TRACED
Privacy Policy
Last updated: 25 August 2026
This policy explains what data TRACED (“the app”, “we”) collects, why, and the choices you have. TRACED is operated by Thomas Baudry Consulting, Paris, France. For any question, contact support@get-traced.app.
1. What TRACED does
TRACED imports your workouts from Strava and turns them into images you can customise and share. Connecting Strava is optional and separate from signing in; you can use, and delete, either independently.
2. Data we process
Account
- When you sign in with Apple or Google we receive your email address and, if you allow it, your name. We never see or store a password.
Strava data (only if you connect Strava)
- Access credentials. Strava OAuth tokens are stored encrypted (AES-256-GCM); the encryption key is held only on our server and never leaves it or reaches the app.
- Activities. The activities you import — type, title, date, distance, time, pace/speed, elevation, splits, and, when present, heart rate, cadence, power, calories, the GPS route, and the city/region the activity started in.
Content you create
- The designs you make and export, and any photo you add to a design. Photos and thumbnails are stored in private, per-user storage that other users cannot access.
Subscriptions
- If you buy a subscription, purchase and entitlement status is processed through the app store and RevenueCat. We do not receive or store your card details.
Diagnostics & usage
- We may collect limited crash reports and product-analytics events to keep the app working and improve it. These are tied to a random identifier, not to your Strava content.
3. Why we process it (legal bases)
- To provide the app (import activities, render and export visuals) — performance of our contract with you.
- Security and reliability (encrypting tokens, preventing abuse, diagnosing crashes) — our legitimate interest.
- Analytics — your consent where required, which you can withdraw.
4. Who we share it with
We do not sell your data. We use these processors to run the service:
- Supabase — database, authentication and file storage (European Union).
- Strava — the source of imported activities, under Strava’s API terms.
- Apple and Google — sign-in.
- RevenueCat and the app stores — subscription management.
- A crash-reporting and an analytics provider, when those are enabled.
5. Strava, specifically
TRACED accesses Strava only with the scopes needed to read your activities
(read, activity:read_all). When you disconnect
Strava in the app, we revoke TRACED’s access at Strava and delete the imported
activities and stored tokens. You can also revoke access at any time from
strava.com/settings/apps.
If Strava tells us an activity was deleted, we delete our copy. Data from Strava
is used only to provide TRACED to you; it is not sold, and it is not used to
train machine-learning models.
6. Retention & deletion
- Disconnect Strava → imported activities and Strava tokens are deleted.
- Delete your account (Settings → Delete account) → all of your data is permanently removed: profile, connections and tokens, activities, designs, exports, stored photos, and entitlements.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. You can delete everything yourself in the app, or contact support@get-traced.app. You may also complain to your local data-protection authority.
8. Children
TRACED is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
9. Changes
We will update this page when our practices change and revise the date above.