Last updated: August 2, 2026
Introduction
Stay Obssd ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This policy explains what information we handle when you use our services and how you can control it.
How the App Works
Stay Obssd accounts use email and password, Apple, Google, or Strava. Email passwords are stored as one-way hashes, and connecting Strava is optional:
- If you connect Strava, you authorize read access to your public profile and activity:read_all access to your activities, including private activities.
- Your Strava activity data is fetched on demand and shown only to you, the authenticated athlete. We never display it to other users or use it for advertising, AI/ML training, aggregated analytics, or resale.
- Designs and editor state are stored locally in your browser or on your device. We do not store your Strava activities on our servers.
- On iPhone, Stay Obssd can read workouts, routes, heart rate, distance, and active energy from Apple Health after you choose to grant access. Apple Health records stay on your device and are used only to create the posters or clips you request. They are not uploaded to Stay Obssd servers, analytics, advertising systems, or other third parties. You can stop using Apple Health in Stay Obssd and change Health permissions at any time in iOS Settings or the Health app.
- Route maps for Strava activities request map images from Stadia Maps using route-derived map tile coordinates. The route sent by Strava has privacy-trimmed start and end points. Stadia Maps receives the tile request and network metadata such as your IP address; its published terms say API request and access logs are normally retained for approximately 7β14 days. We do not send your Stay Obssd account ID to Stadia Maps. Apple Health and manual activity routes never request third-party map tiles.
What We Store on Our Servers
- Account records: an internal user ID, provider account links, verified contact email, preferences, and a one-way password hash when you use email sign-in. OAuth tokens needed to maintain or revoke a provider connection are encrypted at rest and never shared. A connected Strava account also stores your athlete ID, granted scopes, and connection timestamps.
- Webhook event log: technical event envelopes from Strava, never activity contents, retained for up to 30 days for reliability and auditing.
- Billing: purchases made in the iOS app are processed by Apple and managed through your Apple account. Purchases made on the web are processed by Polar and managed through the web billing portal. We do not store card details.
We do not store your Strava activities, routes, or streams. Provider display names and avatars may be stored as part of your account profile.
Data Retention and Deletion
- Disconnect anytime: Disconnect Strava blocks Strava access, asks Strava to revoke the token, and deletes stored tokens after successful revocation. Your Stay Obssd account and other sign-in methods remain active. If Strava is unavailable, the encrypted token is retained only for retries and deleted within 30 days.
- Revoking on Strava: when Strava notifies us that you revoked access, we automatically delete stored tokens. A token-free security record expires within 30 days.
- Strava inactivity: after 90 days without Strava use, we automatically revoke Strava access and delete stored tokens. Your Stay Obssd account remains available and you can reconnect Strava later.
- Webhook event envelopes expire automatically after 30 days.
- You can permanently delete your account in Settings on the web or from the signed-in mobile app. Deletion revokes connected Strava and Apple authorization before removing account data. You can also contact us below; we complete deletion requests as soon as practicable and no later than 30 days.
Analytics
We use Umami only for anonymous analytics on public, signed-out pages and Vercel for hosting. Analytics does not load while you are signed in or on activity URLs, and authenticated Strava data is never sent to analytics providers.
Strava may collect technical usage data related to our use of the Strava API as described in the Strava API Agreement.
Cookies and Similar Technologies
On the web, we use a cookie to keep you signed in and a locale cookie to remember your language. The mobile app stores its signed session in encrypted device storage. Public-page analytics does not create an advertising profile. We do not use Strava data for advertising.
You can refuse cookies in your browser or remove the mobile app's local data, but some parts of the service may not work without a session.
Prohibited Uses and Sharing
We do not sell, license, aggregate, or use Strava data for advertising, product analytics, benchmarking, or AI/ML training, evaluation, context, or operation. We do not transfer raw Strava data to unrelated providers.
Children's Privacy
Our service is not directed to children under 13, and we do not knowingly collect personally identifiable information from children under 13.
Changes to This Privacy Policy
We may update this policy from time to time. We will post changes on this page and update the last-updated date.
Contact Us
For questions about this policy or to request deletion, contact us at:
Send us a message