Move Your Body. Unblock Your Mind.
Walk. Talk. Listen. Relax.
A more natural way to work through life.
Download mobile app from the Store. It’s FREE.
Dynamic Running Therapy (DRT)
Effective Date: June 1, 2026 | Last Updated: May 26, 2026
This Privacy Policy explains how Dynamic Running Therapy (referred to in this Policy as “DRT,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you download, install, register for, or use the Dynamic Running Therapy mobile application (the “App”) and any other DRT activities or websites expressly referenced herein. It also describes the choices and rights you have regarding your personal information.
DRT is a self-guided wellness application that combines movement (such as walking or running), mindfulness prompts, and reflective questions designed to support your general well-being. The App is not a medical device, is not intended to diagnose, treat, cure, or prevent any illness or disease, and does not provide medical, psychological, or psychotherapy services. If you are experiencing a mental health crisis or have a medical concern, please contact a qualified healthcare professional or your local emergency services. By using the App, you acknowledge and accept that it is not a substitute for professional healthcare advice. For more information on our liability limitations, please refer to our Terms and Conditions, which include a liability cap.
We have written this Policy to comply with privacy laws in the regions where the App is available, including the United States (with state-specific addenda below), the European Economic Area (including Ireland), the United Kingdom, Canada, South Africa, Australia, and New Zealand. Sections 16 through 23 of this Policy contain jurisdiction-specific disclosures that supplement, and where applicable override, the general provisions.
By downloading, installing, accessing, or using the App, you confirm that you have read and understood this Policy. If you do not agree with this Policy, please do not use the App.
A current copy of this Policy is available on our website at Dynamic Running Therapy Privacy Policy, and from within the App at any time. We recommend that you save or print a copy for your records.
By downloading, installing, accessing, or using the App, you confirm that you have read, understood, and agree to the Terms and Conditions, including the liability limitations and disclaimers. You must check the box indicating your acceptance of these terms before proceeding to use the App.
The data controller responsible for your personal information under applicable law is:
Dynamic Running Therapy LLC
38 Davis Hill Rd,
Weston,
CT 06883,
USA
info@dynamicrunningtherapy.com
For questions about this Policy, to exercise any of your privacy rights, or to submit a privacy complaint, please contact us at the email address above. We aim to respond to privacy inquiries within thirty (30) days, and within the shorter response times required by specific laws referenced in the jurisdiction-specific sections below.
For privacy-related matters, you may also contact our designated Data Protection Officer at dpo@dynamicrunningtherapy.co.uk. Our designated Data Protection Officer, as required under GDPR Article 37, may be contacted regarding matters involving special categories of data processing at dpo@dynamicrunningtherapy.co.uk.
We collect personal information from and about you in three ways: (a) information you provide to us directly; (b) information we collect automatically when you use the App; and (c) information we receive from third parties.
When you create an account or use the App, you may provide us with:
When you use the App, we and the service providers acting on our behalf automatically collect certain information, which may include:
We may receive limited information about you from third parties, such as the Apple App Store, the Google Play Store, payment processors handling in-app purchases, and analytics or crash-reporting providers. We do not receive financial card details from Apple or Google; they handle payment processing directly and only share with us the information necessary to manage your subscription, such as a transaction reference and subscription status.
Some of the information you provide through the App, such as journal entries describing your feelings, mental state, or well-being, and any health or fitness data you connect, may constitute sensitive personal information under applicable privacy laws. We afford this information heightened protection and process it solely for the following purposes:
We do not use sensitive personal information for product analytics, advertising, profiling, or any purpose unrelated to the direct provision of the App’s features to you, except that anonymized or de-identified data may be used for product improvement.
We do not sell or share sensitive personal information for cross-context behavioral advertising, and we do not use such information to infer characteristics about you for any purpose unrelated to the App.
Specifically, we do not use HealthKit data for advertising purposes or sell it to third parties, in compliance with Apple’s HealthKit guidelines.
