WHYNOT
Features How it works Answers Join the launch
← Back to whynot.run
Legal

Privacy Policy

Last updated: August 25, 2026 · Effective date: at app launch

The short version: Why Not runs on your phone — your plans, your workouts, and your route maps are calculated and stored there. Why Not does need an account, and your account holds your profile, your membership status, a backup copy of your training plan so you can get it back on a new phone, and (when it launches) the runs you choose to share. If you connect Strava, your runs go to Strava too. We don't sell your data, we don't show ads, and we don't track you across the internet. We're a small shop trying to ship a good app.

1. Who we are

Why Not is a running coach app for iPhone and Apple Watch, operated by Why Not Run LLC, a Massachusetts, USA company. You can reach us at support@whynot.run.

2. What data the app handles

On your device

The core of Why Not is local-first: your training is generated, stored, and read on your phone (and, where relevant, mirrored to your paired Apple Watch). No server does the thinking. Here is what the app handles:

  • Profile basics: first name, age, gender (used for fitness calculations and plan personalization).
  • Training plans: generated workout plans, completed and partial workouts, race goals, scheduled run days.
  • Workout history: distances, paces, heart rate summaries, effort ratings, dates, and the GPS route maps of runs you record.
  • App preferences: distance units, voice settings, notification history, training-mode toggles.

The copy your account keeps

Because Why Not needs an account, one part of that list also lives on our servers: a backup copy of your current training plan is saved to your account. That copy is what gets your plan back on a new phone, or after you delete and reinstall the app, instead of making you rebuild it from scratch — the same reason you'd want a backup of anything else you'd hate to lose.

What's in it: your plan and its workouts — including the ones you've finished, with their distances, paces, and effort ratings — the answers you gave the setup wizard (your goal, your race name, date, and location if you entered one, your goal times, and any recent race times), your coaching adjustments, and your unit preference. It's tied to your account, nobody else can read it, and it updates quietly in the background whenever your plan changes.

Some of those numbers can start life outside Why Not. When a run you imported — from Strava or from Apple Health — checks off a planned workout, the distance and pace recorded on that workout came from the imported run. So a pace that originated on your Garmin and arrived through Strava can end up in the plan backup, as part of your training history. It's still only those plan numbers — a distance and a pace on a finished workout — never the imported run itself, and never its route.

What's not in it: your routes. The backup carries no GPS data at all — your route maps stay on your device and in Apple Health, as described in the next section.

Honest limitation: this backup isn't a feature you switch on, and there's no off switch for it while you're signed in — it's part of how the account works. Deleting your account deletes it, and we spell out exactly what that removes below.

Location during runs

If you record a run with Why Not (on the phone or the watch), the app uses GPS to calculate live pace and distance and to draw your route map. Your route is stored on your device and in your Apple Health data. We never hold a full route on our servers.

There are exactly two ways a route can leave your device, and both are things you switch on yourself:

  • Strava, if you connect it. A run you record with Why Not is uploaded to your own Strava account as a complete, untrimmed GPS track — including its true start and end points, the same as any GPS watch would upload. The trimming described below does not apply to Strava. See "Connected services" below.
  • Sharing a run socially, when that launches. The route is trimmed and blurred at its start and end before it leaves your phone, and only that trimmed version is ever stored by us (see the social section below).

So the promise is specific rather than sweeping: your full route never reaches our servers — the most we would ever hold is the trimmed preview of a run you deliberately shared. If you connect Strava, your full route reaches Strava, because that is the entire point of connecting it.

There is one use of location that isn't a run at all: your home screen shows the current conditions where you are, which needs an approximate fix. That one is described under "Permissions the app requests" below.

Apple Health (HealthKit) — optional

If you connect Apple Health, Why Not both reads and writes workout data so your plan reflects everything you actually do:

  • We read: workouts, walking/running distance, active energy, heart rate, and workout routes — including runs recorded by an Apple Watch, Garmin, Coros, Polar, or any other device that syncs to Apple Health.
  • We write: the workouts you record with Why Not, their GPS routes, and your effort ratings, so your runs live in your own Apple Health record.
  • Health data read into the app stays in the app's local storage on your device. We never use Apple Health data for advertising or marketing, and we never sell it or share it with data brokers.
  • You can disconnect at any time in the app, or revoke specific permissions in iPhone Settings → Privacy & Security → Health → Why Not. Apple's handling of Health data is governed by Apple's privacy policy.

