Skip to main content
TreadSimple
Home Support

Privacy, plainly

Privacy Policy

TreadSimple is designed without a user account or workout database operated by the developer.

Effective August 14, 2026 Questions or deletion requests?
privacy@treadsimple.com

This policy explains how TreadSimple handles information through the iPhone app, the TreadSimple website, and support. TreadSimple is designed so that the developer does not operate a user account or server-side workout database. The app stores workout information on the user’s iPhone. Information leaves the phone only in the circumstances described below.

Information kept on the iPhone

TreadSimple stores:

  • workout dates and times, duration, speed, incline, distance, estimated elevation gain, energy, optional heart rate, lap splits, and optional workout notes;
  • for a discarded workout over five minutes, only the Monday date of its free-plan allowance week;
  • Bluetooth device identifiers and names;
  • integration job status and destination activity identifiers;
  • optional height, weight, and birthday used to estimate workout energy and heart-rate zones;
  • heart-rate zone boundaries imported from Strava;
  • display and automatic-sync preferences;
  • a bounded diagnostic history containing typed operational results, with at most 300 entries and a maximum age of seven days; and
  • randomly generated installation and session identifiers used only to correlate diagnostic events. The installation identifier is stored in the iOS Keychain.

Strava access and refresh tokens are stored in the iOS Keychain. This information comes from the user, connected treadmills, running sensors, and heart-rate monitors, calculations performed by the app, and connected services. It is used to record, display, recover, export, and synchronize workouts; provide requested features; and troubleshoot the app.

Bluetooth

The app scans for and communicates with compatible treadmills, running speed and cadence sensors, and heart-rate monitors nearby. Bluetooth readings are processed on the phone and saved as part of the local workout. TreadSimple does not use Bluetooth to infer or collect geographic location.

Consumer health data notice

The consumer health data TreadSimple handles consists of workout and fitness measurements, optional heart-rate data, optional height, weight, and birthday, and information the user adds to a workout. Its sources are the user, connected treadmills and sensors, calculations performed on the iPhone, and Strava when connected. TreadSimple uses this information to provide the recording, display, calculation, history, export, synchronization, support, compatibility, and security functions described in this policy.

At the user’s direction, the app discloses the selected workout categories to Apple Health or Strava as described below. Sentry can receive the limited treadmill compatibility measurements described below as a service provider. A support email or enhanced hardware report contains only the categories the user chooses to include and is shared through the user’s selected email or share service. TreadSimple has no affiliate with which it shares consumer health data and does not sell consumer health data. Applicable access, deletion, withdrawal, and appeal rights are described under United States privacy rights.

TV Mode and AirPlay

When the user chooses TV Mode, TreadSimple sends a read-only presentation of the current workout to the selected television. It can include elapsed and lap time, distance, speed, incline, heart rate and zone, calories, workout state, unit and reduced-motion preferences, and a random identifier that exists only for the current TV session. TV Mode does not send the persisted workout identifier, profile values, device names or identifiers, credentials, exact workout start time, workout files, or raw Bluetooth packets.

With AirPlay, the presentation is rendered by a page bundled inside TreadSimple on the external display. Live TV workout values remain inside the app and the connected display path; TreadSimple does not relay or store them through its AWS service, website, Sentry project, analytics, or a workout database. Users stop sharing by disconnecting AirPlay. The TV hides stale live values after 30 seconds, and a completed summary is cleared after 60 seconds; users should still avoid shared displays when others should not see workout or heart-rate values.

App Store subscriptions

If the user subscribes to TreadSimple Pro, Apple processes the purchase and payment information under the user’s Apple Account. TreadSimple uses StoreKit to read the purchased product identifier, subscription expiration, and revocation or upgrade state needed to unlock paid features. The developer does not receive full payment-card details. Users can restore purchases or manage and cancel the subscription through their App Store account.

Treadmill and sensor information

TreadSimple is a recording and display tool. It does not manufacture, sell, install, inspect, maintain, or repair a treadmill or sensor, and it does not control treadmill speed or incline. Measurements received from third-party equipment can be incomplete, delayed, or inaccurate. The app’s Terms & Safety and Apple’s Standard EULA govern use of the app and applicable limitations of liability. Nothing in this policy limits any right or remedy that cannot be limited under applicable law.

Apple Health

If the user grants permission, TreadSimple writes completed indoor-running workouts, distance, active energy, and heart-rate samples to Apple Health. TreadSimple does not read existing Apple Health data. This transfer occurs on the device and does not pass through TreadSimple servers. Apple controls storage and processing in Apple Health under the user’s Apple settings and Apple’s terms.

