← Back to StridePrivacy policy

StridePrivacy Policy

Last updated Account-based · precise location, narrowly scoped

Stride records precise location, which is the most sensitive category of data in this app. This policy is specific about when it is collected, what it is used for, and who can see it.

The short version

Stride collects precise location only while you have a run recording, and uses it for one thing: drawing and measuring that run. It is never collected when you are not recording, never sold, and never shared with anyone except the friends you choose to share a run with.

Who we are

Stride is operated by Divyansh Karan, trading as Stelr Studio (Remote · India), the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.

Location data — the important part

When it is collected: only while a run is actively recording. Starting a run begins collection; finishing or discarding it ends collection. Stride does not sample your location in the background at any other time.

Why background permission is needed: so that a run keeps recording accurately when your screen is off or you switch apps mid-run. Without it, the route breaks up into a useless fragment. This is the only reason it is requested.

What is stored: the sequence of coordinates and timestamps that make up the route of a run you saved, plus the distance, pace and splits derived from it. Discarded runs are not stored.

What is not done: no location collection outside a recording run, no background fetch (the only declared background mode is location), no advertising or profiling use, no sale, and no sharing with data brokers.

A note on route privacy: a run that starts and ends at your front door reveals where you live. Consider that before sharing a run with people you do not know well.

Account information

DataWhyRequired
Email addressTo create your account, sign you in and send password resetsYes
PasswordStored only as a salted hash by our authentication provider — we never see itYes
Display nameShown to you and to friends you connect withYes
Profile photoShown on your profile and to friendsOptional

Health and fitness data

This is the core of the app, and it is generated by runs you record:

This is health and fitness information. We treat it as sensitive: it is used only to show you your own training and, where you choose, to share a run with friends.

  • Route coordinates and timestamps for each saved run
  • Distance, duration, pace, splits and elevation derived from them
  • Run history, personal records and the analytics computed from them

Social data

Only if you use the social features:

  • Friend connections — which accounts you follow and which follow you
  • Runs you have shared, and who can see them

What we never collect

None of the following is collected, by design:

  • Advertising identifiers, or any data used for advertising or profiling
  • Contacts, calendar, SMS or call logs
  • Data bought from, or shared with, data brokers
  • Any cross-app or cross-site tracking

Permissions

PermissionWhy
Location (when in use)Recording the route of a run. Required for the app's core function.
Location (background / always)Keeping a run recording accurately when the screen is off. Only active during a run.
Foreground service (location)Android's requirement for a recording that continues with the app in the background.
CameraOptional — taking a profile photo.
Photo libraryOptional — choosing a profile photo.
NotificationsOptional — the alerts you turn on.

Who we share data with

We use these processors, and share your data with no one else except where legally required.

ProcessorWhat it handlesTheir policy
SupabaseDatabase, authentication and file storage — account, run and social datasupabase.com/privacy
MapboxMap rendering. Receives map tile requests from your device to draw the map.mapbox.com/legal/privacy
Expo / EASApp builds and updates. No personal data.expo.dev/privacy

Where your data is stored

Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.

How long we keep it

  • While your account exists — as long as you keep it. Delete an individual run at any time and its route is removed with it.
  • When you delete your account — your profile, runs, routes and social connections are permanently deleted.
  • Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.

Security

The protections actually in place:

No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.

  • All traffic between the app and our servers uses HTTPS/TLS.
  • Passwords are stored only as a salted hash by the authentication provider — we never see them.
  • Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
  • Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
  • Sign-in uses the PKCE authorization-code flow.
  • Profile photos are stored in a private bucket and served only through short-lived signed links.
  • Deep links use verified App Links, so no other site can claim to represent the app.

Your rights

Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.

To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.

  • Access — everything we hold is visible inside the app.
  • Correct — edit any entry or profile field directly.
  • Export — request a machine-readable copy of your data.
  • Delete — delete individual runs, or your whole account, from inside the app.
  • Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
  • Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).

Deleting your account

Profile → Account → Delete account. This permanently erases your profile, every run and its route data, your personal records and your social connections.

If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.

Children

Stride is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.

Changes to this policy

If this policy changes, the updated version ships with the Stride release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.

Contact

Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).

This policy covers Stride only. Other Stelr apps have their own policies, listed on the apps page.