Your account

Why Not requires an account. That's how your plan backup, your membership, and (when it launches) anything social stay attached to you rather than to one particular phone. Sign-in is through Sign in with Apple — in the app and on this website's account portal. When you sign in we store:

  • The identifier and email address your sign-in provider shares (Apple lets you hide your real email behind a relay — that works fine with us).
  • Your display name, @handle, and profile photo if you add one.
  • The profile details you enter in the app — first name, age, and gender — so a restored account doesn't have to ask you for them twice.
  • The backup copy of your training plan described above.

Account data is stored with our infrastructure provider, Supabase, on servers in the United States. You can delete your account at any time inside the app (or by emailing us) — deletion removes your profile, your plan backup, any shared runs, and your follow relationships.

Purchases and subscriptions

Apple processes all payments through the App Store — we never see your card number or billing details. We use RevenueCat, a subscription-management service, to know your subscription status (trial, active, lapsed) so the app can unlock the right features; when you're signed in, that status is linked to your account so you can also see it on the web. Managing or canceling a subscription always happens through Apple — our membership pages show your status and link you to Apple's subscription settings.

Sharing runs (social features)

When social features launch, sharing is opt-in and followers-only. If you choose to share a run, your followers see its stats (distance, pace, time, run type) and a route preview. Before a route ever leaves your device, the app trims and blurs its start and end points. Honest limitation: trimming hides where a run started and ended, but a route can still pass near places you frequent — share with people you trust, and use the per-run toggle when in doubt. You can remove a shared run at any time (deleting a run retracts it for everyone), block or report other users, and deleting your account removes everything you shared.

Connected services — optional

Strava. Connecting your Strava account is opt-in and off until you turn it on. You authorize it on Strava's own screen — we never see your Strava password. Once connected, data moves in both directions, each with its own switch in the app's settings:

  • In: runs you recorded elsewhere — on a Garmin, COROS, Polar, or the Strava app itself — are imported into Why Not, so your plan and your coaching reflect everything you actually ran.
  • Out: runs you record with Why Not are uploaded to your own Strava account as a normal activity. That upload includes the full GPS route of the run and, for runs recorded on your watch, your heart rate. It goes to Strava, not to us.

We store the access tokens Strava issues so the connection keeps working; they're used only to talk to Strava on your behalf, and Strava expires them every few hours. One thing that comes with the territory: Strava may monitor and collect usage data about how this integration is used, and may use that data for its own business purposes. That's true of every app on the Strava platform, and it happens on Strava's side of the connection.

Deleting works at three levels, and it's worth being precise about them:

  • One run: any imported run can be deleted in the app, from that run's detail screen ("Delete this run"). That removes the run, its route map, and its metrics from your device, clears its distance and pace from your training plan — and, the next time the plan backup updates, from the backup too — and the run will not be re-imported by a later sync.
  • Disconnecting: disconnecting Strava inside the app revokes the access tokens with Strava, clears them from your device, and removes what those tokens brought in. Runs that are in Why Not only because Strava imported them are deleted — the run, its route map, and its splits — and any planned workout one of them checked off goes back to unfinished, in the app and in the plan backup. Runs you recorded yourself, on your watch or your phone, are kept: only the route and split data Strava supplied for them is stripped, and their own distance, duration, and heart rate are untouched. Reconnect whenever you like and your Strava runs import again. Two things deliberately stay behind: on runs Why Not uploaded to Strava, we keep the id Strava gave that upload, because without it reconnecting could upload the same run to your Strava account a second time; and a badge or milestone you already earned stays earned, even if an imported run helped you get there.
  • Everything: to remove all your Strava-sourced data in one go, email support@whynot.run. We'll delete the imported runs and the data derived from them within 30 days, and confirm to you in writing once it's done.