Strava

If the user connects Strava, the user authorizes TreadSimple to read heart-rate zone boundaries and upload completed workout files to the user’s Strava account. Imported boundaries are stored on the iPhone and used to show the live workout zone. A file can include workout date and time, duration, distance, speed, incline, estimated elevation gain, heart rate when recorded, lap splits, and an optional note entered by the user. Uploads travel directly from the phone to Strava. TreadSimple receives upload status and destination activity identifiers on the phone so it can show completion and avoid duplicate uploads.

A stateless service hosted on Amazon Web Services exchanges, refreshes, and revokes Strava OAuth credentials because Strava requires a server-held client secret. The broker processes authorization codes and tokens only long enough to service each request and does not store them. It also acknowledges Strava webhook event metadata, such as event type and activity or athlete identifiers, without building a user or workout database.

Operational logs contain request identifiers, routes, response status, payload length, event type, and the app-wide webhook subscription identifier. They do not contain workout content, OAuth credentials, athlete identifiers, or activity identifiers and are configured to expire after 14 days.

Strava separately processes information under its Privacy Policy. Strava may monitor and collect usage data related to access to its API for purposes including operating and improving its platform, support, and compliance. TreadSimple does not control Strava’s copies of data the user uploads.

Reliability diagnostics and Sentry

TreadSimple uses Sentry to identify crashes and troubleshoot app reliability, compatibility, and security. A diagnostic event may include the app release and build, deployment environment, device platform and operating-system version, an error type and redacted error message, a stack trace, operation and failure codes, retry and outcome state, event duration, safe diagnostic breadcrumbs, and randomly generated installation and session identifiers. These identifiers are not derived from a name, email address, Strava account, advertising identifier, or hardware identifier. Only one-way hashes of these identifiers are sent to Sentry.

When an active workout receives no usable distance, speed, or incline for 15 seconds, TreadSimple automatically sends one compatibility event. It can contain up to three Treadmill Data notification samples, limited to the first 64 bytes of each packet, plus packet lengths and flags. These protocol samples can contain fitness measurements supplied by the treadmill and are used only to improve treadmill compatibility. They exclude the treadmill name and Bluetooth identifier and are not written to the local diagnostic history.

TreadSimple configures Sentry with default personal-information collection off, performance tracing off, session replay off, screenshots and view hierarchy off, and HTTP and user-interaction breadcrumbs off. Except for the narrowly bounded treadmill compatibility samples described above, redaction controls prohibit workout and health data, heart-rate values, workout files, raw Bluetooth packets, device names and identifiers, Strava athlete or activity identifiers, OAuth credentials, authorization headers, and request or response bodies from diagnostic events. Provider-side controls are configured to remove IP-derived and geographic fields. Diagnostics are used for app functionality and security only, not advertising, marketing, cross-app tracking, or behavioral analytics.

Sentry’s packaged Apple privacy manifest also declares crash, performance, and other diagnostic data. TreadSimple disables performance tracing but conservatively discloses limited operational durations and SDK performance metadata as Performance Data for App Store purposes.

Sentry acts as a service provider for TreadSimple under its customer and data-processing terms. Information about Sentry’s privacy practices is available in its Privacy Policy. Ordinary remote diagnostic events are configured for a 30-day retention period. The Sentry SDK may temporarily queue a limited number of unsent events on the iPhone while the device is offline. When a build has no Sentry configuration, remote diagnostic reporting remains off.

Connection support emails

Connection help is available from the treadmill and heart-rate pairing screens and from Settings > Diagnostics. If those steps do not solve the problem, the user can type a description and optional hardware make and model in TreadSimple. The app can add up to 12 recent privacy-safe diagnostic entries for that connection type and prepare an email to support@treadsimple.com. The user can review the message before sending it. Nothing is sent until the user taps Send in the email app. The automatically added diagnostics exclude device identifiers, workout and health values, credentials, and raw Bluetooth packets.

If the user sends an email or shares a report, the developer receives the sender’s email address, the contents the user chooses to provide, and ordinary email metadata. This information is used to answer the request, investigate the reported issue, protect the service, and meet legal obligations. Users should not include information that is not needed for support.

Optional enhanced hardware report

When troubleshooting an unsupported treadmill, TreadSimple temporarily keeps a bounded set of raw FTMS treadmill-data and machine-status packets in memory for no more than 15 minutes. These packets may encode speed, incline, distance, and a treadmill-reported heart-rate value. They are not written to the diagnostic cache or sent to Sentry. The capture excludes Bluetooth device names and identifiers, heart-rate-monitor packets, OAuth credentials, workout database records, FIT files, and Apple Health payloads.

