Privacy policy
StrideAI is an early-stage personal running-coach application operated by Viet Le in Vietnam. This notice explains how information is handled when you use StrideAI at stride-ai.app.
Information we handle
- Training and recovery inputs: athlete identifier, race goals, training plans, workout dates, distance and intensity, sleep, heart-rate variability, resting heart rate, soreness, pain indicators, fatigue, training decisions, and outcome notes you provide.
- Connected activities: after you authorize Strava, we receive your Strava athlete identifier and name, authorization tokens and permissions, and activity summaries. These can include activity names and types, dates, distance, duration, heart rate, elevation, cadence, and location or route information included in the source summary. Private activities are included if you grant that permission. Activity summaries are stored for training-history and recovery features.
- Uploaded activities: information parsed from Garmin CSV or TCX files you choose to upload. Direct Garmin Connect API access is not currently enabled.
- Generated information: load calculations, recovery assessments, recommendations, explanations, weather context, outcome comparisons, and diagnostic records.
- Technical and contact information: your browser sends ordinary request information, including IP address and browser details, to the hosting service. If you contact us, we receive your email address and message.
Why information is used
We use information to provide your training history, assess recovery and recent load, suggest workout adjustments, explain recommendations, show relevant weather, maintain connected services, troubleshoot problems, and respond to requests. Recommendations support your own decisions; they are not medical diagnoses or treatment.
We do not sell personal data or use activity and recovery information for advertising. Connecting Strava and providing optional recovery measurements are voluntary. Without them, some recommendations or features may be unavailable or less complete.
Services that receive information
- Railway: hosts the application and its persistent database. The current application is deployed in the United States, so information may be processed outside your country.
- Strava: handles your authorization and receives API requests needed to retrieve activities and refresh access tokens. StrideAI does not ask for your Strava password.
- Open-Meteo: receives activity-start coordinates and dates when StrideAI adds historical weather after a Strava sync. For a forecast, it receives the selected coordinates and date; its geocoding service receives place names you search. These requests do not include your Strava tokens or athlete name.
- AI explanations: StrideAI supports optional OpenAI-generated explanations. If enabled, the approved coaching action, recovery factors, safety flags and selected historical outcome context are sent to OpenAI. Without that configuration, explanations are generated within StrideAI. Strava authorization tokens are not part of the explanation prompt.
- Email services: process correspondence when you contact the operator.
Service providers also handle information under their own policies. Information may additionally be disclosed when legally required or necessary to address misuse or protect the service and its users.
Storage, access and retention
Training records and connection details are stored in the application's database. Access to personal API data is restricted by the deployment's access key; website connections use HTTPS. No storage or transmission method can guarantee absolute security.
The current personal deployment has no automatic expiry for stored training records. Records remain until the operator removes them. Retention is reviewed when you request deletion or stop using the service, taking into account maintaining requested training history, resolving support or security issues, and any applicable legal obligations. There is no self-service account deletion screen.
Your choices and requests
You can stop uploading or entering information, disconnect Strava in the app, and revoke authorization in Strava's own settings. Disconnecting in StrideAI removes stored connection tokens but does not automatically delete previously imported activities or recommendations.
Contact Viet Le to request access, a copy, correction or deletion of your stored information, or to raise a privacy concern. We may ask for enough information to verify the request. Depending on your location and applicable law, you may also have rights to restrict or object to processing, withdraw consent, or complain to a privacy regulator. Withdrawing authorization stops future access but does not itself erase previously stored data.
Browser storage
If you save an access key, StrideAI stores it in your browser's local storage and sends it to the app with protected requests. You can remove it by clearing the key in the app or clearing site data in your browser. This deployment does not include advertising trackers or third-party analytics scripts.
Children and changes
StrideAI is intended for adult personal and beta use. Please contact us if a child's information has been submitted. We will update this notice and its effective date when data practices change, including before introducing direct Garmin Connect access or materially different uses.