Stride Privacy Policy
Last updated: 9 October 2026
Stride is a running tracker with an optional weekly league, published by Clearpoint Studios. This policy explains what the app records, what leaves your phone, and what it does with any of it.
Contact: clearpointstudios@proton.me
The short version
Your GPS track never leaves your device. Stride records your route locally so it can draw the map, calculate splits and show the route image, and that recording stays in the app's private storage on your phone. The league receives numbers about a run, never a position and never a route.
Everything social is opt in. Without a runner handle, Stride works as an offline tracker and sends nothing about your running to us at all.
There are no ads, no advertising identifiers, no ad networks and no third party analytics SDK in the app. The few anonymous events we collect ourselves are listed under Anonymous usage events. We do not sell data and we do not share it with data brokers.
What stays on your device
Stored in the app's private storage, readable only by Stride:
- Recorded runs, including the full GPS track, splits, pace, elevation and any notes
- Your settings, units, audio cue preferences and privacy zones
- Manually entered runs
- Your local personal bests, history and trends
Deleting the app removes all of it. You can also erase it from inside the app under Profile, Data and privacy, Delete runs on this device. Privacy zones are applied when a route image is exported or shared, so the parts of a route inside a zone are cut off before the picture leaves the app.
What is sent to the league, and only if you join it
The league runs on a Supabase project we operate. Joining means choosing a runner handle. Until you do, nothing in this section happens.
When you submit a run, the server receives numbers about it:
- Start and end time, and the local calendar day
- Distance, grade adjusted distance, moving time and elapsed time
- Elevation gain and loss, maximum speed
- The split table, meaning the time and distance of each split
- Your best 21.1 km and 42.2 km times from that run, if any
- A random installation identifier and a run identifier, used to recognise duplicate submissions
No coordinates are included, no route, no map, no start or finish location. The server cannot reconstruct where you ran.
Your profile on the league holds the handle you chose, whether you appear anonymously, your country, and whether you opted in. Live status for your crew carries your state, the distance and duration so far, never a position. Crew features store the messages, reactions and duels you send. If you enable push, we store your notification token, your platform and your language so the season close and crew messages can reach you.
The verification rules mean submitted runs are checked for plausibility, and a rejected run is shown to you with the reason.
You can delete everything on the server from inside the app under Profile, Data and privacy, Delete my server data.
Maps
The map in the run tab loads vector map tiles from OpenFreeMap, run by Hyperknot Software Kft. in Hungary and delivered through Cloudflare. Their servers see your IP address and the tile coordinates your phone requests, which reveals the general area you are in. OpenFreeMap says it does not store IP addresses in its regular server logs. Your recorded track is not uploaded, it is drawn on top of the tiles on your device. Loaded tiles stay in a cache on your phone for up to 30 days. Map data is © OpenMapTiles and © OpenStreetMap contributors. OpenFreeMap’s policy is at openfreemap.org/privacy. Leaving the map view stops these requests.
Purchases
Stride Pro is sold through Google Play and handled by RevenueCat, which manages the subscription state. RevenueCat receives a purchase identifier and your entitlement status, and Google handles the payment. We never see your payment details, your card or your billing address. Pro changes nothing about points, ranks, boards or the challenge.
RevenueCat's policy: revenuecat.com/privacy
Anonymous usage events
Stride sends a small number of anonymous events to a service we run ourselves on Cloudflare: that the app was opened, that the Stride Pro screen was shown or closed, which price option was selected, and whether a purchase was started, completed, cancelled or failed. Each event carries a random installation identifier created on your phone, the app version, your language, the platform, the anonymous RevenueCat identifier and whether Pro is active. The service notes the country the request comes from and does not store your IP address. It answers with the price list your installation sees, so that everyone on the same price list keeps it.
No event contains anything about a run: no distance, no time, no route and no position. There is no advertising identifier and no third party analytics provider involved. Events are deleted after 400 days.
Notifications
Push notifications go through Firebase Cloud Messaging. Automatic initialisation is switched off, so Firebase issues an installation identifier and a token only after you have joined the league and allowed notifications. We store that token to notify you when a season closes or a crew message arrives, and nothing else. You can turn notifications off in the app or in Android settings.
