleting an account cannot automatically locate that installation’s historical analytics records. Turning sharing off, removing or reinstalling the app does not itself delete provider-held history. Contact us about an applicable analytics deletion request.
- Website, waitlist, and portal: submissions and operational or analytics records are kept only as long as reasonably needed for the stated service, security, support, campaign, or legal purpose and according to configured provider retention. Email hello@roundone.club to request deletion where the record can be identified.
8. Your choices
- Use Sign in with Apple’s email-sharing choices.
- Manage Health, location, photo-library, and notification permissions in Apple settings.
- Delete individual local workouts, clear local or iCloud workout history using available controls, or remove the app.
- Leave a gym or class and manage connected services where those controls are available.
- Manage subscriptions through Apple.
- In the upcoming analytics-enabled iPhone update, turn Share usage analytics off through Analytics privacy during onboarding or Usage analytics in Settings → Privacy & Data. This stops future collection on that installation and persists after sign-out and relaunch; it does not erase provider-held history.
- Use Delete Account in the app to start account and cloud-data deletion.
- Email hello@roundone.club to request access, correction, deletion, or an applicable marketing or privacy choice.
Rights differ by location. We may need to verify your identity before acting on a request.
9. Security and international processing
RoundOne uses authentication, access rules, transport encryption, protected local storage, integrity checks, and provider security controls designed to protect data. No online service can guarantee absolute security.
RoundOne and its providers may process data in countries other than the one where you live. Those countries may have different privacy laws. Provider contractual and technical safeguards apply according to the relevant service and jurisdiction.
10. Children
RoundOne is not directed to children under 13, and we do not knowingly create accounts for children under 13. A gym or coach using RoundOne with a minor must have the authority and permissions required in their location. Email hello@roundone.club if you believe a child’s information has been provided improperly.
11. Changes
We may update this policy as RoundOne changes. We will publish the revised policy here and change the “Last updated” date. We will update the App Store privacy answers before enabling a materially different app data flow.