Privacy Policy
Stridient AI LTD (“Stridient AI”, “we”, “us”) provides the Stridient AI mobile application (the “App”), an AI-assisted running companion. This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and other applicable laws.
1. What we collect
Where it lives matters as much as what it is, so read this first. Almost everything below is recorded and kept on your phone: your runs, your routes, your heart rate, your photos and your music history are held on the device and in your own iCloud backup if you use one. Two things can change that, and only if you switch them on — the coaching chat, and run sharing for challenges and leaderboards (see 4A). Your route never leaves the device either way. Section 4A names every service of ours that receives anything at all, and what each one gets. This section describes what the app collects; it does not mean we hold a copy.
1.1 Personal information
- Email address — used to create your account and send essential service notices. Required only if you choose to sign in.
- Name — optional. Provided by you or relayed from your sign-in provider if you grant it.
1.2 Health & fitness data — on your device
- Heart rate
- Distance
- Pace
- Cadence
- Calories
- Route GPS data (the geographic trace of your run)
1.3 Location — on your device
- Real-time GPS while a run is active, used to record your route, calculate pace and distance, and power live audio/coaching features. Background location is only used while you have an active run.
1.4 User content
- Route names you create
- Run notes you write
- Photos you choose to attach to or share from a run
1.5 Identifiers
- Apple ID hash — opaque user identifier returned by Sign in with Apple
- Spotify user ID
- Google user ID
- Strava user ID
- Garmin user ID
- Per-provider OAuth access & refresh tokens, stored in the iOS Keychain on your device — not on our servers — and used solely to call the third-party APIs you have authorized.
1.6 Usage data
Stridient AI uses no third-party analytics at all — not by default, and not as an option. There is no analytics SDK in the app.
There is a diagnostics setting in Settings → Privacy, and it is off unless you turn it on. What it does is narrower than it sounds: it lets the app read the performance and crash reports iOS already produces about it, on the device. None of it is transmitted anywhere, to us or to anybody else. If that changes, this paragraph changes with it.
2. How we use your data
- Provide core run-tracking, mapping, coaching and AI features.
- Authenticate you via your chosen sign-in provider.
- Sync activities to/from the third-party services you have connected.
- Send you essential service messages (security, account, legal).
- Diagnose crashes — crash and performance reports are kept on your phone if you opt in. They are never transmitted — there is no route in the app that sends them, and switching the setting off deletes the copy already held.
We do not use your health, fitness, route or location data for advertising. We do not sell or “share” personal information as defined under CPRA.
3. Legal bases (GDPR/UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the App and processing runs you record | Performance of a contract |
| Health & fitness, route GPS, photos | Explicit consent (Art. 9(2)(a) for health data) |
| Connecting Apple / Spotify / Google / Strava / Garmin | Consent — granted via the provider’s OAuth screen |
| Service messages, fraud prevention, legal compliance | Legitimate interests / Legal obligation |
4. Third parties and what we share with each
| Provider | Purpose | Data shared with them | Data we receive |
|---|---|---|---|
| Apple — Sign in with Apple | Authentication | Auth request only (no Stridient AI data is sent) | Apple ID hash (opaque), optional relayed email, optional name |
| Spotify | Music control during runs; show currently-playing track | OAuth token; playback control commands you initiate | Spotify user ID, current playback state |
| Sign-in | OAuth token | Google user ID, profile email/name | |
| Strava | Activity import/export per scopes you grant | OAuth token, and a summary of each run you choose to upload: its name, type, start time, duration and distance, plus a short text description. No route, no GPS point and no heart rate is sent to Strava — if you want a map on your Strava activity, record it with Strava itself. | Strava user ID, profile, activities you authorise us to read |
| Garmin (Garmin Connect) | Activity import per scopes you grant | OAuth token | Garmin user ID, activities, heart rate and route data per scopes you grant |
| YouTube Music (YouTube Data API) | Read your playlists so the app can match tracks to your cadence and heart-rate zone | OAuth token; read requests you initiate | Your playlist names and the tracks in playlists you choose. Held on your device; refreshed on each use; never written back to YouTube |
Each provider processes data under its own privacy policy. You can revoke any connection in Stridient AI under Settings → Connections, or directly in the provider’s account dashboard.
We also use the following operational sub-processors strictly for hosting and infrastructure: cloud hosting and database providers under signed Data Processing Agreements. They process data only on our instructions and never for their own purposes. A current sub-processor list is available on request from info@stridientai.com.
4A. Our own servers
Stridient AI operates a small number of first-party services, and every one of them is named in the table below. One of them holds an account for you, if you choose to sign in. None of them ever receives your routes or your location — that is true of every feature, without exception. Two features can send something about your runs, and both are off until you turn them on: the coaching assistant, and sharing your runs so you can take part in challenges, leaderboards and races.
You can also continue as a guest and give us nothing at all. A guest never contacts our server, and everything on this page about accounts simply does not apply.