Feedback you send us
If you write to us through the in-app support, we receive the message you wrote, the app version, your device model and Android version, your language, and whether you have Pro. This is only sent when you press send. The app does not contact the support service before your first message. Tickets are removed on request, see below.
Studio Bundle and referrals
Stride is part of the Studio Bundle, one purchase that unlocks Pro in several Clearpoint Studios apps, and it has referral codes. Both run on a service we operate on Cloudflare. The app sends this service the anonymous RevenueCat identifier and a one way hash (SHA-256) of your Android identifier. This happens once after installation on first launch, when you redeem a bundle code, when you open your invite code and when you use a referral link or code. The hash lets the service give Pro back after a reinstall on the same phone, limits how many devices one bundle code can unlock, and stops a referral code from being redeemed repeatedly from the same device. The identifier itself never leaves the device. If you installed Stride through a referral link, Google Play passes us the referrer string from that link.
Permissions and why they exist
- Location, precise and approximate: recording your run. Denying it means the tracker cannot record a route, and manual entries still work.
- Foreground service, location: keeping the recording alive while the screen is off. The persistent notification during a run is required by Android.
- Notifications: run controls during a session and, if you opt in, league notifications.
- Internet, network state: the league, purchases, map tiles, anonymous usage events.
- Wake lock: keeping the recording accurate during a run.
- Boot completed: restoring scheduled reminders after a restart.
Legal basis and where data is processed
Where the GDPR applies, we process the league data on the basis of your consent, given by joining with a handle, and to perform the service you asked for. Feedback is processed on the basis of your consent. Purchase state is processed to fulfil the contract. Anonymous usage events are processed on the basis of our legitimate interest in knowing whether the Pro offer works, and you can object by writing to us.
Our Supabase project and the referral and feedback services run on infrastructure in the European Union and the United States. Where data reaches the United States, the transfer is covered by the standard contractual clauses of the respective providers.
Data retention
How long each kind of data is kept, and what ends the retention:
- Runs, tracks, settings and privacy zones on your phone: kept until you delete them in the app or uninstall Stride. They are never copied to a server.
- League profile, submitted run summaries, season results, pod membership: kept while your handle exists, so rankings and history stay correct. Deleted immediately when you tap Delete my server data in the app, or within 30 days of an email request.
- Crew connections, messages, reactions, duels, live status: kept while your handle exists. Live status is overwritten by the next update and holds only the current run. Deleted together with the profile.
- Push notification tokens, platform and language: deleted when you leave the league, when you delete your server data, or when the token stops working.
- Support tickets and messages: kept while the conversation is open. Closed tickets are deleted no later than 12 months after the last message, or earlier on request.
- Bundle and referral records (your bundle code, your invite code, the hash of your device identifier): kept until you ask us to delete them.
- Anonymous usage events: deleted after 400 days. The installation identifier is discarded when you uninstall Stride or clear its data.
- Purchase state: RevenueCat keeps the anonymous app user identifier and entitlement status for as long as the subscription or lifetime purchase exists, according to its own policy. Google Play keeps the transaction under your Google account.
- Server backups: database backups exist for disaster recovery only and are overwritten within 30 days, so deleted data disappears from them within that window.
Data deletion happens on the server itself, not by hiding records. The steps for deleting without the app are at stride-a8x.pages.dev/delete.
Your rights
You can export your runs as GPX or CSV, and back them up as a file, from inside the app. You can delete your local data and your server data separately, both from inside the app. If you no longer have the app, the steps are at stride-a8x.pages.dev/delete. Under the GDPR you can also ask us for access, correction, deletion, restriction, portability, and you can object to processing. Write to clearpointstudios@proton.me and we will answer. You can complain to your local data protection authority.
Children
Stride is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has sent us data, write to us and we will delete it.
Changes
If this policy changes, the date at the top changes with it, and material changes will be pointed out in the app.
Contact
Clearpoint Studios
clearpointstudios@proton.me