We use the personal information we collect to:
We will not use your personal information for any purpose that is incompatible with the purposes described in this Policy unless we obtain your consent or are otherwise permitted to do so by law.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal information only when we have a legal basis to do so under Article 6 of the General Data Protection Regulation, Regulation (EU) 2016/679 (the “GDPR”), and the corresponding provision of the United Kingdom’s retained version of the GDPR (the “UK GDPR”). The legal bases we rely on are:
Where we process special categories of personal data (Article 9 GDPR), including any health-related information you share with us, we rely on your explicit consent (GDPR art. 9(2)(a)) and a condition under Schedule 1 of the Data Protection Act 2018, such as paragraph 1, which relates to processing with consent. You have the right to withdraw your consent at any time without affecting the lawfulness of any processing carried out before withdrawal.
We share your personal information only as set out in this Policy. We may share it with:
We are based in London, United Kingdom, and the service providers we use may be located in other countries, including the United States, the United Kingdom, the European Economic Area, and other regions. When we transfer personal information across borders, we put in place safeguards required by law, including:
You can ask us for a copy of the safeguards we rely on by contacting us at the email address in Section 2.
We keep your personal information only for as long as we need it for the purposes described in this Policy or for as long as the law requires. In general:
We use technical and organizational measures designed to protect your personal information against accidental loss and unauthorized access, use, alteration, or disclosure. These measures include encryption of personal information in transit and at rest using AES-256 and TLS 1.2 or higher, access controls and authentication for our staff, regular review of our security practices, and contractual obligations on our service providers.
No method of transmission over the internet or storage on a mobile device is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.
If a breach of security affecting your personal information occurs, we will notify you and the relevant regulators where required by law, including under Article 33 and 34 of the GDPR and the UK GDPR, the Federal Trade Commission’s Health Breach Notification Rule (16 C.F.R. Part 318), section 22 of POPIA, Part IIIC of the Australian Privacy Act 1988, and Part 6 of the New Zealand Privacy Act 2020. We will establish internal breach response timelines and escalation procedures to ensure compliance with these obligations.
Depending on where you live, you have certain rights in relation to your personal information. The general rights described in this Section 10 apply to all users where the relevant law permits. The jurisdiction-specific sections (16 through 23) explain additional or different rights and how to exercise them.
You generally have the right to:
To exercise any of these rights, contact us at the email address in Section 2. We may verify your identity before responding to your request. We reserve the right to charge a reasonable fee or decline requests that are manifestly unfounded or excessive, to the extent permitted under GDPR art. 12(5). A published fee schedule is available upon request. We will not discriminate or retaliate against you for exercising any privacy right.
The App is not directed to children under the age of sixteen (16), and we do not knowingly collect personal information from anyone under that age. In some jurisdictions, including parts of the European Economic Area, the minimum age at which a person can consent to the processing of their information without parental authorization is lower (as low as thirteen (13) under GDPR art. 8(1)). Regardless of any lower local age limit, we apply a minimum age of sixteen (16) for use of the App. We enforce this policy through age verification mechanisms to ensure compliance.
If we learn that we have collected personal information from a person under the age of sixteen (16) without verifiable parental consent, we will delete that information promptly. If you believe a child has provided personal information to us, please contact us at the email address in Section 2.
For users in the United States, our practices are also designed to comply with the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501-6506, and the FTC’s implementing regulations at 16 C.F.R. Part 312 (“COPPA”).
The App relies on a small number of third-party services to function. These include categories such as app store platforms, cloud hosting, analytics, crash-reporting, and email and communications providers. A current list of specific providers is maintained on our website and can be accessed via a link in this Policy.
Each of these providers has its own privacy notice, which governs its processing of your information for its own purposes. We encourage you to read those notices.
We do not control how third parties process information they collect directly from your device through their software development kits (SDKs) or operating-system features, although we contractually require our processors to act only on our instructions when they process information on our behalf, pursuant to written data processing agreements that comply with Article 28 of the GDPR (and the equivalent provision of the UK GDPR) and other applicable data protection laws.
