Privacy Policy

Version 7 · Updated September 27, 2026 · Replaces Version 6 dated September 21, 2026

Shanghai Fun Pizza Software Technology Co., Ltd. operates Sport Master (formerly AISmartRun), an AI running coach app. This policy explains what data we collect, how we use it, which processors receive it, and how you can exercise your rights. AI-generated content is for training reference only and is not medical advice.

1. Data We Collect

DataWhenPurpose
Phone numberSMS loginAccount authentication and abuse prevention
Other onboarding and profile data: adult age, gender or prefer-not-to-say, longest recent run, training goal, coach style, primary running mode, nickname, height, weight, max heart rate, and injuriesWhen you submit onboarding or edit your profile. Adult age and the initial training profile are required for an account; expanded profile fields are optional.Confirm adult eligibility, establish your training profile, personalize plans, calculate heart-rate zones and calorie estimates, and provide safer coaching
GPS route, distance, pace, altitude, duration, run type, and run notesOnly during a run you actively start. An iPhone outdoor run may continue while the app is in the background or the phone is locked; pausing or ending the run stops location updates. Android uses an active-workout foreground service.Run history, summaries, maps, AI post-run review, and optional leaderboard or group features. For a signed-in Android account, complete route points are uploaded and stored by our backend. On iPhone, raw GPS points are processed on-device to calculate aggregate metrics and are not uploaded or retained.
Heart rate, cadence, steps, active energy, and watch or sensor dataWhen you start a workout on Apple Watch or connect BLE, Garmin, phone sensors, or supported glassesLive guidance, training load, and run analytics
Chat text and voice transcription textWhen you ask the AI coach a questionAI coach replies and safety review. Voice is converted by the device/system speech recognizer; our server receives text, not the recording itself.
Coach schedule answers: goal, weekly frequency and duration, unavailable days, injuries, race details, and refinement textWhen you choose to create or revise a scheduleOur Singapore backend combines your trusted running history with server rules and safety checks. Drafts and revisions are stored under your account and can be deleted separately; an adopted weekly plan remains a separate record.
Nutrition photo and extracted meal textOnly when you choose the photo recognition featureFood recognition and nutrition logging. We do not store the original photo; the new Android app previews the result and stores a meal only after your confirmation or edits. Manual entry requires no AI call. Older app submission endpoints remain compatible.
GPX route files, run notes, and other content you actively submitWhen you import a route, save a run, send feedback, or complete a training profileAccount routes, run history, support, and personalization
App events, device model, OS/app version, crash stack, run-quality diagnostics, and server logsUse of the app and backend; uploaded only for signed-in accounts, optional usage analytics separately require opt-in; guests do not queue analytics eventsSecurity, debugging, service reliability, and aggregate product analytics
Server-issued AI-glasses installation ID, long-lived opaque device credential, 8-character AIUI ID, and binding state (the device SN is neither read nor uploaded)On first registration the server issues an installation_id and signed device_credential. The glasses use them for later identity refresh only after a verified local write; the server separately assigns a cryptographically random AIUI ID.Anonymous use before phone binding, offline retry, de-duplication, abuse prevention, and optional account binding when a signed-in app submits the current AIUI ID

AI glasses identity and optional binding: The normal SmartRun AIUI registration flow does not read, simulate, hash, or upload the device SN, and the glasses do not generate an authentication secret. On first registration the server issues an installation_id and a signed, long-lived opaque device_credential. The glasses use that pair for low-privilege identity refresh only after a verified local write. The server separately assigns a cryptographically random current 8-character AIUI ID. That ID locates an unbound device but cannot authenticate the device or read data by itself. Binding requires a signed-in companion app, and a device that is already bound cannot be claimed by another account. Before binding, run summaries and coach memory belong to the glasses' anonymous identity. After binding, that anonymous history moves into your account. Unbinding requires verification of the current ID, changes the glasses to a fresh anonymous owner, and immediately generates a new AIUI ID so the former ID no longer works; prior history remains in the former account.

Apple Watch and Apple Health: Only after you actively start a run on Apple Watch, the app requests the heart rate, active energy, walking/running distance, and step count needed for that workout and writes the completed workout to Apple Health. Cadence is calculated only from a valid measured step count divided by active workout duration; it is not estimated when steps are unavailable. The completed summary (distance, duration, pace, heart rate, cadence, energy, and workout type) syncs to iPhone and is uploaded to Sport Master (formerly AISmartRun) for history and personalized training. We do not read clinical records or use health data for advertising or sale.

