Privacy Policy
Last updated: July 23, 2026
Active Metrics is made by Spears Software (“we,” “us,” “our”). This policy explains what happens to your data when you use the app, the beacon live-sharing feature, and this website — including during the closed TestFlight beta.
The short version: almost everything stays on your device or in your own iCloud account, which we cannot read. The only things that reach a server we operate are route requests, map tiles, an opt-in live-location share, and whatever you type into the beta-request form on this site. None of it is used for advertising, and we don’t sell or share your personal information.
A. What stays on your device and in your own iCloud
HealthKit. The watch app writes workouts, workout routes, and a workout effort score to Apple Health. The iPhone app never writes to Health — it only reads what’s already there.
The watch reads heart rate, active energy, distance (including swimming), running speed and power, steps, effort scores, activity summaries, and your date of birth. The iPhone app additionally reads VO2max, resting heart rate, heart-rate variability (SDNN), heart-rate recovery, sleep analysis, and biological sex. None of this is transmitted to Spears Software — it’s read locally to power the app’s own screens and analytics.
Health data is never used for advertising, marketing, or use-based data mining.
Your own iCloud. Workout records, imported GPX routes (including the full track), structured workouts, and daily energy data sync through your personal iCloud account via CloudKit’s private database. That means workout health metrics — average and max heart rate, active calories, heart-rate zone distribution, effort scores — travel through iCloud the same way your Health app data does. Spears Software cannot read your CloudKit private database; only you and your own devices can.
Your training zones, cadence and power targets, unit preferences, and beacon settings — including any saved
contacts (name, email, phone) and privacy-zone locations you’ve configured — sync the same way, through
NSUbiquitousKeyValueStore in your own iCloud account. We cannot read this either.
No analytics, no tracking, no third parties in the app itself. Active Metrics has no analytics SDK, no crash reporter, no ad or attribution SDK, and no third-party runtime dependencies at all. There’s no account, no login, and no user ID tied to you.
B. Services we operate
A few features need a server, because your watch and phone can’t generate maps or routes on their own. Here’s exactly what each one sees.
Route generation (route.activemetrics.app) — when you generate a loop, your watch sends waypoint
coordinates (or a starting point, distance, and heading) to this service and gets a route back. Requests are
authenticated with a key that’s identical across every install of the app — it identifies “a copy of Active
Metrics,” not you personally, and can’t be used to link requests to a person. We don’t store requests in a
database; routes are cached at Cloudflare’s network edge for up to 30 days, keyed by coordinates rounded to about
11 meters. Your IP address is used briefly for rate-limiting and isn’t retained beyond that.
Map tiles (tiles.activemetrics.app) — requests for map tiles by coordinate. This requires no account or
user identifier of any kind. The coordinate in the request implies roughly what area you’re looking at, but
nothing is logged that ties it to you.
Live location sharing (live.activemetrics.app, beacon) — off by default, entirely opt-in. When you
share a live link during a run:
- If you haven’t turned on pace or heart-rate sharing, that data is never sent to our server at all — not hidden, not encrypted, just never transmitted.
- What’s stored, per session: timestamps, latitude/longitude, pace and heart rate (only if you enabled them), and a few details about the share itself — your display name, the activity type, and how many people you shared with.
- The link is read-only. Your watch generates a secret write-token locally and the shared link only ever carries a one-way hash of it, so nobody who has the link can write to or end your session — only view it.
- Deletion is automatic. Session data is deleted 30 minutes after your run ends by default (you can change that grace period from 60 seconds to 24 hours), and unconditionally within 6 hours of the session starting no matter what grace period you’ve set. You can also delete it immediately from the app.
- If you’ve set up privacy zones, GPS points inside them are dropped on your watch before anything is sent — they never reach our server — and we add small random padding to the zone’s effective radius each run so the exact boundary can’t be inferred from where sharing starts and stops.
- The web page recipients see is served entirely from our own map-tile infrastructure — viewing a shared link doesn’t send a recipient’s browser or IP address to any third-party mapping service.
If you enable email notifications for a beacon share, we send your display name and the live link to the addresses you provide via Postmark, our email provider. We don’t keep those recipient addresses on our servers afterward. You’re responsible for having permission from anyone you add as a beacon contact — their name, email, or phone number is their personal data, supplied by you.
C. This website and beta applications
The beta-request form on this site collects your name, email, watch model, region, and whatever you write in the message field. Submitting it makes Spears Software the controller of that data for the purpose of running the beta program. We use it only to review and manage beta invitations, and we keep it for as long as the beta program runs plus a reasonable period afterward for our own records, then delete it. Email us (below) to request deletion sooner.
This site uses Cloudflare Turnstile for spam protection, which may set cookies such as __cf_bm and run a
browser challenge. Cloudflare, which hosts this site, also logs standard web request data (IP address, user
agent, timestamp) as part of operating the network — we don’t control or read those logs beyond what’s needed to
keep the site running.
D. Sub-processors
Services that process data on our behalf:
- Cloudflare — Workers, Durable Objects, R2 storage, Pages hosting, edge caching, and Turnstile bot protection.
- Postmark — sends beacon share-notification emails and processes this website’s beta-request form.
- Apple — HealthKit, CloudKit, MapKit, and WeatherKit. WeatherKit receives your coordinates to fetch current conditions for the app’s weather display.
E. Your rights under GDPR
If you’re in the EEA, UK, or Switzerland, this section applies to you.
Controller: Spears Software. Contact us using the email below for any privacy request.
Legal basis for processing:
- Beacon pace and heart-rate data is special-category health data under Article 9 — we process it based on your explicit consent, given when you turn on those toggles before sharing.
- Rate-limiting by IP address is based on our legitimate interest in keeping the service available.
- The website beta-request form is based on consent (submitting it) and contract (administering the beta you’ve asked to join).
Your rights: access, correction, deletion, restriction of processing, data portability, and objection to processing. To exercise any of these, email us below — we’ll respond within a reasonable time.
Retention: covered above, per data type — most is deleted automatically within hours (beacon) or governed entirely by your own iCloud account (everything else).
Where processing happens: our servers and sub-processors operate in the United States.
Complaints: you have the right to lodge a complaint with your local data protection supervisory authority.
F. Your rights under CCPA
If you’re a California resident: we do not sell or share your personal information, and we haven’t in the past 12 months. Categories of personal information we collect are described in sections B and C above (contact info, approximate location during an active beacon share, and — only if you opt in — health/fitness data). You have the right to know what we collect, request deletion, and not be discriminated against for exercising these rights. Contact us below to make a request.
G. Permissions the app asks for
| Permission | Why we ask |
|---|---|
| Health | To read your workout, heart-rate, and recovery data for the app’s own screens, and to save completed workouts back to Health. |
| Location | To record your route during a workout, generate turn-by-turn navigation, and — only if you enable it — power live location sharing. |
| Motion & Fitness | To estimate reps during strength-training workouts using wrist motion. |
| Bluetooth | To connect to external sensors — heart-rate straps, power meters, cadence sensors, and smart trainers. |
| Notifications | To deliver in-workout alerts, like target-zone warnings and lap notifications. |
Children’s privacy
Active Metrics is not directed at children under 13, and we don’t knowingly collect personal information from them.
Changes to this policy
If this policy changes in a material way, we’ll update the “last updated” date above. Since this is beta software, expect the app’s behavior — and this policy — to evolve during the beta period.