DRT disclaims liability for any unauthorized data processing by third-party SDKs, except where required by applicable law.
We may update this Policy from time to time. When we make material changes, we will notify you through the App or by email before the changes take effect, and we will update the “Last Updated” date at the top of this Policy.
Where a change materially affects the purposes for which we process your personal information or the legal basis on which we rely, we will seek your affirmative consent before applying the change to your information.
For all other changes, your continued use of the App after the effective date of the updated Policy means you accept the changes. Non-material changes are those that do not affect your rights or the legal basis for processing your information. If you do not agree with any non-material changes, you should stop using the App and may delete your account.
In this Policy:
In addition to this Policy, the App’s Apple App Store listing displays Apple’s “App Privacy” labels, and its Google Play listing displays Google’s “Data Safety” disclosures. The labels summarize the data we collect and how it is used in the format required by the relevant platform.
We endeavor to keep those labels accurate and consistent with this Policy. If you identify an inconsistency, please notify us using the contact information in Section 2 so that we may investigate and correct it.
This Section 16 applies to users located in the United States and is in addition to the rest of this Policy.
DRT operates the App as a “vendor of personal health records” within the meaning of the Federal Trade Commission’s Health Breach Notification Rule, 16 C.F.R. Part 318. Under that Rule, a “personal health record” (“PHR”) is an electronic record of identifiable health information that has the technical capacity to draw information from multiple sources and that is managed, shared, and controlled by or primarily for the individual. 16 C.F.R. § 318.2. The Rule applies to mobile applications that track health information such as fitness, mental health, sleep, and related categories.
If a breach of security affects unsecured PHR identifiable health information, we will notify each affected U.S. user, the Federal Trade Commission, and, where 500 or more residents of any State are affected, prominent media outlets, in accordance with 16 C.F.R. §§ 318.3 through 318.6. Notification will be sent without unreasonable delay and in any event within sixty (60) days after the breach is discovered by a responsible officer, unless a law enforcement agency determines that notification would impede a criminal investigation, in which case notification may be delayed as permitted under 16 C.F.R. § 318.4(b).
DRT is not a “covered entity” or a “business associate” as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), 42 U.S.C. § 1320d et seq., and its implementing regulations at 45 C.F.R. Parts 160 and 164.
The App is a direct-to-consumer wellness tool. Information you provide through the App is not “protected health information” under HIPAA and is not protected by the HIPAA Privacy or Security Rules. We protect your information through the safeguards described in this Policy and the laws referenced below.
Users must not submit information they believe to be protected health information, and DRT disclaims any liability for any protected health information submitted in violation of this provision.
We are subject to Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, which prohibits unfair or deceptive acts or practices in or affecting commerce. We will not make materially false or misleading statements about our privacy practices, and we will honor the commitments in this Policy, as amended from time to time. In the event of material amendments to this Policy, we will provide notice to affected users in accordance with applicable legal requirements.
In addition to the comprehensive state privacy laws covered in Section 16.5 below, certain U.S. states have enacted laws specifically directed at consumer health information. We comply with the following where they apply, as well as other applicable state health data laws:
Residents of states with comprehensive consumer privacy laws have rights regarding their personal information. The states currently in scope include California (see Section 17 below), Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, among others (subject to applicability thresholds, such as a minimum of 500 residents or specific revenue criteria).
These rights generally include, but are not limited to:
To exercise these rights, contact us at the email address in Section 2. We will verify your identity before responding and will respond within forty-five (45) days unless an extension is permitted by law.
We reserve the right to decline requests that are excessive, repetitive, or manifestly unfounded, and we may limit the frequency of requests to twice per 12-month period, to the extent permitted by applicable law.
This Section 17 applies to “consumers” as defined in the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (the “CCPA”), Cal. Civ. Code §§ 1798.100 et seq.
In the past twelve (12) months, we have collected the following categories of personal information about California consumers, drawn from the categories at Cal. Civ. Code § 1798.140(v):
We collect this information from the sources described in Section 3 of this Policy, use it for the purposes described in Section 4, and share it with the categories of recipients described in Section 6.