Garmin Connect IQ: Only after you start a workout on the Garmin watch or in the companion phone app, the watch app accesses the workout data needed for live metrics and activity recording: GPS position, distance, speed, altitude, heart rate, cadence, pressure and Pulse Ox when supported; Garmin profile heart-rate zones, max/resting heart rate and weight; and the latest Body Battery and stress values. During a connected workout, these values and derived coaching metrics are relayed through Garmin Connect Mobile to the SmartRun Android app and, when you are signed in, to our backend for the purposes listed in this policy. In standalone mode the watch app can save the workout to Garmin Connect without the SmartRun backend. Denying a permission limits the related metric but does not cause background collection before a workout starts. Data you send to SmartRun is submitted to us, not to Garmin; Garmin is not responsible or liable for our processing of that data.

Android routes and weather: Completed Android runs for a signed-in account upload complete route points to our Singapore backend, and a GPX file you actively import is stored as an account route. The new Android app requests Tencent map tiles, exposing the IP address and requested tile coordinates. When you actively request route planning, it sends the start, finish and waypoints to Tencent Location Services for walking or cycling directions. Older or other clients using OSRM/OpenStreetMap follow the corresponding processor entries below. When the home screen uses your position for weather, the new Android app first rounds a recent valid position to about two decimal places and sends those approximate coordinates to our backend, which forwards them to QWeather or Open-Meteo for that real-time request. The weather provider does not create an Sport Master (formerly AISmartRun) account record from that request. These providers also receive network connection data such as an IP address while serving the request.

Optional Android features and local files

Usage analytics are off by default. A signed-in user can separately enable them in Me → Settings & About → Usage Analytics. Only approved event names, random event IDs, timestamps and bounded mode/step/channel values are accepted. Tokens, phone numbers, precise coordinates, health values, chat and free-form input are excluded. Turning this off immediately clears the local owner queue; server confirmation deletes that owner's analytics events. Offline withdrawal remains pending and cannot silently enable collection again. Consent and queues are isolated by account and are not restored from backups. Necessary security and failure diagnostics remain separate.

Local backups are unencrypted ZIP files saved only to the location you select through the system file picker. Selected domains may contain activity tracks, pending uploads, GPX, roadbook photos, offline maps and local settings, including sensitive location and fitness data. Choose a trusted location; any selected storage provider processes files under its own policy. Restore validates the same owner and API environment (and the same installation for guests), previews the replacement scope and does not restore login credentials, device authorization, paid rights, cloud chat or canonical workout execution rights. Selected local clearing does not delete cloud records or another account. Ordinary sign-out preserves local owner data.

Public sharing requires confirmation. Preview alone creates no public link. A published link reveals the nickname, activity summary and protected track to anyone with the link. Points within 500 metres of either endpoint and segments that could cross that area are removed; short routes may have no visible track. This does not guarantee anonymity. Revocation disables our public page and image, but cannot retrieve copies or screenshots already saved by others.

Manual thresholds and wellness: FTP, threshold pace, wheel circumference, hydration goals and confirmed nutrition values are stored per account. Activity threshold snapshots keep their source and revision; missing measurements are not fabricated. A deleted activity leaves only its owner, upload retry key and deletion time until account deletion, so a restored old queue cannot recreate it. No deleted track or score is retained in that retry marker. Account deletion removes local service records and revokes sessions; third-party cloud deletion is a durable retry and cooling sweep, not an immediate completion guarantee. User-exported files must be deleted by the user.

2. Sensitive Data

Precise location, health and fitness metrics, nutrition photos, and injury or health profile fields may be sensitive. We process them only for the product features you choose. System location permission allows the device to record your own active run; it is not consent to publish or contribute location to a leaderboard, group, or anonymous heatmap. Anonymous location sharing is off by default and starts only after you separately and explicitly enable it in the app. You may deny system permission and use an indoor mode, turn sharing off, delete records, or delete your account.

3. Storage and International Transfers

Our backend currently runs in Tencent Cloud Singapore (ap-singapore). If you use the app from another country or region, your data may be transferred to Singapore. Some AI providers process data in other regions as listed below. We use these processors only for the minimum data needed to provide the feature.

If you separately connect EverMe, memory queries and coach turns are also sent to that service. Its privacy policy says the service is generally provided from Singapore and data may also be processed in other jurisdictions.

Separate third-party AI permission: Before a signed-in user sends the first AI coach message, the app identifies DeepSeek, EverMind, optional EverMe, the data categories and purposes, and offers “Allow and Continue” or “Not Now.” Until permission is recorded, the server does not call these providers or trigger third-party AI for new runs, weekly reports, or plans. The rules_v1 coach schedule draft runs only on our Singapore backend and does not send its questionnaire or draft to DeepSeek, EverMind, or EverMe; it remains available without third-party AI permission. EverMe additionally requires you to confirm its specific data scope in the app and authorize read, search, and write access to your own EverMe account in the system browser. General AI permission alone does not connect EverMe. You can withdraw general permission under Me → Settings & About → Third-Party AI Data Permission and disconnect EverMe in the devices/platforms screen. Disconnecting stops future access and requests token revocation but does not automatically delete memories already saved by EverMe.

