Effective date: 28 July 2026
Massive Dreamers ("us", "we", or "our") operates the mobile application Runphony (the "Service").
This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.
Runphony reads a run or walk you have already recorded — from Health Connect or from a file you choose — and generates an original piece of music from it. The analysis and the music are produced on your device. Nothing is uploaded in order to create your music.
We do not show advertisements.
We do not use analytics or tracking SDKs.
We never sell your data, and we never use health or fitness data for advertising.
Your runs stay on your device unless you are signed in and subscribed to Premium.
Service Service means the Runphony mobile application operated by Aqsin Sulxayev.
Personal Data Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
Health and Fitness Data Data describing your physical activity — for example workouts, heart rate, cadence, speed, distance, elevation and route — read from Health Connect with your permission, or contained in a file you import.
Usage Data Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself.
Data Controller Data Controller means the natural or legal person who determines the purposes for which and the manner in which any personal information are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data.
Data Processors (or Service Providers) Data Processor means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
Data Subject (or User) Data Subject is any living individual who is using our Service and is the subject of Personal Data.
We collect a small number of types of information, for the purposes described below.
Link to the privacy policies of the third-party service providers used by the app:
Google Play Services — https://www.google.com/policies/privacy/
Firebase (Authentication, Cloud Firestore, Cloud Messaging) — https://firebase.google.com/support/privacy
Health Connect — provided by Google / your device
This is the most sensitive category the Service handles, so we describe it in full.
What we read. If you connect Health Connect and grant permission, Runphony reads the following record types for the specific workout you select:
Data
Android permission
Required?
Exercise sessions (your workouts)
READ_EXERCISE
Yes
Speed
READ_SPEED
Yes
Steps
READ_STEPS
Yes
Distance
READ_DISTANCE
Yes
Elevation gained
READ_ELEVATION_GAINED
Yes
Heart rate
READ_HEART_RATE
No — optional
Exercise routes (GPS)
READ_EXERCISE_ROUTES
No — optional
Runphony has read access only. It never writes, modifies or deletes anything in Health Connect.
Why we read it. Each type maps to a specific musical decision: steps and cadence set the tempo; speed and distance detect the phases of your run, which become the sections of the song; elevation adds tension on climbs; heart rate, when available, shapes the mood and intensity of the arrangement; the route shapes the song's structure and is drawn as the trajectory picture in the app and in exported videos.
If you deny heart rate or route access, the Service still works — those elements are simply left out.
Where it goes. All analysis and music generation happen locally on your device. The processed run is saved on your device so a past track can be re-opened. Only if you are signed in and subscribed to Premium is that record also copied to your private cloud library — see Cloud Backup below.
What we never do with it. We never use health or fitness data for advertising or marketing, we never sell or rent it, we never share it with data brokers, and we never share it with third parties for their own purposes.
How to withdraw permission. Android Settings → Security & privacy → Health Connect → Runphony, or from the Health Connect app. The Service also links there from Settings → Connections. Revoking stops all future reads immediately.
Runphony does not track your location. The Service does not request Location Services, does not access your location in real time, and does not record your position in the background.
However, a workout you select may contain a GPS route that was recorded earlier by another app or device. If you grant the exercise-route permission, Runphony reads that route in order to draw your trajectory and to shape the structure of the generated music. If you have Premium and are signed in, a simplified outline of that route (reduced to at most 120 points) is included in your cloud backup.
You can prevent this entirely by not granting the route permission, or by not using cloud backup.
Signing in is optional — the Service is fully usable without an account.
If you sign in with Google, we receive, through Firebase Authentication:
your email address,
your display name, if your Google account provides one,
a user ID issued by Firebase.
Before you sign in, the app may use an anonymous Firebase account, which is only a random identifier and contains no personal information.
If you are signed in with a real account and have an active Premium subscription, your track library is backed up to Cloud Firestore, in a location private to your user ID. Each backed-up track contains:
the track's title, creation date, activity type, distance and duration;
the run's data series — cadence, heart rate, speed and elevation over time;
a simplified GPS outline of your route;
your maximum heart rate for that run, the local hour it started, and the chosen music style.
This means your heart-rate and route data leave your device when cloud backup is active. Access is restricted by security rules so that only your own signed-in account can read or write your records. The backup exists solely so you can restore your own library — it is never used for any other purpose.
If you are not subscribed, or not signed in, nothing is uploaded.
