SYNC WORKOUTS / Privacy
Privacy, with clear boundaries.
This notice describes the companion website. The mobile app and each connected provider have their own data processing and permission boundaries.
This website
No third-party advertising, analytics scripts, tracking cookies or third-party fonts are included. Pages and styles are served from this domain. The service does not offer workout uploads or a workout database.
Authorization callbacks
When a provider callback is enabled by the operator, this service validates its shape and forwards only an authorization code or error, state to a fixed app callback. It does not exchange codes, retain tokens or accept a caller-supplied destination. The app must validate the matching authorization attempt. Strava uses the separate OAuth broker.
Server operations
This service does not log request addresses, query strings, authorization headers or callback values. The hosting provider or an external TLS proxy may process connection metadata. The deployment guide requires those systems to exclude callback queries and credentials from logs.
Mobile data
The app reads and writes only the Health data and provider data allowed by your permissions and supported integration. Explicit exports can include sensitive health measurements and precise routes. Choose sharing destinations carefully.
Control and support
Manage permissions in the app, Apple Health or Health Connect and each provider’s settings. For a support request, do not attach tokens, callback links or health data unless you deliberately choose to share them through an appropriate private channel.