🏃the corral

Privacy Policy

Effective: July 10, 2026 · Who we are: The Corral is made by Sand Collective LLC (“we”). Contact: support@thecorral.app

The short version: we collect the minimum needed to run a race-logging app with a small social layer. No ads, no trackers, no analytics SDKs, no selling data — ever.

What we collect

Account. Two ways in, both password-free. With Sign in with Apple we receive a stable anonymous identifier (your Apple “user” ID for our app); Apple also shares your name and email on first sign-in, and only if you allow it — we store the email so you can sign back into the same account by email later. With email sign-in we store your email address and use it for sign-in: sending you 6-digit codes and matching you to your existing account. You can also attach an email to an Apple-created account. We never see a password and never use your email for marketing.

Your public profile. Display name, avatar emoji, location (free text you type — share as much or as little as you like), and bio. These are visible to other runners in the app.

Race reviews. When you rate a race, we store your scores, optional written note, race date, optional finish time, and Boston-qualifier flag. If you log a race that isn't in our catalog, we also store the race name you type, and we screen it before it can appear to other runners (see Moderation). Reviews power community averages, and your written note may appear in followers' feeds.

Apple Health (optional). If you connect Apple Health, The Corral reads your recent running workouts on your device to: match a finished race you've bookmarked and fill in its date and finish time; show your training summary (weekly mileage, longest run, recent pace); and, for a race you've logged, draw your route map and per-mile splits. This includes your workout route (location). It is read-only — we never write anything back to Apple Health. By default, your workout and route data stay on your device: they're read live, shown only to you, and never uploaded to our servers. The only data saved by default is the race result you confirm — the same finish time you could enter by hand — which then follows the “Race reviews” rules above. The one exception is when you explicitly choose to share a run, described next.

Shared runs (optional). Every finished race in your log has a Share toggle, and it is off by default. When you turn it on for a race, we upload that run's GPS route, per-mile splits, distance, finish time, and the name of the source app the workout came from (for example “Apple Watch”), and we show them on your profile. Who can see a shared run follows your race-history privacy setting (Profile → Settings → Privacy: Just Me, Mutuals, or Everyone) and never includes anyone you have blocked. You can unshare any run at any time by turning its toggle off, which hides it from other runners.

Social activity. Who you follow, your friend code, goal titles you share, races you mark as registered (“going”), race-wall posts and replies you write, cheers (🙌) you give and receive, and reports or blocks you submit. Your profile's follower, following, and cheer counts each have their own visibility setting (Profile → Settings → Privacy: Just Me, Mutuals, or Everyone).

Goals. The running goals you set — their titles, icons, and your progress and completion — are stored so your profile can show them. Who can see your goals follows your Goals privacy setting (Profile → Settings → Privacy: Just Me, Mutuals, or Everyone).

Causes & charities (optional). When you dedicate a race to a charity, we store the charity's name (and, if you pick it from our suggestions, its website) plus a cause category you choose, and — if you add them — a short note and a personal fundraiser link. This powers a shared space for everyone running that race for the same charity, and your profile and the race's page show what you're running for. The charity name, note, and links are text you type, and we screen them before they're saved (see Moderation). Who can see your charity flair follows your Cause flair privacy setting (Profile → Settings → Privacy: Just Me, Mutuals, or Everyone) and never includes anyone you've blocked.

Device identifier. A random ID created on install, used to de-duplicate reviews and link them to your account when you sign in. It is not your hardware ID and resets if a different account signs in on the device.

Corral Club subscription (optional). Payment runs entirely through Apple — we never see your card. To know whether your membership is active, our subscription manager (RevenueCat) receives your App Store purchase receipt and your random account id — never your name or email.

Push notifications (optional). If you turn on notifications, we store a push token for your device so Apple's notification service can deliver alerts — new followers, follow requests, cheers, and race-wall activity. Each category has its own toggle in the app, and the token is deleted when you sign out or delete your account.

Race news. We curate occasional racing headlines — like race-weekend spotlights — that appear as cards in your feed. Opening one takes you to that race's page in the app or, for outside stories, to the organizer's or publisher's website in your browser; we don't track what you read.

What never leaves your phone

Date of birth and gender (used only to compute Boston-qualifying standards locally), your full race log, bookmarks, and pace/splits targets. These are stored on your device only. Workouts read from Apple Health also stay on your device, unless you opt to share a specific run — see “Apple Health” and “Shared runs” above.

The home- and lock-screen widgets (race countdown, bibs, pace bands) read this local data through a private App Group container on your device, and the pace-band wallpaper you save goes straight to your Photos library — none of it is uploaded. If you browse as a guest without signing in, everything you do stays on your device; nothing is sent to our servers until you create an account, and your local data is kept if you sign in later.

What we don't do

No advertising, no third-party analytics, no tracking across apps or websites, no data sales, no profiling. The app contains no ad or analytics SDKs.

Service providers

Your data is processed by the infrastructure we run on: Vercel (API hosting), Railway (database), Cloudflare (network routing), Ably (delivering realtime feed and race-wall updates), Resend (sending sign-in code emails), Upstash (request rate-limiting), and RevenueCat (Corral Club subscription status — see above). Race Finder quiz answers (distance, region, vibe preferences) are processed by Anthropic's Claude API to generate recommendations; they are race preferences, not linked to your profile. Anthropic's API also screens public text you submit — posts, review notes, custom race names, charity flair — for safety before it can appear to other runners.

Retention & deletion

Your data is kept while your account is active. You can delete your account in the app (Profile → Settings → Delete Account): this permanently removes your profile, follows, activities, cheers, reviews, race-wall posts and replies, shared runs, cause flair, goals, notifications, and push tokens from our servers, revokes our connection to your Apple ID, and clears local data on the device. Community averages may continue to reflect previously aggregated, non-identifiable statistics.

Moderation

You can report any post, reply, shared run, goal, charity flair, or runner, and block other users in the app. New reports alert our moderation team right away (the alert carries only a count — never the reported content or who reported it), and we review reports within 24 hours and remove content or accounts that violate our Terms of Use.

Children

The Corral is not directed at children under 13, and you must be at least 13 to create an account.

Changes

If this policy changes materially we'll note it here with a new effective date.

Questions? support@thecorral.app