Stz

Privacy policy

Last updated 25 September 2026.

What Stz reads from Strava

When you connect, Stz asks Strava for permission to read your profile and your activities, including private ones.

From your profile it uses your id, first name and unit preference. For each run you open, it also reads the run's details (including its per-km or per-mile splits), heart rate, cadence and altitude data, and its route. To build your weekly dashboard and week cards it also reads the list of your recent runs (name, date, distance, time, elevation and route outline), never the details of runs you haven't opened.

What is stored

Nothing goes into a database. Your Strava access is kept in an encrypted cookie in your browser: your id, first name and Strava access tokens.

To keep card previews quick, the server holds a run's details and your recent runs list in memory for up to 10 minutes. They are never written to disk, and they are deleted when you disconnect or when Strava tells us you revoked access.

Who can see it

Only you. Your runs and stats are never shown to anyone else: there are no public pages, galleries or share links. A card is an image you download or share yourself.

Strava data is never sent to any AI or machine-learning service.

Other services

Strava, to sign you in and provide your data.

If a run's name contains emoji, only those emoji characters are requested from the jsDelivr CDN so they can be drawn on the image.

Cookies

Stz sets a sign-in cookie (encrypted, up to 30 days), a language cookie (one year) and a short-lived cookie that protects the login flow. There are no analytics or advertising cookies.

How to disconnect

Choose Log out in Stz. This revokes Stz's access at Strava and clears your cookie.

You can also revoke access at any time in Strava under Settings, My Apps.