← Locked Run

Privacy Policy

Effective date: June 10, 2026

This Privacy Policy explains how Locked Run collects, uses, and protects your data. Locked Run is operated by Individual Entrepreneur DMYTRO STRUKOV (Georgia). Contact: support@arxa.app.

1. What data we collect

2. How we collect data

We collect data directly from Strava after you grant access, from your in-app actions (for example, sync and account deletion requests), and from technical events needed to operate and secure the service.

3. How we use data

4. Legal basis

We process data as necessary to provide the service you request, based on your consent (including OAuth authorization), our legitimate interests in operating a secure service, and legal obligations where applicable.

5. Data sharing

We do not sell personal data. We may share data only with service providers needed to operate Locked Run, with Strava as part of API integration, or when required by law.

6. Data retention and deletion

You can delete your account in app settings at any time. Account deletion removes your Locked Run account and associated data from active systems immediately after we process your request. Third-party services (for example, Strava or Mixpanel) may retain data under their own policies.

7. Security

We apply reasonable technical and organizational safeguards, including encryption of sensitive Strava tokens at rest. No internet service can be guaranteed to be 100% secure.

8. Children and minimum age

Locked Run is intended only for users who meet the minimum age requirements of Strava and Instagram, and any higher minimum age required by local law in your jurisdiction.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, or restriction of your personal data. To make a request, contact support@arxa.app.

10. Policy updates

We may update this Privacy Policy from time to time. The latest version will always be available on this page with the updated effective date.