TRACED

Privacy Policy

Last updated: 28 September 2026

This policy explains what data TRACED (“the app”, “we”) collects, why, and the choices you have. TRACED is operated by Thomas Baudry Consulting, Paris, France. For any question, contact support@get-traced.app.

1. What TRACED does

TRACED imports your workouts from Strava and turns them into ready made stickers you can share. You choose the sticker, its colour and its typeface. Connecting Strava is optional and separate from signing in; you can use, and delete, either independently.

2. Data we process

Account

  • When you sign in with Apple or Google we receive your email address and, if you allow it, your name. We never see or store a password.

Strava data (only if you connect Strava)

  • Access credentials. Strava OAuth tokens are stored encrypted (AES-256-GCM); the encryption key is held only on our server and never leaves it or reaches the app.
  • Activities. The activities you import: type, title, date, distance, time, pace/speed, elevation, splits, and, when present, heart rate, cadence, power, calories, the GPS route, and the city/region the activity started in.

Stickers you create

  • Stickers are rendered on your device and we never receive the image. It goes to your clipboard, or to your photo library if you tap “Save to Photos”.
  • We keep a usage record of each export, linked to your account: the format, the dimensions, the image quality, the file size, and whether the sticker carried the TRACED wordmark. It never includes the image itself.
  • TRACED asks for add-only access to your photo library so it can save a finished sticker. It cannot read or browse your photos, and there is no way to add a photo to a sticker.

Purchases (only if you subscribe to TRACED Premium)

  • Apple or Google takes the payment. We never receive your card or bank details.
  • Through RevenueCat, we receive a record of each subscription event: the product, the price paid, the currency and taxes, the store country, the store transaction identifiers, any offer code used, the dates of purchase, trial, renewal, cancellation, expiry or refund, and the reason the store gives for a cancellation or an expiry. It is linked to your account through a random identifier, never through your email.
  • To check and restore purchases, the app sends RevenueCat that random identifier, the store receipt or purchase token, your device type, operating system, app version and identifier, preferred languages, store country, the device identifier Apple gives each app vendor on iPhone (it is not the advertising identifier), and, as with any connection, your IP address.
  • We also read these records in RevenueCat’s dashboard to understand how the subscription performs: trials, conversions, renewals and cancellations.

Diagnostics & usage

  • We may collect limited crash reports and product-analytics events to keep the app working and improve it. These are tied to a random identifier, not to your Strava content.

Notifications

  • If you allow notifications, we keep your device’s push token with your account. A notification carries the name and distance of the workout it is about, or your week’s totals on Sunday. You can turn each kind off in Settings, or all of them in your phone’s settings.

3. Why we process it (legal bases)

  • To provide the app (import activities, render and export visuals): performance of our contract with you.
  • To provide TRACED Premium (unlocking what you paid for, restoring it on a new device): performance of our contract with you.
  • Keeping accounting records of purchases: our legal obligation.
  • Understanding how the subscription performs (purchase records read in RevenueCat’s dashboard): our legitimate interest.
  • Security and reliability (encrypting tokens, preventing abuse, diagnosing crashes): our legitimate interest.
  • Analytics: your consent where required, which you can withdraw.
  • Notifications: your consent, given when you allow them, which you can withdraw at any time.

4. Who we share it with

We do not sell your data. We use these processors to run the service:

  • Supabase: database and authentication (European Union).
  • Strava: the source of imported activities, under Strava’s API terms.
  • Apple and Google: sign-in, payment for TRACED Premium through the App Store or Google Play, and delivery of notifications.
  • RevenueCat: subscription management (United States). Data sent to it leaves the European Union under the European Commission’s Standard Contractual Clauses, included in RevenueCat’s data processing agreement.
  • Expo: passes notifications to Apple and Google for delivery (United States). It receives the push token and the text of each notification.
  • A crash-reporting and an analytics provider, when those are enabled.

5. Strava, specifically

TRACED accesses Strava only with the scopes needed to read your activities (read, activity:read_all). When you disconnect Strava in the app, we revoke TRACED’s access at Strava and delete the imported activities and stored tokens. You can also revoke access at any time from strava.com/settings/apps. If Strava tells us an activity was deleted, we delete our copy. Data from Strava is used only to provide TRACED to you; it is not sold, and it is not used to train machine-learning models. Strava itself may monitor and collect usage data about TRACED’s access to the Strava API (such as API request metadata) and may use it for its business purposes, as described in the Strava API Agreement.

6. Retention & deletion

  • Disconnect Strava → imported activities and Strava tokens are deleted.
  • Delete your account (Settings → Delete account) → all of your data is permanently removed: profile, connections and tokens, imported activities, and export records.
  • Push tokens are removed when you sign out, delete your account, or when Apple or Google report that the device no longer receives notifications.
  • Purchase records are the one exception. French accounting law requires us to keep them, and any promotional code you redeemed, for ten years after the end of the financial year. When you delete your account, we keep them pseudonymised: we remove your account and its identifier from them, and keep the accounting record, a one way hash of the identifier and the store transaction identifiers, which is what lets a later store refund or renewal be matched.
  • RevenueCat keeps its own copy of your purchase history, under the random identifier, as long as its data processing agreement allows. Deleting your account does not delete it automatically; write to support@get-traced.app and we will have it deleted.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. You can delete everything yourself in the app, or contact support@get-traced.app. You may also complain to your local data-protection authority.

8. Children

TRACED is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

9. Changes

We will update this page when our practices change and revise the date above.


TRACED · get-traced.app · support@get-traced.app
Powered by Strava.