LEGAL
Privacy Policy
Last updated September 20, 2026. Short version: your data builds your plan, nothing else.
How we protect your data, at a glance
- Secure authentication: we use Strava's own OAuth 2.0 login screen. We never see or store your Strava password.
- Data encryption: everything is encrypted in transit (TLS), and our database provider encrypts stored data at rest (AES-256).
- No sharing: your data is never sold, shared with other users, or used for advertising. It is never used to train any AI model, see "AI and your Strava data" below.
- Easy disconnect: revoke access anytime from Strava's own settings. We detect it automatically and stop syncing within moments, no email needed.
- Transparency: the rest of this page explains exactly what we collect and why, in plain language, not fine print.
Who we are
RunStrengthLab is operated by Akansha Saxena, and is the controller of the personal data described here. You can reach us at saxenaakansha30@gmail.com. RunStrengthLab is an independent app. It is not affiliated with, endorsed by, or sponsored by Strava. Use of the app is also covered by our Terms of Service.
What we collect
From Strava, only after you authorize it, and read-only (we request the
read and activity:read_all permissions; the second includes activities you have marked private, so your training load is not undercounted):
- Your Strava athlete ID and profile photo link, used to sign you in and show your avatar.
- Access and refresh tokens Strava issues to us, used to read your activities on your behalf.
- Your recent running, walking, riding, and swimming activities. Strava sends us the full activity record, but we only use each activity's sport type, start date, and moving time. We read the last four weeks, and only when you ask for your fatigue reading or a plan is generated, not when you simply open the app. We do not store the activity records.
From you, during onboarding and ongoing use: your training goal, experience level, the equipment you have access to, the plans generated for you, and your feedback on individual exercises.
Technical data: a signed session cookie that keeps you logged in, and server logs (internal user ID, timestamps, and error details). We use no advertising or analytics cookies or trackers.
How we use it
Solely to generate and adapt your own strength training plan. Your recent activity is compared, in our own code, against your own normal training load to spot body parts you have been loading hard, and those are quietly left out of that day's exercise options. Your equipment, experience level, and goal shape which exercises you are offered. Your feedback tells tomorrow's plan what to avoid. We also show you the numbers behind your reading (your activity counts, training load, and most recent activity), only to you, and only when you ask for it. That is the entire use case.
What we keep from Strava, and for how long
- Activities, and anything calculated from them: not stored. They are read live from Strava when needed, used to work out your training load, and discarded once the calculation is done. We keep no weekly totals, averages, or history of your activity.
- Athlete ID, tokens, and photo link: kept until you disconnect Strava (tokens and photo link are erased; see below for the athlete ID) or delete your account.
- Per-plan notes: each generated plan may record which body parts were left out because of high fatigue. Those notes are erased when you disconnect Strava or delete your account.
If you delete an activity on Strava, it stops counting the next time we read your activities.
AI and your Strava data
Your Strava data is never given to any AI model, in any form, raw or summarized. It only ever gets compared against your own recent training in our own code, which narrows the list of exercises available before the AI model is involved. We never use Strava data to train, fine-tune, or evaluate an AI model.
What the AI model does receive to write your plan: your goal, the list of exercises available to you, your past exercise feedback, and your recent strength sessions, tied to an internal numeric ID rather than your name.
What we don't do
We never share your data with other users. We never sell it, rent it, or use it for advertising. We never use your Strava data for analytics, product research, or building datasets across users. We only ever compare your data against your own history. We never post anything back to your Strava account.
Service providers who process data for us
We use the providers below to run the app. They act on our instructions and only for the purpose listed. None of them receives your Strava activity data, except where noted.
- Strava: the source of your activity data, subject to Strava's Privacy Policy. Strava is a separate, independent controller of your data. Strava may also collect usage data about how our app uses its API, as described in its own policies.
- Amazon Web Services (Mumbai, India region): hosts the app and stores its server logs. Your Strava data passes through it while a reading is calculated, and your Strava tokens are handled by it as part of running the app.
- Neon: hosts our database, which holds everything listed above, including your Strava tokens.
- Anthropic: the AI model provider that writes your plan from the non-Strava inputs described above.
- Langfuse: records our AI requests and responses so we can monitor cost and quality. Those records contain no Strava data.
- Google Fonts: delivers the typefaces on our pages, so your browser contacts Google when a page loads.
Some of these providers process data outside your country, including in the United States and India. Where the law requires it, transfers rely on the provider's standard contractual safeguards.
Why we may process your data
Where data protection law such as the GDPR applies: we read your Strava data because you consented by authorizing access, and you can withdraw that consent at any time. We process your equipment, goal, and feedback to provide the service you asked for. We keep basic server logs for security and reliability, which is our legitimate interest.
Your control and your rights
Log out anytime to end your session.
- Disconnect Strava (Settings): we revoke our access at Strava and delete your Strava tokens, profile photo link, and per-plan fatigue notes. Your plans, equipment, and feedback history stay. We keep your Strava athlete ID so that reconnecting picks up right where you left off.
- Delete My Account (Settings): permanently deletes your entire account and everything associated with it, including your Strava athlete ID. This takes effect immediately and cannot be undone.
- Revoke from Strava: you can also remove our app under Strava's settings. We detect this automatically, usually within moments, and delete your Strava tokens, profile photo link, and per-plan fatigue notes the same as using Disconnect Strava above. Your plans, equipment, and feedback history stay unless you also use Delete My Account. If automatic detection is ever delayed, email us and we will make sure it's done within 30 days.
- Access, copy, or correct your data: email us and we will send you a copy of the data we hold about you, or fix anything that is wrong, within 30 days.
- Object or restrict processing: email us. Where the GDPR applies you also have the right to complain to your local data protection authority.
If you cannot access your account to do any of this yourself, contact us using the details below and we will take care of it.
Security
Data is encrypted in transit, and our database provider encrypts stored data at rest. Access to production systems is limited to the person who runs the app. If a security incident affects your data, we will notify you and Strava as required by law and by Strava's API terms.
Children
RunStrengthLab is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has signed up, contact us and we will delete the account.
Changes
If how we handle your data changes in any meaningful way, we will update this page and its "last updated" date. If a change affects what we ask Strava for, we will ask for your permission again.
Contact
Questions about your data, or a request from the list above? Reach out at saxenaakansha30@gmail.com.