← Back to the game
🏃Turf Runner · Legal

Privacy Policy

Last updated: 24 Sep 2026

Turf Runner is a running game. You sign in with Google, hand us the track files your watch or phone already saves, and your real runs get mapped onto a virtual “turf” map. We don’t sell your personal data. Everything we store exists to make the game work.

What we collect

From your account (the sign-in you choose): your name and photo, so other players can see who they’re up against.

From your Google sign-in: the account id Google gives us and the verified email address on it. We never see your password, and there is nothing else to hand over — no phone number, no payment details.

A record of your choices: which version of this policy you acknowledged and when, plus the two privacy switches below. That record is what lets us answer “what did this runner agree to?” — a note in your browser could not.

From the runs you add (a track file you export yourself — we never connect to, or read, any running app or account):

  • your run activities: route (GPS track), distance, time, start date, and the name you gave the run.

What the game derives from your runs: which turfs you crossed, your turf scores, leaderboard positions, king titles, streaks, and personal records.

From the connection: the host in front of the app tells us the country a visit comes from, and the login page uses it for one line — whether anyone has claimed turf where you are. It is a country, never an address or a coordinate; it is not stored, and it is not attached to your account. We never ask your browser for your location.

Why we’re allowed to keep it

  • To run the game — your account, your runs, your scores and the boards: this is the service you asked us for.
  • To keep the shared map standing after you leave — turf tiles and leaderboard history, with nothing naming you: a world that survives its players is what makes the game worth playing, and you can erase everything that identifies you at any time.
  • To show your name, photo and routes to other players: your consent — that is what the card on your first visit asks for, and both switches stay in your hands.
  • To fix crashes — error reports, so the app keeps working.

We don’t use your data for advertising or profiling, we don’t make automated decisions about you, and we never sell it.

What is public by default

This is a competitive map game, so game state is public:

  • Your name and photo appear on turf leaderboards, king lists, and runner profiles — and your name in the live event feed — unless you turn on Anonymous mode (profile menu), which swaps your name for a stable random alias and hides your photo.
  • The routes you run are visible to other players on the map — unless you turn on Private routes, which hides the exact route (the turfs you crossed remain visible, since that’s the game).

You can flip either setting at any time from the profile menu.

The app puts all of this in front of you — what we keep, who can see it, and both switches — the first time you play, and records which version you acknowledged. When this policy changes in a way that matters, that same card comes back on your next visit.

Data promises

  • We don’t sell or rent your data to third parties.
  • We only ever process your running data (rides/swims are ignored; we only process runs with GPS routes).
  • If we ever add features that need payment, advertising, or extra data (for example to cover hosting costs), we’ll update this policy first — which means the card comes back on your next visit, before anything turns on.

Third-party services we rely on

  • Google — sign-in. We verify the token Google issues; we never see your password.
  • Supabase — hosts our database (your profile + game data).
  • Vercel — hosts the app itself and provides cookieless, aggregate page-view analytics (which pages are visited — never tied to your account).
  • OpenFreeMap — serves the map tiles (OpenStreetMap data), including the readable place names turfs are named from.
  • OpenStreetMap's geocoder (Nominatim) — asked which country a patch of ground belongs to, and only when the map data we already hold cannot say (a small island, reclaimed land). What we send is the position of that patch of ground — never your route, never your account.
  • Open-Meteo — weather and air-quality numbers for the map (no account, no identifiers).
  • Push notifications — sent by us, straight to your browser's own push service (Apple's, Google's, Mozilla's — whichever your browser uses), and only if you turn them on. We store the subscription your browser creates (an address plus two encryption keys, tied to your account) and nothing else. No notification vendor sits in the middle.
  • Sentry and Discord — receive crash reports so we can fix bugs. They see the error, your browser type and the page you were on — never your runs or your routes.

Each processes only what’s needed for that function. We don’t pass your data to any of them for their own purposes.

Our own app and database run in Singapore. The services above are run by companies in the EU, the UK and the US; where data leaves your country we rely on those providers’ own safeguards for international transfers. Crash reports are not linked to your account — we don’t attach who you are to an error.

Your rights & controls

  • Anonymous mode / Private routes — per-account toggles in the profile menu.
  • Ask for a copy — email us and we’ll send everything tied to your account in one machine-readable file: profile, runs and routes, scores, titles, follows, nudges, reactions, planned runs, push subscriptions.
  • Correct it — your name and photo are yours to change in the app; anything else, ask us.
  • Restrict or object — Anonymous mode and Private routes are the “stop showing me” switches, and deleting your data is the full version.
  • Delete my data — right in the app, no email needed: profile menu → “Delete my data” (two taps to confirm). This removes your profile, runs, scores and turf claims, and anonymizes your feed lines. It can’t be undone — the activities themselves stay safe where you recorded them (on your watch, or in the app that made the file). If you’d ever rather ask a human: keyang.lew@gmail.com.

We answer within a month, and we may ask you to confirm it’s you (by signing in, or replying from the email on the account). We can’t act on a request about somebody else’s account — that privacy is theirs.

Data retention

  • Your account and game data are kept while you’re an active player.
  • Deleting your data removes your profile, runs and routes, scores, crowns, follows, nudges, reactions, planned runs, push subscriptions and your uploaded photo straight away. Share links you created stop working.
  • What stays: turf tiles and leaderboard positions with no account attached — the shared map — and live-feed lines whose name becomes “Runner (deleted)”.
  • Error reports (the page, your browser type, the error text — never your runs) are held briefly by our error-tracking providers and expire on their own retention settings. Our database host keeps its own short-term backups, which we can’t edit row by row; a deleted account ages out of them.

Children

Turf Runner isn’t for children: you need to be at least 13, and older where local law says so. We don’t ask for a date of birth, and we don’t knowingly keep a child’s data — if you believe a child has an account here, write to us and we’ll delete it.

Changes

We record which version of this policy you acknowledged. When a change matters — a new kind of data, a new public surface, a new service behind the scenes, or a different retention period — the version moves and the card comes back on your next visit, so you see it before you keep playing. Wording fixes don’t re-ask, because a card that reappears for nothing stops being read. The date at the top of this page is the one your acknowledgement names.