Some of the categories above include “sensitive personal information” as defined in Cal. Civ. Code § 1798.140(ae), in particular health information and precise geolocation. We use sensitive personal information for the purposes described in Cal. Civ. Code § 1798.121(a) and the implementing regulations of the California Privacy Protection Agency, including but not limited to providing the App and its features as you have requested, security, fraud prevention, and legal compliance.
We do not use or disclose sensitive personal information to infer characteristics about you for any other purpose or to third parties for non-operational purposes. You have the right to limit our use of sensitive personal information by contacting us at the email address in Section 2.
We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising, as those terms are defined in Cal. Civ. Code § 1798.140(ad) and (ah).
No opt-out is required to stop sales or sharing of your personal information because we do not engage in those activities. We honor Global Privacy Control (GPC) signals where technically feasible.
If you would still like to exercise an opt-out as a precaution, you may do so by emailing us at the address in Section 2 with the subject line “Do Not Sell or Share My Personal Information.” This representation is current as of the effective date and subject to future Policy updates, which will be communicated to you in advance.
California consumers have the following rights:
To submit a verifiable consumer request, contact us at the email address in Section 2. We will confirm receipt within ten (10) business days and respond within forty-five (45) calendar days, extendable by an additional forty-five (45) days where reasonably necessary and with notice to you. Cal. Civ. Code § 1798.130(a)(2).
You may also designate an authorized agent to make a request on your behalf. We will require written permission from you, which must include a signed authorization, and may verify your identity directly.
California Civil Code § 1798.83 permits California residents to request information regarding the disclosure of personal information to third parties for the third parties’ direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes, thereby fully satisfying the requirements of § 1798.83.
If you are located in the European Economic Area, this Section 18 applies to you. The General Data Protection Regulation, Regulation (EU) 2016/679 (the “GDPR”), applies to our processing of your personal data. The legal bases on which we rely are set out in Section 5 of this Policy. Section 6 of this Policy describes the recipients of your personal data, and Section 7 describes our international data transfer safeguards.
Under the GDPR, you have the following rights:
To exercise any of these rights, contact us at the email address in Section 2. We will respond within one (1) month of receiving your request, extendable by a further two (2) months where necessary, in which case we will tell you why. GDPR art. 12(3). We reserve the right to charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, as permitted by GDPR art. 12(5).
You have the right to file a complaint with a supervisory authority in the EU Member State where you live, work, or where you believe an infringement has occurred. GDPR art. 77.
Before doing so, we encourage you to contact us directly at the email address in Section 2 to allow us the opportunity to address your concerns. A list of supervisory authorities is available from the European Data Protection Board. Notable authorities include:
For users in the EEA, we apply a minimum age for use of the App that aligns with the age of digital consent in each Member State, ranging from thirteen (13) to sixteen (16) years. We will implement an age verification mechanism to ensure compliance with GDPR Article 8. Where you are a parent or guardian and become aware that your child has used the App without your authorization, contact us at the email in Section 2 and we will delete the account and associated personal data.
If you are located in the United Kingdom, the UK General Data Protection Regulation (the “UK GDPR”) and the Data Protection Act 2018 apply to our processing of your personal data. Your rights mirror those described in Section 18 above, subject to UK-specific derogations and the UK’s data protection framework. We reserve the right under UK GDPR Art. 12(5) to refuse or charge a reasonable fee for excessive or unfounded requests. Additionally, specific carve-outs apply to data retention and health data as per UK regulations.
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane,
Wilmslow, Cheshire SK9 5AF,
United Kingdom
Helpline: 0303 123 1113
Website: https://ico.org.uk
Where we transfer personal data from the United Kingdom to a country that is not subject to a UK adequacy regulation, we use the UK’s International Data Transfer Agreement or, where the UK Addendum to the EU Standard Contractual Clauses is applicable, the UK Addendum, supplemented by additional safeguards where necessary.