| Service | What it is for | What it receives | Default |
|---|---|---|---|
| Accounts | Signing in, so your profile and settings follow you to a new phone instead of being lost with the old one | Your email address, and your password stored only as a slow one-way hash — we cannot tell you what your password is, because we do not know it. A record of each signed-in device, so you can end a session you no longer recognise. If you use the community features, the handle you choose, the runners you connect to, and anyone you block or report. If you switch on run sharing, it also holds a summary of each run — duration, distance, pace, cadence, cadence steadiness and time in your target zone — and, if you agreed to that separately, your average and maximum heart rate for that run — the maximum is what the average is measured against, so effort boards can rank you as a share of your own maximum rather than against other people. It holds the clubs and challenges you are in, the days you marked as rest days, and your time zone. During a live race it briefly holds how far you have run. It never receives your route or your location. | Only if you choose to sign in. Everything else in the app works without an account |
| Tempo index | Looking up the tempo of a recording so your music can match your cadence | The ISRC (a recording’s industry identifier) when a tempo is looked up. If you agree when asked, also the ISRC, tempo and steadiness of a measurement your phone made. We keep a salted, keyed hash of your IP address for rate limiting, erased after 30 days. | Lookups on; contributing measurements requires your explicit agreement |
| Sign-in helper | Connecting Strava or WHOOP without shipping our credentials for those services inside the app | The one-time code that service gives you, which it exchanges for an access token. The token is then stored on your device, not by us. Runs on Cloudflare Workers, separately from the tempo index. | Only used when you connect Strava or WHOOP |
| Coaching assistant | The optional AI coaching chat | One of two features that can send your running data off the device — the other is run sharing. Your message and the conversation so far; a summary of your last 8 qualifying runs — how many days ago, distance, duration, pace, target zone, cadence steadiness and, where recorded, your average heart rate; and a random identifier for your installation, kept so the conversation holds together, which survives reinstalling. No GPS route, no map and no photos are ever sent. | Off. It sends nothing at all unless you turn it on. Every other feature works without it. |
Sharing your runs — off unless you turn it on
Challenges and leaderboards compare your runs with people you have connected to, and that needs a summary of each run to reach our server. It is off by default, it lives in the App under Settings → Sharing Your Runs, and every other feature works without it.
What is sent: how long you ran and how far, your average pace and cadence, how steady your rhythm was, and the time you spent in your target zone along with which zone that was. What is never sent: your route, any GPS point at all, your photos, or what you listened to.
Your heart rate is asked for separately, and stays off even when run sharing is on unless you agree to that too. We ask separately because heart rate is health data and the law treats it differently: under UK and EU data protection law it is “special category” data, which requires your explicit consent rather than being folded into a general permission. It also comes from Apple Health, which carries its own conditions.
Stopping deletes. Turning sharing off removes the summaries already uploaded rather than leaving them in place. Turning off only heart rate strips the heart rate from runs already sent and keeps the rest.
Every service that can send anything to us is named above, with what it sends and whether it is on. Tempo lookups are on by default and send only a recording identifier — never anything about you or your run. Your ROUTE is never stored against your account, by any feature. Run summaries are, but only if you switch on run sharing, and your heart rate only if you then agree to that separately as well. The three things that involve your own running data — contributing a tempo your phone measured, the coaching chat, and sharing your runs — never happen unless you agree. If you would rather your heart rate never left the device, leave the coaching chat off and leave heart rate off under run sharing.
4B. Google and YouTube API Services
Stridient AI uses YouTube API Services. By connecting YouTube Music you agree to be bound by the YouTube Terms of Service, and Google’s Privacy Policy applies to Google’s handling of your data.
Stridient AI’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: YouTube data is used only to provide the music-matching feature you asked for, is never used for advertising, never sold, and never read by humans except with your consent, for security, or as required by law.
Playlist data retrieved from YouTube is stored only on your device and is refreshed each time you use the feature; it is not retained for more than 30 days without being refreshed. You can revoke Stridient AI’s access at any time in the app under Settings → Connections, or via your Google security settings, which removes the token from your device.
5. International transfers
Where personal data leaves the UK/EEA, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) together with supplementary technical and organisational measures.
6. Retention
| Data | Retention |
|---|---|
| Account & identifiers | Until you delete your account |
| Runs, routes, health & fitness data, photos | Held on your device, not by us. Until you delete the item, or use Delete All My Data |
| Shared run summaries (only if you turn sharing on) | Until you turn sharing off, which deletes them |
| OAuth tokens | Until you disconnect the integration or delete your account |
| Crash & performance reports (opt-in) | Kept on your phone until you turn diagnostics off, which deletes them |
| Backups | Up to 30 days after deletion, then irreversibly purged |
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict or object to processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your supervisory authority (e.g. the UK ICO at ico.org.uk) or, in the EEA, your local DPA
To exercise any right, email info@stridientai.com. We respond within 30 days.
Deleting your data, precisely. Settings → Privacy & Data Rights in the App offers two things. Export My Data gives you a machine-readable copy of everything held on the device. Delete All My Data now deletes both: your account on our server, and everything on the device.
What goes immediately: your email address, password, sessions, the device record, your handle, your connections, your invites, the blocks you placed, shared sessions, and any run summaries including heart rate. Your handle is released rather than destroyed, and sits unusable for 30 days so nobody can take your name the moment you leave.
Two things deliberately survive, and it is fair to know why. Blocks placed against you stay — a block is someone else’s decision about their own safety, and deleting your account must not quietly undo their refusal. And moderation reports are kept for 12 months, then permanently deleted. We keep them because otherwise deleting an account would be the way to erase a record of harming someone; we do not keep them indefinitely, because that would be retention without a limit.
If the deletion cannot reach our server — no signal, for instance — nothing is erased at all and the App tells you so, rather than wiping your phone and leaving the account behind.
8. Security
We protect your data with TLS in transit, encryption at rest for credentials and tokens, role-based access control, audit logging, and the principle of least privilege. No system is 100% secure, but we work to follow industry best practice and to notify you and regulators of any qualifying breach within the legally required timeframes.
9. Children
The App is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact info@stridientai.com and we will delete it.
10. Changes to this policy
We will update this page when our practices change and will revise the “Effective date” above. Material changes will also be notified in-app or by email where appropriate.
11. Contact
Stridient AI LTD
Email: info@stridientai.com