What you've already sent to Strava lives in your own Strava account — delete it there if you want it gone. Your use of Strava is governed by Strava's own privacy policy.

We may later add connections to recovery-data services such as WHOOP, Garmin, or Oura — those would be opt-in in exactly the same way, and we'll update this policy before any of them ships.

Bug reports

If you send a bug report from inside the app, we receive what you wrote plus basic technical context (app version, device model, iOS version) so we can fix the problem. Bug reports go to our own backend, and may be surfaced in the internal support tooling we use to triage them, so a human actually sees the report and acts on it. They're kept only as long as needed to resolve the issue.

Crash reports and analytics

In the app: crash reporting uses Apple's built-in system if you have it enabled in iOS Settings; those reports are anonymized by Apple. The app itself contains no third-party analytics SDK — no Google Analytics, no Mixpanel, no Meta SDK, no AppsFlyer, none of it. Nothing you do inside Why Not is reported to an analytics company.

This website: whynot.run is a different thing from the app, and it's fair to be plain about it. These pages — including this one — load Google Analytics 4 so we can count aggregate traffic: how many people visit, which pages they read, roughly which country they're in. We use it to know whether anyone is reading, not to build a profile of you, and it is never joined to your app data, your account, or your training. Any tracker blocker stops it.

3. What we don't do

  • We don't sell your data. Ever.
  • We don't share your data with advertisers or data brokers.
  • We don't use your health or location data for advertising or marketing — full stop.
  • We don't track you across other apps or websites.
  • We don't show you ads inside the app.

4. Permissions the app requests

  • Location (when in use): two things. Recording runs — live pace, distance, and your route map. And the conditions on your home screen: each time you open the Home tab, the app asks iOS for an approximate position and sends it to a weather service to look up your local temperature. That one happens outside of runs, so it's worth being plain about — it's a deliberately coarse fix, no name or account identifier travels with it, and we don't store it. Deny location and everything except run recording and that weather readout still works.
  • Apple Health: optional; read and write as described above.
  • Notifications: optional. Run reminders, "your run is ready" alerts, trophy celebrations, and the app-icon badge. Everything still appears in the in-app notification bell if you decline.

5. Children's privacy

Why Not is not directed to children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, contact support@whynot.run and we will delete it.

6. Your rights (GDPR, CCPA, and similar laws)

Depending on where you live, you may have rights to access, correct, delete, and export your data. Here's how that works with our split of local and server data:

  • On-device data: you have direct access on your phone; editing and deleting happens right in the app. Uninstalling removes the copy on your device — but not the plan backup your account holds, which stays until the account itself is deleted. So if your goal is to have nothing left anywhere, delete your account rather than only deleting the app; the next bullet is how.
  • Account data: delete your account in-app for immediate removal of your profile, your plan backup, shared runs, and follows — or email support@whynot.run and we'll handle deletion, corrections, or an export of what we hold.

7. Data retention

On-device data lives as long as the app is installed. Account data is kept until you delete your account. Bug reports are kept only as long as needed to fix the issue. We don't keep marketing lists, so there's nothing to unsubscribe from.

8. Security

On your device, data is protected by iOS app sandboxing and your lock screen — keep a passcode or Face ID on your phone. On our side, account and shared data is encrypted in transit (TLS) and protected by per-user access rules on the database, hosted with Supabase in the United States. No system is perfect; if we ever learn of a breach affecting your data, we'll tell you.

9. Changes to this policy

If we change anything material — a new connected service, a new data flow — we'll update this page and note it in the app before the change takes effect. The "last updated" date at the top reflects the most recent revision.

10. Contact

Questions, concerns, or requests:

Why Not Run LLC
Massachusetts, USA
Email: support@whynot.run

This policy is written in plain English on purpose. If something is unclear, that's a bug — email us and we'll fix it.

© 2026 Why Not Run LLC. Independent. No investors.
Support · Privacy · Terms · Trial policy
Site built by Sites by Bob — web design →