If you are located in Canada, our processing of your personal information is subject to the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”), and, where applicable, substantially similar provincial laws including Quebec’s Act respecting the protection of personal information in the private sector, CQLR c. P-39.1 (“Law 25”), British Columbia’s Personal Information Protection Act, S.B.C. 2003, c. 63, and Alberta’s Personal Information Protection Act, S.A. 2003, c. P-6.5. In the event of a conflict between PIPEDA and provincial laws, the stricter law will apply.
You have the right to:
You may also direct privacy complaints to the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, Quebec K1A 1H3, or to your provincial Information and Privacy Commissioner.
If a privacy breach creates a real risk of significant harm, we will report the breach to the relevant Privacy Commissioner and notify affected individuals as required by section 10.1 of PIPEDA and corresponding provincial legislation.
We will respond to access requests within thirty (30) days of receipt, with the possibility of extending this period by an additional thirty (30) days if necessary, in accordance with PIPEDA s. 8(3).
If you are located in South Africa, our processing of your personal information is subject to the Protection of Personal Information Act, 4 of 2013 (“POPIA”). For the purposes of POPIA, we act as the “responsible party” and any service providers we use act as “operators.” The Information Officer for DRT can be contacted at the email address in Section 2.
Under POPIA, you have the right to:
The Information Regulator (South Africa) can be contacted at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, by email at enquiries@inforegulator.org.za, or via www.inforegulator.org.za.
Where a compromise of your personal information occurs that may give rise to a risk of harm, we will notify the Information Regulator and you as required by section 22 of POPIA within 72 hours of becoming aware of the breach.
If you are located in Australia, our processing of your personal information is subject to the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (“APPs”) set out in Schedule 1 to that Act.
You have the right to:
Some information you provide through the App is “sensitive information” under section 6 of the Privacy Act 1988, including health information. We collect sensitive information only with your consent and use it only for the purpose for which it was collected, or for a directly related secondary purpose that you would reasonably expect, as permitted by APP 6. Consent is obtained through an in-app acknowledgment mechanism, where users must actively agree to the collection and use of their sensitive information before proceeding.
You can make a complaint about how we handle your personal information by contacting us at the email in Section 2. We will respond to your complaint within thirty (30) days of receipt. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at GPO Box 5288, Sydney NSW 2001, by phone on 1300 363 992, or via www.oaic.gov.au.
Where an eligible data breach occurs, we will notify affected individuals and the OAIC as required by Part IIIC of the Privacy Act 1988 (the Notifiable Data Breaches scheme).
If you are located in New Zealand, our processing of your personal information is subject to the Privacy Act 2020 and the thirteen Information Privacy Principles (“IPPs”) set out in section 22 of that Act. In the event of a privacy breach that is likely to cause serious harm, we will notify the affected individuals and the Office of the Privacy Commissioner within the time required by applicable law.
You have the right to:
Where we disclose your personal information to a person or entity outside New Zealand, we do so in accordance with IPP 12 of the Privacy Act 2020, which requires that the recipient is subject to comparable privacy safeguards or that you have authorized the disclosure after being informed that comparable safeguards may not apply.
For transfers to countries without comparable privacy safeguards, we use lawful and appropriate transfer mechanisms to ensure adequate protection of your personal information. In the event that a transfer mechanism is invalidated due to regulatory changes, we will promptly implement alternative measures to maintain the protection of your personal information.
If you have a complaint about how we handle your personal information, contact us at the email in Section 2. We will acknowledge receipt of your complaint within 5 business days and aim to resolve it within 20 business days.
You may also complain to the Office of the Privacy Commissioner, PO Box 10094, The Terrace, Wellington 6143, by phone on 0800 803 909, or via www.privacy.org.nz.
Where a privacy breach occurs that it is reasonable to believe has caused, or has a risk of causing, serious harm to an affected individual, we will notify the Privacy Commissioner and the affected individuals as soon as practicable, as required by Part 6 of the Privacy Act 2020.