Privacy Policy

Last updated: July 23, 2026

Active Metrics is made by Spears Software (“we,” “us,” “our”). This policy explains what happens to your data when you use the app, the beacon live-sharing feature, and this website — including during the closed TestFlight beta.

The short version: almost everything stays on your device or in your own iCloud account, which we cannot read. The only things that reach a server we operate are route requests, map tiles, an opt-in live-location share, and whatever you type into the beta-request form on this site. None of it is used for advertising, and we don’t sell or share your personal information.

A. What stays on your device and in your own iCloud

HealthKit. The watch app writes workouts, workout routes, and a workout effort score to Apple Health. The iPhone app never writes to Health — it only reads what’s already there.

The watch reads heart rate, active energy, distance (including swimming), running speed and power, steps, effort scores, activity summaries, and your date of birth. The iPhone app additionally reads VO2max, resting heart rate, heart-rate variability (SDNN), heart-rate recovery, sleep analysis, and biological sex. None of this is transmitted to Spears Software — it’s read locally to power the app’s own screens and analytics.

Health data is never used for advertising, marketing, or use-based data mining.

Your own iCloud. Workout records, imported GPX routes (including the full track), structured workouts, and daily energy data sync through your personal iCloud account via CloudKit’s private database. That means workout health metrics — average and max heart rate, active calories, heart-rate zone distribution, effort scores — travel through iCloud the same way your Health app data does. Spears Software cannot read your CloudKit private database; only you and your own devices can.

Your training zones, cadence and power targets, unit preferences, and beacon settings — including any saved contacts (name, email, phone) and privacy-zone locations you’ve configured — sync the same way, through NSUbiquitousKeyValueStore in your own iCloud account. We cannot read this either.

No analytics, no tracking, no third parties in the app itself. Active Metrics has no analytics SDK, no crash reporter, no ad or attribution SDK, and no third-party runtime dependencies at all. There’s no account, no login, and no user ID tied to you.

B. Services we operate

A few features need a server, because your watch and phone can’t generate maps or routes on their own. Here’s exactly what each one sees.

Route generation (route.activemetrics.app) — when you generate a loop, your watch sends waypoint coordinates (or a starting point, distance, and heading) to this service and gets a route back. Requests are authenticated with a key that’s identical across every install of the app — it identifies “a copy of Active Metrics,” not you personally, and can’t be used to link requests to a person. We don’t store requests in a database; routes are cached at Cloudflare’s network edge for up to 30 days, keyed by coordinates rounded to about 11 meters. Your IP address is used briefly for rate-limiting and isn’t retained beyond that.

Map tiles (tiles.activemetrics.app) — requests for map tiles by coordinate. This requires no account or user identifier of any kind. The coordinate in the request implies roughly what area you’re looking at, but nothing is logged that ties it to you.

Live location sharing (live.activemetrics.app, beacon) — off by default, entirely opt-in. When you share a live link during a run:

If you enable email notifications for a beacon share, we send your display name and the live link to the addresses you provide via Postmark, our email provider. We don’t keep those recipient addresses on our servers afterward. You’re responsible for having permission from anyone you add as a beacon contact — their name, email, or phone number is their personal data, supplied by you.

C. This website and beta applications

The beta-request form on this site collects your name, email, watch model, region, and whatever you write in the message field. Submitting it makes Spears Software the controller of that data for the purpose of running the beta program. We use it only to review and manage beta invitations, and we keep it for as long as the beta program runs plus a reasonable period afterward for our own records, then delete it. Email us (below) to request deletion sooner.

This site uses Cloudflare Turnstile for spam protection, which may set cookies such as __cf_bm and run a browser challenge. Cloudflare, which hosts this site, also logs standard web request data (IP address, user agent, timestamp) as part of operating the network — we don’t control or read those logs beyond what’s needed to keep the site running.

D. Sub-processors

Services that process data on our behalf:

E. Your rights under GDPR

If you’re in the EEA, UK, or Switzerland, this section applies to you.

Controller: Spears Software. Contact us using the email below for any privacy request.

Legal basis for processing:

Your rights: access, correction, deletion, restriction of processing, data portability, and objection to processing. To exercise any of these, email us below — we’ll respond within a reasonable time.

Retention: covered above, per data type — most is deleted automatically within hours (beacon) or governed entirely by your own iCloud account (everything else).

Where processing happens: our servers and sub-processors operate in the United States.

Complaints: you have the right to lodge a complaint with your local data protection supervisory authority.

F. Your rights under CCPA

If you’re a California resident: we do not sell or share your personal information, and we haven’t in the past 12 months. Categories of personal information we collect are described in sections B and C above (contact info, approximate location during an active beacon share, and — only if you opt in — health/fitness data). You have the right to know what we collect, request deletion, and not be discriminated against for exercising these rights. Contact us below to make a request.

G. Permissions the app asks for

PermissionWhy we ask
HealthTo read your workout, heart-rate, and recovery data for the app’s own screens, and to save completed workouts back to Health.
LocationTo record your route during a workout, generate turn-by-turn navigation, and — only if you enable it — power live location sharing.
Motion & FitnessTo estimate reps during strength-training workouts using wrist motion.
BluetoothTo connect to external sensors — heart-rate straps, power meters, cadence sensors, and smart trainers.
NotificationsTo deliver in-workout alerts, like target-zone warnings and lap notifications.

Children’s privacy

Active Metrics is not directed at children under 13, and we don’t knowingly collect personal information from them.

Changes to this policy

If this policy changes in a material way, we’ll update the “last updated” date above. Since this is beta software, expect the app’s behavior — and this policy — to evolve during the beta period.

Contact

activemetrics@spearssoftware.com