You can load a run from a JSON, GPX or TCX file you pick from your device. Runphony reads only the file you select, and only at the moment you select it. Its contents are treated exactly like health data above.
We do not operate our own analytics. Our service providers (Google/Firebase) may process limited technical information — such as an IP address and device identifiers — as a necessary part of delivering authentication, cloud storage and push notification services.
Runphony does not use cookies, beacons, tags, tracking scripts, or any cross-app or cross-site tracking. We do not use the Advertising ID.
Runphony contains no advertising and no advertising SDK. No data of any kind is shared for advertising purposes.
Runphony uses the collected data for the following purposes only:
To generate music from the run or walk you select;
To display your run's statistics, trajectory and history;
To keep you signed in and identify your own library;
To back up and restore your library when you have Premium (cloud backup);
To verify whether you hold an active Premium subscription;
To send occasional informational push notifications;
To provide customer support;
To detect, prevent and address technical issues.
If you are from the European Economic Area (EEA), our legal basis for collecting and using the personal information described in this Privacy Policy depends on the data concerned and the context:
Health and fitness data is a special category of data. We process it only on the basis of your explicit consent, given through the Health Connect permission screen. You may withdraw that consent at any time, as described above.
Account data is processed to perform our contract with you (providing the Service).
Cloud backup is processed to perform our contract with you, on your instruction, when you subscribe.
Push notifications are processed on the basis of your consent (the notification permission).
Some processing is necessary to comply with the law.
On-device data is removed when you uninstall the Service or clear its storage. On the free tier, only your most recent runs are kept; older ones are deleted from storage automatically.
Cloud data is retained for as long as your account exists, and is deleted when you delete your account.
We retain data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Your information may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction, where data protection laws may differ. Firebase services store data on Google's infrastructure. Your consent to this Privacy Policy, followed by your use of the Service, represents your agreement to that transfer. We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
We may disclose your Personal Data in the good faith belief that such action is necessary to:
comply with a legal obligation;
protect and defend our rights or property;
prevent or investigate possible wrongdoing in connection with the Service;
protect against legal liability;
protect the personal safety of users of the Service or the public.
We do not sell your data, and we do not disclose health or fitness data to third parties for their own purposes under any circumstances.
Data in transit is encrypted using TLS. Cloud records are protected by security rules limiting access to their signed-in owner. The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
We do not track users across applications or websites, so there is nothing for a Do Not Track signal to disable.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
The right to access, update or delete the information we have on you. Account deletion is available directly in the app (Settings → Account → Delete account).
The right of rectification — to have inaccurate or incomplete information corrected.
The right to object to our processing of your Personal Data.
The right of restriction — to request that we restrict processing.
The right to data portability — to receive a copy in a structured, machine-readable format.
The right to withdraw consent at any time where we relied on your consent — including the health permissions, which you can revoke in Health Connect.
Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data.
We employ third-party companies to facilitate our Service, to provide the Service on our behalf, or to perform Service-related services. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Provider
Purpose
Firebase Authentication (Google)
Sign-in and account identity
Cloud Firestore (Google)
Premium cloud backup of your library
Firebase Cloud Messaging (Google)
Push notifications
Google Play Billing (Google)
Subscription purchases
We do not use any analytics service. Runphony does not include Google Analytics, Firebase Analytics, Crashlytics, or any comparable product.
We do not use any advertising service. Runphony contains no advertisements and no advertising SDK, and no data is used for advertising purposes.
We provide a paid subscription within the Service. Payment processing is handled by a third-party app store.
We will not store or collect your payment card details. That information is provided directly to the payment processor, whose use of your personal information is governed by their own privacy policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
The payment processor we work with on Android is:
Google Play In-App Payments — https://www.google.com/policies/privacy/
Our Service may contain links to sites that are not operated by us. If you click a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party sites or services.
Our Service does not address anyone under the age of 13 ("Children"), or the minimum age of digital consent in your country, whichever is higher.
We do not knowingly collect personally identifiable information from anyone under that age. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from a child without verification of parental consent, we take steps to remove that information from our servers.
You have the right to request deletion of your account and all associated data at any time.
In the app: Settings → Account → Delete account. This permanently deletes all of your cloud records and then your authentication account. It cannot be undone.
By email: write to akshins.lab@gmail.com with the subject line "Account Deletion Request", providing the email address associated with your account. We will process your request and permanently delete your account and associated data within 14 days.
Uninstalling the app removes all data stored on the device.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the effective date at the top.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, please contact us:
By email: akshins.lab@gmail.com