The user must select Review and share report, review an itemized disclosure, and affirmatively choose I agree and share before TreadSimple creates the JSON report and opens the system share sheet. Canceling sends nothing. Packet memory is cleared after the share attempt, after 15 minutes, or when the user deletes all TreadSimple data. TreadSimple support deletes a received enhanced report within seven days. The report is used only to diagnose hardware compatibility.

What TreadSimple does not do

TreadSimple does not:

  • create a TreadSimple user account;
  • collect a name or email address through the app;
  • access contacts or photos;
  • collect geographic location;
  • display advertising or track users across other companies’ apps or websites;
  • sell personal information or consumer health data, or share personal information for cross-context behavioral advertising;
  • use health, fitness, or Strava data for advertising, marketing, data brokerage, or artificial-intelligence models; or
  • use reliability diagnostics for advertising, marketing, behavioral analytics, or user profiling.

Website

The TreadSimple website has no user account, form, advertising, analytics, cookie, remote font, or third-party script. Amazon Web Services processes the network request information needed to deliver and secure the site. TreadSimple has not enabled website access logging and does not use website request information for advertising or cross-site tracking.

Retention and deletion

The local database remains on the iPhone until it is deleted in TreadSimple or the app is removed. Because iOS Keychain items can survive an app reinstall, Settings > Privacy & Legal > Delete all TreadSimple data should be used to revoke and clear Strava credentials and delete the local workout database, discarded-workout allowance markers, samples, remembered devices, sync jobs, settings, local diagnostic history, and the anonymous installation identifier. Disconnecting Strava also revokes its token and removes local Strava-supplied identifiers and imported zone boundaries.

If revocation cannot reach Strava, the user should remove TreadSimple from Strava’s connected-app settings. Deleting local data does not delete workouts already sent to Apple Health or Strava; those copies must be managed in the destination service. AWS broker operational logs are configured to expire after 14 days. Sentry diagnostic events are configured to expire after 30 days. Support emails are kept only as long as reasonably needed to answer the request, maintain a support record, protect the service, and meet legal obligations. Enhanced hardware reports received by support are deleted within seven days. Sentry events already queued for delivery or transmitted are not deleted by the on-device action. Because diagnostic events are not associated with a TreadSimple account, a deletion request may require information sufficient to locate the relevant anonymous installation identifier.

Security and providers

TreadSimple uses the iOS app sandbox, Keychain, HealthKit authorization, TLS network connections, and narrow OAuth permissions. Amazon Web Services provides the stateless broker and operational logging. Sentry provides crash and reliability diagnostics. Strava receives data only when the user authorizes and uses that integration. The developer requires service providers that process data on TreadSimple’s behalf to protect it consistently with this policy and applicable law. Apple, Strava, and any other service the user chooses to send data to may also process that data as an independent provider under its own terms and privacy policy. No security measure can guarantee absolute security.

United States privacy rights

Depending on where the user lives and which law applies, the user may have the right to confirm whether TreadSimple collects, uses, or shares personal or consumer health data; access, correct, or delete that data; withdraw consent for certain collection or sharing; receive a portable copy; or appeal a refusal to act on a request. TreadSimple does not discriminate against a user for exercising an applicable privacy right.

Requests and appeals may be sent to privacy@treadsimple.com. The developer may ask for information reasonably necessary to verify the request and locate the relevant data. An authorized agent may submit a request where applicable law permits it, subject to verification of the agent’s authority. These rights do not apply to information that applicable law permits or requires the developer to retain. On-device information can be viewed and deleted with the controls described above.

Choices, children, and changes

Workout recording and local history work without a TreadSimple account and without connecting Strava or Apple Health. Automatic sync is off by default. Users can disconnect Strava in the app, manage Apple Health and Bluetooth permissions in iPhone Settings, and delete all local data in the app. Essential redacted diagnostics are enabled in distributed app releases; privacy questions and requests concerning retained Sentry events can be sent to the address below.

TreadSimple is not directed to children under 13 and does not knowingly collect personal information from a child under 13. A parent or guardian who believes a child has provided personal information may contact the privacy address below. Optional third-party integrations remain subject to each service’s age requirements and terms.

This policy may be updated when data practices change. Its effective date will be revised and material changes will be presented as required.

TreadSimple is operated by James Allen. Privacy questions or deletion requests can be sent to privacy@treadsimple.com. Because TreadSimple normally has no server-side user record, the developer may direct the user to the on-device or connected-service controls described above.

TreadSimple

Simple indoor workout recording for iPhone.

Home Terms & Safety Support