stride.

Privacy Policy

Last updated: September 15, 2026

About this policy

This policy describes the Stride fitness web application and its connected Fitness Coach MCP backend. Stride helps you create a training profile, receive daily workouts, adapt exercises, and record performance. Workout information may reveal health-related details; provide only information you are comfortable sharing.

Information we access and collect

  • Google account identity: a stable Google account identifier, email address and verification status, and available display-name information. These associate you with your existing fitness-coach customer account.
  • Training information you provide: experience, goals, availability, readiness, workout choices, repetitions, loads, duration, distance, effort ratings, and session notes.
  • Generated information: training plans, exercise selections, workout sessions, adaptations, and performance history stored by the backend.
  • Technical information: requests and error diagnostics processed by the hosting and backend monitoring services, which may include network and device/request metadata.

Sign-in uses Google’s openid, email, and profile scopes. The app does not request access to Gmail, Google Drive, Calendar, or Google Fit, and does not receive your Google password. The frontend receives backend-issued session credentials, not your Google client secret.

How information is used

Account information is used to authenticate you and associate your fitness data with the correct customer. Training information is used to generate and adapt workouts, record performance, and support the fitness-coach service. Technical information is used to operate, secure, and diagnose the service. The current web implementation has no advertising or behavioral-analytics integration.

Storage on your device and the backend

Access tokens stay in browser memory. The gateway stores a backend refresh credential in a host-only HttpOnly, Secure, SameSite=Strict cookie with a rolling lifetime of up to 30 days, so refreshing the page can restore your session. JavaScript does not receive that refresh credential. Temporary OAuth state and the PKCE verifier are stored in sessionStorage during sign-in and removed after successful completion or rejected authorization validation. Signing out clears the refresh cookie and local session but does not revoke already-issued backend tokens or delete your stored fitness data.

The service worker stores public application-shell assets for installation and limited offline use. It does not cache authenticated requests, API responses, or OAuth callback requests. The web app does not persist your tokens in localStorage or sessionStorage. Its refresh cookie is used for authentication and requires cookies to be enabled. Google and third-party providers may use their own cookies when you visit their services.

Customer account, training, and OAuth records are stored by the connected backend, which uses Cloudflare D1 in production. A final retention schedule, backup policy, and deletion process must be confirmed by the service operator; this draft does not promise an automatic deletion deadline.

Providers and external content

Cloudflare hosts the frontend/gateway and production backend. Google provides authentication and hosted web fonts. The backend integrates Sentry for error reporting when configured, with default personally identifiable information collection disabled; this does not guarantee that every diagnostic is free of personal information. Exercise media may load from external catalog providers or open external websites, which receive normal network request information when contacted.

These providers operate under their own policies and may process information outside your country. This policy does not cover independently operated MCP clients or external sites you choose to use.

Your choices and requests

You can stop using the app, sign out, or remove its access from your Google account settings. Removing Google access does not itself delete backend fitness records or invalidate every backend-issued session credential. Contact the operator to ask about accessing, correcting, exporting, or deleting your information. The app currently has no self-service account-deletion screen; request handling and applicable legal rights must be finalized by the operator.

Updates

Changes to data handling should be reflected in this policy and its updated date. Review this page before sharing additional information.

Contact

Service operator: Stride service operator (identity to be confirmed).

Public contact details are being finalized. You can also use the developer support contact shown on the Google consent screen.