Skip to main content

Privacy policy

Last updated: August 12, 2026

What we collect

RunPattern reads your Strava run data (distance, pace, heart rate, and related metrics) to build a pacing profile and trend insights. We do not post to Strava on your behalf.

  • Account email (via Supabase Auth, when enabled)
  • Strava OAuth tokens (stored securely on our API server)
  • Recent run summaries used for threshold calibration

How we use it

Data is used solely to display your dashboard, compute pacing trends, and personalize threshold bands. We do not sell your data.

Strava

RunPattern uses the Strava API with read-only access (read, activity:read). We never post to Strava, never show your Strava data to other users, and never use Strava data to train models or feed third-party systems — pacing profiles are computed by a deterministic rules engine inside our own backend. Your use of Strava data is also subject to Strava's privacy policy. Strava may monitor and collect usage data about our application's use of the Strava API (such as API request metadata) for its own business purposes, as described in the Strava API Agreement.

Data retention & deletion

Strava activity data is held only as a short-lived cache: it is refreshed each time you sync and automatically deleted if not refreshed within 7 days, in line with Strava's API policy. Insights that RunPattern generates from your runs (pacing profiles and trends) are kept so you can see your history, and are deleted when you disconnect.

You can disconnect Strava at any time from Settings. Disconnecting revokes RunPattern's access at Strava and deletes your cached Strava activities and Strava-derived insights from our systems, with on-screen confirmation. If you revoke access from Strava's side, or delete your Strava or RunPattern account, we delete the same data — promptly, and in all cases within 30 days. You can also request deletion, or a copy of your data, by emailing hello@runpattern.coach; we will confirm in writing when deletion is complete.

Subprocessors

We use a small number of service providers to run RunPattern: Vercel (hosting, USA/EU), Supabase (authentication and database, EU), and Stripe (billing — no Strava data is sent to Stripe). Where personal data is transferred outside the UK/EEA, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

Your rights

Under the UK GDPR and GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. Contact us at hello@runpattern.coach to exercise these rights. You also have the right to complain to your supervisory authority (in the UK, the ICO).

Cookies

We use essential cookies for sign-in (Supabase), your unit preference, and to remember your cookie choices. Optional analytics cookies are off unless you opt in via the cookie banner. See our Cookie policy or use Cookie settings in the footer to change preferences.

Billing

RunPattern Pro subscriptions are processed by Stripe when paid plans launch. We do not store card numbers on our servers.

Pro exercise videos

RunPattern Pro may show exercise demonstration videos sourced from YMove. Our API requests exercise metadata from YMove; video files are delivered from their CDN using temporary signed URLs. We do not send your Strava data or account email to YMove for this feature.

Contact

Questions about this policy? Use our contact form or email hello@runpattern.coach.

Related

Privacy policy — RunPattern