PRIVACY.
UPDATED AUGUST 13, 2026
THE SHORT VERSION
Run the Tab is built to keep your run-and-beer comparison history on your iPhone. The iOS app has no Run the Tab account, advertising, health-data analytics, sale of personal information, consumption tracking, or cloud sync. We do not track you across apps or websites.
APPLE HEALTH
With your permission, the iOS app reads eligible completed running workouts, workout distance, active energy, and available workout routes from Apple Health. It does not write to Apple Health. The app uses those facts on device to build your run feed, route map, calorie comparison, local history, and an optional share image.
Run details, available route polylines, the beer you selected, and comparison timestamps are stored in protected local files on your iPhone. Apple Health remains the source of the workout. You can change Health access in system Settings or the Health app.
OPTIONAL STRAVA CONNECTION
The currently uploaded TestFlight build 1.0.0 (4) is Apple Health-only. Prepared candidate 1.0.0 (5) enables an optional read-only Strava connection through the production broker at https://strava.runthetab.xyz. Run the Tab requests the activity:read scope and processes eligible Run, TrailRun, and VirtualRun activities from up to the previous seven days. For each eligible activity, the broker may process its identifier, name, start date and time, elapsed time, distance, calories, device attribution, and an available route polyline.
The Strava client secret and readable provider tokens are not placed in the iPhone app. The broker seals token material inside an encrypted opaque session that the app stores in Keychain for no more than seven days. A separate isolated Neon database stores bounded, HMAC-pseudonymized authorization, webhook-deduplication, activity-deletion/privacy, and deauthorization state. It does not store OAuth tokens, provider identifiers, activity facts, route data, comparison history, or email addresses.
The production webhook and revoke paths have been verified. Webhook state makes later broker requests reject an invalid authorization or filter a deleted or private activity; it does not remotely erase data from an iPhone that is offline. A successful refresh removes local Strava comparisons whose activities are no longer returned, and local Strava comparisons are pruned after seven days. Disconnecting in Settings asks the broker to revoke the Strava grant and removes the opaque session, pending Strava runs, and saved Strava comparisons from the iPhone. You may also email the address below with a Strava access or deletion request. Do not send an access token, refresh token, password, or activity export. Strava may separately collect and monitor API usage under its own policies.
OPTIONAL RUN ALERTS
You may separately enable run alerts in Settings. The app then asks iOS for notification permission and uses HealthKit background delivery to look for a newly completed run. A bounded set of handled workout identifiers stays on your phone to prevent duplicate alerts. Alerts are passive, controlled by iOS, and may not arrive immediately.
LOCAL PREFERENCES AND CACHES
Your appearance, sound, run-source, and alert preferences are stored on your iPhone. Dismissed and handled workout identifiers are personal local caches because they are derived from your workout history. Public beer-catalog and public artwork caches are not user-specific and remain separate from your local history.
PUBLIC BEER CATALOG
The app’s catalog database contains only the public beer catalog. That database does not receive or store Apple Health data, routes, run history, comparisons, preferences, or whether you consumed anything. It is separate from the broker’s bounded Strava webhook-state database described above. The app does not record alcohol consumption.
SHARING
For Apple Health and fictional sample results, the app can render an image that contains run distance, a route map when available, selected beer and package facts, and the calorie equivalent. Nothing is published by Run the Tab. You choose the destination in Apple’s share sheet, and that destination’s privacy practices then apply. Sharing is disabled for results from a live Strava connection.
EXPORT AND DELETE
Settings → Your Data lets you export the local user data the app can read as a documented version 1 JSON file. The export includes local comparison history and routes, dismissed and handled workout identifiers, and app preferences. It does not include source workouts from Apple Health or Strava, or public catalog/artwork caches.
“Delete My Local Data” removes that user-specific app data from the iPhone and resets preferences. If direct Strava is connected, the app first asks the broker to revoke the grant, then removes the opaque session and local Strava data. Deletion does not remove source workouts from Apple Health or Strava, change system Health permissions, or delete non-personal public catalog/artwork caches. Direct Strava is absent from the uploaded 1.0.0 (4) build and enabled in the prepared 1.0.0 (5) Release candidate.
BETA ACCESS AND ANDROID UPDATES
The private iOS PIN gate is separate from the app and its public catalog, and it does not collect your email. When you request Android updates, this site stores your email, platform, request status, and request timestamps. A one-way keyed digest of network information may be kept briefly to limit form abuse; raw addresses are not stored for that purpose. There are no advertising cookies or cross-site trackers.
WEBSITE REQUEST CHOICES
You can remove an Android waitlist email immediately on the support page. Website-request deletion does not affect local iOS app data; use the in-app control for that data.
AGE AND ALCOHOL
Run the Tab is only for people of legal drinking age where they live. It does not sell alcohol, recommend consumption, or record consumption. Results are calorie math—not a safe amount, BAC, sobriety, hydration, recovery, medical, or drinking advice. Exercise does not reduce alcohol risk.
CONTACT
Email support@runthetab.xyz for privacy questions, Strava access or deletion requests, or website access, correction, and deletion requests. Support does not hold a Run the Tab account copy of your local history and cannot export it for you; use Settings in the app.