Privacy Policy
Last Updated: August 2026
This Privacy Policy describes how Rowly ("we", "our", or "us") collects,
uses, and protects your information when you use our mobile application
(the "App").
1. Information We Collect
1.1 Location Data
The App collects GPS location data to track your rowing sessions,
calculate distance, speed, and pace. This data is collected:
- During active rowing sessions
- In the background when a session is running
-
At regular intervals (typically 1 second) during active sessions
Location data includes latitude, longitude, altitude, speed, and heading
information provided by your device's GPS.
1.2 Motion Sensor Data
The App accesses your device's accelerometer and gyroscope to:
- Detect rowing strokes
- Calculate stroke rate
- Measure boat stability
- Analyze rowing technique
1.3 Session Data
The App stores information about your rowing sessions locally on your
device, including:
- Session start and end times
- Total distance traveled
- Average and current pace
- Stroke rate and stroke count
- GPS track data
- Calculated metrics (efficiency, consistency, stability)
1.4 Analytics Data
To help improve the App, we collect anonymous usage data including:
- App usage events (session started, paused, completed)
- Screen views
- App version and platform information
- Device type and operating system
This data is anonymous and does not include personal information, GPS
locations, or session details. You can disable analytics collection in
the App settings at any time.
1.5 Error Reporting
The App uses Sentry to collect crash reports and error information to
help improve app stability. This includes:
- Error messages and stack traces
- Device information (model, OS version)
- App version information
This data is anonymized and does not include personal information or
location data.
1.6 Health and Heart Rate Data
If you choose to use a heart rate source, the App collects heart rate
data during your rowing sessions. You control this entirely: no heart
rate source is active until you select one in the App's settings, and
each source asks for your permission before any data is accessed.
Rowly supports three heart rate sources:
-
Apple Health (iOS): with your permission, the App
reads heart rate samples. If you have the Rowly app installed on a
paired Apple Watch, starting a session in Rowly starts a workout on
the watch so heart rate can be measured continuously, and the watch
streams those readings to your iPhone. When the session ends, the
watch saves the completed rowing workout (including heart rate) to
Apple Health on your device.
-
Health Connect (Android): with your permission, the
App reads heart rate and workout data.
-
Bluetooth heart rate monitors: the App connects
directly to a chest strap or similar Bluetooth Low Energy monitor you
pair with it. Readings are received over Bluetooth and are not sent
to us.
Heart rate readings are stored on your device alongside the rest of your
session data, and are used to display your live heart rate, to record
heart rate against individual strokes, and to show heart rate zones and
charts when you review a session.
We never receive your health data. It is not
transmitted to our servers, and it is never used for advertising or
marketing, sold, or shared with data brokers. Health data is excluded
from the anonymous analytics described in section 1.4 and from the error
reports described in section 1.5.
The one case in which health data leaves your device is when
you choose to send it somewhere: if you connect your
Strava account and upload a session, or export a session file and share
it, the exported activity includes your heart rate readings. See section
3.3 and section 4.
2. How We Use Your Information
We use the collected information to:
-
Provide core app functionality (tracking rowing sessions, calculating
metrics)
- Display your session history and statistics
-
Show your live heart rate, heart rate zones and per-stroke heart rate,
where you have enabled a heart rate source
- Improve app performance and fix bugs
- Understand how the app is used (with your consent)
- Respond to support requests and feedback
3. Data Storage
3.1 Local Storage
All session data — including GPS tracks, stroke data and any heart rate
readings — is stored locally on your device using the Drift database
(SQLite). This data never leaves your device unless you explicitly
export it, share it, or upload it to a connected service such as Strava.
3.2 Subscription Data
If you subscribe to Rowly Premium, we process subscription information through RevenueCat, our payment processor. This includes:
- Anonymous user identifier (not linked to personal information)
- Subscription status and type
- Purchase history and transaction identifiers
- Subscription expiration dates
Payment processing is handled entirely by Apple (App Store) or Google (Play Store). We do not receive or store your payment card details.
3.3 Third-Party Services
We use the following third-party services that may process your data:
-
RevenueCat: Used to manage in-app purchases and subscriptions.
Their privacy policy:
https://www.revenuecat.com/privacy
-
PostHog: Used for optional analytics (only if you
consent). Their privacy policy:
https://posthog.com/privacy
-
Sentry: Used for error tracking and crash reporting.
Their privacy policy:
https://sentry.io/privacy/
-
Strava: Optional, and only if you connect your Strava
account. When you upload a session, the App sends that activity to
Strava on your behalf. The uploaded activity file contains your GPS
track, timing and distance, and — if the session recorded them —
your heart rate readings. Nothing is sent to Strava
unless you connect the account and upload a session; you can
disconnect at any time in the App's settings. Their privacy policy:
https://www.strava.com/legal/privacy
4. Data Sharing
We do not sell, trade, or rent your personal information to third
parties. We only share data:
-
With third-party service providers (RevenueCat, PostHog, Sentry) as
described above
- When required by law or to protect our rights
-
If you explicitly choose to share session data — for example by
exporting a session file, or by connecting your Strava account and
uploading an activity. Where the session recorded heart rate, that
heart rate data is included in what you share or upload
We do not share your health data with any third party on our own
initiative, and we never use it for advertising or marketing purposes.
5. Your Rights
You have the right to:
-
Access your data: All your session data is stored
locally and accessible through the App
-
Delete your data: You can delete individual sessions
or all data through the App settings
-
Opt-out of analytics: Disable analytics collection in
the App settings at any time
-
Control health data: Choose whether to use a heart
rate source at all, and revoke the App's access at any time — on iOS
in Settings › Health › Data Access & Devices, on
Android in Health Connect, or by disconnecting your Bluetooth monitor.
Heart rate stored with a session is deleted when you delete that
session
-
Disconnect Strava: Revoke the App's access to your
Strava account at any time in the App settings
-
Request data deletion: Contact us to request deletion
of any data stored with third-party services
6. Data Security
We implement appropriate technical measures to protect your data:
- All session data is stored locally on your device
- Data transmitted to third-party services is encrypted
-
Analytics data is anonymized and does not include personal identifiers
7. Children's Privacy
The App is not intended for children under the age of 13. We do not
knowingly collect personal information from children under 13.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you
of any changes by updating the "Last Updated" date at the top of this
policy. You are advised to review this Privacy Policy periodically for
any changes.
9. Contact Us
10. Consent
By using the App, you consent to this Privacy Policy. If you do not
agree with this policy, please do not use the App.