4. AI and Third-Party Processors

ProcessorDataPurpose
DeepSeek (Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd.)The current question and recent chat, selected coach style, and relevant EverMe memory excerpts if you connect EverMe; nickname, sex, height, weight, resting/max heart rate, longest run, 5K result, goals and streak; training/weekly insights including date, distance, pace, heart rate and cadence; daily nutrition and hydration summaries. We do not separately attach phone numbers, login credentials, or raw GPS tracks; information you put in your chat may include them.Only after separate permission: AI plans, post-run reviews, weekly reports, and coach replies
Tencent Cloud TTSCoach speech text without direct identifiersSynthetic voice coaching
Tencent TokenHub / Hunyuan visionNutrition photo provided by youFood and portion recognition
Tencent Cloud SMSPhone numberLogin verification code
EverMind AI / EverOS Cloud (api.evermind.ai)Pseudonymous training summaries (date, distance, pace, heart rate and cadence), AI insights, the user's question, and the AI reply. We do not separately attach phone numbers, names, login credentials, or raw GPS tracks; information you put in your chat may include them.Only after separate permission: long-term AI coach memory and personalized coaching context
EverMe (Evermind AI, Inc.; privacy policy)After you connect your account, memory-context requests and a bounded search-keyword query based on your question; after an eligible successful coach reply, we attempt to save the complete question and answer, which may include training, health or other information you put in the chat or that appears in the answer. We do not separately attach your Sport Master phone number, login credentials, raw GPS tracks, or live sensor stream.Only after general AI permission, separate in-app scope confirmation and your EverMe OAuth authorization: cross-session coach memory. Relevant retrieved excerpts are also sent to DeepSeek to generate a reply. Disconnecting stops future read/write access and requests token revocation, but does not automatically delete memories already stored in EverMe.
Google Play services, Garmin Connect IQ / Garmin Connect Mobile, and Rokid SDKDevice-side location; Garmin workout, profile and sensor metrics described in Section 1; HUD data as neededLocation, watch-to-phone relay and activity recording, and glasses HUD
Tencent Maps / Tencent Location ServicesIP address, requested tile coordinates, and start/finish/waypoints when you actively request planning; no account login credentialsNew Android basemap and walking/cycling route planning
OpenStreetMap (older or other clients)IP address and requested map-tile coordinatesDisplay the route basemap
Public OSRM routing service (router.project-osrm.org)Start and loop waypoints and IP address when you actively request route planningReturn a walking/running route for the requested loop
QWeatherCity-level coordinates rounded by our backend to about two decimal placesCurrent conditions and short forecast when configured as the primary provider
Open-MeteoCity-level coordinates rounded by our backend to about two decimal placesCurrent conditions and short forecast as the current default or QWeather fallback
System speech-recognition provider (for example, Google Speech)Your voice for transient speech-to-text processing; our backend receives only the transcriptVoice input you actively start

Equivalent protection: Through applicable service agreements and data-processing terms, data minimization, pseudonymous identifiers, and access controls, we require third-party AI providers to protect received data to the same or an equivalent level as this policy and applicable law, and not to use it for advertising, sale, or unrelated purposes. If we cannot confirm that a provider continues to meet this requirement, we stop sending new personal data to it.

5. Retention

Account and profile data are kept until you delete your account. Run, chat, plan, nutrition, and our AI memory records are kept until you delete the record or account. Coach schedule draft answers and refinements remain until you delete that draft in the app or delete your account; deleting a draft does not delete an already adopted weekly plan. Server logs are kept on a rolling basis for security and debugging. Backups roll off automatically. Disconnecting EverMe or deleting your Sport Master account stops our future access and requests revocation, but does not automatically delete memories already stored in your EverMe account; manage those through EverMe or contact its provider.

6. Your Rights

7. Children

Sport Master (formerly AISmartRun) currently provides account services only to adults who are 18 years of age or older. Anyone under 18 must not register an account or submit a training profile; the current version does not open minor accounts even with guardian consent. If we learn that an account user is under 18, we will stop providing account services and delete or otherwise handle the related personal information as required by applicable law. The guest demo does not require an account, uses isolated on-device sample content, and must not upload personal, location, or health data.

8. Contact

Operator: Shanghai Fun Pizza Software Technology Co., Ltd.
Support email: 2630281760@qq.com
In-app support: Me → Settings → Contact us.

9. Updates

Material changes, such as new data categories, processors, or cross-border transfers, will be announced in the app and may require renewed consent.