StridePrivacy Policy
Stride records precise location, which is the most sensitive category of data in this app. This policy is specific about when it is collected, what it is used for, and who can see it.
The short version
Stride collects precise location only while you have a run recording, and uses it for one thing: drawing and measuring that run. It is never collected when you are not recording, never sold, and never shared with anyone except the friends you choose to share a run with.
Who we are
Stride is operated by Divyansh Karan, trading as Stelr Studio (Remote · India), the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.
Location data — the important part
When it is collected: only while a run is actively recording. Starting a run begins collection; finishing or discarding it ends collection. Stride does not sample your location in the background at any other time.
Why background permission is needed: so that a run keeps recording accurately when your screen is off or you switch apps mid-run. Without it, the route breaks up into a useless fragment. This is the only reason it is requested.
What is stored: the sequence of coordinates and timestamps that make up the route of a run you saved, plus the distance, pace and splits derived from it. Discarded runs are not stored.
What is not done: no location collection outside a recording run, no background fetch (the only declared background mode is location), no advertising or profiling use, no sale, and no sharing with data brokers.
A note on route privacy: a run that starts and ends at your front door reveals where you live. Consider that before sharing a run with people you do not know well.
Account information
| Data | Why | Required |
|---|---|---|
| Email address | To create your account, sign you in and send password resets | Yes |
| Password | Stored only as a salted hash by our authentication provider — we never see it | Yes |
| Display name | Shown to you and to friends you connect with | Yes |
| Profile photo | Shown on your profile and to friends | Optional |
Health and fitness data
This is the core of the app, and it is generated by runs you record:
This is health and fitness information. We treat it as sensitive: it is used only to show you your own training and, where you choose, to share a run with friends.
- Route coordinates and timestamps for each saved run
- Distance, duration, pace, splits and elevation derived from them
- Run history, personal records and the analytics computed from them
What we never collect
None of the following is collected, by design:
- Advertising identifiers, or any data used for advertising or profiling
- Contacts, calendar, SMS or call logs
- Data bought from, or shared with, data brokers
- Any cross-app or cross-site tracking
Permissions
| Permission | Why |
|---|---|
| Location (when in use) | Recording the route of a run. Required for the app's core function. |
| Location (background / always) | Keeping a run recording accurately when the screen is off. Only active during a run. |
| Foreground service (location) | Android's requirement for a recording that continues with the app in the background. |
| Camera | Optional — taking a profile photo. |
| Photo library | Optional — choosing a profile photo. |
| Notifications | Optional — the alerts you turn on. |
Legal bases for processing (GDPR)
If you are in the UK or EEA:
- Contract — your account and the runs you record.
- Consent — location access, camera, photo library and notifications. Withdraw any of them at any time in your device settings; the rest of the app continues to work, though run recording requires location.
- Legitimate interests — keeping the service secure and working.
Where your data is stored
Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.
How long we keep it
- While your account exists — as long as you keep it. Delete an individual run at any time and its route is removed with it.
- When you delete your account — your profile, runs, routes and social connections are permanently deleted.
- Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.
Security
The protections actually in place:
No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.
- All traffic between the app and our servers uses HTTPS/TLS.
- Passwords are stored only as a salted hash by the authentication provider — we never see them.
- Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
- Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
- Sign-in uses the PKCE authorization-code flow.
- Profile photos are stored in a private bucket and served only through short-lived signed links.
- Deep links use verified App Links, so no other site can claim to represent the app.
Your rights
Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.
To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.
- Access — everything we hold is visible inside the app.
- Correct — edit any entry or profile field directly.
- Export — request a machine-readable copy of your data.
- Delete — delete individual runs, or your whole account, from inside the app.
- Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
- Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).
Deleting your account
Profile → Account → Delete account. This permanently erases your profile, every run and its route data, your personal records and your social connections.
If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.
Children
Stride is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.
Changes to this policy
If this policy changes, the updated version ships with the Stride release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.
Contact
Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).
This policy covers Stride only. Other Stelr apps have their own policies, listed on the apps page.
Social data
Only if you use the social features: