Privacy

Your data.
Your decisions.

How the current Stride build handles your information.

Effective 8 September 2026 · Operated by Afek Banyas. For support or privacy requests, contact afek10@gmail.com.

What Stride uses

Account and profile. Your email is used for sign-in. You can add a first name, optional age and maximum heart rate, a women’s or men’s fitness reference group, sleep target, wake time and time zone to personalize your experience.

Connected health records. With your permission, Stride reads sleep sessions and stages; heart rate, nightly heart-rate variability and resting heart rate; breathing rate, oxygen saturation, temperature variation and available fitness estimates; steps, active energy and recorded exercise. Availability varies by device and permissions.

Stride requests read-only access to three Google Health categories: activity and fitness, sleep, and health metrics and measurements. It does not connect directly to your Fitbit over Bluetooth or write changes to your original Google Health records.

Information you add. Journal ratings, optional habits, notes and planned sessions are saved to your account. Unanswered journal questions remain unanswered.

Why it is used

Your records support the visible features in the app: sleep views, personal recovery estimates, recorded-activity load, health signals, cardio fitness age, trends, journal associations and planning. Connection metadata and request limits help manage imports, prevent duplicate syncs and protect account access.

Stride's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the user-facing features described in this policy.

Sharing, transfer and disclosure of Google user data

Google user data includes the health records imported from Google Health, connection permissions and metadata, and Google access and refresh tokens. Stride shares or discloses this information only as described below, using the data needed for each purpose.

  • Supabase (backend service provider): Stride transfers imported Google Health records and connection metadata to Supabase for storage and processing, and stores Google tokens there in encrypted form. Supabase provides the database, authentication and server functions that import records and deliver them to your signed-in app. Its infrastructure providers, including Amazon Web Services for the hosted database, process this data as part of providing those services.
  • Google (connected data provider): Stride sends authorization codes, tokens and requests to Google to establish your connection, read the records you authorize, refresh access or revoke it. Stride does not upload your journal, plans or calculated wellness scores to Google Health.
  • Afek Banyas (Stride's operator): Human access to Google user data is limited to specific support you explicitly agree to, investigating security issues or abuse, or complying with applicable legal requirements. Your health records are not routinely read by the operator.
  • Legal disclosures: Stride may disclose the minimum necessary Google user data to competent authorities when required by applicable law or a valid legal process.
  • At your direction: Export returns your records to you. If you choose to share the exported file, the recipient receives the information you include.

Services that do not receive imported Google Health records: Resend receives your Stride sign-in email address and one-time code to deliver authentication emails; these messages contain no health records or Google tokens. OpenAI Sites and Cloudflare host this public information website and may process ordinary request metadata, such as your IP address. Stride does not send imported Google Health records or Google tokens to these website-hosting services.

Stride does not sell or rent Google user data, disclose it to advertisers or data brokers, use it for advertising, credit or lending decisions, or send it to AI services or use it to train generalized AI or machine-learning models. Stride does not otherwise share, transfer or disclose Google user data for purposes outside this policy.

Apple Health data on your iPhone

In iOS builds supporting Apple Health, you can separately authorize read-only HealthKit access for sleep sessions and stages, heart rate, HRV (SDNN), resting heart rate, respiratory rate, blood oxygen, sleeping wrist temperature, VO₂ max, steps, active energy and workouts. These may come from Apple Watch or other apps and accessories that write supported records into Apple Health. Stride reads up to 60 days, including source and device metadata needed to identify readings and avoid duplicates. It does not request clinical records or write, modify or delete HealthKit records.

Stride uses these readings for its visible wellness features and computes estimates on the iPhone. The imported readings remain in the current app session's memory and are re-read from Apple's protected HealthKit store after reopening. Stride does not upload these readings or their calculated scores to Supabase, RevenueCat, Resend, Google, website hosts or analytics/AI services, and does not create its own persistent HealthKit-record cache or cloud backup. Apple controls storage and any synchronization of the original Health database under your Apple settings. The selected-source preference is saved locally for your Stride account. Profile details, journal entries and plans that you enter in Stride continue to use the account services described elsewhere in this policy.

You choose individual read permissions in Apple's permission sheet and can change them in the Health app. Apple does not reveal whether a missing type was denied or has no records. Disconnect Apple Health, sign-out and successful account deletion remove the imported session view from Stride without altering the original Health records. Disconnecting Stride does not revoke iOS permissions; use the Health app to do that. A later connection requires Stride's disclosure again.

A user-requested export may include the Apple readings currently available in the app session. If you choose to share the exported file, your chosen recipient receives it. Stride does not sell, rent or use Apple Health data for advertising, marketing, data brokerage, insurance or credit decisions, or train generalized AI models with it. Health records are not included in application diagnostic logs.

Subscription and consent records

Apple processes payments. Stride does not receive your complete payment card or bank account details. Apple handles purchase confirmation, renewals, payment recovery and refund decisions under its own terms and privacy policy.

RevenueCat verifies membership. We use RevenueCat to associate App Store purchase and subscription information with your random Stride account identifier. This includes product and transaction identifiers, purchase and expiry dates, store and sandbox status, trial eligibility, renewal status and billing or refund events. Its SDK can also process technical information such as app and SDK version, device platform and IP address to operate the service. We do not send your Google Health records, Google credentials, journal, wellness scores, name or email to RevenueCat. We do not enable advertising attribution or send advertising identifiers.

Supabase stores access and consent. The backend stores the verified membership status, relevant expiry and verification times, and the versions of the Terms and Privacy Policy you accepted with the acceptance time. Limited subscription event records support reliable processing, reconciliation and abuse prevention. Processed event identifiers, types and times are retained for up to 90 days after processing. Events that need retry or investigation remain queued until resolved; account deletion removes their link to your Stride account. They contain no health records, email address, receipts or payment-card details. Subscription decisions do not rely on the app claiming that a payment succeeded.

Account deletion requests removal of the associated RevenueCat customer record as well as Stride's active account records. Apple retains its own transaction records under its policies; deleting Stride does not cancel an Apple subscription or delete those records. Providers may retain limited records where necessary to comply with law, resolve disputes or protect their services. You can contact us about retained information or your data rights. See RevenueCat's Privacy Policy and Stride's subscription terms.

How we protect sensitive data

Stride treats Google Health records and Google authorization tokens as sensitive data. The following safeguards protect their confidentiality and help prevent unauthorized access:

  • Encryption in transit: The app communicates with the hosted backend over HTTPS/TLS. Server requests to Google's authorization and health APIs also use HTTPS/TLS.
  • Encryption at rest: Supabase encrypts the hosted database at rest using AES-256, as described in its security documentation. Stride additionally encrypts Google access and refresh tokens with AES-256-GCM before storing them. The encryption key is held in server secrets separately from the database.
  • Access controls: Database row-level security restricts signed-in users to their own records and requires an active session. Google credentials are kept in a private database schema that app users cannot read. Privileged backend keys and Google tokens are not delivered to the app or included in data exports.
  • Protected authorization: Google connections use a one-time, expiring authorization state, PKCE verification and an allowlist of return addresses. The backend checks authenticated sessions and limits sensitive requests to reduce replay and abuse.
  • Device and browser storage: Native apps use operating-system secure storage for sessions and cached health records. Browser health records stay in memory; browser sign-in storage is described below.
  • Limited application logging: Application error handlers log error codes and status rather than health records, authorization codes or tokens. Infrastructure providers may retain request and security logs under their own retention schedules.

No storage or transmission method can guarantee absolute security. To report a suspected data-security issue, contact afek10@gmail.com; do not include health records, passwords or sign-in codes.

Where it lives

Stride's backend. Supabase provides authentication and the database storing your account, imported Google Health records, journal and plans. Access rules restrict each signed-in account to its own records. Google connection credentials are encrypted on the server and are not stored in the Flutter app.

On your device. The iOS and Android apps use operating-system secure storage for sessions and cached records. The browser app keeps health records in memory, rather than persistent browser storage.

Browser sign-in. The current tab's session storage holds your sign-in session. A sign-in verifier is stored separately across tabs with a one-hour validity period, so an email link can open in a new tab. It is removed after a successful exchange; expired entries are removed when read. It contains no health records.

Sign-in messages. Supabase Auth and Resend process your email address and one-time sign-in code to deliver authentication messages from signin@strideapp.health. Health metrics are not included.

This website. This website has no analytics scripts or contact form and does not collect health records. Hosting infrastructure may use cookies for access control or security. Ordinary web requests reach the hosting provider, which may process request information such as an IP address.

The published website is hosted by OpenAI Sites, using Cloudflare infrastructure. Stride's account database region is Frankfurt, Germany.

Your choices and controls

You choose whether to connect Google Health and which requested permissions to grant. The current connection requires all three requested read-only permissions. You can decline without connecting. Sample mode uses fictional records and does not upload those records to your real account.

  • Export: Open your profile icon, then Your space → Export your data for a portable JSON copy.
  • Disconnect: Choose Disconnect under your Google Health connection to stop new imports. Existing Stride records remain.
  • Delete: Choose Delete account in Your space. After confirmation, Stride revokes Google access and removes the account and associated app records. See the full steps.

Deleting Stride records does not delete the original records held by Google Health. Signing out or uninstalling the app does not delete your server-side account.

We retain your account records while your account remains active. Successful account deletion removes its records from the active database. Infrastructure logs and backups, where present, follow provider retention schedules and are not necessarily erased immediately. Your original Google Health records are unaffected.

Wellness estimates, with context

Recovery compares nightly heart-rate variability and resting heart rate with your prior history and includes sleep context. Baselines require at least seven prior observations. Confidence and missing data are visible in the app.

Sleep performance uses your chosen target. Observed sleep shortfall does not assume what happened on a missing night. Activity load summarizes recorded exercise; it is not a measure of all-day stress or muscular tissue load.

Cardio fitness age compares the median of available VO₂ max estimates in your selected one-day, seven-day or 30-day window with published, sex-specific treadmill fitness references. The reference-group choice is optional and saved in your profile. This is a population fitness comparison, not a validated measure of biological age, cellular aging, remaining lifespan or an aging rate. Wearable estimates and laboratory measurements differ, and the reference population may not represent you.

Journal associations compare reported habits with next-day recovery and show uncertainty. An association does not prove causation.

Stride is intended for adults and general wellness. It is not a medical device, does not diagnose conditions and does not replace professional care.

Contact and policy updates

For a privacy question or a request concerning your records, contact afek10@gmail.com.

Any material change to how connected health data is used will need an updated notice and, where required, renewed consent before that use begins.

Stride is independent of Apple, Google and Fitbit. Those names describe intended compatibility, not sponsorship or endorsement.