Bound privacy policy (beta)
Last updated: 11 October 2026. Bound is in a test phase; this policy describes exactly what the beta app does. It is published at getbound.space/privacy.
Bound is a running game: you run around blocks and neighbourhoods, and the territory inside becomes yours on a shared map. To make that fair, the app records your runs and the server checks them. This page explains what that means for your data.
Contact: contact@getbound.space
What Bound collects
Only while you record a run (you tap Start run; Bound never asks for "Always" location):
- Your position from the phone's GPS, about once a second: time, latitude and longitude, accuracy, altitude, speed and heading.
- Motion summaries from the phone's sensors: step counts and short summaries of the accelerometer signal (how rhythmic your movement is), never raw audio, video or photos. They tell running apart from riding a bike or a car.
- What happened during the run: start, pause, finish, the app going to the background, battery charging.
- The phone's model, operating system version and the app's version.
Your account:
- An account identifier, created automatically the first time you open the app.
- Your name in the game: a generated pseudonym such as SwiftOtter42, or a name you choose instead. Bound never asks for your real name.
- A profile photo, only if you add one.
- How you sign in: your email address (to send you a sign-in code), a Sign in with Apple identifier (Apple can hide your real email), or, with Google, your Google account's email address and identifier.
- A device identifier: the phone's vendor identifier, scrambled with a one-way function, so the server can tell if several accounts share a phone. Bound never uses advertising identifiers.
- If you turn on push notifications: a push token and your phone's time zone (for quiet hours).
Apple Health (only if you connect it, in Activity):
- Bound reads the heart rate recorded during your runs (for example by an Apple Watch) and your latest weight, to show your heart rate on each run and work out calories. It writes each finished run to Health as a running workout with its distance, calories and route.
- This health data stays on your phone and in Apple Health. It is never sent to Bound's server, never shared with anyone, and never used for advertising. Your weight (whether from Health or typed in) is kept on the phone only. You can disconnect in Activity, and remove Bound's access in the Health app at any time.
Not collected: your location when you are not recording a run, your contacts, photos, microphone, or any advertising or tracking identifiers. Bound has no ads and doesn't sell or share data for advertising.
What it's used for
- Checking runs. The server recomputes each run from the raw data to decide whether it was a genuine run on foot (for example, not a car or a replayed track). Raw run data is kept 30 days so a person can look again if you appeal a decision. Statistics per phone model help make these checks fair to every phone.
- The game. Your verified runs claim territory on the shared map; the server keeps your territory, its strength, and what happened to it (claims, sieges, captures).
- Notifications. If you turn them on: at most 3 a day, never between 22:00 and 07:00 on your phone's clock. Everything also appears in the in-app inbox.
What other players can see
- Your profile is private by default. While it is private, your territory is on nobody's map but yours, and you appear on no leaderboard (you still see your own place).
- If you make it public, other players see your name, colour and photo, your territory (on the map, the leaderboards and your profile), the month you joined, and your medals and records (how much territory you have claimed and held).
- Your runs are never shown to other players: no routes, no times, no list of runs.
- No live position, ever. Runs change the map 10 minutes after upload at the earliest.
- Profile photos are stored as public image files: anyone who has a photo's address can open it.
- Share cards are made on your phone, only when you tap Share, and go only where you send them. They show the territory a run claimed on the map (never the route, so not where it started or ended) and the run's distance, time and pace.
- Privacy zones (200–1000 m circles, for example around your home) never become territory on the map, and routes are hidden there.
- Leaderboards list public profiles only.
Who processes the data
- Supabase stores the database and the raw run files.
- Expo builds and updates the app and delivers push notifications to Apple's and Google's push services.
- Apple and Google, if you sign in with them: they confirm who you are and tell Bound your account's email address and identifier.
- OpenFreeMap serves the map's base layer (streets and parks, from OpenStreetMap). Like any website, the map server sees your IP address and the area of the map being shown.
Google user data
If you sign in with Google, Bound receives your email address and your Google account identifier from Google, and nothing else. They are used only to sign you in, including on a new phone. Bound doesn't share them with anyone, doesn't sell them or use them for advertising, and deletes them when you delete your account. Bound's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long it's kept
- Raw run data: 30 days.
- Your runs, territory and account: until you delete your account.
- Records of map events (claims, sieges, captures): 180 days.
- Runs you record stay on your phone until you delete them in the app or delete your account. They belong to your account: if someone else signs in to Bound on the same phone, they don't see your runs, and your runs are never uploaded to their account. If you reinstall Bound or sign in on a new phone, your runs come back from your account (the route as the server keeps it, without the raw GPS and motion data); a run you deleted on a phone isn't put back on that phone.
Your choices
- Export your data at any time: You → Export your data (your profile, territory and every run, as JSON and GeoJSON).
- Delete your account: You → Delete account. Your territory becomes neutral immediately, and your runs and raw data are deleted from the server and from the phone you delete it on.
- Keep your profile private, add privacy zones, and choose which notifications you get.
The beta waiting list
If you ask to join the beta on getbound.space, Bound keeps the email address you type in (it should be your Apple ID's, because TestFlight invitations go to it) and when you sent it. Nothing else: no name, no location, no cookies or tracking. It is stored by Supabase and used only to invite you to the beta through Apple's TestFlight (so Apple receives it too, when the invitation is sent). It is kept until Bound is out on the App Store, or until you ask for it to be deleted at contact@getbound.space.
Children
Bound is not meant for children under 16.
Changes
If this policy changes, the new version will be published at the same address with a new date, and the app will point out significant changes.