Legal

Privacy Policy

Version 1.3 - Effective 5 September 2026

This Privacy Policy explains how Afterlap handles information when you use the Afterlap iOS app, the Afterlap backend, and the website at afterlap.app together, the Service.

Privacy questions, data-access requests, and deletion requests can be sent to afterlap.app@gmail.com.

1. Privacy summary

2. Strava authorization and consent

Afterlap does not access your Strava data until you choose to connect Strava and approve Strava's authorization screen. That screen shows the permissions requested by Afterlap.

You can withdraw authorization at any time by disconnecting Strava inside Afterlap or by revoking Afterlap from Strava's My Apps settings. After authorization is withdrawn, Afterlap stops fetching new Strava data and handles deletion as described below.

3. Information we process

3.1 Strava connection data

When you connect Strava, Afterlap receives authorization credentials needed to maintain the connection and identify the authorized athlete. These credentials are stored server-side and are not exposed to other Afterlap users.

3.2 Strava activity data

For a newly created authorized activity, Afterlap may process the activity ID, activity type, existing activity name and description, distance, moving time, elapsed time, start time, pace or speed, heart rate, elevation, cadence, laps for Coach-mode structure detection, splits, and similar workout metrics made available by Strava and needed for the selected feature. Afterlap does not fetch Strava streams or precise route geometry for normal activity processing.

If you enable the optional weekly summary, Afterlap additionally reads a list of your own recent activities (covering roughly the past week) to compute weekly totals and a per-day breakdown, and writes the resulting recap into the description of your most recent activity for that week.

Afterlap uses this information only to analyze your own activities and create the title, description, weekly summary, or combination requested by you. The resulting update is written back to the same athlete's activity.

3.3 AI text generation

Afterlap analyzes your activity on its backend first and computes a compact set of workout facts (a sanitized summary such as distance, pace or speed, elevation, detected workout structure, and similar metrics). To turn those facts into readable text, Afterlap sends this sanitized workout context — not your name, email address, Strava athlete ID, OAuth credentials, profile information, precise GPS route coordinates, raw Strava streams, or raw lap arrays — to a third-party AI provider (currently Google Gemini and/or Anthropic Claude, accessed through their APIs).

The AI provider processes the summary solely to return the requested title, description, or weekly summary for you. Afterlap does not use Strava data to train, develop, or improve AI or machine-learning models, and Afterlap's AI providers are contractually restricted, under their API terms, from using data submitted through their API to train their models. The generated text is written back only to your own Strava activity.

3.4 Afterlap settings and service metadata

Afterlap stores your selected mode, rewrite target, output language, tone options, weekly-summary preference, app-signature preference, app language, theme, onboarding state, and similar preferences. The backend may also retain non-Strava service metadata needed to operate Afterlap, such as an internal user identifier, app-integrity (device attestation) identifiers, subscription entitlement, free-tier processing counter, and security or job-status information that does not contain cached Strava activity data or workout-derived content.

3.5 Subscription and entitlement data

Purchases are handled by Apple through the App Store. Afterlap does not receive your payment-card number, Apple Account password, or full billing credentials. The backend may store Apple transaction identifiers, subscription status, expiration dates, and entitlement records needed to provide paid features.

3.6 Support messages

If you contact support, Afterlap receives your email address and the information you choose to include. We use it to respond to you, diagnose the issue, and maintain an appropriate support record. Please never send Strava access tokens, refresh tokens, authorization codes, or passwords.

3.7 Website requests

afterlap.app is a static website. Hosting and network providers may process standard request information such as IP address, user agent, requested URL, timestamp, and security events to deliver the site and protect it from abuse.

4. How we use information

Afterlap does not use Strava activity data or data derived from Strava activity data to build public datasets, perform cross-user analytics, generate advertising audiences, benchmark Strava, or improve products through analytics based on Strava data.

5. Legal bases for EEA and UK users

6. Service providers and sharing

Afterlap does not sell personal information and does not disclose Strava activity data for advertising, data-broker, or unrelated commercial purposes.

Information may be processed by service providers that are necessary to operate the Service and are used only for their stated operational role, including:

Afterlap does not sell Strava data or disclose it to advertisers or data brokers, and does not use Strava data to train, develop, or improve AI or machine-learning models. The only sharing of activity-derived data for text generation is the purpose-limited processing by the AI providers described above.

7. Retention

To preserve limited Strava connection capacity for active users, Afterlap may automatically disconnect Strava in these cases: 7 days after the last successfully processed free activity exhausts the 20-activity free allowance if Pro is not started; 7 days after paid entitlement expires or is revoked when no remaining entitlement is available; or 90 days after the last Strava activity seen for an active Pro account. Automatic disconnect deletes the Strava connection and stored authorization credentials, and purges stored Strava-derived generated text and direct activity identifiers where applicable. It does not cancel an App Store subscription, reset free-trial accounting, or erase subscription history that Afterlap must retain for entitlement, legal, accounting, or abuse-prevention purposes.

8. Your data rights, access, and deletion

You can request a copy of personal data held by Afterlap by emailing afterlap.app@gmail.com with the subject “Afterlap data access”.

Disconnecting Strava — in the app or through Strava's My Apps settings — immediately stops further processing, revokes access where possible, and deletes your stored Strava authorization credentials. Raw Strava activity data is transient and is not kept as a durable record. The app also provides a Delete Afterlap Data action that disconnects Strava and removes backend account data under Afterlap's control.

To also remove the minimal processing records described in Retention, request permanent deletion using the instructions on Data Deletion. Following a valid deletion request, Afterlap deletes the connected athlete's remaining Strava-derived personal data — including the retained activity identifiers and generated text — from systems under Afterlap's control, except for the minimum records Afterlap must keep to meet a legal obligation (for example, tax, accounting, or fraud-prevention records). Afterlap provides written confirmation when a user-requested deletion has been completed.

Depending on where you live, you may also have rights to correct, export, restrict, or object to processing of your personal information and to lodge a complaint with a data-protection authority.

9. Strava usage data

Strava may monitor and collect usage information relating to use of the Strava API and may use that information for purposes described in Strava's API terms, including platform operation, support, security, compliance, and improvements to the Strava platform or API.

10. Children

Afterlap is not directed to children under 13. If you believe a child has provided personal information through the Service, contact us so we can take appropriate action.

11. Security

Afterlap uses technical and organizational measures intended to protect data, including server-side credential handling, access controls, transport security, app-integrity (device attestation) checks on sensitive requests, and infrastructure security controls. No system can be guaranteed completely secure.

12. International transfers

Service providers may process information in countries other than where you live. Where required, Afterlap relies on applicable transfer safeguards or other lawful transfer mechanisms.

13. Changes

Afterlap may update this Privacy Policy as the product, backend implementation, law, or third-party platform requirements evolve. The effective date above shows when this version became effective.