Privacy
Your data.
Your decisions.
How the current Stride build handles your information.
Effective 7 September 2026 · Operated by Afek Banyas. For support or privacy requests, contact afek10@gmail.com.
What Stride uses
Account and profile. Your email is used for sign-in. You can add a first name, optional age and maximum heart rate, a women’s or men’s fitness reference group, sleep target, wake time and time zone to personalize your experience.
Connected health records. With your permission, Stride reads sleep sessions and stages; heart rate, nightly heart-rate variability and resting heart rate; breathing rate, oxygen saturation, temperature variation and available fitness estimates; steps, active energy and recorded exercise. Availability varies by device and permissions.
Stride requests read-only access to three Google Health categories: activity and fitness, sleep, and health metrics and measurements. It does not connect directly to your Fitbit over Bluetooth or write changes to your original Google Health records.
Information you add. Journal ratings, optional habits, notes and planned sessions are saved to your account. Unanswered journal questions remain unanswered.
Why it is used
Your records support the visible features in the app: sleep views, personal recovery estimates, recorded-activity load, health signals, cardio fitness age, trends, journal associations and planning. Connection metadata and request limits help manage imports, prevent duplicate syncs and protect account access.
The current build has no advertising integration and does not send health records to an AI model. It does not sell health records or use them to target advertisements.
Google access is governed by the Google API Services User Data Policy. Stride uses Google Health data to provide the features described here, consistent with Google’s Limited Use requirements. Health records are not sold or used for advertising. Access by the operator is limited to support you request, security, or legal obligations.
Where it lives
Stride's backend. Supabase provides authentication and the database storing your account, imported records, journal and plans. Access rules restrict each signed-in account to its own records. Google connection credentials are encrypted on the server and are not stored in the Flutter app.
On your device. The iOS and Android apps use operating-system secure storage for sessions and cached records. The browser app keeps health records in memory, rather than persistent browser storage.
Browser sign-in. The current tab's session storage holds your sign-in session. A sign-in verifier is stored separately across tabs with a one-hour validity period, so an email link can open in a new tab. It is removed after a successful exchange; expired entries are removed when read. It contains no health records.
Sign-in messages. Supabase Auth and Resend process your email address and one-time sign-in code to deliver authentication messages from signin@strideapp.health. Health metrics are not included.
This website. This website has no analytics scripts or contact form and does not collect health records. Hosting infrastructure may use cookies for access control or security. Ordinary web requests reach the hosting provider, which may process request information such as an IP address.
The published website is hosted by OpenAI Sites, using Cloudflare infrastructure. Stride's account database region is Frankfurt, Germany.
Your choices and controls
You choose whether to connect Google Health and which requested permissions to grant. The current connection requires all three requested read-only permissions. You can decline without connecting. Sample mode uses fictional records and does not upload those records to your real account.
- Export: Open your profile icon, then Your space → Export your data for a portable JSON copy.
- Disconnect: Choose Disconnect under your Google Health connection to stop new imports. Existing Stride records remain.
- Delete: Choose Delete account in Your space. After confirmation, Stride revokes Google access and removes the account and associated app records. See the full steps.
Deleting Stride records does not delete the original records held by Google Health. Signing out or uninstalling the app does not delete your server-side account.
We retain your account records while your account remains active. Successful account deletion removes its records from the active database. Infrastructure logs and backups, where present, follow provider retention schedules and are not necessarily erased immediately. Your original Google Health records are unaffected.
Wellness estimates, with context
Recovery compares nightly heart-rate variability and resting heart rate with your prior history and includes sleep context. Baselines require at least seven prior observations. Confidence and missing data are visible in the app.
Sleep performance uses your chosen target. Observed sleep shortfall does not assume what happened on a missing night. Activity load summarizes recorded exercise; it is not a measure of all-day stress or muscular tissue load.
Cardio fitness age compares the median of available VO₂ max estimates over 30 days with published, sex-specific treadmill fitness references. The reference-group choice is optional and saved in your profile. This is a population fitness comparison, not a validated measure of biological age, cellular aging, remaining lifespan or an aging rate. Wearable estimates and laboratory measurements differ, and the reference population may not represent you.
Journal associations compare reported habits with next-day recovery and show uncertainty. An association does not prove causation.
Stride is intended for adults and general wellness. It is not a medical device, does not diagnose conditions and does not replace professional care.
Contact and policy updates
For a privacy question or a request concerning your records, contact afek10@gmail.com.
Any material change to how connected health data is used will need an updated notice and, where required, renewed consent before that use begins.
Stride is independent of Google and Fitbit. Those names describe intended compatibility, not sponsorship or endorsement.